Defending against face search does not work the way most people picture it. They start with sunglasses, masks and tools that "poison" photographs — precisely the measures that deliver the least. The part that works is boring: a map of indexes, seven forms, a review schedule, and a conversation with your press office about which photos go into releases.

I approach this from the other side: we regularly reconstruct a digital footprint from a single photograph, so we know exactly where that footprint comes from. What follows is what I tell clients who ask how to remove themselves from face search — what genuinely closes, what closes halfway, and where a ritual is being sold as protection.

One clarification up front, so you don't chase a false goal. You cannot fully remove your face from the internet. The achievable goal is different: cut your exposure to a manageable level, shut off the inflow of new images, and get a signal when something new appears. Everything beyond that is marketing from services selling subscriptions to "removal from 47 databases."

The mirror image of this task — how the search itself is run — is covered in the piece on how to find someone by photo.


What is actually being searched: your face, not your photo#

The mechanics matter for one conclusion only, but that conclusion drives everything.

A face-search engine does not store your photographs. It crops the face and converts it into an embedding — a vector of several hundred numbers describing geometry: distances between landmarks, jaw shape, cheekbone ratios. Vectors are compared, not pictures. That is why you are found in different clothes, under different lighting, ten years later.

Three consequences follow, and the whole defense rests on them:

  1. Deleting a photo from a website does not remove you from the index. The vector already exists, stored separately from the source file. Two different actions are required: remove the source, and separately demand delisting from the face-search engine.
  2. An opt-out is delisting, not deletion. The service stops showing you in results. The photos stay where they were, and any other engine can index them again.
  3. Every new public image strengthens the index. Different angles produce different vectors, and the combination works better than any single shot. That is why controlling the inflow beats cleaning the archive.

Where your photos come from, and what you actually control#

The classic mistake is assuming this is about photos you posted yourself. For an executive or public figure, the main flow comes from third parties — and that flow decides whether you are findable.

Here is how I break the channels down by controllability during an audit.

Fully controllable. Social avatars and albums, messenger profile pictures, images on personal sites, the photo on your CV or career profiles, family posts featuring you. The fix is immediate: privacy settings and deletion.

Controllable by policy and contract. The "Team" page on the corporate site, annual reports and decks, conference speaker pages, press accreditation terms at your own events, contracts with photographers, employee posts with you in frame. This is not personal hygiene, it is corporate policy: one conference with an open photo report feeds the index more than a year of careful social media behaviour.

Practically uncontrollable. Media archives, industry Telegram channels, stock photo libraries, guest photography at events, frames where you appear in someone else's background.

A practical illustration: in March 2025 an OSINT author published a walkthrough identifying security staff purely from open press-service photo archives, then tracked one individual across several events. None of those people had posted their own photo. Their faces entered the index through official event publications — a channel that closes only through policy.

The conclusion to accept before doing anything else: for a public person, retroactive cleanup hits a ceiling, and the payoff comes from controlling the inflow. Organisational measures work slowly, but they are the only part that compounds over a year. How to fold this into a wider perimeter is covered in OPSEC in practice for executives.


Index map: where your face sits and how each one closes#

This is the core of the article. There is no unified mechanism: every service has its own channel, requirements and burden of proof. I verified the addresses below by hand on 26 July 2026 — several popular guides list them incorrectly, and the request simply never arrives.

Map of face-search indexes: PimEyes and Lenso close through an opt-out form, FaceCheck.ID by selfie, Search4Faces by email, while FindClone has no public mechanism
There is no single button: every engine has its own removal channel and its own burden of proof.
IndexRemoval channelWhat you needWhat actually happens
PimEyesopt-out form — opens without an accountface photo (several angles is better), anonymised ID scan, email, 18+ confirmationyour face is delisted from results; sources remain online
PimEyes, single imageexclusion button directly in the resultsnothing beyond stating a reasonone image drops out of results; per vendor documentation, within 48 hours of approval
FaceCheck.IDremoval pagea selfie (automated, faster) or an anonymised ID (manual review)hidden from new searches immediately, permanent deletion in 1–5 business days
Lenso.aiopt-out formface photo, country, reason, first name, surname, email and phone; no ID requiredthe service states removed faces are not re-indexed — a commitment no other engine makes
Clearview AIprivacy and requests hub, OneTrust formsresidency in a US state from the list on the site itself — it changes, so check before filingno practical mechanism for everyone else; the site also returns 403 to some visitors, so you may need a different connection to open it
Search4Facesemail to search4faces@gmail.com (the optout.html page routes to contacts)a description of which images to removethe service's stated turnaround is within a day; there is no standalone web form
FindCloneno public channel foundthe only lever is closing the source profile
Yandex Images"report this image" in results, plus Webmaster → page removalgrounds: personal data, right to be forgotten, unlawful content, plus evidenceno access to the source site required; once removed at source, the image leaves the index in 2–3 weeks
Social networks feeding avatar-search enginesprivacy settingsdisable face recognition and tagging, restrict profile visibility to logged-in users, switch the profile to privatecloses future collection but does not roll back snapshots already taken

