Google launches selfie video sign-in - MEGA Blog
Back to list
PRIVACY
Google launches selfie video sign-in
Jeraiza Molina
MEGA Staff
Published on 24 Jul 2026
It’s pitched as an easier way back into your account when you’re locked out. Before you record your face for Google (or whether you should), three questions are worth asking: where does the video live, how is it protected, and what else might Google do with it?
On 23 July 2026, Google introduced selfie video sign-in, a new way to recover a Google Account. Instead of a password or a code, you record a short video of your face, and Google checks it against a selfie you enrolled earlier to let you back in.
It also fits a pattern worth noticing. First Google began testing a reCAPTCHA that asks you to wave your hand at the camera; now it wants a short video of your face to sign you in. Each step asks for a little more of your biometric data to prove you’re human.
It’s easy to see the appeal. Passwords get forgotten and phones get lost. But this replaces a thing you know for a copy of your face sitting on Google’s servers, and a face is not a password you can change if it ever leaks. So the details of where it goes, and who gets to use it, matter more than usual.
Join the MEGA privacy revolution. Create a free MEGA account and get 20 GB of storage with zero-knowledge encryption.
Sign up for 20 GB free storage
In this blog<br>What Google actually launched<br>Where your face is stored<br>How it’s stored<br>Will Google use it for anything else?<br>So, should you record a video selfie for Google?<br>Frequently asked questions
What Google actually launched
Setup asks you to look into your camera and complete a few guided head movements, capturing your face from several angles. If you later get locked out, whether from a forgotten password, a lost or stolen phone, or a sign-in on a borrowed device, you record a fresh selfie and Google compares it to the enrolled one to confirm it’s really you.
To stop people fooling it with a photo or a deepfake, Google matches the live video against your saved selfie, asks you to perform simple movements to prove you’re a real, live person, and runs its usual checks for suspicious sign-ins. As a security upgrade over a recycled password, it looks like a genuine step forward. The privacy questions sit underneath it.
Where your face is stored
This isn’t stored only on your phone. For recovery to work when your device is lost or you’re on someone else’s, the enrolled selfie has to live on Google’s side , associated with your Google Account.
The (almost) reassuring part is that Google says the selfie is recorded and stored only with your consent, and that you can delete it at any time from your account settings. So you’re not locked into keeping it. But while it’s enrolled, a biometric record of your face is being held by Google, not by you.
How it’s stored
Google says the selfie video is encrypted at rest , meaning it’s protected while it’s sitting in storage and not in use. That’s good practice, and it guards against the file being lifted straight out of a database.
It’s worth being clear about what “encrypted at rest” does and doesn’t mean, because the phrase does a lot of quiet reassuring. Yes, it protects the stored file from outside theft. But, it does not mean Google can’t see your face. Google holds the keys and has to be able to process your selfie to match it during recovery, so this is company-managed encryption, not end-to-end or zero-knowledge encryption where the provider has no access to your content at all. Your face is protected from others. It isn’t hidden from Google.
Will Google use it for anything else?
This is the question worth slowing down on, and the honest answer is: by default, no, but there’s a door.
Google says the selfie is used solely for sign-in unless you choose to share it for other purposes. The catch is in that second clause. During or after setup, you can opt in to let Google use the video and related data to improve its facial recognition, age estimation, and other identity-verification technologies. In plain terms, there’s a setting that turns your recovery selfie into training data for Google’s biometric models.
It’s opt-in, not automatic, and that’s to Google’s credit. But two things are true at once. A default-off toggle still normalises the idea of handing your face to a company to train its systems. And “used solely for sign-in” is a policy and a settings state, both of which can be changed, misread, or quietly re-defaulted in a future update. The protection holds as long as you decline the option and Google keeps the arrangement it describes today.
So, are we sure Google won’t use your face for its own purposes? You can be reasonably sure it won’t if you don’t opt in. You cannot be sure the option to will always stay off by default, or that the boundary won’t move.
So, should you record a video selfie for Google?
For a lot of people, selfie recovery will be safer than the...