# ComplyAge > ComplyAge is an age-verification and compliance platform for age-gated and regulated sites: a free region-aware Age Gate, billed KYC/identity verification, and free OAuth/SSO account linking — built privacy-first. ComplyAge ships three integrated products: a free region-aware **Age Gate** (detects the visitor's region by IP and applies an allow / verify / deny rule), billed **KYC / identity verification** (facial age estimation, government ID with OCR, payment card, email, phone, username, postal address — results are reusable across transactions), and free **OAuth / SSO** account linking for partner sites. No tracking, no data sales, minimal retention. ## Pages - [Take back your privacy. Keep your freedom.](https://complyage.org/): Privacy-first age verification for age-gated and regulated sites: a free region-aware Age Gate, pay-per-check KYC/identity verification, and free OAuth/SSO. - [About ComplyAge](https://complyage.org/about/): ComplyAge exists to make age and identity verification possible without surveillance. Our mission, our principles, and where we're headed. - [Pricing that matches the product](https://complyage.org/pricing/): Pricing that matches the product. The Age Gate and OAuth/SSO are free; you pay per KYC verification. Simple plans, predictable overage. - [Vendors & partners](https://complyage.org/vendors/): The third-party vendors and partners ComplyAge relies on to deliver age and identity verification, and what each is used for. - [Get in touch](https://complyage.org/contact/): Get in touch with ComplyAge about integration, billing, compliance questions, or partnerships. - [Enforcement Zones](https://complyage.org/enforcement-zones/): Region-specific age-verification rules: where verification is required, where access is allowed or denied, and which methods each jurisdiction accepts. - [Privacy Policy](https://complyage.org/privacy/): How ComplyAge collects, uses, protects, and retains data for age and identity verification — and the rights you have over your information. - [Terms of Service](https://complyage.org/terms/): The terms governing use of ComplyAge's Age Gate, KYC/verification, and OAuth/SSO products. - [Law Enforcement Requests](https://complyage.org/legal/subpoena/): How ComplyAge handles subpoenas and law-enforcement requests: what we require, what we disclose, and how to submit a valid legal request. - [The Age Gate](https://complyage.org/age-gate/): Free Age Gate: detects a visitor's region by IP, applies your allow / verify / deny rule, and shields the page until the visitor passes. One script tag. - [Verification methods](https://complyage.org/verification/): Seven verification methods — facial age estimation, government ID, payment card, email, phone, username, postal address — with reusable results. - [Facial age estimation](https://complyage.org/verification/facial-age-estimation/): Facial age estimation: a live selfie, an on-device liveness check, an age estimate — no ID upload, no stored image, only a protected face anchor. - [Government ID verification](https://complyage.org/verification/government-id/): Government ID check: photograph a passport, licence or ID card; OCR reads the date of birth; a live selfie is matched to the document photo. - [Payment card verification](https://complyage.org/verification/payment-card/): How a payment card proves adulthood: a small authorisation through Stripe — nothing charged — records a valid card as evidence of age. - [Email verification](https://complyage.org/verification/email/): Email verification sends a one-time code and confirms the address. Good for account linking and low-risk gates — not sole proof of age. - [Phone verification](https://complyage.org/verification/phone/): Phone verification texts a one-time code and confirms the number. Consent-based and rate-limited — a supporting signal, not sole age proof. - [Username verification](https://complyage.org/verification/username/): Username verification: a photo of the visitor holding a handwritten sign with their username, read by AI, with paid human review for edge cases. - [Postal address verification](https://complyage.org/verification/postal-address/): ComplyAge mails a postcard with a one-time code; entering it proves the visitor receives mail at that address. Billed per card; US addresses today. - [OAuth / SSO](https://complyage.org/oauth-sso/): OAuth/SSO signs users in with their ComplyAge identity and shares verification status — an OpenID Connect-style flow, free on every plan. - [Developers](https://complyage.org/developers/): Integrate ComplyAge fast: a script tag for the Age Gate, a JavaScript insert for hosted verification, OAuth/SSO for