Your Selfie Isn't a Photo Anymore — It's a Math File That Never Forgets Your Face
Here's something that will probably bother you more the longer you think about it: when you upload your face to try on glasses online, the app doesn't actually keep your photo. It does something weirder — and, legally speaking, far more significant. It measures you. The distance between your eyes. The angle of your jawline. The precise geometry of your nose. Then it throws those measurements into an equation, spits out a string of numbers, and that's what it keeps. Not a picture. A mathematical blueprint of your face.
A selfie is an image your eye can recognize. A biometric template is a hidden math file that can identify you forever — and the law treats them completely differently.
Most people don't know that step exists. And a recent ruling from the Seventh Circuit Court of Appeals — one of the most influential federal appeals courts in the U.S. — just made it very clear that courts are paying close attention to it. The case involved a company called Gunnar Optiks and its virtual try-on feature. The question wasn't really about glasses. It was about whether that invisible conversion step — selfie to math file — creates the kind of data that biometric privacy law was written to protect.
Spoiler: it does. And once you understand how that conversion happens, you'll never look at a "try before you buy" feature the same way again.
What Actually Happens Between Upload and Preview
Picture this. You're on an eyewear website at 9pm. You click "try on frames." The app asks you to take a selfie or upload a photo. You do. Seconds later, you see yourself wearing the glasses. Looks kind of good, honestly. You close the tab and move on.
Here's what happened in those few seconds that you didn't see. This article is part of a series — start with Your Face Was Scanned Saturday Nobody Asked If That Was Lega.
The moment your face appeared on the app's server, software began scanning it for landmarks — specific, measurable points on your face. According to ExploreAnthro, facial recognition systems measure things like the distance between your eyes, the upper outlines of your eye sockets, the sides of your mouth, the location of your nose, and the prominence of your cheekbones. These aren't vague impressions — they're specific numerical measurements, taken from specific points on your face.
Then comes the part that matters. Those measurements don't get stored as a snapshot. They get compressed — run through a mathematical process that converts the geometry of your face into a compact string of numbers. Facia.ai describes this as "a mathematical representation of the user's face allowing for later identification without storing the original images." The photo is gone. What remains is a file that encodes the unique shape of you.
That file is called a biometric template (a reusable mathematical model of your face's geometry — think of it as your face, expressed as a formula rather than a photograph).
The Recipe vs. The Painting
Here's the analogy that makes this click instantly.
Think of your selfie as a painting of your face — a complete image that anyone can look at, copy, or recognize. A biometric template is more like a recipe for your face: "two tablespoons of interocular distance (space between the eyes), one cup of jawline curvature, a precise dash of nose-bridge width." The recipe doesn't look like you. But it describes you so accurately that software can use it to find you in a database — or verify that you're you — without ever needing the painting again.
A painting can be deleted. A recipe can be copied, shared, sold, or matched against other recipes indefinitely. That's the difference. And that's exactly why the law draws a hard line between the two. Previously in this series: That Quick Selfie To Verify Could Be Handing Scammers Your F.
Under Illinois' BIPA — the Biometric Information Privacy Act, which is the toughest biometric privacy law in the U.S. right now — a "biometric identifier" is defined as a scan of face geometry. Not a photo of a face. A scan of its geometry. The word "photographs" is explicitly excluded from BIPA's coverage. But the moment software extracts that mathematical map? The full weight of the law lands. Companies must disclose what they're collecting, why, and how long they'll keep it. They must get written consent. They cannot sell it.
"The instant software extracts a face-geometry template and matches it against a gallery, it has created a biometric identifier, and the full weight of the law lands." — Analysis of the Seventh Circuit ruling, as reported by DiCello Levitt
Where the Court Case Comes In
So what was Gunnar Optiks actually arguing? That their virtual try-on tool might qualify for a healthcare exemption under BIPA. Illinois law carves out an exception for data collected in a healthcare context — patient records, medical imaging, that kind of thing. Gunnar sells prescription eyewear alongside regular frames. Their argument was essentially: collecting facial geometry to help fit prescription lenses is medically adjacent, so maybe the healthcare exemption applies.
