Does ChatGPT store images? What AI tools keep from photos
· Written and maintained by Nonimo
Yes. ChatGPT stores the images you upload as part of the conversation, and it also saves a copy of each uploaded file, photos included, to a part of your account called the Library. Deleting the chat does not delete that copy: OpenAI’s help center says so in one sentence. Gemini and Claude keep a photo as part of the chat it was sent in, on the same clock as the text around it. Microsoft Copilot’s answer depends on which of its two consumer apps you use.
That matters more than it sounds when the photo is of a document. A phone picture of a driver’s license, a medical bill, a prescription label or a signed lease carries things a typed question never would: a face, a signature, a license number, a barcode and, inside the file, often the time and the GPS position where it was taken. None of the four providers says whether it keeps or strips that hidden data at upload.
This guide reads what each provider says about images, plan by plan, with the date on each page. Then it goes through what a photo of a document gives away and how to cover it before it leaves your phone. If what you need right now is a clean copy, start with redacting a driver’s license photo in your browser, all on one screen.
Does ChatGPT store images? Yes, in two places
OpenAI’s US privacy policy, updated September 10, 2026, counts uploads as content: your prompts and “other content you upload, such as files, images, audio and video.” There is no separate category for a photo and no separate set of rules. A picture of a lease is handled like a paragraph pasted from that lease.
Where it goes after that is where ChatGPT differs from the other three. OpenAI’s File Uploads FAQ says files are saved in your account “up to the retention period of the corresponding chat,” which on a personal plan means until you delete the chat. That is the first place. The second is the Library.
The Library copy outlives the chat
OpenAI’s article on the Library says ChatGPT “automatically saves uploaded and created files, including files uploaded in chats,” and names images among them. The Library is on Free, Go, Plus, Pro and Business, and in Enterprise, Edu and Healthcare workspaces. On a personal plan, files stay there “until you delete them manually.”
Then comes the sentence that most writing on ChatGPT retention has not caught up with: “Deleting a chat containing files does not delete those files saved to Library.” OpenAI’s retention article repeats it. So a photo of a client’s ID that you deleted along with its conversation in June can still be in the Library in October, and the 30 days have not started, because the file itself was never deleted.
Deleting it from the Library takes two steps. The file goes to Recently deleted first, and from there OpenAI says deleted files are scheduled for permanent deletion within 30 days. Our guide to OpenAI’s two privacy policies covers the chat side of the same clock.
Temporary Chat keeps the photo out of the Library
Temporary Chat is the one control that changes this. OpenAI’s Library article answers the question directly: files uploaded in a temporary chat “are not saved to your account or Library.” The temporary chat itself may still be kept for up to 30 days for safety purposes.
There is one catch. If you later save that temporary chat, OpenAI says eligible files in it may be saved to the Library at the same time, so a photo you meant to show once becomes a stored file the moment the chat is kept. Images that ChatGPT creates for you live somewhere else again, in the Images tab, and OpenAI’s instruction for removing one is to delete the conversation where it was made.
A scan is a photo by another name. A scanned page with a black box drawn over it in a viewer still holds the original picture underneath, and that is the file the Library keeps.
Does ChatGPT keep photos after you delete them?
For 30 days, and in two cases longer. OpenAI’s privacy policy says that once you choose to delete personal data, it removes it from its systems within 30 days “unless we need to retain it for longer,” and the policy it publishes for Europe uses the same words. That covers a chat with a photo in it, a Library file you deleted, and a whole account.
The first exception is training. If you allowed OpenAI to use your content to improve its models, the policy says deletion does not reach content that has already been deidentified and separated from your account. The second is legal: OpenAI says that after a court order in the New York Times copyright case, it still stores limited user data from April to September 2025, reachable only by a small, audited legal and security team.
Training on photos is on by default for personal plans
OpenAI’s page on consumer services says it may use “the user’s prompts, the model’s responses, and other content such as images and files to improve model performance.” Its Image Inputs FAQ adds that its approach to content, “including images, remains the same for each product.” To stop it, turn off Improve the model for everyone under Settings, then Data controls, or choose Do not train on my content in OpenAI’s Privacy Portal.
Two limits come with that switch. OpenAI says turning it off “does not delete or hide saved chats,” and that a thumbs up or down on an answer means “the entire conversation associated with that feedback may be used to train our models,” photo included.
On ChatGPT Business, Enterprise, Edu and the API, OpenAI says it does not train on inputs or outputs by default. Which of those accounts your staff signs in with is the biggest lever a firm has over what happens to a photo.
Who at OpenAI can see a photo
OpenAI says “a limited number of authorized OpenAI personnel, as well as trusted service providers” may access user content as needed: for abuse and security, for support, for legal matters, and to improve model performance unless you opted out. The same page asks you not to enter sensitive information “that you would not want reviewed or used.”
Business accounts add a reader from your own side, because workspace admins can view, access, export and delete conversations. On Enterprise and Edu, OpenAI says its employees access conversations only to resolve incidents, to recover conversations with your explicit permission, or where the law requires it.
Gemini keeps your photos in Activity, 18 months by default
Google’s Gemini Apps Privacy Hub, updated September 24, 2026, is direct about it: “Your chats and what you share with Gemini (like files, videos, screens, and photos) will be saved in your Activity.” Gemini uses Google Lens technology “to understand what’s in the image and to read the text,” so a photographed letter is read much like a typed one. There is no separate clock for uploads. A photo goes when its activity goes.
That clock is 18 months unless you change it. Google’s privacy notice, last updated June 29, 2026, lets you choose 3 months, 36 months or no automatic deletion instead. With Keep Activity off, or in a temporary chat, chats are kept with your account for 72 hours.
The photos a reviewer saw stay for three years
Google says human reviewers, “including trained reviewers from our service providers,” look at some of the data it collects. Chats they reviewed “are not deleted when you delete your activity. Instead, they are retained for up to three years,” disconnected from your account. Being disconnected from your account does not stop anyone reading a name printed on the card in the photo.
Review is not only about training. Google says that even with Keep Activity off it uses your chats to respond to you and to protect Google, its users and the public, “including with help from human reviewers.” Its notice asks you not to enter confidential information “that you wouldn’t want a reviewer to see.”
Uploads used to improve Google’s services
When Google announced its privacy controls in August 2025, it wrote that with the setting on, “a sample of your future uploads will be used to help improve Google services for everyone,” starting with uploads submitted from September 2, 2025.
The hub now says activity is used to develop and improve services, “including training generative AI models,” and adds that with Keep Activity on, a photo or video you bring in from Google Photos is used to improve services with the help of human reviewers.
Turning Keep Activity off, or using a temporary chat, takes future chats out of that, with one exception: send feedback and Google collects the last 24 hours of your chats and “any content included in those chats (like uploads and data from Connected Apps)”. Our Gemini guide walks through that button and the work account, where Google says uploaded files are not reviewed by humans or used for training outside your domain without permission.
Claude keeps a photo as long as the chat it was sent in
Anthropic’s privacy policy, effective September 10, 2026, treats anything you upload as “Inputs.” A photo dropped into a chat lives in that chat. One added to a project’s Files section is there “for persistent reference across conversations,” so it stays as long as the project does. Anthropic’s consumer pages give no separate clock for images, and its enterprise documentation confirms that deleting a chat deletes the files attached to it.
From there, how long a photo lasts depends on what happened to the chat. Anthropic publishes the numbers in its privacy center.
| What happened to the chat | How long Anthropic may keep it |
|---|---|
| You deleted it | 30 days in back end storage |
| You allowed model training | Up to 5 years, deidentified |
| Automated systems flagged it | 2 years; safety scores up to 7 |
| You rated it thumbs up or down | 5 years |
| It was an incognito chat | 30 days, not used for training |
Anthropic, How long do you store my data?, July 1, 2026, and Use incognito chats, read October 3, 2026.
Training follows your setting, so look at it
The policy says Anthropic “may use your Inputs and Outputs to train and improve Anthropic AI models, unless you opt out through your account settings.” The pages we read on October 3, 2026, do not say which way that switch starts, so open Privacy Settings and check rather than assume. Two exceptions survive opting out: chats flagged for safety review, and material you report yourself, for example through the feedback buttons. Neither has an image rule of its own.
