Clearview AI Face Recognition
Clearview AI · Face Recognition
✓ Reviewed
Index
Clearview AI is not a device you buy — it is a search engine built out of your face. The company runs automated crawlers that, in the UK Upper Tribunal's words, "scrape" the public-facing internet, assign each face a "facial vector," and store the result in a searchable database the Tribunal described in October 2025 as holding "tens of billions of such mapped images." Police, immigration and national-security agencies then upload a photo of an unknown person and get back other pictures of that person from across the web. Nobody in the database consented, was notified, or can realistically avoid it: if a friend posted a photo of you, you are in it. This is the defining feature of the system — it is involuntary mass surveillance of the general public, and Canada's federal and three provincial privacy commissioners said so in as many words, concluding that "What Clearview does is mass surveillance and it is illegal." Regulators in Canada, Australia and Greece found the practice unlawful and ordered deletion; the UK ICO fined the company £7,552,800 and ordered UK data deleted. Clearview disagreed with the Canadian findings and "did not demonstrate a willingness to follow" the recommendations, and EFF's Atlas of Surveillance still records a US state agency buying the product in FY2023. A US court settlement with the ACLU permanently barred it from making the faceprint database available to most businesses and private entities, and its own public privacy policy concedes it keeps data "as long as the company has a need for its use," enumerates deletion rights only for residents of fourteen named US states, and admits its disclosure of scraped photos "may be deemed a 'sale'" under California law. Meanwhile it keeps expanding — in 2025 court records showed it had tried to buy 690 million arrest records and 390 million arrest photos, including Social Security numbers, to bolt onto the face database.
Why this rating
POLICY 8 = -20 sensitive-collection (the public policy states "it collects photos that are publicly available on the internet" and lists as sensitive personal information "Face vectors and photos, and such metadata as image files may contain" and "Government-Issued Identification, such as driver's license, state identification card or passport" — biometric identifiers built from people who never transacted with Clearview) -15 no-opt-out (deletion/opt-out rights are enumerated only for residents of fourteen named US states — California, Colorado, Connecticut, Delaware, Illinois, Iowa, Kentucky, Minnesota, Montana, Nebraska, Nevada, New Hampshire, Utah and Virginia; the tens of billions of other scraped subjects worldwide are given no stated route) -15 indefinite-retention ("Clearview AI shall retain data as long as the company has a need for its use, or to meet legal, regulatory or contractual requirements" — no period is defined anywhere in the public policy; the adjacent promise that PII "shall be deleted or de-identified as soon as it no longer has a business use" is self-judged and sets no clock) -12 sells-data (the policy's own concession that "Clearview's disclosure of photos collected from the Internet may be deemed a 'sale' under the CPRA", notwithstanding the adjacent claim that "Clearview does not sell your personal information, as that term is traditionally understood") -12 law-enforcement-loose (the database is disclosed to users "who are all either law enforcement, government agency, national security professionals, or a contractor authorized to work on behalf of and fulfill a duty on behalf of the foregoing entities", and disclosure is further permitted "to enforce the terms of any agreement, or for any other purpose that is required or permitted by law") -10 policy-vagueness (the operative policy at clearview.ai/privacy-policy is login-gated — that page states only "To view our Privacy Policy, please click the link below and sign in to the Clearview AI platform to access it" — so the binding terms are not publicly readable, and the public-facing substitute sets no retention period) -8 unilateral-change ("We may modify this Policy at any time at our sole discretion... Any changes to this Policy will become effective when we post the revised Policy on our website"). Not applied: broker-disclosure — the public policy names advertising and analytics partners (Microsoft Advertising/Bing, LinkedIn) only in the targeting-cookies section covering clearview.ai website visitors, not the scraped face corpus, and no clause was found permitting onward sale of the face database to data brokers; the 2025 arrest-record purchase attempt was Clearview buying data in, not selling out, so it is scored on the evidence axis instead. EVIDENCE 6 = -25 regulatory-action, unlawful-mass-surveillance (Canada's OPC and the Quebec, BC and Alberta commissioners, 3 Feb 2021, found collection of "more than 3 billion images, including of Canadians and children" without knowledge or consent and stated "What Clearview does is mass surveillance and it is illegal"; they called