Does ChatGPT save your photos? How long AI tools keep them
· Written and maintained by Nonimo
Yes. ChatGPT saves the photos you upload, and so do Gemini, Claude and Microsoft Copilot. A photo is treated as part of the conversation, so it is kept for as long as the chat is kept. ChatGPT goes one step further: it also files your uploads in a separate Library, and OpenAI says deleting the chat does not delete that copy.
That matters most for the photos people take without a second thought: a drivers licence for a rental application, a passport for a new employer, a power bill, a letter from the ATO, a script from the GP, a screenshot of a bank transfer. A picture of a document hands over everything on the paper, including the parts your question never needed, and a few things that are not on the paper at all.
This guide sets out what each of the four says it keeps from an uploaded image, for how long, whether it trains on it and whether a person can look at it. Every period comes from the provider’s own pages, read on 3 October 2026, and where a provider does not say, neither do we.
The last sections cover what the Privacy Act asks of a business, and how to cover a licence on your phone with the NSW licence tool before it goes anywhere.
Does ChatGPT save your photos?
Yes, and in two places. OpenAI’s file uploads FAQ says files uploaded to ChatGPT “are saved in your account up to the retention period of the corresponding chat”. Regular and archived chats stay saved until you delete them, so a photo in a chat you never clear stays for as long as the account does.
The second place is newer, and most advice about ChatGPT has not caught up with it. ChatGPT now has a Library, and OpenAI’s help page says it “automatically saves uploaded and created files, including files uploaded in chats”, with images named in the list. Library is on Free, Go, Plus, Pro and Business, and in Enterprise, Edu and Healthcare workspaces.
None of that is hidden, and OpenAI’s pages are clear about it. The problem is habit. People who clear a chat after a sensitive question believe the photo went with it, and since Library arrived that belief is wrong. Our guide to whether ChatGPT saves your data covers the rest of what OpenAI keeps from a conversation.
Deleting the chat does not delete the Library copy
This is the line to read twice. OpenAI’s Library page puts it plainly: “Deleting a chat containing files does not delete those files saved to Library.” Its page on chat and file retention says the same thing in other words. Clearing the chat clears the conversation, and the photo you sent in it stays where it was filed.
Library files are kept “until you delete them manually”. When you do, they move to a recently deleted area first and are then scheduled for permanent deletion from OpenAI’s systems within 30 days. On Enterprise, Edu and Healthcare workspaces, Library follows the workspace’s own retention policy instead, which the administrator sets.
So when someone asks whether ChatGPT saves your photos after the chat is gone, the honest answer is yes, unless the Library copy went too. If you have used ChatGPT for a while, open Library and look before you assume anything is gone. A licence photo from last year’s rental application may still be sitting there, next to the payslips that went with it.
Pictures ChatGPT makes live somewhere else
Images that ChatGPT generates for you are a separate case. OpenAI saves them under Images, and to delete one there you delete the conversation that created it. That rarely matters for a photo of a document, but it explains why clearing Library does not clear everything visual in an account.
How long ChatGPT, Gemini, Claude and Copilot keep a photo you upload
No provider runs a separate clock for photos on a personal account. An uploaded image is content in the chat, and it follows the chat. The differences are in the defaults, in what deletion reaches, and in the copies that sit outside your history. Our guide to which AI tools a business can use under the Privacy Act sets the same four side by side for text.
| Personal account | How long the photo stays | After you delete it | What can outlive deletion |
|---|---|---|---|
| ChatGPT | until you delete the chat, and the Library copy until you delete that | removed within 30 days | the Library copy, if you only delete the chat |
| Gemini | 18 months by default; 3 months, 36 months or never if you change it | Google says deletion generally takes about 2 months | a chat picked for human review, up to 3 years |
| Claude | until you delete the chat | removed from the back end within 30 days | a training copy, up to 5 years, if model improvement was on |
| Copilot, older app | files no longer than 18 months | not stated separately | not stated |
| Copilot, updated app | not stated | not stated | not stated |
Sources: OpenAI, Google, Anthropic and Microsoft help and privacy pages, read 3 October 2026, each listed under Sources below.
