Connect with us

NEWS

The NameTag Suit Reopens Meta’s Deleted Face File

Parents sued Meta on September 4, 2026, claiming Facebook and Instagram photos fed NameTag and image models after the 2021 faceprint purge.

Published

on

Parents in Illinois and California sued Meta on September 4, 2026, over Facebook and Instagram photos used for NameTag and image models. The Chicago filing says the company pulled biometric data from those pictures without the written notice Illinois law requires. The proposed class starts on September 4, 2021, and the complaint puts the national group in the millions.

Meta already paid to close an older face-tagging fight, then said it would wipe the templates. The new complaint treats those same social photos as the raw stock for glasses matching and for generative image systems that still run.

Parents in Illinois and California Take Meta to Chicago

Wexler Boley & Elgersma LLP filed the 66-page case, Alvarez et al. v. Meta Platforms, Inc., as case 1:26-cv-10773 in the U.S. District Court for the Northern District of Illinois, Eastern Division. The named plaintiffs are Francisco Alvarez and his minor child, both Illinois residents, and Jeremy Wahl, a California resident, and his 10-year-old daughter.

The complaint alleges Meta used images of users and of people who never held an account to train and test NameTag, to build facial templates for that system, and to develop Emu and Muse Image. It says those steps produced numerical face embeddings, vectors, or templates that encode the spatial layout of a face. California claims sit beside the Illinois counts and include the common-law right of publicity, Civil Code § 3344(a), and the state constitution’s privacy clause.

People shouldn’t have to worry if their biometric information will be misused simply because their photographs appear on a social media platform.

Justin N. Boley, partner, Wexler Boley & Elgersma

Boley also called the suit a fight over Meta turning personal information into product fuel. The filing asks the court to certify classes, halt the practices, and award money. None of the proposed classes has been certified.

The Billion Faceprints Meta Said It Deleted

On November 2, 2021, Jerome Pesenti, then Meta’s vice president of artificial intelligence, said the company would shut down Facebook’s face-recognition system and delete more than a billion templates. He wrote that helpful uses had to be weighed against growing concern, and that limiting face recognition to a narrow set of uses was the right call while rules were still unclear.

That post closed Tag Suggestions, the old tool that scanned faces in photos and proposed names. It did not say the underlying photos would stop being training material, and it did not bar a later product from encoding faces again. In 2020, Meta had already agreed to pay $650 million to settle an Illinois class action over that earlier system.

THE FACEPRINT CALENDAR

  1. 2011: Tag Suggestions rolls out and, Texas later said, runs facial recognition on faces in uploaded photos without the consent state law required.
  2. 2020: Meta agrees to pay $650 million to settle the Illinois biometric case over the same family of features.
  3. November 2, 2021: Pesenti’s post says Facebook will shut the system down and delete more than a billion facial recognition templates.
  4. July 30, 2024: Texas announces Meta will pay $1.4 billion over five years to resolve a state biometric suit over Tag Suggestions.
  5. June 4, 2026: A code review finds NameTag, still switched off, inside the Meta AI companion app for Ray-Ban and Oakley glasses.
  6. June 5, 2026: A new app build strips the NameTag code.
  7. September 4, 2026: Alvarez is filed in Chicago, with a class period that begins September 4, 2021.

The class window opens two months before the 2021 shutdown post and runs through the present, so it covers both the tail of the old system and everything built after the templates were supposed to be gone. Texas Attorney General Ken Paxton said Meta would pay Texas $1.4 billion over five years, which he described as the largest sum a single state had ever taken from one case. Together with the Illinois check, those two resolutions total $2.05 billion.

NameTag Code Reached 50 Million Phones

NameTag was built for Meta’s Ray-Ban and Oakley glasses and for the Meta AI companion app that those glasses need. A June 4, 2026 review of that app, which had been downloaded more than 50 million times, found face-matching code that was not turned on for users. The design converted a face seen by the glasses into a biometric signature, compared it with faceprints stored on the phone, and was set up so that on-device store could take updates from Meta.

NAMETAG ON THE PHONE

  • Three models: Code review found an on-device stack that detects a face, crops it, and encodes it as biometric data.
  • Misses stored: Faces the system did not recognize were cropped, indexed, and kept locally for later processing.
  • Server pull: The matching database was written to retrieve faceprints from Meta’s servers and hold them on the user’s device.
  • Then gone: Meta removed the code the day after the review became public, on June 5, 2026.

Before that report, Andy Stone, Meta’s vice president of communications, said the feature did not exist, a line that could not be squared with functional code sitting in a shipping app. After the story, Stone called the work purely exploratory. Chief technology officer Andrew Bosworth called the reporting incredibly misleading and absolutely dishonest. Weeks later he described NameTag as a way for glasses to recognize people a wearer had already met and had asked the device to remember, and said he thought it would be a great feature.

The complaint goes further than “code was present.” It alleges Meta took Facebook and Instagram photographs, extracted numerical representations of the faces in them, and built identifiers that NameTag could use to name people in the street. A Meta patent application published in May, titled “User Identity Verification without Sharing Biometric Data With Platforms,” describes glasses that capture a face, build an embedding, and match it against biometric representations drawn from profile photos, tagged photos, videos, or other images the platform already holds. A patent is not proof the shipping stack worked that way. It is the workflow the plaintiffs say NameTag was built to run.

Meta has said it is not building a central face database. The June review found a system designed to pull faceprints from Meta servers onto phones, which is a different architecture than one giant public gallery and still a networked store of face math. The company also argues that because users never saw a NameTag toggle, the feature never existed as a product. The complaint answers that the work of building templates and training models is the violation, whether or not a consumer setting ever flipped on.

Did Training Emu Count as a Face Scan?

Illinois law carves photographs out of the definition of a biometric identifier and still treats a scan of face geometry as one. That split is the hinge of the generative-AI counts. The plaintiffs say training Emu and Muse Image on pictures of faces caused the models to store identity-related facial traits in parameters, latent representations, or other math, and that those stored traits are biometric information even when no glasses are involved.

Meta’s own Emu paper says the team pre-trained a latent diffusion model on 1.1 billion image-text pairs, then quality-tuned it on a few thousand hand-picked stills. The paper does not say those 1.1 billion pairs were Facebook files. Chief product officer Chris Cox, speaking in 2024, said the company trains on public Facebook and Instagram images and text and does not train on private posts or on things people share only with friends. He called that public pile a data advantage and said Instagram is full of art, fashion, culture, and images of people, which is why the image model looks as good as it does.

The complaint takes Cox at his word and then adds a legal step he did not take. If public photos of faces were training fuel, and if the training run encoded those faces in a form that can distinguish or recreate someone, the plaintiffs say that encoding is a BIPA collection. They make the same claim about prompts: when a user feeds Meta AI a photo that contains a face, the system creates an embedding to edit or copy that person, and that embedding is another capture. Muse Image, released in summer 2026, briefly let people generate pictures from other people’s public Instagram accounts. Meta pulled that feature within days and said it had missed the mark.

That theory would still matter if NameTag stayed on the shelf. A court that treats model training as a face scan would be talking about the photo archive as a biometric source, not about one unreleased glasses toy. It is also untested. Photographs themselves are excluded. Whether a diffusion model’s weights are “information based on” a scan of face geometry is the question the complaint asks a Chicago judge to take seriously, and it is not a finding.

Kids, Bystanders, and a Class Dating to 2021

Wahl’s daughter is 10. Alvarez’s child is a minor. Their photos, if they lived on Facebook or Instagram, were put there by adults, and both children are now named plaintiffs. The proposed national class covers people in the United States whose images were uploaded to Facebook or Instagram, or submitted to Meta’s generative AI systems through prompts, from September 4, 2021, through the present. Illinois and California classes cover residents of those states on the same terms.

The complaint’s non-user theory is the piece that reaches past account holders. A face in a friend’s wedding album, a bystander in a street photo, a child in a parent’s grid: the plaintiffs say Meta can extract the same numerical face from those files and that the person depicted never clicked a box. They argue the models may hold biometric information on people who do not have a Meta account and do not know they were in the set.

That is a hard class to close, and it is also the reason the 2021 deletion does not end the story. Templates tied to opted-in users can be marked for deletion. A training corpus built from public pictures, including pictures of kids and of strangers, does not vanish when a settings page changes. Wahl’s daughter is on the caption in Chicago while Meta also defends a multi-state case over children and the ad business that runs on the same apps.

