Apple Secretly Scanned Your Eyes Without Consent
The Privacy Lie Apple Sold You
Apple built an entire brand identity around privacy. They redesigned their logo with a padlock. They ran Super Bowl ads mocking competitors. They told you Face ID was secure, local, and under your control. What they did not tell you is that every time you glanced at your iPhone to unlock it, Apple was scanning your iris and retina without your knowledge or written consent.
On July 4, 2026, Illinois resident Samantha Mettler filed a class action lawsuit in the United States District Court for the Northern District of Illinois, Western Division, alleging that Apple Inc. violated the Illinois Biometric Information Privacy Act by collecting biometric identifiers from millions of users without the legally required written releases. Case number 1:26-cv-07825.
The lawsuit centers on a distinction Apple deliberately obscured. When users set up Face ID, they consented to facial recognition. They did not consent to iris and retinal scanning. Under Illinois law, these are separate biometric identifiers. Collecting one does not grant permission to collect the other. Apple collected both. They disclosed one. They buried the other in technical support documents that most users will never read.
How Apple’s TrueDepth Camera Tracks Your Eyes
Apple’s TrueDepth camera system is installed on every Face ID-enabled device. According to Apple’s own technical documentation, the system “captures accurate face data by projecting and analyzing thousands of invisible dots to create a depth map of your face and also captures an infrared image of your face.” The complaint alleges that this process includes continuous monitoring of iris and retinal position.
Apple states on its support website that Face ID “recognizes if your eyes are open and your attention is directed toward the device. This makes it more difficult for someone to unlock your device without your knowledge (such as when you are sleeping).” This feature is called attention detection. It cannot function without scanning the user’s iris and retina. Apple never explicitly disclosed this to users during the Face ID enrollment process.
The TrueDepth camera does not stop monitoring when Face ID is inactive. According to Apple’s documentation, “even if you don’t enroll in Face ID, the TrueDepth camera intelligently activates to support attention aware features, like dimming the display if you aren’t looking at your device or lowering the volume of alerts if you’re looking at your device.” The complaint argues this constitutes unlawful biometric surveillance even for users who never enabled Face ID.
The Attention Features Apple Never Told You About
Apple’s Attention Aware Features activate automatically. They are not optional unless the user discovers a toggle buried in Settings under Accessibility, not Privacy. The feature monitors whether the user is looking at the screen. If the user looks away, the display dims. If the user looks at the screen during an incoming notification, the volume lowers. These conveniences require real-time iris and retinal position tracking.
The complaint alleges Apple never disclosed this separate biometric data collection to users. The consent flow for Face ID mentions facial recognition. It does not mention eye tracking. It does not mention iris scans. It does not mention retinal scans. Under Illinois BIPA, this is a violation. Companies must provide written notice specifying exactly which biometric identifiers are being collected and for what purpose.
Apple’s support documentation confirms the system checks “to determine if you’re looking at your device and turns the screen off if you aren’t.” This feature, marketed as a battery-saving convenience, operates through continuous biometric surveillance. Users cannot disable it without navigating to Accessibility settings, a location most users associate with disability accommodations, not privacy controls.
Machine Learning Training You Never Agreed To
Apple converts biometric data into mathematical representations. The complaint alleges these representations are used to train machine learning algorithms. Apple stores this data in a digital vault called the Secure Enclave, which Apple claims is inaccessible even to the company itself. However, users cannot access this data either. They cannot delete it. They cannot audit it. They cannot verify what Apple does with it.
The lawsuit argues that Apple uses biometric information collected from users to improve its biometric collection systems. This creates a feedback loop. The more faces Apple scans, the better Face ID becomes. The more irises Apple tracks, the more accurate attention detection becomes. Users are unknowing participants in algorithmic training. Illinois law requires written consent and a clear retention schedule before this data can be collected. Apple provided neither.
Apple markets the Secure Enclave as a privacy feature. In practice, it functions as a black box. Users cannot verify what data is stored. They cannot verify what data is processed. They cannot verify what data is transmitted. Apple’s privacy claims rest on trust. The lawsuit alleges that trust was misplaced.
The Legal Receipts: What Apple Admitted in Its Own Documentation
“Face ID cannot be set up unless the camera can see your eyes while using Face ID to ensure that the user is actually looking at their phone; this is because Apple’s Face ID uses technology that collects iris or retinal scans.”
“Face ID recognizes if your eyes are open and your attention is directed toward the device. This makes it more difficult for someone to unlock your device without your knowledge (such as when you are sleeping).”
“Even if you don’t enroll in Face ID, the TrueDepth camera intelligently activates to support attention aware features, like dimming the display if you aren’t looking at your device or lowering the volume of alerts if you’re looking at your device. For example, when using Safari, your device checks to determine if you’re looking at your device and turns the screen off if you aren’t.”
“A portion of your device’s neural engine, protected within the Secure Enclave, transforms the depth map and infrared image into a mathematical representation and compares that representation to the enrolled facial data. Face ID automatically adapts to changes in your appearance.”
These statements appear on Apple’s support pages, not during the Face ID enrollment process. They are hyperlinked footnotes in technical documentation. The complaint alleges this does not satisfy Illinois BIPA’s requirement for written notice. Users must be informed in writing that a specific biometric identifier is being collected. They must be informed of the purpose. They must be informed of the retention period. They must provide written consent. None of this occurred.