on the company to stop offering the service in Canada, cease collection, and "delete all previously collected images and biometric facial arrays of individuals in Canada") -20 regulatory-action, multi-jurisdiction (UK ICO monetary penalty of £7,552,800 announced 23 May 2022 plus an enforcement notice to "stop obtaining and using the personal data of UK residents that is publicly available on the internet" and delete it — the First-tier Tribunal allowed Clearview's appeal on jurisdiction, but the Upper Tribunal held on 6 Oct 2025 in ICO v Clearview AI [2025] UKUT 319 (AAC) that the FTT "erred materially in law" and remitted the substantive appeal on the basis that the Commissioner had jurisdiction, so the notices are not extinguished but remain undecided; Hellenic DPA Decision 35/2022, 13 July 2022, EUR 20,000,000 for breaches of GDPR Arts 5(1)(a), 5(2), 6, 9, 12, 14, 15 and 27 with deletion and processing-ban orders; OAIC determination, 3 Nov 2021, breaches of the Australian Privacy Principles) -15 non-compliance (the Canadian authorities recorded that "Clearview disagreed with the findings of the investigation and did not demonstrate a willingness to follow the other recommendations", and EFF's Atlas of Surveillance records the Alaska Department of Public Safety spending $110,000 on Clearview in FY2023 — the company kept selling to US government agencies after deletion orders landed on three continents) -12 covert-collection-proven (Commissioner Falk found "The indiscriminate scraping of people's facial images" and held that "The covert collection of this kind of sensitive information is unreasonably intrusive and unfair", with practices that "fall well short of Australians' expectations for the protection of their personal information") -12 court-ordered-restriction (ACLU v. Clearview AI settlement and consent decree, May 2022: Clearview is "permanently banned, nationwide, from making its faceprint database available to most businesses and other private entities", must "cease selling access to its database to any entity in Illinois, including state and local police, for five years", must keep attempting to filter Illinois-origin photographs for five years, must "end its practice of offering free trial accounts to individual police officers, without the knowledge or approval of their employers", and must run an Illinois-resident opt-out form backed by a $50,000 advertising commitment — restrictions a court considered necessary against a database the plaintiffs described as "more than 10 billion faceprints") -10 expansion-attempt (404 Media, 19 Mar 2025, from arbitration and court records: Clearview "spent nearly a million dollars in a bid to purchase '690 million arrest records and 390 million arrest photos'" from all 50 states, including "current and former home addresses, dates of birth, arrest photos, social security and cell phone numbers, and email addresses"; the deal collapsed in a contract dispute rather than on privacy grounds, and an arbitrator ruled in Clearview's favour in 2024). Not applied: security-research/cve — no verified breach or vulnerability disclosure was located in this pass, so none is scored. DEPLOYMENT COUNT, DELIBERATELY NOT ASSERTED: the only deployment figure this record can support is the single Atlas of Surveillance entry cited above (Alaska DPS, $110,000, FY2023). Contemporaneous reporting on the leaked client list describes a far larger footprint, but no such source was loaded in either the research or the verification pass, so no aggregate deployment count is stated. Similarly, reported actions by the French CNIL, the Italian Garante and the Dutch AP were removed from this record because no page substantiating them could be loaded (cnil.fr returned 'This page is no longer available', the CNIL sanctions index does not list Clearview, and the Dutch authority's site returned HTTP 403); their absence is a limit of this pass, not a finding that they did not happen. SENSORS: has_camera=1 — the agency app's workflow is to capture or upload a probe photograph of an unknown person, and the system's inputs are photographic; has_microphone=0 and has_gps=0 — no loaded source documents audio capture or a device GPS sensor. Caveat carried honestly rather than scored: the public policy states Clearview collects "such metadata as image files may contain", which can include embedded geotags, but that is image metadata, not device geolocation, so no has_gps flag and no separate deduction. requires_account=1 and works_offline=0 describe the agency-facing product: it is a cloud search against a centrally hosted database, and even the privacy policy itself sits behind an app.clearview.ai login.
What it is
- Camera
- Requires a cloud account
- Manufacturer
- Clearview AI
- Category
- Face Recognition
- Model years
- 2020-present
- Market status
- Current
- Companion app
- Clearview AI platform (agency-only web/mobile app, login-gated at app.clearview.ai)
The evidence 10
Independent research, regulatory action, lawsuits, breaches and journalism about this device — the "what actually happens" axis. Each links to its source.
