U.S. citizens get an explicit 12-hour deletion guarantee for facial images CBP collects at airports and seaports. Non-U.S. citizens get no such promise.
Their face scans may be held in short-term TVS storage for up to 14 days, then moved to DHS’s IDENT system for up to 75 years, yet public documents do not detail who can access that long-term record, how access is audited, or what encryption standard applies.
The U.S. Customs and Border Protection can tell a U.S. citizen exactly how long a face scan lives in its systems: 12 hours. The final rule published through the U.S. Government Publishing Office says citizen encounter photos are used only for identity verification and will be discarded within 12 hours of confirming identity and citizenship.
That same rule carries no equivalent clock for foreign travelers.
For non-U.S. citizens, CBP biometric retention follows a two-stage path: up to 14 days in the Traveler Verification Service, then transfer to the Department of Homeland Security‘s IDENT system for up to 75 years. The asymmetry is not buried in a footnote. It is the document’s structure: a hard deletion date for one class of traveler, and an open-ended official-purpose storage rationale for everyone else.
This is not a software limitation. It is a policy choice written into federal regulations.
CBP’s 12-hour deletion promise has a citizenship test
For U.S. citizens, the protection is unusually specific. For travelers arriving by air or sea, gallery photos in CBP’s Traveler Verification Service cloud are erased no later than 12 hours after arrival. A live encounter image of a U.S. citizen whose identity and citizenship are confirmed is also wiped within that same window.
According to CBP, once verification is complete, the images do not move into ATS-UPAX, IDENT, or other CBP and DHS databases. The short retention window exists for operational reasons—protection against delays, outages, or errors while processing arriving travelers.
The specificity is the point. CBP’s privacy threshold analysis treats the 12-hour rule as an air- and sea-arrival business rule. Some notices say gallery photos disappear six hours after an air arrival, but never later than 12 hours.
What the documents do not do is offer a formal statement that every U.S. land port and territory follows the same practice.
For everyone else, retention has no clock
Non-U.S. citizens and lawful permanent residents follow a different route. Their facial images can sit in TVS or ATS-UPAX for up to 14 days, and only for identity confirmation, technology evaluation, algorithm accuracy, and system audits.
Once a traveler is marked “in-scope,” the image moves into IDENT, where the retention schedule can run 75 years or longer if the record is still needed. That is long enough for a face scan taken from a teenager on a first U.S. trip to persist into their nineties. A U.S. citizen on the same flight sees their photo gone within hours.
Biographic records follow the same split. CBP keeps border-crossing histories for non-immigrant aliens and other non-U.S. citizens in BCI and ADIS systems for 75 years. Comparable records for U.S. citizens and lawful permanent residents are purged after 15 years.
| Traveler class | Deletion guarantee for facial images | Stated retention duration for facial images | Biographic travel-history retention | Legal authority cited | Access/audit detail | Public encryption requirement | Opt-out availability |
|---|---|---|---|---|---|---|---|
| U.S. citizens | Live encounter and gallery photos deleted within 12 hours of verification/arrival. | No long-term facial-image retention once identity is verified. | 15 years in BCI and ADIS. | Federal Register rule; TVS and Simplified Arrival PIAs; SORNs. | No facial record retained after verification; biographic histories in BCI/ADIS follow SORN access rules. | No public DHS encryption standard; partner photos must be purged immediately after transmittal. | Citizens may request manual document-based processing. |
| Non-U.S. citizens | No 12-hour deletion guarantee. | 14 days in TVS/ATS-UPAX, then up to 75 years in IDENT. | 75 years in BCI and ADIS. | Same rule; 8 U.S.C. § 1365b; 8 C.F.R. 235.1(f)(1)(ii); SORNs. | CBP and DHS access for border, immigration, law-enforcement; no public role-level detail. | No public DHS encryption standard for IDENT storage; partner photos must be purged immediately after transmittal. | Foreign nationals generally required to submit biometrics; refusal may have consequences. |
| Source: U.S. Customs and Border Protection (CBP); U.S. Department of Homeland Security | |||||||
Access and encryption remain publicly vague
CBP does publish one rule for the private partners that handle these photos. Under the U.S. Federal Register text, approved partners—airlines, airports, and cruise lines—may not keep those photos for their own business use and have to delete them as soon as they are sent to CBP.
For the government’s own long-term storage, no equivalent public detail exists. DHS privacy documents describe IDENT security only at a general level and do not name an encryption standard for the 75-year cache of non-citizen faces. There is also no public breakdown of which job roles can view the records or how each user’s access is audited.
The statute creates the authority; the internal access map is not public.
The EU draws its line at three years
For comparison, the European Union’s Entry/Exit System sets bounded retention for biometric and biographic records of third-country nationals. For each entry, exit, or refusal of entry, the record is stored for three years. The linked file stays on record until three years and one day after the traveler’s last exit or refusal.
If no exit record appears after an authorized stay expires, the data remain for five years.
That timeline is finite by design. It also makes the U.S. difference more conspicuous: a traveler crossing the Atlantic leaves one records regime and enters another with an entirely different clock.
The legal reason the gap exists
The difference traces to two legal authorities: 8 U.S.C. § 1365b and 8 C.F.R. 235.1(f)(1)(ii). The Federal Register final rule published October 27, 2025, cites those provisions as the legal basis for collecting facial images from certain non-U.S. citizens and storing them in secure DHS systems so the agency can verify arrivals and departures. The rule took effect December 26, 2025.
U.S. citizens are not under that same mandate. Their encounter photos have a single job: verify identity at the gate. Once that job finishes, the photo is discarded.
A non-U.S. citizen’s image becomes a travel-history record, tied to legal authority that reaches far beyond the arrival hall.
What this means for you
U.S. citizens can opt out by requesting manual document-based processing from a CBP officer or airline representative. Participation in biometric verification is voluntary for citizens. Foreign nationals generally do not have the same choice: CBP’s air exit procedures state that in-scope foreign nationals must submit biometrics and may face immigration consequences if they refuse.
If you are not a U.S. citizen, do not assume your face scan disappears after the trip. You can file a Freedom of Information Act request with DHS or CBP to seek records about yourself. But the Privacy Act generally does not give immigrants and non-immigrants amendment rights, so you cannot use it to force deletion or correction of a biometric record.
DHS TRIP is the designated contact point for screening difficulties.
Questions? Answers.
Can you opt out of CBP facial recognition?
Biometric checks are optional for U.S. citizens, who can ask to be processed with documents instead. Non-citizens who fall under CBP’s air exit procedures generally have no opt-out, and refusing to provide biometrics can have immigration consequences.
How long does CBP keep records?
U.S. citizen live encounter images are deleted within 12 hours; non-citizen facial images can be held up to 14 days in TVS/ATS-UPAX and then up to 75 years in IDENT. Biographic border-crossing records are kept 15 years for citizens and lawful permanent residents, and 75 years for non-immigrant aliens.
Can a non-U.S. citizen have their CBP biometric record deleted or corrected?
Non-citizens can submit a Freedom of Information Act request to DHS or CBP for records about themselves. DHS policy generally does not grant Privacy Act amendment rights to immigrants and non-immigrants, so the Privacy Act cannot be used to delete or correct a biometric record.
Flight deals
most people never see
Our AI monitors 150+ airlines for pricing anomalies that traditional search engines miss. Air Traveler Club members save $650 per trip per person on average: see how it works.
Each deal saves 40–80% vs. regular fares: