Discord's Persona age verification experiment DID keep photo IDs for 7 days - BUT ALL BLURRED except photo + date of birth - USEFUL ONLY for debugging / rapid manual rechecks
- hypothesis: likely in seach of a partner to handle surges momentarily if K-ID gets overwhelmed
This is to debunk a number of FALSE claims about Discord’s brief experiment using another age verification company Persona to handle some age verification requests in the UK.
Video: Discord's Persona age verification test kept IDs for 7 days - BLURRED except photo + date of birth
Shorter summary and also covering Peter Thiel
Video: Why Discord's Persona experiment respected privacy and had nothing to do with ICE or Peter Thiel
See also
Contents
Summary of what is true and false about Discord’s Persona experiment
What this means for you - most people it makes no difference
Summary of what is true and false about Discord’s Persona experiment
I think the best way to cover this quickly for someone panicking is a quick list of what is true and what is false. Then I’ll go into details.
FALSE ❌ Discord did NOT break promises.
TRUE ✅Discord announced it.
FALSE ❌ the Persona experiment is NOT a way for ICE to get hold of your details
TRUE ✅Persona has nothing to do with ICE or Palanatir
So here is what I found with a fact check (see below)
TRUE ✅Discord itself announced this experiment on THEIR OWN age verification page.
TRUE ✅ This was only a short term experiment for UK users
Hypothesis - it may be for a plan B to handle surges during the roll out
TRUE ✅ALL THE INFORMATION IS BLURRED OUT on the government ID except the photograph and date of birth and kept for only 7 days.
For this reason
TRUE ✅Persona CAN’T use the information to search in government databases.
I also checked out the supposed connection with Peter Thiel and ICE and it FAILS BASIC FACT CHECK
TRUE ✅ Peter Thiel is CEO of Palantir which has been accused by Amnesty International of unethical practices not being careful enough about how their services are used by ICE.
FALSE ❌Peter Thiel is NOT a CEO or in any way associated with policy decisions for Persona.
FALSE ❌Persona was NOT set up by Peter Thiel, he is just a partner in one of many investment funds that invested in Persona with a few % stake. It’s no different from say Paypal or AirBnB which has Founder’s Fund as one of its many investors.
I’ve done a separate debunk for the Peter Thiel details see:
Then specifically on Persona (see below)
TRUE ✅ Persona does do data mining for fraud detection if the client requests it and can retain data for long periods of time if requested to do so
TRUE ✅ Persona hasn’t been involved in any data breaches or any accusations of unethical practice
FALSE ❌They are NOT switching to Persona. They are doing it as an experiment, likely to handle surges if they do use them duing the global rollou
FALSE ❌Discord doesn’t use the Persona fraud detection services - it ensures that Persona sees an ID with everything blurred out except photo and date of birth an Persona only sees those for 7 days likely mainly for debugging
Summary of previous videos / blog posts and what I have left to debunk
What we have already from the previous videos and blog posts:
Discord IS doing this to protect kids
kids are online far more than they were just a few years ago.
they need age verification for much the same reasons they can’t buy alcohol in many countries without showing a photo ID to prove they are old enough
The age verification is done by the UK, Australia other countries with
very strong privacy protection
Because of that
any age verification has to be very secure and privacy protecting
That is what Discord wants too. As unintrusive as possible and to protect your privacy.
I go into this here:
I then looked at how Discord does it.
With those goals this is what Discord does:
Most people will skip age verification - Discord can deduce you are adult based on information it has already
Most of the age verification is done by K-ID which is very secure
Your selfie remains on the device and is age verified by software that runs in your browser that has a high level of accuracy deducing the age from pixels
If you do need to upload your photo ID, then K-ID just checks the date of birth and photo fields and immediately deletes it
All K-ID has in its records is pass or fail for “adult” linked to an anonymous token that it generated itself not to your username
All Discord has in its records is pass or fail for “adult” attached to your user name and it never sees your photo ID or selfie.
My background is that I am a self taught programmer learnt to program in 1971 and since the 1990s I sold my own software over the internet.
I am able to understand the techy details of how Discord / K-ID do it and explain it in the second blog post and video. It is well designed and very secure and protects your privacy well.
So all that is already covered in the first two blog posts / videos.
