Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy discloses that Robinhood and its vendors extract facial geometry data from user-submitted selfies and photographs for identity verification and fraud detection purposes.
This analysis describes what Robinhood's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that biometric data, specifically facial geometry, is collected and processed by both Robinhood and named third-party vendors such as Persona. State biometric privacy statutes impose specific consent, retention, and destruction requirements that may apply to this collection depending on user location.
The updated privacy policy reorganizes how Robinhood discloses its handling of financial information, now grouping GLBA-regulated disclosures by individual service entity with updated reference links rather than listing all entities in a single section. The policy also removed coverage of Robinhood Social, meaning privacy practices for that social media product are no longer described in this statement. The revised policy clarifies that it applies when you are logged into services or interact through online customer service channels, and directs users to a separate Robinhood Markets US Online Privacy Statement for information about non-financial data collection practices.
View change record →This provision authorizes collection of biometric facial geometry data from selfies submitted during identity verification processes. The agreement states that third-party vendors may also collect biometric data from user photographs and voice for these purposes.
Cross-platform context
See how other platforms handle Biometric Data Collection and Processing and similar clauses.
Compare across platforms →Monitoring
Robinhood has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Biometric Data : We extract facial geometry data from selfies/photographs/videos to verify your identity and detect/prevent fraud. The information collected from your photo and your voice by our vendors for these purposes may include biometric data.Excerpt from Robinhood's Privacy Policy
1. REGULATORY LANDSCAPE: This provision directly implicates the Illinois Biometric Information Privacy Act (BIPA), which requires written consent, a publicly available retention schedule, and prohibition on sale of biometric data. Texas and Washington have enacted similar statutes. The FTC has enforcement authority over deceptive or unfair biometric data practices. The document does not specify a biometric data retention schedule or destruction timeline, which may be required by applicable state law. 2. GOVERNANCE EXPOSURE: High. BIPA litigation has resulted in substantial class action exposure for companies collecting biometric identifiers without compliant consent and retention policies. The disclosure that vendors including Persona may also collect biometric data from user photographs requires vendor contract review to confirm BIPA-compliant data processing agreements are in place. 3. JURISDICTION FLAGS: Illinois (BIPA), Texas (CUBI Act), Washington (My Health MY Data Act as potentially applicable), and New York create heightened exposure. Users in these states may have distinct consent and disclosure rights that the current policy language does not fully address with jurisdiction-specific detail. 4. CONTRACT AND VENDOR IMPLICATIONS: The reference to Persona as an identity verification vendor requires confirmation that data processing agreements address biometric data handling, retention schedules, destruction obligations, and prohibition on secondary use or sale consistent with applicable state biometric statutes. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should confirm that biometric data consent mechanisms satisfy BIPA and similar state statute requirements, that a publicly available biometric data retention and destruction schedule exists, and that vendor agreements with biometric data processors include required contractual protections. Data mapping should separately categorize biometric data from general identity data.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that biometric data, specifically facial geometry, is collected and processed by both Robinhood and named third-party vendors such as Persona. State biometric privacy statutes impose specific consent, retention, and destruction requirements that may apply to this collection depending on user location.
This provision authorizes collection of biometric facial geometry data from selfies submitted during identity verification processes. The agreement states that third-party vendors may also collect biometric data from user photographs and voice for these purposes.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Robinhood.