If you logged onto Twitter or Facebook over the past day or so, you probably saw friends who appeared to have suddenly aged 30 or 40 years. That’s because a new app that allows users to accelerate their age, change their hair colour and even “swap” their gender went viral. Celebrities like Nick Jonas and Drake are doing it. My friends are doing it. Even I did it – several times.
The problem is that as soon as the app took off, some people began raising serious privacy concerns about it. Two privacy concerns, to be specific: one about the general ecosystem of apps that vacuum up our information, and one about FaceApp’s country of origin.
Originally released two years ago, FaceApp was designed by the St. Petersburg, Russia-based firm Wireless Lab. Twitter quickly took notice of the app’s national origin, and several users expressed concern that their funny aged photos (any may be the originals, too) were being sent across the cloud to servers in Russian President Vladimir Putin’s backyard – for who knows what.
Privacy Matters and several news outlets (some in rather alarming terms) pointed out that when you use the app, you grant Wireless Lab a lot of rights. That includes a “perpetual, irrevocable, nonexclusive, royalty-free, worldwide, fully-paid, transferable sub-licensable license to use, reproduce, modify, adapt, publish, translate, create derivative works from, distribute, publicly perform and display your User Content … without compensation to you.”
That basically means FaceApp can do whatever it wants with your photos, according to New York Law School professor Ari Waldman. “You retain copyrights and photos that you upload, but you grant them the opportunity to pretty much do anything they want with the photos that are stored on their servers,” Waldman told me. And in many cases, it’s not just photos of the individual using the app – people upload images of their friends and families, too, meaning such a database of faces would be massive, and that same policy would apply regardless of who is in the photo. “It’s pretty broad, to say the least,” Waldman said.
But the worst of the panic about FaceApp’s privacy protections happened when a now-deleted tweet suggested that FaceApp might be gaining access to and uploading a user’s entire camera roll. If true, that could have been a massive privacy concern. After all, people also store screenshots of bank records and credit card numbers in their camera rolls as well as personal shots that – let’s just say – they wouldn’t want in the hands of the Russian government or anyone else, really.
using a network traffic analyzer, I tried to replicate the thing people are talking about with FaceApp allegedly uploading your full camera roll to remote servers, but I did not see the reported activity occur.
here is marlo stanfiekd with a beard though pic.twitter.com/6wy8cHLNuA
— Will Strafach (@chronic) July 17, 2019
(Marlo Stanfield is a character on the HBO series, The Wire) That reassurance aside, there’s no real way to know if data is ending up in Russia somehow, how long it’s staying there and what the company is using it for. Photos you actively select are uploaded to the cloud, which isn’t really standard practice for a photo-editing app, according to Strafach.
Most photo-editing applications perform edits on the phone instead of in the cloud. “When you select a photo and edit it, it does get sent to their servers,” Strafach said. “To me, as someone who hadn’t used the app before, they did not make it obvious that they were sending it to their servers. When you apply filters, it’s their servers performing the edits.” In essence, it’s not just the final version you picked to post on your Instagram story that’s been sent to the cloud somewhere – it’s all the edits and the original, too.
Yaroslav Goncharov, FaceApp’s creator and Wireless Lab CEO, said in an emailed statement that no user data is transferred to Russia even though “the core R&D team is located” there, and he echoed that the entire camera roll is not tapped for upload. Forbes reported that FaceApp uses Amazon servers located in the US and Australia. And, to be fair, FaceApp said it deletes most photos after 48 hours: “We might store an uploaded photo in the cloud. The main reason for that is performance and traffic: we want to make sure that the user doesn’t upload the photo repeatedly for every edit operation.”
But, again, all we have here is its word. When I asked Goncharov what Wireless Lab uses the photos for, he didn’t say. “Privacy policies and terms are drafted by lawyers and they always prefer to be on the safe side,” Goncharov wrote in an email. “We are planning to do some improvements here.” I directly asked if the company actively uses personal data for commercial purposes, and he didn’t respond.
1. No #faceapp terms arent different from other social apps.
2. Yes now they own irrevocable rights to your likeness.
3. Yes a Russian company now has a db of AI enhanced photos & your personal details.
4. Yes they likely hoovered up other metadata.
5. No you cant have it back.
— Marc Rogers (@marcwrogers) July 17, 2019
This viral sensation does offer a glimpse at how quickly millions of faces could be gathered up for nefarious purposes, though. And such a collection of data in the hands of any company could have pretty significant commercial possibilities. FaceApp has an “insanely detailed data set for anyone who wants to work on facial recognition technology,” Waldman said.
Facial recognition technology – even though it’s been shown to be biased and discriminatory – and the databases that power it are becoming increasingly profitable for government surveillance, law enforcement and even marketing. A collection like FaceApp’s could be used to train facial recognition technology or to form a database that could be sold to another company. In 2017, the Guardian reported on a similar technology in Russia, FindFace, that allowed users to photograph people in crowds and work out their identity with nearly 70% reliability. (To be clear, FaceApp doesn’t seem to be connected to FindFace.) The public features of FindFace have been discontinued, but it remains available for government and business use.
Concerns about privacy in the app has risen as far as the US Democratic National Committee, which told presidential campaigns not to use the viral app because of the Russian developers. US Senator Chuck Schumer has even asked the US Federal Bureau of Investigation and the Federal Trade Commission to investigate FaceApp. With the combination of social media, personal data privacy, and Russia, it’s no wonder there is a widespread concern. But Baptiste Robert, a French security expert who goes by the pseudonym Elliot Alderson, said on Twitter the “story is out of control,” especially considering the app uses mostly US-based internet infrastructure like Amazon Web Services and Google – and that its terms are not markedly different than other social media companies like Snapchat, for example.
Still, Waldman says it’s always good to be wary. “It’s a Russian company, which, with the statist structure they have over in Russia, means that there are likely connections between the company and the government.” So if you haven’t already aged your face, it’s probably a good idea to be cautious.
But that applies to your entire digital life, not just FaceApp. Technology companies and app developers out there are after data, and they will design any tool – especially entertaining ones – that dupes or manipulates people into handing over their data, according to Waldman. And we shouldn’t just be worried about Russian companies. “We should be equally (and significantly) concerned about all of it,” Waldman said. “Both FaceApp and Facebook are manipulative tools that enrich their designers by data gathering via a pretext of fun.”