Is the ‘FaceApp Challenge’ Safe?

4
8.5

Published -

Searching the network...

Millions of Americans spent mid-July watching themselves age 40 years in a single tap, then started asking who else was watching them.

The FaceApp Challenge turned into one of the fastest-spreading trends of the summer, with the Jonas Brothers, Kevin Hart and Carrie Underwood among the celebrities posting AI-aged selfies for tens of millions of followers. The app itself is simple: upload a photo, let its neural network render a decades-older version, share it. But within days, cybersecurity researchers and privacy advocates started picking apart what FaceApp’s terms of service actually allow the company to do with those images.

  • FaceApp’s developer, Wireless Lab, is based in Saint Petersburg, Russia, and was founded by Yaroslav Goncharov.
  • The app’s terms of service grant Wireless Lab an irrevocable, perpetual, royalty-free, sub-licensable license to use, reproduce, modify and publicly display uploaded photos and likenesses, without paying users.
  • Wireless Lab says it does not sell or share user data with third parties, does not transfer data to Russia, deletes most uploaded photos within 48 hours, and allows users to request deletion of their data.

Drivers of Viral App Growth

FaceApp isn’t new — it first surfaced back in 2017 — but its aging filter caught fire again this July as celebrities began posting side-by-side “young self, old self” images. The Jonas Brothers, Kevin Hart and Carrie Underwood posting theirs gave the trend the celebrity push it needed to jump from app-store novelty to a genuine cultural moment, pulling in tens of millions of users who wanted the same rendered-gray-hair, wrinkled-skin version of themselves showing up in their feed.

The Terms of Service Problem

The backlash wasn’t really about the aging filter — it was about the fine print. Security analysts flagged that FaceApp’s terms of service hand Wireless Lab a broad, sub-licensable license to use, reproduce and publicly display any photo a user submits, indefinitely, without compensation. That’s a standard clause in a lot of photo and social apps, but paired with a facial-recognition product and an unfamiliar Russian developer, it read very differently to privacy watchdogs than it might have coming from a Silicon Valley name.

Author and cybersecurity commentator David Fergusson summed up the core concern that kept circulating through tech and security circles that week.

“We just don’t know enough about this organization.”

That opacity — a company with limited public track record, operating out of Saint Petersburg, holding broad rights to facial images — was enough to put privacy advocates on alert even before anyone could point to an actual data breach.

Separating Fact From Rumor

One claim spread faster than any actual FaceApp policy: that the app was secretly uploading a user’s entire camera roll to Russian servers the moment it was installed. Security researchers who examined the app’s traffic pushed back on that specific fear, clarifying that FaceApp only uploads the photo a user actively selects, sending it to cloud servers run by Amazon Web Services and Google Cloud — not shadowy Russian infrastructure — for the AI processing.

Wireless Lab issued its own statement addressing the panic directly, denying that it sells or shares user data with third parties or routes data to Russia. The company said most uploaded photos are deleted from its servers within 48 hours and that users can request full erasure of their data. Whether that satisfied skeptics was another matter — the license grant in the terms of service was still real, and facial-recognition training concerns didn’t disappear just because the camera-roll rumor turned out to be overstated.

Key Factors Influencing User Decisions

Strip away the panic and the actual tradeoff was fairly plain: a fun, shareable photo filter in exchange for handing a foreign-based company broad, long-term rights to your face. That’s not radically different from risks people already accept with other viral apps and social platforms — a topic that’s tripped up plenty of public figures before, as seen in actors who’ve ruined their careers on social media and even reporters who’ve done the same. The difference with FaceApp was the biometric layer — a face isn’t a password you can reset — which is why privacy advocates kept urging users to read the license before tapping “allow.”

By the time the Jonas Brothers’ aged-up selfies had racked up millions of likes, the app had already made its point twice over: it’s genuinely fun, and it’s genuinely worth reading what you agreed to before you uploaded your face to it. Wireless Lab’s 48-hour deletion promise and its denial of a Russia data pipeline calmed some nerves, but the underlying license — perpetual, royalty-free, sub-licensable — was still sitting in the terms of service exactly as written, for anyone who bothered to scroll down and check.

8.5 Total Score

User Rating: 4.25 (20 votes)
Advanced Search Options
Searching the network...
InfoSearched Entertainment — The filter, not the firehose.
Logo