Anthropic may ask to see your passport. Why AI apps are checking IDs
Anthropic's privacy policy, effective 8 July 2026, covers ID scans and face geometry. What to check before you upload ID to any app.
Claude may ask you to prove who you are. A photo of a government ID. A selfie. A template of your face geometry. The category has a name, Verification Data, and it entered Anthropic's privacy policy on 8 July 2026.
Anthropic is one name on a growing list. Roblox, Discord and adult sites all run checks of some kind in 2026. In law, a passport scan and a face template are different objects, and that difference matters before you upload either.
The policy text itself
We fetched Anthropic's live policy on 12 September 2026. It reads:
Verification Data: In certain circumstances, we may ask you to verify your age or identity. If you choose to do so, data we will collect includes, depending on the method: an image of your government-issued identity document and the information appearing on it (such as your ID number and date of birth); your image in photo or video form, facial geometry templates (which may be considered ‘biometric data’ in some jurisdictions); and the result of the verification (for example, whether your age meets the applicable threshold).
Anthropic's privacy update page lists Verification Data among the changes effective 8 July 2026. Those changes cover consumer accounts only: Claude Free, Pro and Max.
The scope shifted between June and August
TechCrunch reported the change on 22 June 2026, before it took effect. Its report quoted Anthropic's Thariq Shihipar. He said the update applied to a “small subset of users” whose accounts were flagged but not banned, as an update to the appeals process.
That was June. Anthropic's identity verification help page, dated 11 August 2026, reads more broadly. Verification is rolling out “for a few use cases”, it says, and a prompt may appear “when accessing certain capabilities, as part of our routine platform integrity checks, or other safety and compliance measures.”
The policy text names no trigger at all. It says “in certain circumstances” and leaves it there.
The help page is specific. It wants a physical government photo ID in your hand: passport, driving licence or national identity card. It wants a phone camera for a live selfie. Photocopies and mobile driving licences are refused.
Persona holds the file
Anthropic names Persona Identities as its verification partner. Your ID and selfie are held by Persona, the help page says, rather than on Anthropic's own systems. Anthropic remains the data controller and can view the records through Persona to review an appeal.
Retention is where the published detail stops. The page states no period. The privacy policy names Persona once, in its Republic of Korea disclosure, which sets three years of recipient retention.
Age checks run on a separate track. Anthropic's age assurance page, dated 18 May 2026, names Yoti. Yoti deletes the selfie and documents as soon as the age is checked, that page says, and Anthropic receives only a pass or fail. Two flows, two data trails.
Face geometry sits in its own legal box
Anthropic's own wording flags that facial geometry templates “may be considered ‘biometric data’ in some jurisdictions”. Illinois is the clearest case. Its Biometric Information Privacy Act, in force since 2008, lists a “scan of hand or face geometry” as a biometric identifier. An ID number is not on that list.
From the statute itself, at 740 ILCS 14/15 and 14/20:
A company holding biometric data must publish a written retention and destruction schedule.
It must destroy the data once the purpose is met, or within three years of your last interaction, whichever is first.
It must state in writing beforehand what is taken and for how long, then obtain a written release.
Anyone aggrieved can sue. Liquidated damages run at $1,000 for negligence and $5,000 for intentional or reckless conduct.
A scanned licence triggers none of that machinery in Illinois. The face template does. One upload screen, two quite different legal objects.
The wave is wider than AI
Checks reached mainstream consumer apps through 2026, on dates worth pinning down:
7 January 2026: Roblox began requiring an age check to use chat, first in the United States, then all regions with chat within a week. Its announcement says facial age estimation images go to Persona and are deleted immediately after processing.
9 February 2026: Discord said it would take age verification global the following month, as TechCrunch reported.
24 February 2026: Discord pushed that back to the second half of 2026, after a backlash. Its CTO Stanislav Vishnevskiy wrote that many users “walked away thinking we’re requiring face scans and ID uploads from everyone just to use Discord”.
6 May 2026: TechCrunch reported a survey of a thousand children by Internet Matters, a UK non-profit. About half said age checks were easy to bypass. One reported method was drawing on facial hair with a makeup pencil.
One check, one more database
The check is quick. The record it creates lasts. Discord's own press release, published 3 October 2025 and updated on 9 October 2025, describes an unauthorised party compromising a third-party customer service vendor. Roughly 70,000 users may have had government-ID photos exposed. The vendor used them to review age-related appeals. Roblox says its age-check images are deleted at once. A retention policy separates those outcomes.
Weigh these up before you upload
Who holds the image: the app, or a named third party? Anthropic says Persona.
How long for? A stated period is worth more than an assurance of care.
Does the flow return a pass or fail, or store the document? Anthropic's Yoti age check returns a result; the Persona flow keeps records.
What happens if you decline? Discord said accounts, servers and DMs all stay, and only age-restricted content goes.
Which country stores it? TechCrunch noted that Persona can face US government demands for data it holds.
Questions worth asking about deletion
Short enough to paste into a support ticket:
What is the retention period for my ID image, and for my face template?
Is the template destroyed after the check, or kept so I can be re-verified later?
Can I ask for deletion once the check has passed?
In the EEA or the UK, what is the legal basis, and can I withdraw consent?
Anthropic's help page says verification data is used solely to confirm who you are, and is not used to train its models. A published retention period would be the next commitment worth making.
Where we stand
MultiChats runs no verification flow: no document upload, no age-check vendor. Our terms set an 18 or over minimum and take your word for it. What we keep, and what survives account deletion, is on our privacy page. Conversations are a different question. We do not train on yours. Where a provider's handling of them differs by model, that model's info card carries a notice.
Age checks are spreading. Minors are on these platforms, and regulators are asking for them. The practical question is what happens to that data afterwards. Once your passport photo and face template sit on a vendor's servers, who deletes them, and when?