Worldcoin stores the biometric data for opt-in users. They say it themselves. It’s stored “encrypted” which means the original data is retrievable, and kept in Worldcoin’s custody. All Worldcoin claims is that it has safeguards against retrieving the data it does collect and store, like say Equifax or 23andme claim about your PII.