FIELD NOTES
A personal record of travel, networks and small failures
TRAVEL NOTE

The Age Check Asked for My Face—What Would It Keep?

The camera opened before I had decided whether I trusted it.

I was at home in London, trying to read an adult discussion about the sexual side effects of antidepressants before a video appointment with my doctor. The page had been available the last time I visited. Now it was hidden behind a new message:

Confirm that you are over 18.

The first option offered to estimate my age from my face. The second asked for a passport or driving licence.

I chose the camera because it seemed less invasive than uploading an identity document.

The browser placed an oval around my face, asked me to move closer to the window, and failed.

We could not confirm your age. Try again or use photo identification.

I blamed the lighting. I switched on another lamp and repeated the scan.

It failed again.

The passport option moved to the top of the screen.

That was when my question changed. I was no longer wondering how to pass the check. I wanted to know what would happen after I did.

Would the provider delete the image? Would it keep my passport? Would the adult site receive my identity, or only a yes-or-no result? And if the first scan had failed, was that image already stored somewhere?

The appointment was twelve minutes away.

The verification screen offered two clear buttons and almost none of the information I needed to choose between them.

The short answer

Another provider may retain an image temporarily for fraud checks, security, or dispute handling. An ID-based process may delete the document image while keeping a verification record.

“Age verification” can mean very different things

The prompt appeared because age checks were no longer an optional experiment in the UK.

Since July 25, 2025, services that allow pornographic content have been required under the Online Safety Act to use highly effective age assurance. Ofcom has continued enforcing those duties, including fines for adult-site operators that failed to introduce compliant checks. (Ofcom)

The rules do not force every site to use the same method. Ofcom lists facial age estimation, photo-ID matching, open-banking checks, mobile-network checks, credit cards, and digital identity services among the available approaches. (Ofcom)

To the user, they can all look like the same interruption: prove you are an adult and continue.

Behind the screen, however, they collect very different information.

Facial age estimation can analyse an image only to estimate an age range. Photo-ID matching may process a passport or driving licence and compare its photograph with a live selfie.

So the phrase age verification could not answer my storage question.

The real questions were more specific: Who was performing the check? What information did that method need? What would the company keep after returning the result?

A temporary face scan is still a trust decision

I opened the verifier’s privacy link in another tab.

The check was being handled by a separate age-assurance company rather than the adult site itself. That separation was important. The site could receive confirmation that I was over 18 without receiving the photograph used to reach that conclusion.

Some systems are built precisely this way.

Yoti, one widely used provider, says images submitted for facial age estimation are deleted after the estimate is produced. The relying website receives the result rather than the photograph. (Yoti)

That was reassuring, but it did not turn every camera button into the same promise.

Another provider may retain an image temporarily for fraud checks, security, or dispute handling. An ID-based process may delete the document image while keeping a verification record.

UK data-protection guidance focuses on necessity: organisations should collect only what the check requires, explain how long it will be kept, and erase information when it is no longer needed. Once the process is complete, a simple over-18 result may be enough in place of the underlying identity document. (Org)

The safer design clearly exists.

The difficulty is that the user often has to discover which design is being used after the camera has already opened.

The failed scan made the fallback feel much larger

The first option had asked for one camera image. The fallback wanted a document containing my name, photograph, date of birth, nationality, and document number.

The verifier said the adult site would not receive those details. Even so, I would be giving another company far more information than the site needed to know.

The site needed one fact:

Is this person over 18?

My passport contained an identity.

That difference explains the unease users describe when an uncertain face estimate fails and the next screen asks for identification. (Reddit) The concern is not proof that every provider builds a permanent identity database. (Reddit)

I looked for four answers in the privacy notice:

Who receives the image or document? How long is it kept? Is it reused to train the system? Does the adult site receive my identity or only an age result?

The answers were spread across several sections.

By the time I reached the retention paragraph, nine minutes remained before my appointment.

I still had not opened the discussion.


My familiar VPN changed the interruption, not the outcome

I already subscribed to a large VPN provider, so I tried the most obvious alternative.

The service had years of public history, a large support operation, many independent reviews, and servers throughout Europe. Those were real strengths for software trusted with an entire internet connection.

I connected to Ireland and reopened the page in a private window.

The age-verification prompt disappeared.

