privacysecurity

3 Million Photos Built a Facial Recognition AI — Secretly

The FTC's April 2026 OkCupid settlement reveals how app photos quietly become AI training data — and what to do about it.

In April 2026, the Federal Trade Commission announced the resolution of a case that had been open since 2019. The target was OkCupid, the dating app. The finding: OkCupid had, in 2014, handed nearly three million user photos to a facial recognition company called Clarifai — along with location data and demographic information — without telling users, without their consent, and outside the boundaries of what OkCupid’s own privacy policy permitted.

Clarifai used those photos to train a facial recognition AI.

The settlement required Clarifai to delete the photos and any AI models trained on them. Match Group, OkCupid’s parent company, was banned from misrepresenting its data practices for twenty years. There was no financial penalty — the FTC lacked authority to impose one for this type of violation.

It took twelve years from the initial data transfer to any accountability at all.


What Actually Happened

The detail that makes this case particularly notable is the relationship involved. OkCupid’s founders were investors in Clarifai. When Clarifai’s founder requested access to OkCupid’s user data in 2014, OkCupid obliged — nearly three million photos were transferred, with no formal data-sharing agreement, no restrictions on how the data could be used, and no disclosure to users.

At the time, OkCupid’s privacy policy stated that user data would not be shared with third parties except under specific conditions. Facial recognition training was not one of those conditions. The transfer happened anyway.

For more than a decade, millions of users’ photos — photos uploaded to find a romantic partner — were used to train a system designed to identify people’s faces. None of them knew.


Why This Matters Beyond Dating Apps

The instinct when reading about a case like this is to treat it as an OkCupid story, or a dating app story. It’s neither.

OkCupid is a consumer app that held user photos. The photos were shared with a third party without consent. The third party used them to train AI. The regulatory response took years and resulted in no financial consequence.

That sequence of events could describe hundreds of apps across every category. Photo-editing apps. Fitness trackers with camera features. Social platforms. Document scanners. Health apps. Games with avatar features. Recipe apps that let you photograph meals.

The common thread isn’t the nature of the app. It’s that the app held photos, had a third-party relationship with an AI company, and lacked meaningful external enforcement preventing it from sharing.

Most consumer apps contain language in their privacy policies permitting broad data sharing with “business partners,” “service providers,” or entities involved in “product improvement.” Whether any of those relationships involves facial recognition training, or other AI training on your images, is almost never disclosed.


Users of OkCupid had agreed to a privacy policy. That policy was violated. But even a privacy policy that was followed would not have protected them if it had disclosed the transfer.

“Consent” in the context of consumer app privacy policies is a legal fiction. No one reads them. A 2022 Carnegie Mellon study found that reading all the privacy policies you encounter in a year would require roughly 76 work days. The policies are therefore technically available and practically invisible.

Even when users nominally consent to data sharing by accepting terms of service, they have no idea what they’ve agreed to. They certainly have no understanding that photos uploaded to find a date might end up building a facial recognition system for an entirely unrelated company.

The meaningful question isn’t “did the user consent?” It’s “could the user have reasonably anticipated this use of their photos?” In the OkCupid case, the answer is obviously no. In most cases involving broad data-sharing clauses, the answer is the same.


What “Deleted the Models” Actually Means

The remedy in the OkCupid case — deletion of the photos and any models trained on them — deserves scrutiny.

Deleting training data is straightforward: you remove the files. Verifying that a company has done this is reasonably achievable.

Deleting a model trained on that data is more complicated. Neural networks don’t store training examples in a retrievable form. They extract statistical patterns from training data and encode those patterns in millions or billions of numerical weights. The weights are the model.

When regulators require model deletion, they mean: delete the file containing those weights. This is done. But the company can retrain a new model that may learn the same patterns from the same distribution of data — including legally held photos from other sources. Deletion of the model isn’t deletion of the knowledge it extracted.

This isn’t a criticism of the OkCupid settlement specifically. It’s an observation about the inherent limits of current enforcement mechanisms. “Deleting” an AI’s relationship with your photos is not technically equivalent to erasing that relationship entirely.


The No-Penalty Problem

Perhaps the most significant aspect of the April 2026 settlement is what wasn’t imposed: a financial penalty.

