A consent record needs six things: who is depicted and how their identity was established, what specific uses they agreed to, the media and territory covered, the duration, where likeness files live and when they're deleted, and the payment terms. All of it has to be retrievable rather than merely filed. A signed release in an inbox is evidence you asked. It isn't evidence you can produce.
The mistake isn't failing to get consent. It's getting it, storing it somewhere reasonable, and being unable to produce it eighteen months later when someone asks.
What is a rights review actually looking for?
Whoever conducts it is answering one question: can this be shown, and can that be demonstrated?
Not whether you behaved reasonably. Not whether consent was given. Whether it can be evidenced now, by you, in a form someone else can read.
That shifts what "keeping consent" means. The signature is the easy part and the part everyone does. The retrievable, structured, complete record is the part that fails.
Consent is not a signature. It's a record you can produce.
Which makes this an operational problem rather than a legal one. The legal question — do you need consent — is answered elsewhere. This post is about the filing.
What has to be in it?
Six fields. A record missing any of them has a hole a reviewer will find.
| Field | What it has to say | Why a reviewer asks |
|---|---|---|
| Who is depicted, and how identity was established | Named, with evidence they are who they say they are | A consent that doesn't establish identity can't be matched to the face on screen |
| What they consented to | The specific uses, not a general permission | "Any use" is rarely enforceable and rarely what the person understood |
| Media and territory | Which channels, which countries | Decides where the work can run, and it's the clause most often misread |
| Duration, and what it applies to | How long new use remains available, and what happens to work already delivered | Those are two different things with two different answers |
| Storage and deletion | Where likeness files live, who can reach them, when they go | Determines whether an ongoing custodial obligation is being met |
| Payment terms | Amount, trigger, whether it recurs per use | Separates licensing a likeness from buying one |
Source: Hexcoded, September 2026, based on the Actor Licence and Privacy Policy. Guidance rather than a legal standard. Not legal advice.
What does "retrievable" actually mean?
Three properties, and most record-keeping fails at least one.
Findable by character, not by date. When a reviewer asks about the woman in episode 12, you need to get from that face to that document without remembering when you shot it. Filing by shoot date fails here.
Complete without you. If the only person who knows which reference images belong to which character is you, the record doesn't survive you leaving the project.
Readable in five years. A link to a signing platform you no longer subscribe to is not a record. Keep the exported document, not the reference to it.
What does a platform hold for you?
More than most people realise, and it's worth knowing precisely rather than assuming.
Hexcoded's onboarding for a human creator runs a liveness check and a face-match between a selfie and the submitted likeness, processed through AWS Rekognition. A voice recording is processed separately to create the voice. A likeness cannot be published without clearing both checks.
The consent itself is a clickwrap acceptance of the actor licence, recorded with a timestamp and IP address. That record is kept permanently, as proof consent existed — not for the duration of a project, permanently.
The master face and voice recordings are treated differently. They're kept only while brand content generated with that likeness remains licensed, then deleted or irreversibly anonymised.
And when you cast, you're shown a consent-verified receipt — evidence that a real, verified person accepted the licence, which a signed form on its own doesn't demonstrate.
Where this falls short. All of that covers the platform's side. What you still need is your own record of which creator appears in which project under which terms, because the reviewer's question is about your production rather than the platform's library.
What about characters you generated?
Different record, and you still need one.
A character generated from a text description needs no consent, because nobody's likeness is present. What it needs is a note of what created it.
The reason is accidental resemblance. A claim turns on resemblance rather than intent, and if a generated character happens to look like someone real, your only evidence is what your inputs actually were. That either exists from the start or it doesn't exist at all — the finished video doesn't carry it.
There's a place for it built in. Every reference you save to your library takes an optional description field of up to 200 characters. Use it to record what the character is and what created it. Five seconds at the time, unrecoverable afterwards.
Where this falls short. A note of your inputs proves what you used. It doesn't prove the model didn't produce a resemblance from its training data, which is a question nobody currently has a good answer to.
