Skip to content
Kiwi Kiwi
Open navigation
Get the app Safety FAQ Legal

Legal document

Back to Legal

Kiwi Kiwi Verification and Face Processing Notice

Last updated: September 26, 2026

1. An optional, specific use of face information

Photo Verification uses a camera liveness check and facial comparisons to help determine whether your profile photos depict you. It can support a public Photo Verified badge. You can use Kiwi Kiwi without choosing Photo Verification, subject to the ordinary account and discovery rules. Another member may choose a Photo Verified-only filter, but unverified profiles are not excluded from default discovery solely for lacking the badge.

Before this processing begins, the Profile Verification screen explains its purpose and provides this notice. Choosing Agree & Continue provides your specific permission to Kiwi Kiwi LLC and Amazon Web Services (AWS), our processing provider, for the collection, use, storage, and processing described here. General Terms acceptance or camera permission alone is not that consent.

2. Information and purpose

AWS’s Amazon Rekognition Face Liveness processes the camera session to evaluate whether it appears to involve a live person rather than a spoof. A successful reference capture is used to create a private mathematical facial representation, sometimes called a face template or verification reference. This representation is stored in a private provider collection. Kiwi Kiwi holds private references and limited records needed to operate the feature.

Kiwi Kiwi and AWS also analyze your current and future profile photos, including new or replacement photos, and compare suitable faces with the active verification reference. The purpose is to establish and maintain your Photo Verified status for the current profile, not to verify your legal identity.

Processing can include the liveness video and temporary reference image; face detection, image quality, and comparison information; the stored facial representation; current-photo check outcomes; and limited session, timing, retry, and consent information. Public surfaces expose the badge, not face templates, scores, provider identifiers, or detailed reasons. Your own verification screen can show a safe explanation of what needs attention.

3. What we do not use this permission for

We do not use this permission to build a broad index of ordinary members’ profile faces for duplicate-account, impersonation, ban-evasion, photo-reuse, or cross-account safety matching. That broad index is disabled for this version. A future additional use requires its own applicable notice, choices, and approval; this permission is not silently expanded to cover it.

We do not sell or license reusable face data for a third party’s independent use, use it for advertising, or authorize unrelated general-purpose model training with it. Ordinary image-content moderation is separate from Photo Verification. Declining verification does not exempt uploaded content from moderation.

4. AWS processing and storage

AWS/Amazon Rekognition helps perform the liveness check, create the verification representation, and compare photos. The stored collection entry is a facial feature representation rather than an archive of the original liveness image. It remains sensitive biometric information.

Kiwi Kiwi does not retain the raw liveness video in its own application storage, requests no liveness audit images, and does not configure a liveness output-image archive in an S3 bucket. We use the temporary reference image to establish the verification reference. Your ordinary profile photos are stored separately to provide your profile; they are not deleted simply because verification is turned off.

A short period of availability for a liveness session or reference-image API is not a guarantee that every provider-side copy is destroyed at that moment. Provider processing and deletion are governed by applicable law, our instructions, and the provider arrangements and controls. Our provider arrangements and applicable service-improvement opt-out controls restrict use of the verification inputs to providing the disclosed service and other processing specifically required by law, rather than optional use to develop unrelated services or models. We instruct the provider to delete the reusable representation when its retention ends.

5. The face check and the badge are different

A successful face check establishes a verification reference. The badge also requires the current visible approved photos to satisfy the comparison rules: at least one clear solo photo, or a photo where you are clearly the main person, must match, and there must be no clear contradictory solo/main-person photo.

Group photos can support verification when a suitable face in the photo matches your active reference, including when you are not the largest face in the image. They do not replace the clear matching solo/main-person baseline or override contradictory-photo rules. Other faces in a group do not automatically make a profile fail. Photos of pets, scenery, food, and hobbies are neutral; the main profile photo does not itself have to contain a face.

For a group-photo check, the process detects faces and temporarily compares individual face regions to identify a match to your active reference. Those regions are used only for the check and are not kept as a separate image archive. We do not add other people’s faces to a stored face collection or create reusable verification anchors for them through that comparison. Temporary analysis is still processing; not storing a bystander anchor does not mean no other face was analyzed. Your own consent does not supply a legally required consent on another person’s behalf. Upload only photos you have the right to use, with any permissions required for the described processing.

New photos may need clearer lighting or a more visible face. A missing badge can reflect photo quality, mismatch, pending checks, or a technical problem even when the previous successful face reference remains usable. The screen explains available next steps without treating every photo problem as a failed liveness check. Reordering unchanged photos does not, by itself, require a new camera check.

6. Redoing the face check

You can choose to reverify to update your reference without first turning verification off. Your existing valid reference remains in use until a replacement is successfully established. A cancelled, inconclusive, failed, or technically interrupted attempt does not, on its own, invalidate the previous good reference or remove an otherwise-supported badge.

