Terms of Service
Effective June 22, 2026 · Version 2.0
FaceIn Terms of Service
Effective Date: June 22, 2026 Last Updated: July 23, 2026 Version: 2.1
Agreement Overview
These Terms of Service ("Terms") constitute a legally binding agreement between you and WBX3 Holdings, Inc., a Delaware corporation doing business as FaceIn ("FaceIn," "we," "us," or "our"). These Terms govern your access to and use of the FaceIn mobile application (the "App"), the FaceIn developer dashboard at dashboard.facein.id (the "Dashboard"), the FaceIn JavaScript SDK ("@facein/sdk" or the "SDK"), the FaceIn Password Vault, and all related services, websites, and content (collectively, the "Service").
By accessing or using the Service, you agree to be bound by these Terms. If you do not agree to these Terms, do not access or use the Service. If you are using the Service on behalf of an organization, you represent and warrant that you have the authority to bind that organization to these Terms, and "you" refers to both you individually and the organization.
Table of Contents
- Definitions
- Service Description
- Account Registration and Eligibility
- Biometric Authentication Consent
- Consumer App Terms
- Developer SDK Terms
- Developer Dashboard Terms
- Password Vault Terms
- Fees and Payment
- Acceptable Use Policy
- Intellectual Property
- Third-Party Services and Platform Compatibility
- Privacy and Data Protection
- Disclaimer of Warranties
- Limitation of Liability
- Indemnification
- Dispute Resolution and Arbitration
- Governing Law
- Termination
- Modifications to the Service
- Modifications to These Terms
- General Provisions
- Contact Information
1. Definitions
In these Terms, the following words and phrases have the meanings set forth below:
-
"Biometric Data" means data resulting from specific technical processing relating to the physical, physiological, or behavioral characteristics of a natural person that allows or confirms the unique identification of that person, including fingerprints, facial geometry, iris scans, voiceprints, and similar biometric identifiers.
-
"Consumer User" means an individual who uses the FaceIn App for personal biometric authentication and/or password management.
-
"Developer" means any person or entity that registers for a Developer Account and uses the FaceIn SDK or Dashboard.
-
"Developer Account" means an account on the Dashboard used to access the SDK, manage API keys, and configure authentication settings.
-
"End User" means an individual who authenticates on a Developer's website or application using the FaceIn SDK.
-
"JWT Token" means a JSON Web Token issued by FaceIn containing authentication verification results.
-
"MAU" means Monthly Active Users — the number of unique End Users who authenticate using the FaceIn SDK in a given calendar month.
-
"Password Vault" means the FaceIn feature that allows Consumer Users to store, manage, and auto-fill website credentials.
-
"SDK" means the FaceIn JavaScript software development kit (@facein/sdk) made available for integration into third-party websites and applications.
-
"Zero-Knowledge Architecture" means FaceIn's architectural design in which Biometric Data is processed and stored exclusively on the user's device and is never transmitted to, received by, or accessible to FaceIn's servers.
2. Service Description
FaceIn provides a biometric authentication platform consisting of the following components:
2.1 FaceIn App (Consumer)
A mobile application for iOS and Android that enables users to authenticate their identity using device-native biometric methods (face recognition, fingerprint) instead of traditional passwords. The App also includes a Password Vault for secure credential storage and auto-fill.
2.2 FaceIn SDK (Developer)
A JavaScript SDK (@facein/sdk) that allows developers to integrate FaceIn's biometric authentication into their websites and web applications. The SDK communicates with the FaceIn App on the user's device to facilitate authentication and returns a signed JWT token containing verification results.
2.3 FaceIn Dashboard (Developer)
A web-based management console at dashboard.facein.id where developers can register applications, manage API keys, view analytics, configure authentication settings, and manage their subscription.
2.4 Zero-Knowledge Architecture
All biometric processing occurs on the user's device. FaceIn's servers never receive, store, or process Biometric Data. The Service transmits only cryptographic verification results (success/failure assertions) between the user's device and FaceIn's servers.
3. Account Registration and Eligibility
3.1 Eligibility
To use the Service, you must:
- Be at least 13 years of age (or the minimum age required in your jurisdiction, such as 16 in the EEA/UK) to access non-biometric features of the Service
- Be at least 18 years of age to enroll in or use biometric authentication. Biometric enrollment is subject to a flat minimum age of 18, with no lower regional variation and no parental- or guardian-consent exception. This 18+ biometric enrollment minimum is distinct from, and applies in addition to, the general age floor above for non-biometric features.
- Have a compatible device with biometric hardware (for the App)
- Provide accurate and complete registration information
- Not have been previously suspended or removed from the Service
If you are under 18 (or the age of majority in your jurisdiction), you may use non-biometric features of the Service only with the involvement of a parent or legal guardian who agrees to be bound by these Terms. Biometric authentication is not available to any individual under 18 under any circumstances, including with parental or guardian consent.
We rely on your representation of your age at enrollment. By enrolling in biometric authentication, you represent and warrant that you are at least 18 years of age.
3.2 Account Creation
To access certain features of the Service, you must create an account by providing a valid email address and completing the registration process. You may also be required to verify your identity through email verification.