The FTC found that OkCupid violated its own stated privacy policy, transferred the personal data of three million people to a facial recognition company without consent, and contributed to the construction of a system designed to identify people’s faces. The consequence was: a ban on misrepresenting data practices for twenty years, and mandatory deletion of the misused data.

No fine. No compensation for affected users. No penalty that creates a financial deterrent for the next company considering a similar arrangement.

The incentive structure this creates is not reassuring. An app company that transfers user photos to an AI company gains: a trained AI model with real commercial value, a business relationship with the AI company, and possible investment returns. If caught — years later — it may have to delete those assets. But it doesn’t have to pay for having obtained them.

This is not unique to the OkCupid case. US privacy enforcement for consumer data generally lacks the financial penalties that make the calculus unfavourable. GDPR enforcement in Europe has produced larger fines, but cases still move slowly and settlements still often fall short of meaningful deterrence.


What You Can Do With Information You Don’t Have

The fundamental problem users face is informational. You can’t make good decisions about which apps to trust with your photos if you don’t know what those apps do with them.

A few approaches that improve your position, even without perfect information:

Read the data-sharing sections, not the highlights. Most privacy policies lead with reassuring statements (“we take your privacy seriously”) and bury the meaningful disclosure in sections on data sharing with partners and affiliates. The vague language in those sections — “third parties involved in providing services,” “companies we partner with to improve our product” — is where photo-sharing arrangements typically live.

Minimise what you upload. If an app doesn’t need your photo to function — or if the core function could work with a lower-resolution version — giving it less reduces your exposure. Profile photos on apps that don’t require them should be considered carefully.

Check what “improve our services” means. This phrase appears in virtually every app’s privacy policy. It can mean anything from fixing bugs to training AI on your data. Companies that use this language to permit AI training don’t typically disclose that plainly.

Pay attention to investor relationships. The OkCupid case turned on a founder relationship between two companies. This kind of arrangement — where a data-holding company and an AI company share investors, board members, or executives — creates the conditions for informal data-sharing that bypasses formal review.

Prefer apps that make categorical commitments. “We never share user photos with third parties for AI training” is a specific, verifiable claim. “We take privacy seriously” is not.


The Facial Recognition Dimension

The specific use of OkCupid photos for facial recognition training adds a dimension beyond general AI privacy concerns.

Facial recognition systems identify people by their face. A system trained on your photos, even photos you shared in a different context years ago, can be used by the company that holds the model — or by anyone who licenses, buys, or steals it — to identify you. This identification doesn’t require your cooperation. It doesn’t require your presence.

The commercial facial recognition market has companies that provide identification-as-a-service to employers, landlords, law enforcement, retailers, and other clients. The provenance of training data for these systems is rarely disclosed. Whether photos from consumer apps form part of their training sets is, for the most part, not publicly known.

This is a different category of risk from most data privacy concerns. Knowing your email address or location creates limited permanent risk. Training a model on your face creates a persistent identification capability that follows you through the physical world.


What Private Storage Changes

The OkCupid case is about photos uploaded to a consumer social platform. daftei is a different type of product: a personal memory vault designed specifically to keep your files away from the kind of third-party sharing this case illustrates.

daftei doesn’t share user content with third parties for any purpose. Photos stored in daftei aren’t processed through AI pipelines, aren’t shared with facial recognition companies, and aren’t used to train models. The business model is subscription revenue — there’s no commercial incentive to extract value from your photos beyond securely storing them.

Files are encrypted at rest with AES-256 and in transit with TLS 1.3. The 5 GB free tier gives you space to store your most sensitive files without a financial commitment. Unlimited storage is available on Pro at $5.99/month or $44.99/year.


The Larger Pattern

The OkCupid story is twelve years old. The photos were transferred in 2014. The FTC opened an investigation in 2019. The case was resolved in 2026.

The AI companies that might have received photo data from consumer apps in the last few years will have their investigations opened, if at all, years from now. The apps that quietly shared your photos with an AI partner in the last product cycle may face accountability in a decade — or may not.

The gap between when data is used and when accountability arrives means that by the time enforcement comes, the commercial value has been extracted, the models have been deployed, and the window for meaningful remedy has narrowed significantly.

This isn’t an argument for despair. It’s an argument for being thoughtful about which apps get access to your photos — before, not after, the fact.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts