> ## Content Index
> Fetch the complete content index at: https://www.thedelatorrereview.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# In the Matter of Everalbum, Inc.
- URL: https://www.thedelatorrereview.com/in-the-matter-of-everalbum-inc/
- Published: 2021-01-11T15:08:00.000Z
- Updated: 2026-08-15T15:26:00.000Z
- Description: A practical analysis of the FTC's first facial recognition enforcement action, explaining how deceptive privacy practices, unauthorized use of biometric data to train AI models, and false deletion promises led to a landmark order requiring the destruction of affected algorithms.
- Author: Lydia
- Tags: FTC, Regulatory Enforcement, Biometric Data, Facial Recognition, AI Governance, Section 5, Consent, Data Retention

## Introduction

Artificial intelligence systems are only as trustworthy as the data used to train them. As organizations increasingly rely on biometric information—including facial recognition—to develop and improve AI models, regulators have made clear that deceptive data collection practices can taint not only the data itself, but also the technologies built upon it.

The FTC's enforcement action against Everalbum, Inc. represents a significant milestone in U.S. privacy enforcement. The case centered on a consumer photo storage application that allegedly misrepresented how it used facial recognition technology and what happened to users' photos after they deactivated their accounts. More significantly, the FTC alleged that the company used consumers' photographs to develop proprietary facial recognition technology without obtaining the level of user consent it claimed to require.

The resulting consent order did more than require changes to the company's privacy practices. It also required Everalbum to delete facial embeddings and destroy AI models and algorithms that had been developed using biometric information collected from users without the required affirmative express consent.

# Background

Since 2015, Everalbum operated Ever, a cloud-based photo storage and organization application available on mobile devices, desktops, and the web. The application allowed users to upload photographs and videos from multiple sources, including mobile devices and social media accounts, and automatically organized them into albums.

In February 2017, Everalbum introduced a facial recognition feature called Friends, which grouped photographs based on the people appearing in them. Users could assign names or aliases to recognized faces to organize their photo collections.

According to the FTC, when the feature launched, facial recognition was enabled by default for all users of the Ever mobile application, and many users were not given an option to disable it. Starting in May 2018, Everalbum rolled out a process through which Ever presented Ever mobile app users located introduced opt-in prompts and settings allowing users in Texas, Illinois, Washington, or the European Union —and later all users—to choose whether facial recognition should be enabled. Approximately one quarter of users presented with the opt-in prompt chose not to enable facial recognition. 

# Enforcement analysis

The Everalbum matter illustrates that privacy enforcement may extend beyond the improper collection or retention of personal information. Where biometric information is used to train artificial intelligence systems, **regulators may require organizations not only to delete improperly collected data, but also to destroy the AI models and algorithms derived from that data.**

The case also reinforces two longstanding FTC principles. First, organizations must accurately describe how privacy features operate; users cannot meaningfully exercise choice if the company's representations are inconsistent with its actual practices. Second, representations regarding deletion and retention of personal information must accurately reflect operational reality. If a company promises deletion upon account deactivation, it must implement processes that fulfill that promise.

Finally, the consent order demonstrates the FTC's willingness to **treat biometric information as particularly sensitive** and to require affirmative express consent before it is used to create facial embeddings or develop facial recognition technologies. 

# The FTC's Complaint

The FTC alleged that Everalbum engaged in deceptive practices in violation of Section 5 of the FTC Act through two principal categories of misrepresentations.

## Count I: Misrepresentation Regarding Users' Ability to Control the Face Recognition Feature

The FTC alleged that Everalbum represented that facial recognition would be used only when users enabled or turned on the feature. For example, the company's website explained that when face recognition was enabled, users were "letting us know" that the company could create facial embeddings from the people appearing in their photographs.

According to the FTC, this representation was false or misleading because, until April 2019, facial recognition was enabled by default for users located outside Texas, Illinois, Washington, and the European Union. Those users could not disable the feature and therefore never affirmatively chose to activate it. Nevertheless, Everalbum applied facial recognition technology to their uploaded photographs.