Gemini: photos go into your Activity
Google’s Gemini Apps Privacy Hub, last updated 24 September 2026, says your chats and what you share with Gemini, “like files, videos, screens, and photos”, are saved in your Activity. Gemini uses Google Lens technology to understand what is in an image and to read its text, so a photographed letter is read much like a typed one.
The review copy is what changes the picture. Google’s privacy notice says chats reviewed by people, with related data such as location info, “are not deleted when you delete your activity”, and the hub adds that data reviewed by service providers is disconnected from your account. Deleting the photo from your history does not reach a copy that has already been pulled for review. Our guide to whether Gemini shares your data goes through the rest of Google’s settings.
Claude: photos follow the chat or the project
Anthropic’s privacy policy, effective 10 September 2026, calls anything you upload your Inputs. A file can go into a single chat, or into a project’s files, where Anthropic says it stays for reference across conversations. When you clean up, check both places.
Two clocks sit outside the table. If a classifier flags a conversation under Anthropic’s usage policy, it keeps the inputs and outputs for up to 2 years, and the safety scores for up to 7. Rate a reply or report it, and the data tied to that feedback is kept for 5 years. A photo in that conversation is part of its inputs. The Claude guide explains each clock in turn.
Microsoft Copilot: two apps, two rulebooks
Since 18 August 2026 Microsoft has published two sets of consumer pages, one for an updated Copilot app and one that, in its own banner, “applies only to the older version”. Which set describes your photos depends on which app you have, and the two should not be mixed.
The older app has the only photo rule with a shorter life than the chat. Microsoft says screenshots and camera images shared with Copilot Vision “aren’t stored after your session ends”. For the updated app, its pages say prompts, responses and “your file contents” are not used to train foundation models, and they say nothing about how long a file is kept.
Across both, Microsoft’s general privacy statement, last updated September 2026, lists “images and related data, like picture metadata” among what it collects when you upload an image to Copilot. It also says ads may be shown that relate to your Copilot conversations, including files you share. The Copilot guide explains how a work account changes that.
Does ChatGPT save your photos in Temporary Chat? Private modes compared
Three of the four offer a way to chat without building a history, and all three still keep something for a while. A photo sent in a private chat is part of that chat, so it gets the same treatment.
OpenAI’s answer to whether files uploaded in a temporary chat go to Library is a flat no: they “are not saved to your account or Library”. The catch is the save button. If you later save a temporary chat that had files in it, OpenAI says eligible files may be saved to Library at that point. Either way, it may keep a copy of a temporary chat for up to 30 days for safety purposes.
Claude’s incognito chats are kept for 30 days for safety, and Anthropic says they are not used for training. Gemini’s temporary chats, and any chat with Keep Activity switched off, are kept with your account for 72 hours. Google says temporary chats are not used to improve its AI with help from human reviewers, and also that, with Keep Activity off, it still uses chats to protect Google, its users and the public, including with help from human reviewers.
Short is not the same as nothing
A private mode changes how long the photo stays in the provider’s systems. It does not change the fact that the photo arrived there. For a business that is the moment the Privacy Act cares about, as the section below explains, and a 72 hour window is still a disclosure. Details covered before the upload never reach anyone, which is what the tool does on our page for the Victorian licence.
Do AI tools train on your photos, and can a person look at them?
On a personal account, images mostly follow the same training rules as text. What changes from one provider to the next is the default, and whether people can see the content.
| Personal account | Trains on uploads by default | People who may look | How to stop the training |
|---|---|---|---|
| ChatGPT | yes, images and files included | authorised staff and trusted service providers, as needed | turn off Improve the model for everyone |
| Gemini | yes, while Keep Activity is on | human reviewers, including from service providers | turn off Keep Activity, or use a temporary chat |
| Claude | as your setting says; the default is not stated | a small number of staff involved in model training | turn off model improvement in settings |
| Copilot, older app | yes, unless you opt out | reviewers, with no opt out from review | Copilot’s training controls |
| Copilot, updated app | not for foundation models | not stated | nothing to switch for foundation models |
Sources: OpenAI, Google, Anthropic and Microsoft pages listed under Sources, read 3 October 2026.
OpenAI is the most explicit. Its page on consumer data says it may use “other content such as images and files to improve model performance”, and its image inputs FAQ says its approach to images is the same as for everything else. Google announced in August 2025 that, with the setting on, a sample of uploads submitted from 2 September 2025 would be used to help improve its services.
The one rule written for images
Only one provider has a training rule written for pictures. Microsoft’s FAQ for the older Copilot app says that before training it takes steps to de-identify images and files, “such as removing metadata or other personal data and blurring images of faces”. That is a promise about what goes into training. It is not a promise about the copy kept with your conversation.
The rating button reopens the door
Turning training off can be undone with one click. OpenAI says that if you rate a reply, “the entire conversation associated with that feedback may be used to train our models”, even with training switched off. Google says feedback sent with Keep Activity off takes in the last 24 hours of chats and “any content included in those chats (like uploads …)”. A photo in that window goes with the feedback.
Work accounts are a different contract
The business plans reverse most of the table. OpenAI does not train on ChatGPT Business, Enterprise or Edu by default, though Business administrators can view, export and delete conversations. Google says chats and uploaded files in Workspace are not reviewed by people or used to train models outside your domain without permission.
Anthropic does not train on its commercial products by default. Microsoft says Copilot for work accounts does not train foundation models on prompts and responses, has opted out of abuse monitoring with human review, and stores uploaded files in the user’s OneDrive for Business, under retention policies the administrator sets. Any of these plans still faces the Privacy Act question below, and our comparison of AI tools under the Privacy Act goes through the plans one by one.
What a photo of a document gives away that typed text does not
When you type a question, you choose every word that leaves your screen. When you photograph the document instead, you send all of it, and the AI reads what it can. Google says Gemini reads the text in an image, and a number printed on a card is text like any other.
The photo printed on a licence or passport, clear enough to recognise you.
A clean image of it, ready to copy onto a form.
Licence and card number, passport number, Medicare number, account numbers.
The two coded lines at the foot of a passport photo page, which repeat your name, number and date of birth.
The envelope on the bench with your address, the screen behind, the other card in the wallet.
The phone model, the time and, with location on, where the photo was taken.
Most of that is visible if you look for it. The question to ask of each item is whether the AI needs it to answer you. To explain a condition code on a licence, it needs the code. To check a date on a letter, it needs the date. Our list of personal identifiers to remove before AI works through the same test for whole documents.
The metadata none of the four explain
The last item is the one nobody sees. Apple’s Australian guide says that when location is on for the Camera, the coordinates where a photo was taken “are embedded into each photo and video”. A licence photographed at the kitchen table carries the address of the kitchen.
None of the four providers says whether it keeps that data or strips it when you upload a photo. OpenAI says its model “doesn’t process original file names or metadata”, which is about what the model reads, not what is stored. Microsoft lists picture metadata among what it collects, and its older app mentions removing metadata only as a step before training. Our guide to removing metadata from Word and PDF files shows the same problem inside office documents.
Screenshots, letters and scripts
A screenshot looks safer than a photo and often is not. A banking screenshot carries the account number and balance, and the bar at the top can carry somebody else’s message as a notification. A photo of a letter from the ATO often carries a tax file number in the reference block, which our guide to redacting a TFN helps you find.
Health paperwork is the hardest case. A photographed referral or script names the patient, the doctor and the condition at once, and a clinic sending one to a chatbot is handling health information, which is where the Ahpra AI guidelines come in.
Photos under the Privacy Act: what the OAIC says
For a business covered by the Privacy Act 1988, a client’s photo is personal information like any typed detail, and putting it into a public chatbot has the same consequence. The OAIC’s guidance on commercially available AI products, published 21 October 2024 and updated 17 January 2025, uses an insurance company as its example: “By entering the personal information into the AI chatbot, the insurance company is disclosing the information to the owners of the chatbot.”
That disclosure is governed by APP 6. The regulator’s advice on top of it is a recommendation on best practice: that organisations do not enter personal information, “and particularly sensitive information”, into publicly available generative AI tools. A training switch or a private mode, from the sections above, does not change that the upload happened.
A face is personal information, and sometimes sensitive
The Privacy Act draws a narrow line around faces. Section 6(1) counts biometric information as sensitive when it is to be used for automated biometric verification or biometric identification, along with biometric templates. A photo on a licence is not sensitive information on that limb just because it shows a face.
The OAIC’s AI guidance widens the view from another side. Its examples of sensitive information include photographs from which race or health can be inferred, and it says “many photographs or recordings of individuals” contain sensitive information and may not be usable as input to AI without the individual’s consent. Our guide to sensitive information under the Privacy Act shows where that comes up in ordinary office files.
The numbers on the card
A driver licence number, a Medicare number and a Centrelink reference number are what the OAIC calls government related identifiers, and it treats copies of them with care. Its tenancy guidance says a real estate agent that needs to use or disclose a document with such an identifier, including copying it, “must generally blank” the identifier out. The same habit is the right one before a chatbot sees the card.
What to do before you upload a photo of a document
It takes a minute between taking the photo and sending it, and these five steps, in order.
- Ask whether the AI needs the picture. Often the question is about one line. Type that line, with the personal details left out, and the photo never leaves your phone.
- Crop to the part you are asking about. A crop removes the background, the other cards in the wallet and the envelope with your address on it.
- Cover what the question does not need. The cover has to change the pixels. A box drawn on top of a PDF can be lifted off, as our guide to redacting a PDF shows.
- Take the location out. On an iPhone, Apple’s guide says to tap Options in the share sheet and turn Location off, or stop the Camera recording it in Location Services.
- Use the private mode, then check Library. A temporary or incognito chat shortens the stay. In ChatGPT, delete the photo from Library as well as the chat.
For a licence, steps 3 and 4 are done for you by the tool the next section describes.
Cover a licence on your phone, and nothing is uploaded
Nonimo’s identity document tool sits at the top of the NSW licence page and the Victorian one. Drop a photo or a PDF of your licence, or take one with your phone, and it reads the card and shows a chip for each field: name, photo, licence number, card number, signature, date of birth, address, expiry date.
For a copy you send to an agent, your name and photo start visible and the rest covered. For a chatbot question, tap the name and photo chips as well, so nothing about you is left; the licence class and conditions stay, because they are usually what the question is about. A watermark saying who the copy is for is on from the start; switch it off if you only need the picture for the question.
When you download, as PNG, JPG or PDF, the boxes are burned into the image and the file leaves without its metadata, so no EXIF details and no GPS location go with it. Your document never leaves your device: it is read and redacted in your browser. The same tool works on the other ID documents Nonimo redacts, from passports to licences.
Or don’t upload the whole photo at all
The four providers are open about most of what they keep, and most offer a setting that shortens it. None has a setting that stops a photo arriving with everything on it. That part is yours, and it takes a minute: crop, cover, take the location out, and ask yourself whether typing the one line would do.
If you do upload, clear the chat and, in ChatGPT, clear Library too. And if the photo is a client’s, remember the OAIC’s point that the upload is the disclosure. For the documents a practice handles every day, Nonimo covers names and identifiers on your computer before text goes to ChatGPT, Copilot or Claude, and the NSW licence tool does the same for a photo in your browser.
Sources
Each source was read on 3 October 2026. OpenAI’s help pages show relative dates, converted here to approximate days.
- OpenAI, Using Library to manage files in ChatGPT (updated 3 October 2026). Library saves uploaded files, images included; deleting a chat does not delete files saved to Library; files kept until you delete them; deletion within 30 days; the plans with Library; Temporary Chat files not saved to Library. help.openai.com
- OpenAI, File Uploads FAQ (about 11 September 2026). Files saved in your account up to the retention period of the corresponding chat. help.openai.com
- OpenAI, Chat and file retention in ChatGPT (about 22 September 2026). Regular and archived chats kept until you delete them; deleting a chat does not delete a file saved in Library. help.openai.com
- OpenAI, Temporary chat in ChatGPT (about 19 September 2026). A copy kept for up to 30 days for safety; files may be saved to Library when you save the chat. help.openai.com
- OpenAI, How OpenAI handles data in consumer services (about 28 September 2026). Images and files used to improve model performance; access by authorised personnel and trusted service providers as needed. help.openai.com
- OpenAI, How your data is used to improve model performance (about 28 September 2026). The Improve the model for everyone setting; feedback sends the entire conversation; no training on Business, Enterprise, Edu or the API by default. help.openai.com
- OpenAI, ChatGPT Image Inputs FAQ (September 2026). The model does not process original file names or metadata; images resized before analysis; the same approach to images as to other content. help.openai.com
- OpenAI, Images in ChatGPT (about 10 September 2026). Generated images saved under Images and deleted with their conversation. help.openai.com
- OpenAI, Enterprise privacy (updated 8 January 2026). Business administrators can view, export and delete conversations. openai.com
- Google, Gemini Apps Privacy Hub (hub updated 24 September 2026, privacy notice 29 June 2026). Photos saved in Activity; Google Lens reads images; 18 months by default with 3, 36 or indefinite; 72 hours with Keep Activity off or in temporary chats; reviewed chats kept up to three years and not deleted with your activity; human reviewers including service providers; use for protection with Keep Activity off; feedback pulling in uploads from the last 24 hours. support.google.com
- Google, Temporary chats and new privacy controls (13 August 2025). A sample of uploads submitted from 2 September 2025 used to improve Google services when the setting is on. blog.google
- Google, How Google retains data we collect. Deletion generally takes around two months. policies.google.com
- Google, Generative AI in Google Workspace Privacy Hub (updated 14 August 2026). Chats and uploaded files not reviewed by people or used to train models outside your domain without permission. knowledge.workspace.google.com
- Anthropic, Privacy Policy (effective 10 September 2026). Uploads are Inputs; use for training unless you opt out. anthropic.com
- Anthropic, How long do you store my data? (1 July 2026). 30 days after deletion; up to five years, in what Anthropic calls a de-identified format, with model improvement on; 2 and 7 years for flagged conversations; 5 years for feedback. privacy.claude.com
- Anthropic, Use incognito chats. Kept for 30 days for safety; not used for training. support.claude.com
- Anthropic, Upload files to Claude. Files in a chat or in a project’s files for reference across conversations. support.claude.com
- Anthropic, Who can view my conversations? Access for training limited to a small number of staff. support.claude.com
- Anthropic, Is my data used for model training? (commercial) (18 August 2026). No training on commercial products by default. privacy.claude.com
- Microsoft, Privacy FAQ for Microsoft Copilot (older app). Files kept no longer than 18 months; Vision images not stored after the session; training on uploads with an opt out; images de-identified before training; no opt out from human review. support.microsoft.com
- Microsoft, Copilot privacy controls (older app). The training controls. support.microsoft.com
- Microsoft, Copilot for individuals: your activity history (updated app, from 18 August 2026). File contents not used to train foundation models. support.microsoft.com
- Microsoft, Privacy Statement (September 2026). Images and picture metadata collected on upload to Copilot; ads related to Copilot conversations, including files shared. microsoft.com
- Microsoft Learn, Data, privacy and security for Microsoft Copilot (18 August 2026) and Copilot Chat privacy and protections (24 August 2026). No foundation model training; abuse monitoring with human review opted out; retention policies in Purview; uploads stored in OneDrive for Business. learn.microsoft.com · learn.microsoft.com
- OAIC, Guidance on privacy and the use of commercially available AI products (21 October 2024, updated 17 January 2025). The insurance company example; the best practice recommendation; photographs that contain sensitive information and consent for AI input. oaic.gov.au
- OAIC, APP guidelines, Chapter B: Key concepts. The section 6(1) definition of sensitive information, including biometric information used for automated verification or identification and biometric templates. oaic.gov.au
- OAIC, Tenancy. An agent copying a document with a government related identifier must generally blank it out. oaic.gov.au
- Privacy Act 1988 (Cth). Section 6(1) and Australian Privacy Principle 6. legislation.gov.au
- Apple Support (Australia), Manage location metadata in Photos. Coordinates embedded in each photo and video; the Options and Location Services settings. support.apple.com/en-au
Common questions
Does ChatGPT save your photos?
