Yep, the KYC provider keeps them.
Could they be put in what bitcoin people call "cold storage"? I can't imagine they're used every day.
They're used pretty often, so not really. The KYC providers anyway wouldn't code anything like that.