[nonimo]
EN
Download

Does ChatGPT keep your photos? An Irish guide to AI uploads

· Written and maintained by Nonimo

Yes. ChatGPT keeps a photo you upload for as long as the chat that holds it, and it also saves a copy of the image to Library, a part of your account that deleting the chat does not empty. Gemini and Claude keep an uploaded photo as part of the conversation, on the same clock as the text. Microsoft Copilot’s answer depends on which of its two consumer apps you have.

And none of the four says, on the pages we read on 3 October 2026, whether the location and camera details inside a phone photo are kept or removed when it arrives.

That matters most for photos of documents: a passport page, a driving licence, a letter from Revenue, a prescription, a screenshot of your banking app. The image carries a face, a signature, a document number and sometimes a point on a map that the question you were asking never needed. The cheapest fix is to cover them on your own device before the upload, which is what our passport redaction tool does in your browser.

Does ChatGPT keep your photos? The four assistants side by side

No provider runs a separate clock for images. A photo is treated as content you uploaded, like the words around it, and it lives where the conversation lives. The exceptions are the ones worth knowing, and they are all in this table.

Assistant, personal accountWhere an uploaded photo is keptHow long
ChatGPTIn the chat, and a copy in LibraryUntil you delete the chat, and the Library file separately
ChatGPT, Temporary ChatNot in your history or LibraryUp to 30 days, for safety
GeminiIn your Gemini Apps Activity18 months by default; 72 hours with Keep Activity off
ClaudeIn the chat, or in a project’s filesUntil you delete it, then up to 30 days
Copilot, app of 18 August 2026Not stated by MicrosoftNot stated by Microsoft
Copilot, older appFiles held for a short timeNo longer than 18 months

Each provider’s own help and privacy pages, read 3 October 2026 and listed in the sources.

What happens after you press delete is a second clock, and it is where the four differ most. ChatGPT, Gemini and Claude each keep something longer in specific cases: a chat a reviewer read, a chat you rated, a chat a safety system flagged. The sections below take them one at a time, starting with the one most people use, and our guide to what ChatGPT keeps of your data covers the conversation side in more depth.

Does ChatGPT keep your photos after you delete the chat?

OpenAI’s privacy policy counts images among the content you upload, alongside prompts, files, audio and video. Its help centre then says that files uploaded to ChatGPT are saved in your account up to the retention period of the chat they belong to, and that regular and archived chats stay saved until you delete them.

So far that is the same rule as for text. When you delete, OpenAI’s Europe privacy policy says it removes personal data from its systems within 30 days unless it needs to keep it longer. Its US policy spells out one more exception in that sentence: content already de-identified and disassociated from your account for model training, if you allowed that.

Library: the copy that outlives the chat

The newer part is Library. OpenAI says ChatGPT automatically saves uploaded and created files, including files uploaded in chats, and it names images among them. Library is available on Free, Go, Plus, Pro and Business, and on Enterprise, Edu and Healthcare workspaces, including those in the European Economic Area, so it applies to accounts in Ireland.

Not deleted with the chat
"Deleting a chat containing files does not delete those files saved to Library." OpenAI Help Center, Using Library, read 3 October 2026

Files in Library are saved to your account until you delete them manually. So does ChatGPT keep your photos once the chat is gone? In Library, yes. That breaks a habit many people rely on: ask the question, delete the chat, assume the photo of the passport went with it.

To remove it, open Library and delete the file there too. It moves to a recently deleted step first, and OpenAI says deleted files are then scheduled for permanent deletion from its systems within 30 days.

Temporary Chat keeps the photo out of Library, not out of OpenAI

A Temporary Chat changes this in one direction. OpenAI says files uploaded in a Temporary Chat are not saved to your account or to Library, and that it may keep a copy of a temporary chat for up to 30 days for safety purposes.

There is a catch at the end of the conversation. If you save a temporary chat that includes uploaded files, OpenAI says eligible files may then be saved to Library as well, so the photo ends up in Library after all.

Images that ChatGPT creates for you live somewhere else again, under Images. To delete one of those, OpenAI’s instruction is to delete the conversation the image was made in.

That rule is about images the assistant generates, not the photos you upload, and mixing the two up is how a document photo gets left behind. A spreadsheet you attach follows the same Library rule, which is one more reason to trim a CSV to the columns the question needs before it goes.

