Elements

What liveness verification means, and why it's on record

Format Short dramaMarket Global English
Short answer

A liveness check confirms a submitted likeness belongs to a live person rather than a photograph, a video, or someone else's image. On Hexcoded it runs at onboarding alongside a face-match between a selfie and the submitted likeness, both processed through a third-party service, and a likeness cannot be published without clearing both. The consent that accompanies it is recorded with a timestamp and kept permanently.

Every platform with real people in it says the consent is verified. Almost none of them say what the verification actually consists of, which is the only part that would matter if anyone asked.

What problem does a liveness check solve?

Uploading someone else's photograph.

That's the whole problem, and it's trivially easy without a check. A face submitted as your own might be a photograph of a stranger, a still from a film, or a public figure. Nothing about the file distinguishes those cases from a genuine submission.

A liveness check is the step that does. It asks the submitter to demonstrate they're a live person in front of a camera at the moment of submission, rather than someone in possession of an image.

Paired with a face-match, it answers a second question: is the live person the same person as the likeness being submitted. Those are separate checks and both are needed — being alive doesn't prove the face is yours.

Liveness proves someone is real. A face-match proves it's them. Neither works alone.

What actually happens on Hexcoded?

Four steps, in order, and the sequencing matters more than the mechanics.

1

A likeness is submitted

The creator provides the images and video that will become their AI likeness, along with a voice recording processed separately to create the voice.

2

Liveness and face-match run

A liveness check confirms a live person, and a face-match compares a selfie against the submitted likeness. Both are processed through a third-party verification service rather than assessed in-house.

3

The licence is accepted

The creator accepts the actor licence as a clickwrap agreement, recorded with a timestamp and IP address. That record is the consent.

4

Publication becomes possible

Only after both checks pass does the likeness become available to cast. The order is the point — verification is a gate rather than an audit.

That last step is what separates this from a takedown process. A platform can verify after a complaint, or before publication. The second means an unverified likeness never becomes castable in the first place.

Which is also why it's a worse experience for the creator submitting and a better one for you casting.

What record survives the check?

Two things, kept on very different timescales, and the asymmetry is deliberate.

The consent record is kept permanently. The timestamped acceptance of the actor licence stays on file indefinitely, as proof that consent existed. It doesn't expire when a campaign ends or when a creator leaves the platform.

The master recordings are not. The face and voice recordings used to build the likeness are kept only while brand content generated with that likeness remains licensed. Once none does, they're deleted or irreversibly anonymised.

So the evidence outlives the material. That's the right way round — you need to prove consent existed years later, and nobody needs the source recordings once nothing is running.

The proof is permanent. The raw material isn't. Those should be opposites and usually aren't.

What does it give you when you cast?

A consent-verified receipt, shown at the point of casting.

That's a small interface element doing a specific job. It tells you the creator you selected is a real, verified person who accepted the licence — which is a different statement from "this face is licensed," and a much more useful one if someone asks you to substantiate it.

The practical difference shows at approval stage rather than in the edit. "We used a licensed actor" is an assurance. "Here is the receipt confirming a verified person accepted the licence for this use" is evidence.

Where this falls short. The receipt confirms the platform's verification. It doesn't discharge your own record-keeping — you still need to know which creator appears in which project under which terms, because that's what a reviewer asks about.

Your side of the paperwork

What isn't verified?

Anything you upload yourself, and this is worth being direct about.

There is no consent step when you upload a face. The platform accepts a photograph and turns it into an actor in your library without checking whose face it is. No liveness check, no face-match, no attestation.

That's a deliberate asymmetry rather than an oversight. The library exists to be verified; your own uploads exist to be fast. Uploading your own photograph is the intended case and needs no gate.

The consequence is that consent for anyone else's face is a discipline you keep rather than something the tool enforces. If you upload a colleague, a founder, or a friend who agreed verbally, nothing in the product will stop you and nothing will record that you asked.

The verification described in this post applies to human creators in the library. It does not apply to faces you upload. Those two routes produce the same kind of asset with completely different evidence behind them.

What else is on record?

Three things worth knowing, because they're the parts people assume rather than check.

Face and voice data is never used to train general models. It's used only to build and operate that creator's own likeness. That's stated in the actor licence and in the privacy policy, and it's a narrower permission than most platforms take.

Identity is verified again at payout. A separate know-your-customer check runs when a creator withdraws earnings — so being verified to appear and being verified to be paid are two checks, not one.

Creators are accepted globally. The platform isn't limited to one market, and local-law rights are honoured where they apply. Which means the applicable data-protection regime may not be the one you'd assume from where you're sitting.

What can a creator do afterwards?

Withdraw, and it's worth knowing because it's the other side of being verified.

A creator can stop new use of their likeness at any time. Content already generated and delivered stays valid — the licence on it is perpetual. What stops is new generation.

Separately, anyone whose data is processed can request access, correction, completion, updating or erasure, and can withdraw consent. Withdrawal stops future processing and new generations rather than affecting what's already lawfully been made.

On death, heirs may ask that new use stops, with unpaid earnings passing to the estate.

Where this falls short. For a long-running series that's a real planning risk rather than a footnote. Being verified doesn't mean being permanent.

This describes Hexcoded's verification and retention practices as published in its privacy policy and actor licence, current as of the publication date. Hexcoded's terms and actor licence are governed by the laws of India, with jurisdiction in Gurugram, Haryana. Nothing here is legal advice.

The bottom line
  • A liveness check proves a live person. A face-match proves it's the same person. Both run, and both are needed
  • Both are processed through a third-party service rather than assessed in-house
  • Publication is conditional on passing. It's a gate before casting, not an audit after a complaint
  • Consent is a timestamped clickwrap record, kept permanently as proof it existed
  • Master face and voice recordings are kept only while licensed content remains, then deleted or irreversibly anonymised
  • You're shown a consent-verified receipt when you cast. That's evidence rather than an assurance
  • None of this applies to a face you upload. There's no consent step on upload at all
  • Face and voice data is never used to train general models — only that creator's own likeness

A check confirming a submitted likeness belongs to a live person rather than a photograph, a video, or someone else's image. It asks the submitter to demonstrate they're in front of a camera at the moment of submission, rather than merely in possession of a file.

They answer different questions. Liveness proves someone is real; a face-match compares a selfie against the submitted likeness to prove it's the same person. Being alive doesn't prove the face is yours, which is why both run.

At onboarding, before publication. A likeness cannot be published — and therefore cannot be cast — without clearing both checks. That's a gate rather than an audit after the fact.

Two things on different timescales. The consent, a timestamped acceptance of the actor licence, is kept permanently as proof it existed. The master face and voice recordings are kept only while brand content generated with that likeness remains licensed, then deleted or irreversibly anonymised.

No. There's no consent step when you upload a face — no liveness check, no face-match, no attestation. That's the intended design for uploading your own photograph, and it means consent for anyone else's face is a discipline you keep rather than a gate the tool enforces.

Yes. A creator can stop new use of their likeness at any time. Content already generated and delivered stays valid, because the licence on it is perpetual — what stops is new generation. Anyone whose data is processed can also request access, correction or erasure.

Verified before it's castable

Human creators pass a liveness check and a face-match before their likeness can be published, and you're shown a consent-verified receipt when you cast. The consent record is kept permanently; the source recordings aren't.

Read the privacy position

More on characters, consent and reusable elements in Elements.