What the MAC Lawsuit Means for Your Privacy When Using AI Beauty Tools
If you’ve ever used a virtual try-on tool to test a lipstick shade or let an app analyze your skin, you’ve handed over something more valuable than you might realize: biometric data. A recent lawsuit against MAC Cosmetics has brought this practice into the spotlight, raising questions about how beauty brands collect, store, and potentially misuse facial data via AI features. For everyday consumers, the case is a practical reminder to look past the convenience and understand what’s happening behind the camera.
What Happened
According to a report published on June 23, 2026, MAC is facing a lawsuit over alleged privacy violations tied to its AI-powered beauty tools. The suit claims that MAC’s virtual try-on and skin analysis features collected users’ facial scans and other biometric information without proper consent or adequate security measures. While the full details of the complaint are still emerging, the case centers on whether the company violated state privacy laws—particularly in Illinois, where the Biometric Information Privacy Act (BIPA) sets strict rules for collecting identifiers like face geometry.
The lawsuit is not yet resolved, so it’s too early to say whether the allegations will hold up in court. But the mere fact that it was filed signals a growing legal scrutiny of how beauty tech companies handle sensitive personal data.
Why It Matters
AI beauty tools work by scanning your face to map features, detect skin tone, or simulate makeup. That process doesn’t just happen in real time on your device—it often sends data to company servers for analysis or improvement of the AI model. Even when apps claim to process images locally, the metadata, timestamps, or derived measurements may still be transmitted.
The MAC case highlights a few specific risks:
- Biometric data is irreplaceable. Unlike a password, you can’t change your face. Once collected and stored, a facial scan can be used for other purposes—such as identity verification or targeted advertising—without your knowledge.
- Consent is often vague. Many beauty apps bury data collection details in long privacy policies. Users click “agree” without realizing they may be granting permission to share data with third parties.
- Security may be weak. Biometric databases are attractive targets for hackers. A breach of facial data could lead to identity fraud or unauthorized access to accounts that rely on face recognition.
The implications go beyond this single brand. If MAC is found to have mishandled data, it could force other companies to reconsider their own data practices—or face similar lawsuits. For consumers, the case is a wake-up call to treat virtual try-on tools with the same caution you’d apply to any other data-hungry app.
What Readers Can Do
You don’t have to stop using beauty apps altogether, but you can take a few concrete steps to limit your exposure:
Check the app’s privacy policy before you scan. Look for what data is collected, where it’s stored, and whether it’s shared with third parties. Pay special attention to phrases like “biometric identifiers” or “facial geometry.” If the policy is vague or nonexistent, that’s a red flag.
Use camera permission controls. On both iOS and Android, you can revoke camera access for apps you don’t trust. Consider granting access only temporarily—during a single session—and then turning it off in your device settings.
Disable facial analysis features when possible. Some apps let you opt out of data collection or use a “guest” mode that doesn’t store your data. Others may offer a local processing option that keeps your scan on your device.
Update your software regularly. Security patches can close vulnerabilities that might otherwise let an app leak your data.
Be selective about which brands you share your face with. Bigger, well-known companies with dedicated privacy teams may have stronger safeguards, but that’s not guaranteed. Research any brand’s privacy track record before using its AI tools.
Know your legal rights. In states like Illinois, Texas, and Washington, laws give you the ability to sue companies that collect biometric data without consent. Even if you don’t live in those states, the growing number of lawsuits may eventually push for federal protections.
Sources
- Personal Care Insights – “MAC lawsuit highlights privacy risks in AI beauty tools, says expert” (published June 23, 2026). The article cites expert commentary on the data collection practices of AI beauty tools and the legal implications of the lawsuit.
- Illinois Biometric Information Privacy Act (BIPA) – 740 ILCS 14.
Note: This article reflects the lawsuit as reported in June 2026. Legal outcomes may change as the case progresses.