Opening a personal wellbeing app can be as quick as looking at your phone. That familiar gesture hides several different questions: who is unlocking the device, which account is being accessed, and what happens to the information after sign-in?
Biometrics and passkeys are different things
A biometric check compares a physical characteristic, such as a fingerprint, with an enrolled reference. A passkey is a cryptographic credential used to sign in. In FIDO authentication, a biometric or device PIN can authorize use of that credential; the biometric data stays on the device rather than being sent to the website.[1]
A face or fingerprint prompt does not automatically mean an app uses passkeys. An app could use device authentication to unlock a local screen or an existing session. To understand what is protected, look for the service’s description of the sign-in method rather than judging by the animation on your phone.
Three useful distinctions
- Authentication asks whether this account access should be accepted.
- Authorization decides which information or actions the account may use.
- Privacy governs collection, purpose, sharing, and retention after access.
What a passkey sign-in can look like
A simplified FIDO example
The service sends a challenge
The website asks your authenticator to prove it holds the appropriate credential. It is not asking for a copy of your face.
You approve on your device
A supported biometric, PIN, or other local method unlocks use of the credential. The available options depend on the device and provider.
The service verifies a signature
The authenticator signs the challenge. The service verifies the result with the public key registered for that account.
FIDO passkeys can be synchronized through a credential provider or bound to a single device or security key. Those choices affect recovery and portability. “The biometric stays local” does not mean every kind of passkey is permanently confined to one phone.[2]
Why recovery deserves equal attention
Imagine replacing a broken phone. A sign-in method is only useful if you can regain legitimate access without making account takeover easy. Before relying on an app for personal notes, check how a lost device is removed, how access is recovered, and whether you can review other active sessions.
NIST’s digital identity guidance treats biometrics as sensitive information, not secrets, and supports their use under specific conditions alongside a physical authenticator. It also calls for a non-biometric alternative. This is an engineering standard, not a claim that every consumer app meets those requirements.[3]
Questions for an app or credential provider
- Can I use an accessible alternative if a biometric check does not work for me?
- What happens if my device is lost, damaged, shared, or replaced?
- Does a sensitive action require a new check, or rely on an old session?
- How do I revoke access from a device I no longer control?
- What protections apply to any account used to synchronize credentials?
What biometric sign-in cannot promise
It does not establish that an AI response is correct, that the account holder has consented to every new data use, or that a conversation will remain private under all circumstances. It also does not tell you whether messages are retained or sent to a model provider. Those need separate answers and controls.
How this relates to a wellness companion
MiAngel’s GMAI architecture treats identity and consent as separate questions in a governed interaction. That distinction matters: knowing which account made a request should not become permission to use every available memory. Evaluate the actual controls and privacy terms of the service you use. A product diagram is an explanation, not a security certification.
Common questions
Does a passkey require my fingerprint?
Not necessarily. Supported devices can use a PIN or another local verification method. Check the options available with your authenticator.
Can I change a fingerprint like a password?
A physical characteristic is not a replaceable password. This is one reason biometric handling, local processing, and alternative access methods matter.
Does secure sign-in make an AI a therapist?
No. Account security and clinical qualifications are different. A wellness companion does not become professional healthcare because it has a strong login method.




