I used Face App on one picture. What did I give away?
What they're not telling you: The Portrait You Uploaded: What FaceApp's Permission Requests Actually Access FaceApp's standard iOS permission architecture grants the application access to photo library metadata including EXIF coordinates, device identifiers, and contact relationships β data the user interface does not clearly distinguish from the image file itself. The question posed on r/privacy reflects a widespread gap between what users believe they're authorizing and what mobile operating systems actually permit. When FaceApp requests "photo library access," Apple's iOS framework doesn't isolate individual images.
What the Documents Show
The permission grants read access to the entire library structure, including timestamps, geolocation tags embedded in photos, and thumbnail caches. A user believing they've shown the app a single photograph has actually granted it access to metadata patterns across potentially thousands of images. The second permission request the user references β likely "camera" or "microphone" access β operates on similar terms. iOS presents these as binary allowances with granular timing options ("only when app is in use" versus "always"), but this distinction masks a deeper technical reality. When restricted to "app in use," the permission still permits continuous access during any session where FaceApp runs, including background processes.
Follow the Money
The app receives full sensor data during operation; the restriction only prevents background collection. This means location services, accelerometer data, and network identifiers remain available throughout active use sessions. FaceApp, developed by Wireless Lab (registered in Saint Petersburg, Russia), operates servers that receive uploaded images. The company's privacy policy states that photos are deleted after processing, but this claim exists entirely outside any enforceable audit framework. No third-party technical verification of server-side deletion occurs. Users grant permission; images transfer; deletion status becomes a matter of corporate assertion rather than verifiable fact.
What Else We Know
The infrastructure performing this image processing exists on cloud servers operated by Amazon Web Services and Google Cloud Platform. Both companies maintain standard data retention policies independent of FaceApp's contractual obligations. AWS retains VPC flow logs for fifteen minutes by default; Google Cloud Platform stores load balancer logs for thirty days. The image file itself may be deleted from FaceApp's direct storage while existing in backup systems, access logs, or machine learning training datasets operated by the cloud infrastructure providers. A user's single photograph enters a chain of custody spanning multiple corporations across multiple jurisdictions, none of which the user explicitly authorized. The permission interface itself β Apple's iOS framework β determines what choices appear available to the user.
Primary Sources
- Source: r/privacy
- Category: Tech & Privacy
- Cross-reference independently β don't take our word for it.
Disclosure: NewsAnarchist aggregates from public records, API feeds (Federal Register, CourtListener, MuckRock, Hacker News), and independent media. AI-assisted synthesis. Always verify primary sources linked above.