Does ChatGPT store photos? What AI tools keep, and how long
· Written and maintained by Nonimo
Yes. ChatGPT keeps a photo you upload as part of the conversation for as long as you keep the chat, and it also saves the image to Library, where it stays until you delete it there yourself: deleting the chat does not remove it. Gemini keeps photos with the rest of your activity, 18 months by default. Claude keeps them with the chat. Copilot’s answer depends on which version of the app you have.
And not one of the four says whether it strips the location data hidden inside your photo.
That matters most for the photos people take of documents: a passport for a letting agent, a driving licence, a hospital letter, a payslip, a screenshot of a banking app. A typed question carries what you chose to type. A photo carries everything in the frame. So the practical answer, before the provider detail below, is to cover what the AI does not need on your own device first, which the passport tool on our watermark and redact page does in your browser.
What follows comes from the providers’ own help and privacy pages, read on 3 October 2026. Where a provider says nothing, this guide says so rather than guessing.
Does ChatGPT store photos you upload?
It does, in two places. OpenAI’s privacy policy treats anything you upload, files, images, audio and video, as your Content, and its help centre says files uploaded to ChatGPT are saved in your account up to the retention period of the chat they belong to.
A saved chat stays until you delete it, and once you delete it OpenAI says it removes the data from its systems within 30 days, with some exceptions set out in our guide to whether ChatGPT shares your data.
That would be the whole story if photos only lived in the chat. They do not.
The Library copy that outlives the chat
ChatGPT now saves files automatically to Library, and OpenAI’s help page lists images among them, alongside documents, spreadsheets and presentations uploaded in chats. Library is available on Free, Go, Plus, Pro and Business, and in Enterprise and Edu workspaces. The sentence that matters is short:
“Deleting a chat containing files does not delete those files saved to Library.” OpenAI, Using Library to manage files in ChatGPT
On a personal account, a Library file is kept until you delete it by hand. When you do, it goes to Recently deleted first and is then scheduled for permanent deletion from OpenAI’s systems within 30 days. So the photo of your passport you asked about in March can still be sitting in your account in October, long after the conversation that prompted it is gone.
On Enterprise, Edu and Healthcare workspaces, Library files follow the retention policy the workspace sets, so the answer there belongs to whoever runs the account.
Temporary Chat keeps the upload out of Library
A photo sent in a Temporary Chat is not saved to your account or to Library, OpenAI says, unless you later save that chat, in which case eligible files may be saved to Library with it. OpenAI may still keep a copy of a temporary chat for up to 30 days for safety purposes. So a temporary chat is shorter, not invisible.
Images ChatGPT creates for you live somewhere else again, under Images, and OpenAI says the way to remove one is to delete the conversation that produced it.
How long does ChatGPT store photos? The four tools side by side
On personal plans, a photo rarely has a clock of its own. An uploaded image is part of the conversation and follows its retention, with a few exceptions that are worth knowing because each one is longer or shorter than people assume.
| Tool, personal account | Saved chat | After you delete it | Shorter mode |
|---|---|---|---|
| ChatGPT | Until you delete it; the Library copy too | Within 30 days, chat and Library separately | Temporary Chat: up to 30 days, not in Library |
| Gemini | 18 months by default (3, 36 or never) | Reviewed chats kept up to 3 years | Keep activity off or temporary chat: 72 hours |
| Claude | Yours to delete at any time | Within 30 days; longer if used for training or flagged | Incognito: 30 days |
| Copilot, older app | Chats 18 months; files no longer than 18 months | Not stated | Vision camera images not kept after the session |
| Copilot, updated app | Not stated | Not stated | Not stated |
From each provider’s help and privacy pages, read 3 October 2026. “Not stated” means the provider’s pages do not give a figure.
Gemini: your activity, and the copy a reviewer saw
Google’s privacy hub, last updated on 24 September 2026, says the photos and files you share with Gemini are saved in your activity along with your chats. When you add an image, Gemini also uses Google Lens to work out what is in it and read any text, and Google says it uses that like any other prompt. A photographed letter is, in practice, a typed letter as well.
