Wealthfront collects a selfie photograph from Clients to verify their identity, and in some states this counts as biometric data under privacy law. The company requires its identity verification vendors to delete this data within 90 days.
This analysis describes what Wealthfront's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
Biometric data carries heightened legal protection in several states, and the 90-day vendor destruction timeline is a contractual commitment rather than a statutory minimum, meaning enforcement depends on Wealthfront's vendor contracts rather than direct regulatory obligation in all jurisdictions.
Interpretive note: The adequacy of the consent mechanism ('where required by law') varies by jurisdiction; Illinois BIPA requires affirmative written consent before collection, and the policy's conditional framing may not satisfy this standard uniformly.
The updated policy establishes that Wealthfront may collect personal information about minors when adult account holders designate them as beneficiaries or when custodians provide information during account opening. The policy clarifies that the company does not have actual knowledge of collecting information directly from minors themselves. Additionally, the revised terms disclose that the company may use client personal information to train, develop, and improve AI-powered features, which may be tested with employees or released to clients. The policy states that AI feature outputs are provided for informational purposes only and do not constitute investment advice, and that Wealthfront makes no representation that such outputs are accurate, complete, or suitable for any purpose. If you become aware your child has directly provided information to Wealthfront without your consent, you may contact support@wealthfront.com to request deletion.
View change record →Provision expanded with specific details about vendor destruction requirements and conditional consent mechanisms for biometric data.
View full change record →Clients must submit a selfie photograph for identity verification, which may be treated as biometric data under laws like Illinois BIPA; this data is held by third-party vendors and is contractually required to be destroyed within 90 days, but consumers have no direct mechanism to request earlier deletion from those vendors.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
To stop us collecting your location information, you can update your device settings, stop using the Service, or uninstall our mobile apps.
"We may use third-party vendors for identity verification. These vendors analyze whether the Client's "selfie" matches the government-issued identity document. The information collected from Client photographs may constitute biometric information in some jurisdictions. Where required by law, we will seek consent from you prior to any such collection. We require our third-party vendors who support identity verification to agree to destroy any potential biometric data that is created or gathered for purposes of verifying your identity no more than ninety (90) days after its collection.Excerpt from Wealthfront's Privacy Policy
(1) REGULATORY LANDSCAPE: This provision directly engages Illinois BIPA (740 ILCS 14), which requires informed written consent before collecting biometric identifiers and mandates a retention and destruction schedule, and Texas and Washington biometric privacy statutes.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Biometric data carries heightened legal protection in several states, and the 90-day vendor destruction timeline is a contractual commitment rather than a statutory minimum, meaning enforcement depends on Wealthfront's vendor contracts rather than direct regulatory obligation in all jurisdictions.
Clients must submit a selfie photograph for identity verification, which may be treated as biometric data under laws like Illinois BIPA; this data is held by third-party vendors and is contractually required to be destroyed within 90 days, but consumers have no direct mechanism to request earlier deletion from those vendors.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Wealthfront.