Three points matter more than the table itself.

Sequence matters. Close the sources you control first, then file opt-outs. In the reverse order the index simply refills: you get yesterday's images delisted and tomorrow's freshly indexed.

A PimEyes request is not a legal demand. The public form has no country field and no legal-basis field: the procedure is built on identity verification. This breaks the advice circulating in English-language guides ("cite GDPR Article 17 or you will be rejected"). If you are not in the EU, that basis is not yours to cite — but the service has nothing to reject you on either, since jurisdiction is not part of the flow. State a legal basis only if GDPR, CCPA or BIPA genuinely applies to you; otherwise treat it as a verification process and move on.

Regional services close differently. Invoking a national data-protection law against a foreign engine goes nowhere — it is not an operator in your jurisdiction. Meanwhile some regional engines have no form at all but do have a working email channel, and others have neither, leaving source privacy as the only lever.

How to file so the request goes through#

The rejection mechanic is simple, and once you understand it the guesswork disappears. The service runs your reference photo through its own model against the candidates in the index. If similarity falls below threshold, the request fails — the system was not convinced you are you.

Hence the requirements, which are engineering rather than bureaucracy:

  • a recent photo, front-facing, nothing covering the face. Sunglasses, hats, masks and low resolution are the most common reason for rejection;
  • several angles are better: the blocking vector is built more accurately;
  • file multiple requests with different photos from different years rather than one perfect one. The index holds several versions of you, and one request may close only part of them.

One fork that no popular guide addresses: ID anonymisation requirements differ between services. PimEyes asks you to redact the scan per its own instruction, while some sources insist the name must stay visible. Do not carry one service's instruction over to another — read the requirements on the specific form. And with FaceCheck.ID, prefer selfie verification and do not send a document at all.

On cadence: the "refile every month" advice comes from services that sell monthly filing by subscription. The defensible rule is to refile when new results appear, with frequency driven by your review schedule rather than the calendar.

The fork: disappear or watch#

There is a non-obvious consequence that even paid removal services stay quiet about — it does not suit them.

PimEyes alerts (notifications when a new photo of you appears) only work if your face is not opted out — stated outright in the service's own FAQ. The logic is straightforward: the engine cannot search for what it has forbidden itself to show. So the choice is strategic:

The face-search defense fork: opting out of every engine removes your monitoring, keeping one engine as a sensor preserves visibility of new publications
Disappear everywhere or keep one engine as a sensor — the choice is strategic, not technical.
  • Blind protection. Opt out everywhere. Strangers stop finding you, but you also stop seeing what appears. Sensible when the main threat is mass curiosity and stalking.
  • Sighted monitoring. Keep one engine as a sensor and close the rest. Sensible for a public figure whose photos are unremovable anyway — there, speed of detection is worth more.
  • The hybrid I recommend by default. Opt out of the engines strangers use to find you, keep access to one engine for your own audits, and add external sensors not tied to your face: name alerts, company mention monitoring.

This is a separate class of risk. It is not about face-search engines but about state and corporate systems, and it closes with different levers. Most English-language guides ignore it entirely; readers outside the US and EU are left with nothing.

National biometric systems. Where a country runs a centralised biometric registry, there is usually a statutory right to withdraw consent and demand deletion of the biometric template, exercised through the state's digital services portal or an in-person application. In Russia that right comes from Federal Law 572-FZ of 29 December 2022, with the route running through the Gosuslugi portal or an MFC office.

Banks are a separate perimeter, and this is the common mistake. Withdrawing consent in a central registry does not delete biometrics held inside individual banks. A separate application goes to every bank where you enrolled. Statutory deadlines are worth citing in that application — Russian law, for instance, gives the operator ten business days to stop processing on demand (extendable by five with a reasoned justification) and up to thirty days to destroy the data once consent is withdrawn. Expect one caveat everywhere: anti-money-laundering rules oblige banks to retain client identification records for years, so the realistic target is the biometric template, not your entire file.

