Unreal Engine · Epic Games Privacy Policy · View original document ↗

Facial Image Collection for MetaHuman

High severity Medium confidence Explicitdocumentlanguage Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Unreal Engine Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

If you use the MetaHuman feature to create a game character based on your appearance, Epic collects photos of your face, but states the images are used only to generate a 3D mesh and not to identify you.

This analysis describes what Unreal Engine's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Facial images are considered biometric data under several state laws, and the policy's assertion that they are not used for identification does not necessarily exempt their collection from biometric privacy statute requirements in states like Illinois, which require prior written consent regardless of the intended use.

Interpretive note: Whether the facial image collection for MetaHuman triggers biometric privacy statutes depends on jurisdiction-specific definitions and whether the mesh generation process involves extraction of biometric identifiers, which is not technically specified in the policy.

Clause Stability Stable

0
Changes
3
Months Monitored
May 9, 2026
First Seen
May 20, 2026
Last Seen
This clause type exists across 3350 other provisions on other platforms.

Consumer impact (what this means for users)

Users of Epic's MetaHuman tool who submit facial photos should be aware that biometric privacy laws in some states may give them specific rights regarding how their facial image data is collected, retained, and deleted, independent of Epic's stated purpose limitation.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Contact Epic using the privacy contact information listed in Section 12 of this policy to request deletion of facial image data collected through MetaHuman. Specify that you are requesting deletion of biometric or facial image data and identify your Epic account.

How other platforms handle this

Ledger Medium

At Ledger, earning and maintaining our users' trust is a top priority. That's why we are deeply committed not only to protecting your privacy and securing your personal data, but also to being fully transparent about how we handle it.

Strava Medium

If we collect health information from these integrations (such as heart rate), we will not sell or use it for advertising or other similar purposes; we do not disclose it to third parties without your prior consent; and we will only use it for the specific purposes described in this Policy.

eBay Medium

We collect your personal data when you use our Services, create a new eBay account, provide us with information via a web form, add or update information in your eBay account, participate in online community discussions or otherwise interact with us.

See all platforms with this clause type →

Monitoring

Unreal Engine has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
When you use MetaHuman to create in-game characters, we collect images of you to generate a mesh solely to provide the requested functionality, not to identify you.

— Excerpt from Unreal Engine's Epic Games Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: Facial images collected for 3D mesh generation may constitute biometric identifiers or biometric information under Illinois BIPA (740 ILCS 14), Texas CUBI, Washington's My Health MY Data Act, and other state biometric frameworks, which in some cases apply regardless of the collector's intent to identify the individual. Illinois BIPA in particular does not require identification as an element of the regulated activity and has generated significant class action litigation. GDPR Article 9 classifies biometric data processed for the purpose of uniquely identifying a natural person as a special category requiring explicit consent, though the policy's assertion of a non-identification purpose may affect this classification under EU law. GOVERNANCE EXPOSURE: High for Illinois and other states with active biometric privacy statutes. BIPA provides a private right of action with statutory damages of $1,000 to $5,000 per violation, and class actions in the gaming and technology sectors have resulted in significant settlements. The policy's purpose limitation language ('solely to provide the requested functionality, not to identify you') may be relevant to GDPR Article 9 classification but does not substitute for compliance with state biometric statutes that do not require identification as a predicate. JURISDICTION FLAGS: Illinois (BIPA, private right of action, class action risk), Texas (CUBI), Washington state (My Health MY Data Act), EU/EEA (GDPR Article 9 special category data assessment required), United Kingdom (UK GDPR). California's CPRA includes biometric information in its definition of sensitive personal information, triggering opt-out rights. CONTRACT AND VENDOR IMPLICATIONS: If MetaHuman's image processing involves third-party computer vision or mesh generation vendors, those vendors' handling of facial images must be covered by data processing agreements that address biometric data obligations. Retention and deletion timelines for raw facial images should be contractually specified and aligned with the policy's purpose limitation assertion. COMPLIANCE CONSIDERATIONS: Compliance teams should (1) conduct a biometric data legal assessment for all jurisdictions where MetaHuman is available, mapping facial image collection against applicable state and national biometric privacy statutes; (2) implement and document consent mechanisms that satisfy BIPA's written release requirement for Illinois users if not already in place; (3) establish and publish a publicly available retention and deletion schedule for facial images as required by BIPA; and (4) confirm whether raw facial images are retained after mesh generation and, if not, document and operationalize the deletion process.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • State AG
    State Attorneys General in Illinois, Texas, and Washington have authority over biometric privacy statutes that may apply to facial image collection in consumer applications.
    File a complaint →
  • FTC
    The FTC has authority over unfair or deceptive practices and has issued guidance on biometric data collection and privacy disclosures in consumer-facing products.
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
COPPA
United States Federal
Connecticut Data Privacy Act Amendments
US-CT
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US
VPPA
United States Federal

Provision details

Document information
Document
Epic Games Privacy Policy
Entity
Unreal Engine
Document last updated
May 5, 2026
Tracking information
First tracked
May 9, 2026
Last verified
May 9, 2026
Record ID
CA-P-007189
Document ID
CA-D-00086
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
6c9a1562e0e89a4ac5fd75fde762ccb9cff446945926d63aea566c2fd9cfb2e1
Analysis generated
May 9, 2026 15:56 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Unreal Engine
Document: Epic Games Privacy Policy
Record ID: CA-P-007189
Captured: 2026-05-09 15:56:42 UTC
SHA-256: 6c9a1562e0e89a4a…
URL: https://conductatlas.com/platform/unreal-engine/epic-games-privacy-policy/facial-image-collection-for-metahuman/
Accessed: June 30, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Unreal Engine's Facial Image Collection for MetaHuman clause do?

Facial images are considered biometric data under several state laws, and the policy's assertion that they are not used for identification does not necessarily exempt their collection from biometric privacy statute requirements in states like Illinois, which require prior written consent regardless of the intended use.

How does this clause affect you?

Users of Epic's MetaHuman tool who submit facial photos should be aware that biometric privacy laws in some states may give them specific rights regarding how their facial image data is collected, retained, and deleted, independent of Epic's stated purpose limitation.

Is ConductAtlas affiliated with Unreal Engine?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Unreal Engine.