[nonimo]
EN
Download

Does ChatGPT save your photos? How long AI tools keep them

· Written and maintained by Nonimo

Yes. ChatGPT saves the photos you upload, and so do Gemini, Claude and Microsoft Copilot. A photo is treated as part of the conversation, so it is kept for as long as the chat is kept. ChatGPT goes one step further: it also files your uploads in a separate Library, and OpenAI says deleting the chat does not delete that copy.

That matters most for the photos people take without a second thought: a drivers licence for a rental application, a passport for a new employer, a power bill, a letter from the ATO, a script from the GP, a screenshot of a bank transfer. A picture of a document hands over everything on the paper, including the parts your question never needed, and a few things that are not on the paper at all.

This guide sets out what each of the four says it keeps from an uploaded image, for how long, whether it trains on it and whether a person can look at it. Every period comes from the provider’s own pages, read on 3 October 2026, and where a provider does not say, neither do we.

The last sections cover what the Privacy Act asks of a business, and how to cover a licence on your phone with the NSW licence tool before it goes anywhere.

Does ChatGPT save your photos?

Yes, and in two places. OpenAI’s file uploads FAQ says files uploaded to ChatGPT “are saved in your account up to the retention period of the corresponding chat”. Regular and archived chats stay saved until you delete them, so a photo in a chat you never clear stays for as long as the account does.

The second place is newer, and most advice about ChatGPT has not caught up with it. ChatGPT now has a Library, and OpenAI’s help page says it “automatically saves uploaded and created files, including files uploaded in chats”, with images named in the list. Library is on Free, Go, Plus, Pro and Business, and in Enterprise, Edu and Healthcare workspaces.

2 places
Where ChatGPT saves a photo uploaded in a chat: the chat itself and Library. OpenAI, Using Library, read 3 October 2026

None of that is hidden, and OpenAI’s pages are clear about it. The problem is habit. People who clear a chat after a sensitive question believe the photo went with it, and since Library arrived that belief is wrong. Our guide to whether ChatGPT saves your data covers the rest of what OpenAI keeps from a conversation.

Deleting the chat does not delete the Library copy

This is the line to read twice. OpenAI’s Library page puts it plainly: “Deleting a chat containing files does not delete those files saved to Library.” Its page on chat and file retention says the same thing in other words. Clearing the chat clears the conversation, and the photo you sent in it stays where it was filed.

Library files are kept “until you delete them manually”. When you do, they move to a recently deleted area first and are then scheduled for permanent deletion from OpenAI’s systems within 30 days. On Enterprise, Edu and Healthcare workspaces, Library follows the workspace’s own retention policy instead, which the administrator sets.

So when someone asks whether ChatGPT saves your photos after the chat is gone, the honest answer is yes, unless the Library copy went too. If you have used ChatGPT for a while, open Library and look before you assume anything is gone. A licence photo from last year’s rental application may still be sitting there, next to the payslips that went with it.

Pictures ChatGPT makes live somewhere else

Images that ChatGPT generates for you are a separate case. OpenAI saves them under Images, and to delete one there you delete the conversation that created it. That rarely matters for a photo of a document, but it explains why clearing Library does not clear everything visual in an account.

How long ChatGPT, Gemini, Claude and Copilot keep a photo you upload

No provider runs a separate clock for photos on a personal account. An uploaded image is content in the chat, and it follows the chat. The differences are in the defaults, in what deletion reaches, and in the copies that sit outside your history. Our guide to which AI tools a business can use under the Privacy Act sets the same four side by side for text.

Personal accountHow long the photo staysAfter you delete itWhat can outlive deletion
ChatGPTuntil you delete the chat, and the Library copy until you delete thatremoved within 30 daysthe Library copy, if you only delete the chat
Gemini18 months by default; 3 months, 36 months or never if you change itGoogle says deletion generally takes about 2 monthsa chat picked for human review, up to 3 years
Claudeuntil you delete the chatremoved from the back end within 30 daysa training copy, up to 5 years, if model improvement was on
Copilot, older appfiles no longer than 18 monthsnot stated separatelynot stated
Copilot, updated appnot statednot statednot stated

Sources: OpenAI, Google, Anthropic and Microsoft help and privacy pages, read 3 October 2026, each listed under Sources below.

Gemini: photos go into your Activity

Google’s Gemini Apps Privacy Hub, last updated 24 September 2026, says your chats and what you share with Gemini, “like files, videos, screens, and photos”, are saved in your Activity. Gemini uses Google Lens technology to understand what is in an image and to read its text, so a photographed letter is read much like a typed one.

The review copy is what changes the picture. Google’s privacy notice says chats reviewed by people, with related data such as location info, “are not deleted when you delete your activity”, and the hub adds that data reviewed by service providers is disconnected from your account. Deleting the photo from your history does not reach a copy that has already been pulled for review. Our guide to whether Gemini shares your data goes through the rest of Google’s settings.

Claude: photos follow the chat or the project

Anthropic’s privacy policy, effective 10 September 2026, calls anything you upload your Inputs. A file can go into a single chat, or into a project’s files, where Anthropic says it stays for reference across conversations. When you clean up, check both places.

Two clocks sit outside the table. If a classifier flags a conversation under Anthropic’s usage policy, it keeps the inputs and outputs for up to 2 years, and the safety scores for up to 7. Rate a reply or report it, and the data tied to that feedback is kept for 5 years. A photo in that conversation is part of its inputs. The Claude guide explains each clock in turn.

Microsoft Copilot: two apps, two rulebooks

Since 18 August 2026 Microsoft has published two sets of consumer pages, one for an updated Copilot app and one that, in its own banner, “applies only to the older version”. Which set describes your photos depends on which app you have, and the two should not be mixed.

The older app has the only photo rule with a shorter life than the chat. Microsoft says screenshots and camera images shared with Copilot Vision “aren’t stored after your session ends”. For the updated app, its pages say prompts, responses and “your file contents” are not used to train foundation models, and they say nothing about how long a file is kept.

Across both, Microsoft’s general privacy statement, last updated September 2026, lists “images and related data, like picture metadata” among what it collects when you upload an image to Copilot. It also says ads may be shown that relate to your Copilot conversations, including files you share. The Copilot guide explains how a work account changes that.

Does ChatGPT save your photos in Temporary Chat? Private modes compared

Three of the four offer a way to chat without building a history, and all three still keep something for a while. A photo sent in a private chat is part of that chat, so it gets the same treatment.

OpenAI’s answer to whether files uploaded in a temporary chat go to Library is a flat no: they “are not saved to your account or Library”. The catch is the save button. If you later save a temporary chat that had files in it, OpenAI says eligible files may be saved to Library at that point. Either way, it may keep a copy of a temporary chat for up to 30 days for safety purposes.

ChatGPT, Temporary Chat30 days
Claude, incognito chat30 days
Gemini, temporary chat or Keep Activity off72 hours
The longest each provider says it may keep a private chat. OpenAI, Anthropic and Google, read 3 October 2026

Claude’s incognito chats are kept for 30 days for safety, and Anthropic says they are not used for training. Gemini’s temporary chats, and any chat with Keep Activity switched off, are kept with your account for 72 hours. Google says temporary chats are not used to improve its AI with help from human reviewers, and also that, with Keep Activity off, it still uses chats to protect Google, its users and the public, including with help from human reviewers.

Short is not the same as nothing

A private mode changes how long the photo stays in the provider’s systems. It does not change the fact that the photo arrived there. For a business that is the moment the Privacy Act cares about, as the section below explains, and a 72 hour window is still a disclosure. Details covered before the upload never reach anyone, which is what the tool does on our page for the Victorian licence.

Do AI tools train on your photos, and can a person look at them?

On a personal account, images mostly follow the same training rules as text. What changes from one provider to the next is the default, and whether people can see the content.

Personal accountTrains on uploads by defaultPeople who may lookHow to stop the training
ChatGPTyes, images and files includedauthorised staff and trusted service providers, as neededturn off Improve the model for everyone
Geminiyes, while Keep Activity is onhuman reviewers, including from service providersturn off Keep Activity, or use a temporary chat
Claudeas your setting says; the default is not stateda small number of staff involved in model trainingturn off model improvement in settings
Copilot, older appyes, unless you opt outreviewers, with no opt out from reviewCopilot’s training controls
Copilot, updated appnot for foundation modelsnot statednothing to switch for foundation models

Sources: OpenAI, Google, Anthropic and Microsoft pages listed under Sources, read 3 October 2026.

OpenAI is the most explicit. Its page on consumer data says it may use “other content such as images and files to improve model performance”, and its image inputs FAQ says its approach to images is the same as for everything else. Google announced in August 2025 that, with the setting on, a sample of uploads submitted from 2 September 2025 would be used to help improve its services.

The one rule written for images

Only one provider has a training rule written for pictures. Microsoft’s FAQ for the older Copilot app says that before training it takes steps to de-identify images and files, “such as removing metadata or other personal data and blurring images of faces”. That is a promise about what goes into training. It is not a promise about the copy kept with your conversation.

The rating button reopens the door

Turning training off can be undone with one click. OpenAI says that if you rate a reply, “the entire conversation associated with that feedback may be used to train our models”, even with training switched off. Google says feedback sent with Keep Activity off takes in the last 24 hours of chats and “any content included in those chats (like uploads …)”. A photo in that window goes with the feedback.

Work accounts are a different contract

The business plans reverse most of the table. OpenAI does not train on ChatGPT Business, Enterprise or Edu by default, though Business administrators can view, export and delete conversations. Google says chats and uploaded files in Workspace are not reviewed by people or used to train models outside your domain without permission.

Anthropic does not train on its commercial products by default. Microsoft says Copilot for work accounts does not train foundation models on prompts and responses, has opted out of abuse monitoring with human review, and stores uploaded files in the user’s OneDrive for Business, under retention policies the administrator sets. Any of these plans still faces the Privacy Act question below, and our comparison of AI tools under the Privacy Act goes through the plans one by one.

What a photo of a document gives away that typed text does not

When you type a question, you choose every word that leaves your screen. When you photograph the document instead, you send all of it, and the AI reads what it can. Google says Gemini reads the text in an image, and a number printed on a card is text like any other.

Your face

The photo printed on a licence or passport, clear enough to recognise you.

Your signature

A clean image of it, ready to copy onto a form.

The numbers

Licence and card number, passport number, Medicare number, account numbers.

The machine readable zone

The two coded lines at the foot of a passport photo page, which repeat your name, number and date of birth.

The background

The envelope on the bench with your address, the screen behind, the other card in the wallet.

The metadata

The phone model, the time and, with location on, where the photo was taken.

What a phone photo of an ID document can carry beyond your question

Most of that is visible if you look for it. The question to ask of each item is whether the AI needs it to answer you. To explain a condition code on a licence, it needs the code. To check a date on a letter, it needs the date. Our list of personal identifiers to remove before AI works through the same test for whole documents.

The metadata none of the four explain

The last item is the one nobody sees. Apple’s Australian guide says that when location is on for the Camera, the coordinates where a photo was taken “are embedded into each photo and video”. A licence photographed at the kitchen table carries the address of the kitchen.

None of the four providers says whether it keeps that data or strips it when you upload a photo. OpenAI says its model “doesn’t process original file names or metadata”, which is about what the model reads, not what is stored. Microsoft lists picture metadata among what it collects, and its older app mentions removing metadata only as a step before training. Our guide to removing metadata from Word and PDF files shows the same problem inside office documents.

Screenshots, letters and scripts

A screenshot looks safer than a photo and often is not. A banking screenshot carries the account number and balance, and the bar at the top can carry somebody else’s message as a notification. A photo of a letter from the ATO often carries a tax file number in the reference block, which our guide to redacting a TFN helps you find.

Health paperwork is the hardest case. A photographed referral or script names the patient, the doctor and the condition at once, and a clinic sending one to a chatbot is handling health information, which is where the Ahpra AI guidelines come in.

Photos under the Privacy Act: what the OAIC says

For a business covered by the Privacy Act 1988, a client’s photo is personal information like any typed detail, and putting it into a public chatbot has the same consequence. The OAIC’s guidance on commercially available AI products, published 21 October 2024 and updated 17 January 2025, uses an insurance company as its example: “By entering the personal information into the AI chatbot, the insurance company is disclosing the information to the owners of the chatbot.”

That disclosure is governed by APP 6. The regulator’s advice on top of it is a recommendation on best practice: that organisations do not enter personal information, “and particularly sensitive information”, into publicly available generative AI tools. A training switch or a private mode, from the sections above, does not change that the upload happened.

A face is personal information, and sometimes sensitive

The Privacy Act draws a narrow line around faces. Section 6(1) counts biometric information as sensitive when it is to be used for automated biometric verification or biometric identification, along with biometric templates. A photo on a licence is not sensitive information on that limb just because it shows a face.

The OAIC’s AI guidance widens the view from another side. Its examples of sensitive information include photographs from which race or health can be inferred, and it says “many photographs or recordings of individuals” contain sensitive information and may not be usable as input to AI without the individual’s consent. Our guide to sensitive information under the Privacy Act shows where that comes up in ordinary office files.

The numbers on the card

A driver licence number, a Medicare number and a Centrelink reference number are what the OAIC calls government related identifiers, and it treats copies of them with care. Its tenancy guidance says a real estate agent that needs to use or disclose a document with such an identifier, including copying it, “must generally blank” the identifier out. The same habit is the right one before a chatbot sees the card.

What to do before you upload a photo of a document

It takes a minute between taking the photo and sending it, and these five steps, in order.

  1. Ask whether the AI needs the picture. Often the question is about one line. Type that line, with the personal details left out, and the photo never leaves your phone.
  2. Crop to the part you are asking about. A crop removes the background, the other cards in the wallet and the envelope with your address on it.
  3. Cover what the question does not need. The cover has to change the pixels. A box drawn on top of a PDF can be lifted off, as our guide to redacting a PDF shows.
  4. Take the location out. On an iPhone, Apple’s guide says to tap Options in the share sheet and turn Location off, or stop the Camera recording it in Location Services.
  5. Use the private mode, then check Library. A temporary or incognito chat shortens the stay. In ChatGPT, delete the photo from Library as well as the chat.

For a licence, steps 3 and 4 are done for you by the tool the next section describes.

Cover a licence on your phone, and nothing is uploaded

Nonimo’s identity document tool sits at the top of the NSW licence page and the Victorian one. Drop a photo or a PDF of your licence, or take one with your phone, and it reads the card and shows a chip for each field: name, photo, licence number, card number, signature, date of birth, address, expiry date.

For a copy you send to an agent, your name and photo start visible and the rest covered. For a chatbot question, tap the name and photo chips as well, so nothing about you is left; the licence class and conditions stay, because they are usually what the question is about. A watermark saying who the copy is for is on from the start; switch it off if you only need the picture for the question.

When you download, as PNG, JPG or PDF, the boxes are burned into the image and the file leaves without its metadata, so no EXIF details and no GPS location go with it. Your document never leaves your device: it is read and redacted in your browser. The same tool works on the other ID documents Nonimo redacts, from passports to licences.

