Privacy Policy
Last updated: 2026-08-20 Effective: 2026-08-20
Tenet is a service that proves a yes without handing over a document. This policy explains what we do with personal information — and, more to the point, what we do not keep.
We have tried to write this so that it can be read. Where a plain sentence and a precise sentence differ, we have kept the precise one.
1. Who we are
3A Labs LLC, a Texas limited liability company, trading as Tenet ("Tenet", "we", "us"). Registered address: 5900 Balcones Drive, STE 100, Austin, TX 78731, United States — our registered agent's office, and not a contact address.
Contact us at privacy@choosetenet.com. Security reports go to security@choosetenet.com (see our Security page).
This policy covers:
- choosetenet.com — our business website
- withtenet.app and the Tenet wallet app — our consumer surfaces
- the Tenet verification service — the hosted flow a business sends you to in order to check your age
2. The one distinction that explains this whole policy
We hold three different kinds of information, for three different reasons, for three very different lengths of time. Almost every question about Tenet's privacy practices is really a question about which of these you are asking about.
| Whose data | Why we have it | How long we keep it | |
|---|---|---|---|
| A. Verification data | A person being age-checked | A business asked us to check | The images are never stored at all. A decision record is kept 7 years |
| B. Wallet contact details | A person who asked us to send them a credential | To deliver a credential they asked for | 30 days, then deleted |
| C. Business contact details | Someone at a company enquiring about Tenet | To answer the enquiry | 24 months from last contact |
When we say we hold nothing, we are talking about category A — the selfies, the photographs of driving licences, the personal details printed on them. That claim is exact, and section 3 sets out its one honest limit.
Business contact details that a prospective customer voluntarily types into a form on our website are a different thing entirely. We keep those, under a stated window, because we cannot answer an email we have deleted. Saying so plainly is the point of this section.
3. Verification data — what actually happens to your face and your ID
This is the section that matters most, so it is the most specific.
3.1 What we receive
Depending on which method you use, we may receive:
- a selfie, for AI age estimation
- photographs of a government-issued identity document (front, and back where applicable) plus a selfie, for document verification
- a cryptographic proof from a digital wallet — which contains no image at all, only a signed answer to the question asked
3.2 What we do with it — stream-through processing
Images are processed in transit and never written to disk. They are held in memory only for as long as the check takes, passed to the age-estimation or document-verification service, and discarded. No image is stored, logged, backed up, or used to train a model.
This is enforced in the software rather than promised in a policy: our logging configuration redacts image payloads at source, so an image cannot reach a log file even by mistake.
3.3 What we keep — and the honest limit on "we keep nothing"
We keep a decision record for each check. It exists so that the business who asked for the check can prove to a regulator that it happened, and so that we can show how an automated decision was reached. It contains:
- which method and which service made the decision, and the model version
- the outcome, the confidence score, and the threshold applied at the time
- the age threshold that was requested (for example, "is this person over 18")
- a one-way hash of the input — which cannot be turned back into your photograph
- a one-way hash of the reference the business uses for you — not the reference itself
- the provider's own reference for the decision, so a disputed one can be re-examined
What a document check keeps, stated plainly. Where a check used a government-issued document, your date of birth is read from it and used at the moment of decision — we cross-check it against the provider's own verdict, so that a document which passes an authenticity check still cannot admit someone under age. What survives that decision is the age the date implies, as a whole number — not the date itself. Your name, address, and document number are discarded at the point of receipt and never reach our storage.
The distinction is the point: an age is what the record needs in order to mean anything to a regulator, and a birth date is re-identifying data that nobody could ever recall from a seven-year immutable archive.
Decision records are append-only and immutable. They are written to storage that physically cannot be altered or deleted for seven years, because a compliance record that can be edited is not a compliance record.
3.4 The consequence of immutability, stated up front
Because those records cannot be altered, we cannot delete them on request, and neither can we. Not "will not" — the storage does not permit it, by design, and that is the property that makes the record worth anything to a regulator.
If you ask us to erase your data, we will delete everything we are able to delete and tell you specifically what remains and why. What remains is the decision record described above. We rely on the legal exemptions for records retained to comply with a legal obligation and to establish or defend legal claims.
3.5 Who we are acting for
When a business sends you to Tenet to check your age, that business decides that the check happens, and we carry it out on their instructions. In data-protection terms they are the controller and we are the processor. If you want your data deleted, or want to know why you were asked to verify, start with them — though you are welcome to contact us and we will help you reach the right place.
4. Biometric information — notice, consent, and destruction
This section is our written notice and retention schedule for biometric information. It exists to satisfy state biometric privacy laws, including the Illinois Biometric Information Privacy Act (740 ILCS 14/) and the Texas Capture or Use of Biometric Identifier Act (Tex. Bus. & Com. Code § 503.001).
What is collected. AI age estimation and document face-matching analyse the geometry of your face. That analysis may constitute a biometric identifier or biometric information under those laws.
Why. For one purpose only: to estimate or confirm your age, or to confirm that the person holding the document is the person in front of the camera. Nothing else.
How long it is kept. The facial analysis is transient. It exists only inside the running check and is destroyed when the check completes — in practice, seconds. We do not create, store, or maintain a facial template, and we have no database of faces to search.
Our destruction schedule. Biometric identifiers and biometric information are destroyed immediately upon completion of the verification for which they were collected, and in every case no later than the earlier of (a) the purpose being satisfied, or (b) one year after our last interaction with you. Because we do not persist the data at all, the first limb always applies.
