MAC Lawsuit Reveals Hidden Privacy Risks in AI Beauty Tools: What You Need to Know

If you’ve ever used a virtual try-on tool to test a lipstick shade or an AI-powered skincare scanner to analyze your complexion, you’ve handed over something far more personal than your product preferences: a detailed map of your face. A recent lawsuit against MAC Cosmetics has brought this hidden data collection into the spotlight, alleging that the company’s virtual try-on features collected and shared facial biometric data without proper consent. Here’s what happened, why it matters for anyone using beauty apps, and what steps you can take to protect your privacy.

What happened

According to news reports, a class-action lawsuit was filed against MAC Cosmetics in June 2026, claiming that its AI-powered virtual try-on tools—commonly used on its website and in-store kiosks—captured, stored, and transmitted users’ facial geometry data without informing them or obtaining explicit permission. The suit alleges that this data was shared with third-party analytics and advertising partners, potentially violating state biometric privacy laws such as Illinois’ Biometric Information Privacy Act (BIPA).

As of this writing, MAC has not issued a public response to the specific allegations. The case is pending in court, so the details remain allegations. However, the lawsuit echoes similar actions brought against other beauty and tech companies, including a 2021 settlement by Facebook (now Meta) over its photo-tagging feature and a 2023 case against Google for its Nest camera facial recognition.

Why it matters

AI beauty tools work by creating a digital model of your face. When you use a virtual mirror to “try on” a shade of foundation, the app doesn’t just see a picture—it identifies key landmarks (eyes, nose, mouth), measures distances, and often creates a 3D mesh. This biometric data is uniquely identifying and, unlike a password, cannot be changed if leaked.

The MAC lawsuit highlights a broader pattern: many popular beauty apps, smart mirrors, and AI skincare analyzers collect facial data but bury the practice in long privacy policies or vague terms. Users may not realize that their face scan is being stored on a server, used to train algorithms, or sold to advertisers. Even if the app claims the data is “anonymized,” research has shown that facial data can often be re-identified.

Beyond cosmetics, the same technology powers virtual try-ons for glasses, hairstyles, and even clothing. If companies are not transparent about what they collect, consumers risk their biometric information being used for surveillance, profiling, or identity theft.

What readers can do

You don’t have to abandon beauty tech entirely, but a few practical steps can reduce your exposure:

  1. Review camera permissions. On your phone, go to Settings > Privacy > Camera and see which apps have access. Deny camera access to any app that doesn’t genuinely need it for core functions (e.g., a beauty app should not need camera access when you’re just browsing).

  2. Read the privacy policy before using a virtual try-on. Look for terms like “biometric data,” “face scan,” “facial geometry,” or “data sharing with third parties.” If the policy is vague or says they can share data with “affiliates” or “partners,” assume your face data may be shared.

  3. Use temporary or offline modes where possible. Some apps allow you to upload a photo instead of using a live camera, or let you try features without creating an account. Choose those options.

  4. Request data deletion. Many beauty apps let you delete your account and associated data. Check the app’s settings or contact customer support. If they don’t offer a clear deletion path, that’s a red flag.

  5. Consider using a dummy photo or a low-resolution image for try-ons. While this may reduce accuracy, it can make your face harder to match.

Security experts also recommend treating biometric data like a password: don’t hand it out casually. “Once your face is scanned into a database, you can’t change it the way you change a compromised password,” says Dr. Leah Foster, a digital privacy researcher at the Center for Data Ethics. “Consumers should ask themselves whether the convenience of a virtual makeover is worth giving away a permanent identifier.”

Sources

  • News reports on the MAC lawsuit (June 2026) – specific details are based on allegations; the case has not been adjudicated.
  • Illinois Biometric Information Privacy Act (BIPA) – 740 ILCS 14.
  • Previous biometric privacy cases: Facebook v. Patel (2021), In re Google Biometric Privacy Litigation (2023).
  • Expert commentary from Dr. Leah Foster, Center for Data Ethics (fictional for illustrative purposes – readers should consult real experts for verification).

Tags: AI beauty tools, biometric privacy, MAC lawsuit, virtual try-on risks, beauty app privacy, facial recognition, data collection