Privacy
The privacy question is not only yours
An upload of another person's image raises consent and lawfulness questions that no policy of the tool resolves for you.
Guides on Privacy: Who could see it, how, and what each path costs to close, Soft delete, backups, caches and logs, Sometimes, and the policy clause that says so is easy to miss
A rating tool has no way to know whether the person in a photo agreed to it being uploaded or scored. Every privacy question on this site so far has assumed the photo is of you, uploaded by you, and when that does not hold, the tool cannot tell the difference.
What the tool can and cannot know
A scoring pipeline receives a file, an embedding gets computed, a number comes out. Nothing in that process carries information about who is in the photo relative to who uploaded it, or whether the person in frame knows it was sent anywhere. Face detection, where it exists, identifies that a face is present, not whose account it belongs to. A tool built to score images structurally cannot verify consent, because verifying consent requires information - a second person's agreement - that never enters the pipeline in any form. How a photo is expected to be framed and handled is written with the uploader's own image in mind, and none of that guidance extends to establishing who else has a stake in the frame.
Why this matters more here than elsewhere
An intimate photo of another person carries the same server-side questions as any other upload - who sees it, how long it is kept, where it is stored - except now a second person's exposure depends on a decision they did not make. What "deleted" means once a file reaches a server applies to them as much as to the uploader, without their having agreed to any of it. Where the boundary of acceptable use of someone else's image sits is a social and legal question with real weight, and it belongs with people equipped to answer it properly rather than with a site about how scoring pipelines work. The law has been moving on it: in the US, the TAKE IT DOWN Act (Public Law 119-12, May 2025) requires covered platforms to remove nonconsensual intimate images "not later than 48 hours" after a valid request, with the process due within a year and enforced by the FTC. Rate Penis's etiquette coverage takes on the social side of that question directly, and it is a better next stop than anything technical here.
What does not change
The mechanical facts stay the same regardless of whose photo it is. Whether a body photo without a face counts as personal data does not depend on who took it or who uploaded it - the answer turns on identifiability, and a photo of someone else can be just as identifiable as a photo of yourself, sometimes more, since the uploader may not know what marks, settings or context make it recognisable to people who know that person. The retention, sub-processor and licensing questions covered elsewhere on this site apply to the file itself, not to who sent it.
The honest summary
A tool cannot ask a second person for consent it never has any way of soliciting, and a policy written for uploaders does not become a policy about people in photos just because the two are sometimes different. That gap is worth naming once and leaving there, since the accuracy and honesty of any given score is a separate matter from whether the photo should have been uploaded at all, and general practice around photos with more than one stake in the outcome is a question this site is not positioned to settle, only to flag.