Palms are private.They should stay that way.

VeryAI is designed to be privacy-first. That idea runs through everything we do, from how we handle user data to our privacy policy.

Read Privacy Policy

VeryAI provides biometric authentication rather than KYC checks and does not require users to submit government IDs.

We believe that you should not have to sacrifice your privacy or share governmental information to prove you’re a real person.

How Very handles your data

When a new user registers and scans their palm, Very converts their features into a mathematical Palm Model directly on the user’s smartphone.

What never leaves a smartphone What Very holds onto in encrypted servers What Very never collects
Original, high-resolution palm images are deleted immediately Palm Model, the encrypted palm signature from registration. Name
The local biometric template Very ID, the user identifier Government-issued credentials like a driver’s license or passport
Liveness processing Expired Very IDs Date of birth
Last-activity signals (like when a user last logged in) Physical address
Session id Face scans
Low-resolution palm images held for 180 days for auditing fraud and malicious accounts

The data Very collects can be permanently deleted by the user in the “Settings” menu of the Very app.

Keeping user data safe

Raw, unencrypted biometric data never leaves a user’s device at all.

All encryption happens directly on the smartphone before transit.

All biometric data is encrypted using AES-256, both at rest and in transit.

Palm Models are stored in an isolated, encrypted environment and are never shared with the platforms that use Very.

The fight against deepfakes never ends.

Very works with outside research to stay ahead of the latest deepfakes and scams.

SOC 2 Type IIGDPRiBeta Level 1DEA EPCS

More information on Very’s trust and safety policies

How does palm verification work?

At registration, users scan their palm multiple times either within a platform through the Very SDK or within the VeryAI app. That scan is converted into a mathematical Palm Model and stored on encrypted servers. When a user is asked to reverify their palm, it is once again converted into a Palm Model and compared against the original version.

How is data protected?

All biometric data is encrypted using AES-256, both at rest and in transit.

How do users delete their data?

The data VeryAI collects can be permanently deleted by the user in the “Settings” menu of the Very app.

What do platforms receive after a verification?

Platforms never receive raw biometric data or the Palm Model. Instead, they get a pass or fail state from VeryAI.

Is VeryAI GDPR compliant?

Yes, VeryAI is GDPR compliant.

What happens in a security incident?

In the event of a security incident, we will notify you in accordance with Article 34 GDPR, UK GDPR, and applicable state notification laws. Where legally required, we will also notify the relevant supervisory authority.

What is stored on the device versus on VeryAI’s servers?

The only data stored on the device is the local biometric template. Raw, high-resolution palm images are deleted immediately.

Everything VeryAI stores on its servers is encrypted at rest and in transit: the Palm Model, the Very ID user identifier, last-activity signals like recent logins, session id and other session artifacts, and low-resolution copies of palm images, which are held for 180 days for audit purposes.

Does the same person get the same Very ID across two different platforms?

Yes, the same Very ID can be used across multiple platforms that use VeryAI. A user’s Very ID is linked to their palm, not any specific account.

VeryAI

Get the VeryAI app

Scan the QR code to download the app