Privacy: Can You Trust FaceApp With Your Face?

FaceApp is an app that can edit photos of people's faces to show younger or older versions of themselves.  The fashionable smartphone software used to simulate the effects of ageing on its users' features is at the centre of a global cybersecurity row with majors concerns expressed over its terms and conditions. 

Thousands of people are sharing the results of their own experiments with the app on social media. While such clauses are not dissimilar to those used by other social media firms, the company’s Russian background stoked fears it could be vulnerable to abuse. 

They argue that the company takes a cavalier approach to users' data - but FaceApp said in a statement most images were deleted from its servers within 48 hours of being uploaded. The company also said it only ever uploaded photos that users selected for editing and not additional images.

What is FaceApp?
FaceApp is not new. It first hit the headlines two years ago with its "ethnicity filters". These  transform faces of one ethnicity into another - a feature that sparked a backlash and was soon dropped. The app can, however, turn blank or grumpy expressions into smiling one and it can manipulate styles of make-up. This is done with the help of artificial intelligence (AI). An algorithm takes the input picture of your face and adjusts it based on other imagery.

So what's the problem?
Eyebrows were raised lately when app developer Joshua Nozzi tweeted that FaceApp was uploading troves of photos from people's smartphones without asking permission, however, a French cyber-security researcher who uses the pseudonym Elliot Alderson investigated Mr Nozzi's claims , finding that no such bulk uploading was going on - FaceApp was only taking the specific photos users decided to submit. FaceApp confirmed to BBC reporters that only the user-submitted photo is uploaded.

Other researchers have speculated that FaceApp may use data gathered from user photos to train facial recognition algorithms. This can be done even after the photos themselves are deleted because measurements of features on a person's face can be extracted and used for such purposes. Some question why FaceApp needs to upload photos at all when the app could in theory just process images locally on smartphones rather than send them to the cloud.

In FaceApp's case, the server that stores user photos is located in the US. FaceApp itself is a Russian company with offices in St Petersburg. From a business perspective, hiding the photo processing code in their server makes it hard for potential competitors from copying. It also makes piracy harder

Before using FaceApp for taking our photos of your own, its worth reading FaceApp's privacy policy which suggests some user data may be tracked for the purposes of targeting ads. The app also embeds Google Admob, which serves Google ads to users.

FaceApp's CEO, Yaroslav Goncharov told the BBC that  terms in FaceApp's privacy policy were generic and denies that the company shares any data for ad-targeting purposes, as the business model is to make money from paid subscriptions for premium features.

What else does FaceApp have to say?
Mr Goncharov shared a company statement that said FaceApp only uploads photos selected by users for editing. "We never transfer any other images," he said in a  statement.

"We might store an uploaded photo in the cloud....The main reason for that is performance and traffic: we want to make sure that the user doesn't upload the photo repeatedly for every edit operation....Most images are deleted from our servers within 48 hours from the upload date."

The statement said that while FaceApp accepts requests from users to have their data deleted, the company's support team was currently "overloaded". FaceApp advises users to submit such requests through settings, support, "report a bug" and add "privacy" in the subject line. User data was not transferred to Russia, the statement added.

The UK's Information Commissioner's Office (ICO) told BBC News it was aware of stories raising concerns about FaceApp and that it would be considering them.

"We would advise people signing up to any app to check what will happen to their personal information and not to provide any personal details until they are clear about how they will be used," a spokeswoman for the ICO said.

BBC:       Telegraph:        CNET:

You Might Also Read: 

Limit The Duration Google Holds Your Data:

Get Ready For ePrivacy Regulation:

 

 

« Russian FSB Hacked: "Largest data breach in its history"
Business Leaders Are Ignoring Cyber Risks »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

SOTI

SOTI

SOTI is an industry leader in Enterprise Mobility Management (EMM).

Global Information Assurance Certification (GIAC)

Global Information Assurance Certification (GIAC)

GIAC provides certification in the knowledge and skills necessary for a practitioner in key areas of computer, information and software security.

NewGens

NewGens

NewGens is a solution and service provider to banking institutions in the APAC region. Areas of expertise include cybersecurity, AML, fruad prevention, compliance and risk management.

GuardSight

GuardSight

GuardSight is a provider of specialized cybersecurity services to safeguard businesses, government, and remote workers against sophisticated cyber threats.

State Service of Special Communications & Information Protection of Ukraine (SSSCIP)

State Service of Special Communications & Information Protection of Ukraine (SSSCIP)

State Service of Special Communications and Information Protection is the technical security and intelligence service of Ukraine, under the control of the President of Ukraine.

Global Resources

Global Resources

Global Resources' planning and management capabilities support city, regional, and national utility and infrastructure management, and information systems and cyber security service delivery.

Nexon Asia Pacific

Nexon Asia Pacific

Nexon solutions include cloud infrastructure and services, unified communications, managed security services, business continuity, secured high-performance network and business applications.

Prima Cyber Solutions (PCS)

Prima Cyber Solutions (PCS)

Prima Cyber Solutions is focused on protecting your business from the massive and devastating impacts that cyber-attacks may cause.

evolutionQ

evolutionQ

evolutionQ delivers quantum-risk management strategies and robust cybersecurity tools designed to be safe in an era with quantum computing technologies.

Software Improvement Group (SIG)

Software Improvement Group (SIG)

Software Improvement Group helps business and technology leaders drive their organizational objectives by fundamentally improving the health and security of their software applications.

Klaatu IT Security (KITS)

Klaatu IT Security (KITS)

Klaatu IT Security is a boutique provider of cyber security services, empowering our clients to prioritise and reduce their cyber risk.

GreenPages Technology Solutions

GreenPages Technology Solutions

GreenPages provide expert strategic guidance and proven cloud-era solutions for our clients. Every day we help organizations leverage the cloud securely with less risk and cost.

CyBourn

CyBourn

Cybourn's diverse offerings include engineering, analysis, product development, assessment, and advisory services in the cybersecurity space.

SplxAI

SplxAI

Our mission at SplxAI is to secure and safeguard GenAI-powered conversational apps by providing advanced security and pentesting solutions, so neither your organization nor your user base get harmed.

Grey Market Labs

Grey Market Labs

Grey Market Labs is a special place. It is a data privacy and security skunkworks.

Arcfield

Arcfield

Arcfield protects the nation and its allies through innovations in systems engineering and integration, space and mission launch assurance, cybersecurity, and missile support.