Gemini keeps your photos with your activity, 18 months by default

Google’s Gemini Apps Privacy Hub, updated on 24 September 2026, puts photos in the same list as everything else: your chats and what you share with Gemini, such as files, videos, screens and photos, are saved in your Activity. Gemini also uses Google Lens technology to understand what is in an image and to read the text in it, so the number on a document is read, not just seen.

Retention follows that Activity setting. The default is 18 months, and you can change it to 3 months, 36 months or indefinitely. Temporary chats, and chats you have with Keep Activity off, are kept with your account for 72 hours. Google does not give a separate clock for uploads.

72 hourswith Keep Activity off, or in a temporary chat
18 monthsthe default for Gemini Apps Activity
3 yearsat most, for chats read by human reviewers, even after you delete them
Gemini Apps Privacy Notice, 29 June 2026, and Gemini Apps Privacy Hub, 24 September 2026

Chats a reviewer reads can stay up to three years

Google says human reviewers, including trained reviewers from its service providers, read some of the data it collects. Chats that reviewers have read, with related data such as your language, device type or location information, are not deleted when you delete your activity. They are kept for up to three years, disconnected from your account. Google’s own advice is not to enter confidential information you would not want a reviewer to see.

Review is not only about improving the models. Google says that even with Keep Activity off it uses your chats to respond to you and to help protect Google, its users and the public, with help from human reviewers. And if you send feedback with Keep Activity off, the content of the chats it covers, uploads included, goes with it.

A sample of uploads, since September 2025

In August 2025 Google announced that, with the setting on, a sample of your future uploads would be used to help improve Google services for everyone, starting with uploads submitted from 2 September 2025.

The current hub adds a line about photos you bring in from Google Photos: with Keep Activity on, they are used to improve Google services with the help of human reviewers. Our guide to whether Gemini uses your data sets out what the Keep Activity switch reaches and what it does not.

Claude keeps an uploaded image as part of the chat

Anthropic’s privacy policy calls whatever you upload your Inputs, and an image is one of them. You can upload files to a single chat, or to a project’s Files section for persistent reference across conversations. A photo placed in a project is there for every conversation in that project until you take it out, which is worth remembering before you drop a scan of an ID into a project called Admin.

Anthropic’s consumer pages give no separate clock for files. Its documentation for organisations says that deleting a chat removes its attached files with it. When you delete a conversation, Anthropic says it is removed from its backend storage within 30 days. Incognito chats are kept for 30 days for safety and are not used for training.

Your training setting, and the clocks behind it

Anthropic’s policy says it may use your inputs and outputs to train its models unless you opt out through your account settings, and the pages we read do not set a separate rule for images. Nor do they state, in so many words, which way the switch starts on a new account, so the setting in your own account is the thing to check.

If you allow training, Anthropic says it may keep your data in de-identified form for up to five years in its training pipelines. A chat its safety systems flag is kept for up to two years, and the classification scores for up to seven. A chat you rate with the feedback buttons is kept for five years.

Data already used in a finished training run stays in that model. Our guide to whether Claude trains on your data works through each of those clocks.

Copilot: two apps, and two sets of answers about your photos

Since 18 August 2026 Microsoft has documented its consumer Copilot twice, with a banner telling you which version each page applies to. The answer to whether Copilot keeps your photos depends on which one is on your phone or laptop, and the two do not agree.

The new app: no training on your files, no stated clock

For the Copilot app released on 18 August 2026, Microsoft says that prompts, responses and your file contents are not used to train foundation models. The pages for that app that we read do not state how long chats or files are kept, and do not say whether people review them.

Microsoft’s general Privacy Statement, updated in September 2026, adds a detail none of the other three spell out. Among the data Microsoft collects it lists images and related data, like picture metadata, and it gives uploading an image to Copilot as its example.

The older app: 18 months for files, and a rule about faces

The older app’s privacy questions and answers are more specific. A file you upload is stored for a short time, no longer than 18 months, and then automatically deleted, and conversation activity is stored for 18 months by default. Screenshots and camera images shared with Copilot Vision are not stored after the session ends.