-
The Upper Tribunal "allowed the appeal, set aside the decision of the First-tier Tribunal, and remitted the matter to the First-tier Tribunal to decide the substantive appeal on the basis that the Information Commissioner had jurisdiction to issue the notices", holding that the FTT "erred materially in law in finding that the Respondent's processing was outside the material scope of the GDPRs by operation of Article 2(2)(a)". The judgment records that Clearview uses "crawlers" to "scrape" the public-facing internet, that images are "assigned facial vectors, and stored in a searchable database" comprising "tens of billions of such mapped images", and that the business consists of "selling access to its database to public and private sector clients operating in the fields of national security or criminal law enforcement". The page refers to "an enforcement notice and a monetary penalty notice" without stating the amount (see the ICO citation below).
Why it matters here: Primary judicial record. Establishes the database's scale and business model in a court's own words, and confirms the UK notices are not extinguished — the substantive appeal is still to be decided.
-
A joint investigation by Canada's federal and three provincial privacy authorities concluded Clearview AI violated federal and provincial privacy law by collecting "more than 3 billion images, including of Canadians and children" from the internet without consent. Commissioner Daniel Therrien stated plainly: "What Clearview does is mass surveillance and it is illegal." The authorities called on Clearview to stop offering the service to Canadian clients, cease collecting images of people in Canada, and "delete all previously collected images and biometric facial arrays of individuals in Canada". The release records that "Clearview disagreed with the findings of the investigation and did not demonstrate a willingness to follow the other recommendations".
Why it matters here: The clearest regulatory statement anywhere that this is involuntary mass surveillance, from four independent authorities acting jointly — and documented refusal to comply, which is what separates an evidence-axis finding from a paper violation.
-
Commissioner Angelene Falk determined that Clearview AI breached the Australian Privacy Act by collecting Australians' sensitive information without consent, collecting personal information by unfair means, failing to notify individuals of collection, failing to take reasonable steps to ensure disclosed information was accurate, and failing to implement compliant practices and systems. The determination describes "the indiscriminate scraping of people's facial images" from a database of "more than three billion images", and finds that "the covert collection of this kind of sensitive information is unreasonably intrusive and unfair", with practices that "fall well short of Australians' expectations for the protection of their personal information". Clearview was ordered to "cease collecting facial images and biometric templates from individuals in Australia, and to destroy existing images and templates collected from Australia".
Why it matters here: Supplies the covert-collection and unfair-means findings on the record, and the regulator's own framing that people captured had no expectation of it — the core of the involuntary-capture case.
-
The Hellenic DPA fined Clearview AI EUR 20,000,000 in Decision 35/2022 for violating GDPR Articles 5(1)(a) and 5(2) (lawfulness, transparency and accountability), 6 and 9 (lawful basis and special-category biometric data), and 12, 14, 15 and 27 (transparency, data subject access rights and the EU-representative duty). It ordered Clearview to satisfy the complainant's access request, prohibited any further collection or processing of Greek residents' personal data by facial recognition means, and issued "an order to delete the personal data of those subjects located in Greece, which the defendant collects and processes using those methods". The case began as a complaint "lodged by the civil nonprofit organization 'Homo Digitalis' on behalf of a complainant" and expanded into a review of the company's wider practices.
Why it matters here: A second EU regulator reaching the maximum-tier penalty, and specifically finding breaches of Article 9 on biometric special-category data plus failures on access rights and the Article 27 EU-representative duty — evidence that even the narrow rights Clearview's policy gestures at are not honoured in practice.
-
The ICO announced a monetary penalty of £7,552,800 against Clearview AI Inc for using images of UK residents collected from websites and social media to build a global facial recognition database, together with an enforcement notice requiring the company to "stop obtaining and using the personal data of UK residents that is publicly available on the internet" and to delete UK residents' data from its systems. Note: ico.org.uk returns HTTP 403 to automated retrieval; this is the ICO's own newsroom distribution page carrying the same release.
Why it matters here: The only loadable source for the exact £7,552,800 figure quoted in the rationale. The Upper Tribunal judgment above references the notices but does not state the amount, so this citation is what makes the penalty figure checkable by a reader.