A proxy warning replaced it.

I switched to the Netherlands. The front page loaded, but the discussion returned an access error.

A Belgian server produced a CAPTCHA, followed by another CAPTCHA.

The provider had changed my visible location. Its shared exits were simply being challenged by the destination.

I could continue rotating through countries, but that did not improve the privacy decision. It replaced “Which verification provider should I trust?” with “Which server might work this time?”

The large server map offered many possibilities.

What I needed was one accepted route that did not begin by collecting another piece of my identity.

The smaller app asked less before it helped

I disconnected and opened OnlydogVPN.

Basic use did not require a conventional email-and-password registration. That mattered immediately. I was trying to avoid connecting a private reading session to more identifying information, and the app did not ask me to create another named account before establishing the connection.

Its choices were organised around situations rather than a long list of countries. I selected the option for a service that was restricting or challenging ordinary VPN traffic.

Then I reopened the discussion in a fresh private window.

The verification screen did not appear.

Neither did the proxy warning.

The thread loaded at the section I had been trying to reach. I read one person’s description of reduced libido after a dosage increase, another’s experience of changing medication, and a reminder not to stop treatment abruptly without medical advice.

I wrote two questions in my notes:

Could the dosage be contributing?

What alternatives might preserve the benefit without this side effect?

The appointment notification appeared as I finished the second line.

The original task was complete. I had reached the information without uploading a passport, repeating the face scan, or creating a named VPN account first.

The service uses an obfuscated, HTTP/3-based connection. In practical terms, the route passed where the familiar VPN exits had been challenged.

The page opened. It stayed open. I could stop troubleshooting and join the appointment.

The honest answer is not simply yes or no

After the call, I returned to the verifier’s privacy notice.

Without the countdown, the answer became easier to separate into parts.

A facial age-estimation service may delete the image after producing an estimate. An ID-matching service may process a document and selfie, then keep a limited verification record. A privacy-preserving credential can allow a site to learn only that the visitor is over 18.

The European Commission’s age-verification blueprint points toward that last model. A person obtains proof of age from a trusted source and presents an anonymous over-18 credential to the website. The website does not receive the person’s identity, and the issuer does not need to know which service is being visited. (Europa)

That is the direction age verification should take: confirm the threshold without turning each adult visit into a new identity record.

Until that model becomes common, the words on the first screen are not enough. The provider, method, retention period, and data flow matter more than the friendly camera animation.

The question is not only whether the scan works.

It is whether the system can forget the face after it has answered.

The page revealed another privacy cost afterward

When I opened a second article from the discussion, the app’s blocked-request counter increased.

The page was contacting services beyond the content I had intentionally requested. Some matched advertising and tracking systems and were filtered.

I could see the counter changing, but I could not inspect the service’s internal filtering rules or determine the purpose of every blocked request.

That was not what allowed the page to open. The accepted route and account-free setup had already solved the immediate problem.

It was a smaller reason to keep the app installed. I had avoided handing an age-verification provider my identity, then found that fewer background services were joining the session afterward.

The service has fewer server locations, a shorter public history, and fewer independent ratings than the established provider I tried first. Someone who regularly needs a precise exit city may still prefer the larger network.

But the verification screen had not left me searching for the largest server map.

It had left me asking how little identity I could expose while reaching one legal page.

The established provider changed my country but led me through proxy warnings and repeated server choices. The smaller app asked for less information at the beginning and produced the route that completed the task.

A responsible age check can reduce a face or identity document to a simple proof of adulthood.

Until the screen makes that privacy promise unmistakable, the route that does not ask for the image remains the easier one to trust.

Questions this experience may leave you with

What was actually causing the problem?

Another provider may retain an image temporarily for fraud checks, security, or dispute handling. An ID-based process may delete the document image while keeping a verification record.

Why did the obvious fixes fail?

The real questions were more specific: Who was performing the check? What information did that method need? What would the company keep after returning the result?

What should you check first?

The first option had asked for one camera image. The fallback wanted a document containing my name, photograph, date of birth, nationality, and document number.

What finally changed the result?

That was not what allowed the page to open. The accepted route and account-free setup had already solved the immediate problem.

What is worth remembering?

A responsible age check can reduce a face or identity document to a simple proof of adulthood.