The older app trains on uploads unless you opt out, and it is the only one of the four with a written rule for images: before training, Microsoft says it takes steps such as removing metadata and blurring faces. That rule is about training, not storage.

The same page says some conversations get automated and human review, and that an opt out of human review is not available. Our guide to which Copilot has your data explains how to tell the apps and accounts apart.

Training and human review: who may look at your photo

Keeping a photo and using it are separate questions. A photo can be stored for months without anyone looking at it, or be read by a reviewer. On a personal account the four answer the second question like this.

Assistant, personal accountTrains on uploads by defaultPeople may see it
ChatGPTYes, images includedAuthorised staff and service providers, when needed
GeminiYes, with Keep Activity onYes, reviewers from providers too
ClaudeYour setting decidesA few training staff, after the chat is separated from your account
Copilot, new appNo, for foundation modelsNot stated
Copilot, older appYes, with faces blurred firstYes, with no opt out

OpenAI, Google, Anthropic and Microsoft help and privacy pages, read 3 October 2026.

OpenAI says plainly that it may use content such as images and files to improve its models, and its image FAQ says its approach to content, images included, stays the same for each product. The switch is Improve the model for everyone, under Settings and then Data controls. Turning it off does not delete or hide saved chats, and OpenAI’s own line on this is direct: do not enter sensitive information you would not want reviewed or used.

The feedback buttons undo the opt out

A thumbs up or thumbs down is the quiet exception. OpenAI says that if you give feedback, the entire conversation linked to it may be used to train its models, which includes the photo in it. Anthropic keeps a rated chat for five years. Rating an answer about your passport offers the passport up for training, so leave those buttons alone on anything with a document in it.

A work account changes the answer

On a work account all four move towards the cautious end, and for most offices this is the version that matters.

Work accountTrains by defaultWho else may see an upload
ChatGPT BusinessNoYour workspace admins, and contractors reviewing abuse
Gemini in Google WorkspaceNo, not outside your domain without permissionNo human review without permission
Claude Team or EnterpriseNoNot stated beyond flagged chats
Copilot on a work accountNoMicrosoft has opted out of human review; files sit in OneDrive for Business

OpenAI Enterprise privacy, 8 January 2026; Google Workspace Privacy Hub, 14 August 2026; Anthropic privacy centre, 18 August 2026; Microsoft Learn, 18 and 24 August 2026.

On these plans, how long a conversation and its files are kept is largely set by the organisation rather than by you, which is the strongest reason to put a photo of a client’s document through the firm’s account rather than a personal one. Our guide to which AI is GDPR compliant compares the business plans in more detail.

What a photo of a document carries that typed text does not

Type “what does a code in column 12 of my licence mean” and you have sent a question. Upload a photo of the licence to ask the same thing and you have sent your face, your signature, your date of birth, your address, your driver number and whatever else was on the table when you took it. The question did not change; what travels with it did.

The face

A clear, front facing photo, printed to be recognised. Personal data on its own.

The signature

On a licence, a Public Services Card and some passport pages. Few questions about a form need it.

The numbers, twice

A passport number in the page and again in the two lines at the foot; a PPS number on the card.

The data you cannot see

The time, the phone model and often the place where the photo was taken.

What a phone photo of an Irish ID document carries beyond the question you asked

The Data Protection Commission puts a name or an image among the direct identifiers in its guidance on anonymisation, the details that point to one person without any help. A typed question can usually be asked without one. A photo of a document almost never can.

A face is personal data, and facial matching makes it biometric

The GDPR draws a careful line here. Recital 51 says the processing of photographs should not systematically be treated as processing special categories of data, because a photo is covered by the definition of biometric data only when it is processed through specific technical means that allow a person to be uniquely identified.

Article 4(14) names facial images as an example of biometric data in that sense, and Article 9(1) prohibits processing biometric data to uniquely identify someone unless an exception applies.

Ireland has a recent example of where that line sits. On 12 June 2025 the DPC announced its decision on the Department of Social Protection’s use of facial matching when people register for a Public Services Card. It found infringements of Article 9(1) among others, reprimanded the Department and fined it €550,000. In 2021, the DPC said, the Department held biometric facial templates for 70% of the population of the State.