Illinois Capped Repeat Hits at One Recovery

For the Illinois counts, the complaint cites BIPA Section 15(a) for the lack of a public retention and destruction policy and Section 15(b) for collecting biometric data without written notice of purpose and duration and without a written release. Statutory damages are $5,000 for each intentional or reckless violation, or actual damages if greater, and $1,000 for each negligent violation, or actual damages if greater, plus an injunction. The statute also tells a company that holds biometric data to destroy it when the original purpose is done, or within 3 years of the person’s last interaction, whichever comes first.

META’S BIOMETRIC PAYOUTS

Year Matter What changed
2020 Illinois class action over face tagging $650 million settlement
2021 Facebook face-recognition shutdown More than 1 billion templates slated for deletion
2024 Texas CUBI case over Tag Suggestions $1.4 billion to the state over five years
2026 Alvarez complaint, BIPA statutory ask $1,000 or $5,000 per person per violation, plus an injunction

The money column is smaller than it would have been before August 2, 2024. That day Illinois Governor J.B. Pritzker signed SB 2979, which says that collecting the same biometric identifier from the same person by the same method is one violation, with at most one recovery. On April 1, 2026, the Seventh Circuit held in Clay v. Union Pacific Railroad Co. that the change is retroactive because it alters the remedy, not the duty. A class of millions is still a large statutory stack. It is no longer a per-photo multiplier.

WHAT BIPA REQUIRED BEFORE A SCAN

  • Written notice: Tell the person, in writing, that a biometric identifier is being collected or stored.
  • Purpose and time: Say in writing why it is being collected and how long it will be kept and used.
  • Written release: Get a signed release from the person or from someone legally allowed to sign for them.
  • Public policy: Publish a retention schedule and destroy the data when the original purpose is done, or within 3 years of last contact.

The plaintiffs say Meta skipped those steps. Meta says it has been open about how it uses people’s information to build AI products. Those two sentences are the case in miniature, and a judge, not a product blog, will have to pick.

Meta Says Nothing Has Shipped

A Meta spokesperson, answering the suit on September 11, 2026, called the filing empty and said it misstates the company’s work.

This lawsuit is without merit and misrepresents our work. We’ve been transparent about how we use people’s information to build and improve our AI products. As for NameTags, nothing has shipped to consumers and no final decision has been made on what to do here, if anything.

Meta spokesperson, statement, September 11, 2026

The same statement said that if Meta does roll something out, it will do so with full transparency, and that one decision is already firm: the company is not building a universal face database. Ryan Daniels, a Meta spokesperson, had used the same “nothing has shipped” line after the June code review, along with the claim that Meta was not building a central face database. The complaint concedes that Meta has not disclosed which images, if any, were used to generate biometric data, and says that information remains in the company’s possession.

Bosworth still described NameTag as a feature he liked. The 2021 post still sits on Meta’s newsroom. In between those two facts, matching code reached an app on more than 50 million phones, Emu was trained at the scale Meta’s own paper describes, and parents in two states asked a Chicago court to treat the photo archive as a biometric store again. The classes are not certified. Meta has not yet filed a substantive answer in the case.

Disclaimer: This article is news reporting and analysis of a pending civil complaint and related public statements. It is for information only and is not legal advice, not a view on the merits of Alvarez et al. v. Meta Platforms, Inc., and not a prediction of any court’s ruling, any settlement, or any person’s right to join a class. Readers who think their photos or their children’s photos may be at issue should consult a licensed attorney in the relevant state before taking any legal step, including opting in or out of a class. Figures, case status, product details, and Meta’s public positions reflect the filings and statements cited here as of the dates on those documents and can change as the docket moves.

Harry is the editor of Oton Technology, an independent site he owns and edits, covering the part of technology that people actually have to act on. After ten years in journalism, first reporting and then editing, he works from primary material by habit: the advisory rather than the write up of it, the filing rather than the press release, the changelog rather than the launch video. Every figure in an article carries its source and its date, and where a number comes from a vendor or an analyst model rather than a count, he says so plainly instead of letting it stand as established fact. What he leaves out is anything he could not verify himself, which on a beat full of unnamed supply chain claims removes a great deal. That standard applies across all the sections the site publishes for an international audience, from artificial intelligence and security to phones, computers, gaming, crypto and the software businesses depend on. He corrects errors in the open and labels them, because a site that hides its mistakes is asking readers to trust the rest on nothing.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending