Skip to content
Ethics

Privacy and Face Recognition: What You Should Know

Facial recognition privacy concerns come from face data being biometric: you can change a password but not your face, and faces can be captured without consent. Good practice is to collect only what is needed, keep no photos and delete data quickly. Ollie processes your photo in memory for the search and never saves it.

Wendy WeiAugust 7, 2026 · 5 min read
A security camera above a 'Security cameras in use' sign
Image: Myotus, CC BY-SA 4.0, via Wikimedia Commons (resized)

What Makes Face Recognition Data Sensitive

Facial data is a form of biometric data, it is linked to biological identity in ways that cannot be changed if compromised. You can change your password; you cannot change your face. This permanence makes facial data qualitatively different from other personal data: a leak of facial data has lifelong implications in a way that a leaked email address does not.

Additionally, facial data can be collected passively and at scale, without the subject's knowledge or consent. This is not relevant to a consumer application where you deliberately upload your own photo, but it is what makes widespread face recognition infrastructure, used in public spaces, substantially more privacy-invasive than other forms of personal data collection.

How Ollie Handles Your Data

Ollie processes your photo to extract a facial embedding for the duration of your session. Your photo and the resulting embedding are not stored after the session ends. No persistent biometric record is created. The system does not require account creation or identity verification; it does not link your search to any persistent profile.

This design reflects a deliberate commitment to data minimisation: collecting only what is necessary for the immediate function, retaining nothing beyond the immediate session. This approach is not just ethical practice; it substantially reduces the risk surface associated with data breaches, since data that is never stored cannot be leaked.

The Broader Context

Consumer celebrity matching applications represent one end of a spectrum. At the other end are large-scale government and commercial surveillance systems that build persistent databases of facial embeddings linked to identities. These raise fundamentally different privacy and civil liberties concerns, concerns about chilling effects on public assembly, disproportionate targeting of specific groups, and the normalization of continuous identity tracking.

Understanding the spectrum helps calibrate response. The appropriate question is not 'is any face recognition acceptable?' but 'does this specific application, with this specific data handling, in this specific context, produce net benefits while managing risks appropriately?' Those are evaluable questions that require specific answers, not categorical positions.

Frequently Asked Questions

Does Ollie store my face data?

No. Ollie processes your photo to compute a facial embedding during the session but does not store your photo or embedding after the session ends.

Is facial data more sensitive than other personal data?

Yes. Facial data is biometric, permanently linked to your biological identity. Unlike a password, it cannot be changed if compromised. Regulations like GDPR classify it as a special category of sensitive personal data.

What is biometric data minimisation?

Data minimisation means collecting only the biometric data needed for the immediate function, retaining nothing beyond what is necessary, and deleting data as soon as the purpose is served.

Try it yourself

Find your celebrity lookalike

Upload a photo and see which celebrities you look most like. Free to try, and your photo is never stored.

Find my celebrity look alike

Related Articles