privacy

Your Face Is the Product: How Photo Editing Apps Harvest Biometric Data

Facetune, VSCO, and similar apps do far more with your photos than apply filters. Here's what your face data is really worth to them.

You open a photo editing app, upload a selfie, and smooth out your skin. Thirty seconds later you export the result. Simple. Clean. Over.

Except it isn’t. The moment that selfie touched the app’s servers, a detailed map of your facial geometry may have been extracted, stored, and in some cases sold — without your meaningful consent.

The photo editing industry has a biometric data problem, and it’s worse than most people realise.


What “Biometric Data” Actually Means

Biometric data is any information derived from your physical characteristics that can uniquely identify you. That includes fingerprints, iris patterns, and — most relevant here — facial geometry.

Facial geometry is the mathematical description of your face: the distance between your eyes, the width of your nose, the shape of your jaw. These measurements, derived from image analysis algorithms, can identify you across different photos, different hairstyles, and even different ages. They are extraordinarily difficult to change or revoke.

When a photo editing app analyses a selfie to apply smoothing, skin tone adjustments, eye enhancement, or digital makeup, it is — by definition — performing facial analysis. The question is what happens to that analysis afterward.


The Facetune Case: $4.5 Million and an Admission of Sorts

Lightricks, the company behind Facetune, Photoleap, Videoleap, and LTX Studio, agreed to pay nearly $4.5 million to settle a class action lawsuit alleging its apps collected and stored users’ biometric data in violation of the Illinois Biometric Information Privacy Act (BIPA).

The core allegation: when users upload photos to Facetune, the app uses “complex algorithms” and AI to scan and extract their facial geometries — without first obtaining a written release and without publicly disclosing its data retention schedule, as Illinois law requires.

The settlement covered anyone in Illinois whose image was analysed by a Lightricks app at any time between September 2017 and November 2024. Class members were eligible for a cash payout.

What’s notable is what the settlement does not establish. It was not a finding of guilt. Lightricks did not publicly admit wrongdoing. But the $4.5 million figure — the cost of making the lawsuit go away — speaks its own language.

Why BIPA Matters Beyond Illinois

BIPA is currently the only state law in the US that creates a private right of action for biometric privacy violations, which is why most biometric data lawsuits are filed under it. But the underlying data practices described in these cases aren’t unique to Illinois users. The apps operate the same way for users everywhere.

The difference is that users outside Illinois — and outside jurisdictions with similar laws — have little legal recourse.


VSCO: 21 Third-Party SDKs and a Wide Data Net

VSCO presents itself as the artist’s photo editor: no algorithm, no engagement metrics, no ads in the traditional sense. That positioning is partly true. But a look under the hood tells a more complicated story.

VSCO’s app has been found to integrate 21 third-party SDKs — software development kits that add functionality but also add data collection. Among those SDKs: Facebook’s SDK, Google AdMob, and Firebase Analytics.

Data VSCO collects includes purchases, location, contact information, contacts, user content, search history, identifiers, usage data, and diagnostics. According to its App Store privacy label, VSCO uses some of this — contact info, identifiers, and other data — to track users across other companies’ apps and websites.

VSCO does state that its AI-powered editing tools analyse content only to apply user instructions and that it deletes analysis data after edits are complete. It says it does not use these tools to recognise specific people or extract biometric information in a persistent form.

Taking that at face value: the editing process itself may not retain biometric data. But the broader data collection apparatus is substantial, and much of it feeds third-party companies whose privacy practices VSCO does not control.


The Camera Roll Problem

Some photo editing apps request access not just to the photo you want to edit, but to your entire camera roll.

This access, once granted on older versions of iOS and most Android versions, means the app can see every photo on your device — family snapshots, screenshots of financial documents, medical images, photos of your home. The edit request becomes a wholesale photo survey.