Or don’t upload the whole photo at all

The four providers are open about most of what they keep, and most offer a setting that shortens it. None has a setting that stops a photo arriving with everything on it. That part is yours, and it takes a minute: crop, cover, take the location out, and ask yourself whether typing the one line would do.

If you do upload, clear the chat and, in ChatGPT, clear Library too. And if the photo is a client’s, remember the OAIC’s point that the upload is the disclosure. For the documents a practice handles every day, Nonimo covers names and identifiers on your computer before text goes to ChatGPT, Copilot or Claude, and the NSW licence tool does the same for a photo in your browser.

Sources

Each source was read on 3 October 2026. OpenAI’s help pages show relative dates, converted here to approximate days.

Common questions

Does ChatGPT save your photos?

Yes. A photo you upload is saved with the chat for as long as the chat is kept, and ChatGPT also files it in Library automatically. OpenAI says deleting a chat that contains files does not delete the copies saved to Library: you delete those separately, and they leave its systems within 30 days. Before you upload a photo of a document, cover what your question does not need on your own phone.

If I delete a ChatGPT chat, is the photo I uploaded deleted too?

Not necessarily. OpenAI's help page on Library says that deleting a chat containing files does not delete those files saved to Library. Open Library, delete the photo there as well, and OpenAI says it is then scheduled for permanent deletion within 30 days. Photos sent in a Temporary Chat do not go to Library unless you later save that chat.

Are photos sent in a temporary chat kept?

For a while. OpenAI may keep a copy of a temporary chat for up to 30 days for safety purposes, Anthropic keeps Claude incognito chats for 30 days, and Google keeps Gemini temporary chats, and chats with Keep Activity off, for 72 hours. A private mode shortens the stay. It does not stop the photo reaching the provider, which is why covering details before the upload matters more.

How long does Gemini keep the photos I upload?

As long as the chat they were in. Google saves photos and files you share in your Gemini Apps Activity, which is deleted automatically after 18 months by default; you can choose 3 months, 36 months or never. If a chat is picked for human review, Google keeps that copy for up to three years, and deleting your activity does not delete it. Workspace accounts follow the administrator's settings instead.

Does Claude keep images I upload?

Yes, as part of the conversation. Anthropic's consumer pages give no separate clock for files: a deleted conversation is removed from its back end storage within 30 days. If you allowed model improvement, it may keep chats for up to five years in training pipelines, in what it calls a de-identified format, and Anthropic's pages do not say whether that setting starts on or off. Incognito chats are kept for 30 days and not used for training.

Does Microsoft Copilot store my photos?

It depends which app you have. For the older consumer Copilot app, Microsoft says uploaded files are kept no longer than 18 months, and camera images shared with Vision are not stored after the session ends. For the updated app, available since 18 August 2026, it says file contents are not used to train foundation models but does not state how long files are kept. Work accounts follow the organisation's own retention policies.

Do ChatGPT, Gemini, Claude or Copilot remove the location from a photo?

None of the four says so for the photo it keeps. OpenAI says its model does not process file metadata, which is about what the model reads rather than what is stored. Microsoft lists picture metadata among what it collects, and its older Copilot app strips metadata only before training. Take the location out before you upload, or download a covered copy from Nonimo's licence tool, which carries no location or camera data.

Is it safe to upload a photo of my drivers licence to ChatGPT?

Only if nothing on it identifies you. A clear licence photo carries your name, face, date of birth, address, signature and both numbers a NSW identity check needs, and a personal ChatGPT account may train on it unless you switch that off. For a question about a condition code, cover every personal field first. Nonimo's licence tool does that in your browser, so the original never leaves your phone.

Is a photo of a face sensitive information under the Privacy Act?

Not automatically. Under section 6(1) of the Privacy Act 1988, biometric information counts as sensitive when it is to be used for automated biometric verification or identification. The OAIC adds that many photographs of people contain sensitive information, such as race or health that can be inferred from them, and may need consent before they are used as input to AI. A business should treat a client's photo with that care.