Your Face. Forever

Twelve years of one life

Imagine a scenario. 2012. A young woman creates an Instagram account. She posts her first photo — a smile, a summer day, a good mood. Geotag: Tallinn. Caption: first name, surname, a link to Facebook. 2015. A corporate party. A photographer shoots everyone. The photos are posted to a shared group. She is in them. Where she works is visible. 2018. A friend’s wedding. Photos from the celebration — in the friend’s profile, with a tag. The family circle is visible. 2021. She tries a new app — a filter that «ages» your face. Funny. She shares it with friends. 2024. A job-search app asks for a profile photo. She uploads it. She did not think of it as a system. Each action was separate, innocent, personal. But the system thought for her. Over twelve years she built a biometric database about herself. More precise than any state surveillance system. Voluntarily. For free. With pleasure. Her face is in dozens of databases. On servers in countries she has never visited. In algorithms she never authorised. In profiles that are sold to companies whose existence she does not know about. And to delete it is impossible.

Why a face is not just a photograph

There is a fundamental difference between a photograph and biometric data. A difference that most people do not understand — and that the industry prefers not to explain. A photograph is an image. It shows how you look. Facial biometric data is a mathematical model. A unique numerical vector that describes the geometry of your face. The distance between the eyes. The width of the nose. The shape of the cheekbones. The ratio of proportions. Hundreds of parameters that together create your unique biometric identifier. This identifier is like a fingerprint, but better. Because it can be extracted from any photograph without your knowledge. Without your presence. Without your consent. You did not give your fingerprint to anyone — except border control and an employer if it was required. You controlled to whom and when. Your facial biometrics you gave to everyone. Every time you posted a photo. Every time you were photographed and published without being asked. Every time an app requested access to the camera. And unlike a fingerprint — you cannot change it. You have one face. For life.

What happens to a photo after posting

You posted a photo. What happens next.

The first seconds: the platform

The platform — Instagram, Facebook, VKontakte, LinkedIn — receives the image. Runs a face-recognition algorithm. Creates a biometric vector. Saves it in a database, linked to your account. This happens automatically. It is built into the architecture. This is exactly how the «tag people in the photo» function works. The algorithm does not search by name — it matches biometric vectors. In 2021 Facebook announced that it was disabling automatic face recognition and deleting the biometric templates of more than a billion users. It sounds like a privacy victory. But it means one thing: until 2021 the company stored the biometric templates of a billion people. For years. Without their explicit consent.

The second stage: search engines

The photo is indexed. Google Images. Yandex Images. Bing. They download a copy. Store it on their servers. Create their own indexes. You deleted the original — the indexed copies remained. Google Images can show your photo for years after you deleted it from your page.

The third stage: aggregators and data brokers

Companies that specially collect public data from social networks. Build profiles. Sell access. PimEyes — a face search engine. You upload a photo — you get all the public mentions of this face on the internet. The service works openly. For a fee. For everyone. Clearview AI — the same thing but for law-enforcement bodies. It has collected more than 30 billion photographs from open sources. Without the consent of the people in these photographs. It sells access to police and intelligence services in dozens of countries. You posted a photo in 2015. Today your face is in Clearview’s database. A police officer in any country that has bought a subscription can upload your photograph and find you across all public sources in seconds. You did not consent to this. You were not asked.

Apps that entertain. And take your face for it

There is a separate class of threats that works through entertainment. Remember the FaceApp app that «aged» your face. 2019. A viral trend. Tens of millions of people uploaded their photo to see how they would look in old age. It was made by the Russian company Wireless Lab — founder Yaroslav Goncharov, a former manager at Yandex. The user agreement gave the company a perpetual, irrevocable licence to the uploaded images. Today the service is owned by FaceApp Technology Limited, registered in Cyprus. The company claimed that the photos were not transferred to Russia and were processed in the Amazon and Google clouds. The user had no way to verify this. That was the essence of the complaint — not a proven transfer, but the impossibility of verification. The US Senate initiated an investigation. The FBI called FaceApp a potential counterintelligence threat. But by that point tens of millions of biometric samples had already been uploaded. People laughed at their aged photos. And at the same time handed biometric data to a company whose storage and intentions they could not verify. This is not an isolated case. It is a pattern. Apps that draw you as an anime character — take your face. Apps that show your «double» from another era — take your face. Filters that «improve» your appearance — take your face. Each of them offers a second of entertainment. Each takes a biometric sample that lives on someone else’s servers longer than you remember downloading that app.

