Imagine: you lost your phone, forgot your password, and your backup codes are long outdated. Until July 23, 2026, this meant days of correspondence with Google support without a guaranteed result. Now the company is offering a different solution — a video recording of your face.
How it works
The "Selfie for sign-in" feature is optional and designed primarily as a backup method when all other login options are unavailable. To set it up, you need to record a short video with head movements in different directions — the system verifies that a live person is in front of the camera, not a photograph. During each subsequent login, Google compares the new video with the saved template. If your computer doesn't have a camera, you can complete the process via smartphone by scanning a QR code.
According to Google's product management director John Grönberg, video is stored in encrypted form and is not used for anything else without explicit user consent. The recording can be deleted at any time — although Google notes that physical deletion occurs "after a certain period of time," not immediately.
Where the contradiction lies
Technically, the method differs fundamentally from passkeys — a more secure standard where the server never receives the biometric identifier. As noted by Vouched, a company specializing in identity verification, Google's selfie video works through biometric template matching: the template is stored, compared during login — and remains on the company's servers.
"This is not a zero-disclosure approach. Google stated that it may reuse basic biometric data to train facial recognition models and assess age."
Vouched.id, analysis of Google selfie sign-in feature
According to TechCrunch, regulators are increasingly actively scrutinizing this category of products — those that collect facial and voice biometrics. By agreeing to share video for "improving features," the user is effectively training Google's systems beyond their own account.
What this means in practice
- By default, video is used only for login — not for advertising, not for model training.
- If you agreed to additional use — permission can be revoked, but it's not always clear when exactly the data stops being processed.
- Account compromise now means a potential leak not of login and password, but of the biometric template of your face — data that cannot be "changed" like a password.
- Available not yet to everyone: Google is gradually rolling out the feature for personal accounts; you can check availability at g.co/signin-selfie.
The convenience is obvious — especially for people who rarely update their backup login methods. But if a major breach occurs from Google's servers tomorrow, affected users won't be able to simply "change their password" — and no company has yet explained what to do with a stolen biometric template of your face.
Whether this feature will remain truly optional — or over time become de facto mandatory for account recovery, as happened with phone numbers — depends on whether EU or US regulators impose a requirement for minimum biometric data retention by the end of 2026.