Effective Date: July 26th, 2026
You Are Accountable, Inc. (“Accountable,” “we,” “us”) uses facial verification to confirm the identity of individuals submitting alcohol and drug tests through our platform. This policy explains what biometric data we collect, how long we keep it, and how and when we permanently destroy it. It applies everywhere we operate and is maintained as required by biometric privacy laws, including the Illinois Biometric Information Privacy Act and the Colorado Privacy Act’s biometric provisions.
1. What biometric data we collect
Breathalyzer (alcohol monitoring) submissions: face-geometry data is generated momentarily to compare the submission against the user’s enrolled reference photo. This data is not stored — it is discarded as soon as the comparison completes. (The photograph taken with each submission is retained as an ordinary testing record, not as biometric data.)
Video-recorded drug test submissions: a face template — stored face-geometry data derived from the user’s face — is created and retained by our identity-verification service provider (Amazon Web Services Rekognition) on our behalf, to verify the user’s identity across submissions.
We collect biometric data only with the individual’s prior written consent, only for identity verification and fraud prevention, and never for advertising. We do not sell, lease, trade, or otherwise profit from biometric data.
2. Retention schedule
We retain stored face templates only while they serve the purpose for which they were collected — verifying the identity of an active user. Specifically, a face template is retained only while the user’s account or monitoring program is active, and never longer than the outer limit below.
3. Destruction schedule
A user’s stored biometric data is permanently destroyed at the earliest of:
Purpose satisfied — the user’s account is closed or their monitoring program ends;
Request — the user submits a verified deletion request or withdraws biometric consent (privacy@youareaccountable.com or (646) 450-7641); or
Automatic time limit — twenty-four (24) months after the user’s last login, enforced by an automated destruction process that runs without any manual action.
The 24-month limit satisfies Colorado’s requirement (destruction within 24 months of last interaction) and is well within Illinois BIPA’s outer limit (three years after last interaction). If a specific law, court order, or legal hold requires us to retain biometric data longer, we retain it only as long as that obligation requires and destroy it promptly afterward.
4. How destruction is performed
Destruction is permanent and irreversible: face templates are deleted from our identity-verification provider’s systems, and the deletion propagates through our storage environment, including backup media on our standard backup rotation cycle. Each destruction event is logged (what was deleted, when, and under which trigger), and those logs are retained as evidence of compliance. Destruction applies to the biometric data itself; photographs, videos, and testing records are retained and deleted under the schedules in our Privacy Policy.
5. Security and incident response
Biometric data is protected in transit and at rest with encryption, and access is restricted to authorized systems — our personnel do not directly handle face templates. In the event of a security incident affecting biometric data, we follow our incident-response protocol: contain and assess the incident, determine the individuals and data affected, notify affected individuals and regulators as required by applicable law (including HIPAA breach-notification rules where they apply and state biometric and breach-notification statutes), and remediate the cause. Suspected incidents can be reported to privacy@youareaccountable.com.
6. Governance
This policy is reviewed at least annually and whenever our biometric processing changes. The destruction schedule stated here is enforced by automated systems, and compliance is verified periodically by reconciling stored templates against active accounts. Questions about this policy: privacy@youareaccountable.com · (646) 450-7641 · You Are Accountable, Inc., 331 Newman Springs Road, Building 3, Suite 320, Red Bank, NJ 07701.





