Role and processing location
Retention controls
Configure retention in Business Console → App Settings → Data.Open retention settings
Choose a retention policy
Save

Manual deletion
Delete individual sessions from the Console when you need one-off removals.- Navigate to Dashboard → Verifications.
- Search or filter for the target session.
- Click the Delete button (top-right) and confirm.

Programmatic deletion
Delete a session via the API at any time by calling the Delete Session endpoint.{"deletion_instruction": "privacy_erasure"} in the body so that any retained biometric template for that person is purged as well.
Biometric template retention
Every KYC session with a liveness selfie carries a face embedding that powers duplicate detection and Face Search 1:N. By default that embedding is deleted with the session, so a person whose session you deleted can verify again without being flagged as a duplicate. Workflows whose Liveness step has automatic Face Search switched off never store that embedding in the first place, so retention has nothing to keep for their sessions. If you delete sessions soon after approval but still need to catch repeat sign-ups, enable biometric-template retention. Didit then deletes the session and all of its data as usual and keeps one separately managed, image-free face biometric template anchored to the User.Enable it
Open retention settings
Turn on Retain biometric template
Set a finite retention period
Save
PATCH /v3/webhook/:
delete_with_session until you change the policy. Nothing enables retention on your behalf.
What is retained and what is erased
Per-deletion control
Every deletion reports its outcome, and every delete call can override the policy:- Console: the delete confirmation shows whether each session’s template will be retained or deleted. The confirmation reads: This deletes the session and starts deletion of its session data. If biometric-template retention is enabled for this operational deletion, an image-free biometric template remains separately until its scheduled expiry or earlier purge. Privacy-erasure requests also purge the template. Sessions without a User cannot retain a template and are marked as such.
- API: send
retain_face_embeddings,face_retention_days,face_retention_deadline,deletion_instruction, andinstruction_idon Delete Session or Batch Delete Sessions.
Two kinds of deletion instruction
When a template is purged
- You purge it in Lists → Biometric templates or through the Biometric Templates API.
- You delete the User with Batch Delete Users.
- You delete any session of that User with
deletion_instruction: "privacy_erasure". - Its retention period ends. Didit purges it automatically.
Where to see them
- Lists → Biometric templates lists every template with its User, source, retained and expiry dates, and status, with single and bulk purge.
- Users → [user] → Biometric templates shows the templates anchored to one User.
- The Biometric Templates API exposes the same data and actions, and every retain and purge is recorded on the audit trail.
Process-and-purge pattern
For maximum data minimization, process verification data through Didit and purge it immediately after receiving results via webhooks.Create a session
Didit runs checks
Receive webhook
status, session_id, vendor_data, and full verification data.Persist only what you need
status, vendor_data).Delete from Didit
session_id to delete the session and its data from Didit. If you rely on duplicate detection across future sign-ups, enable biometric-template retention first; otherwise the face embedding is deleted too.Security and assurance
ISO/IEC 27001
Penetration testing
No known breaches
Internal security team
Privacy-minimized storage
We are adding features that let you retain only selected data fields — for example, keepstatus and vendor_data while auto-purging heavier artifacts like images and documents. This gives stricter control for teams operating under data-minimization principles.
FAQ
Can I set different retention per environment?
Can I set different retention per environment?
Can I export data before deletion?
Can I export data before deletion?
Will a deleted user still be caught as a duplicate?
Will a deleted user still be caught as a duplicate?
Where can I see who accessed what?
Where can I see who accessed what?
Implementation checklist
Configure retention
Subscribe to webhooks
Persist minimal fields
Implement programmatic deletion
Confirm processing region
Separate environments