Deepfake: when your face works without you

Until now we have talked about how your face identifies you. That is a first-level problem. There is a second-level problem. Your face can act on your behalf. Without you. Against you. Deepfake technology — the synthesis of video in which someone else’s face is replaced with yours — ceased to be an exotic thing in 2023–2024. The quality of available tools reached a level at which the result is indistinguishable from real video to the naked eye.

What is needed for a convincing fake

A few dozen photographs of a face from different angles. Preferably with different expressions. With different lighting. This is exactly what you provided — by posting photos over the years. A selfie in profile. A photo from a party where the face is visible under different lighting. A video from a story. Photos with different emotions. This is enough. Technically. Already now.

How it is applied

Pornographic deepfake. The most widespread application. According to researchers at Deeptrace — the company later became known as Sensity — in a 2019 report, 96% of deepfake videos on the internet were pornographic. Practically all the victims are women. Their faces are overlaid on other people’s bodies without their consent. The videos spread. To delete them is practically impossible. Fraud through voice and face synthesis. In 2024 cases were recorded where fraudsters created video calls with a synthesised face and voice of a real person — to convince relatives to transfer money. «Mum, I’m in trouble, I urgently need money.» The voice is real. The face is real. The person — not. Political manipulation. Synthesised videos of politicians saying things they never said. A tool of discreditation that becomes cheaper and more accessible every month. Blackmail. A person is shown a synthesised video with their face in a compromising situation — and money is demanded for its non-distribution. The video may be entirely fake. But it is hard to prove. And the harm from its distribution is real.

Indecent content you did not film

This is the most painful angle of the topic. People post photos without thinking that their face may end up in a context they never chose. Did not plan. Did not imagine possible. The technology works like this. A public photo is taken. The face is extracted by an algorithm. It is overlaid on existing video material. The result — a video that looks real. This is happening right now. Not in the future. There exist platforms — some closed, some open — where users do this with public photographs of ordinary people. Not only celebrities. Any person whose face is publicly available is a potential victim. And here it is important to understand the scale of the deletion problem. You found out that such a video exists. You went to the platform with a demand to delete it. The platform deleted it. But during the time the video existed — it was downloaded. Re-posted. Uploaded elsewhere. To another platform. To another jurisdiction. The internet does not forget. This is not a metaphor. It is a technical reality. Content that once got into the network is reproduced faster than it is deleted. This is precisely why prevention is the only real defence. Not reaction after. Awareness before.

Children: a separate conversation

There is a category that cannot protect itself. Parents post photographs of their children. This is understandable. It is a desire to share joy with loved ones. First steps. A birthday. The first day at school. But each such photograph is a biometric sample of a person who cannot yet give informed consent. Who does not understand what is happening. Who will one day grow up and discover that their biometric profile has existed since birth. Publicly available. On someone else’s servers. In databases they did not choose. France passed a law on a child’s right to their own image — on 19 February 2024. It does not grant the right to demand deletion upon reaching adulthood. It does something else: it establishes that both parents jointly protect the child’s right to their image, forbids one from publishing without the consent of the other, and allows the family court to prohibit publication. And if publications seriously harm the child’s dignity — the court can transfer part of the parental rights to a third party. That is, the child’s image was built into the concept of private life. And the parent was made responsible before the child. This is a signal. European legislators have begun to understand the scale of the problem. But the law reacts to what has already happened. The photographs already exist. The biometric data is already collected.

What the GDPR says

Biometric data — Article 9 of the GDPR. A special category. Maximum protection. The processing of biometric data is prohibited without explicit consent or without one of the strictly limited exceptions. This is the highest bar of protection in European law. But there are three problems the GDPR does not fully solve.