sign-in, and test keys for staging. - [The Age Gate and SEO](https://complyage.org/developers/age-gate-and-seo/): Does an age gate hurt SEO? Why ComplyAge's overlay leaves your HTML — and your rankings — intact, plus guidance on bots, previews and Core Web Vitals. - [Age verification glossary](https://complyage.org/glossary/): Plain-English definitions of age-assurance terms: age estimation, liveness, face anchor, enforcement zone, double-blind, highly effective age assurance. - [Frequently asked questions](https://complyage.org/faq/): Straight answers about ComplyAge: what is free, which verification methods exist, where they are accepted, what is stored, and how to integrate. - [Full site text](https://complyage.org/llms-full.txt): every page above as Markdown in one file. ## Frequently asked questions - **Is the Age Gate really free?** Yes. The region-aware Age Gate and OAuth/SSO are free. You only pay when you run a billed KYC/identity verification. ([source](https://complyage.org/)) - **What verification methods are supported?** Facial age estimation, government ID with OCR, payment card, email, phone, username, and postal address — chosen to match the compliance rule for the visitor's region. ([source](https://complyage.org/)) - **Do you track or sell user data?** No. We don't profile users or sell data. We collect only what a verification requires, encrypt it, and minimize retention. ([source](https://complyage.org/)) - **How does region detection work?** We detect the visitor's region by IP and apply the compliance rule you've configured for that region — allow, verify, or deny. ([source](https://complyage.org/)) - **Who is ComplyAge for?** Operators of age-gated or regulated sites who need to verify age or identity and want to do it without compromising user privacy. ([source](https://complyage.org/about/)) - **What makes ComplyAge different?** We treat verification as a transaction, not a data-collection opportunity. We minimize what we store, never sell it, and make verifications reusable. ([source](https://complyage.org/about/)) - **What's free?** The region-aware Age Gate and OAuth/SSO are free on every plan. You only pay for billed KYC verifications. ([source](https://complyage.org/pricing/)) - **How does overage work?** Each plan includes a verification allowance; checks beyond it are billed at the plan's per-verification overage rate. Live amounts appear on the billing screen. ([source](https://complyage.org/pricing/)) - **Can I start for free?** Yes. The FREE plan lets you integrate the Age Gate and OAuth/SSO and run a small number of verifications before you choose a paid plan. ([source](https://complyage.org/pricing/)) - **Do vendors get to keep user data?** No. Vendors receive only the data a specific verification requires, for the purpose of that check, and are bound by contract on retention and use. ([source](https://complyage.org/vendors/)) - **How quickly do you respond?** We aim to reply to every message within two business days. Integration and billing questions from existing customers are prioritised. ([source](https://complyage.org/contact/)) - **Where do I report a security issue?** Email us with the details, or use the contact in our security.txt at complyage.org/.well-known/security.txt. Please give us a chance to respond before disclosing publicly. ([source](https://complyage.org/contact/)) - **Do you offer integration help?** Yes. The Age Gate and OAuth/SSO are designed to be drop-in, but if you need help mapping regions, choosing verification methods, or wiring webhooks, say so in your message and we'll walk you through it. ([source](https://complyage.org/contact/)) - **Can I override the rule for a region?** Yes. ComplyAge ships sensible defaults, but you set the final allow/verify/deny rule for each region. ([source](https://complyage.org/enforcement-zones/)) - **What happens in a 'verify' region?** The visitor is sent through the configured verification method before they can access age-gated content. ([source](https://complyage.org/enforcement-zones/)) - **Which regions are in the catalogue?** US states with adult-content age-verification statutes — Texas, Louisiana, Utah, Mississippi, Virginia, Arkansas, Montana, North Carolina, Idaho, Kansas, Kentucky, Nebraska, Indiana, Alabama, Oklahoma, Florida, South Carolina, Tennessee, Georgia, Wyoming, South Dakota, North Dakota, Arizona — plus the United Kingdom, France and Australia. Everywhere else defaults to allow at 18. ([source](https://complyage.org/enforcement-zones/)) - **Do you sell my data?** No. We never sell personal data and we don't run advertising profiles. ([source](https://complyage.org/privacy/)) - **How long do you keep verification data?