On Claude Team, Enterprise and the API, Anthropic says it does not train on inputs or outputs by default, though feedback can still store a conversation for five years. Our Claude guide covers that switch and the owner setting that closes it.
As for who looks, Anthropic says access for training “is limited to a small number of personnel involved in model training,” and that conversations are delinked before any review. Its support page lists “Confidential business or personal documents” among the things to be careful with.
Microsoft Copilot: two apps, two sets of answers since August 18, 2026
On August 18, 2026, Microsoft released a new consumer Copilot app and kept the older documentation online, each page under a banner saying which version it describes.
For photos the two sets say different things, so check which app you have before trusting either.
| Newer app | Older app | |
|---|---|---|
| How long files are kept | Not stated | No longer than 18 months |
| Trains on uploads | Not for foundation models | Yes, you can opt out |
| Human review | Not stated | Yes, with no opt out |
| Camera images in Vision | Not stated | Not stored after the session |
Microsoft Support, Copilot for individuals pages and Privacy FAQ for Microsoft Copilot (older app), read October 3, 2026.
What the newer app says, and leaves out
Microsoft’s activity history page for the new app says that “prompts, responses, and your file contents when using the Microsoft Copilot app aren’t used to train foundation models.” None of the new app pages we read gives a retention period for files or says whether people review them.
The Microsoft Privacy Statement, updated September 2026, fills in what is collected: “Images and related data, like picture metadata,” including the image you upload to Copilot. It also says ads may be shown that relate to your Copilot conversations, “including files you share.”
The older app blurs faces, but only for training
The older app’s privacy FAQ is the only consumer page we read with a rule written for images. Files you upload are stored “no longer than 18 months” and then deleted. They can be used for training unless you opt out, and before that Microsoft says it takes steps to deidentify them, “such as removing metadata or other personal data and blurring images of faces.”
That happens before training, not at upload. The same FAQ says users cannot opt out of human review.
On a work or school account the answers change again. Uploaded files are stored in the user’s OneDrive for Business, Microsoft says prompts and responses are not used to train foundation models, and Microsoft says Copilot services have opted out of the abuse monitoring that includes human review. Our Copilot guide sorts the four products that share the name.
How long each assistant keeps a photo, side by side
Put the four personal plans next to each other and only two rows hold a surprise: ChatGPT’s Library copy, and the chats Gemini’s reviewers read.
| Assistant | While the chat is saved | After you delete it | Private mode |
|---|---|---|---|
| ChatGPT | Until you delete it, plus the Library copy | 30 days; Library copy stays until deleted | Temporary Chat, up to 30 days |
| Gemini | 18 months by default | Reviewed chats up to 3 years | Keep Activity off, 72 hours |
| Claude | Until you delete it | 30 days | Incognito, 30 days |
| Copilot, older app | Files up to 18 months | Not stated | Vision images not stored |
| Copilot, newer app | Not stated | Not stated | Not stated |
Provider pages listed under Sources, read October 3, 2026. Personal plans only.
Training and human review sort the four differently, and here the gaps are the point.
| Assistant | Trains on photos by default | People can look |
|---|---|---|
| ChatGPT, personal | Yes, you can opt out | Staff and service providers |
| Gemini, personal | Yes, with Keep Activity on | Reviewers, including vendors |
| Claude, personal | Your setting; default not stated | Training staff, flagged reviews |
| Copilot, newer app | Not for foundation models | Not stated |
| Copilot, older app | Yes, deidentified first | Yes, with no opt out |
Same sources and date.
For a firm, the work accounts are the better answer at every provider: no training by default, and on most of them a retention period your own admin can set. If a client’s documents go through any of these tools, the AI paragraph of your engagement letter should name the account, not just the brand.