€550,000
in fines on the Department of Social Protection over its facial templates for Public Services Card registration. DPC, 12 June 2025

The photo itself is ordinary personal data. What turns a face into biometric data is what someone does with it afterwards, and once a photo is uploaded, that happens on another company’s systems under its rules.

None of the four providers states a rule for identity documents or faces in the photos users upload; Microsoft says its work Copilot’s analysis of an image with people in it may include their physical and facial characteristics, and that the model cannot otherwise identify unique individuals. Our guide to special category data and AI covers the categories that need an exception before they go anywhere.

The number, twice

Identity documents repeat themselves. The two machine readable lines at the foot of a passport page carry your name, passport number, nationality, date of birth and expiry date again, in a format any reader takes in at a glance. Covering the number in the body and leaving it in those lines protects nothing.

Irish cards add numbers of their own. A Public Services Card prints your PPS number, and a driving licence carries your driver number at 4d. Our list of what personal data to redact treats each of those as an identifier in its own right, and the same goes for an Eircode on a letter you photograph.

The metadata in a phone photo: EXIF, GPS and what the providers say

A phone photo is more than its pixels. The DPC’s guidance on redacting documents notes that some phones and cameras add metadata to files, including the username of the person who took the photo, the date and time, the location, and even the lens and camera settings. The standard name for most of that is EXIF, and the location part is the GPS position.

0 of 4
assistants whose pages say whether the GPS and camera data in an uploaded photo is kept or removed on arrival. Read 3 October 2026

What the four do say is narrower than it sounds. OpenAI says its model does not process original file names or metadata, and that images are resized before analysis; that is about what the model reads, not what OpenAI stores.

Microsoft lists picture metadata among the image data it collects, and the older Copilot says it removes metadata before training, a rule about training rather than storage. Anthropic’s documentation for organisations says images can be served as a processed copy rather than the uploaded bytes, without saying the metadata goes. Google’s location rules for Gemini concern your device’s location, not the data inside a photo.

When nobody commits to removing something, the only removal you can count on is your own. A copy saved without metadata has nothing to keep. Our guide to removing metadata from files shows what a photo inside a Word file gave away in a test, GPS included.

Before you upload a photo of a document: what to cover

The DPC’s advice on AI tools starts where this guide does, with knowing what happens to the data before you put it in:

“Before you start using an AI system, you should first understand what personal data it uses, how it uses it, where the personal data goes (…) whether it is retained by the provider of the AI product.”

Data Protection Commission, AI, Large Language Models and Data Protection, 18 July 2024

The GDPR’s principle of data minimisation, in Article 5(1)(c), says personal data should be limited to what is necessary for the purpose. For a photo going to a chatbot, that turns into a short routine.

  1. Ask whether it needs the photo. Many questions about a form or a letter can be typed. If the words are enough, the image does not need to go at all.
  2. Crop to the part you are asking about. A question about a licence category needs the categories, not the whole card and the kitchen table under it.
  3. Cover the person. Face, name, signature, date of birth, document number and the machine readable lines, unless the question is about one of them.
  4. Send a copy without metadata. A clean export drops the time, the phone and the place. Do not count on the assistant to do it for you.
  5. Choose the short clock. A Temporary Chat, an incognito chat or Keep Activity off keeps the photo for days or weeks rather than months, and training switched off keeps it out of model training, as long as you leave the feedback buttons alone.
  6. Delete in every place it went. The chat, the ChatGPT Library file, any Claude project, and the original in your camera roll if you do not need it.

Less goes, and less is kept

Covering is data minimisation done before the upload: what the question does not need stays on your device, so none of the clocks above applies to it. Our guide to copying a driving licence shows which fields a typical question about a licence actually needs.

Already uploaded one? Deleting a photo from each assistant

If a photo of a document has already gone, deleting it is still worth doing, as long as you delete it in the right places. Each assistant keeps something after the delete button, and this is where.

AssistantWhat to deleteWhat can outlast it
ChatGPTThe chat, then the image in LibraryUp to 30 days; copies already de-identified for training
GeminiThe chat in Gemini Apps ActivityChats a reviewer read, for up to 3 years
ClaudeThe chat, and the file in any projectUp to 30 days; longer if training was on or you rated the chat
CopilotThe chat, from its menu or the privacy dashboardNot stated for either app; older app files are capped at 18 months

Provider pages as cited above, read 3 October 2026.

