Does ChatGPT keep your photos? An Irish guide to AI uploads
· Written and maintained by Nonimo
Yes. ChatGPT keeps a photo you upload for as long as the chat that holds it, and it also saves a copy of the image to Library, a part of your account that deleting the chat does not empty. Gemini and Claude keep an uploaded photo as part of the conversation, on the same clock as the text. Microsoft Copilot’s answer depends on which of its two consumer apps you have.
And none of the four says, on the pages we read on 3 October 2026, whether the location and camera details inside a phone photo are kept or removed when it arrives.
That matters most for photos of documents: a passport page, a driving licence, a letter from Revenue, a prescription, a screenshot of your banking app. The image carries a face, a signature, a document number and sometimes a point on a map that the question you were asking never needed. The cheapest fix is to cover them on your own device before the upload, which is what our passport redaction tool does in your browser.
Does ChatGPT keep your photos? The four assistants side by side
No provider runs a separate clock for images. A photo is treated as content you uploaded, like the words around it, and it lives where the conversation lives. The exceptions are the ones worth knowing, and they are all in this table.
| Assistant, personal account | Where an uploaded photo is kept | How long |
|---|---|---|
| ChatGPT | In the chat, and a copy in Library | Until you delete the chat, and the Library file separately |
| ChatGPT, Temporary Chat | Not in your history or Library | Up to 30 days, for safety |
| Gemini | In your Gemini Apps Activity | 18 months by default; 72 hours with Keep Activity off |
| Claude | In the chat, or in a project’s files | Until you delete it, then up to 30 days |
| Copilot, app of 18 August 2026 | Not stated by Microsoft | Not stated by Microsoft |
| Copilot, older app | Files held for a short time | No longer than 18 months |
Each provider’s own help and privacy pages, read 3 October 2026 and listed in the sources.
What happens after you press delete is a second clock, and it is where the four differ most. ChatGPT, Gemini and Claude each keep something longer in specific cases: a chat a reviewer read, a chat you rated, a chat a safety system flagged. The sections below take them one at a time, starting with the one most people use, and our guide to what ChatGPT keeps of your data covers the conversation side in more depth.
Does ChatGPT keep your photos after you delete the chat?
OpenAI’s privacy policy counts images among the content you upload, alongside prompts, files, audio and video. Its help centre then says that files uploaded to ChatGPT are saved in your account up to the retention period of the chat they belong to, and that regular and archived chats stay saved until you delete them.
So far that is the same rule as for text. When you delete, OpenAI’s Europe privacy policy says it removes personal data from its systems within 30 days unless it needs to keep it longer. Its US policy spells out one more exception in that sentence: content already de-identified and disassociated from your account for model training, if you allowed that.
Library: the copy that outlives the chat
The newer part is Library. OpenAI says ChatGPT automatically saves uploaded and created files, including files uploaded in chats, and it names images among them. Library is available on Free, Go, Plus, Pro and Business, and on Enterprise, Edu and Healthcare workspaces, including those in the European Economic Area, so it applies to accounts in Ireland.
Files in Library are saved to your account until you delete them manually. So does ChatGPT keep your photos once the chat is gone? In Library, yes. That breaks a habit many people rely on: ask the question, delete the chat, assume the photo of the passport went with it.
To remove it, open Library and delete the file there too. It moves to a recently deleted step first, and OpenAI says deleted files are then scheduled for permanent deletion from its systems within 30 days.
Temporary Chat keeps the photo out of Library, not out of OpenAI
A Temporary Chat changes this in one direction. OpenAI says files uploaded in a Temporary Chat are not saved to your account or to Library, and that it may keep a copy of a temporary chat for up to 30 days for safety purposes.
There is a catch at the end of the conversation. If you save a temporary chat that includes uploaded files, OpenAI says eligible files may then be saved to Library as well, so the photo ends up in Library after all.
Images that ChatGPT creates for you live somewhere else again, under Images. To delete one of those, OpenAI’s instruction is to delete the conversation the image was made in.
That rule is about images the assistant generates, not the photos you upload, and mixing the two up is how a document photo gets left behind. A spreadsheet you attach follows the same Library rule, which is one more reason to trim a CSV to the columns the question needs before it goes.