3.3 Account Security
You are responsible for:
- Maintaining the confidentiality of your account credentials
- All activity that occurs under your account
- Notifying us immediately at mazy@facein.id if you become aware of any unauthorized use of your account
We are not liable for any loss or damage arising from your failure to maintain the security of your account.
3.4 Account Accuracy
You agree to provide accurate, current, and complete information during registration and to update such information to keep it accurate, current, and complete. We reserve the right to suspend or terminate your account if any information provided is found to be inaccurate, incomplete, or fraudulent.
4. Biometric Authentication Consent
4.1 Informed Consent
By enabling biometric authentication in the FaceIn App, you acknowledge and consent to the following:
(a) Your device will use its biometric hardware (camera for facial recognition, fingerprint sensor) to verify your identity when you initiate an authentication request through FaceIn.
(b) Biometric Data is processed and stored exclusively on your device by your device's operating system (Apple iOS, Google Android). FaceIn does not collect, receive, store, transmit, or process your Biometric Data.
(c) FaceIn receives only a cryptographic verification result (a signed assertion of success or failure) from your device. This assertion contains no Biometric Data.
(d) You may disable biometric authentication at any time through the App's settings or your device's settings without losing access to your account.
(e) You may revoke this consent at any time by disabling biometric login, uninstalling the App, or contacting us to delete your account.
(f) Alternative authentication methods may be available and will be presented to you if you choose not to use biometric authentication.
4.2 Illinois Residents — BIPA Disclosure
If you are a resident of Illinois, this Section 4.2 serves as the written disclosure required by the Illinois Biometric Information Privacy Act (740 ILCS 14/15(b)):
- What is collected: FaceIn itself does not collect biometric identifiers or biometric information. Your device's operating system collects and processes biometric data locally to perform authentication. FaceIn receives only a verification result (success or failure).
- Purpose: Biometric authentication is used to verify your identity for login and authentication purposes.
- Duration: Because FaceIn does not store biometric data, there is no retention period applicable to FaceIn. Biometric templates on your device are retained according to your device manufacturer's policies and can be deleted at any time.
- Destruction: FaceIn does not possess biometric data to destroy. Biometric templates on your device may be deleted by removing your biometric enrollment from your device's settings or by uninstalling the App.
- No sale or profit: FaceIn does not sell, lease, trade, or otherwise profit from any biometric identifiers or biometric information.
By enabling biometric authentication in the FaceIn App, you acknowledge that you have received this disclosure and consent to the use of biometric authentication as described herein. You may provide your consent electronically through the App's biometric enrollment flow.
4.3 Minimum Age for Biometric Enrollment
Biometric authentication is available only to individuals who are at least 18 years of age. This minimum age applies uniformly across all jurisdictions and cannot be satisfied through parental or guardian consent. A parent or guardian may consent to a minor's use of non-biometric features of the Service in accordance with Section 3.1, but may not enroll a minor in, or consent on a minor's behalf to, biometric authentication. By enrolling in biometric authentication, you represent and warrant that you are at least 18 years of age.
5. Consumer App Terms
5.1 License Grant
Subject to your compliance with these Terms, we grant you a limited, non-exclusive, non-transferable, revocable license to download, install, and use the App on a device that you own or control, solely for your personal, non-commercial use.
5.2 App Features
The App provides the following features:
- Biometric authentication for third-party websites and applications that integrate the FaceIn SDK
- Password Vault for secure credential storage and auto-fill (see Section 8)
- Account management and security settings
- Authentication history and activity log
5.3 Availability
The App requires a compatible device with biometric hardware and a supported operating system version. We will make reasonable efforts to maintain the App's availability but do not guarantee uninterrupted access. The App may be temporarily unavailable for maintenance, updates, or reasons beyond our control.
6. Developer SDK Terms
6.1 SDK License Grant
Subject to your compliance with these Terms and payment of applicable fees, we grant you a limited, non-exclusive, non-transferable, worldwide license to:
(a) Integrate the SDK into your websites and web applications
(b) Use the SDK to enable FaceIn biometric authentication for your End Users
(c) Receive and process JWT Tokens and verification results from the SDK
This license does not include the right to sublicense, modify, decompile, reverse engineer, or create derivative works of the SDK, except to the extent that such restrictions are prohibited by applicable law.
6.2 API Keys and Authentication
(a) You must register your application on the Dashboard and obtain valid API keys before integrating the SDK.
(b) API keys are confidential and must not be shared, published in public repositories, or embedded in client-side code in a manner that exposes them to unauthorized access.
(c) You are responsible for all activity associated with your API keys. If you believe your API keys have been compromised, you must revoke them immediately through the Dashboard and generate new keys.