Under Article 77 of the GDPR you can complain to a supervisory authority in the Member State where you live or work, which for most readers of this guide means the DPC. Before that route, the deletion tools above are quicker, and our guide to what ChatGPT keeps of your data covers the memory and the other copies a deleted chat can leave behind.

Cover a photo of your passport or licence in your browser

The Nonimo passport tool works on a phone or a computer. Drop in a photo or PDF of your passport data page or Passport Card, and it recognises the document and covers the signature, the dates, the place of birth and the bottom lines straight away. Each detail appears as a chip with its own name; tap one to cover it or show it again.

For an AI, tap your name, passport number and photo too, so nothing about you is left visible. The driving licence version does the same for the NDLS card: tap the name, licence number and photo there too, and the categories a question is usually about stay readable.

Then download the result as PNG, JPG or PDF, with the boxes burned into the pixels and no location or camera data in the file. Your document never leaves your device: it is read and redacted in your browser. What reaches the chatbot is the copy you chose to send.

For the text you put into AI tools at work, the same habit is built into our app: software that covers names, PPS numbers and Eircodes before your text reaches ChatGPT.

Sources

Common questions

Does ChatGPT keep your photos?

Yes. A photo you upload is saved with the chat for as long as the chat is kept, and ChatGPT also saves uploaded images to Library, where they stay until you delete them yourself. Deleting the chat does not delete the Library copy. Covering the face, signature and document number on your own device before the upload, which our passport tool does in the browser, means less of you is kept.

Does deleting a ChatGPT chat delete the photo I uploaded?

Not on its own. OpenAI's help page on Library says that deleting a chat containing files does not delete those files saved to Library. Open Library, delete the image there as well, and it goes to a recently deleted step before OpenAI schedules it for permanent deletion within 30 days. Photos uploaded in a Temporary Chat are not saved to Library unless you save that chat.

How long does Gemini keep photos I upload?

As long as your Gemini Apps Activity keeps the chat: 18 months by default, or 3 months, 36 months or indefinitely if you change it. With Keep Activity off, or in a temporary chat, chats are kept with your account for 72 hours. A chat read by a human reviewer is kept for up to three years, disconnected from your account, even after you delete your activity.

Does Claude keep images I upload?

Yes, as part of the conversation, or in a project's files if you add the image there. When you delete a conversation, Anthropic says it leaves its backend storage within 30 days. If you allow model training, data can stay in de-identified form for up to five years, and a chat you rate with the feedback buttons is kept for five years. Anthropic gives no separate clock for images.

Does Microsoft Copilot keep my photos?

It depends on the app. For the Copilot app of 18 August 2026, Microsoft says your file contents are not used to train foundation models, but its pages do not state how long files are kept. For the older app, Microsoft says files are kept no longer than 18 months, and that screenshots and camera images shared with Copilot Vision are not stored after the session ends.

Do ChatGPT, Gemini, Claude or Copilot remove location data from photos?

None of the four says so for an uploaded photo. OpenAI says only that its model does not process original metadata, which is about what the model reads, not what is stored. Microsoft lists picture metadata among the image data it collects. A phone photo can carry the time, the place and the camera, so the safe course is a copy without metadata, which is what our tool downloads.

Can people at OpenAI or Google see the photos I upload?

They can. OpenAI says a limited number of authorised staff and trusted service providers may access user content when needed, including to improve models unless you opt out. Google says human reviewers, some from its service providers, read a subset of Gemini chats, also for safety with Keep Activity off. Neither excludes images. Covering a document before the upload limits what anyone sees.

Is a photo of my face biometric data under the GDPR?

Not automatically. Recital 51 of the GDPR says a photograph counts as biometric data only when it is processed through specific technical means that allow a person to be uniquely identified, and Article 9 restricts biometric data used for that purpose. A face in a photo is still personal data, so covering it before an upload remains the sensible default for any image the question does not need.

What should I cover before I upload a photo of my passport to an AI?

Everything the question does not need: your photo, name, passport number, signature, date and place of birth, and the two machine readable lines at the foot of the page, which repeat most of those details. Then send a copy without location data. Our passport tool does all of that in your browser, with each detail as a chip you can tap to cover or show.