Gemini keeps your photos with your activity, 18 months by default
Google’s Gemini Apps Privacy Hub, updated on 24 September 2026, puts photos in the same list as everything else: your chats and what you share with Gemini, such as files, videos, screens and photos, are saved in your Activity. Gemini also uses Google Lens technology to understand what is in an image and to read the text in it, so the number on a document is read, not just seen.
Retention follows that Activity setting. The default is 18 months, and you can change it to 3 months, 36 months or indefinitely. Temporary chats, and chats you have with Keep Activity off, are kept with your account for 72 hours. Google does not give a separate clock for uploads.
Chats a reviewer reads can stay up to three years
Google says human reviewers, including trained reviewers from its service providers, read some of the data it collects. Chats that reviewers have read, with related data such as your language, device type or location information, are not deleted when you delete your activity. They are kept for up to three years, disconnected from your account. Google’s own advice is not to enter confidential information you would not want a reviewer to see.
Review is not only about improving the models. Google says that even with Keep Activity off it uses your chats to respond to you and to help protect Google, its users and the public, with help from human reviewers. And if you send feedback with Keep Activity off, the content of the chats it covers, uploads included, goes with it.
A sample of uploads, since September 2025
In August 2025 Google announced that, with the setting on, a sample of your future uploads would be used to help improve Google services for everyone, starting with uploads submitted from 2 September 2025.
The current hub adds a line about photos you bring in from Google Photos: with Keep Activity on, they are used to improve Google services with the help of human reviewers. Our guide to whether Gemini uses your data sets out what the Keep Activity switch reaches and what it does not.
Claude keeps an uploaded image as part of the chat
Anthropic’s privacy policy calls whatever you upload your Inputs, and an image is one of them. You can upload files to a single chat, or to a project’s Files section for persistent reference across conversations. A photo placed in a project is there for every conversation in that project until you take it out, which is worth remembering before you drop a scan of an ID into a project called Admin.
Anthropic’s consumer pages give no separate clock for files. Its documentation for organisations says that deleting a chat removes its attached files with it. When you delete a conversation, Anthropic says it is removed from its backend storage within 30 days. Incognito chats are kept for 30 days for safety and are not used for training.
Your training setting, and the clocks behind it
Anthropic’s policy says it may use your inputs and outputs to train its models unless you opt out through your account settings, and the pages we read do not set a separate rule for images. Nor do they state, in so many words, which way the switch starts on a new account, so the setting in your own account is the thing to check.
If you allow training, Anthropic says it may keep your data in de-identified form for up to five years in its training pipelines. A chat its safety systems flag is kept for up to two years, and the classification scores for up to seven. A chat you rate with the feedback buttons is kept for five years.
Data already used in a finished training run stays in that model. Our guide to whether Claude trains on your data works through each of those clocks.
Copilot: two apps, and two sets of answers about your photos
Since 18 August 2026 Microsoft has documented its consumer Copilot twice, with a banner telling you which version each page applies to. The answer to whether Copilot keeps your photos depends on which one is on your phone or laptop, and the two do not agree.
The new app: no training on your files, no stated clock
For the Copilot app released on 18 August 2026, Microsoft says that prompts, responses and your file contents are not used to train foundation models. The pages for that app that we read do not state how long chats or files are kept, and do not say whether people review them.
Microsoft’s general Privacy Statement, updated in September 2026, adds a detail none of the other three spell out. Among the data Microsoft collects it lists images and related data, like picture metadata, and it gives uploading an image to Copilot as its example.
The older app: 18 months for files, and a rule about faces
The older app’s privacy questions and answers are more specific. A file you upload is stored for a short time, no longer than 18 months, and then automatically deleted, and conversation activity is stored for 18 months by default. Screenshots and camera images shared with Copilot Vision are not stored after the session ends.
The older app trains on uploads unless you opt out, and it is the only one of the four with a written rule for images: before training, Microsoft says it takes steps such as removing metadata and blurring faces. That rule is about training, not storage.
The same page says some conversations get automated and human review, and that an opt out of human review is not available. Our guide to which Copilot has your data explains how to tell the apps and accounts apart.
Training and human review: who may look at your photo
Keeping a photo and using it are separate questions. A photo can be stored for months without anyone looking at it, or be read by a reviewer. On a personal account the four answer the second question like this.
| Assistant, personal account | Trains on uploads by default | People may see it |
|---|---|---|
| ChatGPT | Yes, images included | Authorised staff and service providers, when needed |
| Gemini | Yes, with Keep Activity on | Yes, reviewers from providers too |
| Claude | Your setting decides | A few training staff, after the chat is separated from your account |
| Copilot, new app | No, for foundation models | Not stated |
| Copilot, older app | Yes, with faces blurred first | Yes, with no opt out |
OpenAI, Google, Anthropic and Microsoft help and privacy pages, read 3 October 2026.
OpenAI says plainly that it may use content such as images and files to improve its models, and its image FAQ says its approach to content, images included, stays the same for each product. The switch is Improve the model for everyone, under Settings and then Data controls. Turning it off does not delete or hide saved chats, and OpenAI’s own line on this is direct: do not enter sensitive information you would not want reviewed or used.
The feedback buttons undo the opt out
A thumbs up or thumbs down is the quiet exception. OpenAI says that if you give feedback, the entire conversation linked to it may be used to train its models, which includes the photo in it. Anthropic keeps a rated chat for five years. Rating an answer about your passport offers the passport up for training, so leave those buttons alone on anything with a document in it.
A work account changes the answer
On a work account all four move towards the cautious end, and for most offices this is the version that matters.
| Work account | Trains by default | Who else may see an upload |
|---|---|---|
| ChatGPT Business | No | Your workspace admins, and contractors reviewing abuse |
| Gemini in Google Workspace | No, not outside your domain without permission | No human review without permission |
| Claude Team or Enterprise | No | Not stated beyond flagged chats |
| Copilot on a work account | No | Microsoft has opted out of human review; files sit in OneDrive for Business |
OpenAI Enterprise privacy, 8 January 2026; Google Workspace Privacy Hub, 14 August 2026; Anthropic privacy centre, 18 August 2026; Microsoft Learn, 18 and 24 August 2026.
On these plans, how long a conversation and its files are kept is largely set by the organisation rather than by you, which is the strongest reason to put a photo of a client’s document through the firm’s account rather than a personal one. Our guide to which AI is GDPR compliant compares the business plans in more detail.
What a photo of a document carries that typed text does not
Type “what does a code in column 12 of my licence mean” and you have sent a question. Upload a photo of the licence to ask the same thing and you have sent your face, your signature, your date of birth, your address, your driver number and whatever else was on the table when you took it. The question did not change; what travels with it did.
A clear, front facing photo, printed to be recognised. Personal data on its own.
On a licence, a Public Services Card and some passport pages. Few questions about a form need it.
A passport number in the page and again in the two lines at the foot; a PPS number on the card.
The time, the phone model and often the place where the photo was taken.
The Data Protection Commission puts a name or an image among the direct identifiers in its guidance on anonymisation, the details that point to one person without any help. A typed question can usually be asked without one. A photo of a document almost never can.
A face is personal data, and facial matching makes it biometric
The GDPR draws a careful line here. Recital 51 says the processing of photographs should not systematically be treated as processing special categories of data, because a photo is covered by the definition of biometric data only when it is processed through specific technical means that allow a person to be uniquely identified.
Article 4(14) names facial images as an example of biometric data in that sense, and Article 9(1) prohibits processing biometric data to uniquely identify someone unless an exception applies.
Ireland has a recent example of where that line sits. On 12 June 2025 the DPC announced its decision on the Department of Social Protection’s use of facial matching when people register for a Public Services Card. It found infringements of Article 9(1) among others, reprimanded the Department and fined it €550,000. In 2021, the DPC said, the Department held biometric facial templates for 70% of the population of the State.
The photo itself is ordinary personal data. What turns a face into biometric data is what someone does with it afterwards, and once a photo is uploaded, that happens on another company’s systems under its rules.
None of the four providers states a rule for identity documents or faces in the photos users upload; Microsoft says its work Copilot’s analysis of an image with people in it may include their physical and facial characteristics, and that the model cannot otherwise identify unique individuals. Our guide to special category data and AI covers the categories that need an exception before they go anywhere.
The number, twice
Identity documents repeat themselves. The two machine readable lines at the foot of a passport page carry your name, passport number, nationality, date of birth and expiry date again, in a format any reader takes in at a glance. Covering the number in the body and leaving it in those lines protects nothing.
