The MAC Lawsuit and What It Means for Your Privacy When Using AI Beauty Tools

Virtual try-on tools have become a routine feature on beauty brand websites and apps. You point your phone camera at your face, and the software shows you how a lipstick shade or foundation might look. It’s convenient, especially when you can’t test products in person. But a recent lawsuit against MAC Cosmetics has raised questions about what happens to that facial data after you tap “try on.”

The lawsuit, filed in Illinois, alleges that MAC’s virtual try-on tool collected and stored customers’ biometric data without properly informing them or obtaining their consent, as required by the state’s Biometric Information Privacy Act (BIPA). MAC is owned by The Estée Lauder Companies. The case is still ongoing, and MAC has not yet issued a public response to the specific allegations. However, the situation is a reminder that even well‑known brands can fall short on privacy protections.

What happened

According to the complaint, when users activated the AI‑powered try‑on feature, the software captured detailed measurements of their facial features — what’s known as a “facial geometry scan.” This type of biometric data is considered sensitive in several states because it is unique to each person and cannot be changed like a password. The lawsuit claims that MAC did not provide a clear notice about how this data would be used, stored, or shared, nor did it obtain a written release as BIPA requires.

MAC is not the first beauty brand to face this kind of legal action. Similar lawsuits have been filed against other companies that offered virtual try‑on tools, including some owned by L’Oréal and Ulta Beauty. The outcomes of those cases vary, but they point to a broader pattern: many consumers are unaware that the “fun” feature on a shopping app may trigger privacy laws designed for fingerprints and retina scans.

Why it matters to everyday consumers

The risks go beyond a lawsuit. When a beauty app collects your facial data, that information may be stored on company servers, sold to third parties, or used to train AI models — often without your explicit knowledge. If that data is ever breached, you cannot simply replace your face the way you replace a credit card number.

Right now, only a handful of U.S. states have laws that specifically regulate biometric data. Illinois, Texas, and Washington are the most notable. In other states, consumers have far fewer protections. This means that even if you live outside Illinois, your facial data could be collected with minimal legal safeguards. The MAC lawsuit is a useful case study because it highlights how a national brand with a popular app can run into legal trouble over privacy practices that might otherwise go unnoticed.

It’s also worth noting that the company collecting the data is not always the only entity involved. Many beauty brands license their AI try‑on technology from third‑party vendors. Those vendors may have their own data policies, and the brand may not fully control what happens to the data after it leaves your device.

What you can do to protect your privacy

You don’t have to stop using virtual try‑on tools, but you can take a few practical steps to reduce the risk.

  1. Check the app’s privacy policy before you use the try‑on feature. Look for specific mentions of biometric data, facial recognition, or “biometric identifiers.” If the policy is vague or doesn’t address data retention and deletion, that’s a red flag.

  2. Adjust your device permissions. On both iOS and Android, you can revoke camera access for individual apps. Use the try‑on tool, then go to your phone’s settings and turn off camera permission for that app until you need it again. This limits the app’s ability to capture facial data outside the session.

  3. Use offline or store‑based try‑on options when available. Some brands now offer “virtual try‑on” through in‑store mirrors that do not save your image. If you have the choice, opt for a method that does not rely on cloud processing.

  4. Stay informed about laws in your state. Organizations like the Electronic Privacy Information Center (EPIC) and the Electronic Frontier Foundation (EFF) publish updates on biometric privacy legislation. If your state is considering a BIPA‑style law, supporting it can help extend protections.

  5. Consider whether you truly need the feature. If you already know your shade or are comfortable with online swatches, you can skip the camera‑based tool entirely. Not using it is the simplest way to avoid data collection.

Expert perspective

According to a privacy advocate quoted in Personal Care Insights (the same publication that first reported the MAC lawsuit), “Consumers often assume that if a brand offers a feature, it must be safe. But the legal landscape for biometric data is still developing, and companies are learning on the job.” That uncertainty means the burden currently falls on the user to be cautious.

Sources

  • Personal Care Insights article on the MAC lawsuit (June 2026)
  • Illinois Biometric Information Privacy Act (BIPA) text
  • Previous similar lawsuits against L’Oréal and Ulta Beauty (public court filings and news reports)
  • Electronic Frontier Foundation (EFF) – biometric privacy resources

The MAC case may take months or years to resolve. In the meantime, it serves as a practical warning: the next time you hold your phone up to your face to “try on” a shade of lipstick, it’s worth asking — who else is looking at that image?