(also posted in r/cybersecurity_help)
So I was dumb enough at 13 to upload my face and ID to Roblox back in 2023 for that voice chat thing...
And now I'm seeing how unsafe that was and not to mention Persona
I'm genuinely worried for my privacy and stuff I don't know what's real or misinfo... Do they actually del
What the Documents Show
This anxiety is not paranoia; it reflects a documented reality the mainstream tech press largely normalizes. Roblox uses Persona, a third-party identity verification service, to process these submissions. The architecture here matters: the user's biometric data doesn't stay with Roblox alone—it flows to an external vendor with its own data retention policies, access logs, and potential vulnerabilities. Mainstream coverage of age-gating typically frames it as a privacy *protection*, focusing on preventing child access to age-inappropriate content. This narrative obscures the actual trade-off: platforms aren't reducing data collection; they're *expanding* it by requiring biometric verification that creates permanent records.
Follow the Money
The user's core question—do they actually delete this data?—goes unanswered in most corporate privacy policies, which use deliberately vague language about "retention periods" and "legitimate business purposes." The broader surveillance infrastructure here operates without warrant requirements because it's *consensual*—users (or parents) agree to terms of service. No court order needed. No legal burden of proof. For minors, this consent is often illusory; a 13-year-old wanting to use voice chat with friends faces a binary choice: upload biometric data or lose access. That's not genuine consent; it's coercion dressed in platform policy. Once collected, facial recognition data becomes a permanent asset.
What Else We Know
Unlike passwords or credit cards, you cannot change your face. If Persona's systems are breached—or if the company is acquired, pivots its business model, or faces pressure from law enforcement—that biometric template follows the user indefinitely. The mainstream tech narrative also underplays data-sharing agreements between vendors. Persona doesn't exist in isolation. Identity verification companies have history of selling or licensing aggregated datasets to data brokers, law enforcement, or other corporate clients. A minor's biometric profile collected for age-verification could theoretically be matched against other databases, creating a surveillance foundation laid in childhood and extending into adulthood.
Primary Sources
- Source: r/privacy
- Category: Surveillance State
- Cross-reference independently — don't take our word for it.
Disclosure: NewsAnarchist aggregates from public records, API feeds (Federal Register, CourtListener, MuckRock, Hacker News), and independent media. AI-assisted synthesis. Always verify primary sources linked above.
This article is produced by NewsAnarchist's AI reporting system, not a human staff reporter. It's built from the primary source cited above (a FOIA release, an agency's own policy or procurement document, court filings from surveillance litigation, or the wire reporting linked in the body) and reports what that source states, attributed to it — it does not allege intent behind a surveillance program beyond what the record shows. Part of our Surveillance State hub. Found an error? Tell us.