Irish cards add numbers of their own. A Public Services Card prints your PPS number, and a driving licence carries your driver number at 4d. Our list of what personal data to redact treats each of those as an identifier in its own right, and the same goes for an Eircode on a letter you photograph.
The metadata in a phone photo: EXIF, GPS and what the providers say
A phone photo is more than its pixels. The DPC’s guidance on redacting documents notes that some phones and cameras add metadata to files, including the username of the person who took the photo, the date and time, the location, and even the lens and camera settings. The standard name for most of that is EXIF, and the location part is the GPS position.
What the four do say is narrower than it sounds. OpenAI says its model does not process original file names or metadata, and that images are resized before analysis; that is about what the model reads, not what OpenAI stores.
Microsoft lists picture metadata among the image data it collects, and the older Copilot says it removes metadata before training, a rule about training rather than storage. Anthropic’s documentation for organisations says images can be served as a processed copy rather than the uploaded bytes, without saying the metadata goes. Google’s location rules for Gemini concern your device’s location, not the data inside a photo.
When nobody commits to removing something, the only removal you can count on is your own. A copy saved without metadata has nothing to keep. Our guide to removing metadata from files shows what a photo inside a Word file gave away in a test, GPS included.
Before you upload a photo of a document: what to cover
The DPC’s advice on AI tools starts where this guide does, with knowing what happens to the data before you put it in:
“Before you start using an AI system, you should first understand what personal data it uses, how it uses it, where the personal data goes (…) whether it is retained by the provider of the AI product.”
Data Protection Commission, AI, Large Language Models and Data Protection, 18 July 2024
The GDPR’s principle of data minimisation, in Article 5(1)(c), says personal data should be limited to what is necessary for the purpose. For a photo going to a chatbot, that turns into a short routine.
- Ask whether it needs the photo. Many questions about a form or a letter can be typed. If the words are enough, the image does not need to go at all.
- Crop to the part you are asking about. A question about a licence category needs the categories, not the whole card and the kitchen table under it.
- Cover the person. Face, name, signature, date of birth, document number and the machine readable lines, unless the question is about one of them.
- Send a copy without metadata. A clean export drops the time, the phone and the place. Do not count on the assistant to do it for you.
- Choose the short clock. A Temporary Chat, an incognito chat or Keep Activity off keeps the photo for days or weeks rather than months, and training switched off keeps it out of model training, as long as you leave the feedback buttons alone.
- Delete in every place it went. The chat, the ChatGPT Library file, any Claude project, and the original in your camera roll if you do not need it.
Less goes, and less is kept
Covering is data minimisation done before the upload: what the question does not need stays on your device, so none of the clocks above applies to it. Our guide to copying a driving licence shows which fields a typical question about a licence actually needs.
Already uploaded one? Deleting a photo from each assistant
If a photo of a document has already gone, deleting it is still worth doing, as long as you delete it in the right places. Each assistant keeps something after the delete button, and this is where.
| Assistant | What to delete | What can outlast it |
|---|---|---|
| ChatGPT | The chat, then the image in Library | Up to 30 days; copies already de-identified for training |
| Gemini | The chat in Gemini Apps Activity | Chats a reviewer read, for up to 3 years |
| Claude | The chat, and the file in any project | Up to 30 days; longer if training was on or you rated the chat |
| Copilot | The chat, from its menu or the privacy dashboard | Not stated for either app; older app files are capped at 18 months |
Provider pages as cited above, read 3 October 2026.
Under Article 77 of the GDPR you can complain to a supervisory authority in the Member State where you live or work, which for most readers of this guide means the DPC. Before that route, the deletion tools above are quicker, and our guide to what ChatGPT keeps of your data covers the memory and the other copies a deleted chat can leave behind.
Cover a photo of your passport or licence in your browser
The Nonimo passport tool works on a phone or a computer. Drop in a photo or PDF of your passport data page or Passport Card, and it recognises the document and covers the signature, the dates, the place of birth and the bottom lines straight away. Each detail appears as a chip with its own name; tap one to cover it or show it again.
For an AI, tap your name, passport number and photo too, so nothing about you is left visible. The driving licence version does the same for the NDLS card: tap the name, licence number and photo there too, and the categories a question is usually about stay readable.
Then download the result as PNG, JPG or PDF, with the boxes burned into the pixels and no location or camera data in the file. Your document never leaves your device: it is read and redacted in your browser. What reaches the chatbot is the copy you chose to send.
For the text you put into AI tools at work, the same habit is built into our app: software that covers names, PPS numbers and Eircodes before your text reaches ChatGPT.
Sources
- OpenAI, Europe privacy policy (updated 24 August 2026). Deleted personal data removed from OpenAI’s systems within 30 days unless it must be kept longer. openai.com
- OpenAI, Privacy policy (updated 10 September 2026). Content includes files and images you upload; the exception for content already de-identified and disassociated from your account for model improvement. openai.com
- OpenAI Help Center, Using Library to manage files in ChatGPT (read 3 October 2026). Uploaded files, images included, saved automatically; availability on personal and business plans including the EEA; deleting a chat does not delete Library files; saved until deleted manually; deleted files scheduled for permanent deletion within 30 days; Temporary Chat uploads not saved to Library. help.openai.com
- OpenAI Help Center, File uploads FAQ, and Chat and file retention in ChatGPT. Files saved up to the retention period of the chat; regular and archived chats kept until you delete them. File uploads, retention
- OpenAI Help Center, Temporary chat in ChatGPT. Copy kept for up to 30 days for safety; eligible files may go to Library if you save the chat. help.openai.com
- OpenAI Help Center, How OpenAI handles data in consumer services, How your data is used to improve model performance, and Data controls in ChatGPT. Images and files may be used to improve models; access by authorised staff and service providers; the opt out and the feedback exception; turning training off does not delete chats. Consumer services, model performance, data controls
- OpenAI Help Center, ChatGPT Image Inputs FAQ, and Images in ChatGPT. The model does not process original file names or metadata, and images are resized; the same approach to images as other content; generated images saved under Images and deleted with their conversation. Image inputs, Images
- OpenAI, Enterprise privacy (updated 8 January 2026). Business admins can view and export conversations; contractors review Business content for abuse. openai.com
- Google, Gemini Apps Privacy Hub (updated 24 September 2026) and Gemini Apps Privacy Notice (29 June 2026). Photos saved in Activity; Google Lens reads text in images; 18 month default with 3, 36 months or indefinite; 72 hours with Keep Activity off; reviewed chats kept up to three years; reviewers from service providers; review for safety with Keep Activity off; Google Photos and reviewers; device location rules. support.google.com
- Google, The Keyword, 13 August 2025. A sample of future uploads used to improve Google services when the setting is on, for uploads from 2 September 2025. blog.google
- Google Workspace, Generative AI in Google Workspace Privacy Hub (14 August 2026). Chats and uploaded files not reviewed by humans or used to train models outside your domain without permission. knowledge.workspace.google.com
- Anthropic, Privacy Policy (effective 10 September 2026). Uploads are Inputs; training unless you opt out through account settings. anthropic.com
- Anthropic privacy centre, How long do you store my data? (1 July 2026), and Is my data used for model training? (commercial, 18 August 2026). 30 days after deletion; five years de-identified if training is allowed; two and seven years for flagged chats; five years for feedback; models already trained; no training by default on commercial products. Retention, commercial training
- Claude Help Center, Upload files to Claude, and Use incognito chats. Files in a chat or in a project’s Files section; incognito chats kept 30 days for safety and not used for training. Upload files, incognito
- Anthropic, Compliance API documentation. Deleting a chat removes its attached files; images may be served as a processed copy. platform.claude.com
- Microsoft Support, Copilot for individuals: your activity history (app of 18 August 2026). File contents not used to train foundation models. support.microsoft.com
- Microsoft Support, Privacy FAQ for Microsoft Copilot (older app). Files kept no longer than 18 months; conversations 18 months; Vision images not stored after the session; images de-identified before training; no opt out of human review. support.microsoft.com
- Microsoft Privacy Statement (September 2026). Images and related data, like picture metadata, collected when you upload an image to Copilot. microsoft.com
- Microsoft Learn, Copilot Chat privacy and protections (24 August 2026), and Data, Privacy, and Security for Microsoft Copilot (18 August 2026). Uploaded files stored in OneDrive for Business; no training of foundation models; Copilot services opted out of abuse monitoring with human review. Copilot Chat, Microsoft Copilot
- Microsoft Support, Frequently asked questions about Microsoft 365 Copilot Chat. Image analysis may include physical and facial characteristics; the model cannot otherwise identify unique individuals. support.microsoft.com
- Regulation (EU) 2016/679 (GDPR). Recital 51 on photographs; Article 4(14) on biometric data; Article 5(1)(c) on data minimisation; Article 9(1); Article 77 on complaints. eur-lex.europa.eu
- Data Protection Commission, press release of 12 June 2025. Decision on facial matching at Public Services Card registration: infringements including Article 9(1), a reprimand and fines of €550,000; facial templates for 70% of the population in 2021. dataprotection.ie
- Data Protection Commission, AI, Large Language Models and Data Protection (18 July 2024). Understand what personal data an AI system uses, where it goes and whether the provider keeps it. dataprotection.ie
- Data Protection Commission, Guidance on Anonymisation and Pseudonymisation (June 2019). A name or image as a direct identifier; masking alone not normally anonymisation. dataprotection.ie
- Data Protection Commission, Redacting Documents and Records (August 2021). Phones and cameras add the username, date, time, location and camera settings to a photo. dataprotection.ie
Common questions
Does ChatGPT keep your photos?
