Building KYC Systems That Work for Under-18s

·8 mins

Through my work at Hack Club, a 501(c)(3) STEM non-profit for under 18s, we recently rolled out AKYC verification ahead of our Summer 2026 partnership with NASA.

Understandably, some privacy-conscious teens in our community were concerned with our use of Persona, a large identity check provider.

Why do we need KYC?

KYC, or know your customer, is a standard process in most business-to-business (B2B) and business-to-consumer (B2C) companies to ensure that the person on the other end of the service is a real human and is not abusing/misrepresenting themselves maliciously.

In the context of a non-profit, we use KYC to fulfil part of our safeguarding policy to ensure that adults can’t gain access to a community built for 13- to 18-year-olds We also do this for fraud purposes to prevent duplicates and malicious accounts from manipulating our referral systems or our more lenient programmes.

Hack Club was founded to create a community of like-minded teenagers. Since 2014, we’ve reached over 70,000 teenagers globally. That number is only going to grow. The Stardance Challenge, Hack Club’s Summer NASA Flagship event, has already reached 23,000 teens globally.

This level of growth is completely new to us. A year ago Nora released Hack Club Auth, a single sign-on and verification provider for Hack Club centrally, as part of our mission to reduce fraud and decrease account friction across our platforms as we grow more as an organisation. To date, it’s now processed over 40,000 verifications.

Nora & I knew that Auth was never built for this scale - so far, the average wait time all time has been 3 days, yes in the last month (prior to Persona’s launch) it’s been ~4 hours, but that’s because we haven’t seen the high numbers we’d usually see during a large summer event. With Stardance just around the corner we knew that Auth in its current form would simply not be able to cope with the influx of teens.

Just looking at the numbers, our ID verification wait time would be days at launch, massively increasing user attrition. There’s a deeper problem as well; humans aren’t actually that good at the specific job of spotting a sophisticated fake. Fraudsters use AI-generated documents, better Photoshop, and tooling that improves faster than any reviewer’s eye can keep up with. A liveness check and a trained detection model catch things a person staring at a scan simply won’t. That’s the part we hand to Persona, not because we don’t trust our own team, but because catching fakes at speed and scale is a different skill from the one humans are good at. Where humans are good, and where we keep them, is the opposite case: making sure a real person never gets wrongly turned away.

Why Persona?

I think it’s a fair question to ask why we chose Persona. The easy answer is that it was cheaper than the alternative and we liked the platform more. However, this wasn’t just a commercial decision. From the research that I’d done and the articles that I’d read, it was clear to me that Persona does genuinely care about user safety and their track record is clean (for PII leaks) since working with them. Their team has been fantastic and it is empowering to know that a small non-profit in Vermont is being taken seriously by a multi-billion dollar company.

A good amount of people in the #meta thread that was made following this release asked about Persona’s connections to Peter Thiel and Palantir. While Persona have received venture capital funding from the Founders Fund, that doesn’t mean that they have creative direction or would sell data to Palantir. I am open to being proven wrong but at present I trust Persona’s privacy guarantees. I’m confident that Persona has the ability to operate independently of companies whose privacy or public privacy policies may come under scrutiny

How have we rolled this out?

The elephant in the room is that we are attempting to run KYC on 13 to 18-year-olds, many of whom may not have a governmentally issued ID. This is a fact that will not change. One of our North Stars is that everyone should be able to verify themselves in some way, regardless of their socioeconomic, or geographical status. If a Hack Clubber has a government ID that’s scannable by Persona, for example MRZ-readable passports, verifying through Persona is a quick and easy way to get full access to all Hack Club programmes and receive funding with an average approval time of under 24 hours. However it is a known fact that many countries do not issue government ID to under 18s or under 16s in some cases and/or there are barriers to obtaining them, whether that is logistical or monetary. While I’d love to live in a society where everyone has the ability to verify themselves, to prove their identity without paying for it, this is unfortunately not a reality.

In the US we’re able to mitigate this through a custom Persona ‘Inquiry’ using their selfie feature and document uploads to allow some US students to prove their identity through a student ID card and a transcript. We’ve seen great success in this programme and look to continue to expand it and improve its efficiency to further decrease the barrier to entry for Hack Club programmes.

Outside of the US we’re still working on country-specific approval mechanisms for those without government-issued IDs. However, we may not always be able to provide students with prizes or monetary grants if we cannot confidently verify that they are real, unique students.

Persona won’t be optional for everyone. However, on decisioning, we let Persona’s algorithms handle acceptance, because as above, catching a fake is what they’re best at. We never let an algorithm be the final word on rejection. When Persona flags an ID as rejected, it goes into a manual review queue and a human double-checks it before anything is final. On your end it stays “pending”, and you might get a follow-up email asking for another check. The machine is there to catch the fraud our team would miss. The human is there to catch the real person the machine got wrong.

What happens to your data?

When you verify, Persona processes your selfie scan and ID images to run the liveness and document checks. The biometric data (your selfie scan) is deleted as soon as that check completes. The underlying selfie and document images are deleted within 7 days from Persona’s system. We have a contractual agreement that Persona will not use any data for secondary use or model training.

We keep more than Persona does, and I want to be straight about that. Hack Club retains your selfie and ID images until you age out of the community at 18, or sometimes indefinitely if an account is removed for fraudulent activity. We hold them because the alternative, re-verifying every teen from scratch and losing the ability to spot a banned fraudster signing up again, would undermine the safeguarding our entire system exists to provide. That being said, access is highly sensitive. Only three Hack Club employees: me (Operations Lead), Nora (Lead Engineer), and Zach (CEO + Founder) can view raw ID images, and every access goes through a break-the-glass scheme that requires an audit reason. Images are also encrypted at rest, through our US-based servers.

You can request deletion at any time via our Privacy Policy, but the tradeoff is that it’s final. Once your verification data is gone you lose access to Hack Club services, and that email can’t be used to verify again, because we’d have no way left to distinguish you from a new or duplicate account.

”I don’t want to use Persona”

This is a fair concern, and we want to take it seriously. But the question underneath it, the one a lot of you are actually asking, is: “Is there an alternative?” or “Can a human just review my ID directly, without Persona in the loop?”

In the interest of transparency, here’s my thinking:

The hard truth is that Persona is both faster and more accurate than any of us. Me, Nora, Bartosz, the rest of the HCB team, we can’t run liveness checks or selfie scans by hand. That’s the entire reason we pay Persona: they’re one of the best in the industry at exactly this, and they have a clean track record (and no, leaked unminified code from a theoretical non-prod government app doesn’t count as a breach).

So a “skip Persona, get a manual review” button sounds reasonable until you look at it from the other side. Picture a fraudster landing on that screen. They’re not going to sit through the checks designed to catch them. They’re going to click the button that says “bypass the smart computer.” Every bypass we build for the privacy-conscious teen is the same door we hold open for someone trying to abuse the platform.

We don’t want this to feel like a black box. But some opacity is deliberate, the same way the Hack Club Fraud Prevention team operates, because total transparency about our defenses is the same as publishing the playbook for beating them. I’d bet we’re one of the only platforms that’s open-source and willing to talk through this with our community at all.

Closing

This process isn’t finished. We will keep iterating, and improving until we can find a solution that works for everyone. I would love your feedback. But when you weigh in, hold both people in your head at once: the privacy-conscious teen who distrusts big tech, and the fraudster clicking “skip the checks that keep Hack Club the safe community it’s meant to be.” The design problem is serving the first without opening the door to the second. If you’ve got an idea for how, I want to hear it.