I now need to look at two more things
Discord’s Persona experiment
this blog post / video
Discord’s manual support ticket system if you take out a complaint about your age classification (next blog post / video) - this is system that was breached in October and I will go into details of how that happened and on what the breach means
next blog post / video.
I will then do
a summary of it all.
So let’s go back to the Discord experiment with Persona.
Why did they do the experiment since K-ID is so good for what they want? Likely for a plan B to handle surges as they roll out age verification to 10 times as many users
The experiment has ended and Discord doesn’t say what the conclusion of the experiment is. My guess is that they were experimenting to see if it could be useful for handling surges in requests for age verification. If they do use it in that way they would announce that later.
It’s nothing to be worried about at all.
Discord believes it will be able to put almost all its users into the adult or child class by itself based on information it already has.
But what if it gets a sudden rush of say a million new people to age verify that slip through its internal checks. Will K-ID be able to keep up?
How many users can K-ID manage per minute?
K-ID now has lots of experience from many companies including Discord, from the UK and Australia, they know what they are doing but Discord is likely K-IDs biggest customer.
K-ID and Discord know it’s a big challenge to step up from a tenth of the global population of Discord users to all Discord users
Discord currently has age verification for
27.9 million users for the UK
well over a million users for Australia.
The total number of active users in the US + Brazil + India + UK + Gemany - the top five countries - is 373.6 million.
https://worldpopulationreview.com/country-rankings/discord-users-by-country
So it has to scale up age verification to more than ten times as many users.
They plan to do this slowly not all at once. Even so they may well get surges of age verification.
As far as I can tell, Discord is currently one of the main users of K-ID along with Quora.
This is K-ID’s list of the main companies it is trusted by for age verification.
Discord
Konami
Capcom
Quora
Moonbug
Another Axiom
Nexus Mods
Krunker
Magic Potion Games
Windup Minds
Nexus
Tribela
Favorited
From the scrolling list on their page here
The list also includes Google but I’m not sure why, as google handles its own age verification.
So K-ID’s biggest customers are likely Discord and Quora and it’s a reasonable guess that Discord may be higher volume than Quora.
So - it is likely not as much as a ten times increase but it could easily be five-fold or more.
If I was in Discord’s shoes I’d look at its biggest age verification surge so far, suppose it is say 10,000 verifications in a minute.
I’d say to K-ID, “Can you handle 100,000 age verifications in a minute? What about 200,000?”
If K-ID just says “maybe” I’d be looking for a plan B. If it says “fine we can handle a million or 2 million” then I’d say “Okay great nothing to worry about here”.
So, it’s natural for Discord to consider whether it may need to partner with other age verifiers perhaps on a temporary basis so I expect that is what this is about.
Alternatively it could just slow down its roll out if Discord sticks with K-ID as the sole age verification partner for the automated age verification. But the problem with surges is they can be unpredictable.
In more detail, I think what is going on is:
Discord is likely reasonably confident that it can handle the surge with K-ID alone, especially since most of the users won’t need any age verification.
With K-ID it can say the data is deleted immediately and forgotten because that is what K-ID itself does.
However it needs a plan B just in case it hits an unexpected surge during the roll out.
So then Persona may be part of that Plan B. It may be confident that K-ID can handle it - but you always think in terms of multiple redundancy just in case, the last thing you want is people doing age verification and then the system says to them “Sorry can’t do this right now, we are experiencing high traffic, try again later”.
It must avoid that.
So then it is likely TESTING Persona as a backup for surges during roll out.
Why Discord might have been interested in Persona - a reliable age verifier that’s been an industry leader since 2018 - has never been hacked - flexible data handling rules that they can set to maximum privacy - and would likely easily handle a surge
This is a past experiment. I think it is likely either
The experiment failed and they won’t use Persona at all or
The experiment succeeded and they may use Persona for surges in traffic in the early stages of the rollout
If they do use Persona then it is
all details blurred out except date of birth and photo before Persona sees the ID and they keep it for up to 7 days
or might be they delete it immediately as Persona has that option
I can’t see them switching to Persona instead of K-ID since K-ID is clearly superior for their needs.
Important phrases highlighted in bold and with bullet points:
QUOTE Important:
If you’re located in the UK, you may be part of an experiment where your information will be
processed by an age-assurance vendor, Persona. The information you submit will be
temporarily stored for up to 7 days, then deleted. For ID document verification,
all details are blurred except your photo and date of birth, so only what’s truly needed for age verification is used.
Here Persona is a reputable age verification company which is used by Reddit amongst others.
They don’t seem to have been hacked, no mention in the Wikipedia page about them for instance.
The main criticism they get that their privacy policy permits them to retain data for as long as the partner requires. Persona also says it can search for the names and other details in government databases for fraud prevention.
However it is up to the partner to decide how Persona uses the data.
In this case Discord has decided
it wants only the most basic debugging and fraud prevention by
removing all information from the ID that Discord sees except the photo and date of birth.
You
can’t do a search in a government database with that minimal information of just a photograph and a date of birth.
Remember that from Discord’s point of view it just wants age verification.
Discord wants the data to be private and safe.
There is
no plus to Discord if any of the information is misused, just bad publicity.
So, Discord is on your side. It wants the age verification to be secure. It wouldn’t benefit if Persona somehow got hold of information it shouldn’t have.
So why the 7 days? Probably because Persona is built differently from K-ID and works more naturally with a short retention period
The 7 days is likely just because K-ID is built around deleting the data within minutes. But Persona is used to retaining some data for fraud prevention, and to check for mistakes and other reasons.
Persona can delete the data instantly but it typically retains data either to correct mistakes or for fraud prevention
Persona from Discord’s point of view is an enterprise grade company that’s been around for longer than K-ID, since 2018 instead of 2023 for K-ID. Persona is used by Reddit.
https://en.wikipedia.org/wiki/Persona_(identity_verification_service)
It doesn’t seem to have been involved in any data leaks or have any controversy associated with it from the Wikipedia page.
From its own page the data retention policy is set by the customer. They, from their side, will not retain data for more than three years. Most data is deleted instantly, but some can be retained for fraud protection. It is up to the customer what the precise policy is.
https://withpersona.com/legal/privacy-policy
So then Discord had to decide what to do and it could have told Persona to delete all the data instantly.
It can’t be retaining the blurred ID for fraud prevention.
So the reason for retaining a blurred government ID is likely for debugging, so that it can ask Persona to recheck if it makes mistakes matching the selfie to the photo in the ID. Or perhaps to help monitor to be able to figure what went wrong if there’s a batch of Persona IDs that it doesn’t check.
So this is more to do with the internal policies of Persona and K-ID than Discord. They have a different workflow.
Then Discord has likely negotiated with Persona and decided on a 7 day retention period but with all except the photo and the date of birth blurred.
The 7 days is NOT for fraud prevention - can’t be done with blurred out data
The 7 days is NOT to use the normal fraud prevention services that Persona provides.
Almost all will required the blurred out data.
It’s not likely to get duplicate IDs with the same photo / Date of Birth either (apart from identical twins).
So - seems virtually nothing it can do by way of fraud prevention.
Likely for debugging glitches / to reverify manually in a quick simple way
It’s likely mainly to deal with any glitches / mistakes, especially with such a short period. If say Discord finds that Persona is making too many mistakes it can then ask Persona to reverify manually and find out what went wrong.
The 7 days can’t be for the original verification. There is no way that a Discord user has to wait more than minutes.
So then the other possibility is if the user disputes the age verification and opens out a ticket with Discord, the independent team that handles the tickets might then ask Persona to re-check the blurred out ID with the main reason for a mistake likely to be a mistake in matching the photo to the selfie, before manually checking the ID itself.
What this means for you - most people it makes no difference
My recommendation here is that
If you are age verified automatically or just age verify via a selfie then this isn’t relevant at all.
If you upload the government ID then check on the age verification page to see if it is going through K-ID or some other company.
If it is K-ID it is very very safe.
I think there is a possibility they may use Persona at some points early in the roll out to handle surges.
They might
Use Persona but ask it to delete the data immediately - this then is similar to K-ID
Use Persona but with the 7 day retention
If they use Persona with 7 day retention:
Persona has never been hacked as far as I can tell
Hackers could in principle get your photo and date of birth but not your name.
Since Persona has nee been hacked your risk of that is very low.
So then it is about personal risk management. How are you about a very low risk of a leak of
A photo of you linked to your date of birth but not your name or any other details and not linked to your Discord username.
So then - well in my case my photo is all over the web anyway. I am a small business sole trader.
Many other people have their photos on the internet associated with their names for instance
Public facing in commerce, share name and photo as part of building trust in you business
Judge, lawyer, advocate, doctor, psychiatrist
Academic associated with any university - and also often your name and photo is published if you got a degree at any university or college
Sports at school or college, if your team got in the news then it is likely to include photos and names
Ran as a candidate in any elections
Actor or actress even for minor roles normally your name and photo is public
If there’s a Wikipedia page about you and it has a photo
Then - your date of birth - if you have a Wikipedia page with a photo most of them also have date of birth too.
The risk here is of leaking your date of birth and photo but without your name.
Especially if your photo is not linked to your name online anywhere there’s zero risk of a hacker finding your name.
If there is a link online - it’s still pretty hard unless you are well-known or unless you share the same photo as for your photo ID.
And the most they could get is your date of birth which isn’t much use for identity theft nowadays.
If you still as a personal risk assessment you don’t want to take this minute risk then
don’t upload your photo ID until you are sure it is going to be processed only by K-ID (or Persona or other age verifier if it is set to delete the info immediately)
Just wait a few weeks and probably they will stop using Persona as they clearly favour K-ID and are likely only using Persona as a backup and may soon find they don’t need them.
But chances are that you are assessed as adult without ever needing to upload a government ID.
Worst case is you are treated as an under 18 member which makes little difference to most Discord members
And the worst case is that you experience Discord like an under 18 member which makes almost no difference unless you want to look at content that would be age rated as over 18 or want to take part in one of the small minority of age gated private servers on Discord.
I will go into this in more detail later.
Next blog post: Ticket system
Next though let’s look at the ticket system. That is if you manually dispute the age verification.
That is for my next video and blog post. It is ready now:
See also
CONTACT ME VIA ddebunked.org OR EMAIL
You can Direct Message me on Substack - but I check this rarely. Better, email me at support@robertinventor.com
OR contact me at our new forum
https://ddebunked.org
Please do NOT Direct Message me on Facebook any more unless you are already in contact with me.
If already in contact on FB then please understand if I don’t reply for a while except to very urgent messages
Try email or other ways to talk to me until this is sorted out.
For now I only want to talk on FB about how to message me somewhere else.
FOR MORE HELP
To find a debunk see: List of articles in my Debunking Doomsday blog to date See also my Short debunks
Scared and want a story debunked? Post to our forum which is set up for voluntary fact checking.
The forum itself is here:
Also do join our forum if you can help with fact checking or to help scared people who are panicking.
Alternatively you can post to our Facebook group. Please look over the group rules before posting or commenting as they help the group to run smoothly
Facebook group Doomsday Debunked
However I am not able to comment or post there at present because
SEARCH LIST OF DEBUNKS
You can search by title and there’s also an option to search the content of the blog using a google search. Try different terms e.g. Russia, Putin etc as it only searches the title.
CLICK HERE TO SEARCH: List of articles in my Debunking Doomsday blog to date
NEW SHORT DEBUNKS
I do many more fact checks and debunks on our Facebook group than I could ever write up as blog posts. They are shorter and less polished but there is a good chance you may find a short debunk for some recent concern.
I often write them up as “short debunks”
See Latest short debunks for new short debunks
I also tweet the debunks and short debunks to my Blue Sky page here:
I do the short debunks more often but they are less polished - they are copies of my longer replies to scared people in the Facebook group.
I go through phases when I do lots of short debunks. Recently, I’ve taken to converting comments in the group into posts in the group that resemble short debunks and most of those haven’t yet been copied over to the wiki.
TIPS FOR DEALING WITH DOOMSDAY FEARS
If suicidal or helping someone suicidal see my:
BLOG: Supporting someone who is suicidal
If you have got scared by any of this, health professionals can help. Many of those affected do get help and find it makes a big difference.
They can’t do fact-checking, don’t expect that of them. But they can do a huge amount to help with the panic, anxiety, maladaptive responses to fear and so on.
Also do remember that therapy is not like physical medicine. The only way a therapist can diagnose or indeed treat you is by talking to you and listening to you. If this dialogue isn’t working for whatever reason, do remember you can always ask to change to another therapist and it doesn’t reflect badly on your current therapist to do this.
Also check out my Seven tips for dealing with doomsday fears based on things that help those scared, including a section about ways that health professionals can help you.
I know that sadly many of the people we help can’t access therapy for one reason or another - usually long waiting lists or the costs.
There is much you can do to help yourself. As well as those seven tips, see my:
BLOG: Breathe in and out slowly and deeply and other ways to calm a panic attack
BLOG: Tips from CBT
— might help some of you to deal with doomsday anxieties
PLEASE DON’T COMMENT HERE WITH POTENTIALLY SCARY QUESTIONS ABOUT OTHER TOPICS - INSTEAD JOIN OUR NEW FORUM ddebunked.org
PLEASE DON’T COMMENT ON THIS POST WITH POTENTIALLY SCARY QUESTIONS ABOUT ANY OTHER TOPIC:
INSTEAD PLEASE COMMENT IN OUR NEW FORUM HERE:
It’s just a forum not social media. No age verification. Set up by myself with free open source software Flarum.
For details:
If you have any issues joining it do let me know.
Why I ask you to post to our forum with anything scary off topic instead of here
The reason I ask you to post there instead of comment with your concerns about unrelated topics here is that I often can’t respond to comments here for some time. The unanswered comment can scare people who come to this post for help on something else
Also even an answered comment may scare them because they see the comment before my reply.
Do comment here with anything that is on topic for this post, E.g. if you spot any mistakes however small please let me know.
Also, though your first comment should be on topic, it is absolutely fine to digress and go off topic in conversations here in a natural way if that is how the conversation develops.
This is specifically about off topic comments here hat might scare people on a different topic.
PLEASE DON’T TELL A SCARED PERSON THAT THE THING THEY ARE SCARED OF IS TRUE WITHOUT A VERY RELIABLE SOURCE OR IF YOU ARE A VERY RELIABLE SOURCE YOURSELF - AND RESPOND WITH CARE
This is not like a typical post on substack. It is specifically to help people who are very scared with voluntary fact checking. Please no politically motivated exaggerations here. And please be careful, be aware of the context.
We have a rule in the Facebook group and it is the same here.
If you are scared and need help it is absolutely fine to comment about anything to do with the topic of the post that scares you.
But if you are not scared or don’t want help with my voluntary fact checking please don’t comment with any scary material.
If you respond to scared people here please be careful with your sources. Don’t tell them that something they are scared of is true without excellent reliable sources, or if you are a reliable source yourself.
It also matters a lot exactly HOW you respond. E.g. if someone is in an area with a potential for earthquakes there’s a big difference between a reply that talks about the largest earthquake that’s possible there even when based on reliable sources, and says nothing about how to protect themselves and the same reply with a summary and link to measures to take to protect yourself in an earthquake.




PLEASE DON’T COMMENT ON THIS POST WITH POTENTIALLY SCARY QUESTIONS ABOUT ANY OTHER TOPIC
Also please check the purpose of this substack - to help people scared of many things. Welcome:
- questions if you are still scared and need help
- fact checks if I got anything wrong however small
- help with debunking
Please don't post potentially scary things here unless you are yourself scared and needing help.
FOR POTENTIAL SCARY QUESTIONS ABOUT OTHER TOPICS YOU WANT DEBUNKED - PLEASE COMMENT IN OUR NEW FORUM HERE
https://ddebunked.org
There are many there who can answer you not just me. And it is setup for voluntary fact checking and far easier to use than comments here
https://ddebunked.org
It’s just a forum not social media. No age verification. Set up by myself with free open source software Flarum.
For details see my:
https://robertinventor.substack.com/p/our-own-new-discussion-forum-for
We only need your user name and email address to join and the email address is just for notifications, we don't look at it (unless needed to help you or for debugging) or share with anyone.
If you have any issues joining it do let me know.
I was going around political optimism on Reddit (the only decent sub I frequent) but I saw someone mention this and it's getting people worried https://vmfunc.re/blog/persona