Blog

We Never Store Your Photo — and That Was Always the Point

July 16, 2026

Recently, the story of Discord's age-verification struggles made headlines again — and the detail that stopped us wasn't the regulatory pressure, or the delayed rollout, or even the pivot to Google Wallet. It was the number: 70,000. That's how many ID photos leaked from a prior verification vendor. Seventy thousand people who handed over their faces and government documents, trusting they were protected.

They weren't. Not because the technology failed in some exotic way. Because photographs existed on a server somewhere — and servers get breached.

"You cannot expose a photo that was never taken. You cannot leak an image that was never stored. That principle shaped every architectural decision we made at Wink."

THE QUESTION WE ASKED FIRST

What if we never stored the image itself?

Wink Face Scan
01101000
01101001
00100010
01100100
01101001
01100111
01101110111011110000100110110111100000011111010001011
Verified
No biometric data stored
Age 21+ verified Confirmed via biometric match
Ready to scan Analyzing facial data Mapping facial geometry Checking liveness Encrypting facial data
Secured by Wink
www.wink.cloud
Hello, Kylie
You're verified — welcome back

When we were designing Wink, we asked ourselves a question that too few companies ask early enough: what if we never stored raw biometric images at all? No photos. No ID scans. No face captures sitting in a database.

Here's how Wink actually works: when you authenticate, our platform converts your biometric — your face, voice, or palm — into an encrypted mathematical vector. That vector is what lives in the cloud, secured and tokenized. The original image is never retained. What gets stored is a numerical representation that cannot be reverse-engineered back into a recognizable photograph of you.

Discord's new vendor, Incode, has moved toward on-device processing — raw biometrics never leaving the user's phone. That's a step in the right direction. But there's a meaningful difference between a vendor promise and a structural design decision made at the foundation. And as we'll explain, on-device processing comes with real limitations that matter enormously for the future of identity-powered commerce.

ON-DEVICE VS. CLOUD

Why we chose the cloud — and what it makes possible

On-device biometrics have one genuine privacy appeal: the raw signal never transmits. We respect that instinct. But Wink's answer is: we transmit and store only an encrypted vector, never the image — so the exposure risk is categorically different, not just incrementally lower. And in exchange, cloud-based processing unlocks capabilities that on-device simply cannot match.

Why cloud-based biometrics

Built for everywhere commerce happens

On-device biometrics tie your identity to a single phone. Wink's encrypted cloud vectors work across every channel, every device — without ever storing a photo of you.

Works everywhere

On-device ties your identity to one phone. Wink works across kiosks, POS terminals, ATMs, websites, and shared workstations. Your identity travels with you — not your hardware.

Smarter fraud detection

Cloud processing runs advanced liveness detection and deepfake defense across the full network. On-device models are constrained by phone hardware and can't see cross-merchant fraud signals.

Shared device support

On-device doesn't work for kiosks, retail POS, or shared workplace terminals. Wink is built for these environments from the ground up — no single-consumer-phone assumption.

No single point of failure

Lose your phone and on-device biometrics are gone or locked. Wink's cloud model means your identity is never held hostage by one piece of hardware.

Compliance-ready

Regulated industries — payments, banking, healthcare — require audit trails and centralized access controls. Cloud gives you that. On-device is a black box from a compliance standpoint.

Always improving

Cloud models update silently and continuously. On-device models are locked to app versions, creating security lag between when new threats emerge and when patches reach users.

The privacy protection isn't in where the processing happens. It's in what you choose to store afterward. Wink made that choice clearly: encrypted vectors, never images. The cloud gives us the reach, the intelligence, and the resilience to build identity infrastructure that actually scales.

WHY THIS MATTERS BEYOND COMPLIANCE

Privacy is the foundation of trust — and trust is the business

The companies that treat privacy as a compliance burden will always be one breach away from an apology blog post. The companies that treat privacy as a design principle build something more durable: genuine trust.

Trust isn't soft. It converts. It retains. It becomes a moat. When your customers know — not just believe, but structurally understand — that even if something went wrong, there is no photo of them to expose, they engage differently. They advocate for you. They stay.

"The real competition isn't about technology. It's about trust. Whoever earns that trust wins the future of commerce."

We're seeing this in practice — in merchants who choose Wink not just for fraud reduction and frictionless checkout, but because they want to offer their customers a biometric experience they can genuinely stand behind. Identity-powered commerce built on a trust layer, not a photo archive.

WHAT THE DISCORD STORY REVEALS

Vendor risk is structural, not incidental

One more thing from this week's news deserves attention: the breach didn't originate inside Discord. It came from a third-party vendor. You can do everything right internally and still inherit catastrophic risk from a partner holding raw data on your behalf. The industry keeps learning this lesson — and keeps being surprised by it.

The answer isn't only to find better vendors. It's to minimize how much sensitive raw data flows to any vendor at all. The less your partners hold in identifiable form, the less they can lose. That principle guided how we built Wink's entire partner model.

The platforms that will earn the next decade of user trust are building with this in mind from day one. Not retrofitting privacy after a breach. Not issuing statements. Not delaying a rollout. Building it in — before the first line of code.

We did. And we're just getting started.