Give us your data and you'll look old. FaceApp at its best.

- FaceApp collects biometric data and sends it to insecure servers.
- Data privacy remains unclear, and users have no insight into how their data is used.
- Terms of service grant FaceApp extensive rights to the images.
- Data deletion is uncertain, despite GDPR rights.
- FaceApp can access location data and browser history.
The free app downloads in a flash. Your face is artificially aged just as quickly. And your biometric data? That’s gone even faster. Anyone joining the current FaceApp hysteria and participating in the #FaceAppChallenge on social media has already uploaded their photos to FaceApp and handed over their data. But what happens to that data now? Let’s trace the trail.
Tracking the data – FaceApp and data privacy
What exactly is FaceApp? It is a smartphone application developed by the St. Petersburg-based company Wireless Lab and offered for free. If users want to see what they look like aged, with different makeup, or even as the opposite gender, this app does the trick. Once users accept the terms and conditions, FaceApp puts an artificial intelligence to work, making users look old—in both the literal and figurative sense. Because FaceApp’s terms of service are quite something.
Are photos safe on FaceApp?
To answer this question, you first have to understand where user data goes. The photos that the app pulls from your smartphone are not processed on the phone itself, but are sent to a server—including, among others, the cloud service AWS from Amazon. However, where else the data is stored, where all the servers used are located, or what the security of these storage locations is like, is unknown. Only then does the AI begin to process the uploaded images. The more data provided to this artificial intelligence, the more it learns (machine learning) and the better it becomes. According to FaceApp, this includes using Google’s AI software TensorFlow, while the other AIs are not specified.
An opaque jungle
The question remains open as to exactly what data is being collected. The privacy policy here is more than inadequate: "So here you are handing over a photo of yourself or others that is biometrically analyzable , meaning it can be linked to you, to a third, unknown party," warns the German Federal Commissioner for Data Protection, Ulrich Kelber. While Yaroslav Goncharov, the head of the company behind FaceApp, explains in this context that the images are deleted after processing, this is by no means certain – because the fact is that by accepting the terms and conditions, users grant the app provider
- unrestricted
- irrevocable
- indefinite
- worldwide and
- royalty-free
access to their images and thus to their personal data. Any further use, for example in public spaces or for commercial purposes, cannot be ruled out or prevented after the fact. It is therefore quite possible that as a FaceApp user, you might soon find yourself in an advertisement without your knowledge. While FaceApp claims not to share data with third parties, the app is still not GDPR-compliant: Data protection expert Elena Sommer-Hörl from Proliance points out in an interview with the radio station RPR1 that, in general, it must first be determined whether such vague terms of use as those of FaceApp are even permissible, because "these additional agreements are very well hidden in the terms of use and are by no means obvious." Sommer-Hörl considers the "unclear use and transfer" of data to be particularly dangerous. Incidentally, it is not possible to view all data collected by FaceApp or to request the data already processed by FaceApp.
Deleting data from FaceApp – is it possible?
Thanks in no small part to the GDPR, every user has the right to have their data deleted, but Goncharov admits that his team is "overwhelmed" due to the massive hype surrounding the app. When and if requests to delete data will be processed is unknown. And even if the images are deleted, this applies to the app itself, but not to the servers. The images remain there – something you also agree to as a user in the terms of use.
Of course, FaceApp is by no means the only app that uploads biometric data to servers, but at the moment it seems to be the most widely used one with terms of use that are disadvantageous to the user . These terms state, among other things, that the user's location is accessed and their browser history is read. But why should such information be relevant for a modified photo?
Senate Democratic Leader Chuck Schumer views the app and FaceApp's approach to data privacy as a national security risk. That may be an exaggeration, but the fact remains that the images collected by the app could, for example, be used as training photos for an AI . And this is not some horror scenario cooked up by overanxious privacy advocates; it has actually happened recently: according to reports from NBC, the cloud provider Ever used photos stored by its users to train the company's own facial recognition software. This was only added to Ever's terms and conditions after the scandal broke. Such a lax approach to highly sensitive personal data by apps is irresponsible and should be enough to shake any user into deleting FaceApp. If you have already used the app, it is, of course, too late for that.
Brief fame, lasting consequences
The fact that the developers of FaceApp are Russian seems to bother Americans most of all. That is why, as Schumer's statement above makes clear, there is particular concern in the US regarding the use of the app. The rest of the world should be more concerned with the question of whether a brief moment of social media success is worth giving away your biometric data. Because while the fun of images altered by FaceApp will soon be forgotten, the millions of photos collected as a result will remain on unknown servers, waiting for potential future use.
Do you have further questions on this topic? Our experts will be happy to advise you free of charge.