-
Settlement and consent decree in ACLU v. Clearview AI, brought under the Illinois Biometric Information Privacy Act. Clearview is "permanently banned, nationwide, from making its faceprint database available to most businesses and other private entities"; must "cease selling access to its database to any entity in Illinois, including state and local police, for five years"; must, "over the next five years... continue its current measures to attempt to filter out photographs that were taken in or uploaded from Illinois"; must "end its practice of offering free trial accounts to individual police officers, without the knowledge or approval of their employers"; and must maintain an opt-out request form "allowing Illinois residents to upload a photo and fill out a form to ensure their faceprints will be blocked from appearing in Clearview's search results", backed by a commitment of "$50,000 to pay for internet ads publicizing the opt-out mechanism". The filing describes "more than 10 billion faceprints from peoples' online photos across the globe", with a projected 100 billion being enough to ensure "almost everyone in the world will be identifiable". The page itself carries no publication date; 9 May 2022 is the widely reported announcement date, with the consent order signed 11 May 2022.
Why it matters here: A binding court-enforced restriction rather than a fine, showing a US court accepted that unrestricted access to this database was itself the harm. Also documents that the opt-out route exists only because litigation forced it, and only for one state.
-
Reporting from court records filed in a contract arbitration, 404 Media documented that Clearview AI "spent nearly a million dollars in a bid to purchase '690 million arrest records and 390 million arrest photos'" from the intelligence firm Investigative Consultant, Inc., spanning all 50 states — records that would have included "current and former home addresses, dates of birth, arrest photos, social security and cell phone numbers, and email addresses". The deal collapsed over disputes about the data's usefulness; an arbitrator ruled in Clearview's favour in 2024 and ordered the money returned, ICI has not paid, and Clearview has sought court enforcement. The article also notes Clearview deposited the funds directly into a personal checking account rather than using escrow.
Why it matters here: Shows the trajectory is expansion, not retrenchment: a company under deletion orders on three continents was simultaneously trying to fuse identity-grade records including SSNs onto its face database. The attempt failed for commercial reasons, not privacy ones.
-
Clearview's publicly readable policy states "it collects photos that are publicly available on the internet" plus information derived from them, and lists as sensitive personal information "Face vectors and photos, and such metadata as image files may contain", "Government-Issued Identification, such as driver's license, state identification card or passport", and account login information. Retention is open-ended: "Clearview AI shall retain data as long as the company has a need for its use, or to meet legal, regulatory or contractual requirements", alongside a self-judged promise that PII "shall be deleted or de-identified as soon as it no longer has a business use". The images are disclosed to users "who are all either law enforcement, government agency, national security professionals, or a contractor authorized to work on behalf of and fulfill a duty on behalf of the foregoing entities", plus disclosure "to enforce the terms of any agreement, or for any other purpose that is required or permitted by law". It asserts "Clearview does not sell your personal information, as that term is traditionally understood" while conceding that "Clearview's disclosure of photos collected from the Internet may be deemed a 'sale' under the CPRA". Deletion and opt-out rights are enumerated for residents of fourteen named US states: California, Colorado, Connecticut, Delaware, Illinois, Iowa, Kentucky, Minnesota, Montana, Nebraska, Nevada, New Hampshire, Utah and Virginia. Changes are unilateral: "We may modify this Policy at any time at our sole discretion... Any changes to this Policy will become effective when we post the revised Policy on our website." Advertising and analytics partners (Microsoft Advertising/Bing, LinkedIn) are named only in the targeting-cookies section covering website visitors, not the scraped photo corpus.
Why it matters here: The sole source for every POLICY-axis deduction, all seven of which were re-verified verbatim against the live page.
-
The page at Clearview's canonical privacy-policy URL does not display a policy. It states in full: "To view our Privacy Policy, please click the link below and sign in to the Clearview AI platform to access it", with an "ACCESS PRIVACY POLICY" link that requires authentication to app.clearview.ai.
Why it matters here: Substantiates the policy-vagueness deduction structurally rather than by interpretation: the operative policy governing a database built from tens of billions of non-customers is readable only by the paying agency customers, not by the people in it.
-
EFF's crowd-sourced Atlas of Surveillance returns one Clearview AI deployment record: "The Alaska Department of Public Safety spent $110,000 on Clearview AI face recognition technology in FY 2023." The Atlas is a partial, volunteer-compiled census and is not a complete list of Clearview's government customers.
Why it matters here: The only loadable evidence in this pass that Clearview continued selling to US government agencies after the 2021 Canadian and Australian deletion orders and the 2022 UK, Greek and Illinois actions. Cited to support the non-compliance deduction; deliberately not used to assert an aggregate deployment count.
Descriptive, cited, not legal advice; ratings are versioned and corrections create a new version. Data from the IoT Info Grabber DB research project, CC BY-SA 4.0.