The exception is the one our guide to whether Gemini uses your data dwells on. Chats reviewed by human reviewers, and related data such as your language, device type and location, are not deleted when you delete your activity: they are kept for up to three years. If a reviewer saw the photo, deleting it from your activity does not reach that copy.
Claude: the chat’s clock, and a project’s files
Anthropic’s consumer pages give no separate period for uploads, so a photo follows its conversation. Delete the chat and Anthropic says it leaves your history immediately and back end storage within 30 days.
If you allow your chats to be used to improve Claude, Anthropic may keep the data, with identifiers removed, for up to five years in its training pipelines; a chat flagged by its safety systems is kept for up to 2 years. The detail is in our guide to whether Claude trains on your data.
One practical point: Claude lets you add files to a project, where they stay available across conversations. A photo put there is not tied to any one chat, so deleting a chat leaves it in place.
Copilot: two apps, two sets of answers
Since 18 August 2026 Microsoft has published two sets of consumer documentation, one for the updated Copilot app and one that, in its own words, applies only to the older version. The older app’s FAQ is specific: an uploaded file is stored for no longer than 18 months and then deleted automatically, conversations are kept for 18 months by default, and screenshots and camera images shared with Copilot Vision are not stored after the session ends.
The updated app’s pages give no retention period at all for chats or files. Which numbers apply to you depends on which app you have, and our guide to Copilot and confidential information explains why the work version is a different product again.
Is your photo used for training, and can a person see it?
Two separate questions, and the four providers answer them separately. Training decides whether your photo helps shape a future model. Review decides whether a person may look at it. A setting that switches off the first does not always switch off the second.
| Tool, personal account | Trains on uploads by default | People may see it | Where to switch training off |
|---|---|---|---|
| ChatGPT | Yes, images and files included | Authorised staff and service providers, as needed | Settings, Data controls, Improve the model for everyone |
| Gemini | Yes, with Keep activity on | Reviewers, some from service providers; also for safety | Turn Keep activity off, or use a temporary chat |
| Claude | Depends on your setting | A small number of training staff, after the data is unlinked from you | Privacy settings |
| Copilot, older app | Yes, after steps such as removing metadata and blurring faces | Yes, and you cannot opt out of review | Copilot’s privacy settings |
| Copilot, updated app | Not used to train foundation models | Not stated | Nothing to switch off for foundation models |
Provider help and privacy pages, read 3 October 2026.
OpenAI is explicit that its approach to images is the same as to everything else: on personal plans it may use prompts, responses and other content such as images and files to improve its models, and its own warning is not to enter sensitive information you would not want reviewed or used.
Google’s version is blunter: “don’t enter confidential information that you wouldn’t want a reviewer to see”. It also announced in August 2025 that, with the setting on, a sample of uploads made from 2 September 2025 would be used to help improve its services.
Anthropic’s privacy policy, effective 10 September 2026, says it may use your inputs to train its models unless you opt out in your account settings. Rather than assume which way yours is set, open Privacy settings and look.
The feedback button takes the photo with it
A thumbs up or thumbs down is the quiet exception. OpenAI says that if you rate a reply, the entire conversation attached to that feedback may be used to train its models, even with training switched off. Anthropic keeps data linked to a feedback submission for five years. On Gemini, feedback sent with Keep activity off brings in the last 24 hours of chats and any content in them, uploads included.
So a photo of a document and a quick thumbs up are, together, a contribution to a training set. If the photo was uncovered, so was the contribution.
Work accounts answer differently
Business plans change the defaults, which is why the GDPR compliant AI tools checklist starts with the account rather than the tool. OpenAI does not train on ChatGPT Business, Enterprise or Edu by default. Google says chats and uploaded files in Workspace are not reviewed by people or used to train models outside your domain without permission. Anthropic does not train on its commercial products by default.
Microsoft 365 Copilot Chat stores uploaded files in your OneDrive for Business and has opted out of the abuse monitoring that includes human review.
What a photo of a document carries that a typed question does not
When you type a question, you decide every word that goes. When you photograph a document, the camera decides, and it captures the whole page, the edges of the next page and whatever was on the table.
| In the photo | In a typed question |
|---|---|
| Your face, sometimes twice on the same page | Nothing, unless you describe yourself |
| Your signature | Never |
| The document number, printed and repeated | Only if you type it |
| Machine readable lines that encode all the above | Never |
| Other papers, people and rooms in the frame | Never |
| Camera details and, often, GPS coordinates | Never |
Our comparison. The machine readable lines are defined in ICAO Doc 9303; EXIF and GPS are covered in the next section.
Passports and licences: the face, the number and the bottom lines
A UK passport data page is the densest example. The two lines of letters, digits and chevrons at the foot repeat your name, passport number, nationality, date of birth, sex and expiry date, so covering a field above them is undone if the lines stay visible. Page 3, which faces the data page, carries your signature and a second portrait, and a photo of the open book catches both.
A photocard driving licence has its own trap: the driver number is built from your surname, date of birth and initials, so a date of birth covered on the card can still be read from the number, as the driving licence guide shows with DVLA’s own description.
Letters, prescriptions, payslips and screenshots
Most photos sent to a chatbot are not ID documents. They are a letter from HMRC someone does not understand, a repeat prescription, a payslip, a screenshot of a banking app with a payment that looks wrong. Each has a header full of identifiers above the part the question is actually about: a National Insurance number in a reference line, an NHS number, an account number, an address.
The question rarely needs any of it. What the letter asks you to do and by when, or what a code on the payslip means, survives without the header, which is the point the National Insurance number guide makes about pension and benefit letters.
EXIF and GPS: the location data inside the photo
A phone writes data into every photo it takes, known as EXIF: the make and model of the phone, the time the picture was taken and, when location is switched on for the camera, the coordinates of where you were standing. You do not see it on the screen. It travels with the file. A passport photographed on your kitchen table can carry the position of your kitchen.
The ICO counts this among the personal information hidden in files, in its guidance on avoiding accidental breaches, and suggests removing image metadata with photo editing software or Windows File Explorer before a document is released. Our guide to removing metadata from PDF and Word files shows a test photo keeping its GPS position after being placed inside a Word letter.
What each provider does say
Each of the four says something near the point, and none says the thing you want to know. OpenAI says its model does not process original file names or metadata and that images are resized before analysis, which is about what the model reads, not what is stored. Microsoft’s privacy statement says it collects images uploaded to Copilot together with related data, “like picture metadata”. The older Copilot app’s FAQ mentions removing metadata from images only as a step before training, not for the copy kept with the conversation.
Google explains how it reduces your device’s location to a general area in Gemini activity, which is a different thing from coordinates inside a photo. Anthropic’s developer documentation says only that an image may be served back as a processed copy rather than the uploaded file.
So the safe assumption is that the location data arrives with the photo, and the only way to be sure it is not stored is that it was never in the file you uploaded.
UK GDPR and the ICO: is a photo of a face biometric data?
Not automatically, which surprises people. Article 4(14) of the UK GDPR defines biometric data as personal data resulting from “specific technical processing” of someone’s physical characteristics that allows or confirms their unique identification, and gives facial images as an example. The ICO’s guidance on special category data spells out the consequence: digital photographs of people are not automatically biometric data, even when used for identification, and only become so when processed technically, usually to create a template for automated matching.
So a chatbot reading a passport photo to answer your question is not, on that reading, processing special category data merely because a face is in it. Biometric data becomes special category data under Article 9 when it is processed to uniquely identify someone, and our guide to special category data in AI covers the categories that catch office paperwork far more often than faces do.
Minimisation is the rule that applies
A photo of a passport or a payslip is still personal data, and for an office handling someone else’s documents, the UK GDPR applies to the decision to upload it. The principle that settles most cases is Article 5(1)(c): personal data must be adequate, relevant and limited to what is necessary for the purpose. If the purpose is to ask what a box on a form means, the name, number and face are not necessary.
The ICO’s page on identity theft names passports and driving licences among the documents to keep safe, and describes identity theft as someone using details such as your name, date of birth and address to impersonate you. A full, uncovered copy sitting in a chatbot’s file store is one more copy of exactly that.
Other people in the picture
Photos catch people who never agreed to be in them: a child on the sofa behind the document, a colleague’s face in a screenshot of a video call. Google’s Gemini privacy hub asks you to get permission before using other people’s faces or voices in Gemini, and the older Copilot app says it may ask your permission before processing biometric data such as faces or hands in Vision. Crop them out before you upload.
What to cover before you upload a photo to an AI
It takes a minute before the upload, in this order.
- Ask whether the AI needs the picture at all. For most questions about a letter, typing the sentence you do not understand gets the same answer as photographing the page.
- Crop to the part you are asking about. The header, the address block and the edges of other papers rarely help the answer.
- Cover what identifies you. On an ID document that means name, number, date of birth, photo, signature and the machine readable lines; on a letter, the reference line and the address. The personal data to remove before an AI reads a document lists the UK identifiers one by one.
- Make the cover permanent. A shape laid over a file can be lifted off, as our PDF redaction guide shows; block the area out and export a flat PNG or JPG, so the cover is part of the pixels.
- Leave the location data behind. Export a new copy without EXIF, or switch off location for the camera before you photograph documents at all.
- Use the short mode, and check Library. A temporary chat in ChatGPT or Gemini, or an incognito chat in Claude, limits how long the upload is kept, and Anthropic and Google say those chats are not used for training; in ChatGPT, delete the Library copy if you used an ordinary chat.
Cover an ID photo in your browser before an AI sees it
For passports and driving licences, the tool on our passport watermark and redact page does steps 3 to 5 in one go. Drop in a photo or a scan, JPG, PNG, WEBP, PDF or the HEIC photos an iPhone saves, or take the picture from the page on a phone.
The tool reads the document and shows a chip for each field. Your name, the document number and your photo start visible and everything else it reads starts covered, from the date of birth to the machine readable lines.
When the copy is for an AI rather than a person, tap the name, number and photo chips as well, so nothing personal is left. Then download a PNG, JPG or PDF with the boxes burned into the pixels and the photo’s hidden data, EXIF and GPS, left behind.
Your document never leaves your device: it is read and covered in your browser, and the photo you drop is not uploaded to our servers or anyone’s. The only copy that travels is the one you choose to send, and that copy shows the AI the part of the page your question is about. The same tool handles a UK photocard driving licence, and the full list of documents it reads is in the ID documents section of our UK homepage.
Already uploaded it? How to delete a photo from each tool
If a full, uncovered photo has already gone, deleting it shortens how long it is kept, though not for every copy.
- ChatGPT: delete the conversation, then open Library and delete the file there too; it passes through Recently deleted first. Both go from OpenAI’s systems within 30 days, subject to the exceptions in its policy. OpenAI also says it still stores limited user data from April to September 2025 because of the New York Times litigation.
- Gemini: delete the chat from your Gemini activity. A chat a reviewer has already seen stays for up to three years, unlinked from your account.
- Claude: delete the conversation, and remove the photo from any project you added it to. Deleted chats leave back end storage within 30 days.
- Copilot: delete the conversation. On the older app an uploaded file is in any case deleted after no longer than 18 months.
If the photo was a client’s or a patient’s document uploaded from work, it is no longer only a question of deleting it. Tell whoever handles data protection in your organisation, and read whether putting client data in ChatGPT is a data breach, which sets out the tests and the 72 hour clock. For your own passport, the ICO’s identity theft page lists the steps if you think a copy is being misused, including protective registration with Cifas.
Next time, cover it first: the passport tool takes about a minute.
Sources
- OpenAI, Using Library to manage files in ChatGPT, read 3 October 2026. Uploaded files, images included, saved automatically to Library; deleting a chat does not delete files saved to Library; files kept until deleted manually; Recently deleted, then permanent deletion within 30 days; plans where Library is available; Temporary Chat uploads not saved to Library; workspace retention for Enterprise and Edu.
- OpenAI, File uploads FAQ. Uploaded files saved in your account up to the retention period of the corresponding chat.
- OpenAI, Chat and file retention in ChatGPT. Saved chats kept until you delete them; a file saved in Library survives deletion of the chat.
- OpenAI, Temporary chat in ChatGPT. A copy kept for up to 30 days for safety; eligible files saved to Library if you save the chat.
- OpenAI, Europe privacy policy, updated 24 August 2026. Uploaded files and images as Content; deleted personal data removed within 30 days, with exceptions.
- OpenAI, How OpenAI handles data in consumer services. Images and files may be used to improve models on personal plans; authorised staff and trusted service providers may access content; the warning about sensitive information.
- OpenAI, How your data is used to improve model performance. The Improve the model for everyone setting; the whole conversation may be used if you give feedback; no training on Business, Enterprise, Edu or the API by default.
- OpenAI, ChatGPT image inputs FAQ. The model does not process original file names or metadata; images resized before analysis; the same approach to images as to other content.
- OpenAI, Images in ChatGPT. Created images saved under Images; deleting the conversation removes one.
- OpenAI, Response to the New York Times’ data demands, update of 22 October 2025. Limited historical user data from April to September 2025 still stored.
- Google, Gemini Apps Privacy Hub, last updated 24 September 2026, with the privacy notice of 29 June 2026. Photos and files saved in activity; Google Lens reads uploaded images; 18 months by default, 3, 36 months or indefinite; 72 hours with Keep activity off or in temporary chats; reviewed chats kept up to three years after deletion; reviewers from service providers; review for safety with Keep activity off; feedback bringing in the last 24 hours of chats and uploads; general area location; permission before using other people’s faces; the warning about confidential information.
- Google, Temporary chats and new privacy controls, 13 August 2025. A sample of uploads from 2 September 2025 used to help improve Google services when the setting is on.
- Google, Generative AI in Google Workspace Privacy Hub, last updated 14 August 2026. Chats and uploaded files not reviewed by people or used for training outside your domain without permission.
- Anthropic, Privacy Policy, effective 10 September 2026. Uploads as Inputs; inputs may be used to train models unless you opt out in your account settings.
- Anthropic, How long do you store my data?, 1 July 2026. Deleted chats removed from history immediately and from back end storage within 30 days; up to five years in training pipelines if you allow it; flagged chats up to 2 years; feedback data five years.
- Anthropic, Use incognito chats. Incognito chats retained for 30 days for safety and not used for training.
- Anthropic, Upload files to Claude. Files uploaded to a chat or to a project’s files for use across conversations.
- Anthropic, Who can view my conversations?. Access limited to a small number of staff involved in model training, after data is unlinked.
- Anthropic, Is my data used for model training? (commercial), 18 August 2026. No training on commercial products by default.
- Anthropic, Compliance API: content and data. Images may be served as a processed copy rather than the uploaded file.
- Microsoft, Privacy FAQ for Microsoft Copilot, older app. Files kept no longer than 18 months; conversations 18 months by default; Vision images not stored after the session; training on uploads with an opt out; metadata removed and faces blurred before training; no opt out of human review; permission for biometric data in Vision; the banner dating the updated app to 18 August 2026.
- Microsoft, Copilot for individuals: your activity history, updated app. Prompts, responses and file contents not used to train foundation models.
- Microsoft Privacy Statement, last updated September 2026. Images uploaded to Copilot collected with related data such as picture metadata.
- Microsoft, Copilot Chat privacy and protections, 24 August 2026. Uploaded files stored in the user’s OneDrive for Business.
- Microsoft, Data, privacy and security for Microsoft 365 Copilot, 18 August 2026. No training of foundation models; abuse monitoring with human review opted out.
