The 90s TikTok Trend Isn't a Scam. What's Been Happening for 20 Years Is Worse.
A viral TikTok post is warning millions of people that the "Hey Dad, what were you like in the 90s?" trend is an intentional data mining scam. It isn't. But the real story—the one the post accidentally gestures at without ever finding—is considerably worse.
The post in question, published by user @davidturkell, has accumulated over 49,000 likes and 8,800 reshares. It displays an organizational chart linking Cambridge Analytica, Steve Bannon, the SCL Group, the Mercer family, and the Trump campaign, then concludes: "This trend is just another data mining scam created to steal your information." The trend it targets is sentimental, accessible, and built around the Goo Goo Dolls' "Iris"—users posting current video of themselves alongside old photographs from the 1990s. Courteney Cox participated. John Stamos participated. In every measurable way, it is an organic cultural moment.
The Cambridge Analytica background in the post is broadly accurate as historical record. But the post uses it as a launchpad to make a causal claim it never proves: that this specific nostalgia trend was intentionally designed as a harvesting operation. That leap is not supported by evidence. You cannot manufacture a viral trend. You can spend millions trying, and most of it dies on the vine. The 90s nostalgia format caught because it tapped into something real—the specific bittersweet emotion of watching your parents' youth in photographs, of understanding they were once your age. That is not a psyop. That is human nature.
What you can manufacture—slowly, methodically, over decades—is policy. And that is the story the post never tells.
Verdict: Misleading
The "Hey Dad, what were you like in the 90s?" trend shows no evidence of being an intentionally designed data mining scheme. However, the underlying concern about biometric data exposure when uploading photos and videos to social media platforms is entirely legitimate—and far older and more systemic than this post suggests. The post gets the alarm right and the diagnosis wrong, which is its own kind of misinformation.
Our research into the real data privacy landscape around social media photo and video uploads reveals a pattern that predates TikTok, predates Cambridge Analytica, and predates the smartphone in your pocket. It begins in 2006 with a quiet corporate acquisition that almost nobody noticed at the time.
In August of that year, Google purchased a company called Neven Vision—a biometric specialist with patents centered on face recognition from digital photos and video. Two years later, in September 2008, Google deployed that technology inside Picasa Web Albums under the friendly name "Name Tags." The feature automatically scanned your uploaded photos, detected faces, grouped them by similarity, and invited you to label them. It was marketed as a convenient way to organize your memories. People thought it was remarkable. Bloggers marveled at its accuracy. Almost nobody asked what Google was doing with the resulting biometric data on the back end.
Facebook watched and followed. In December 2010, the platform launched a facial recognition feature called "Tag Suggestions," automatically generating biometric identifiers from uploaded photos without notifying users or obtaining consent. By 2015, a class-action lawsuit was filed. Facebook eventually settled for $650 million in January 2020. Their facial recognition system, called DeepFace, was reported to be 97% accurate—more accurate than the FBI's own system at 85%. Facebook announced it was shutting the feature down. What they did not announce was that they were keeping the underlying algorithm. And with Meta's pivot into virtual reality headsets requiring eye-tracking and face-tracking, the infrastructure for biometric collection did not disappear. It evolved.
Then came TikTok. In June 2021, the platform quietly updated its U.S. privacy policy to state that it "may collect biometric identifiers and biometric information" from users' content—including what it described as "faceprints and voiceprints." The policy did not define those terms. It did not explain why the data was needed. It stated only that TikTok would seek user consent "where required by law"—a carefully chosen phrase that, given only a handful of U.S. states have biometric privacy laws, effectively meant the majority of American users could have their biometric data collected without being asked. The ACLU raised alarms. TechCrunch pressed TikTok for answers. TikTok declined to provide them.
Privacy experts were unambiguous about why this mattered. Unlike a compromised password or a stolen credit card number, a faceprint cannot be changed. Your face is permanent. If that data is breached, misused, or sold, the exposure follows you for life. There is no reset button.