6.3 Permitted Uses
You may use the SDK solely for the purpose of enabling biometric authentication on your websites and web applications. This includes:
- Replacing or supplementing password-based authentication with FaceIn biometric authentication
- Multi-factor authentication (MFA) using FaceIn as one of the authentication factors
- Identity verification for account creation, login, and transaction authorization
6.4 Prohibited Uses
You may not use the SDK to:
(a) Collect, store, transmit, or attempt to access End Users' Biometric Data
(b) Reverse-engineer, de-anonymize, or correlate FaceIn user identifiers with Biometric Data or other personal information not provided by FaceIn
(c) Use authentication results for surveillance, tracking, profiling, or any purpose other than authenticating End Users to your service
(d) Circumvent, disable, or interfere with the SDK's security features or authentication protocols
(e) Use the SDK in any application or service that is directed at children under 13 (or the applicable age in your jurisdiction) without complying with COPPA and equivalent laws
(f) Use the SDK for any illegal purpose or in violation of any applicable law or regulation
(g) Resell, sublicense, or redistribute the SDK as a standalone product or as part of a competing authentication service
(h) Exceed the rate limits, MAU limits, or other usage limits associated with your subscription tier
(i) Attempt to access FaceIn's backend systems, databases, or infrastructure beyond the documented SDK API endpoints
(j) Use the SDK to facilitate unauthorized access to any third-party system, service, or data
6.5 Developer Data Handling Obligations
As a Developer using the FaceIn SDK, you agree to:
(a) Maintain a Privacy Policy: You must maintain a publicly accessible privacy policy that accurately describes your use of FaceIn for authentication, what data you collect from End Users, and how you handle that data. Your privacy policy must disclose that you use a third-party biometric authentication service (FaceIn) and explain what data is shared with FaceIn.
(b) Obtain Consent: You are responsible for obtaining any consents required under applicable law for your use of the SDK and your collection and processing of End User data, including any biometric-related consents required by BIPA, GDPR, CCPA, or other applicable laws.
(c) Data Minimization: You must collect and retain only the minimum data necessary for your authentication purposes. You must not retain JWT Tokens or verification results beyond their expiration or beyond the period necessary for your legitimate authentication purposes.
(d) Security: You must implement reasonable technical and organizational security measures to protect End User data received through the SDK, including JWT Tokens and user identifiers.
(e) Data Subject Requests: You must promptly respond to End User requests regarding their data, including requests for access, correction, and deletion, in compliance with applicable privacy laws.
(f) Incident Notification: You must notify FaceIn within 48 hours if you become aware of any security breach or unauthorized access affecting data received through the SDK.
(g) Compliance: You must comply with all applicable laws and regulations regarding your use of the SDK and your handling of End User data, including but not limited to GDPR, CCPA/CPRA, BIPA, COPPA, and any other applicable data protection or privacy laws.
(h) Minimum Age and Age Assurance: FaceIn biometric enrollment is restricted to End Users who are at least 18 years of age. You represent, warrant, and agree that you will not enable, offer, or facilitate FaceIn biometric enrollment for any End User whom you know or reasonably should know to be under 18 years of age. You must present, or allow FaceIn to present through the SDK, an age-confirmation step (a date-of-birth or "18 or older" confirmation) prior to biometric enrollment, and you must not suppress, bypass, circumvent, or pre-populate that step. You are responsible for honoring the results of that age confirmation and for not enrolling End Users who do not satisfy the 18+ requirement. This obligation is in addition to your obligations under Section 6.4(e) regarding services directed at children. FaceIn relies on your representations and on End User self-attestation of age; FaceIn is not required to independently verify the age or identity of any End User, and nothing in these Terms obligates FaceIn to perform government-identity or documentary age verification.
6.6 Usage Limits and Rate Limiting
(a) Your use of the SDK is subject to the MAU limits and rate limits associated with your subscription tier, as described on our pricing page and in your Developer Account.
(b) We may impose rate limits on API requests to protect the stability and performance of the Service. You must implement appropriate error handling and retry logic in your integration.
(c) If you exceed your MAU limit, we may charge you for the overage at the rate specified in your subscription tier, throttle your API requests, or both.
6.7 SDK Updates
(a) We may release updates, patches, or new versions of the SDK from time to time. We recommend that you keep your SDK integration up to date to benefit from security patches, bug fixes, and new features.
(b) We will use commercially reasonable efforts to maintain backward compatibility, but we reserve the right to deprecate older SDK versions with at least 90 days' prior notice. Continued use of a deprecated SDK version after the deprecation period may result in service disruptions.
6.8 Service Level
(a) We will use commercially reasonable efforts to maintain 99.9% uptime for the SDK authentication API, measured on a monthly basis.
(b) Uptime excludes scheduled maintenance (with at least 48 hours' prior notice), force majeure events, and downtime caused by your systems or third-party systems.
(c) In the event that we fail to meet the 99.9% uptime target, eligible Developers may request service credits in accordance with our Service Level Agreement, which is available upon request.
7. Developer Dashboard Terms
7.1 Dashboard Access
Access to the Dashboard requires a Developer Account. You must provide accurate company and billing information during registration.
7.2 Dashboard Features
The Dashboard provides:
- Application registration and API key management
- Authentication analytics and usage metrics
- Subscription management and billing
- SDK configuration and customization options
- Security settings and webhook configuration
7.3 Dashboard Security
You are responsible for securing access to your Dashboard account, including using strong passwords, enabling multi-factor authentication if available, and limiting access to authorized personnel within your organization.
