If your app uses Face ID or similar biometric matching, that data has to stay within Apple's local authentication APIs — it can't be captured, stored, or transmitted for any other purpose, including a custom facial-match feature.
Apps trying to build a custom facial-recognition feature, rather than using Face ID purely for unlock or authentication, run into this almost immediately during review.
"Your app uses facial recognition technology for a purpose other than device authentication, without complying with applicable privacy requirements, per guideline 2.5.13."