TL;DR: A user completing Sony PlayStation age verification through Yoti on a GrapheneOS device was told their phone had been "automatically reported to both the authorities and our security team." Yoti says the screenshots are fabricated. GrapheneOS calls it "customer support making ridiculous claims." But the bigger story is what new academic research reveals: Yoti, which handles age checks for Meta, TikTok, Sony, and OnlyFans, broadcasts your facial photos, device fingerprints, and IP addresses to credit card companies, geolocation services, and data brokers. Spain already fined Yoti $1.1 million in March 2026 for mishandling biometric data. Age verification is becoming a surveillance funnel, and privacy-focused users are the canaries in the coal mine.
The Allegation: "Your Device Has Been Reported"
In early June 2026, a Reddit user named PaiDuck tried to verify their age through Yoti for Sony PlayStation. They were using GrapheneOS, an open-source Android operating system built for security and privacy. The verification failed.
When they contacted Yoti support, the response was alarming. According to screenshots posted to Imgur and shared across forums, a Yoti support agent wrote: "Yoti automatically flags [...] any devices running GrapheneOS. These instances are automatically reported both to the authorities and our security team" [1].
The screenshots spread fast. Reddit threads, YouTube videos, the GrapheneOS community forum, and tech news outlets all picked up the story. The implication was clear: use a privacy-focused phone, and a private company will report you to law enforcement.
Both Sides Say the Other Is Wrong
Yoti denied it. A senior company official emailed GrapheneOS directly, stating they "believe the screenshots of the exchange to be fabricated" and could not locate any record of the communications. The company said it would "never report any user to the police or any other third party based on their choice of operating system or device" [2].
GrapheneOS took a middle position. The project called the support message "fearmongering based on customer support making ridiculous claims to someone" rather than actual company policy. But they acknowledged the technical reality: GrapheneOS is detectable through standard Android APIs like hardware attestation and Google Play Integrity, which return failed verdicts for any non-Google-certified operating system [3].
Community investigators also flagged credibility issues with the original poster, noting a history of posts about bypassing age verification systems. The allegation might be fabricated, exaggerated, or the result of a rogue support agent making things up to close a ticket [2].
But whether this specific incident happened exactly as described is almost beside the point. The reaction it provoked, and the research it surfaced, reveals something much worse.
The Real Problem: Your Face Goes to Data Brokers
On May 20, 2026, researchers from the Georgia Institute of Technology and the University of California, Irvine presented "Papers Please: A First Look at Age Verification on the Web" at the IEEE Symposium on Security and Privacy in San Francisco [4].
Their findings are damning. Yoti, which handles age checks for roughly 60% of websites requiring verification, broadcasts sensitive personal information to third and fourth-party companies during the verification process. That includes facial photographs, device fingerprints, and IP addresses. The recipients include credit card companies, IP geolocation services, and data brokers [4].
As lead researcher Michael A. Specter, an assistant professor at Georgia Tech's School of Cybersecurity and Privacy, put it: "What is really happening is the bartender is making photocopies of the patron's license and sending it to their food vendors" [4].
Think about that. You scan your face to prove you're old enough to play a video game. Your face, your device fingerprint, and your IP address get shipped to companies you've never heard of. Companies that have no relationship with you. Companies that aggregate and sell data for a living.
Yoti responded by publishing an open letter demanding the researchers retract their paper. As of June 10, 2026, the researchers and their universities have not issued any corrections [5].
Yoti's Track Record
This is not Yoti's first run-in with regulators. In March 2026, Spain's data protection agency (AEPD) fined the London-based company a total of €950,000 (roughly $1.1 million) across three separate GDPR violations [6]:
- €500,000 for unlawful processing of biometric special category data. Yoti claimed it used facial data only to authenticate users, not to identify them. The AEPD disagreed.
- €200,000 for invalid consent through pre-ticked checkboxes. Users were "consenting" to their biometric data being used in research and development without ever reading the policy.
- €250,000 for keeping geolocation data for five years, far longer than any reasonable purpose required.
Yoti rejected the decision "in the strongest possible terms" and is appealing to the Spanish High Court [7]. But the pattern is hard to ignore: a company that handles biometric data for some of the world's largest platforms keeps getting caught treating that data carelessly.
Age Verification as Surveillance Infrastructure
Yoti is not some fringe startup. It provides age verification for Meta, TikTok, Sony PlayStation, OnlyFans, Spotify, and dozens of other platforms [4]. When governments mandate age checks (25 U.S. states now have laws requiring them, plus the UK's Online Safety Act), Yoti is often the company that gets the contract [4].
That means a single London-based company is building one of the largest biometric databases on the planet. Every person who scans their face to use Instagram, watch TikTok, or play a PlayStation game is feeding that system. And as the Georgia Tech research shows, the data doesn't stay with Yoti.
The GrapheneOS incident, real or fabricated, exposed a structural truth: age verification systems built on Google's integrity framework treat any non-standard device as suspicious. Google Play Integrity returns a "failed" verdict for any phone that isn't running stock, Google-certified Android. That means GrapheneOS, LineageOS, CalyxOS, and every other privacy-focused Android variant gets flagged before the age check even starts [3].
The people most likely to use privacy-focused phones are the people who care most about not having their biometric data broadcast to data brokers. And the age verification system punishes them for it.
What You Can Do
- Know what age verification actually does. It's not just checking your age. It's collecting biometric data, device fingerprints, and IP addresses, and in Yoti's case, sharing them with unnamed third and fourth parties.
- Use a VPN when completing age checks. It won't stop the biometric collection, but it limits the geolocation data attached to your verification.
- Check if credit-card-based verification is an option. Some platforms offer alternatives to face scanning. A credit card check still involves data sharing, but it's a much smaller surface than a facial photograph.
- Push back on platforms that use Yoti. If you're verifying your age on PlayStation, TikTok, or Meta services, let them know you're aware of the Georgia Tech findings and Yoti's AEPD fine. Consumer pressure is what got Meta to strip facial recognition code from its smart glasses app.
- Support right-to-verify alternatives. Some proposals would let users verify age through privacy-preserving cryptographic proofs (zero-knowledge proofs) rather than biometric scans. The technology exists. The industry just hasn't been forced to use it.
- If you use GrapheneOS or similar, expect failed verifications on services that rely on Google Play Integrity. This is a feature of the verification system, not a bug in your phone.
The Bartender Is Photocopying Your License
The Yoti/GrapheneOS story broke because a user posted screenshots that may or may not be real. But the academic research is real. The Spanish regulatory fine is real. The data flowing from your face to unnamed data brokers is real.
Governments keep passing age verification mandates as "child safety" measures. Companies like Yoti keep winning the contracts. And every time you scan your face to prove you're old enough to use a website, your biometric data enters a pipeline you can't see, controlled by companies you've never heard of, stored for years longer than anyone told you.
The bartender is supposed to glance at your ID and hand it back. Instead, he's photocopying it and faxing it to his vendors. And if you walk in with a phone that takes privacy seriously, he's calling it suspicious.
Sources
- The CyberSec Guru: "Yoti Reported GrapheneOS User to Authorities" (June 2026)
- AlternativeTo: "GrapheneOS User Reported to Authorities by Age Verification Company Yoti" (June 2026)
- GrapheneOS Discussion Forum: Community response and official statement (June 2026)
- Georgia Institute of Technology: "Online Age Checks Create a Pointless Privacy Risk" (May 2026)
- Biometric Update: "Yoti challenges academic research, invites independent audit" (May 2026)
- Biometric Update: "Spain's AEPD fines Yoti $1.1M for biometric data handling violations" (March 2026)
- Yoti: "Yoti's response to AEPD sanctions and fine" (March 2026)