Yes. A photo you upload is saved with the chat for as long as the chat is kept, and ChatGPT also saves uploaded images to Library, where they stay until you delete them yourself. Deleting the chat does not delete the Library copy. Covering the face, signature and document number on your own device before the upload, which our passport tool does in the browser, means less of you is kept.
Does deleting a ChatGPT chat delete the photo I uploaded?
Not on its own. OpenAI's help page on Library says that deleting a chat containing files does not delete those files saved to Library. Open Library, delete the image there as well, and it goes to a recently deleted step before OpenAI schedules it for permanent deletion within 30 days. Photos uploaded in a Temporary Chat are not saved to Library unless you save that chat.
How long does Gemini keep photos I upload?
As long as your Gemini Apps Activity keeps the chat: 18 months by default, or 3 months, 36 months or indefinitely if you change it. With Keep Activity off, or in a temporary chat, chats are kept with your account for 72 hours. A chat read by a human reviewer is kept for up to three years, disconnected from your account, even after you delete your activity.
Does Claude keep images I upload?
Yes, as part of the conversation, or in a project's files if you add the image there. When you delete a conversation, Anthropic says it leaves its backend storage within 30 days. If you allow model training, data can stay in de-identified form for up to five years, and a chat you rate with the feedback buttons is kept for five years. Anthropic gives no separate clock for images.
Does Microsoft Copilot keep my photos?
It depends on the app. For the Copilot app of 18 August 2026, Microsoft says your file contents are not used to train foundation models, but its pages do not state how long files are kept. For the older app, Microsoft says files are kept no longer than 18 months, and that screenshots and camera images shared with Copilot Vision are not stored after the session ends.
Do ChatGPT, Gemini, Claude or Copilot remove location data from photos?
None of the four says so for an uploaded photo. OpenAI says only that its model does not process original metadata, which is about what the model reads, not what is stored. Microsoft lists picture metadata among the image data it collects. A phone photo can carry the time, the place and the camera, so the safe course is a copy without metadata, which is what our tool downloads.
Can people at OpenAI or Google see the photos I upload?
They can. OpenAI says a limited number of authorised staff and trusted service providers may access user content when needed, including to improve models unless you opt out. Google says human reviewers, some from its service providers, read a subset of Gemini chats, also for safety with Keep Activity off. Neither excludes images. Covering a document before the upload limits what anyone sees.
Is a photo of my face biometric data under the GDPR?
Not automatically. Recital 51 of the GDPR says a photograph counts as biometric data only when it is processed through specific technical means that allow a person to be uniquely identified, and Article 9 restricts biometric data used for that purpose. A face in a photo is still personal data, so covering it before an upload remains the sensible default for any image the question does not need.
What should I cover before I upload a photo of my passport to an AI?
Everything the question does not need: your photo, name, passport number, signature, date and place of birth, and the two machine readable lines at the foot of the page, which repeat most of those details. Then send a copy without location data. Our passport tool does all of that in your browser, with each detail as a chip you can tap to cover or show.