This isn’t the only possible way to do it, but I believe it’s the most common and effective approach.
So it’s not at all unlikely that when running the identifier, they simply don’t match against people who say no to this. They’d never be recognized at all, and the system would just identify their face as an “unknown” identity.
I cannot say for sure whether or not this is how they implemented it, but it seems likely.