Biometric Data Retention & Destruction Policy
Effective date: 1 August 2026 · Last reviewed: 1 August 2026
Illinois BIPA — 740 ILCS 14/15(a)Publicly available policy. This document constitutes the written policy on the retention and destruction of biometric identifiers and biometric information required under Section 15(a) of the Illinois Biometric Information Privacy Act (BIPA), 740 ILCS 14/15(a). It is freely accessible at this URL without any login or account requirement.
1. Scope and applicability
This policy applies to Emvio Intelligence ("Emvio", "we", "our") and governs all biometric identifiers and biometric information, as those terms are defined in 740 ILCS 14/3, that Emvio collects, stores, uses, or destroys in connection with its AI-powered video recruitment platform ("Emvio Recruit").
This policy applies to all individuals who participate in an AI interview session conducted through Emvio Recruit, including Illinois residents who are protected by the Illinois Biometric Information Privacy Act (BIPA), 740 ILCS 14/ et seq.
2. What biometric data we collect
Emvio Recruit collects or derives the following categories of biometric data during an AI interview session:
| Data type | BIPA classification | Description | How collected |
|---|---|---|---|
| Voice audio recording | Biometric identifier — voiceprint-capable data | Raw microphone audio captured during the interview session (PCM audio stream) | Browser microphone via WebRTC. Audio is streamed to Deepgram for real-time speech-to-text; the raw audio is not stored on Emvio servers — only the transcript is retained. |
| Gaze direction signals | Biometric information (derived from facial geometry) | Estimated eye-gaze direction, computed in-browser from camera frames using MediaPipe FaceMesh (Phase 2 feature). Raw video frames are never transmitted to Emvio servers. | In-browser computation only. Only the derived behavioural flag (e.g., "gaze left", "gaze right") is transmitted — never raw camera frames or facial landmarks. |
What we do not collect: We do not collect fingerprints, retina or iris scans, face geometry (faceprints), or other biometric identifiers beyond those described above. We do not build voiceprint models or facial recognition models from candidate data.
3. Purpose of collection
Biometric data is collected solely for the following purposes, consistent with the initial disclosure provided at the point of consent:
- Conducting the AI interview — converting voice to text so that Riya (the AI interviewer) can evaluate candidate responses in real time.
- Interview integrity analysis — detecting behavioural patterns (e.g., consistent long response delays, reading from a hidden screen) that are inconsistent with genuine unassisted answers.
Emvio does not use biometric data to train AI models, for identity verification beyond the interview session, for marketing, or for any purpose other than those listed above.
4. Consent
Before any biometric data is collected, Emvio:
- Informs the individual in writing of the specific biometric identifiers or information being collected;
- Informs the individual of the purpose and length of time for which the biometric data is being collected, stored, and used;
- Informs the individual that a publicly available retention and destruction policy exists at this URL; and
- Receives a written, explicit release via a granular, per-category consent checkbox on the interview entry screen, which the individual must actively tick before the session begins.
Consent is obtained via the interview entry screen at /interview/{token}. Separate consent checkboxes exist for: (1) voice recording, (2) gaze & behavioural tracking, (3) AI-powered scoring, and (4) interview integrity analysis. The session cannot begin until all four are explicitly accepted.
Consent records — including the timestamp, IP address, user-agent, and which categories were accepted — are stored in an immutable audit log and cannot be deleted.
5. Retention schedule
Biometric identifiers and biometric information are retained for the shortest of the following periods:
Voice audio — not retained
Raw audio is streamed directly to Deepgram (our speech-to-text provider) and is never stored on Emvio servers. Deepgram does not retain raw audio after the transcript is produced. The in-session audio buffer is discarded when the WebSocket session closes.
Interview transcript — 730 days (2 years) from session date
The speech-to-text transcript of the interview is retained as part of the application record for up to 730 days. This is consistent with EEOC record-keeping guidance for employment selection records.
Gaze / behavioural flags — 730 days (2 years) from session date, or 3 years from collection — whichever is shorter
Derived behavioural signals (direction flags, not raw video) are stored as part of the anti-cheat score record. Raw camera frames are never stored.
Mandatory outer limit — 3 years from collection
In all cases, and regardless of the above, all biometric data is permanently destroyed no later than 3 years from the date of collection, in compliance with 740 ILCS 14/15(a). Our automated daily retention script enforces this limit.
On request — within 14 days
If a data subject requests erasure of their biometric data under BIPA or GDPR Art. 17, all biometric identifiers and biometric information will be permanently destroyed within 14 days of the verified request. See Section 9.
On first purpose expiry — immediately
If the initial purpose for collection is fulfilled and no other retention obligation applies, biometric data is destroyed immediately. For voice audio, this means when the WebSocket session closes.
6. Destruction process
Emvio uses a cascading, audited destruction process:
- Storage file deletion — résumé and any stored interview artefacts are deleted from the Supabase cloud storage bucket via the Supabase Storage API. The API confirms deletion before proceeding to the next step.
- Application row deletion — the application database record (containing the interview transcript and AI scores) is permanently deleted. Foreign-key cascades automatically remove linked interview session records.
- Candidate profile deletion — the candidate profile record is permanently deleted, removing all linkages to the individual.
- Audit log entry appended — an immutable, append-only audit log entry is written citing the legal basis for erasure (GDPR Art. 17 / BIPA / AIVIA), the timestamp, the category of data destroyed, and who initiated the deletion. This audit entry cannot itself be deleted (EU AI Act Art. 26).
The daily automated retention script (scripts/retention_cleanup.py) runs on our production servers at 02:00 UTC and performs steps 1–3 for all records whose expires_at timestamp has passed. Step 4 is performed by the manual erasure endpoint used for individual requests.
Destruction is permanent and irreversible. Emvio does not maintain "soft delete" or archival copies of biometric data.
7. Prohibition on sale and profit
Emvio does not sell, lease, trade, or otherwise profit from an individual's biometric identifiers or biometric information. This prohibition applies to all current and future commercial arrangements and cannot be waived by contract.
8. Third-party disclosure
Biometric data is disclosed to the following third parties solely to the extent necessary to provide the interview service:
| Third party | Data disclosed | Purpose | Contractual safeguards |
|---|---|---|---|
| Deepgram Inc. (USA) | Raw voice audio stream (in-session only) | Real-time speech-to-text transcription | Deepgram DPA; audio is not retained by Deepgram after transcription; zero data-retention option enabled |
No other third party receives biometric identifiers or biometric information. Gaze signals are processed entirely in-browser and only boolean flags (not geometric data) are transmitted to Emvio servers. Neither OpenAI, Sarvam, LiveKit, Supabase, nor any other sub-processor receives raw biometric data.
9. Individual requests
You may submit a request to access, correct, or permanently destroy your biometric data at any time using either of the following channels:
- Online: Log in to your candidate account and use the Privacy & Data Centre. Select "Request data deletion".
- Email: Send a request to [email protected] with the subject line "BIPA Biometric Erasure Request". Include your full name, email address used during registration, and the date of your interview.
We will verify your identity before processing any request. Verified deletion requests will be completed within 14 days. We will send a written confirmation upon completion.
There is no fee to exercise your rights under BIPA. We will not deny service, charge a higher price, or penalise you for submitting a request.
10. Contact
Data Protection & Biometric Privacy Contact:
Emvio Intelligence
Email: [email protected]
If you believe Emvio has violated this policy or your rights under BIPA, you may also pursue a private right of action under 740 ILCS 14/20.
This policy was last updated on 1 August 2026. Material updates will be communicated via the Emvio Recruit platform and this page's revision date will be updated.