Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsChecklistsAI RankingsNewsletterStatusTagsAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Checklists
AI Rankings
Newsletter
Status
Tags
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

429+ Articles
114+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Persona Source Code Leak Exposes Hidden Biometric
Persona Source Code Leak Exposes Hidden Biometric
NEWS

Persona Source Code Leak Exposes Hidden Biometric

A 53MB source code leak from identity verification giant Persona reveals how routine age verification selfies feed into a surveillance system linking...

Dylan H.

News Desk

February 20, 2026
5 min read

Your Selfie Is Going Places You Didn't Expect

A 53MB source code leak from Persona, the identity verification platform used by OpenAI, Reddit, Roblox, Discord, and Character.AI for age checks, has exposed what researchers describe as a hidden surveillance infrastructure that transforms routine verification selfies into entries in a biometric database linked to financial records and law enforcement systems.

The leak occurred due to a misconfigured Vite build tooling that left Persona's original frontend source code publicly accessible. Researchers who analyzed the code found capabilities and data flows that go far beyond what users are told when they snap a verification selfie.


What the Code Reveals

FindingDetailImpact
Watchlist databaseRoutine ID checks feed into a dedicated "watchlist" system operational since 2023Users flagged without knowledge or consent
Biometric-to-financial linkingFacial biometrics are processed through a system connecting to financial records and law enforcement databasesSelfies become surveillance tools
3-year data retentionSelfies and biometric data stored for up to 3 yearsContradicts shorter retention claims by some clients
Government agency sharingData shared with US and Canadian federal agenciesAge verification becomes a government data pipeline
Cross-platform linkingVerification data can be correlated across client platformsSingle selfie creates a multi-platform identity profile

How It Works

What Users Think Happens

1. App asks you to verify your age
2. You take a selfie and upload your ID
3. Persona confirms you're 18+
4. Your data is deleted after verification

What Actually Happens (According to Leaked Code)

1. App asks you to verify your age
2. You take a selfie and upload your ID
3. Persona extracts facial biometrics and creates a biometric template
4. Template enters a "watchlist" database operational since 2023
5. Biometrics are cross-referenced with financial records
6. Data is accessible to law enforcement databases
7. Selfie and biometric data retained for up to 3 years
8. Data shared with US and Canadian federal agencies

Platforms Using Persona

PlatformUse CaseEstimated Users Affected
OpenAIAge verification for ChatGPTTens of millions
RedditAge verification for NSFW contentMillions
RobloxAge verification for voice chatMillions of minors
DiscordUK age verification (pilot)Millions
Character.AIAge verificationMillions

The Retention Discrepancy

A key finding is a mismatch between stated and actual data retention:

  • OpenAI's stated policy: One-year biometric retention
  • Persona's code: Three-year retention cap found in source
  • Gap: Two years of additional biometric storage beyond what users were told

This discrepancy raises serious questions about whether platforms using Persona are accurately representing their data practices to users.


Privacy and Legal Implications

Biometric Privacy Laws

Several jurisdictions have strict biometric privacy regulations:

  • Illinois BIPA — Requires explicit consent before collecting biometric data, with statutory damages of $1,000-$5,000 per violation
  • EU GDPR — Classifies biometric data as "special category" requiring explicit consent and purpose limitation
  • California CCPA/CPRA — Grants consumers rights to know, delete, and opt out of biometric data processing
  • Canada PIPEDA — Requires meaningful consent for collection of sensitive biometric information

If the leaked code accurately represents Persona's operations, the company and its clients could face significant regulatory exposure across multiple jurisdictions.

Consent Problems

Users consenting to "age verification" are not consenting to:

  • Long-term biometric storage
  • Cross-referencing with financial databases
  • Law enforcement data sharing
  • Multi-platform identity correlation

Persona's Response

Persona's CEO has engaged with researchers and the security community about the findings. The company has not issued a formal public statement addressing all allegations as of publication.


Industry Reaction

"If age verification selfies are ending up in a three-year biometric watchlist linked to law enforcement databases, that fundamentally changes the privacy calculus for every user who's been asked to 'just take a quick selfie' to prove their age." — Privacy researcher

"The real question is whether the platforms using Persona — OpenAI, Reddit, Discord — knew the full extent of what was happening with user biometric data, or whether Persona was operating these capabilities without full client transparency." — Digital rights advocate


Key Takeaways

  1. Age verification selfies feed into a biometric surveillance system operational since 2023
  2. Data retained for up to 3 years — potentially exceeding what platforms tell users
  3. Biometrics linked to financial records and law enforcement — far beyond age verification
  4. Major platforms affected — OpenAI, Reddit, Roblox, Discord, Character.AI
  5. Significant legal exposure — Potential violations of BIPA, GDPR, CCPA, and PIPEDA

Sources

  • Cybernews — Persona Leak Links Age Verification and Federal Surveillance
  • Security Boulevard — Age Verification Vendor Persona Left Frontend Exposed
  • PiunikaWeb — Persona Age Verification Under Fire After Researchers Expose Alleged Biometrics Surveillance
#Privacy#Biometrics#Surveillance#Persona#Age Verification#OpenAI#Reddit

Related Articles

OpenAI Says ChatGPT Ads Are Not Rolling Out Globally For Now

OpenAI confirmed that ChatGPT ads remain a U.S.-only pilot for Free and Go plan users, despite a global privacy policy update that alarmed international...

6 min read

Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More

This week's cybersecurity roundup covers supply chain attacks hitting CI/CD pipelines, long-running IoT botnets finally disrupted, the FBI's warrantless...

4 min read

Cegedim Santé Breach Exposes 15.8 Million French Healthcare Records Including HIV Status

A cyberattack on French healthcare software vendor Cegedim Santé exposed 15.8 million patient records from 3,800 doctors, with leaked data including...

4 min read
Back to all News