Privacy
The phrases that should stop you
Some clauses are boilerplate; a few, in a tool that handles intimate images, are decisive, and they are easy to list.
Guides on Privacy: Who could see it, how, and what each path costs to close, Soft delete, backups, caches and logs, Sometimes, and the policy clause that says so is easy to miss
Five phrases in an image tool's privacy policy deserve a slow read: a perpetual, sublicensable licence; unnamed affiliates and partners; "to improve our services" with no training carve-out; retention with no duration; and silence on sub-processors. The rest is mostly boilerplate that applies to any web form.
The licence grant
Almost every service needs some licence to your upload just to process it - to store it in a database, resize it, run it through a model. The phrase to watch for is how far that licence extends beyond processing. "Perpetual", "irrevocable", "sublicensable" and "royalty-free" stacked together in one grant is broader than anything needed to run a scorer, and each word does separate work: perpetual means it does not expire when you delete your account, sublicensable means the company can hand the right to someone else, irrevocable means asking later does not undo it. A licence scoped to "operating and improving the service, for the duration your account is active" is doing a real, narrower job.
"Affiliates and partners"
A policy that shares data with "affiliates" or "partners" without naming them is not committing to anything checkable. Affiliates can mean a parent company, a shell entity, or a firm acquired next year that inherits the user base and the licence along with it. The absence of a name is the tell - a company confident in a short, stable list of who sees the data usually names it.
"To improve our services"
This phrase is doing a lot of unstated work. It commonly covers using uploads as training data, and whether an upload trains the model is frequently answered somewhere other than where you would look, which is itself worth noticing. "Improve our services" without a specific carve-out for training, and without an opt-out, should be read as training data unless the policy says otherwise.
Retention stated as a purpose, not a duration
"We retain data as long as necessary to provide the service" states a purpose and not a number. Purpose-based retention can be anything from a day to forever, and the policy is the only place that decides which, so a version of this clause with no accompanying figure anywhere - no days, no months, nothing - has told you nothing measurable. UK data protection law expects more: the ICO's guidance on the right to be informed lists the retention periods, and the recipients or categories of recipients, among the information a privacy notice must give. Reading a retention clause for the actual number is a separate, worthwhile pass once you have found where the number should be and is not.
No mention of sub-processors
Most scoring tools call at least one external service somewhere in the pipeline - a model API, a storage provider, an analytics vendor. A policy silent on sub-processors is not a policy where none exist; it is a policy that has not told you. Third-party inference calls are common enough in this category that their absence from a policy is more likely an omission than a genuine absence, and comparing how different tools disclose this is a faster way to calibrate what normal looks like than reading any single policy in isolation.
What a table of phrases implies
| Phrase | What it usually licenses |
|---|---|
| Perpetual, irrevocable, sublicensable | Rights that outlast your account and can be passed to a third party |
| Affiliates and partners, unnamed | Sharing outside the company with no accountable list |
| Improve our services, no carve-out | Use as training data, opt-out unlikely |
| Retain as necessary, no duration given | Retention period effectively undisclosed |
| No sub-processor disclosure | External vendors in the pipeline, unnamed |
Reading the whole thing once
None of these phrases is illegal, and most services use several of them for ordinary reasons - broad licences make lawyers comfortable, vague affiliate language covers restructuring that has not happened yet. Reading a policy you actually use against this list, rather than a hypothetical one, is the version of this exercise that pays off. The point of the list is not to find a villain; it is to read the five clauses that matter instead of the whole document, because a general checklist for what happens to an uploaded photo already covers the wider process and this is the narrower, phrase-level pass that sits underneath it. Once you can spot these five, a policy takes about two minutes to assess, and what a "we do not store your photos" claim can actually mean is a good next stop if a specific sentence looks like it is doing exactly this kind of work in the other direction. Whether the same standard applies to a human reviewing your photo rather than a model is a related but different question, and it lives with how a commissioned human review is handled rather than here.