Face recognition at office and building entrances. A face used for identification is biometric personal data, and processing it generally requires explicit written consent specifying the operator, purposes, data categories and retention period. The practical lever is twofold: demand the alternative access method that policy must provide (card or pass), and withdraw consent already given. Regulators have treated office-entry biometrics as personal data and required access-control systems operating without proper consent to be brought into compliance.

Deindexing images. Search engines offer two channels: reporting an image directly in image results, and a webmaster-style removal request citing grounds such as personal data or the right to be forgotten. Access to the source site is not required. Once the photo is removed at source, it leaves the image index in roughly two to three weeks. The wider process is covered in how to delete yourself from the internet.


What breaks recognition, and what only looks like protection#

This is where the mythology lives, so let me lead with the argument that is missing from nearly every consumer guide.

At ICLR 2022, Radiya-Dixit and co-authors published "Data Poisoning Won't Save You From Facial Recognition", testing attacks against Fawkes and LowKey — the two best-known photo cloaking tools. The finding is structural rather than version-specific: the user perturbs a photo once and for all, while the adversary can simply wait. Once the image is scraped, any future model — trained adaptively or merely newer — retroactively strips the protection. There is no arms race here: the defender gets one move, the attacker gets unlimited moves.

Which gives an honest scorecard:

MeasureAgainst internet indexesNote
Fawkes, LowKey (cloaking)future publications onlylast Fawkes release is 1.0, April 2021; not a shield against 2026 engines
Glazeirrelevantprotects artists' style, not faces; constantly confused with the above
Sunglassesuseless for already published photosagainst street cameras, better than a mask: they cover the periocular region, the most informative for the model
Medical maskbarely worksmodels were deliberately retrained on masked faces after the pandemic
Makeup, head turn, new hairstyle, weight changedoes not workembeddings are largely invariant to these
CV Dazzle, patterned clothingdoes not workdesigned against a previous generation of detectors
Not publishing a clean frontal photoworksthe most underrated measure
Reducing the number of public imagesworksevery new angle strengthens the index
Blurring other people's faces before postingworksa direct Privacy International recommendation

A useful calibration for anyone waiting on a technical fix: EFF offers no individual disguise advice in its face-recognition work at all and criticises the opt-out paradigm itself, arguing for opt-in consent. Privacy International calls the mask a symbol of resistance rather than practical protection. Both agree the burden should not sit on the individual — but while it does, effort is better spent on sources than on pixels.


Monitoring: paid and unpaid#

Detection matters more than prevention, for the simple reason that not everything can be prevented.

Paid tier. PimEyes bundles alerts into its subscription, and the spread is wide (figures from the official pricing page as of 28 July 2026, billed monthly): Open Plus at €33.99 with up to 75 searches a day and 10 alerts; PROtect at €38.99 with up to 125 searches and 20 alerts plus reports and result management, with removal-request support (Takedown Agent) sold separately at €13.99 a month; Advanced at €330.99 with unlimited searches, 500 active alerts and full Deep Search. Note what you are buying even at the top tier: monitoring of your face, not removal of it from anywhere. Lenso offers alerts too, but creating an alert is precisely what makes the service store your image permanently — monitoring costs more than money.

Unpaid tier is a schedule, not a tool:

  • once a quarter, run yourself through two or three engines (one face-search plus a general image search) using 3–5 photos from different years and angles;
  • alerts on your name and its transliterations;
  • a check after every event where you spoke;
  • log results in one file — what matters is the delta between checks, not any single snapshot.

And one thing to know immediately: you cannot find out who searched for your face. Public services offer no such function. It surfaces only indirectly, through breaches — in June 2026 law enforcement gained access to the user data of a popular lookup bot, meaning the record of who searched for whom. The practical takeaway: use legitimate engines even when they cost money, and never grey bots, not even to check yourself. A related habit is checking whether your data has been breached, which catches a different class of signal.


If your face is already being used#

Three different scenarios with three different mechanisms — they get mixed up constantly.

Synthetic intimate imagery and sextortion. The working preventive mechanism is StopNCII.org: the image hash is generated on your own device and the image itself never leaves it. The hash is shared with participating platforms — Facebook, Instagram, TikTok, Reddit, Snap, Bumble, OnlyFans, PornHub, Threads — which block matching uploads. Per the operator, over 500,000 images belonging to 200,000 people are covered, and more than 10,000 upload attempts have been prevented.

