by Dr Nawab John DarAI photo apps may collect facial data beyond images, raising privacy concerns about biometric information, data retention, model training, and user consent, despite their entertainment appeal. Its concern, and the concern of privacy regulators generally, is with companies that are not honest about how images are handled or how long biometric data sticks around. In California, where I am currently located, the CCPA, as expanded by the CPRA, classifies biometric information used to identify a consumer as “sensitive personal information.” The Biometric Information Privacy Act, in place since 2008, requires a private company to give written notice of what biometric data it is collecting and why, and to get written consent before collecting it. Users in the EU and UK benefit from the GDPR’s stronger baseline protections around biometric data, and Illinois residents have BIPA’s written consent requirement working in their favor.