This brings us to the TikTok sale—and a question worth asking out loud. The U.S. government's stated reason for forcing a divestiture of TikTok from its Chinese parent company ByteDance was national security: the concern that Beijing could access data on 200 million Americans. In January 2026, a deal was finalized creating TikTok USDS Joint Venture LLC, with Oracle, Silver Lake, and MGX taking controlling stakes, and U.S. user data moving into Oracle's cloud infrastructure. The biometric data collection language remains in TikTok's live privacy policy. The data did not disappear. It changed hands. Whether access to one of the largest biometric databases ever assembled on American citizens played any role in the urgency of that acquisition is a question the public record does not definitively answer—but it is a question the public record absolutely supports asking.
Nobody was tricked in a single moment. Everybody was gradually acclimated over twenty years.
The slow boil runs like this: In 2006, Google acquires biometric specialist Neven Vision—almost no public attention. In 2008, facial recognition arrives in Picasa Web Albums as "Name Tags" and users call it cool. In 2010, Facebook launches "Tag Suggestions" using facial recognition on uploaded photos, without user notice or consent. Between 2015 and 2020, the class-action lawsuit against Facebook plays out, settles for $650 million, and the underlying algorithm survives. In 2021, TikTok quietly claims the right to collect "faceprints and voiceprints"—most users never read it—and separately pays $92 million to settle a class-action for using facial recognition to identify users' age, gender, and ethnicity without consent. In January 2026, TikTok is sold to a U.S. investor consortium led by Oracle, the biometric data collection language remains active in the privacy policy, and 200 million Americans participate in a nostalgia trend, uploading decades of photographs of their own faces. Most call it fun.
TikTok is not alone in this. The practice of collecting facial biometric data from user-uploaded content—packaged as convenience features—is industry-wide. The 90s nostalgia trend is simply the latest in a long line of occasions where millions of people voluntarily uploaded high-quality images of their own faces to platforms with the legal right to process them.
The @davidturkell post is trying to do something useful. It is trying to make people pause before they participate in a trend. That impulse is exactly right. But by framing the problem as an intentional scam—implying a bad actor engineered this specific trend to harvest data—the post actually makes the real problem harder to see.
Scams are discrete. You can avoid a scam by being alert to a specific trick. What has actually happened over the past twenty years is not a scam. It is normalization. The tech industry has spent two decades slowly acclimating hundreds of millions of people to handing over their most permanent biological identifiers, one delightful feature at a time. Name your friends in photos. Tag yourself. Make a face movie. Try this filter. Show us what you looked like in the 90s.
No single moment felt like a betrayal. Each one felt like a small, pleasant convenience. That is precisely what makes it more dangerous than any viral scam. There is no obvious villain. There is no single moment you should have refused. There is only a long, quiet policy that was normalized while you were busy enjoying the app.
The media literacy lesson here is not simply "be careful about trends." It is broader and more important: be at least as skeptical of features that feel useful and fun as you are of posts that feel alarming. The danger in the digital age rarely arrives looking like a threat. It arrives looking like a new way to organize your photos.
The danger in the digital age rarely arrives looking like a threat. It arrives looking like a new way to organize your photos.
Read the privacy policy. Not because it is enjoyable reading—it isn't—but because the fine print is where the real story has always been. And understand that every photo or video you upload to any social media platform, as part of any trend or no trend at all, carries with it the same underlying exposure. The 90s nostalgia trend did not create this problem. It just gave it a Goo Goo Dolls soundtrack.
Sources consulted: TechCrunch reporting on TikTok's 2021 biometric policy update; TikTok U.S. Privacy Policy (active); ACLU analysis of TikTok biometric data collection; TIME expert analysis of faceprint and voiceprint exposure; Wikipedia and BetaNews on Google's acquisition of Neven Vision and the Picasa facial recognition launch; EPIC documentation of the Facebook Tag Suggestions class action; BuzzFeed News on Facebook's algorithm retention and Meta VR biometric collection; NPR and The Hacker News on the TikTok USDS Joint Venture formation (January 2026); El Estoque on TikTok's post-sale privacy policy; ISACA on the permanence of biometric data in the age of AI; Distractify on the "What were you like in the 90s?" trend.
Written with Claude.ai assistance for research synthesis and structural editing.
— J.L.L.