Opinion
For a few years, Privacy.com was one of the easiest recommendations I could make. If you've ever tried to cancel a gym membership, a streaming service, or some "free trial" that quietly turns into a monthly charge, you know the game. The company makes signing up take thirty seconds and makes leaving take a phone call, a retention pitch, and a small piece of your soul.
Privacy.com fixed that. You made a virtual card for each merchant. If a company wouldn't let you cancel, you killed the card and walked away. If a free trial was about to convert, you paused the card the day before. You could set a limit, say $15 a month for a streaming service, and if they decided to raise the price without asking, the charge just bounced and you found out about it on your terms instead of theirs.
It was a simple idea that gave regular people a little leverage over companies that have spent years designing their billing to be a trap. That's why so many people recommended it, including a lot of us who never got a cent for doing so.
That's also why what's happening now stings.
The pause
Longtime users have been logging in to find their accounts paused. No warning, no email beforehand. Just a pop-up saying that before you can keep using the service, you need to verify your identity through a third party called Persona.
Persona is an identity verification company. Selfie, photo ID, the whole thing. And the consent screen is where it gets ugly. You're asked to agree that Persona can collect and process your biometric data and keep it for up to three years. Buried in the terms is the part that should make anyone pause: that data can be used to improve Persona's own platform.
A service called Privacy is asking you to hand your face to another company so that company can improve its product with it.
I understand that some verification is part of running a financial service. I'm not naive about that. But "we need to confirm you're a real person" and "we need your face, and our vendor gets to use it for their own benefit" are two very different things. The first is compliance. The second is a business model, and it's not yours.
What Privacy.com says
After the backlash, Privacy.com's team posted a response on Reddit. Here it is in full, so you can read it for yourself:
Privacy team here. We understand the concern and appreciate the community holding us to a high standard.
Understandably, our name, “Privacy,” sets an expectation around how we handle your personal information. But because we’re a regulated financial service, we’re required to verify the identity of every person who opens an account. This helps us meet our regulatory requirements and protect our customers and ourselves from fraud and identity theft. That’s been the case since we started Privacy.
Persona is one of the tools we use to fulfill that obligation. We only request biometric verification (a selfie and photo ID) from around 6% of signups, and in an extremely limited number of cases, we may also request it from existing customers who trigger a flag for additional verification. As part of our legal and compliance obligations, we’re required to conduct ongoing checks on accounts, which can sometimes require us to re-verify a customer’s identity.
We hear these concerns, and they’re helpful as we think about where we can do better.
The short version: because they're a regulated financial service, they're required to verify the identity of everyone who opens an account, and they say that's been true since day one. Persona is one of the tools they use to meet that obligation. They say they only ask for a selfie and photo ID from around 6% of new signups, and that in "an extremely limited number of cases" existing customers may be asked to re-verify if their account gets flagged during ongoing compliance checks.
It's a reasonable-sounding statement. It also doesn't touch the actual complaint. Nobody is arguing that a card issuer shouldn't know who its customers are. The problem is the retention period, the third party, and the clause that lets that third party use your biometrics to improve its own service. The statement explains why verification exists. It doesn't explain why it has to look like this.
And "an extremely limited number of cases" is cold comfort when you're the one staring at a paused account, needing to shut off a card so some company can't keep billing you.
It didn't used to be like this
Scroll through the privacy forums and you'll find people who've used the service for three or four years without ever being asked for anything like this. One user figured it was because they'd linked a checking account as their funding source. Another commenter pointed out the more likely answer: the ID requirements got a lot stricter around two years ago. If you signed up early, you slipped through. If you sign up today, or get flagged tomorrow, you won't.
That same longtime user made a point I think is honest and worth repeating. They said Privacy.com protects your identity and card number from the merchants you buy from, but it doesn't protect your data from Privacy.com itself. You're giving a lot of information to one company instead of a little to many. For them, that trade was worth it.
That's a fair position. But the trade has changed. It's no longer "a lot of info to one company." It's a lot of info to one company, plus your face to a second company that gets to keep it and use it.
About Persona
Persona isn't some small, obscure vendor. It's a major player in identity verification, with investment from Peter Thiel's Founders Fund, and it sits behind a lot of the "verify your identity" screens you see across the internet. That scale is exactly why its security record matters. Earlier this year, researchers reported finding an exposed development configuration on a public server connected to Persona's systems, reportedly touching sensitive databases. Whatever the full story turns out to be, the lesson is the same one we keep relearning: the more places your biometrics live, the more places they can leak from.
You can change a password. You can cancel a card. You can't get a new face.
On recommending things
A lot of people found Privacy.com because someone they trusted recommended it. A YouTuber, a blogger, a friend in a Discord. Some of those recommendations were paid. Plenty weren't.
If you've ever recommended a product to an audience, paid or not, I think you owe them a follow-up when that product changes. Too many creators take the sponsorship money, read the ad, and then go completely quiet when the service starts treating customers badly. The audience trusted the recommendation, not the company. When the company changes, the recommendation should too.
So here's mine. The Privacy.com I used to point people toward isn't the one that exists today. I'm not recommending it anymore.
This keeps happening
None of this is unique. It's the same arc we see over and over. A product launches, it's genuinely good, people love it, it grows, and then slowly the priorities shift from the user to everyone else: investors, partners, vendors, regulators, whoever. The laptop line you swore by starts overheating playing a video. The app that was clean fills up with dark patterns. The service built around privacy starts collecting biometrics.
You can't stop companies from changing. What you can do is refuse the trade when it stops being fair.
So here's the one piece of advice I'd leave you with. Any time a company asks to scan your face, your ID, or anything else about you, and the fine print says it'll be used to "improve" someone else's product, say no. Close the tab. Find another way. Your data should be something you give for a reason, not something you pay just to keep using a service you already signed up for.
Lyle Heartman