The verified mark is here
A photo on a dating profile proves almost nothing on its own, and everybody knows it. So Orthodate now has selfie verification. The server picks a pose at random — smile, raise your eyebrows, turn your head — you hold it for a couple of seconds, and a person checks the result against your profile photos. Pass, and a small mark appears next to your name wherever you show up.
What changed
The video never leaves your device
Pose detection runs in your browser. Exactly two still frames are uploaded, and nothing else.
A person makes the decision
Your phone coaches you on lighting and framing, but it does not decide anything. A human compares the stills to your photos.
No faceprint is stored
We do not generate or keep a face template, face geometry or biometric identifier. The review is done by eye.
How it works, in about ten seconds
You open the camera and get a full-screen view rather than a little box inside a settings page, because a camera buried in a form does not read as a camera. First beat: frame yourself. The app tells you if you are too dark, too far away or off-centre, and captures a neutral frame once you are steady.
Second beat: the pose is revealed. Not before — after your neutral frame exists. You hold it, there is a three-two-one countdown, the screen flashes, and you are done. Two stills go up: the neutral one and the posed one.
Holding the pose back until after the first capture is both nicer to use and much harder to cheat. A photograph held up to the lens cannot perform the transition between two frames, which is exactly what the pair proves.
What we do and do not keep
The pose detection runs entirely in your browser using a model your device downloads once. The landmark data it produces is transient, never uploaded and never stored. We do not build a faceprint, and that is a deliberate legal position as much as a technical one — biometric identifiers are heavily regulated in several states, and the honest way to avoid that regime is to not create one.
What we keep is two photographs and a decision. The photos live in a private bucket that nobody can browse. Reviewers open them through links that expire on their own. Capture images are deleted on a thirty-day schedule, and deleting your account removes the folder outright.
All of that is written into the privacy policy in its own section rather than buried in a general clause, and the wording is deliberately precise so it stays checkable against what the app actually does.
- Uploaded: two still images, plus a record of which pose was requested.
- Not uploaded: the video feed, any landmark data, any face template.
- Reviewed by: a person, comparing the stills to your profile photos.
- Deleted: capture images on a thirty-day schedule, immediately on account deletion.
It vouches for every photo, not just one
The first version showed you a single circle with your first photo in it while it explained what the mark meant, and a member told us exactly what that implied: “I put three pictures of myself, not just one.” Fair. It looked like we were verifying one image.
The intro screen now fans out up to three of your photos with the mark pinned to the main one, and the copy says what is true — the check vouches for every photo on your profile. If your photos stop being of you, the mark is not meant to survive that, which is one of the reasons a review can be reopened.
The part where it was broken for two days
Worth writing down, because it is a good lesson. The verification assets — the detection model and its runtime — were generated by a script that we ran by hand on a laptop. They were also excluded from version control. So they existed locally, worked perfectly in testing, and did not exist at all on the production servers.
Every member who tried to verify in that window got a camera error, because the code mapped any failure to “could not open the camera”. It looked like a permissions problem for two days. It was a missing file, and the misleading error message is what cost the time.
Both halves are fixed. The assets are generated by the build itself and the build fails if they are missing, and camera failures and model failures now say different things. If we ever break this again, at least the error will tell you which half broke.
Should you bother?
It is optional, and it will stay optional. But an unverified profile in a world of generated photographs is a weaker signal every year, and the mark is the cheapest credibility you can buy on this app — about ten seconds, once.
It is also the thing that makes the rest of our safety work mean something. Reporting, blocking and moderation all assume that the person on the other side is a person.
Try it