Persona Identities, Inc. is facing a class action lawsuit in Illinois brought by DoorDash delivery drivers who allege the identity verification company collected and stored scans of their facial geometry without following the disclosure and retention rules required by the state’s Biometric Information Privacy Act. After a failed attempt by Persona to push the dispute into individual arbitration, an Illinois appellate court sent the case back to the trial court in August 2024, and it is now proceeding on the merits.
What the DoorDash Drivers Allege
The case, Washington v. Persona Identities, Inc., was filed in late 2021 by two DoorDash drivers, Charles Washington and Katie Sims. The proposed class covers all Illinois residents whose biometric identifiers or biometric information were possessed by Persona within the applicable limitations period.1Caselaw Findlaw. Washington v. Persona Identities, Inc.
The complaint centers on how Persona’s software fits into DoorDash’s onboarding and reverification flow. Prospective drivers submit a live selfie and a photograph of their driver’s license. Persona’s system then analyzes and stores a scan of the driver’s facial geometry to confirm identity. After a driver is active, DoorDash prompts additional selfie checks through the app; by late 2024, more than 150,000 DoorDash drivers were performing those checks weekly.2Biometric Update. Persona’s Selfie Biometrics Power More Real-Time ID Verification for Dashers
BIPA requires any private entity that collects biometric identifiers to publicly disclose a written policy for retaining and destroying that data. The drivers allege Persona did not. They also claim Persona failed to meet BIPA’s other prerequisites for collecting facial geometry from Illinois residents.3Illinois Courts. Washington v. Persona Identities, Inc., 2024 IL App (3d) 240210
The Arbitration Ruling That Sent the Case Back to Court
Rather than answer the biometric claims directly, Persona moved in September 2023 to stay the litigation and compel individual arbitration. The theory: DoorDash drivers sign an Independent Contractor Agreement with an arbitration clause, and Persona argued it was a third-party beneficiary of that clause because of its role in identity verification.1Caselaw Findlaw. Washington v. Persona Identities, Inc.
The trial court granted the motion in February 2024. The plaintiffs appealed, and in August 2024 the Appellate Court of Illinois reversed. The panel held that a generic arbitration clause does not extend to nonparties unless the contract names them, and it emphasized a strong presumption that contracts are meant only for the parties who signed them. The DoorDash agreement referred to background checks being “administered by a third-party vendor,” but the court found that language did not reach Persona: Persona provides a software interface for identity verification, while DoorDash uses a separate vendor, Checkr, to administer background checks.3Illinois Courts. Washington v. Persona Identities, Inc., 2024 IL App (3d) 240210
The appellate court also handled a jurisdictional question along the way, ruling that the Federal Arbitration Act’s bar on interlocutory appeals in federal court does not preempt Illinois state appellate procedure. The case was remanded for further proceedings.1Caselaw Findlaw. Washington v. Persona Identities, Inc.
What BIPA Damages Look Like
BIPA carries statutory damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation. In 2019, the Illinois Supreme Court held in Rosenbach v. Six Flags that plaintiffs can sue for technical violations without proving actual harm, and more than 1,500 BIPA lawsuits followed. The largest resolutions include Facebook’s $650 million settlement in 2020, TikTok’s $92 million in 2021, and Google’s $100 million in 2022.4Commercial Litigation Update. Biometric Backlash: The Rising Wave of Litigation Under BIPA and Beyond
In August 2024, Illinois amended BIPA to soften the arithmetic. Repeated collection or transmission of the same biometric data from the same person by the same entity using the same method now counts as a single violation, with one recovery per person. The amendment also allows consent by electronic signature. Whether the amendment applies retroactively to conduct before August 2024 is unsettled, and courts have split on the question.5WilmerHale. Year in Review: 2024 BIPA Litigation Takeaways Because the reverification selfies at issue in the Persona case stretch back years and repeat weekly, retroactivity could substantially affect the class’s potential recovery.
