Privacy
Memorisation, and how likely it is for a scoring model
Generative models have reproduced training images; a scoring model outputs numbers, which makes extraction far harder but not a non-question.
Guides on Privacy: Who could see it, how, and what each path costs to close, Soft delete, backups, caches and logs, Sometimes, and the policy clause that says so is easy to miss
A generative image model can leak a training image: researchers have prompted some into reproducing one almost exactly. A scoring model is far less likely to, because it outputs a number rather than pixels, and that difference matters more than most discussions of "does AI remember my photo" admit.
Two kinds of model, two kinds of risk
A generative model's entire job is to produce images, so its output space is images, and if it memorised a training example strongly enough, that memorised example can be its output. Carlini et al. (2023) demonstrated exactly this for diffusion models, using a generate-and-filter pipeline to "extract over a thousand training examples from state-of-the-art models" - a result that got wide attention specifically because it showed memorisation is a real, measurable failure mode and not just a theoretical worry.
A scoring model's output space is a number, or a small vector of per-axis numbers. Whatever the model "remembers" about a training image is compressed down to a scalar rating before it ever reaches you, and there is no mechanism in a standard scoring architecture that turns that number back into pixels. This is why extraction from a discriminative model is structurally harder than from a generative one: the information bottleneck between "what the model learned" and "what you can see" is far narrower.
Harder does not mean impossible
The narrower bottleneck rules out casual regurgitation - nobody uploads a photo to a rating tool and gets back someone else's face - but it does not rule out every attack. Model inversion, the research area concerned with reconstructing inputs from a trained model's outputs and internals, has shown partial success against classifiers under specific conditions: repeated, high-precision queries against the same model, sometimes with access to internal gradients rather than just the final number. Fredrikson et al.'s 2015 work on model inversion against a facial recognition classifier is the reference result here, and it worked against a system with far more accessible internals than a typical black-box rating API exposes to a user. The realistic risk for a scoring tool sits closer to what can be recovered from a stored embedding than to full image extraction from the trained model itself, because an embedding retains more of the original signal than a single output number ever does.
What would have to be true
For meaningful extraction from a scoring model to be a practical concern rather than a research curiosity, several things would need to line up: the model would need to have overfit rather than generalised, meaning it memorised specific examples instead of learning the general pattern - overfitting is its own failure mode with its own symptoms - an attacker would need repeated, structured access to the model's outputs for the same or related images, and the training set would need to be small or repetitive enough that any one image carries disproportionate weight in what the model learned. Large, diverse training sets dilute any single image's influence on the final weights, which is part of why well-resourced training pipelines actively avoid overfitting rather than only being lucky enough to avoid it.
What this does and does not settle
None of this means a scoring model's training data is unrecoverable in every configuration, and it is not a reason to treat the question as closed. It means the realistic threat model for a rating tool is different from the one that made headlines for generative models, and conflating the two overstates one risk while potentially understating the other - the embedding-reconstruction question is the one worth taking seriously here, not verbatim image regurgitation. Whether uploading trains a model at all is the prior question this one builds on, since a model that was never trained on your photo in the first place has nothing to extract regardless of the architecture.
Where to look for the honest version
Rate Cock states its position on training use directly in its privacy documentation, which is the first thing worth checking before worrying about a second-order extraction risk that only applies if training happened at all. Measurement data carries a parallel but different risk profile, since a number in centimetres does not memorise the way an image can, and the two should not be assumed to behave the same way under the same attack. Comparing how tools describe their model architecture and training practices is exactly the kind of feature comparison Penis Rater's tool coverage exists to make easier, and a stated training policy is one of the more informative rows once you know what question it is actually answering. A human reviewer carries none of this risk in the same technical sense, since a commissioned judge is not a trained model that can memorise anything - the analogous concern there is about a person's own memory and notes, which is a different kind of question entirely.