Yes. A photo you upload is saved with the chat for as long as the chat is kept, and ChatGPT also files it in Library automatically. OpenAI says deleting a chat that contains files does not delete the copies saved to Library: you delete those separately, and they leave its systems within 30 days. Before you upload a photo of a document, cover what your question does not need on your own phone.
If I delete a ChatGPT chat, is the photo I uploaded deleted too?
Not necessarily. OpenAI's help page on Library says that deleting a chat containing files does not delete those files saved to Library. Open Library, delete the photo there as well, and OpenAI says it is then scheduled for permanent deletion within 30 days. Photos sent in a Temporary Chat do not go to Library unless you later save that chat.
Are photos sent in a temporary chat kept?
For a while. OpenAI may keep a copy of a temporary chat for up to 30 days for safety purposes, Anthropic keeps Claude incognito chats for 30 days, and Google keeps Gemini temporary chats, and chats with Keep Activity off, for 72 hours. A private mode shortens the stay. It does not stop the photo reaching the provider, which is why covering details before the upload matters more.
How long does Gemini keep the photos I upload?
As long as the chat they were in. Google saves photos and files you share in your Gemini Apps Activity, which is deleted automatically after 18 months by default; you can choose 3 months, 36 months or never. If a chat is picked for human review, Google keeps that copy for up to three years, and deleting your activity does not delete it. Workspace accounts follow the administrator's settings instead.
Does Claude keep images I upload?
Yes, as part of the conversation. Anthropic's consumer pages give no separate clock for files: a deleted conversation is removed from its back end storage within 30 days. If you allowed model improvement, it may keep chats for up to five years in training pipelines, in what it calls a de-identified format, and Anthropic's pages do not say whether that setting starts on or off. Incognito chats are kept for 30 days and not used for training.
Does Microsoft Copilot store my photos?
It depends which app you have. For the older consumer Copilot app, Microsoft says uploaded files are kept no longer than 18 months, and camera images shared with Vision are not stored after the session ends. For the updated app, available since 18 August 2026, it says file contents are not used to train foundation models but does not state how long files are kept. Work accounts follow the organisation's own retention policies.
Do ChatGPT, Gemini, Claude or Copilot remove the location from a photo?
None of the four says so for the photo it keeps. OpenAI says its model does not process file metadata, which is about what the model reads rather than what is stored. Microsoft lists picture metadata among what it collects, and its older Copilot app strips metadata only before training. Take the location out before you upload, or download a covered copy from Nonimo's licence tool, which carries no location or camera data.
Is it safe to upload a photo of my drivers licence to ChatGPT?
Only if nothing on it identifies you. A clear licence photo carries your name, face, date of birth, address, signature and both numbers a NSW identity check needs, and a personal ChatGPT account may train on it unless you switch that off. For a question about a condition code, cover every personal field first. Nonimo's licence tool does that in your browser, so the original never leaves your phone.
Is a photo of a face sensitive information under the Privacy Act?
Not automatically. Under section 6(1) of the Privacy Act 1988, biometric information counts as sensitive when it is to be used for automated biometric verification or identification. The OAIC adds that many photographs of people contain sensitive information, such as race or health that can be inferred from them, and may need consent before they are used as input to AI. A business should treat a client's photo with that care.