ANTHROPIC PRIVACY POLICY BIOMETRICS DATA SHARING AGENTIC

Anthropic Builds Identity Verification and Agentic Data Flows Into Its Privacy Policy

A Big One

Anthropic published a new Privacy Policy on June 8, effective July 8, for consumer accounts only (Free, Pro, Max), not Team, Enterprise, or the API. It adds a verification-data category that can include a government ID and facial geometry, rewrites the standard for sharing data with law enforcement, and for the first time describes Claude taking actions inside third-party apps on your behalf. Anthropic's cover email was unusually candid by industry standards, though it left some of the more consequential details one layer deeper in the document itself.

In human terms: A motion designer on a Pro plan reads the email, sees "we don't sell your data, Claude stays ad-free, you control training," and files it as routine. Those three statements hold. What the email does not lead with is that the same revision describes collecting a government ID and facial geometry if asked to verify age, and broadens who Anthropic can hand data to and on whose say-so. None of it is hidden. It is one summary layer above where the substance lives.

Why this matters: Most of this is genuine clarification, but two items are more than that: the biometric-class verification data is new collection, and the law-enforcement disclosure standard is looser than the one it replaced. Freelancers and studio staff who opened consumer accounts on a work email should also note a new clause that can link those accounts to an employer's enterprise relationship. Below for more…

The mechanics • New verification data. "we may ask you to verify your age or identity," collecting "an image of your government-issued identity document... your image in photo or video form, facial geometry templates (which may be considered 'biometric data' in some jurisdictions)." • Disclosure standard widened.

BEFORE disclosure to "governmental regulatory authorities as required by law." AFTER sharing with "government authorities, law enforcement, or other third parties" under a good-faith-belief test.

• Agentic flows named. Outputs "may result in actions with effects outside the Services, such as sending communications, modifying files, or interacting with third-party services on your behalf." Training stays opt-out, with carve-outs for safety-flagged and self-reported content.

This originally appeared in Vol. 26, No. 15, Anthropic ID Verification, Ideogram Updates Language but Neglects Revision Date, Can AI Smoke?

View Full Issue →

Sign up for The Ledger Newsletter