Somewhere today, someone will open an AI chatbot, take a picture of their child, and upload it just to ask a simple question about it. They won’t think twice. Most people don’t. This is for them — and for anyone who has never been told what happens after they press send.
What Actually Happens When You Hit Send
Here’s what nobody tells you: when you upload a photo to an AI chat box, it doesn’t just get “looked at” and forgotten. It makes a journey, and most of that journey happens after you’ve already gotten your fun result back.
First stop — the waiting room. Your photo lands on the company’s server. Before the AI even touches it, it’s sitting there, saved, as a file. Like a photo dropped into someone else’s photo album, except this album belongs to a company you’ve never met.
Second stop — the makeover. This is the part you see: the cartoon version, the dreamy portrait, the “you as a Pixar character.” It takes seconds. Fun, right?
Third stop — the part you don’t see. Your original photo often stays behind. While you’re busy sharing your cute new portrait, the actual original upload may still be sitting on a server somewhere — sometimes for days, sometimes for much longer, depending on rules written in a privacy policy almost nobody reads. That’s not laziness; it’s human nature. Nobody reads terms of service written in dense legal language across dozens of pages.
Why “It Was Public Data Anyway” Isn’t Consent
The AI industry’s default assumption has been: if content is available online, it’s free to be collected, scraped, and used. The Brookings Institution calls this the “AI data gold rush” and notes the attitude is essentially that if content is available online or “in public,” it’s free for the taking.
But being publicly visible was never the same as consenting to AI training. A photo shared with friends a decade ago wasn’t posted so a machine could learn from it.
This isn’t theoretical, either. Companies including X, Zoom, and Google have updated their privacy policies to allow training AI models on scraped or user data — Zoom quietly altered its policy to claim rights over customer data for AI training, only backing down after public backlash. The FTC has warned that silently changing privacy policies to cover new AI uses of previously collected data may itself be unlawful.
Your Upload Can Expose Other People, Too
When you upload a group photo, a picture of your child, or a screenshot of a chat, you’re not just sharing your own data. You’re exposing other people who never agreed to anything at all.
Clearview is the extreme version of this. Your group photo upload is the everyday version of the same logic — and it has already happened at scale.
This Has Already Happened at Scale: Clearview AI
If this sounds paranoid, consider Clearview AI. A New York Times investigation in January 2020 revealed that this one company had scraped over 3 billion face images from social media Facebook, YouTube, Twitter, Venmo to build a facial recognition database sold to police. Since then, the database has grown to roughly 30 billion images, all scraped without the knowledge or consent of the people in them.
Regulators haven’t been quiet about it. The Netherlands fined Clearview AI for violating the EU’s GDPR, and France, Italy, and Australia have made similar rulings. Critics say it puts everyone into a “perpetual police line-up.”
Clearview is an extreme case, but it shows what becomes possible when “public” photos are treated as free raw material.
The Fine Print Nobody Reads
Here’s the thing most people don’t realize: the photo they upload for five minutes of fun often lives far longer than the trend itself.
What ChatGPT’s Retention Policy Actually Says
According to OpenAI’s own retention policies, your chats stay on their systems until you delete them — and even after you delete them, the data isn’t fully wiped for up to 30 days, longer if there’s a legal or security reason. OpenAI has also confirmed it’s been ordered to retain user data beyond its normal policy in response to litigation. Files, like uploaded images, can follow their own retention windows separate from the chat itself. So while the conversation “disappears” from your screen, your file may still be sitting on their servers for weeks.
What Google’s Gemini Does With Your Photos
Google’s own support documentation states that if you share a photo from your gallery or Google Photos with Gemini — and your “Keep Activity” setting is on — that photo can be used to improve Google services, with human reviewers possibly looking at it. Google’s technology retention policy notes that conversations selected for human review can be kept for up to three years, even after you delete your activity. Deleting the chat doesn’t reach into that pipeline and pull your photo back out.

Meanwhile, as AI Improves, It Improves Partly by Training on Our Data
Every Ghibli-style portrait, every “make me a Pixar character” selfie feeds that loop. And here’s where it gets unsettling: AI models don’t always forget your photo after learning from it.
Researchers have found that image generators like Stable Diffusion memorize some of the images they’re trained on and can spit them back out as nearly identical copies. In one study, when researchers prompted Stable Diffusion with the name of a real person, it reproduced the exact photograph from her Wikipedia page, almost pixel-for-pixel. The same research found the models could regurgitate copyrighted images and identifiable photos of real people on demand — raising privacy risks for anyone whose face ended up in the training data. Researchers studying Google’s Imagen model found similar behaviour, noting that images appearing many times in a dataset are far more likely to get memorized — exactly what happens when millions of people upload the same kind of trending selfie at once. Their advice? Don’t apply these models to privacy-sensitive imagery.
It’s not just the models — the archives behind them leak too. When Tumblr and WordPress struck deals to hand users’ posts over to OpenAI and Midjourney for training, internal documents revealed the data dump had accidentally included content that “should not have been included.” Your photos end up in systems governed by deals you never heard about.
The apps feel free because they are free, but you’ve heard the saying everywhere: if you don’t know what the product is, you are the product. You’re not paying with money — you’re paying with your face.
To be clear, this isn’t about blaming anyone. Nobody reads a 40-page privacy policy before joining a fun trend, and companies make sure the important details are buried deep. That’s exactly the problem. A Stanford study looked at the privacy documents of six major US companies — Amazon, Anthropic, Google, Meta, Microsoft, and OpenAI — and found that all of them process user inputs by default (training on your data unless you actively opt out), and that their privacy documentation is often so tangled and unclear that users genuinely can’t tell what they’ve agreed to. The researchers’ conclusion was simple: people should think twice about what they share with AI chats, and opt out where they can.
So no, this isn’t about blaming anyone for wanting a cute Ghibli version of themselves. It’s about noticing that most of us click “upload” subconsciously, the same way we accept cookies without reading them. The goal isn’t shame. It’s awareness. Once you know the photo goes on a journey without you, you can decide consciously whether that trade is worth it.
Who This Hurts the Most
Not tech-savvy people. Students, grandparents, small business owners — people who simply want an answer and don’t know the technical difference between an image processed and forgotten versus one stored indefinitely. Awareness alone can’t fix this; it will take regulation and industry norms, because expecting billions of users to read legal documents has never worked and never will.
What You Can Actually Do
Before uploading an image into any AI tool, pause and ask: “Would I be comfortable pasting this on a public wall?”
If the answer gives you even a little hesitation, then before you hit upload: check the service’s data and training policy; blur or crop faces and personal details; prefer services with strong, published privacy commitments — for example, services built with zero-access encryption that don’t train on user data; and never upload other people’s images, especially children’s, without a very good reason.
Nowadays, AI companies spend a lot of marketing telling us our data is safe and “in our hands.” Maybe some of them even mean it. But here’s a funny little story that shows exactly the world we’re living in.
The Meta Glasses Story
You’ve probably heard of Meta’s Ray-Ban smart glasses — the ones with a camera and microphone built in, marketed for vlogging your life. Except people are using them to film strangers without their consent. There have been real incidents of women discovering they’d been secretly filmed and posted in viral videos they never agreed to be in — “I had no say,” as one woman put it. Legal analysts have flagged the privacy exposure baked into always-on wearable cameras, and reporting suggests public pushback is starting to change behaviour around how openly people will film strangers with them. Meta’s own terms state that voice recordings, photos, and videos captured by the glasses are used to train and improve Meta’s AI models by default — so a stranger’s casual recording of you doesn’t just stay on their glasses. It can end up training a company’s AI.
And here’s the ironic twist the internet came up with: a viral trick called “copyright hacking” — if you suspect you’re being filmed by smart glasses, play a Disney song out loud. The theory is that when the recording gets uploaded to YouTube or Instagram, the platform’s automated copyright detection will catch the Disney song and block or mute the footage before it spreads. Even police departments got drawn into it — a city councilmember in Santa Ana, California caught one of their own officers playing copyrighted music specifically because “it will be copyright infringement for him” to record it.
Sit with the irony for a second: your face has no such protection. A stranger can capture your face, upload it, and it spreads freely. But a Disney song in the background gets the video blocked. In this world, a human face carries less legal weight than a corporate melody.
I’m not saying this to scare anyone — privacy in public was always a fragile thing, and we were never fully private anyway. What we can do is choose. What we share, what we upload, whose images we touch — that’s still in our hands. In a world that profits from everything you give away, choosing carefully isn’t paranoia. It’s power.
If this blog makes even one person pause before uploading, it did its job.
Sources & Further Reading
Chats, files & retention
- Chat and File Retention Policies in ChatGPT — OpenAI
- US Privacy Policy — OpenAI
- Response to NYT Data Demands — OpenAI
- Gemini Apps Privacy Hub — Google
- How Google Retains Data
Consent & policy changes
- The Case for Consent in the AI Data Gold Rush — Brookings
- Changing Terms of Service for AI Could Be Unfair or Deceptive — FTC
Clearview AI
- The Secretive Company That Might End Privacy as We Know It — NYT
- Face search company Clearview AI overturns UK privacy fine — BBC
- Netherlands fines Clearview AI for GDPR violation — Library of Congress
AI training & memorization research
- Study exposes privacy risks of AI chatbot conversations — Stanford News
- AI Spits Out Exact Copies of Training Images — Vice
- AI models spit out photos of real people — MIT Technology Review
- Stable Diffusion “memorizes” some images — Ars Technica
- Tumblr and WordPress to Sell Users’ Data to Train AI Tools — 404 Media
Meta glasses & the Disney song story
- Being filmed by Meta smart glasses? The internet says to play Disney music — Mashable
- Woman covertly filmed by Meta AI smart glasses — CBS News
- Smart Glasses and Privacy Risks — Purdue Global Law School
- Pushback against Meta’s ‘pervert glasses’ — Fortune