- UK GDPR, Article 4. Article 4(14), the definition of biometric data, with facial images as an example.
- UK GDPR, Article 5. Article 5(1)(c), data minimisation.
- UK GDPR, Article 9. Biometric data processed to uniquely identify a person as special category data.
- ICO, What is special category data?. Digital photographs not automatically biometric data; only after specific technical processing, usually a template for automated matching.
- ICO, How do we avoid an accidental breach when personal information is ‘hidden’ in documents?, 31 July 2025. EXIF with GPS as hidden personal information; photo editing software or Windows File Explorer to remove it.
- ICO, Identity theft. Passports and driving licences among the documents to keep safe; protective registration with Cifas.
- ICAO, Doc 9303, Part 4 (PDF). The two machine readable lines of a passport and the data they hold.
Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT. No account needed, and the app does it without your files leaving your machine.
Common questions
Does ChatGPT store photos you upload?
Yes. A photo you upload is saved with the conversation for as long as you keep the chat, and ChatGPT also saves uploaded images to Library, where they stay until you delete them yourself. Deleting the chat does not delete the Library copy. Photos sent in a temporary chat are not saved to Library unless you save that chat. Covering the document first, in your browser, means the stored copy shows nothing personal.
If I delete a ChatGPT chat, is the photo deleted too?
Not necessarily. OpenAI's help centre says deleting a chat containing files does not delete the files saved to Library, so the photo has to be deleted there as well. A deleted Library file goes to Recently deleted first and is then scheduled for permanent deletion from OpenAI's systems within 30 days. Check Library after you delete any chat that held a document.
How long does Gemini keep photos I upload?
As long as the rest of your Gemini activity: 18 months by default, which you can change to 3 months, 36 months or no automatic deletion. With Keep activity off, or in a temporary chat, Google keeps chats with your account for 72 hours. A chat a human reviewer has seen is kept for up to three years, even after you delete your activity.
Does Claude keep images after I delete a chat?
Anthropic gives no separate clock for images on its consumer pages, so a photo follows its conversation: removed from your history straight away and from back end storage within 30 days. Longer periods apply if you allow your chats to improve Claude, if a chat is flagged by its safety systems, or if you send feedback. A photo added to a project's files is not tied to any one chat, so remove it there too.
Does Microsoft Copilot store uploaded images?
It depends on which app you use. Microsoft's pages for the older Copilot app say an uploaded file is kept for no longer than 18 months, and that camera images shared with Vision are not kept after the session. The pages for the updated app, available since 18 August 2026, do not state a retention period. Delete the conversation when you have finished with it, whichever app you use.
Do AI chatbots remove the location data from my photos?
None of the four says so. OpenAI, Google, Anthropic and Microsoft do not state whether the EXIF data in an uploaded photo, including GPS coordinates, is kept or stripped when you upload it. Microsoft's privacy statement says it collects picture metadata with images uploaded to Copilot. The safe course is to remove it yourself: the Nonimo tool downloads a new image without the camera or location data.
Is a photo of a face biometric data under UK GDPR?
Not automatically. The ICO says digital photographs of people are not biometric data just because they could identify someone; they become biometric data only through specific technical processing, usually a template used for automated matching. A photo of a passport is still personal data, though, and when an organisation uploads someone else's document, the UK GDPR's data minimisation principle applies to that choice.
Can someone at OpenAI or Google see the photos I upload?
Possibly. OpenAI says a limited number of authorised staff and trusted service providers may access user content as needed, including to improve its models unless you have opted out. Google says human reviewers, some from its service providers, review some Gemini data, and that this can happen for safety even with Keep activity off. Cover what you would not want a stranger to read.
Is it safe to upload a photo of my passport to ChatGPT?
Not as it is. The full data page shows your face, name, date of birth, passport number and two machine readable lines that repeat the lot, and an uploaded photo can be kept long after the chat. If you need help reading the page, cover the personal fields first. Nonimo's passport tool does that in your browser, so the original never leaves your phone.