8. Password Vault Terms
8.1 Description
The Password Vault is a feature of the FaceIn App that allows you to securely store website credentials (usernames, passwords, and other login information) and auto-fill them after biometric authentication.
8.2 Local Storage and Encryption
(a) All credentials stored in the Password Vault are encrypted using AES-256 encryption on your device.
(b) Encryption keys are derived from device-local secrets associated with your biometric authentication. FaceIn's servers never receive, store, or have access to your stored credentials or the encryption keys.
(c) The Password Vault operates using standard platform credential management APIs (iOS AutoFill Credential Provider Extension, Android Autofill Framework) and standard browser autofill mechanisms.
8.3 Your Responsibilities
(a) You are solely responsible for the credentials you store in the Password Vault.
(b) You acknowledge that if you lose access to your device and have not set up an account recovery method, your stored credentials may be permanently inaccessible. FaceIn cannot recover your credentials because we do not have access to them.
(c) You are responsible for ensuring that your stored credentials comply with the terms of service of the respective third-party websites and applications.
8.4 Auto-Fill Functionality
(a) The Password Vault's auto-fill functionality operates by populating credential fields in websites and applications using your device's platform APIs and standard browser mechanisms.
(b) FaceIn is not responsible for the accuracy, functionality, or security of third-party websites or applications where credentials are auto-filled.
(c) The auto-fill feature may not function correctly on all websites due to variations in website design, security measures, or platform restrictions. FaceIn does not guarantee compatibility with all websites or applications.
8.5 No Warranty on Third-Party Authentication
FaceIn does not warrant that the Password Vault will be compatible with all websites, applications, or platforms. Third-party platforms may change their login systems, implement security measures that affect auto-fill functionality, or impose restrictions that limit or prevent the Password Vault from functioning. FaceIn is not responsible for any such changes or restrictions.
9. Fees and Payment
9.1 Consumer Users
The FaceIn App is free for Consumer Users. We reserve the right to introduce premium features or subscription tiers for Consumer Users in the future, with appropriate notice.
9.2 Developer Pricing
(a) Developer access to the SDK and Dashboard is subject to usage-based fees calculated on a per-MAU (Monthly Active User) basis.
(b) Current pricing is available on our website at https://facein.id/pricing and in your Developer Account.
(c) We may offer free tiers, trial periods, or promotional pricing at our discretion.
9.3 Billing
(a) Developer fees are billed monthly in arrears based on your actual MAU usage during the billing period.
(b) Payment is due within 30 days of invoice date. We accept payment via the methods specified in the Dashboard.
(c) All fees are stated in U.S. dollars unless otherwise specified. Fees are exclusive of applicable taxes, which are your responsibility.
9.4 Late Payments
(a) Overdue amounts accrue interest at the rate of 1.5% per month or the maximum rate permitted by law, whichever is less.
(b) We reserve the right to suspend your access to the SDK and Dashboard if payment is more than 30 days overdue, upon 10 days' prior written notice.
9.5 Price Changes
(a) We may change our pricing at any time by providing at least 30 days' prior notice.
(b) Price changes will apply to billing periods beginning after the effective date of the change. Your continued use of the Service after a price change constitutes acceptance of the new pricing.
(c) If you do not agree with a price change, you may cancel your subscription before the new pricing takes effect.
9.6 Refunds
Fees are generally non-refundable, except where required by applicable law or as otherwise stated in a separate agreement between you and FaceIn.
10. Acceptable Use Policy
10.1 General Conduct
You agree not to use the Service to:
(a) Violate any applicable law, regulation, or third-party rights
(b) Engage in any fraudulent, deceptive, or misleading activity
(c) Impersonate any person or entity, or falsely state or misrepresent your affiliation with any person or entity
(d) Interfere with, disrupt, or attempt to gain unauthorized access to the Service, its servers, or its networks
(e) Transmit any viruses, malware, worms, or other malicious code
(f) Engage in any activity that could damage, disable, overburden, or impair the Service
(g) Use the Service to harvest, collect, or store personal information about other users without their consent
(h) Use the Service for any purpose that is competitive with FaceIn, including benchmarking the Service for a competing product
10.2 Biometric-Specific Prohibitions
You specifically agree not to:
(a) Attempt to capture, intercept, or extract Biometric Data from the authentication process
(b) Use the Service to build a database of biometric identifiers or biometric information
(c) Use the Service for unauthorized surveillance, facial recognition, or biometric tracking
(d) Attempt to bypass or circumvent the Service's biometric authentication mechanisms
(e) Use the Service to discriminate against individuals based on biometric characteristics
10.3 Enforcement
We may investigate and take any action we deem appropriate in response to violations of this Acceptable Use Policy, including suspending or terminating your account, removing content, and reporting violations to law enforcement authorities.
11. Intellectual Property
11.1 FaceIn's Intellectual Property
(a) The Service, including the App, SDK, Dashboard, and all associated content, features, functionality, software, code, designs, trademarks, logos, and documentation, is owned by WBX3 Holdings, Inc. and is protected by United States and international copyright, trademark, patent, trade secret, and other intellectual property laws.
