A lone figure on a cracked, post-industrial horizon.

Privacy-first age verification

Frequently asked questions

Everything people ask before they integrate — about the products, privacy, pricing and the law.

ComplyAge is an age-verification and compliance platform: a free region-aware Age Gate, billed KYC/identity verification with seven methods and reusable results, and free OAuth/SSO. The questions below cover what it costs, how each method works, where each is accepted, what is stored, and how to integrate.

Frequently asked questions

What is ComplyAge?
An age-verification and compliance platform for age-gated and regulated sites. It ships a free region-aware Age Gate, billed KYC/identity verification with reusable results, and free OAuth/SSO account linking.
What is free and what is billed?
The Age Gate and OAuth/SSO are free on every plan. You pay per completed KYC verification: facial age estimation and government ID draw from a plan allowance; payment card, postal address and human review are billed per check.
Which verification methods are supported?
Facial age estimation, government ID with OCR and selfie match, payment card, email, phone (SMS), username (hold-a-sign selfie) and postal address (mailed postcard).
Which methods count as age proof?
Government ID, facial age estimation and payment card are accepted age methods. Email, phone, username and postal address confirm possession or identity and are used as supporting signals, not sole age proof in enforced zones.
Is facial age estimation accepted in Texas?
No. Texas HB 1181 and Louisiana Act 440 are strict zones in ComplyAge's catalogue; only government ID or a payment card is offered there. Most other US states, the UK, France and Australia are flex zones that also accept estimation.
How does region detection work?
The visitor's region is resolved from their IP address and matched to an enforcement zone with a rule — allow, verify or deny — and a list of accepted methods. You can override any rule per region.
What happens if a visitor uses a VPN?
The gate decides on the region the connection presents. A visitor who tunnels into an enforced region is gated; one who tunnels out of it is not. That is a limit of every geo-based control, and the reason statutes attach obligations to the site's reasonable methods rather than perfect detection.
Are verifications reusable?
Yes. A verification belongs to the user's ComplyAge identity and satisfies later checks for the same or another partner without repeating the method.
Do you track users or sell data?
No. ComplyAge does not profile users, run ad networks or sell data. It collects only what a check requires, encrypts it, and minimises retention.
What do you store after a verification?
A reusable record — method, time, outcome. The evidence (images, document reads) is sealed into an encrypted audit archive kept only to answer a valid legal request, and deleted when retention ends.
Does the partner site see my ID or selfie?
Never. A partner receives a verification status through the gate or OAuth — not the document, the image or the card.
Is my photo kept after facial age estimation?
No. The frame is discarded after the estimate. Only a protected face anchor — not reversible to an image — is retained to recognise you later.
Does the Age Gate hurt SEO?
No. The gate overlays the page in the browser; the HTML search engines fetch is unchanged, so content indexes normally. Legally required interstitials are excluded from Google's intrusive-interstitial signal.
Does the gate work with my framework?
Yes — it is a script tag and a first-party cookie, framework-agnostic. Hosted verification is a JavaScript insert; OAuth works with any standard client library.
Can I test without being billed?
Yes. Every integration has test keys that never bill and never produce live verifications. Swap to live keys when you ship.
How do I integrate?
Create an integration in the members portal, add the Age Gate script tag to <head>, add the verification insert where you need an explicit check, and wire OAuth/SSO for sign-in. Test keys let you do all of it on staging.
What happens if ComplyAge is unreachable?
The Age Gate fails open: if the decision request cannot complete, the page is revealed rather than every visitor being locked out. The next page load tries again.
How long does a gate pass last?
By default 30 days. It is a signed token in a first-party cookie on your domain, verified locally with your integration's public key.
Which laws does ComplyAge cover?
The catalogue includes the US states with adult-content age-verification statutes (Texas, Louisiana, Utah, Virginia, Florida, Mississippi, North Carolina, Indiana and more), the UK Online Safety Act, France's SREN/Arcom framework and Australia's Online Safety Act. Zones are updated as laws change; you control the final rule per region.
How do you respond to subpoenas?
Only to a valid legal request, only with what the request lawfully requires, and never with more. The law-enforcement page sets out what we require and what we disclose.
Where do I report a security issue?
Email us, or use the contact in security.txt at complyage.org/.well-known/security.txt. Please give us a chance to respond before disclosing publicly.
How quickly do you answer support requests?
Within two business days. Integration and billing questions from existing customers are prioritised.