What a photo of a document carries that typed text does not
Type a question about a parking restriction and the AI gets the question. Photograph the license to ask it and the AI gets the whole card. A photo has no way to send only the part that matters.
| On a phone photo of a license | Where it is | Needed to answer your question? |
|---|---|---|
| Your face | Front of the card | Almost never |
| Signature | Front of the card | Never |
| License number and DD number | Front of the card | Almost never |
| Date of birth and address | Front of the card | Rarely |
| PDF417 barcode | Back of the card | Never |
| Time, camera and GPS position | Inside the file | Never |
Fields from the AAMVA card design standard, as set out in our driver’s license guide.
The same goes for other paper. A passport data page has two machine readable lines at the bottom that repeat the page’s main data. A photographed W-2 or benefits letter often carries a Social Security number, and a picture of an SSN is still an SSN. The background counts too: the kitchen table, the envelope with your address, the screen behind the paper.
The metadata nobody sees
A phone photo usually carries EXIF data: the camera model, the moment it was taken and, with location on, the latitude and longitude. Removing metadata from photos shows where it hides and how to turn location off on an iPhone.
What the four providers say about that data at upload is almost nothing. OpenAI says its model “doesn’t process original file names or metadata,” which is about what the model reads, not what the company stores. Microsoft lists picture metadata among what it collects. The older Copilot app removes metadata before training. Anthropic’s enterprise documentation says images can be served as a processed copy, which is not a statement about EXIF.
So the only way to know the location is gone is to take it out yourself, before the upload.
What US law says about a photo of an ID
The United States has no general federal data protection law, and no regulator dedicated to one the way European countries have.
What applies depends on who is uploading and whose document it is: your own license is your business, but a firm that photographs a client’s or an employee’s ID and sends it to a chatbot is handling someone else’s data.
The FTC counts the photo itself
The Federal Trade Commission’s policy statement on biometric information and Section 5 of the FTC Act, issued in May 2023, defines the term broadly. Its example is plain: “both a photograph of a person’s face and a facial recognition template” count as biometric information. The statement is aimed at companies that collect and use such data, and it is a useful measure of how the agency reads a face photo.
California counts the number and the location
California’s Civil Code 1798.140(ae) lists driver’s license, state ID and passport numbers as sensitive personal information, along with precise geolocation, which section (w) defines as device data used to locate a consumer within a circle with a radius of 1,850 feet. Biometric information makes the list only when it is processed “for the purpose of uniquely identifying a consumer.” The law binds businesses that meet its size tests, and their employees’ data has been covered since 2023, as the PHI and PII guide explains.
Health practices have a narrower rule on top. HIPAA’s safe harbor lists “full face photographic images and any comparable images” among the identifiers that must be removed for health data to count as deidentified, which takes in an ID scan with the holder’s face on it; the HIPAA guide goes through all eighteen.
Before you upload a photo, cover what the AI does not need
The safest photo is the one you never upload. Most questions about a document can be typed, and the AI answers the same. When the picture really is needed, in this order:
- Ask what the AI needs. Usually the layout, a label or one line of text, almost never your name or number.
- Crop to the part that matters. Leave out the back of the card, the background and anything around the paper.
- Cover every field the question does not need. Face, signature and numbers first, and box them into the pixels, not as a layer on top.
- Strip the location. On a phone, turn off location in the share options, or download a copy without EXIF.
- Use the private mode. Temporary Chat, a Gemini temporary chat or Claude’s incognito chat keeps the copy short lived.
- Delete it afterward, everywhere. In ChatGPT that means the Library too, and nobody presses a thumbs button on that chat.
Step 3 is where most people stop short, because a box drawn in a photo app can be lifted off. The driver’s license redaction tool burns the boxes into the image. For everything else on the page, the list of personal information to remove before AI goes group by group.
Cover a document photo in your browser before any AI sees it
Nonimo’s photo tool sits at the top of the driver’s license guide. Drop a photo or a PDF of the card, in JPG, PNG, WEBP, HEIC or PDF; on a phone that opens the camera or the gallery.
Each field it reads gets its own chip. It starts with the DD number, signature, date of birth, address and expiration date covered, and your name, license number and photo visible, which suits a copy for a landlord. For an AI, tap those three chips as well, so the assistant sees the layout and the labels and nothing that identifies you.