(b) These Terms do not grant you any right, title, or interest in or to the Service, except for the limited licenses expressly granted herein.
(c) The FaceIn name, logo, and all related names, logos, product and service names, designs, and slogans are trademarks of WBX3 Holdings, Inc. You may not use these marks without our prior written permission.
11.2 Your Content
(a) You retain ownership of any content, data, or information that you submit to the Service ("Your Content").
(b) By submitting Your Content to the Service, you grant us a limited, non-exclusive, royalty-free license to use, reproduce, and process Your Content solely as necessary to provide the Service to you.
(c) We do not claim ownership of Your Content, and this license terminates when you delete Your Content or your account.
11.3 Feedback
If you provide us with any feedback, suggestions, or ideas regarding the Service ("Feedback"), you grant us an irrevocable, non-exclusive, royalty-free, perpetual, worldwide license to use, modify, and incorporate such Feedback into the Service without any obligation to you. You acknowledge that Feedback is not confidential and that your provision of Feedback is voluntary.
11.4 Open-Source Components
The SDK may incorporate open-source software components, which are subject to their respective open-source licenses. A list of open-source components and their licenses is available in the SDK documentation and/or the SDK repository.
12. Third-Party Services and Platform Compatibility
12.1 Third-Party Services
The Service may interact with or rely upon third-party services, platforms, and operating systems (including but not limited to Apple iOS, Google Android, web browsers, and third-party websites). These third-party services are governed by their own terms of service and privacy policies, which are not under FaceIn's control.
12.2 Platform Compatibility Disclaimer
(a) FaceIn's functionality depends on compatibility with third-party platforms, devices, operating systems, and browsers. We do not guarantee that the Service will be compatible with all platforms, devices, operating systems, or browsers, or that it will continue to be compatible if third parties modify their platforms.
(b) Third-party platforms may change their terms of service, security requirements, APIs, or technical specifications in ways that affect FaceIn's functionality. FaceIn is not responsible for any loss of functionality resulting from changes made by third-party platforms.
(c) The Password Vault's auto-fill functionality operates through standard platform APIs and browser mechanisms. Third-party websites may implement security measures (such as CAPTCHAs, anti-automation systems, or custom login flows) that prevent or limit auto-fill functionality. FaceIn is not responsible for such limitations.
12.3 No Endorsement
References to or integrations with third-party services do not constitute endorsement by or affiliation with those third parties. FaceIn is an independent company and is not affiliated with Apple, Google, Microsoft, Meta, or any other platform provider unless expressly stated.
13. Privacy and Data Protection
13.1 Privacy Policy
Our collection, use, and disclosure of information in connection with the Service is described in our Privacy Policy, which is incorporated into these Terms by reference. By using the Service, you acknowledge that you have read and understood our Privacy Policy.
13.2 Zero-Knowledge Commitment
We are committed to our zero-knowledge architecture. We will not modify our systems to collect, intercept, or access Biometric Data. Any material change to this architecture would require updated Terms, a new Privacy Policy, and your affirmative consent.
13.3 Data Processing (Developers)
If you are a Developer whose End Users are located in the EEA, UK, or Switzerland:
(a) FaceIn acts as a data processor with respect to End User data processed through the SDK on your behalf. You are the data controller.
(b) We will process End User data only in accordance with your instructions (as embodied in your use of the SDK) and applicable data protection laws.
(c) A Data Processing Addendum ("DPA") is available upon request and governs our processing of personal data on your behalf. The DPA, when executed, is incorporated into these Terms.
(d) We maintain appropriate technical and organizational measures to protect personal data, as described in our Privacy Policy and Security documentation.
13.4 BIPA Compliance (Developers)
If you are a Developer with End Users located in Illinois:
(a) You acknowledge that FaceIn does not collect, store, or process Biometric Data. The biometric authentication performed through the SDK occurs on the End User's device.
(b) You are responsible for providing any BIPA-required disclosures to your End Users regarding biometric authentication on your website or application.
(c) You must not use data received through the SDK (JWT Tokens, user identifiers) in any manner that would constitute collection of biometric identifiers or biometric information under BIPA.
13.5 EEA and UK Developers
If you are a Developer established in, or your End Users are located in, the European Economic Area (EEA), the United Kingdom (UK), or Switzerland:
(a) Business capacity. You enter into these Terms in the course of your trade, business, craft, or profession and not as a consumer. The consumer-specific provisions of these Terms do not apply to you, and you acknowledge that the Service, SDK, and Dashboard are business-to-business offerings.
(b) Mandatory local rights preserved. Nothing in these Terms — including the governing law, jurisdiction, and arbitration provisions in Sections 17 and 18 — operates to deprive you of the protection afforded by mandatory provisions of the law of your country of establishment that cannot be derogated from by agreement. Where such mandatory local law applies, it prevails over any conflicting provision of these Terms to the extent of the conflict.
(c) Controller obligations for your End Users. As the data controller for your End Users (see Section 13.3), you are solely responsible for establishing a valid lawful basis under the UK GDPR and EU GDPR for processing your End Users' personal data, for providing all required transparency information, and for honoring data subject rights. You are also responsible for complying with the applicable minimum age of digital consent in each EEA/UK jurisdiction in which your End Users are located, which ranges from 13 to 16 depending on the Member State, in addition to the FaceIn 18+ biometric enrollment minimum in Section 6.5(h).