** Only as long as needed for the verification's purpose and any legal retention obligation, after which it is deleted. ([source](https://complyage.org/privacy/)) - **When do these terms apply?** They apply whenever you access or integrate ComplyAge. Continued use after an update means you accept the revised terms. ([source](https://complyage.org/terms/)) - **Will you notify me if my data is requested?** Where the law permits and the legal process does not prohibit it, we aim to notify affected users before disclosure. ([source](https://complyage.org/legal/subpoena/)) - **What do you require from law enforcement?** Legally valid process appropriate to the data and jurisdiction. We review each request for validity and scope before responding. ([source](https://complyage.org/legal/subpoena/)) - **Does the Age Gate hide my content from Google?** No. The shield is a CSS overlay; the page's HTML is unchanged, so crawlers index your content normally. See the developer note on the gate and SEO. ([source](https://complyage.org/age-gate/)) - **What happens to visitors outside enforced regions?** Nothing visible — the shield is removed as soon as the decision comes back unenforced, typically within a few hundred milliseconds of page load. ([source](https://complyage.org/age-gate/)) - **Can I use it without KYC?** Yes. Set every region to allow or deny and the gate never opens a verification window; it behaves as a pure geo-gate. ([source](https://complyage.org/age-gate/)) - **Does it work on single-page apps?** Yes. The script runs once per page load and the pass cookie is first-party to your domain, so client-side navigation is unaffected. ([source](https://complyage.org/age-gate/)) - **What does the visitor see in a verify region?** A centred verification window over the shielded page, offering only the methods that region accepts — for example government ID or payment card in Texas, plus facial age estimation in most other zones. ([source](https://complyage.org/age-gate/)) - **Which method should I offer?** Offer what the visitor's region accepts and let the visitor choose. Facial age estimation is fastest and needs no documents; government ID is the strongest proof; a payment card suits regions that recognise it as a commercially reasonable method. ([source](https://complyage.org/verification/)) - **Is a verification reusable across sites?** Yes. The record belongs to the user's ComplyAge identity, so a second partner sees the same verified status through OAuth/SSO or the gate without running a new check. ([source](https://complyage.org/verification/)) - **Do you store my users' documents?** Not in the clear, and not with the reusable record. Evidence is sealed into an encrypted audit archive kept only for lawful legal response; the record itself holds the outcome, the method and the time. ([source](https://complyage.org/verification/)) - **Can a visitor use their phone for the camera steps?** Yes. The verification window shows a QR code; scanning it opens a one-shot mobile handoff that completes the selfie or document capture and returns the result to the desktop window. ([source](https://complyage.org/verification/)) - **Is my photo kept?** No. The frame is discarded after estimation. Only a protected face anchor is retained, and it cannot be turned back into an image. ([source](https://complyage.org/verification/facial-age-estimation/)) - **What if I look younger than I am?** You are offered another method — government ID or a payment card — rather than being turned away. The buffer above the minimum age exists precisely so adults near the threshold are not wrongly refused. ([source](https://complyage.org/verification/facial-age-estimation/)) - **Does it work with glasses, beards or low light?** Usually. Detection guides the visitor into good framing and lighting; if a usable frame cannot be captured, the window falls back to another method. ([source](https://complyage.org/verification/facial-age-estimation/)) - **Is facial age estimation accepted in Texas?** No. Texas HB 1181 and Louisiana Act 440 are strict zones in ComplyAge's catalogue: only government ID or a payment card is offered there. ([source](https://complyage.org/verification/facial-age-estimation/)) - **Do you keep a copy of my ID?** Not with your reusable record. Images are sealed into an encrypted audit archive for lawful legal response only, and deleted when retention ends. Nobody browses it. ([source](https://complyage.org/verification/government-id/)) - **Which documents can I use?** Any government-issued passport, national ID card or driving licence with a photo and a printed date of birth. It must be in date. ([source](https://complyage.org/verification/government-id/)) - **What if the document cannot be read?