Persona’s Stated Data Practices
Persona’s public privacy policy describes a tiered retention framework. Age estimation scans are deleted immediately once an outcome is determined. Identity scans used for age assurance are deleted by default, though customers can direct longer retention for fraud prevention. Full identity verification data that includes ID and selfie scans is destroyed upon completion of services or within three years of the user’s last interaction, subject to customer instructions and legal requirements.6Persona. Privacy Policy
The policy states that Persona does not use personal data, including biometric data, for AI or model training, and that it will not sell, lease, or trade biometric data. Disclosure is limited to completing authorized transactions, complying with law, responding to court orders, and cases with express consent. The policy also includes a class action waiver for U.S. residents, requiring disputes over facial scans or biometric information to be handled individually.6Persona. Privacy Policy
Public statements from CEO Rick Song emphasize deletion “as soon as we can” on behalf of the customer.7Malwarebytes. Age Verification Vendor Persona Left Frontend Exposed The written policy’s three-year window for identity verification data, subject to customer instructions, means how long any given user’s data actually lives depends on what the client tells Persona to do.
Other Controversies Feeding Scrutiny
The BIPA case is the active lawsuit, but Persona has drawn attention on two other fronts that shape how the litigation is being read publicly.
In January 2026, Discord used Persona as a vendor for a limited UK age verification test under the Online Safety Act. Users submitted government-issued IDs, and a FAQ disclaimer said data was temporarily stored for up to seven days before deletion. On February 15, 2026, Discord deleted the FAQ disclaimer that identified Persona as the vendor, which intensified user suspicion. By late February 2026, Discord confirmed the partnership was over and set a new requirement that any facial age estimation partner process data entirely on-device. Discord stated that Persona did not meet that standard, and delayed its global age assurance rollout to the second half of 2026.8MediaPost. Discord Ditches Age Verification Partner Following Backlash9Biometric Update. Discord Apologizes for Persona Snafu, Delays Global Age Verification Rollout
On February 16, 2026, a security researcher operating under the handle @vmfunc published findings that uncompressed frontend code belonging to Persona had been left publicly accessible on a subdomain, onyx.withpersona-gov.com, exposing 2,456 files of readable frontend code. The researcher reported that the code referenced 269 distinct verification checks, including facial recognition against watchlists and politically exposed persons, adverse-media screening across 14 categories, risk and similarity scoring, and code paths that appeared to facilitate filing Suspicious Activity Reports to FinCEN and screening crypto addresses via Chainalysis.7Malwarebytes. Age Verification Vendor Persona Left Frontend Exposed10DL News. OpenAI KYC Provider Persona Accused of Sharing Users’ Crypto Addresses With FinCEN
Persona disabled the subdomain the day of the notification. In a post-incident review, the company said the exposed files were frontend source maps from a non-production environment, and that no secrets, credentials, backend systems, or customer data were affected. Song said the frontend contained a “superset” of features, meaning many of the 269 capabilities existed in the codebase but were not necessarily used by any single customer.11Persona. Post-Incident Review: Source Map Exposure Non-Production Subdomain12vmfunc.re. The Watchers, Pt. 2
Neither the Discord episode nor the frontend exposure is part of the BIPA lawsuit. They involve different users, different jurisdictions, and different legal frameworks. They matter to the case only as context: they are the reason the retention and consent questions at the heart of Washington are receiving broader attention than a typical BIPA action.
Where the Case Stands
With arbitration off the table, Persona now has to defend the biometric claims in Illinois court. The central factual question will be whether Persona publicly maintained a compliant retention and destruction policy for facial geometry data collected from DoorDash drivers, and whether it obtained the informed written consent BIPA requires before collection. The size of any recovery, if the plaintiffs prevail, will turn on the classification of violations as negligent or reckless, on the size of the certified class, and on whether the August 2024 amendment collapsing repeated same-method scans into a single violation applies to the reverification selfies at issue.