Biometric Data Retention and Destruction Schedule
Version 1.0 · Effective 20 August 2026
This Schedule sets out how long Luqas keeps biometric identifiers and biometric information, and how we destroy them. It is a companion document to the Privacy Policy (section 10) and the Terms of Service (section 7.6), and is made publicly available as required by 740 ILCS 14/15(a).
1. What counts as biometric data here
We treat the following as biometric identifiers or biometric information: voice recordings you upload for the purpose of creating a Voice Model, voiceprints and embeddings derived from that audio, and the trained Voice Model itself. Your own live microphone audio during a conversation is processed to operate the session and is not itself retained as a separate biometric record beyond what is described below.
2. Written release before capture
Before we extract a voiceprint or other biometric feature from Source Material, we obtain the written release described in Terms of Service section 7.6, consistent with BIPA section 15(b).
3. Retention while a Voice Model is active
A Voice Model, and the voiceprints and embeddings underlying it, are retained for as long as the account that created it remains open and the Voice Model has not been deleted. This is an active, in-use record, not an indefinite archive: it exists to operate the AI Companion, and nothing else.
4. Unused Voice Models
If a Voice Model — whether newly created or previously used — goes unused for 18 consecutive months (meaning the AI Companion built on it has not been used in a conversation in that time), we automatically and permanently delete it, as described in Terms of Service section 8.6. We notify the account holder by email in advance of automatic deletion, and they may begin or resume using the AI Companion, or export the underlying Source Material, at any time before then to prevent it.
5. Destruction triggers
We destroy the biometric artefacts associated with a Voice Model — the voiceprint, embeddings, and trained model weights — on the earliest of the following:
- You delete the AI Companion or retire the Voice Model (Terms of Service section 8.5)
- You withdraw the written release described in Terms of Service section 7.6
- You delete your account
- The Voice Model is retired following a substantiated objection under our Estate and Likeness Consent and Takedown Policy
- The 18-month unused-Voice-Model period in Section 4 above expires without use (Terms of Service section 8.6)
Destruction takes place within 7 days of the triggering event. Withdrawal of consent or deletion of a Voice Model is a destruction event, not a status flag: the underlying biometric artefacts are actually deleted from our systems and from our subprocessors' systems, not merely marked inactive.
6. Statutory backstop
Independent of the destruction triggers in Section 5, BIPA section 15(a) sets a backstop: biometric identifiers and biometric information must be destroyed on the earlier of (a) the initial purpose for collection being satisfied, or (b) three years from your last interaction with us. Where an account remains open and technically active but has no actual interaction with an AI Companion for an extended period, this backstop may require destruction even though none of the Section 5 triggers has occurred.
7. No sale, lease, trade, or profit
We do not sell, lease, trade, or otherwise profit from voiceprints or other biometric identifiers within the meaning of BIPA section 15(c). Fees you pay for the Service are for the AI Companion experience, not for the biometric data itself.
8. Security measures
Voice recordings, voiceprints, and embeddings are encrypted in transit, and are stored under access-controlled, authenticated conditions with no public web address — unlike other application media such as avatars, voice recordings cannot be fetched by an unauthenticated request. They are not currently held under a separate, per-object encryption key distinct from other stored files; see Privacy Policy sections 10 and 15 for the complete, accurate description of our current storage and security architecture.
9. Changes to this Schedule
If we change a retention period or destruction method described here in a way that shortens your rights, we will not apply the change retroactively to biometric data already scheduled for a longer retention period without your consent. Material changes are announced at least 30 days in advance, consistent with Privacy Policy section 20.
Related policies