Problem one: jurisdiction

The GDPR applies to companies that process the data of EU residents even if they themselves are outside the EU. To apply it in practice is a separate battle. Clearview AI is an American company. It has received fines from the regulators of France, Italy, Greece, the United Kingdom. It continues to operate. PimEyes is a separate case. It began as a Polish startup in 2017. In 2020 it moved to an offshore structure and relocated to the Seychelles. In 2021 it was bought by Giorgi Gobronidze, who registered a company in Dubai for the deal and another in Belize. He himself lives in Tbilisi. What such a construction means in practice was shown by a lawsuit from five Illinois residents. Lawyers spent two years trying to serve the company with court documents. They looked for representatives in Georgia, Dubai, Belize. They found no one. The case was closed. The plaintiffs’ lawyer said it was like a lawsuit against a ghost. In April 2026 the organisation noyb sued the Hamburg regulator — for inaction. The regulator considers PimEyes’s practice unlawful, but does not pursue the company, because it «seems to be located in Dubai». By that point the complaint had been sitting for five years.

Problem two: public data

You yourself posted a photo publicly. A company collected it from a public source. Where is the border between the public and the protected? European regulators consistently take the position: publicity does not mean consent to any use. The Italian regulator explicitly indicated that Clearview violates the GDPR even by collecting public photos. But this position has not yet become an indisputable norm in all jurisdictions.

Problem three: the right to deletion in practice

Article 17 of the GDPR — the right to deletion. You can demand that a company delete your data. But you must know that the company exists. Must know that it has your data. Must know how to submit a request. Must wait for a response within 30 days. Must have a mechanism to verify that the data was actually deleted. Clearview AI created a form for EU residents to request the deletion of their data. You must upload your photo — so that the system can find you in the database and delete you. The irony is that to delete your photo from a face-recognition database — you must send your face into this database again.

What really helps

This is not a call to delete all your accounts. It is information about what changes the level of risk.

Privacy settings

They work, but not the way you think. «Friends only» limits who sees a photo on the platform. It does not limit what the platform does with the biometric data extracted from the photo. It has already been extracted at the moment of upload. But it still matters. The fewer people see the photo — the fewer chances that it will be copied and end up in public aggregators.

Geotags

A photo with a geotag ties your face to a specific place. Regular geotags create a map of your routes. Combined with face recognition this is a ready-made tracking system. Turning off the geotag by default is a simple action that removes one of the most informative layers of data.

Apps with camera access

Every app to which you gave camera access potentially processes images of your face. Not necessarily maliciously. But technically it has the capability. Check the list of apps that have access to the camera. On iOS: Settings → Privacy → Camera. On Android: Settings → Apps → Permissions → Camera. A flashlight app does not need the camera. A calculator app does not need the camera. If it is there — that is a question.

«Entertainment» apps that require a face

A simple rule. If the only function of an app is to process your face and return a result, this app takes a biometric sample. The entertainment lasts a second. The sample remains. This does not mean not to use it. It means to understand the price.

The right of access to data — Article 15 of the GDPR

You can request from any company operating in the EU: what data about me are you processing. Including biometric. The company is obliged to respond within 30 days. This is not an abstract right. It is a concrete tool. To send a request is free. Without a lawyer. A template letter is publicly available.

The future that has already begun

There is something important about the timeline. Databases of faces are growing. Every day. Billions of new photographs. Billions of new biometric vectors. The links between the databases are strengthening. Today your face in Instagram is not necessarily linked to your face in Clearview’s database, not necessarily linked to your face in a state-control database. Tomorrow these databases may be linked. Technically it is already possible. The photographs you posted in 2015 do not become obsolete. The algorithms of 2015 are no longer what they are now. A new algorithm of 2026 processes old photos with new precision. Data that previously did not allow reliable identification — now allows it. This means that the decisions you make now affect not only the present. They affect what your biometric profile will be in ten years. When the technologies become even more precise.

A face that cannot be changed

A password can be changed. A phone number can be changed. An email address can be changed. Even a name — legally — can be changed. A face — no. This is the fundamental difference of biometric data from all others. It is inalienable. It is linked to you forever — in the sense that you cannot physically revoke it. You can demand deletion from a specific database. But you cannot cancel the fact that it existed. This is precisely why a decision about what to publish, made now, has a different weight than a decision about any other data. Other data can be revoked. Facial biometrics — cannot. Not because the law provides no mechanism. Because the reality of the internet is such that data lives longer than the requests to delete it. This is not a call not to be photographed. Not a call to disappear from the network. It is a call to understand exactly what you are giving away when you press «publish». Not a photograph. A biometric identifier that will exist longer than you remember it does. And that works — with or without your knowledge — in systems whose existence you may never learn of. Knowing this does not change the past. But it changes the next decision.

← All journal entries