Yeah, from what I've seen in a few setups I've messed with, a lot of these systems run the whole liveness thing right on your phone or device without sending the raw selfie off anywhere permanently. They basically do a quick face match between your live shot and the ID photo, plus check for stuff like natural movements or skin reflections to spot fakes, then toss everything once it's done. No long-term biometric storage at all, which keeps it way safer privacy-wise. I actually like how some tools handle this fully offline in local memory—like if you check out https://ocrstudio.ai/id-scanner/ it runs everything on-premise with zero data leaving the device. Makes me feel less sketched out compared to cloud-based ones that might log stuff. Just my two cents after dealing with a bunch of these verifications lately.