** The window asks for a retake with framing tips; if OCR still cannot read it with confidence, the visitor is offered another method instead of a guess. ([source](https://complyage.org/verification/government-id/)) - **Is my ID shared with the site I'm visiting?** No. The partner site receives a verification status, never the document, the number or the images. ([source](https://complyage.org/verification/government-id/)) - **Will I be charged?** No. The check places a temporary authorisation that is voided immediately; it may appear as a pending hold for a few days and then disappears. ([source](https://complyage.org/verification/payment-card/)) - **Do you store my card number?** No. Card details are entered into Stripe's element and tokenised there; ComplyAge sees the outcome, not the number. ([source](https://complyage.org/verification/payment-card/)) - **Is a card accepted as proof of age everywhere?** In every zone ComplyAge ships, yes — but some regulators prefer credit over debit or prepaid cards. You can restrict a zone to government ID where that matters. ([source](https://complyage.org/verification/payment-card/)) - **Does an email code count as age verification?** No. It confirms control of an address. In enforced zones the visitor must also complete an accepted method such as government ID, facial age estimation or a payment card. ([source](https://complyage.org/verification/email/)) - **How long is the code valid?** A few minutes, and for one attempt at the session that requested it. A new code invalidates the old one. ([source](https://complyage.org/verification/email/)) - **Do you send marketing to verified addresses?** No. Addresses are used for the code and, if you choose, account recovery — never for marketing and never sold. ([source](https://complyage.org/verification/email/)) - **Does an SMS code prove my age?** No. It proves you hold the number. In enforced zones you must also complete an accepted method such as government ID, facial age estimation or a payment card. ([source](https://complyage.org/verification/phone/)) - **How do I stop messages?** Reply STOP to any message. You will receive one confirmation and nothing further. Codes are only ever sent after you tick the consent box. ([source](https://complyage.org/verification/phone/)) - **Where is the SMS consent policy?** It is shown inside the verification window and published publicly at app.complyage.org/sms-optin. ([source](https://complyage.org/verification/phone/)) - **Does the sign have to be handwritten?** Yes. A handwritten sign in the live photo is what makes the proof hard to fake; printed or edited images are rejected. ([source](https://complyage.org/verification/username/)) - **What does human review cost?** It is billed per review and shown in the window before you request it. Most photos pass the automated read without one. ([source](https://complyage.org/verification/username/)) - **Does this prove age?** Not on its own. It proves the account holder is a real, present person. Pair it with facial age estimation or government ID where age matters. ([source](https://complyage.org/verification/username/)) - **How long does it take?** Several business days from send to arrival, depending on the postal service. The window shows the card's status as it moves. ([source](https://complyage.org/verification/postal-address/)) - **What if the card never arrives?** After the waiting period you can request a replacement from the same window. A card that failed to print or send is re-sent free. ([source](https://complyage.org/verification/postal-address/)) - **Does this prove age?** No. It proves you receive mail at an address. Pair it with an accepted age method where a jurisdiction requires one. ([source](https://complyage.org/verification/postal-address/)) - **Is OAuth/SSO really free?** Yes, on every plan. You pay only for billed verifications a user completes, whether inside the OAuth flow or through the Age Gate. ([source](https://complyage.org/oauth-sso/)) - **Is it OpenID Connect?** It follows the OpenID Connect shape — authorisation-code flow, consent, userinfo — with a ComplyAge verifications extension. Standard OAuth client libraries work with it. ([source](https://complyage.org/oauth-sso/)) - **Can users revoke access?** Yes. Every grant is listed in the user's members portal with a revoke button; revocation invalidates the partner's tokens. ([source](https://complyage.org/oauth-sso/)) - **Can I link an existing account by email?