The Seventh Circuit was not convinced. As DiCello Levitt reported, the court observed that the try-on service was "aesthetic, not medical" — and that "better-appearing glasses are not medical treatment." The class action was revived. The case moves forward.
But here's what's more interesting than the legal outcome: the ruling confirms that intent doesn't change the technology. Gunnar wasn't being malicious. They probably genuinely believed they were just helping people pick frames. The software didn't care about their intent. It extracted geometry anyway. And that extraction — not the company's purpose, not the website's design, not whether someone bought prescription or non-prescription lenses — is what triggered the law.
That's the part worth sitting with. A company can mean well and still create regulated biometric data without realizing it.
Why People Get This Wrong (And It's Not Their Fault)
Almost everyone assumes that "using your face" in an app means the app is storing a picture of you — maybe in some folder on a server, maybe getting sold to advertisers, maybe being reviewed by a real human somewhere. That's the mental model most of us carry around. And honestly, it makes sense. That's how cameras have always worked. You take a picture. Someone has a picture. Up next: Monroe County Biometric Disclosure Retail Facial Recognition.
But modern facial processing doesn't work that way. As Fora Soft explains, the regulated act under BIPA isn't recording video or capturing an image — it's building a faceprint from that image. The photo is often discarded almost immediately. What remains is the template: a file that doesn't look like a face, doesn't contain pixels, but can still uniquely identify you across any database it's ever matched against.
Here's why that's actually more dangerous, not less. A photo of your face can be cropped, filtered, or simply not matched if lighting is different. A biometric template is built to be resilient. It's designed to find you even when conditions change — different lighting, different angle, five years older. The recipe works even when the painting looks different.
This is exactly where CaraComp focuses — understanding the gap between what facial technology appears to do (show you a preview) and what it's actually doing underneath (building a persistent identity file). That gap is where most people's intuition breaks down, and where the real privacy questions live.
What You Just Learned
- 🧠 A biometric template is not a photo — it's a mathematical file of facial measurements, and it can identify you without ever storing your image
- 🔬 The law triggers at the extraction step — under BIPA, the regulated moment is when software converts your face geometry into a template, not when a photo is taken
- ⚖️ Intent doesn't change the data — a company helping you pick glasses creates the same regulated data as a company doing something more serious with your face
- 💡 The right question to ask any app — not "can it see me?" but "is it turning my face into a file it can keep, compare, or share later?"
When an app uses your face, the safety question isn't "can it see me?" — it's "is it turning my face into a measurement file it can store, compare, or reuse?" A photo of you is data. A biometric template of you is an identity key. Those are not the same thing, and the law is finally starting to treat them differently.
So next time an app says "use your face to find your fit" — for glasses, makeup, hair color, anything — the question to ask yourself is simple: does this app tell me whether it's storing a template, or just a photo? Most don't say. Most people don't think to ask. But knowing the difference between a painting and a recipe? That's the thing that makes you harder to fool.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Education
"Better-Appearing Glasses Are Not Medical Treatment": The 4 Words That Just Changed Your Face-Scan Rights
A federal court just ruled that scanning your face to try on glasses virtually isn't a healthcare activity — and that distinction matters for your privacy rights. Here's what the Gunnar Optiks ruling actually teaches us about when biometric privacy laws apply.
biometricsYour Selfie Isn't What's Protecting You: The 4 Hidden Checks Running Behind Every ID Scan
Most people think a selfie is how apps verify your identity. It's actually just one of four checks running in the background — and the others are far more interesting. Here's what's really going on.
digital-forensicsThat Urgent Video From Your Boss? Watch How the Face Moves — Not How It Looks
A deepfake can look totally convincing frame by frame. But researchers found that how a face moves is much harder to fake than how it looks — and the detection accuracy is over 95%. Here's exactly how that works.