(d) Data Processing Addendum and international transfers. The Data Processing Addendum referenced in Section 13.3(c), including the applicable European Commission Standard Contractual Clauses and the UK International Data Transfer Addendum where relevant, governs any processing of personal data FaceIn performs on your behalf and any transfer of such data outside the EEA, UK, or Switzerland. In the event of a conflict between the DPA and these Terms with respect to the processing of personal data, the DPA prevails.
(e) No consumer-arbitration waiver imposed. To the extent any mandatory EEA or UK law would render the arbitration or class-action provisions of Section 17 unenforceable as to you, those provisions do not apply to you, and any dispute will instead be resolved under the jurisdiction and governing law framework permitted by such mandatory law.
14. Disclaimer of Warranties
14.1 "AS IS" and "AS AVAILABLE"
THE SERVICE IS PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS, WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED. TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, FACEIN DISCLAIMS ALL WARRANTIES, INCLUDING BUT NOT LIMITED TO:
(a) IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT
(b) WARRANTIES THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, SECURE, OR FREE OF VIRUSES OR OTHER HARMFUL COMPONENTS
(c) WARRANTIES REGARDING THE ACCURACY, RELIABILITY, OR COMPLETENESS OF ANY CONTENT OR INFORMATION PROVIDED THROUGH THE SERVICE
(d) WARRANTIES THAT THE SERVICE WILL MEET YOUR SPECIFIC REQUIREMENTS OR EXPECTATIONS
14.2 Biometric Authentication Disclaimer
FACEIN DOES NOT WARRANT THAT BIOMETRIC AUTHENTICATION WILL SUCCESSFULLY VERIFY YOUR IDENTITY IN ALL CIRCUMSTANCES. Biometric authentication relies on your device's hardware and software, which may be affected by lighting conditions, physical changes, device malfunctions, or other factors beyond FaceIn's control. FaceIn is not responsible for authentication failures caused by your device's biometric hardware or software.
14.3 Password Vault Disclaimer
FACEIN DOES NOT WARRANT THAT CREDENTIALS STORED IN THE PASSWORD VAULT WILL BE RECOVERABLE IN ALL CIRCUMSTANCES. Because of our zero-knowledge architecture, FaceIn cannot access or recover your stored credentials. If you lose access to your device or your biometric enrollment changes, your stored credentials may be permanently inaccessible. It is your responsibility to maintain backup copies of your credentials.
14.4 Jurisdictional Limitations
Some jurisdictions do not allow the exclusion of certain warranties. In such jurisdictions, the above exclusions apply to the fullest extent permitted by applicable law.
15. Limitation of Liability
15.1 Exclusion of Consequential Damages
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL FACEIN, ITS AFFILIATES, DIRECTORS, OFFICERS, EMPLOYEES, AGENTS, OR LICENSORS BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO:
(a) Loss of profits, revenue, data, or business opportunities
(b) Loss of or inability to access stored credentials
(c) Authentication failures or delays
(d) Unauthorized access to your accounts on third-party services
(e) Damages arising from the acts or omissions of third-party platforms, services, or providers
(f) Any damages arising from your reliance on the Service
WHETHER BASED ON WARRANTY, CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, OR ANY OTHER LEGAL THEORY, EVEN IF FACEIN HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
15.2 Aggregate Liability Cap
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, FACEIN'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICE SHALL NOT EXCEED THE GREATER OF:
(a) The total fees paid by you to FaceIn in the twelve (12) months immediately preceding the event giving rise to the claim, or
(b) One hundred U.S. dollars ($100.00)
15.3 Essential Purpose
The limitations of liability in this Section 15 shall apply even if any remedy specified in these Terms is deemed to have failed of its essential purpose.
15.4 Jurisdictional Limitations
Some jurisdictions do not allow the exclusion or limitation of certain damages. In such jurisdictions, the above limitations apply to the fullest extent permitted by applicable law.
16. Indemnification
16.1 Your Indemnification Obligations
You agree to indemnify, defend, and hold harmless FaceIn, its affiliates, and their respective directors, officers, employees, agents, and licensors (the "FaceIn Parties") from and against any and all claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or relating to:
(a) Your use of the Service in violation of these Terms
(b) Your violation of any applicable law, regulation, or third-party rights
(c) Your Content or any data you submit to the Service
(d) Your negligence or willful misconduct
(e) Any dispute between you and any third party arising from your use of the Service
16.2 Developer-Specific Indemnification
If you are a Developer, you additionally agree to indemnify the FaceIn Parties from and against any claims arising out of or relating to:
(a) Your integration of the SDK, including any claims by End Users
(b) Your handling of End User data received through the SDK
(c) Your failure to comply with applicable privacy laws, including GDPR, CCPA, BIPA, and COPPA
(d) Your failure to obtain required consents from End Users, including biometric authentication consents
(e) Your use of authentication results for purposes other than those permitted under these Terms
(f) Your enabling, offering, or facilitation of FaceIn biometric enrollment for any End User under 18 years of age, or your failure to present or honor the age-confirmation step required by Section 6.5(h)
16.3 Indemnification Procedures
(a) We will provide you with prompt written notice of any claim subject to indemnification (provided that failure to provide timely notice will not relieve your indemnification obligations except to the extent you are materially prejudiced by such failure).