Modern iOS (version 14 and later) introduced a “limited access” mode that lets users grant apps access to only selected photos. But many users, presented with a permission prompt in the middle of wanting to edit a photo, simply tap “Allow Access to All Photos” without considering what that means.

On Android, the situation varies by manufacturer and OS version. Many devices still present an all-or-nothing choice for photo library access.

The Right Move

When any photo editing app requests photo access, select limited access if the option is available. Grant access only to the specific photo you want to edit. Review which apps have full photo access under Settings → Privacy & Security → Photos (iOS) or Settings → Privacy → Permission Manager → Photos and videos (Android).


What Data These Apps Can Infer Beyond Your Face

Even without persistent facial geometry storage, photo editing apps operating at scale have access to significant inference opportunities from the content people choose to edit:

  • Age and appearance — derived from the type of edits requested (wrinkle reduction, skin tone adjustment)
  • Self-perception and insecurity — the specific enhancements a person makes to their own image
  • Location — extracted from EXIF metadata attached to uploaded photos
  • Social graph — people who appear in multiple uploaded images
  • Emotional state — some research suggests face analysis can infer mood with reasonable accuracy

When you consider that hundreds of millions of people use these apps globally, the aggregate dataset is extraordinarily valuable — for advertising targeting, insurance underwriting, or sale to data brokers.


Adobe Lightroom Mobile: A Different Model, But Not Exempt

Adobe’s Lightroom Mobile is widely used by serious photographers. Adobe’s privacy practices are materially better than some of the consumer beauty apps — it does not currently face biometric data class actions and has clearer data use documentation.

But Adobe is not above scrutiny. Its 2023 terms of service update, which Adobe later walked back after public outcry, contained language that some users interpreted as granting Adobe a licence to train AI on user content. The controversy illustrated that even established software companies can change their terms in ways that affect how your most personal content is used.

Adobe’s current terms state that it does not train generative AI models on user content from cloud services without consent. Users should verify this remains true each time Adobe updates its terms.


The Honest Assessment

The photo editing app category sits at a problematic intersection: the entire value proposition requires deep access to your most intimate images, and the business models of most free apps require monetising something in return.

Paid apps — those charging a meaningful subscription — have at least some financial incentive to treat your data carefully, because subscription retention depends on user trust. Free apps, especially those backed by advertising or data licensing revenue, have the inverse incentive.

This does not mean every free photo editing app is misusing your data. But it does mean that before you install one, the relevant questions are:

  • Who makes this app and how do they make money?
  • Does the app need full camera roll access, or can I grant limited access?
  • What does the privacy policy say about facial analysis and data retention?
  • Is this app integrated with ad networks or data broker SDKs?

Why This Points Toward Controlled Storage

The deeper issue is not just which app you use to edit a photo. It’s where your original photos live and who has access to them as a result of where they’re stored.

If your full photo library is synced to Google Photos or iCloud and you then edit a photo using a third-party app that also accesses those accounts, your data exposure is multiplied.

daftei keeps your photos and personal files isolated from advertising ecosystems. Files are stored with AES-256 encryption at rest. daftei does not sell your data, does not show ads, and does not share your content with third-party AI training systems. When you delete your account, data is permanently and irreversibly erased after a 30-day grace window — it doesn’t linger in backup servers for 90 days the way it does with some platforms.


Key Takeaways

  • Photo editing apps may extract facial geometry as part of their core function — and not all of them discard it after the edit.
  • Lightricks (Facetune) settled a $4.5 million biometric privacy class action covering the period 2017–2024.
  • VSCO integrates 21 third-party SDKs and uses some data to track users across apps.
  • Granting full camera roll access to editing apps creates exposure far beyond the photo you wanted to edit.
  • Paid apps with subscription models have more incentive to protect user trust than free apps subsidised by data.
  • Review and revoke photo permissions for any editing app you no longer use actively.

The editing app is not neutral ground. Every selfie you upload is, for the duration of that upload, someone else’s data.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts