Everyday Privacy9 min read·

What AI Image Generators Actually Do With Your Uploads

GS
GhostShield VPN
A woman wearing a face mask focuses on her laptop screen in dim lighting, highlighting remote work.
Photo by Engin Akyurt on Pexels
Continue reading

The upload is the part people skip

Most of the privacy conversation about AI tools is about what you type. The prompt box feels like the risky part, so that is where attention goes. But the higher-stakes action is quieter: dragging a photo in. A prompt is a sentence you wrote. A photo is a real place, a real face, and a file that has been quietly recording things about you since the moment it was taken.

Once that file leaves your device it is subject to whatever the service's terms allow, and those terms vary far more than the interfaces suggest. Two tools that look identical can have completely different answers to "is this stored, who can see it, and does it train the model."

Three different questions, usually answered as one

When people ask "is it private", they are actually asking three separate things, and services routinely answer only the easiest one.

Is it retained? Almost always yes, at least temporarily. Generation is asynchronous, so the file sits on a server while the job runs, and it typically stays in logs and caches afterwards. Retention windows in 2026 range from 24 hours to indefinite. "We do not sell your data" is not an answer to this question, and it is frequently offered as though it were.

Can a human see it? Usually yes, under defined conditions. Trust-and-safety review, abuse investigation, and support access are near universal. This is not sinister, it is how you stop a service being used for things it should not be used for, but people are consistently surprised by it. If a policy mentions "review for compliance with our acceptable use policy", humans can see your uploads.

Does it train the model? This is the one that actually varies, and it is where you have leverage. Consumer tiers frequently train on uploads by default. Paid and business tiers frequently do not. Some offer a toggle. Some offer a toggle that only covers future uploads and not the ones already ingested.

Mobile phone on a gray surface showing cat and flower images on screen. Photo by Airam Dato-on on Pexels

How to read a policy in about two minutes

You do not need to read the whole document. Search it for five specific words and you will learn more than a full read-through would tell you.

  • "train" or "improve our models". This is the training question. If you find it without a nearby opt-out, assume your uploads train the model.
  • "retention" or "delete". Look for a number. A policy with no retention period is telling you there isn't one.
  • "human review". Confirms whether staff or contractors can open your files.
  • "affiliates" or "third parties". Determines whether "we don't sell your data" still allows sharing it.
  • "biometric". If you are uploading faces, this word decides whether the strictest category of privacy law applies to what you just did.

If a service will not answer these plainly, that is itself the answer. The tools that do not train on your uploads say so prominently, because it is a selling point.

Strip the metadata before it leaves your machine

Separate from any policy is the data you are handing over without meaning to. A photo straight off a phone typically carries EXIF metadata: GPS coordinates accurate to a few metres, the exact timestamp, the device model, and sometimes the serial number.

This means an innocuous photo of a living room can carry your home address in a field nobody looks at. Uploading it to any service, AI or otherwise, hands that over alongside the image.

Stripping it takes seconds. On iPhone, share the photo, tap Options at the top, and turn off Location. On Android, open the photo in Google Photos, tap the info panel, and remove the location. On Windows, right-click the file, go to Properties → Details, and choose Remove Properties and Personal Information. On macOS, open in Preview, then Tools → Show Inspector and delete the GPS entry. Do this before uploading anywhere. It costs nothing and it removes the single most sensitive field in the file.

For the broader picture of what your photos give away, our guide to stopping photos revealing your location covers the same problem outside of AI tools.

Close-up of tower servers in a data center with blue and red lighting. Photo by panumas nikhomkhai on Pexels

What good practice looks like from the tool's side

It is worth knowing what a well-configured service looks like, so you can recognise one. The bar is not especially high, and plenty of tools clear it.

Uploads are encrypted in transit and at rest. Retention is a stated number of days rather than "as long as necessary". Training on user uploads is off by default on paid tiers, or at minimum is a real toggle that covers past uploads too. Human review is scoped to abuse investigation rather than general quality sampling. Deletion actually deletes, including from backups, within a stated window.

LArtist AI, which we also build, sits in this category, and the reason we mention it here is narrower than a recommendation: it is a useful reference for what the policy language should look like when a tool is not training on your uploads. Compare whatever you are using against that shape rather than against marketing copy. The disclosure matters because we have an obvious interest, and you should weigh the comparison accordingly.

The practical rules

If you take nothing else from this: strip metadata before uploading, assume retention unless a number says otherwise, and check the training question specifically rather than trusting a general privacy reassurance.

Beyond that, be deliberate about categories. Faces of people who did not consent, documents with identifiers, anything involving children, and images of the inside of your home are all worth a second thought before they go into a generation queue. Not because something bad will definitely happen, but because you cannot un-upload a file, and the retention policy you agreed to today is the one that governs it.

A VPN protects the connection those files travel over, which matters on networks you do not control. It does not change what a service does with a file after it arrives. Those are different problems and it is worth being clear that one does not solve the other. For the connection half, our public WiFi risks guide covers where that actually matters.

Related Topics

AI image generator privacyAI photo upload dataAI training data opt outgenerative AI privacyphoto metadata EXIF

Keep Reading

Protect Your Privacy Today

GhostShield VPN uses AI-powered threat detection and military-grade WireGuard encryption to keep you safe.

Download Free