We are getting scanned more than we ever have, and almost none of it leaves a trace we can see. Cameras at the gate, at the door, at the register.
I was walking through an airport with a friend, coming back from a work trip. An "I'll meet you at the gate" situation. He'd paid for Clear, so he strolled up, looked into the camera, let it read his iris, and was through in seconds. He knew exactly what he was trading and what he got for it: ten minutes, for a scan.
A few feet away, a camera took my face by default. There's a way to decline it, technically a sign, a line already moving, an agent waiting. He chose. I didn't, and I don't remember being asked. Both of us handed over biometric data. Neither one of us walks away with a record of what happened.
This isn't about whether they should scan us. They will, and most days we'll let them, or just never know it happened. It's about what you don't get back. If something happens to that data, now or ten years from now, what actually exists to protect the person it came from? Everyone just shrugs. And the ones affected mostly don't realize that the most personal and unique thing about them got handed over. Willingly, unwillingly, or because it was required.
When a company captures something as permanent as your face, and you walk away with no record it ever happened, what do you actually have if it goes wrong?
Mostly, nothing you can do. The data leaks, you get the email, you sigh, you move on. Not because you don't care. Because there was never anything in your hands to begin with. You can't dispute what you were never given a record of.
It sounds like a small thing, but it isn't. And to figure out what we're owed, I had to understand how the law already handles this.
Every road I traveled down kept leading me back to Illinois. The Biometric Information Privacy Act. The few states that actually have biometric legislation build their own versions on top of it, but BIPA is the groundwork. And the biggest biometric cases in the country trace back to the same thing: companies collected the data and skipped the rules, leaving users vulnerable.
The Illinois Supreme Court ruled in 2023 that every biometric scan counts as its own violation. The exposure stacked fast. White Castle put its own potential liability near $17 billion, from a fingerprint clock-in its employees had to use to get paid. Numbers like that force change. Not in your favor or mine. Illinois moved to bring them down. In 2024 the state changed the math: scan someone a thousand times and they can only recover once. In 2026 a federal court applied that cap to a case filed before the amendment passed. One worker had been scanned around 1,500 times. His employer's exposure dropped from roughly $7.5 million to $5,000.
Here's what didn't change. Collecting that worker's fingerprints without telling him was illegal before, and it's illegal now. The conduct is still a violation, the price just happened to collapse. And the worker who started the whole thing still has no record it ever happened. The law moved twice, hard, in the companies' favor, and his side of the ledger stayed empty.
All of this surfaced from just digging through the popular cases regarding biometric privacy. And the deeper you go, I stopped seeing it as only a privacy problem and started to see what's sitting underneath it all.
The biometric industry is missing a piece of infrastructure. The capture works. The proof doesn't. Everyone keeps their own logs. No one produces an independent account of what happened, and the person it came from? Never sees a thing.
Here's how it works on the ground. A vendor installs the hardware. A company hires the vendor and runs it day to day. Maybe it's how employees clock in. Maybe it's what lets you into your apartment. When something goes wrong, who is responsible lives buried in which device got set up how and who maintained it, and there's nothing to point to that exists apart from the company's own word for it.
Then the lawsuit comes, and the company has to prove what happened. The consent records are in one system. The vendor contracts are in another. The access logs are in a third. None of them were built to line up, and months go into reconstructing by hand what a clean record would have shown in one export.
When money moves, I get something back. A receipt at the register. A text the second the card gets charged. A confirmation sitting in my inbox before I'm out the door. Proof that something happened between me and another party, and that I am owed my piece of it.
When a company scans my face, my fingerprint, my palm, my iris? I get nothing. No receipt. No record. No way to even start asking what happened.
Here's the thing about receipts. Most of them are junk. You grab one at CVS and it's in the trash before you hit the parking lot. And that's fine. The slip is small, what it's holding is small, and you can afford to lose it. Ignore it, assume nothing goes wrong, and most days you win that bet. That's the deal that comes with a four-dollar receipt.
But watch what you get handed when the thing gets big. Nobody closes on a house and walks out empty-handed. You leave holding the papers, and not because you went looking for them. A thing that size isn't allowed to happen without putting something in your hands. The stakes decided it for you. The more it matters, the more you walk away holding.
Your face is the most permanent thing you have. The one piece of you that you can't reset like a password or cancel like a card. And it's the one exchange where you walk away holding nothing. We know it's not because the stakes are small. They're as high as they get, and this is somehow the place where the rule breaks. The thing you can never take back is the one thing no one puts in your hands.
So this isn't a receipt you might want someday, the way you keep your CVS receipt or glance at when you get charged in Target. It's the one you should've been handed at the door, for the same reason the closing table hands you the deed. Proof you're owed the moment that it happens. A thing that permanent doesn't get to happen with nothing on your side. Every exchange that matters already works this way. This is the one that doesn't.
That missing receipt is what I built Clavira to be.
Clavira never holds your face, your fingerprint, or your voice. It doesn't see the scan. It doesn't keep tabs on you. It doesn't stop the scan from happening, and it can't undo what's already been taken.
What it does is make a record of what the company did. Not who you are, not where you go. What happened, who did it, under whose authority, and when.
The point isn't that the record exists. The company already keeps its own logs, and a log a company writes about itself is worth what everyone assumes it's worth. Clavira's record is made the moment the event happens, held outside the company's own systems, and built so that any later change to it shows. When the question comes years on, there's finally something to point to that doesn't trace back to the word of the party being asked. Whether that record reaches your hands isn't solved yet. But nothing gets handed over that wasn't built to be handed over, and a company's own logs were never built for you. What I built is made on the premise that the record is owed to you. That doesn't put it in your hands. It makes putting it in your hands possible.
A record of an exchange where, until now, only one side ever walked away holding anything.
Everywhere else, the more an exchange can cost you, the more you're handed. Your face is the most it can cost, and the one exchange that hands you nothing. Whether that finally changes, whether you ever get to see what happened, is the only question left. Every other exchange in your life has already answered it. This one hasn't.
