Privacy
Sometimes, and the policy clause that says so is easy to miss
Some services use uploads to improve their models, some do not, and the sentence that tells you which is usually not where you expect it.
The honest answer is that it depends on the service, and the sentence that settles it is rarely the one that uses the word "training." It is usually the one that says "to improve our services," which is doing more work than it looks like it is doing.
Why the question even has an answer to hide
Training a scoring model needs labelled examples: images paired with a rating, a rank, or a category that a human or an existing model assigned. A service already receiving a steady stream of uploads has an obvious, cheap source of exactly that material sitting in its own storage. Using it costs nothing extra to collect and improves the product the company is trying to sell, which is a strong incentive that exists whether or not a given service acts on it. Some do, some deliberately do not, and a few have not thought about it as a policy decision at all, which is its own kind of answer.
The two shapes a policy takes
Opt-out by default. The clause exists, uploads are used for improvement unless the user finds a setting and turns it off, and the setting is often several menus deep from the account page that shows results. This is the more common pattern across consumer AI products generally, not something unique to image-rating tools, and it follows the logic of any feature that is more valuable to the company the more people leave it on.
Opt-in only. Uploads are not used for training unless the user actively agrees, usually via a separate checkbox at upload time or in account settings, described in plain language rather than folded into a general terms-of-service paragraph. This pattern is rarer because it costs the company a smaller and more reluctant training set, but it is the version that treats the decision as the user's to make rather than the company's to assume.
A policy can also land between the two: training only on uploads flagged for public sharing, or only on a account tier that explicitly consents in exchange for a discount. The variations matter less than which of the two shapes the specific clause you are reading belongs to.
Where the sentence actually lives
Search a privacy policy for the word "training" and you will sometimes find nothing, not because the practice does not happen but because the drafting avoided the word. The functional sentence is more often phrased around "improve," "develop," "enhance our services," or "for research and development purposes," each of which can legally cover model training without naming it. That phrasing is not necessarily evasive - "improve our services" is standard boilerplate lifted across an entire industry - but it means a policy that never says "we do not train on your images" has not actually told you the negative. Absence of the word "training" is not absence of the practice; it is absence of the word.
The clause worth finding is the one that states a specific, checkable fact: whether uploads are used to train or fine-tune a model, whether that use is on by default, and whether it can be turned off without deleting the account entirely. A policy that answers all three in one place is unusually clear, and unusual is worth noticing.
What "opt out" actually opts out of
Even a working opt-out has edges worth understanding before relying on it. Turning off future training use does not retroactively remove images already used in a completed training run, because a model does not store its inputs in a form that can be selectively subtracted once training has finished - the images contributed to the weights and the weights are what remain. Whether a specific photo could ever be recovered from those weights is a separate, narrower question than whether it was used, and the two get conflated constantly in casual discussion of the topic. An opt-out is forward-looking: it stops new uploads from entering a future training set, and it is worth reading closely whether it also stops uploads already sitting in storage that has not yet been used, since "we will not train on this going forward" and "we have removed this from consideration" are different promises.
Why the clause matters more for this category of photo than most
The general advice to read a privacy policy applies to every kind of upload, but the stakes attached to an intimate image are not the same as the stakes attached to a photo of a receipt or a document. If a photo trains a model, in the narrow technical sense it does not sit in storage the way a file does - it contributes to weights that are then reused across every future user of that model, indefinitely, in a form nobody can extract a single image back out of on request. Whether that means a specific photo could ever be recovered again is a separate technical question from whether it was used at all, and the two get treated as one question by most people reading a policy for the first time, which is exactly where a service benefits from vagueness. The asymmetry is worth naming plainly: a user can ask a service to stop, and in some cases delete stored files, but a user cannot ask a completed training run to forget one input among millions once the run is finished. That makes the upstream decision - opt in or stay silent - more consequential here than for most categories of photo, because it is the one point in the whole pipeline where consent is still meaningfully revocable.
What labelling adds to the picture
Training on raw uploads is one path; a second, less discussed path runs through labelling. A model does not learn "good" or "bad" from a photo alone - it learns from a photo paired with a rating, a rank, or a category, and those labels have to come from somewhere. Some of that labelling is done by people reviewing submitted images directly, which means "used to improve the model" can translate concretely into a contractor viewing an individual upload, a detail that a policy focused only on whether "training" happens can leave out entirely. A service that says it does not train on uploads but does use them for internal quality review has answered a narrower question than the one most readers think they asked, and the labelling question is worth checking for separately rather than assuming it is covered by the training clause.
Third parties change the answer
Many image-scoring products do not run their own model end to end. A photo can leave the company that operates the website and travel to a separate inference provider, and once it does, that provider's own training policy applies alongside - not instead of - the website's. This routing is common enough to be worth understanding on its own terms, because a privacy policy that promises "we do not train on your data" can be entirely true about the operator and silent about the subprocessor actually running the model. The practical version of due diligence is checking both: what the site you uploaded to says, and whether it names which model or vendor does the actual scoring.
Where the honest version of this looks like
The clearest privacy policies on this specific point read like a short FAQ answer rather than legal boilerplate: a plain statement of whether training happens, a toggle if it is optional, and a note about what a toggle does and does not retroactively affect. A model card, where one exists, is the parallel document on the technical side - it is meant to state what a model was trained on, and a rating tool that publishes neither a clear training clause nor a model card has left the question fully to inference. None of this requires assuming bad faith from a provider that stays quiet on the point; ambiguity here is common across the industry, and reading the clause is simply the only way to replace an assumption with an answer.
A practical way to check
Search the policy for "train," "improve," "research," and "third party" or "subprocessor," in that order, and read the sentence each match sits inside rather than the heading above it. If none of those turn up anything specific, the honest conclusion is that the policy has not told you, not that the practice does not happen - a document's silence on a mechanism a company would benefit from is not evidence against that mechanism. Rate Cock states its position on this in its own privacy documentation, and checking the equivalent page on any tool before uploading is the same five minutes regardless of which service you land on. How to read a retention clause without a lawyer covers the same close-reading skill applied to storage duration rather than training use, and the two questions are worth running together since they usually sit in adjacent paragraphs of the same document.
Where this sits next to measurement and human review
None of this is specific to AI scoring in the sense that matters here: any service asking for an upload, a measurement, or a review submission has the same incentive to reuse what it collects, and the same obligation to say so plainly. Measure My Cock's data section covers the equivalent question for a submitted measurement rather than a photo, since a number entered into a form can be reused for aggregate statistics in ways that deserve the same disclosure a photo does. Comparing how different tools handle this, feature by feature, is the kind of side-by-side Penis Rater's tool coverage is set up to do, and a stated training policy is one of the more consequential rows in that comparison, more consequential than most of the features people compare first. Where a human judge reviews a submission rather than a model scoring it, the equivalent question is whether that reviewer's notes or the submission itself ever become training material for anything downstream, which Rate Penis's judge coverage addresses from the commissioning side, since a person's judgement is not reused the same way a model's weights are.
The underlying shape of the question does not change across any of these: something was uploaded, something might be reused to build a future product, and the only way to know which is true is to find the sentence that says so and read it as a specific claim rather than a general reassurance.