We do not sell it. We do not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information. We do not disclose it except to the service providers in section 6 that perform the analysis on our behalf, and only for that purpose.
Your consent. Before your camera opens, we show you a written notice — what is measured, why, how long the record is kept — and ask you to agree. Nothing is captured until you do. The notice is a fixed document with a version stamp; the version you were shown is 2026-08-17, and the record of your decision names it, so the exact words you agreed to can be produced years later rather than reconstructed.
You can decline, and declining is a real option. It is a button of the same size in the same place as agreeing. If you decline, the check ends there, nothing is collected, and the business that sent you is told only that the check did not complete — not that you refused, and nothing about you.
We record the decline too. That may read as odd, so it is worth saying plainly: "we asked and you said no" and "we never asked" are different facts, and only the first is evidence that we did the right thing. What is stored is the decision, the version of the notice you saw, which checks it covered, and the time — no image, and no measurement of you. That record is append-only: the database rejects any attempt to change or remove it, and we do not delete it on request either. § 3.4 explains why that property is the point.
The server enforces it, not just the screen. Our systems refuse to analyse a face at all unless that record already exists. A consent screen alone can be skipped by a bug or by future code; this cannot, and that is deliberate.
5. The other two categories
5.1 Wallet contact details (category B)
If you complete a check and we offer to send you a reusable credential, you may give us an email address or a phone number so we can deliver it.
- We use it to send you that credential, and to remind you it is waiting. Nothing else.
- It is encrypted at rest.
- It is deleted after 30 days if you have not claimed the credential.
- If you decline both the wallet and leaving contact details, the credential is discarded immediately. We do not keep orphaned credentials.
5.2 Business contact details (category C)
If you contact us through our website — a demo request, an enquiry — we collect what you type: typically your name, work email, company, and your message.
- We use it exclusively to respond to your enquiry. We do not sell it, and we do not share it.
- We keep it for 24 months from our last contact with you, then delete it.
- We do not currently store the network address of the person submitting the form.
- We will not add you to a marketing list on the strength of an enquiry. If we ever run one, it will be a separate, unticked, explicit opt-in.
Our lawful basis, where one is required, is our legitimate interest in responding to a person who has asked us to get in touch.
5.3 Our website
choosetenet.com uses no third-party analytics, no advertising trackers, and no cross-site cookies. We do not run a consent banner because we have nothing to ask consent for. Any measurement we do is server-side, aggregated, and cannot identify you.
Putting a tracker on the front door of a privacy company would be a self-inflicted wound.
6. Who else touches your data
We use a small number of service providers. Each is bound by contract to process data only on our instructions, and each is listed with what it actually does:
| Provider | What it does | Sees verification images? |
|---|---|---|
| Hetzner | Hosts our services and databases (United States) | No |
| Amazon Web Services | Stores the immutable audit archive (United States) | No |
| Cloudflare | Manages our domain names and, where enabled, protects against attack | In transit only, as a network layer |
| Modal | Runs our own age-estimation model | Yes — transiently, not stored |
| Yoti | Third-party age estimation, used as a fallback | Yes — transiently, per their retention terms |
| ID Analyzer | Document verification and face matching | Yes — transiently, per their retention terms |
The current list, and notice of changes to it, is maintained on our Security page.
We also disclose information where the law requires it — a valid court order, a lawful request from a regulator. We will tell the affected business unless we are legally prohibited from doing so.
We have never received a national security request of any kind. If that ever changes, this sentence will be removed rather than reworded — its absence is the disclosure we may not be permitted to make directly.
7. Your rights
Depending on where you live, you may have the right to know what we hold, to get a copy, to correct it, to delete it, to opt out of sale or sharing, and not to be discriminated against for exercising any of these.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We never have.
To exercise a right, email privacy@choosetenet.com. We will respond within 45 days (extendable once by a further 45 where genuinely necessary) and will verify your identity proportionately — we will not demand a copy of your ID to process a privacy request, which would rather defeat the point.
Two limits, stated honestly:
- For verification data, the business that sent you is usually the right first stop — they hold the context we lack.
- The immutable decision record cannot be deleted. See section 3.4.
If you are in the EU or UK: we do not currently offer the service there, but if you have dealt with us, the same rights apply and you may complain to your supervisory authority. We rely on the Standard Contractual Clauses where personal data is transferred out of the EEA or UK.
Illinois, Texas, and Washington residents — see section 4, which is written for you specifically.
8. Children
The Tenet service exists partly to keep children out of places they should not be.
We do not knowingly collect personal information from a child under 13. Where a check concludes that the person is under 13, the flow stops: we do not mint a credential, we do not capture contact details, and we do not retarget. The only thing recorded is the decision itself.
If you believe a child has given us personal information, email privacy@choosetenet.com and we will delete what we are able to delete.
9. Security
Summarised here, described properly on our Security page: everything is encrypted in transit and at rest, sensitive identifiers are encrypted at the application layer with keys separate from the database, access is least-privilege, and the wallet's private key is generated inside your phone's security chip and cannot be extracted — not by you, not by us, not by anyone holding a court order.
No system is perfectly secure, and anyone who tells you otherwise is selling something.
10. Changes
We will post any change here and update the date at the top. If a change materially reduces your protections, we will say so prominently rather than quietly re-dating the page.
11. Contact
privacy@choosetenet.com — privacy questions and rights requests security@choosetenet.com — vulnerability reports
We do not operate a postal contact channel. The registered address in section 1 identifies the company — it is our agent's office, and mail sent there does not reach us. Email is the route that does, and it is monitored by a person.