What Makes Face Recognition Data Sensitive
Facial data is a form of biometric data, it is linked to biological identity in ways that cannot be changed if compromised. You can change your password; you cannot change your face. This permanence makes facial data qualitatively different from other personal data: a leak of facial data has lifelong implications in a way that a leaked email address does not.
Additionally, facial data can be collected passively and at scale, without the subject's knowledge or consent. This is not relevant to a consumer application where you deliberately upload your own photo, but it is what makes widespread face recognition infrastructure, used in public spaces, substantially more privacy-invasive than other forms of personal data collection.
How Ollie Handles Your Data
Ollie processes your photo to extract a facial embedding for the duration of your session. Your photo and the resulting embedding are not stored after the session ends. No persistent biometric record is created. The system does not require account creation or identity verification; it does not link your search to any persistent profile.
This design reflects a deliberate commitment to data minimisation: collecting only what is necessary for the immediate function, retaining nothing beyond the immediate session. This approach is not just ethical practice; it substantially reduces the risk surface associated with data breaches, since data that is never stored cannot be leaked.
The Broader Context
Consumer celebrity matching applications represent one end of a spectrum. At the other end are large-scale government and commercial surveillance systems that build persistent databases of facial embeddings linked to identities. These raise fundamentally different privacy and civil liberties concerns, concerns about chilling effects on public assembly, disproportionate targeting of specific groups, and the normalization of continuous identity tracking.
Understanding the spectrum helps calibrate response. The appropriate question is not 'is any face recognition acceptable?' but 'does this specific application, with this specific data handling, in this specific context, produce net benefits while managing risks appropriately?' Those are evaluable questions that require specific answers, not categorical positions.