** Yes. A link-by-email endpoint connects an existing partner account to a ComplyAge identity after the address is confirmed with a one-time code. ([source](https://complyage.org/oauth-sso/)) - **Do I need a backend?** Not for the Age Gate or hosted verification — both are browser-only. OAuth's token exchange and any webhook receiver run on your server. ([source](https://complyage.org/developers/)) - **Is there an SDK?** The gate script and the verify insert are the SDK: dependency-free JavaScript served by ComplyAge. OAuth works with any standard client library. ([source](https://complyage.org/developers/)) - **Can I test without being billed?** Yes. Test keys never bill. Use them on staging and swap to live keys when you ship. ([source](https://complyage.org/developers/)) - **Does the gate work with my framework?** It is framework-agnostic: a script tag and a first-party cookie. React, Vue, Rails, WordPress — anything that serves HTML. ([source](https://complyage.org/developers/)) - **Is an age gate cloaking?** Not this one. Cloaking is serving crawlers different content from users. ComplyAge's gate serves identical HTML to everyone and only overlays it in the browser. ([source](https://complyage.org/developers/age-gate-and-seo/)) - **Will Google penalise the overlay as an intrusive interstitial?** Google's guidance explicitly excludes interstitials required by law — cookie consent, age verification — from the intrusive-interstitial signal. ([source](https://complyage.org/developers/age-gate-and-seo/)) - **Can Googlebot verify its age?** No, and it does not need to: the content it indexes is in the HTML and the rendered DOM regardless of the overlay. ([source](https://complyage.org/developers/age-gate-and-seo/)) - **Does the gate slow my pages down?** Measurably little: a small synchronous shield, an async decision request, and a local pass check for returning visitors. Keep the script in and async. ([source](https://complyage.org/developers/age-gate-and-seo/)) - **What is the difference between age verification and age estimation?** Verification establishes age from an authoritative source — a document or a bank. Estimation infers it, most often from a live face, and is probabilistic, so it is used with a buffer above the legal minimum. ([source](https://complyage.org/glossary/)) - **What does highly effective age assurance mean?** It is Ofcom's standard under the UK Online Safety Act for methods that are accurate, robust, reliable and fair. Photo-ID matching, facial age estimation, credit-card and mobile-network checks qualify; self-declaration does not. ([source](https://complyage.org/glossary/)) - **What is ComplyAge?** An age-verification and compliance platform for age-gated and regulated sites. It ships a free region-aware Age Gate, billed KYC/identity verification with reusable results, and free OAuth/SSO account linking. ([source](https://complyage.org/faq/)) - **What is free and what is billed?** The Age Gate and OAuth/SSO are free on every plan. You pay per completed KYC verification: facial age estimation and government ID draw from a plan allowance; payment card, postal address and human review are billed per check. ([source](https://complyage.org/faq/)) - **Which verification methods are supported?** Facial age estimation, government ID with OCR and selfie match, payment card, email, phone (SMS), username (hold-a-sign selfie) and postal address (mailed postcard). ([source](https://complyage.org/faq/)) - **Which methods count as age proof?** Government ID, facial age estimation and payment card are accepted age methods. Email, phone, username and postal address confirm possession or identity and are used as supporting signals, not sole age proof in enforced zones. ([source](https://complyage.org/faq/)) - **Is facial age estimation accepted in Texas?** No. Texas HB 1181 and Louisiana Act 440 are strict zones in ComplyAge's catalogue; only government ID or a payment card is offered there. Most other US states, the UK, France and Australia are flex zones that also accept estimation. ([source](https://complyage.org/faq/)) - **How does region detection work?** The visitor's region is resolved from their IP address and matched to an enforcement zone with a rule — allow, verify or deny — and a list of accepted methods. You can override any rule per region. ([source](https://complyage.org/faq/)) - **What happens if a visitor uses a VPN?** The gate decides on the region the connection presents. A visitor who tunnels into an enforced region is gated; one who tunnels out of it is not. That is a limit of every geo-based control, and the reason statutes attach obligations to the site's reasonable methods rather than perfect detection. ([source](https://complyage.org/faq/)) - **Are verifications reusable?