AI Photo Apps and Privacy: What to Look For
The five questions worth asking before you upload a photo of your face, where the answers are usually buried, and what the answers should look like.
Uploading a photo of your face is not the same as uploading a photo of your lunch, and the policies that govern it are usually written at a level of abstraction that makes the difference hard to see.
This is what to look for, and roughly where to find it.
The five questions
1. Are my photos used to train models?
The most consequential question, because training is the one thing that cannot be undone. Deleting a file removes the file. It does not remove whatever that file contributed to a model's weights.
What a good answer looks like: an explicit statement that uploads are not used for training, or a clear opt-in that is off by default.
What to be wary of: silence, or broad language about "improving our services", which is doing a lot of work in a small number of words.
2. How long are my photos kept?
There is a real difference between processing an image and discarding it, and storing it indefinitely in a gallery you may never revisit.
Look for a stated retention period. Look also for what happens to backups, which commonly persist on a separate schedule after you have deleted something — thirty to ninety days is typical and reasonable, but you want it stated rather than assumed.
3. Who else sees them?
Almost no photo app runs its own models. Your image is likely handled by:
- A model provider, which does the actual generation
- A cloud storage provider
- Possibly an analytics or crash-reporting service
None of that is alarming. But it means the app's policy is not the only one governing your photo, and a good policy names the categories of recipient rather than gesturing at "trusted partners".
4. Can I actually delete things?
Three separate capabilities, often confused:
- Delete a single result
- Delete all content but keep the account
- Delete the account and everything with it
Check that the one you care about exists, and whether it is available in the app or requires emailing someone. Requiring an email is not disqualifying, but it is friction, and friction is how deletion quietly never happens.
5. What metadata travels with the upload?
The one most people never consider. A photo straight from a phone carries EXIF data: GPS coordinates accurate to a few metres, the exact timestamp, the device model and often a device identifier.
A careful app strips this before the image leaves your phone. Most policies do not mention it either way. If it is not stated, assume it is not happening, and strip it yourself if the location matters.
Where these answers live
Not, usually, in the app store listing. The privacy label there is a summary written by the developer and it is coarse.
The actual answers are in the privacy policy, and the sections worth reading are typically titled something like How we use your information, Data retention, Sharing and disclosure, and Your rights. Search the document for the words "train", "retain", "delete", "third party" and "vendor" — that gets you to the substance in under a minute without reading the whole thing.
What good looks like
A policy that answers the five questions above in language a person can act on, states periods in numbers rather than adjectives, names categories of recipient, and does not rely on a broad "improve our services" clause to cover training.
Kitana's own answers, for what it is worth: photos are used to produce your result and nothing else, EXIF including GPS is stripped before upload, deleting a result in the app removes it from storage, and emailing support from the address you want removed gets your data deleted. The full text is in the privacy policy, which is the document that actually binds — not this paragraph.
The practical version
If you are about to upload a photo of your face somewhere and you have thirty seconds:
- Search the privacy policy for "train". Read that sentence.
- Search for "retain" or "retention". Read that sentence.
- Decide.
That catches the two things that matter most and takes less time than picking a filter.
For the broader question of how to pick between apps on more than privacy, see how to choose the right AI photo app. The related question of what you owe other people when you edit photos of them is in the ethics of AI-generated photos.
Frequently asked questions
- What is the single most important thing to check?
- Whether your photos are used to train models. This is the term with the most lasting consequences, because training is not reversible — once an image has contributed to a model's weights, deleting the file does not remove its influence. Look for an explicit statement, and treat silence as a no answer rather than a yes.
- Does deleting my account delete my photos?
- Not automatically, and not always completely. Policies commonly distinguish between deleting your account, deleting your content, and purging backups, which can run on a separate schedule of thirty to ninety days. If it matters to you, look for a stated retention period rather than assuming.
- Do these apps send my photos to other companies?
- Most do, because most do not run their own models. Your photo typically goes to a model provider, and possibly to a cloud storage provider and an analytics service. That is not inherently bad, but it means the app's privacy policy is not the only one that applies to your image.
- Is EXIF data a real concern?
- Yes, and it is the one most people miss. A photo straight from a phone can carry GPS coordinates, the exact time, and the device identifier. Good apps strip this before upload. If an app does not say whether it does, assume it does not.
- Are free apps worse for privacy than paid ones?
- Not reliably, but the incentive differs. A paid app has a revenue model that does not depend on your data. A free one may or may not. Read the policy either way — plenty of free apps are careful and plenty of paid ones are vague.
- What about apps that process photos on my device?
- On-device processing is genuinely better for privacy, because the image never leaves your phone. The trade-off is capability: the models that run on a phone are smaller than the ones that run in a data centre, so results are usually more limited.
Ready to put this into practice?
Create with Kitana using the tool that fits this guide.
Try photo creationReady to try it yourself?
Download Kitana and create your first AI photo in under a minute.