TwinEthosRequest access

Control

AI analysis of users' stored photos, files, or messages runs without their opt-in

AI features that run in the background over content people have stored with a service (photo and video libraries, documents and files, email, chat messages, notes, screen or call recordings), such as face grouping or recognition, object and scene tagging, summarising or indexing for an assistant, or extracting interests, are off until each user turns them on after being told what is analysed and why; turning a feature off stops the analysis and deletes what it derived (face templates, embeddings, tags, summaries). Analysis a user asks for on a specific item at that moment, and screening for malware, spam, or abuse, are outside this control. Face and voice templates are also governed by the biometric-consent controls where that law applies.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: Biometric data from AI features is collected, kept, or disclosed without consent or limits · control id cond.ai-analysis-of-stored-content-without-opt-in

Reach

1items this one guard addresses
0jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

The guard to add

Default each AI feature over stored content to off, check the user's opt-in inside every job that runs it, and delete derived data when it is turned off.

Consider giving each AI feature that runs over stored content (face grouping, auto-tagging, inbox or document summaries, an assistant's index of the user's files) its own per-user setting that defaults to false in the settings model and migration, set to true only from an opt-in screen that says what is analysed and why. Check that setting inside every background, on-upload, and batch job (Celery or queue tasks, storage-event handlers, cron indexers) before calling a vision, face, embedding, or language model, and filter batch jobs to opted-in users in the query itself. When the user turns the feature off, stop the job and delete what it produced (face collection entries, embeddings in the vector store, tags, summaries). A request the user makes on one item at that moment ('summarise this file') needs no separate opt-in.

Where it goes: 1 application source code, 2 data models, 3 config and feature flags, 14 user-facing text.

What reviewers look for: settings fields for library-wide AI features (face_grouping, ai_photo_analysis, smart_features, aiMailInsights and similar) defaulting to false; a check of that field, or a filter on it in the batch query, before rekognition.index_faces, rekognition.detect_labels, face_recognition.face_encodings, vision ImageAnnotatorClient.label_detection or face_detection, embeddings.create, or a summarising model call over stored items; a disable handler that deletes face collection entries, embeddings, tags, and summaries.

Example (Django + Celery + Amazon Rekognition), before:

class UserSettings(models.Model):
    user = models.OneToOneField(User, on_delete=models.CASCADE)
    face_grouping = models.BooleanField(default=True)

@shared_task
def index_new_photo(photo_id):
    photo = Photo.objects.get(id=photo_id)
    rekognition.index_faces(CollectionId=f'user-{photo.owner_id}',
                            Image={'S3Object': {'Bucket': BUCKET, 'Name': photo.key}})

After:

class UserSettings(models.Model):
    user = models.OneToOneField(User, on_delete=models.CASCADE)
    face_grouping = models.BooleanField(default=False)   # set only from the opt-in screen

@shared_task
def index_new_photo(photo_id):
    photo = Photo.objects.select_related('owner__settings').get(id=photo_id)
    if not photo.owner.settings.face_grouping:
        return
    rekognition.index_faces(CollectionId=f'user-{photo.owner_id}',
                            Image={'S3Object': {'Bucket': BUCKET, 'Name': photo.key}})

def disable_face_grouping(user):
    user.settings.face_grouping = False
    user.settings.save()
    rekognition.delete_collection(CollectionId=f'user-{user.id}')

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

TwinEthos recommendation (not law) (1)

Related incidents

  • Thele v. Google: suit alleges Gemini analysis of Gmail, Chat, and Meet content was switched on by default (2025; alleged (not proven)). A putative class action filed November 11, 2025 in the U.S. District Court for the Northern District of California (No. 5:25-cv-09704) alleges that Google secretly turned on Gemini for users' Gmail, Chat, and Meet accounts, enabling AI to track private communications without users' knowledge or consent, and that the 'Smart features' setting was on by default while still worded as an opt-in; the first amended complaint put the change on or about October 10, 2025, and the second amended complaint 'in or around the fall of 2025'. On July 7, 2026 the court granted Google's motion to dismiss the first amended complaint with leave to amend for lack of standing, observing among other things that the plaintiffs had not alleged that their own data was affected or that the Gemini features were not already on by default before October 10, 2025; it did not rule on the merits. The plaintiffs filed a second amended complaint on August 18, 2026 (ECF 39), adding a third plaintiff, and a motion to dismiss it was docketed on September 29, 2026 (ECF 43), which Law360 reported as Google's. Google's Gmail help page states that smart feature settings are off by default for people in the European Economic Area, Japan, Switzerland, and the United Kingdom. The allegations have not been adjudicated. Source: First Amended Class Action Complaint, Thele v. Google LLC, No. 5:25-cv-09704 (N.D. Cal., filed 2025-11-12, ECF 6) · evidence grade: primary · cited by Keep AI analysis of people's stored photos, files, and messages off until they opt in
  • Microsoft makes Recall, which analyzes screen snapshots with on-device AI, off unless the user turns it on (2024-06; disclosed by the operator). Recall periodically takes snapshots of what appears on the screen and analyzes them locally with on-device AI so people can search what they have seen. On June 7, 2024, ahead of the feature's release, Microsoft said it was updating the Copilot+ PC set-up experience to give people a clearer choice to opt in to saving snapshots, that Recall would be off by default unless the user proactively turns it on, and that Windows Hello enrollment would be required to enable it, citing feedback that it should be easier for people to choose whether to enable Recall and that privacy and security safeguards should improve. Source: Microsoft, Windows Experience Blog (Pavan Davuluri, 2024-06-07) · evidence grade: primary · cited by Keep AI analysis of people's stored photos, files, and messages off until they opt in
  • FTC alleges Facebook's face recognition stayed on by default while its data policy implied users had to opt in (2018-04; alleged (not proven)). The FTC's July 2019 complaint alleges that Facebook's data policy, updated in April 2018, suggested that users would need to opt in to having facial recognition enabled for their accounts, while tens of millions of users who had the older 'Tag Suggestions' setting had facial recognition turned on by default. The case was resolved by a settlement order that imposes a $5 billion penalty and requires clear and conspicuous notice of Facebook's use of facial recognition and affirmative express consent before any use that materially exceeds its prior disclosures. The allegations were not adjudicated. Source: U.S. Federal Trade Commission (press release, 2019-07-24) · evidence grade: primary · cited by Keep AI analysis of people's stored photos, files, and messages off until they opt in
  • FTC order requires Everalbum to delete face-recognition models trained on users' photos (2017-09; alleged (not proven)). The FTC alleged that Everalbum's Ever photo app enabled face recognition by default for most users and that, from September 2017 to August 2019, the company combined facial images extracted from users' photos with public datasets to develop its face-recognition technology, in part without affirmative express consent. Everalbum settled without admitting or denying the allegations; the final order (May 2021) requires deletion of face embeddings from users who had not consented and of any models or algorithms developed in whole or in part with Ever users' biometric information. Source: U.S. Federal Trade Commission (press release, 2021-05-07) · evidence grade: primary · cited by Keep AI analysis of people's stored photos, files, and messages off until they opt in