** Yes. A verification belongs to the user's ComplyAge identity and satisfies later checks for the same or another partner without repeating the method. ([source](https://complyage.org/faq/)) - **Do you track users or sell data?** No. ComplyAge does not profile users, run ad networks or sell data. It collects only what a check requires, encrypts it, and minimises retention. ([source](https://complyage.org/faq/)) - **What do you store after a verification?** A reusable record — method, time, outcome. The evidence (images, document reads) is sealed into an encrypted audit archive kept only to answer a valid legal request, and deleted when retention ends. ([source](https://complyage.org/faq/)) - **Does the partner site see my ID or selfie?** Never. A partner receives a verification status through the gate or OAuth — not the document, the image or the card. ([source](https://complyage.org/faq/)) - **Is my photo kept after facial age estimation?** No. The frame is discarded after the estimate. Only a protected face anchor — not reversible to an image — is retained to recognise you later. ([source](https://complyage.org/faq/)) - **Does the Age Gate hurt SEO?** No. The gate overlays the page in the browser; the HTML search engines fetch is unchanged, so content indexes normally. Legally required interstitials are excluded from Google's intrusive-interstitial signal. ([source](https://complyage.org/faq/)) - **Does the gate work with my framework?** Yes — it is a script tag and a first-party cookie, framework-agnostic. Hosted verification is a JavaScript insert; OAuth works with any standard client library. ([source](https://complyage.org/faq/)) - **Can I test without being billed?** Yes. Every integration has test keys that never bill and never produce live verifications. Swap to live keys when you ship. ([source](https://complyage.org/faq/)) - **How do I integrate?** Create an integration in the members portal, add the Age Gate script tag to , add the verification insert where you need an explicit check, and wire OAuth/SSO for sign-in. Test keys let you do all of it on staging. ([source](https://complyage.org/faq/)) - **What happens if ComplyAge is unreachable?** The Age Gate fails open: if the decision request cannot complete, the page is revealed rather than every visitor being locked out. The next page load tries again. ([source](https://complyage.org/faq/)) - **How long does a gate pass last?** By default 30 days. It is a signed token in a first-party cookie on your domain, verified locally with your integration's public key. ([source](https://complyage.org/faq/)) - **Which laws does ComplyAge cover?** The catalogue includes the US states with adult-content age-verification statutes (Texas, Louisiana, Utah, Virginia, Florida, Mississippi, North Carolina, Indiana and more), the UK Online Safety Act, France's SREN/Arcom framework and Australia's Online Safety Act. Zones are updated as laws change; you control the final rule per region. ([source](https://complyage.org/faq/)) - **How do you respond to subpoenas?** Only to a valid legal request, only with what the request lawfully requires, and never with more. The law-enforcement page sets out what we require and what we disclose. ([source](https://complyage.org/faq/)) - **Where do I report a security issue?** Email us, or use the contact in security.txt at complyage.org/.well-known/security.txt. Please give us a chance to respond before disclosing publicly. ([source](https://complyage.org/faq/)) - **How quickly do you answer support requests?** Within two business days. Integration and billing questions from existing customers are prioritised. ([source](https://complyage.org/faq/)) ## Languages Every page is available in 18 languages; each translation declares hreflang alternates. Locale roots: - English (en): https://complyage.org/ - Deutsch (de): https://complyage.org/de/ - Français (fr): https://complyage.org/fr/ - Español (es): https://complyage.org/es/ - Italiano (it): https://complyage.org/it/ - Português (pt): https://complyage.org/pt/ - Nederlands (nl): https://complyage.org/nl/ - Polski (pl): https://complyage.org/pl/ - Svenska (sv): https://complyage.org/sv/ - Dansk (da): https://complyage.org/da/ - Suomi (fi): https://complyage.org/fi/ - Norsk (nb): https://complyage.org/nb/ - Ελληνικά (el): https://complyage.org/el/ - Čeština (cs): https://complyage.org/cs/ - Română (ro): https://complyage.org/ro/ - Magyar (hu): https://complyage.org/hu/ - 中文 (zh): https://complyage.org/zh/ - 日本語 (ja): https://complyage.org/ja/ ## Contact - Email: complyage@gmail.com - Contact page: https://complyage.org/contact/ - Security disclosures: https://complyage.org/.well-known/security.txt