The Complaint further alleges that Everalbum's use of facial recognition extended beyond organizing photographs within the Ever application. After initially relying on publicly available facial recognition technology, the company began developing its own proprietary models by extracting millions of facial images from users' photographs and combining them with publicly available datasets to train and improve its technology. The resulting technology was later used both within the Ever application and in the company's enterprise facial recognition business, Paravision. Although the FTC did not allege that users' photographs were shared with enterprise customers, it alleged that users' biometric information was used to develop the underlying facial recognition technology. These factual allegations explain why the alleged deception regarding users' ability to control facial recognition was significant. 

## Count II: Misrepresentation Regarding Deletion of Users' Photos Upon Account Deactivation

The FTC also alleged that Everalbum misrepresented what would happen when users deactivated their accounts.

According to the Complaint, Everalbum informed users that deactivating an account would permanently delete their photographs and videos. Similar representations appeared in customer support communications, which stated that deactivation would permanently delete all content stored in the user's account.

The FTC alleged that these statements were false because, until at least October 2019, Everalbum did not delete photographs or videos associated with deactivated accounts. Instead, it retained that information indefinitely before later implementing a practice of deleting data associated with accounts that had been deactivated for more than three months. As a result, the FTC alleged that Everalbum's representations regarding account deletion were deceptive in violation of Section 5 of the FTC Act. 

# Resolution

Without admitting or denying the FTC's allegations, Everalbum entered into a consent order resolving the matter. The order imposed both forward-looking privacy obligations and extensive remediation requirements. 

## Prohibition against future misrepresentations

The order prohibits Everalbum from misrepresenting:

- how it collects, uses, retains, deletes, or discloses covered information;
- consumers' ability to control their information;
- how long personal information is retained after account deletion;
- who may access covered information; and
- its privacy and security practices generally.

## Notice and affirmative express consent

Before using biometric information to create facial embeddings or to train, develop, or modify facial recognition models or algorithms, Everalbum must:

- provide a clear and conspicuous disclosure describing every intended use of the biometric information; and
- obtain the user's affirmative express consent.

The required disclosure must be separate from the company's privacy policy or terms of use. 

## Mandatory deletion of data and AI models

Perhaps the most significant aspect of the order was its remediation requirement.

The FTC required Everalbum to:

- delete photographs and videos belonging to users who had deactivated their accounts;
- delete facial embeddings created from users who had not affirmatively consented to facial recognition; and
- delete or destroy any models or algorithms developed, in whole or in part, using biometric information collected from Ever users.

The order also required the company to certify under penalty of perjury that these deletions had been completed. 

## Compliance and oversight

The consent order further required ongoing compliance reporting, recordkeeping, acknowledgments by relevant personnel, and FTC monitoring for an extended period. The order remains in effect for up to twenty years, subject to the terms specified in the order. 

## Conclusion

For organizations developing AI systems, the case underscores a broader compliance lesson: **lawful collection and transparent disclosures are not simply prerequisites for using personal information—they may determine whether the resulting AI systems can continue to exist at all.**

The FTC's action against Everalbum stands as an early and influential enforcement action addressing the intersection of privacy, biometric information, and artificial intelligence. Rather than limiting relief to deletion of improperly retained data, the Commission required destruction of facial recognition models and algorithms developed using biometric information obtained without the required consent.Conclusion

## Resources

[Everalbum, Inc: In first facial recognition misuse settlement, FTC requires destruction of algorithms trained on deceptively obtained photos](https://jolt.law.harvard.edu/digest/everalbum-inc-in-first-facial-recognition-misuse-settlement-ftc-requires-destruction-of-algorithms-trained-on-deceptively-obtained-photos?ref=thedelatorrereview.com) / By Zachary Sorenson — Edited by Anastasia Pyrinis / January 13, 2021 / Harvard Law

*In the Matter of Everalbum, Inc*., File No. 1923172 (FTC Jan. 11, 2021) - [FTC’s complaint](https://www.ftc.gov/system/files/documents/cases/everalbum%5Fcomplaint.pdf?ref=thedelatorrereview.com).

*In the Matter of Everalbum, Inc*., File No. 1923172 (FTC Jan. 11, 2021) - [FTC's Proposed settlement](https://www.ftc.gov/system/files/documents/cases/everalbum%5Forder.pdf?ref=thedelatorrereview.com) 

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/08/Screenshot-2026-07-04-at-4.45.19---PM.png)