By Olivia Harper. Researched from Character AI’s official Age Assurance documentation, Persona’s public incident disclosure, and independent security reporting.
Character AI’s own claims hold up on paper. Your selfie and ID go to Persona, not Character AI directly, and both get deleted within a week. What complicates the picture is Persona itself. In February 2026, researchers found that Persona’s own systems were less locked down than its privacy language suggested, and that changed the honest answer from a simple yes.
This article covers what actually gets collected, what that security exposure means for you, and why there is no way to use Character AI’s full features without handing something over.
What Persona Actually Collects and Keeps?
Character AI states a narrow scope for this data. A facial image from your selfie confirms your age estimate, and a government ID only enters the picture if that first step comes back unclear.
If you want to understand the practical purpose of this process before deciding whether to complete it, see our guide to what verifying your age on Character AI does.
Both pieces get a short shelf life on paper. Persona holds either one for seven days, then deletes it, according to Character AI’s own help documentation. Character AI itself never opens or stores the file at any point in that process.
One phrase in the company’s disclosure deserves a closer look though. Character AI says verification data also supports quality assurance, a term broad enough to cover testing, monitoring, and general system improvements beyond just confirming your age. That is not necessarily misuse, but it does mean the stated purpose stretches further than a single yes or no check.
Persona’s own infrastructure handles far more than Character AI’s specific request. Across its full client base, Persona builds its systems to process government ID numbers, phone numbers, and device details for other clients running deeper background checks. Character AI does not use those extra features, but the capability sits inside the same vendor relationship.
The February 2026 Persona Security Incident
Security researchers found something in February 2026 that went beyond a routine bug. A misconfigured system left part of Persona’s frontend code sitting in the open, and thousands of files gave outsiders a look at how the platform actually works underneath its public description.
What they found stretched well past age checks. The exposed code pointed to watchlist screening, adverse media checks, and risk scoring running behind the scenes, tools built for background investigations rather than confirming someone is over eighteen.
Discord took the incident seriously enough to act on it. The company dropped Persona entirely and moved its own age checks to a different vendor within weeks of the report.
The reporting around this incident did not name Character AI. It still uses Persona for its own verification though, so the same vendor relationship applies here even without a direct mention. Persona called the exposed environment isolated from its production systems and said no personal data actually leaked, a claim researchers have not independently confirmed.
None of this proves your specific selfie or ID was ever at risk. It does mean the vendor holding that data runs infrastructure built for far more than Character AI’s stated seven day age check.
You Can’t Opt Out
Most privacy advice starts with a simple option. Decline and move on. That option does not exist here.
If the system flags your account, full access requires going through Persona in some form. If you’re trying to complete the process yourself, here’s a step-by-step guide on how to verify your age on Character AI.
There is no setting that lets you keep companion chat while refusing the selfie or ID step entirely. Privacy researchers call this a forced consent scenario, since the only real choice is between handing over the data or losing the feature you actually want.
Companies frame this differently. Character AI would call it a required safety and legal step rather than a request. From a data minimization standpoint though, the account holder never gets to weigh a smaller ask against a larger one, since only one path gets offered.
Anyone uncomfortable with that tradeoff has one real option left. Skip the companion chat features entirely, and use Character AI only for the video or story tools that stay open to flagged accounts.
If Persona is refusing your verification or the process keeps failing, see our guide on Character AI age verification not working.
How This Compares to Other Verification Methods?
Not every platform handles this the same way. Comparing methods shows where Character AI’s approach sits on the privacy spectrum.
The weakest method just asks for a typed birthdate. A self declared birthdate stops nobody determined to lie. It also collects nothing beyond a number, so the privacy tradeoff runs the opposite way from Character AI’s system.
Some platforms require a full ID scan from everyone, regardless of age. That collects more data than Character AI’s approach. Its selfie first system only asks for a document when Persona cannot confidently confirm you are eighteen or older.
Discord’s response shows a real alternative. After the security incident, the company switched to k-ID, a competing vendor, instead of dropping verification altogether. Platforms do have a choice in who handles this data, even though checking age itself stays required by law.
The bigger risk is vendor concentration. Persona serves Character AI, Roblox, and OpenAI’s ChatGPT at once. One vendor’s security failure can touch millions of accounts across totally unrelated platforms.
What Parents and Cautious Users Should Actually Do?
Age verification alone will not cover every risk. Treat it as one layer, not the whole plan.
Device level controls work underneath any app. Screen time limits and app blocks stop access even if someone fools a verification check.
Character AI also offers Parental Insights, a built in feature for linked accounts. It shows weekly activity stats without exposing full chat logs.
Talk with your teen about what verification actually collects. A short conversation about the selfie and ID step does more than any setting alone. If you would rather avoid Character AI’s verification requirements altogether, you can also explore Character AI alternatives.
None of these steps require trusting Persona’s security record. They work whether or not that vendor stays reliable.
FAQ’s
Has Character AI itself ever had a data breach?
Not one tied to age verification specifically. The February 2026 incident happened on Persona’s side, and no report has linked it to a direct leak from Character AI’s own systems.
Does any law protect your biometric data here?
Some states have biometric privacy law, like Illinois. These laws can require consent and limit how long a company keeps facial scan data, though enforcement varies once your data crosses into a third party vendor’s hands.
Can you ask Character AI to delete your verification data?
You can submit a request through support, but Persona controls the actual file once it is uploaded. The seven day deletion window already applies automatically regardless of a manual request.
Is the data encrypted during the verification process?
Character AI has not published specific encryption details for this step. Standard practice across the identity verification industry includes encryption in transit, though the company’s own documentation does not confirm it directly for this exact process.

