There’s a tool available to anyone with a credit card that can scan the internet for photos of your face and return results in seconds. It doesn’t require law enforcement credentials, a warrant, or special authorization. You upload a photo. It searches billions of images. It shows you where that face appears online.
Most people don’t know it exists. Most people don’t know their face is already in the database.
How Consumer Facial Recognition Search Works
Tools like PimEyes operate by crawling publicly accessible web pages and extracting faces from images found there. The faces are converted into biometric faceprints — mathematical representations of facial geometry — and stored in a searchable database.
When someone uploads a query photo, the engine computes a faceprint from it and searches the database for similar ones. Results link back to the original web pages where the images were found.
The scale of these databases is significant. PimEyes claims to index roughly 3 billion face images. A newer entrant, Eyematch.ai, launched in 2026 explicitly marketing itself as a way to “find every photo of your face online.” Clearview AI, which serves law enforcement rather than consumers, has more than 50 billion images.
The consumer tools position themselves as privacy protection services. The pitch is: “Search for your own face to see where your photos are appearing without your knowledge, then request takedowns.” That’s a legitimate use case. The problem is that the enforcement mechanism is minimal. Any photo can be uploaded. There is no verification that the person searching is the person in the photo.
What Your Face Has Been Indexed From
You may be wondering how your face ended up in these databases in the first place. The answer is: anywhere your photo appeared on the public web.
That includes:
Social media profiles. Even if you’ve since deleted them. Many of these databases crawled the web continuously for years before platforms began restricting scraping access. Images cached or archived before a deletion may persist in facial recognition databases long after the original has been removed from the platform.
News articles and event coverage. A local newspaper photo from a community event. A conference attendee list with headshots. A school graduation announcement.
Professional directories. LinkedIn profiles, company team pages, alumni directories, professional association listings.
Background appearances. You appear in the background of someone else’s photo. They post it. Your face is indexed.
Old personal websites and blogs. Content you published years ago, possibly under different assumptions about how the internet worked.
Photo-sharing services. Historical uploads to Flickr, Picasa, and similar platforms that were publicly accessible at the time of crawling.
The practical implication is that even people who are careful about what they post today may have a substantial historical footprint that they cannot fully remove.
The Regulatory Landscape Is Improving — Slowly
The legal status of consumer facial recognition databases has been contested for years.
Poland’s data protection authority fined PimEyes for GDPR violations. The UK Upper Tribunal ruled in October 2025 that UK GDPR applies to Clearview AI’s data collection activities. Clearview has accumulated more than €95 million in unpaid European fines that it disputes on jurisdictional grounds.
The EU AI Act, which entered full application on August 2, 2026, classifies most biometric identification systems as high-risk. Real-time facial recognition in publicly accessible spaces is outright prohibited for most uses. Consumer facial recognition search engines sit in a contested middle ground — they don’t operate in real time in physical spaces, but they enable identification using biometric data collected without consent.
In the United States, biometric privacy laws in Illinois, Texas, Washington, and several other states impose restrictions on the collection and use of facial geometry data. Illinois’ BIPA has been the basis for substantial litigation against facial recognition companies. But federal law on biometric data remains fragmented and incomplete.
The FTC’s March 2026 enforcement action against Match Group and OkCupid specifically cited the misrepresentation of how biometric identifiers are collected and used — a signal of increased regulatory attention, though not a direct ruling against facial recognition search engines.
The Opt-Out Problem
Most consumer facial recognition search engines offer an opt-out mechanism. PimEyes allows users on paid plans to request exclusion from search results.
Read that again: you need to pay PimEyes to stop PimEyes from indexing your face.
The opt-out only affects search results — your faceprint may remain in the database even after exclusion from results. Opt-outs don’t extend to other databases that may have independently crawled the same images. And opt-outs typically require you to submit a photo of your face to verify ownership — the very thing you’re trying to prevent.
Even if you successfully opt out of one service, the landscape includes dozens of similar tools at various stages of development, many operating in jurisdictions with weaker data protection laws.
What You Can Actually Do
The options for protecting yourself from facial recognition indexing fall into a few categories:
Reduce your public footprint. Review what’s currently publicly accessible on social media. Set old accounts to private or delete them if they’re inactive. Request removal of photos from websites where you have a reasonable basis to ask.
Use Google’s “Results About You” tool. Google’s tool won’t remove images from third-party facial recognition databases, but it can remove search result links to pages containing your image, reducing the discoverability of indexed photos.
Request removals from specific databases. PimEyes, Eyematch.ai, and similar services have opt-out or removal request processes. These are imperfect and time-consuming but are worth pursuing for the most prominent tools.
Be deliberate about what you post publicly going forward. The facial recognition databases are continuously updated. Reducing new public photo exposure limits your ongoing footprint even if historical exposure cannot be eliminated.
Understand what’s in scope. Photos stored in private cloud storage, private social media posts, or on-device photo libraries are not being scraped by these services. The exposure is to publicly accessible content — what you or others have made visible on the open web.
The Part That Should Concern You Most
The stalking risk is real. In 2022, the New York Times documented cases where PimEyes was used to identify and locate people who had tried to remain anonymous, including survivors of domestic abuse who had moved and deliberately avoided any public internet presence for years. One photo — posted by a friend, appearing in a local news article, or taken at a public event — was enough.
The service ostensibly prohibits this use in its terms of service. Terms of service enforcement against bad actors who are already trying to stalk someone is not a meaningful protection.
The more common risk is reputational surveillance — employers, landlords, or others using facial search tools to compile background information on people beyond what traditional search engines surface. The legal status of this practice is unclear in most jurisdictions.
Why Private Storage Matters Differently Here
The facial recognition indexing problem is specifically a problem of public exposure. Photos stored privately — in your own file storage, in a private cloud account that doesn’t index or share content publicly — are not accessible to these search engines.
When you keep personal photos in a storage service that doesn’t make them publicly accessible, doesn’t use them to power public-facing AI features, and doesn’t share them with data brokers or third-party services, those photos aren’t contributing to the biometric databases.
That’s not a complete solution — historical public exposure is already indexed. But it prevents new exposure and keeps your ongoing personal photo library outside the reach of these tools.
The distinction between public and private storage has always mattered for privacy. Facial recognition search engines have made it matter more acutely for photos specifically.