(b) You will have sole control over the defense and settlement of any claim, provided that you may not settle any claim that imposes any obligation on FaceIn or admits fault on behalf of FaceIn without our prior written consent.
(c) We will provide reasonable cooperation in the defense of any claim at your expense.
17. Dispute Resolution and Arbitration
17.1 Informal Resolution
Before initiating any formal dispute resolution, you agree to first contact us at mazy@facein.id and attempt to resolve the dispute informally for at least 60 days. Most disputes can be resolved through informal negotiation.
17.2 Binding Arbitration
IF INFORMAL RESOLUTION IS UNSUCCESSFUL, YOU AND FACEIN AGREE THAT ANY DISPUTE, CLAIM, OR CONTROVERSY ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICE ("DISPUTES") WILL BE RESOLVED THROUGH BINDING INDIVIDUAL ARBITRATION RATHER THAN IN COURT, except that either party may seek injunctive or equitable relief in court for infringement or misappropriation of intellectual property rights.
(a) Arbitration Rules: Arbitration will be administered by the American Arbitration Association ("AAA") under its Consumer Arbitration Rules (for Consumer Users) or Commercial Arbitration Rules (for Developers), as applicable. The AAA Rules are available at www.adr.org.
(b) Arbitration Location: Arbitration will take place in Wilmington, Delaware, unless you and FaceIn agree to a different location. For Consumer Users, arbitration may be conducted by phone, video conference, or based on written submissions if you prefer.
(c) Arbitrator: The arbitration will be conducted by a single arbitrator with relevant experience in technology and internet disputes.
(d) Arbitration Fees: For Consumer Users, FaceIn will pay all AAA filing fees and arbitrator fees for claims under $10,000. For claims over $10,000, the AAA fee schedule will apply. For Developers, arbitration costs will be allocated in accordance with the AAA Commercial Arbitration Rules.
(e) Arbitration Decision: The arbitrator's decision will be final and binding. Judgment on the arbitration award may be entered in any court of competent jurisdiction.
17.3 Class Action Waiver
YOU AND FACEIN AGREE THAT DISPUTES WILL BE RESOLVED ONLY ON AN INDIVIDUAL BASIS AND NOT IN A CLASS, CONSOLIDATED, OR REPRESENTATIVE ACTION. If for any reason a Dispute proceeds in court rather than in arbitration, both you and FaceIn waive any right to a jury trial. If a court or arbitrator determines that this class action waiver is unenforceable as to a particular claim or request for relief, then that claim or request for relief shall be severed and resolved in court, while the remaining claims shall be resolved in arbitration.
17.4 Opt-Out Right
You may opt out of this arbitration agreement by sending written notice to mazy@facein.id within 30 days of first accepting these Terms. Your notice must include your name, email address associated with your FaceIn account, and a clear statement that you wish to opt out of the arbitration agreement. If you opt out, the Governing Law and jurisdiction provisions in Section 18 will apply.
17.5 Exceptions to Arbitration
Notwithstanding Section 17.2, either party may:
(a) Bring an individual action in small claims court for Disputes within the court's jurisdiction
(b) Seek injunctive or equitable relief in a court of competent jurisdiction for claims involving intellectual property infringement, unauthorized access, or misuse of the Service
17.6 Survival
This arbitration agreement will survive termination of these Terms and your use of the Service.
18. Governing Law
18.1 Choice of Law
These Terms and any Disputes arising out of or relating to these Terms or the Service shall be governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to its conflict of laws principles.
18.2 Jurisdiction
To the extent that arbitration does not apply (as provided in Section 17), you consent to the exclusive jurisdiction of the state and federal courts located in New Castle County, Delaware for the resolution of any Disputes arising out of or relating to these Terms or the Service.
18.3 International Users
If you access the Service from outside the United States, you are responsible for compliance with all applicable local laws. Nothing in these Terms limits any rights you may have under mandatory consumer protection laws in your jurisdiction.
19. Termination
19.1 Termination by You
(a) Consumer Users: You may terminate your account at any time by using the account deletion feature in the App or by contacting us at mazy@facein.id.
(b) Developers: You may terminate your Developer Account at any time by providing 30 days' written notice to mazy@facein.id. You remain responsible for all fees incurred through the date of termination.
19.2 Termination by FaceIn
We may suspend or terminate your access to the Service, in whole or in part, at any time and for any reason, including but not limited to:
(a) Violation of these Terms or the Acceptable Use Policy
(b) Non-payment of fees (for Developers)
(c) Fraudulent, abusive, or illegal activity
(d) Extended inactivity (accounts inactive for more than 24 months)
(e) Discontinuation of the Service or any part thereof
We will provide reasonable notice before termination, except where immediate termination is necessary to protect FaceIn, its users, or third parties from harm.
