Guides
Sep 15, 2026

What Happens to Your ID After You Upload It

Your passport scan doesn't stay with the company you signed up to. Where it goes, how long it's kept, and what the public record shows when these files leak.

What Happens to Your ID After You Upload It

You open an account. You photograph your passport, tilt your face at a camera until a green tick appears, and the flow completes. Most people never think about that file again.

It is worth thinking about, because it almost never stays with the company you signed up to, it is kept far longer than the moment it was needed for, and the public record of what happens to these files is not reassuring.

It goes to a company you have never heard of

Very few businesses build identity verification in-house. The camera step is almost always handed to a specialist vendor, and that vendor does the document authentication, the liveness check and the watchlist screening.

This matters for a simple reason: your file is held by an organisation you did not choose, were probably not told about, and cannot audit. You evaluated the brand on the front of the app. Your passport went somewhere else.

It is kept for years, not minutes

Verification is a one-off event; retention is not.

Anti-money-laundering rules in most jurisdictions require records to be held for five years after a business relationship ends, and firms routinely keep them longer because deleting records carries its own regulatory risk. Even where the check is trivial, retention can be substantial — in February 2026, researchers examining an exposed dashboard codebase from the verification vendor Persona found it could retain identity and biometric data, including ID numbers, facial data and device fingerprints, for up to three years after a simple age check.

Worth being accurate about that one, because it is widely misreported: what was exposed in the Persona incident was a codebase and configuration on a misconfigured endpoint, not customer records. Persona's post-incident review states the environment was isolated from production, that no personal data was exposed, and that the domain had never had federal customers or customer data. Discord did stop using them for age verification afterwards. The story there is about how much these systems are built to collect and keep — 269 distinct verification checks, facial recognition against watchlists, adverse-media screening — not about a leak.

Other incidents are not so qualified.

The record

IDmerit — around one billion records, no password. In November 2025, Cybernews researchers found an unprotected MongoDB belonging to an identity verification provider serving banks and fintechs. Roughly a terabyte, about three billion records in total, of which approximately one billion carried personal information: names, home addresses, postcodes, dates of birth, national ID numbers, phone numbers and email addresses, spanning 26 countries with 204 million records in the United States alone. It had no password. The database was secured the next day; public disclosure came 99 days later.

Fractal ID — 50,000+ crypto users' passports. In July 2024, an unauthorised party got into an operator account at this Web3 verification vendor and ran an API script for a little over two hours. It pulled names, email addresses, wallet addresses, physical addresses, phone numbers, facial images and photographs of passports and driving licences for more than 50,000 people. The vendor served crypto projects including Gnosis Pay. Note the combination: wallet addresses alongside government ID, in one file.

AU10TIX — administrative credentials exposed for over a year. This vendor verifies identity for platforms including TikTok, Uber and X. Credentials were stolen in December 2022 and posted publicly in March 2023, and remained usable for a long time afterwards. Reachable data included names, dates of birth, nationality, images of passports and driving licences, and facial scans.

Three vendors, three different failures: an open database, a compromised account, and leaked credentials. The common factor is not a particular mistake. It is that the file existed in one place, indefinitely, in a form that is directly useful to whoever obtains it.

Why this data is worse than a password

A leaked password is an inconvenience. You change it and the leaked one is worthless.

You cannot reissue your face. You can replace a passport number, eventually, with effort and a fee — but the scan of the old one still shows your face, your name, your date and place of birth, and those do not change. A verification selfie plus a government ID is close to a permanent credential, and it is precisely the pair that account-recovery processes at other companies ask for.

The crypto-specific version is worse still. When wallet addresses sit in the same record as identity documents, as at Fractal ID, the leak does not just expose who you are. It links who you are to what you hold, on a public ledger that anyone can read forever. That is a physical-security problem, not only a privacy one.

What you can actually control

Not much, once a file is uploaded — which is the argument for thinking about it beforehand.

  • Assume it is permanent. You cannot recall a passport scan. Decide whether a service is worth it on that basis, not on the assumption you can undo it.
  • Ask who does the verification. Some providers name their vendor in the privacy policy. It is a reasonable thing to want to know, and a company that will not say has told you something.
  • Minimise the number of copies. Each additional verified account is another vendor, another retention schedule, another chance. Fewer accounts is a genuine risk reduction.
  • Keep the fiat boundary narrow. You will KYC somewhere — that is how fiat enters. What you can decide is how much of your activity sits behind that boundary afterwards.

That last point is where non-custodial systems change the shape of the problem. A protocol that never asks for identity has no file to lose, no retention schedule and no vendor. It does not make you anonymous — your on-chain history is public and permanently linkable, and the exchange you bought through still knows exactly who you are. But it means the position itself is not sitting behind a document bundle in a third party's database, waiting on that company's worst day.

We looked at how that plays out in practice in Revolut's September disclosure, where KYC files and full Bitcoin transaction histories were released to a spoofed government request without anything being hacked at all.


Sources: Cybernews and Fox News on IDmerit; The Block and CryptoSlate on Fractal ID; Malwarebytes on Persona, including the company's own post-incident review. Nothing in this article is financial advice.

About the author.