What Happens to the Photos You Upload to an AI Photo Tool?

A phone gallery with several selfies selected, mid-upload

Somebody on a review site put it more plainly than any privacy policy ever will. He had uploaded twenty photos to get six accepted, and he wrote: "The fact that they probably keep all 20 to feed their AI means there doesn't seem to be an incentive to fix that."

He is not being paranoid. He handed his face to a website he found yesterday, and nothing on the page told him where it went.

This is the answer he should have been given.

The chain, step by step

An upload passes through four places, and each one is a different question.

Your device → the tool's storage. The photos leave your phone and land in the company's infrastructure. They stay there, because they have to: the reference photos are what every later generation is built from. A tool that deleted them after the first batch could not make you a second one.

Storage → the model. This is the step almost nobody mentions. Very few of these companies run their own image model. They send your reference photos and your scene choice to a large provider — Azure OpenAI, OpenAI, Google, or similar — which generates the picture and sends it back. Your face leaves the company you bought from.

Back to storage. The results are saved alongside the references.

Storage → wherever else. Marketing pages. Example galleries. A public feed. Training runs. This is the step that varies most between companies, and the step they write about most vaguely.

"We don't train on your data" is the sentence that matters

It is also the sentence most often missing.

Watch for the difference between these two:

We may use your content to improve our services.

We do not train AI models on your uploads or generated images.

The first covers training and usually means it. The second is a commitment that can be held against them.

And if the tool sends your photos to a third-party model — which, as above, most do — it needs to say what that provider does too. The major API providers do not train on data sent through their APIs by default. That is a real protection, and it is also a thing the tool should be telling you rather than leaving you to look up.

The gallery problem nobody warns you about

There is a quieter risk than training, and it catches people who would never have agreed to it.

Many of these products have a community feature: share a result, get feedback, vote on other people's photos. It is a reasonable thing to want. But on some platforms, pressing that button also moves your photo into the pool the company draws on for its own marketing — the examples page, the ads, the landing page.

Those are two different permissions and they get bundled into one tap. Consenting to strangers rating your photo is not consenting to appear in an advertisement.

If a tool has a share or feedback feature, the thing to check is whether "public to other users" and "usable by us in marketing" are separate settings. Often they are the same one.

What a delete actually deletes

Three levels, and only one of them is real:

  1. Hidden from your gallery. The file is still there. This is the most common.
  2. Results deleted, references kept. Your generated photos go; the twenty selfies that made them stay.
  3. Everything, irreversibly. Uploads, results, derived data.

Only the third is deletion. And a tool that makes you email support to get it is telling you something about how the rest of the data is handled.

The four questions

You can assess any of these tools in about two minutes:

1. Does the privacy policy contain the word train, in a sentence that says they don't? If the word is absent entirely, that is an answer.

2. Does it name the third parties your photos are sent to? Not "trusted partners" — names. If they cannot name them, they have not thought about it.

3. Is there a delete button, and does it say what it removes? Look for the word reference or source alongside generated.

4. Were you asked before the first generation? A consent screen before your face is transmitted anywhere is a sign that somebody thought about the order of operations.

What we do, including the part that leaves

Since this article is on our site, the fair thing is to answer our own four questions.

Your reference photos are stored in our own infrastructure and are private by default — they are never shown publicly, and they are deliberately excluded from our examples gallery. They are not sold, not published, and not used to train models, ours or anyone else's.

And they do leave, for one purpose. To generate an image, we transmit your reference photos and your scene selection to Microsoft Azure OpenAI or OpenAI. The results come back to us and are stored in our own infrastructure. Both providers are contractually bound to equivalent data protection and do not train on this data. The app asks for your explicit permission before the first generation, because that transmission is the thing you are actually agreeing to, and it should not be buried.

If you use selfie verification, the selfie and a match score are kept for that purpose only. To choose the best reference photos we may derive facial-structure descriptors from your uploads. Used only to make and verify your own photos — never for advertising.

And you can delete them.

We would rather tell you that your photos leave for inference than let you assume they don't. Every tool in this category does something like it. The ones worth using say so.

The short version

Your photos are kept — they have to be. The real questions are whether they are used for anything beyond making your pictures, who else receives them, whether a share button quietly doubles as a marketing release, and whether delete means delete.

Ask those four before you upload, not after. The answers take two minutes to find, and a tool that makes them hard to find has already answered.

Reconnecting…