Of Faceprints & Photo Apps

September 08, 2026
dipayan@ente.com

The word ‘faceprint’ is really clever. 

It borrows the authority of ‘fingerprint’ and its years of forensic legitimacy, and ties it to a technology that’s maybe just a decade old. And it’s quite an ingenious articulation, because it captures the essence of what the tech actually is.

A faceprint is a unique digital and mathematical code that represents the specific geometry and features of a person's face. The distance between the eyes, the width of the nose bridge, the curve of the jaw, all translated into a vector that a machine can comprehend and analyze. It’s as unique to every individual as fingerprints and iris scans. 

But to assess its impact in the future, we need to first look at the past.

In 2014, Facebook's research team published DeepFace, a system that could verify whether two photos showed the same person with a 97.35% accuracy, just a whiff away from the 97.53% that human judges managed on the same set. This was significant because once a neural network could match faces about as well as the human brain does, at a cost approaching zero and a speed no person could match, everything built on top of that capability became cheaper to build. Tag suggestions. Photo tagging at scale. And eventually, search.

Around the same time, circa 2017, a company called Clearview AI figured out that the open web was full of faces nobody had locked down, and that there was nothing to stop a determined scraper from pulling all of it into one database. By the time anyone had even understood what was happening, Clearview had indexed something like 3 billion images - from Facebook profile photos, news articles, Linkedin pages, mugshot databases. They even built a searchable lookup tool and sold it to police departments and, for a while, private companies, letting them upload a photo of a stranger and instantly get a name back. Nobody in those 3 billion had agreed to it. Most of them probably still don’t know that they are even on it.

These two developments, happening concurrently, is how we got to ‘face recognition is a fact of ordinary life’ within about 6 years. 

The law took its time catching up, as the law generally tends to do.

But catch up it did. And when that happened in the US, Facebook’s tag suggestion feature, which had generated more than a billion faceprints, ran straight into it. Facebook ended up paying $650 million, one of the largest privacy settlements in American history (at that point). More importantly, Meta shut down the whole system, allegedly deleting the faceprints of more than a billion users.

Clearview's reckoning took a different shape. A class-action lawsuit against them ended with the company allocating a 23% equity stake towards the affected class, though the reward was conditional based on certain specific business outcomes. More importantly, a separate settlement with the ACLU forced Clearview to stop selling to most private companies and limit its customer base largely to law enforcement.

In Europe, where GDPR treats biometric data as a special, more protected category, data protection authorities in Italy, France, and the Netherlands fined the company roughly €75 million between 2022 and 2024. And the EU's AI Act, now phasing into force, includes a provision that reads almost like it was drafted with Clearview's business model in mind - an outright ban on building a facial recognition database through the untargeted scraping of images from the internet or CCTV. 

So, are faceprints dangerous?

Well…it depends. 

On the one hand, it’s a property you cannot change. If a password leaks, you change the password, but there is no (practical) way to change your face. So any breach poses a more significant potential of harm than, say an email or phone number getting leaked. Moreover it is timeless, so a photo posted for a wedding album and a selfie taken thirty years apart, in different countries, on different platforms, can be matched based on the mathematical code.

On the other hand, a phone unlocking because it recognizes your face, or a photo app grouping the pictures of your kids, doesnt quite exist on the same spectrum as a company building a lookup tool for strangers off the open web.

Facebook's $650 million fine came from building a faceprint for every user of a feature nobody explicitly signed off on. Similarly, Clearview's problem was that none of the people from those 3 billion images ever got asked, ever got a notice, ever got a release to sign, or had an idea the lookup even existed. 

Which brings us to today, and photo apps.

Google Photos gets consent from exactly one person - whoever uploaded the photos and agreed to Google's terms. It doesn't get consent from anyone else who shows up in those photos, and that gap is precisely what Illinois residents sued over, leading to a $100 million settlement in 2022. Texas's Attorney General filed a similar suit a few months later. Google's fix for the compliance problem wasn't to get better at asking for consent. It was simply to switch off the features in those two states. 

What’s particularly interesting is that across the pond, in the EU, Google Photos continues to offer their basic faceprinting features, even though GDPR treats biometric identification as a special category of personal data.

Maybe it has something to do with the fact that in these US states it could lead to class-action lawsuits, while in the EU they may only face regulatory fines, turning this into a ‘cost of doing business’ option. Or maybe it has to do with narrower definitions of when faceprints become illegal. It’s hard to tell for sure. What is clear is that the consent situation is fuzzy at best.

But there is another way

Ente Photo’s version of the faceprint avoids these consent issues. Because its AI model runs on the device, looks at a photo only that device can decrypt, and the resulting index gets encrypted before it's allowed to sync anywhere. There's no actual faceprint sitting on a server because there's no readable server-side copy to begin with. When nothing meaningful is collected or stored, the issue of consent becomes much smaller.

What this comes down to, in the end, is that the cat is out of the bag. Pandora’s box has opened and there’s no putting the rabbit back into the hat. Faceprints are here to stay, and they are going to remain an intrinsic part of photo apps. What you have to decide is how much access you want to allow companies to have over your faceprints. 

Because it is such a clever, clever technology.