19.3 Effects of Termination
Upon termination:
(a) All licenses granted under these Terms will immediately terminate.
(b) You must cease all use of the Service, including the SDK.
(c) Developers must remove all FaceIn SDK integrations from their websites and applications within 30 days.
(d) Credentials stored in the Password Vault remain on your device and are not affected by account termination. However, you will no longer be able to use FaceIn's authentication service.
(e) We will delete your account data in accordance with our Privacy Policy and data retention schedule.
19.4 Survival
The following Sections survive termination of these Terms: 1 (Definitions), 10 (Acceptable Use Policy — to the extent obligations continue), 11 (Intellectual Property), 13.2 (Zero-Knowledge Commitment), 14 (Disclaimer of Warranties), 15 (Limitation of Liability), 16 (Indemnification), 17 (Dispute Resolution and Arbitration), 18 (Governing Law), 19.3 (Effects of Termination), 19.4 (Survival), and 22 (General Provisions).
20. Modifications to the Service
(a) We reserve the right to modify, update, suspend, or discontinue the Service (or any part thereof) at any time, with or without notice.
(b) We will use commercially reasonable efforts to provide advance notice of material changes to the Service that may affect your use.
(c) If we discontinue a material feature of the Service that you rely upon as a Developer, we will provide at least 90 days' notice and reasonable assistance in transitioning to alternative solutions.
(d) We are not liable to you or any third party for any modification, suspension, or discontinuation of the Service.
21. Modifications to These Terms
(a) We may modify these Terms from time to time. When we make material changes, we will:
- Update the "Last Updated" date at the top of these Terms
- Notify you via email (for account holders) or a prominent notice within the App or Dashboard at least 30 days before the changes take effect
- For changes to the arbitration agreement, biometric consent provisions, or limitation of liability, provide at least 60 days' notice
(b) Your continued use of the Service after the effective date of the modified Terms constitutes your acceptance of the changes.
(c) If you do not agree with the modified Terms, you must stop using the Service and, if applicable, terminate your account before the changes take effect.
(d) Disputes arising before the effective date of modified Terms will be governed by the Terms in effect at the time the dispute arose.
22. General Provisions
22.1 Entire Agreement
These Terms, together with the Privacy Policy and any other agreements expressly incorporated by reference herein, constitute the entire agreement between you and FaceIn regarding the Service and supersede all prior and contemporaneous understandings, agreements, representations, and warranties.
22.2 Severability
If any provision of these Terms is held to be invalid, illegal, or unenforceable, the remaining provisions will continue in full force and effect. The invalid or unenforceable provision will be modified to the minimum extent necessary to make it valid, legal, and enforceable while preserving its original intent.
22.3 Waiver
Our failure to enforce any provision of these Terms shall not be deemed a waiver of that provision or any other provision. A waiver of any provision is effective only if in writing and signed by an authorized representative of FaceIn.
22.4 Assignment
(a) You may not assign or transfer these Terms or your rights under these Terms without our prior written consent.
(b) We may assign these Terms to any affiliate or in connection with a merger, acquisition, corporate reorganization, or sale of all or substantially all of our assets, upon notice to you.
22.5 Force Majeure
Neither party shall be liable for any failure or delay in performance resulting from causes beyond its reasonable control, including but not limited to acts of God, natural disasters, pandemics, war, terrorism, riots, government actions, power failures, internet or telecommunications failures, and cyberattacks. This Section does not excuse your obligation to pay fees.
22.6 Notices
Notices to FaceIn must be sent to mazy@facein.id. Notices to you will be sent to the email address associated with your account. Notices are deemed received when sent via email.
22.7 No Third-Party Beneficiaries
These Terms are for the benefit of you and FaceIn only. There are no third-party beneficiaries, except as expressly stated in the indemnification provisions.
22.8 Headings
Section headings are for convenience only and do not affect the interpretation of these Terms.
22.9 Electronic Agreement
You agree that these Terms and all related documents may be executed electronically and that your electronic acceptance constitutes your binding agreement, equivalent to a handwritten signature.
22.10 Export Compliance
You agree to comply with all applicable export and re-export control laws and regulations, including the Export Administration Regulations maintained by the U.S. Department of Commerce, trade and economic sanctions maintained by the U.S. Treasury Department's Office of Foreign Assets Control (OFAC), and the International Traffic in Arms Regulations maintained by the U.S. Department of State. You represent that you are not located in, under the control of, or a national or resident of any country subject to U.S. embargo or sanctions.
22.11 Government Use
If you are a U.S. government entity, the Service is provided as "commercial computer software" and "commercial computer software documentation" in accordance with FAR 12.212 and DFARS 227.7202. Use, reproduction, and disclosure are subject to the terms of these Terms and applicable FAR/DFARS provisions.
23. Contact Information
For questions about these Terms, please contact us:
WBX3 Holdings, Inc. Email: mazy@facein.id Website: https://facein.id
For legal notices, service of process, and formal correspondence:
WBX3 Holdings, Inc. Attn: Legal Department Email: mazy@facein.id
These Terms of Service were last reviewed and updated on June 22, 2026.