A successful replacement is followed by checks of current photos. Old reusable references that are no longer needed are deleted/deindexed rather than kept as a permanent face-history archive. Independent changes to photo eligibility, consent, or legal retention can still require a badge change or deletion.

7. Turning verification off and on again

On the same Profile Verification screen, choose Turn off Photo Verification. The confirmation explains that the badge will be removed, future verification comparisons will stop, and reusable face-verification data will be deleted. Other account functions and ordinary profile photos remain, subject to their own rules.

Once withdrawal is accepted, verification processing is disabled and the reusable representation is promptly deleted/deindexed, including provider-side entries. Temporary protected cleanup information may remain only as needed to finish deletion reliably; a delayed callback or retry does not restore permission. We do not intentionally hold the face reference for another 30 days after withdrawal.

To turn verification on again, accept the current notice and complete a new liveness check. We record the new grant after withdrawal even if the notice wording has not changed. The deleted reference is not restored.

8. Retention and destruction

We retain an active reusable facial representation only while needed to maintain the optional Photo Verification feature and supported by valid permission. We stop active use and promptly delete/deindex it when you turn verification off, delete the account, or the verification purpose otherwise ends. When a new successful reference replaces an old reference, the old reusable reference is deleted/deindexed once no longer needed for the safe replacement; a failed replacement does not delete the last valid one.

Nationwide inactivity backstop: reusable verification face data is deleted/deindexed no later than 24 months after your last interaction with Kiwi Kiwi. Earlier withdrawal, account deletion, purpose completion, or a shorter applicable legal deadline prevails. A background check by our systems does not count as your interaction or renew that period. The backstop is not a requirement that active users repeat liveness every two years. Once an expired reference has been deleted, later verification requires fresh consent and liveness.

We review whether continued biometric retention remains necessary at least annually. If that review finds retention unnecessary, inadequate, or irrelevant to the disclosed purpose, we delete the affected data at the earliest reasonably feasible time and within any applicable deadline. The review does not extend an earlier purpose-end, withdrawal, or inactivity deadline. This schedule includes obsolete or orphaned provider references, not just the row marked active.

Deletion includes instructing AWS to remove the relevant stored face entries, removing reusable biometric references from Kiwi Kiwi’s active systems, and ending pending comparisons that no longer have permission. We retain only temporary protected information needed to complete and confirm cleanup safely. We do not characterize provider deletion as complete solely because a local link was removed.

Failed or cancelled attempts do not justify a reusable face-reference archive. After deactivation, unnecessary verification operating records are deleted or retired from ordinary use. Minimal non-biometric evidence of notice version, consent, withdrawal, and compliance may remain under applicable legal-record rules. That consent evidence does not include a face template, liveness image, similarity score, or provider Face ID.

Specific records may be preserved when a valid law, warrant, subpoena, or court order permits or requires an exception to destruction. Any such preservation is limited to the affected data, restricted in use and access, and ends when its legal basis ends. A generic safety, fraud, analytics, or backup label does not override the biometric destruction schedule. See the Account Deletion Policy and, where applicable, the Consumer Health Data Privacy Policy.

9. Changes to this processing

Clearer wording or other nonmaterial edits do not themselves cancel a valid reference or require you to repeat liveness. A materially changed processing scope or a legal requirement can require new consent before the changed processing applies.

When existing permission still lawfully covers the original use, that use and its eligible badge can continue without silently adding a new purpose. Renewing legal consent alone does not require a new camera check. If the current scope requires renewed consent that has not been given, we do not continue processing under an invalid permission; the affected feature or badge can be unavailable while consent is unresolved. We retain a reference during that period only where the existing retention remains lawful and within this schedule. If permission or the lawful basis for retention ends, we stop that processing and follow the applicable destruction requirements. If the reference has been deleted, a future opt-in needs fresh liveness.

10. Limitations, access, and contact

Liveness and facial comparisons can be wrong, inconclusive, delayed, or unavailable. Lighting, image quality, pose, appearance changes, accessibility needs, and device/provider performance can affect results. A failure does not establish misconduct.

Photo Verification is not government-ID, legal-identity, age, criminal-background, relationship-status, or safety verification. It is not a guarantee that a person is authentic in every respect, sincerely dating, trustworthy, responsive, or someone you will meet.

For questions or privacy requests, email support@kiwikiwi.dating. You may use the in-app controls to withdraw without closing the whole account. Applicable access, deletion, and privacy appeal rights are explained in Privacy Rights and Data Requests.

Kiwi Kiwi

A search-and-browse dating app with token-based matching, built to help people find what they’re looking for more easily and match more deliberately.

Get the appAboutSafetyFAQLegalPrivacyConsumer Health Data PrivacyTerms

© 2026 Kiwi Kiwi. All rights reserved.

Kiwi Kiwi is pre-launch.

Apple and the Apple logo are trademarks of Apple Inc. App Store is a service mark of Apple Inc. Google Play and the Google Play logo are trademarks of Google LLC.