PRIVACY
It’s pitched as an easier way back into your account when you’re locked out. Before you record your face for Google (or whether you should), three questions are worth asking: where does the video live, how is it protected, and what else might Google do with it?
On 23 July 2026, Google introduced selfie video sign-in, a new way to recover a Google Account. Instead of a password or a code, you record a short video of your face, and Google checks it against a selfie you enrolled earlier to let you back in.
It also fits a pattern worth noticing. First Google began testing a reCAPTCHA that asks you to wave your hand at the camera; now it wants a short video of your face to sign you in. Each step asks for a little more of your biometric data to prove you’re human.
It’s easy to see the appeal. Passwords get forgotten and phones get lost. But this replaces a thing you know for a copy of your face sitting on Google’s servers, and a face is not a password you can change if it ever leaks. So the details of where it goes, and who gets to use it, matter more than usual.
Join the MEGA privacy revolution. Create a free MEGA account and get 20 GB of storage with zero-knowledge encryption.
In this blog #
What Google actually launched #
Setup asks you to look into your camera and complete a few guided head movements, capturing your face from several angles. If you later get locked out, whether from a forgotten password, a lost or stolen phone, or a sign-in on a borrowed device, you record a fresh selfie and Google compares it to the enrolled one to confirm it’s really you.
To stop people fooling it with a photo or a deepfake, Google matches the live video against your saved selfie, asks you to perform simple movements to prove you’re a real, live person, and runs its usual checks for suspicious sign-ins. As a security upgrade over a recycled password, it looks like a genuine step forward. The privacy questions sit underneath it.
Where your face is stored #
This isn’t stored only on your phone. For recovery to work when your device is lost or you’re on someone else’s, the enrolled selfie has to live on Google’s side, associated with your Google Account.
The (almost) reassuring part is that Google says the selfie is recorded and stored only with your consent, and that you can delete it at any time from your account settings. So you’re not locked into keeping it. But while it’s enrolled, a biometric record of your face is being held by Google, not by you.
How it’s stored #
Google says the selfie video is encrypted at rest, meaning it’s protected while it’s sitting in storage and not in use. That’s good practice, and it guards against the file being lifted straight out of a database.
It’s worth being clear about what “encrypted at rest” does and doesn’t mean, because the phrase does a lot of quiet reassuring. Yes, it protects the stored file from outside theft. But, it does not mean Google can’t see your face. Google holds the keys and has to be able to process your selfie to match it during recovery, so this is company-managed encryption, not end-to-end or zero-knowledge encryption where the provider has no access to your content at all. Your face is protected from others. It isn’t hidden from Google.
Will Google use it for anything else? #
This is the question worth slowing down on, and the honest answer is: by default, no, but there’s a door.
Google says the selfie is used solely for sign-in unless you choose to share it for other purposes. The catch is in that second clause. During or after setup, you can opt in to let Google use the video and related data to improve its facial recognition, age estimation, and other identity-verification technologies. In plain terms, there’s a setting that turns your recovery selfie into training data for Google’s biometric models.
It’s opt-in, not automatic, and that’s to Google’s credit. But two things are true at once. A default-off toggle still normalises the idea of handing your face to a company to train its systems. And “used solely for sign-in” is a policy and a settings state, both of which can be changed, misread, or quietly re-defaulted in a future update. The protection holds as long as you decline the option and Google keeps the arrangement it describes today.
So, are we sure Google won’t use your face for its own purposes? You can be reasonably sure it won’t if you don’t opt in. You cannot be sure the option to will always stay off by default, or that the boundary won’t move.
So, should you record a video selfie for Google? #
For a lot of people, selfie recovery will be safer than the password sticky-note or the recycled login it replaces, and that’s a real benefit. This isn’t a scandal, per se. It’s a trade, and it’s worth making with your eyes open. There’s also a way to need recovery far less often. Most lockouts come down to a forgotten password or the same one reused everywhere. A password manager removes that weak point: if every login is unique and stored somewhere you can actually get to it, the moment you’d reach for a face scan rarely arrives. MEGA Pass creates and stores a unique password for every account, with built-in two-factor authentication, so getting locked out becomes the rare exception rather than a routine event.
Read more
Is Google Password Manager safe? The risks, and a better alternative.The benefits of a password managerWhat is credential stuffing, how it works and how MEGA prevents it
If you do enrol, the practical moves are simple: the classic think before you click, make sure you‘re not opting in to anything, check that setting again after major account updates, and remember you can delete the enrolled selfie whenever you like. And weigh, as you would with any biometric feature, whether the convenience is worth handing a copy of your face to a company at all. In this case, the company is Google, the biggest out there known to monetise user data. It’s also a reminder that “encrypted” isn’t one thing. Encryption that a company can reverse protects you from outsiders but not from the company. Encryption where the provider holds no keys protects you from both. That’s the standard MEGA is built on for your files in MEGA Cloud, and it’s a useful yardstick to hold up against any service asking to store something as permanent as your face.
Try zero-knowledge encryption for yourself. Create a free MEGA account and get 20 GB of storage with zero-knowledge encryption.
Frequently asked questions #
Where does Google store my selfie video?
On Google’s servers, linked to your Google Account, so it can be used for recovery even if your device is lost. Google says it’s stored only with your consent and can be deleted at any time from your account settings.
Is the selfie video encrypted?
Google says it’s encrypted at rest, which protects the stored file from theft. It is not end-to-end or zero-knowledge encryption, so Google can still access and process your face to perform the sign-in match.
Will Google use my face to train its AI?
Not by default. Google says the selfie is used only for sign-in unless you opt in to let it improve facial recognition, age estimation, and other identity-verification technology. That option is a choice you can decline.
Can I delete my enrolled selfie?
Yes. Google says you can remove it at any time from your Google Account settings.
Is selfie sign-in safer than a password?
For account recovery, it can be, because it’s harder to phish or guess than a password and includes liveness checks against deepfakes. The trade-off is that it stores a biometric record of your face, which, unlike a password, you can’t change if it’s ever exposed.