How do you actually organise it?
One record per character, not one per shoot. That's the whole structure.
Create the entry at casting, before any footage exists
Every character gets a record when it's cast, not when it's delivered. Retrofitting a record onto finished work is where gaps come from.
One file per character, named for the character
Not per shoot, per episode or per date. A reviewer asks about a face, so the filing has to start from the face.
Use the reference description field as the log
Two hundred characters recording what the character is and what created it, attached to the reference itself. It travels with the asset rather than sitting in a separate document that can drift out of sync.
Keep exported documents, not links
For anything you signed yourself, keep the file. Platforms lapse, links rot, and a record you can't open isn't a record.
Record what happens at the end
Deletion is an ongoing obligation rather than a final step. A record saying files will be deleted, with nothing saying they were, is half a record.
The four questions a reviewer opens with
- Who is the person on screen, and can you show they consented?
- Does that consent cover this specific use, in this territory?
- Has it expired, and what happens to published work if it has?
- For anyone not covered, what created that character?
If you can answer those four for every character in under ten minutes without reconstructing anything, your record works. If any of them requires you to remember something, it doesn't.
What rights does the depicted person keep?
Worth knowing, because it affects what your record has to survive.
Under Hexcoded's privacy policy, anyone whose data is processed can request access, correction, completion, updating or erasure, and can withdraw consent. Withdrawal stops future processing and new generation — it doesn't affect content already lawfully generated and delivered.
For a creator that's a two-sided fact. Your delivered work stays valid. Your ability to make more with that face can end at any point, which is a production risk rather than a records one.
The platform also accepts creators globally rather than from a single market, and honours rights under local law where it applies — so the applicable regime may not be the one you'd assume from where you're sitting.
Current as of the publication date. This post describes record-keeping practice rather than legal requirements, which vary by jurisdiction and by contract. Hexcoded's terms and actor licence are governed by the laws of India, with jurisdiction in Gurugram, Haryana. Nothing here is legal advice.
- Consent is a record you can produce, not a signature you obtained
- Six fields: who and how verified, what uses, media and territory, duration, storage and deletion, payment terms
- File by character, not by shoot date. A reviewer starts from a face
- On a library platform much of this is held for you — permanently, in Hexcoded's case. Your record is which creator appears where
- Note what created a generated character too. Accidental resemblance is the exposure and your inputs are the only evidence
- Use the reference description field as the log. It travels with the asset
- Record that deletion happened, not just that it was promised
- If answering four questions takes more than ten minutes, the record doesn't work
Six things: who is depicted and how their identity was established, the specific uses they consented to, the media and territory covered, the duration and what it applies to, where likeness files are stored and when they're deleted, and the payment terms including whether payment recurs.
A signature is evidence you asked. A rights review needs evidence you can produce — retrievable, structured, and complete without you. A signed release nobody can find eighteen months later doesn't answer the question being put.
On Hexcoded, more than you'd assume. A liveness check and face-match at onboarding, a clickwrap consent record with timestamp kept permanently, master recordings kept only while content remains licensed and then deleted or irreversibly anonymised, and a consent-verified receipt shown when you cast.
Not consent records, since no real person is depicted. You do need a note of what created the character. Accidental resemblance claims turn on resemblance rather than intent, and your inputs are the only evidence that the resemblance wasn't derived from that person.
One record per character, named for the character, created at casting rather than at delivery. A reviewer asks about a face, so the filing has to start from the face — filing by shoot date means reconstructing the link every time.
Yes. On Hexcoded a creator can stop new use at any time, and anyone whose data is processed can withdraw consent. Withdrawal stops future processing and new generation; it doesn't affect content already lawfully generated and delivered.
The paperwork, already held
Human creators on Hexcoded pass a liveness check and face-match before publication, and their consent is a timestamped record kept permanently. Master recordings are deleted once no licensed content remains. Your record becomes a line rather than a file.
Read the privacy positionMore on characters, consent and reusable elements in Elements.