Yeah, "they" probably simply have our FaceID data that we're willingly collecting ourselves, supposedly for our own security.

Would be rather difficult for "them" to get it off my $80 CAD vertical flip phone, I dare say.

Face ID is entirely on device and it is cryptographically difficult to extract the data even with a jailbroken device.

Well, hopefully this is indeed the case!

i mean so they say? but really?