Topic
Privacy
What happens to a photo you upload to an AI tool, and what to check before you do.
-
A partial face is enough for a face-recognition system
Face-matching models work from far less than a full face, so an edge of one in frame is a linkage risk that cropping fixes and blurring may not.
-
Model improvement often means human eyes
Training data needs labels, and labels usually come from people, so 'used to improve the model' can mean a contractor viewed the image.
-
A promise with several possible mechanisms behind it
The sentence can mean in-memory processing, short TTL storage, or storage of derivatives, and each is a different privacy outcome.
-
Inversion attacks, and what they recover
An embedding is lossy, but research has shown partial reconstruction from some models, so 'we only keep the vector' is a weaker promise than it sounds.
-
Crop, filter, export - and the EXIF is often still there
Most editors preserve metadata by default because photographers want it, so an edited export is not a cleaned one.
-
What a VPN covers in an upload
A VPN changes the address the service sees; it does not touch metadata, account linkage, payment or fingerprinting, which is most of the risk.
-
Synthetic data avoids uploads, with its own catch
Some teams train on generated images so no user photo enters training, which is a real privacy gain and a real accuracy trade.
-
A device identifier hiding in MakerNotes
Some cameras and phones write a body or sensor serial into metadata, which links every photo from that device to each other.
-
The privacy question is not only yours
An upload of another person's image raises consent and lawfulness questions that no policy of the tool resolves for you.
-
C2PA metadata, and what it discloses
Some cameras and apps now sign photos with provenance data that can include device and edit history, which is a new field to strip.
-
The mechanics behind 'we have deleted your data
A deletion request triggers a process, and how thorough it is depends on whether the service can find every copy it made.
-
Clicking a link tells the next site where you came from
Browsers send the referring URL by default, so following a link from a results page can disclose that page to the destination.
-
Edge caches hold images after the origin forgets them
An image served through a CDN can sit at edge nodes past its deletion at the origin, until the cache expires or is purged.
-
The payment processor knows who you are
An anonymous account becomes a named one at checkout, and the linkage lives with the processor and in the service's records.
-
The result can appear where anyone can read it
Push and email notifications preview their contents on the lock screen and in inboxes, so the score can be seen without unlocking anything.
-
IP, time, path, size, and sometimes more
Every request leaves a log line, and the line often includes enough to link an upload to a device even when the image itself is gone.
-
The photo stays; the result and telemetry may not
Running the model on your phone means the image never uploads, but results, crash reports and analytics can still leave, so read what does.
-
Metadata is not only an EXIF thing
PNG images can hold text fields, editing history and even prompts from generation tools, and most stripping advice forgets them.
-
No account is not the same as no identifier
An upload without an account still arrives from an IP address at a time, and that pair narrows a person down more than most people assume.
-
Inventory the data first, then judge the risk
A breach exposes whatever was retained: files, derivatives, results, emails, logs; the harm depends on which of those the service kept.
-
Your camera roll may already be on a server
If photos sync automatically, the image reached a cloud provider before you chose to upload it anywhere, under that provider's terms.
-
How image search matches, and what it needs
Reverse search finds near-duplicates well and different-photo matches poorly, so the risk depends on whether the same file was ever posted elsewhere.
-
Data region, jurisdiction and what it means for a photo
The country a file is stored in decides which rules govern it, and most services do not say, which is itself an answer.
-
A time-limited link is a capability, not a login
Many services hand out signed links to stored files; anyone holding the link can open it until it expires, and the expiry varies wildly.
-
Debugging pipelines capture inputs
When inference fails, some systems save the failing input for engineers, and that path is rarely covered by the retention promise.
-
The tag on the page reports the visit somewhere else
Third-party analytics and ad scripts see the page URL and often the visitor identity, so the visit is known to more than the site.
-
A rule on a bucket, not a person pressing delete
Most services store uploads in object storage with automatic expiry rules, and the rule's setting is the real retention period.
-
Location is the headline; the rest is the fingerprint
A photo file carries camera model, serial number, lens, software version and timestamps, and together they identify a device even without coordinates.
-
Cropping the photo does not always crop the preview inside it
Many files carry a small preview image in their metadata, and some editors leave it untouched, so the original framing rides along with the crop.
-
Internal access controls are the part you cannot verify
Encryption and deletion aside, the question is which staff can view stored images and whether access is logged, and few policies say.
-
A still that carries a short clip and its own metadata
Live and motion photos bundle a video segment with the still, and uploading the bundle uploads the seconds around the shot.
-
Shareable links carry the thing they share
A result URL that encodes the score or an image ID can be read from history, logs and referrers, so the link itself is data.
-
Strip EXIF before you upload anything
Your camera writes your location into the file. Removing it is quick, permanent, and worth doing before any upload rather than after.
-
Browser and device traits as an identifier
A site can recognise a returning browser from its configuration alone, so clearing cookies does not make two uploads unlinkable.
-
TLS protects the wire; it does not protect the server
A padlock in the browser means the upload was encrypted on the way; what happens once it arrives is a separate question with a separate answer.
-
Hashing identifies; it does not hide
Storing a hash instead of an image is described as privacy-preserving, and it is - unless the point of the hash is to recognise the same photo again.
-
What actually happens to a photo you upload
The file leaves your device, and where it goes next varies enormously between tools. What to check, and what the answers should be.
-
Who could see it, how, and what each path costs to close
Listing the realistic paths from upload to unwanted exposure turns a vague worry into a short set of checks, most of which are cheap.
-
Soft delete, backups, caches and logs
Deleting a file from an app removes a pointer; the bytes can persist in backups, caches and logs for as long as each is retained.
-
Sometimes, and the policy clause that says so is easy to miss
Some services use uploads to improve their models, some do not, and the sentence that tells you which is usually not where you expect it.