The Non-Financial Ledger: Surveillance Without Consent
Samantha Mettler is an Illinois resident living in Dekalb County. She owns an Apple device with Face ID enabled. She used Face ID to unlock her phone. She had no idea Apple was scanning her iris and retina. She believed she had consented to facial recognition. She did not believe she had consented to eye tracking. When she learned the truth, she felt violated.
Millions of Illinois residents used Face ID under the same assumption. They thought they were unlocking their phones with their faces. They did not know Apple was harvesting additional biometric identifiers. They did not know the TrueDepth camera was monitoring their eye movements every time they used their devices. They did not know this data was being converted into mathematical models to train machine learning systems.
The harm is not financial. The harm is the loss of control. Biometric identifiers are immutable. You cannot change your iris. You cannot change your retina. If this data is compromised, you cannot reset it like a password. If this data is misused, you cannot reclaim it. Apple took this data without permission. Apple stored this data without transparency. Apple used this data without accountability.
The complaint describes this as surveillance. It is surveillance that users did not consent to. It is surveillance they could not opt out of without discovering a hidden toggle in accessibility settings. It is surveillance Apple marketed as a privacy feature. The lawsuit alleges this violated Illinois state law designed specifically to prevent exactly this kind of corporate overreach.
Societal Impact Mapping
Privacy Degradation and Consent Erosion
Apple’s conduct reflects a broader pattern in the technology industry. Biometric data collection is normalized through incremental disclosure failures. Companies collect more data than they disclose. They bury disclosures in documentation users will never read. They present opt-outs as accessibility features rather than privacy controls. Over time, surveillance becomes the default. Consent becomes a legal fiction.
Illinois passed BIPA in 2008 because lawmakers understood biometric data is different. It is permanent. It is unique. It can be used to track individuals across every digital interaction. The statute requires written consent precisely because verbal consent and buried terms of service are insufficient. Apple’s alleged violations demonstrate why these protections are necessary.
Economic Inequality and Algorithmic Power
Apple profits from this data. The machine learning models trained on user biometrics make Face ID faster, more accurate, and more valuable. These improvements translate into competitive advantages. They translate into market dominance. They translate into higher device prices. Users provided the data. Users did not receive compensation. Users did not receive transparency.
The economic model is extraction. Apple extracts biometric data from users. Apple uses that data to improve its products. Apple sells those improved products back to the same users at premium prices. The users who provided the data do not share in the profits. They do not control how the data is used. They do not even know the full extent of what was collected.
Regulatory Capture and Enforcement Gaps
Apple operates across all fifty states. Illinois is one of the few states with a private right of action under biometric privacy law. In most states, users have no legal recourse. Federal privacy law is nearly nonexistent. The result is a patchwork system where corporate accountability depends on geography. Apple’s alleged violations occurred in Illinois. The same conduct likely occurred in every other state. Only Illinois residents can sue.
This creates a perverse incentive structure. Companies calculate the cost of BIPA violations in Illinois against the revenue generated from unregulated data collection in 49 other states. If the penalties are low enough, violation becomes a business decision. The lawsuit seeks statutory damages. Under Illinois law, companies face $1,000 per negligent violation or $5,000 per reckless or intentional violation. With millions of potential class members, the damages could be substantial. Whether they are substantial enough to deter future violations remains to be seen.
The Cost of a Life Metric
Apple collected biometric data from millions of users. Apple used that data to improve its products. Apple charged users premium prices for those products. Users received nothing. They were not compensated. They were not informed. They were not asked. The value extracted from their biometrics accrued entirely to Apple.
What Now?
The lawsuit is in its early stages. Apple has not yet filed a response. The company is headquartered in Cupertino, California. The case is being litigated in federal court in Illinois under the Class Action Fairness Act. Plaintiff Mettler seeks to certify a class of all Illinois residents whose biometric identifiers were collected by Apple through Face ID or Attention Aware Features without adequate written consent.
The complaint names no individual executives. Apple Inc. is the sole defendant. The legal team representing the plaintiff is Yagman PLLC, based in Uniondale, New York. Attorney Blake Hunter Yagman signed the complaint. The case number is 1:26-cv-07825. The complaint was filed on July 4, 2026.
Regulatory Watchlist
- Illinois Attorney General’s Office (Consumer Fraud Bureau)
- Federal Trade Commission (Bureau of Consumer Protection)
- California Attorney General’s Office (Privacy Enforcement Section)
- Electronic Privacy Information Center (EPIC)
- American Civil Liberties Union (ACLU Privacy & Technology Project)
What You Can Do
If you are an Illinois resident who used Face ID on an Apple device, you may be a member of this class action. Monitor the docket for updates on class certification. If you want to disable Attention Aware Features on your device, navigate to Settings > Accessibility > Face ID & Attention and toggle off “Attention Aware Features.” This will not delete data already collected.
Support organizations fighting for stronger biometric privacy laws. BIPA is one of the few statutes in the country with a private right of action. Corporate lobbying efforts have attempted to weaken it. Grassroots pressure is required to preserve and expand these protections. Contact your state legislators. Demand federal biometric privacy legislation. Demand transparency. Demand consent that actually means something.
The source document for this investigation is attached below.
Explore by category
Product Safety Violations
When companies sell dangerous goods, consumers pay the price.
View Cases →Financial Fraud & Corruption
Lies, scams, and executive impunity that distort markets.
View Cases →

