Skip to main content
LiMP VPN
All news

Meta Built Secret Biometric Database From Instagram Photos

Meta Built Secret Biometric Database From Instagram Photos

In short: Since September 2021, Meta Platforms secretly extracted biometric faceprints from millions of Instagram and Facebook photos — without notification or legally required consent. The data trained generative AI models and built the NameTag facial recognition system, discovered as hidden code in the Meta AI app on over 50 million smartphones in June 2026. A federal class action was filed in US District Court on September 4, 2026. Here is what every Instagram user should understand.

Hidden code on 50 million phones

In early June 2026, security researchers found a near-complete but deliberately disabled facial recognition module inside the official Meta AI app — already installed on more than 50 million smartphones. The feature is called NameTag. After WIRED's reporting and a wave of press inquiries, Meta removed the code but provided no public explanation of how long it had been there or what it had been doing on users' devices, as reported by SecurityLab.ru.

It also emerged that three AI models linked to NameTag had already been downloaded from Meta's servers to user devices. The feature was not technically activated — but all the infrastructure for immediate deployment was already in place.

On September 4, 2026, law firm Wexler Boley & Elgersma LLP filed a federal class action in the US District Court for the Northern District of Illinois, on behalf of Illinois and California residents, including minors. The complaint alleges that since September 4, 2021, Meta systematically extracted biometric identifiers — digital faceprints — from user photos without notice and without the written consent required by law.

How NameTag works: identify a stranger in one second

NameTag was designed for Ray-Ban and Oakley AI smart glasses. The concept: the glasses camera photographs people nearby, the app converts their faces into unique biometric templates, and compares them against a database stored on the user's phone — continuously updated from Meta's servers. The result: the wearer receives a notification identifying a "recognised" face, identified from a single photo, without the subject's knowledge or consent.

A critical detail from the lawsuit: biometric collection extended beyond registered users. If your face appeared in any photo uploaded to Instagram or Facebook — even a friend's snapshot — your biometric profile may have been created without your account, your knowledge, or any ability to revoke consent. Learn more about how tech companies handle personal data on our digital privacy blog.

Why Meta was collecting biometric data from your photos

According to the lawsuit, user photos were used for two purposes.

Training generative AI. Meta's Emu (image generation) and Muse Image (AI editor) models were trained on Instagram and Facebook user content. Personal photos — memories, portraits, family events — became training data for commercial algorithms without permission.

Building the NameTag biometric database. For each recognised face, a unique biometric template was created and stored in a data structure ready for matching. The complaint specifies that collection ran from September 4, 2021 — nearly five years before the lawsuit was filed.

The legal case: BIPA and Meta's prior $650 M and $1.4 B settlements

The plaintiffs' primary legal tool is the Illinois Biometric Information Privacy Act (BIPA), one of the strictest biometrics laws in the United States. BIPA requires companies to obtain written consent before collecting any biometric data — including digital faceprints — and to publicly disclose retention policies. It allows $1,000 per negligent violation and $5,000 per intentional violation. With millions of affected users, the potential liability is enormous.

This is not Meta's first BIPA clash: in 2020, the company paid $650 million to settle a similar facial recognition lawsuit. In 2024, the state of Texas collected $1.4 billion from Meta for comparable biometric data violations. If the court certifies the new class action, a ruling for plaintiffs could set a precedent extending well beyond Meta — to any tech company that uses user-generated photos for AI training.

What to do right now

Filing the lawsuit does not automatically delete your data from Meta's systems. These steps reduce your risk going forward.

Lock down your Instagram and Facebook profiles. Switch accounts to "followers only" visibility: public photos are accessible to more than just friends — including AI training pipelines. Revoke previously granted permissions for data personalisation in your privacy settings.

Remove Meta AI from your phone. That is where the NameTag code was found. Apps running in the background continue transmitting data within whatever permissions you granted at install time.

Protect your phone's network traffic. Many apps transmit telemetry and behavioural data even while running silently in the background. LiMP VPN for iOS and Android encrypts all outgoing traffic and masks your real IP address: your ISP and any Wi-Fi operator cannot see which servers your phone is connecting to. One honest limit: a VPN does not block in-app biometric collection by Meta itself — it secures traffic at the network level. But it is one meaningful layer of a well-rounded privacy posture. See LiMP VPN plans to add this protection.

Monitor the case. If the court certifies the class and you fall within the affected category, you may be eligible for compensation. Notices are distributed through class counsel; follow official announcements through public sources.

Sources

Meta Built Secret Biometric Database From Instagram Photos