Deepfakes using your face, from the fake-executive scam to advertising you never recorded. Regulation is in flux: several jurisdictions are still moving from framework AI rules and content-labelling requirements toward specific criminal liability, so in most places there is no dedicated offence to point at yet. In practice you work through general offences, platform complaints and civil claims.

A specific photo on a specific site. The sequence: a demand to the site owner and data controller → a complaint to the data protection regulator → deindexing in search → a civil claim over the unauthorised use of your image if needed.

What to do in the first 24 hours: document before you delete. Preserve evidence (notarised inspection of the page or archiving), collect every copy through reverse image search, and only then file complaints. Anything removed without documentation cannot be produced later. Check the current police reporting route and notarisation costs at the moment you file — both shift, and a mistake here costs you the evidence.

What not to do: mass-delete your own accounts (you lose your control points while third-party copies survive) and react publicly before documenting — attention will grow faster than the material disappears.

The perimeter is wider than one face#

Approaches to a principal usually run through the people around them, so protection built around one individual is porous by design.

  • Children. Since October 2023 PimEyes states that it blocks searches for minors and proactively excludes such data. No independent testing of that block exists, so treat it as a vendor promise rather than a guarantee — and note that other engines do not even make the promise.
  • Posting about children supplies material not only for recognition but for voice and video deepfakes: the standard pressure play is a generated "message from your child."
  • Assistants, drivers, security, contractors. Their posts routinely include you in frame or allow the context to be reconstructed: place, time, route.

The practice is simple: the publication policy extends to the immediate circle and is written into the rules rather than requested verbally. The baseline settings a whole family should start with are in 10 digital hygiene mistakes.


Priority order: what pays off and what is a ritual#

The consolidated checklist. It is ordered by effort-to-result, not by ease.

Face-search defense priorities: auditing, closing sources, opt-outs and deindexing pay off, while cloaking and physical disguise deliver almost nothing
Ordered by effort-to-result: the two bottom items, where most people start, deliver the least.
#ActionEffortImpact
1Audit: run your face through 3–4 engines and record what surfaces30–60 minuteshigh — everything else is blind without it
2Close the sources you control: avatars, tags, old posts, personal sites1–2 hourshigh — cuts off index growth
3File opt-outs with the engines where you were found1–2 hoursmedium-high — delisting, not deletion
4Remove and deindex sources: site owners, webmaster tools, regulator complaintsdays to weekshigh but slow — the only thing that truly removes a photo
5Biometric perimeter: withdraw registry consent, file with banks, demand a non-biometric access option1–3 hoursmedium — closes a different class of risk
6Monitoring: alerts or a quarterly self-check routinesubscription or 30 minutes a quartermedium — detection instead of prevention
7Organisational measures: event photo policy, accreditation terms, contractor requirementsweekshigh over a year
8Cloaking new photos1–2 hourslow — future publications only
9Physical disguiseclose to zero for internet indexes

Almost everyone who asks how to block face search starts at items 8 and 9 — the exact two that deliver least. The first four lines can be done in a single working day and account for most of the result.

When the perimeter is complex — a public role, a family, a team, a regular event calendar — this becomes a project rather than an afternoon: our security and risk consulting starts with precisely the audit in line one.


FAQ#

Can I fully remove my face from the internet?#

No. An opt-out removes your face from one service's results but does not delete photos from the sites hosting them, and does not stop another engine from indexing those same photos. The achievable goal is to cut exposure, shut off the inflow of new images, and get alerted when something new appears.

Do sunglasses and masks help?#

Against street cameras, partly: sunglasses beat a medical mask because they cover the periocular region, the most informative area for the model. Against a search based on an already published photo they do nothing — the system already has that image.

Do Fawkes and other cloaking tools still work in 2026?#

As insurance for future publications, partly. As protection for what is already online, no. The last Fawkes release was version 1.0 in April 2021, and the ICLR 2022 paper exposed a structural flaw in the whole class: the photo is perturbed once, while the adversary's model can be retrained at any time.

Yes. Withdrawal at the registry level does not touch banks' internal systems. A separate application goes to each institution where you enrolled your biometrics.

Can I find out who searched for my face?#

Public services offer no such function. It only surfaces through breaches — in June 2026 law enforcement obtained the user data of a popular lookup service, including the record of who searched for whom. That is also the argument against using such bots even to check yourself.