CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
privacy

Your Kid's ID Photo Just Became Someone Else's Database

Your Kid's ID Photo Just Became Someone Else's Database

Tens of thousands of Discord users found out the hard way that an app asking for your ID isn't necessarily the same as an app protecting your ID. When Discord rolled out age verification through a third-party vendor, that vendor got breached — and government ID images spilled out into the open. Real documents. Real faces. Real families. The verification worked perfectly, right up until it didn't.

TL;DR

The Supreme Court just allowed Texas to force apps to verify kids' ages and get parental consent — which sounds great until you realize "age verification" and "identity data collection" are often the same thing, and the companies handling that data aren't always careful with it.

Now the Supreme Court has handed down a ruling that will bring that same setup to apps across the country. The court allowed Texas to enforce its App Store Accountability Act, which requires app stores to verify whether a buyer is a minor and get parental consent before letting kids download certain apps. About half the states already have similar rules in place. The legal dominos are falling, and fast.

Here's what nobody in the headlines is saying clearly enough: this is not just a kids' safety story. It's a story about where your family's most sensitive information ends up — and who's watching it.


What the Law Actually Does

The Texas law puts the responsibility on app stores — think the place where you download apps on your phone — to check ages before a purchase or download goes through for a minor. If your kid wants a new app, the store has to verify how old they are. And if they're under 18, a parent has to say yes first.

That sounds reasonable. It probably is reasonable, in principle. Children can access almost anything online without their parents ever knowing, and that's a documented problem. Regulators and child safety advocates have been pushing for exactly this kind of guardrail for years. The FTC has made clear it wants strict limits on how any data collected through these checks can actually be used, according to CNBC.

The problem isn't the goal. The problem is the method — and who gets hired to carry it out. This article is part of a series — start with Face Detection Before Identification How Facial Analysis Act.

~50%
of U.S. states already have age-verification requirements similar to Texas's new law
Source: SCOTUSblog / Al Jazeera reporting on the Texas App Store Accountability Act

The Part That Should Make You Pause

When a platform faces a new legal obligation — especially one with real consequences if they get it wrong — they don't build a solution from scratch. They outsource it. Fast. They call a vendor who promises quick compliance, signs the paperwork, and gets the check.

That vendor then has your family's identity information. Maybe a government ID photo. Maybe a facial scan (that's a digital map of someone's face used to confirm identity). Maybe your child's date of birth tied to their name and your account. And here's the structural problem nobody's fixing: Texas requires platforms to delete age-related data once verification is complete, according to Al Jazeera's coverage of the ruling. Sounds good. Except enforcement becomes nearly impossible once a third-party vendor is holding data across multiple clients in their own systems. The law says delete it. The vendor's business model says keep it — that data is useful across contracts.

The Discord breach wasn't a fluke. It was a preview.

"By 2026, age verification is likely to be a default requirement across much of the consumer internet, with the central question no longer whether verification will exist, but how it will be implemented, and at what cost to privacy and access." TechTimes, on the future of age verification infrastructure

Read that again. Not whether. How. And at what cost.


Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

Why This Matters to Your Family Right Now

The Supreme Court ruling doesn't tell platforms how to verify ages. It just says they have to. That gap — between legal obligation and actual method — is where your family's data disappears into a pipeline you'll never see.

Why This Matters

  • Verification means collection — Every age check is a moment where identity data gets gathered. Who stores it, for how long, and under what rules varies widely by vendor.
  • 📊 Third-party vendors multiply the risk — When platforms outsource verification, your data moves to a company you've never heard of, operating under contracts you can't read, with security standards you can't audit.
  • 🔮 Half the country is about to follow Texas — This ruling gives legal cover to roughly 25 other states already drafting or enforcing similar laws, meaning the verification moment is coming to nearly every app download near you.
  • 🛡️ Better tech exists — but it's not the easy choice — Privacy-preserving methods that check age without storing identity are real and tested. Platforms just won't use them unless they're forced to, because the cheap route is faster.

Think about the moment you're going to face. Your kid wants to download something. A prompt pops up asking for age verification. Maybe it wants a government ID scan. Maybe it wants a selfie. You have about 30 seconds before your child is annoyed and you're tired and you just click through. That 30-second window is what this entire system is built around. Previously in this series: Your Banks Back Door Is A Selfie And A Sticky Note.

Nobody is betting you'll read the fine print.

There IS a Better Way — It's Just Not the Profitable Way

Here's something the debate often skips: you don't actually need to collect identity information to verify someone's age. Smart engineers figured this out. There are systems that look at a face — or an ID — make a determination (old enough? yes or no) and then immediately discard everything. No stored photo. No database entry. Just the answer. According to the IEEE Standards Association, technical standards like IEEE 2089.1™ exist specifically to support age verification systems that preserve privacy while still being trustworthy — systems built around telling you the outcome without holding onto the inputs.

That's not magic. That's just good design. The problem is good design takes longer to build and costs more upfront. Platforms facing a compliance deadline will choose the vendor who can go live in two weeks, not the one who builds it right.

So the question isn't whether age verification is a reasonable idea. Of course keeping a 10-year-old off adult content is reasonable. The question is: does verifying age require building a giant database of your family's biometric data (your face, your fingerprints, the physical markers that are uniquely you)? The answer is no. But that's what most platforms will do anyway, because nobody's requiring otherwise.

That's the gap the Supreme Court just left wide open.


What You Can Actually Do

You're not helpless here, even if it feels that way. Before you hand over any identity document in a verification flow, ask one question: what happens to this data after the check is done? Look for a privacy policy that specifically says the verification data is deleted immediately after use — not "after a reasonable period," not "in accordance with applicable law," but actually deleted. If you can't find that language in under two minutes, treat it as a red flag. Up next: Before Facial Recognition Names You It Has To Find You And T.

If an app verification flow asks for a full government ID when a birth year would do — that's a signal the system was designed for data collection, not age checking. There's a meaningful difference between "tell us your birthdate" and "upload a photo of your driver's license." One answers the question. The other builds a file.

The CaraComp case study on the Discord vendor breach is worth a few minutes of your time — it walks through exactly how a seemingly routine identity check became an exposure event, and what the warning signs looked like in advance. If you've ever wondered whether a face scan or an ID photo is truly private once it leaves your hands, that's the exact question this kind of technology exists to answer. Knowing what a system does with your data before you submit it isn't paranoia. It's the only real protection you have right now.

Key Takeaway

Age checks are becoming identity checks — and the Supreme Court ruling that was supposed to protect your kids may end up creating the largest collection of family identity data the internet has ever seen, stored in the hands of vendors you'll never know exist. The law says verify ages. It doesn't say do it safely. That part is up to you to demand.

Texas law technically requires that age-related personal data be deleted once verification is complete. It also technically makes that nearly impossible to enforce across a web of third-party vendors operating in different states under different contracts. That gap isn't an accident. It's an opportunity — just not yours.

So the next time an app asks your kid to prove how old they are, the real question isn't whether your child is old enough to use the app. It's whether you trust the company doing the checking enough to hand them a document you can never take back.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search