Then download it as PNG, JPG or PDF. The boxes are burned into the pixels, and the copy carries no metadata such as EXIF or GPS. Your document never leaves your device: it is read and redacted right in your browser, and not uploaded to our servers or anyone’s.
On Mac and Windows, the Nonimo app handles the same photo and also recognizes US passport cards. How the app handles your files is set out on Nonimo’s security page.
Two things you will read elsewhere that are wrong today
We checked both claims against the providers’ pages on October 3, 2026.
The first is that deleting a ChatGPT chat deletes everything in it within 30 days. That was the whole story before the Library. Today it is true of the conversation and not of the files: an uploaded photo stays in the Library until you delete it there, and only then do the 30 days begin. The ChatGPT guide explains the chat side of that clock.
The second is that AI tools strip location data from the photos you give them. None of the four says that about uploads. The older Copilot app removes metadata before training, which is a different moment and a different promise, and Microsoft’s own pages split by app version on most of the rest.
Both mistakes come from reading a true sentence about one thing as a sentence about another: the chat for the file, training for storage. With photos of documents, the difference is your face and your license number.
Sources
Checked October 3, 2026.
- OpenAI, US privacy policy, updated September 10, 2026. Uploads such as files and images counted as content; deletion within 30 days unless OpenAI needs to keep data longer; deidentified training data not reached by deletion.
- OpenAI, EU privacy policy, updated August 24, 2026. The same 30 day deletion wording.
- OpenAI, File Uploads FAQ. Files saved up to the retention period of the corresponding chat.
- OpenAI, Using Library to manage files in ChatGPT. Uploaded files, images included, saved automatically; plans where Library is available; files kept until deleted manually; deleting a chat does not delete Library files; Recently deleted and permanent deletion within 30 days; Temporary Chat files not saved to Library unless the chat is saved; training on Library files when the setting is on.
- OpenAI, Chat and file retention in ChatGPT. Saved chats kept until deleted; deleting a chat does not delete a file that stays in Library.
- OpenAI, Temporary chat in ChatGPT. A copy kept up to 30 days for safety; files saved to Library if you save the chat.
- OpenAI, How OpenAI handles data in consumer services. Content such as images and files used to improve model performance; who may access content and why; the warning about sensitive information.
- OpenAI, How your data is used to improve model performance. The opt out, the Privacy Portal, feedback using the entire conversation, and no training by default on business products and the API.
- OpenAI, Data controls in ChatGPT. Turning training off does not delete or hide saved chats.
- OpenAI, ChatGPT Image Inputs FAQ. The same approach to images in every product; the model does not process original file names or metadata.
- OpenAI, Images in ChatGPT. Generated images saved under Images, deleted by deleting their conversation.
- OpenAI, Enterprise privacy, updated January 8, 2026. Business admins can view and export conversations; staff access on Enterprise and Edu.
- OpenAI, How we’re responding to The New York Times’ data demands, June 5, 2025, update of October 22, 2025. Limited historical user data from April to September 2025 still stored, with access limited to a small audited team.
- Google, Gemini Apps Privacy Hub, hub updated September 24, 2026, notice updated June 29, 2026. Photos and files saved in Activity; Google Lens reading images; 18 months by default and the alternatives; 72 hours; reviewed chats kept up to three years; reviewers from service providers; review for safety with Keep Activity off; feedback carrying uploads; the confidential information warning; Google Photos used with human reviewers when Keep Activity is on.
- Google, Temporary chats and new privacy controls, August 13, 2025. A sample of future uploads used to improve Google services, for uploads from September 2, 2025.
- Google, Generative AI in Google Workspace Privacy Hub, updated August 14, 2026. Uploaded files on work accounts not reviewed by humans or used for training outside your domain without permission.
- Anthropic, Privacy Policy, effective September 10, 2026. Uploads as Inputs; training unless you opt out; the two exceptions.
- Anthropic, How long do you store my data?, July 1, 2026. 30 days after deletion, up to 5 years deidentified with training on, 2 years for flagged content and 7 for scores, 5 years for feedback.
- Anthropic, Is my data used for model training? (commercial), August 18, 2026. No training by default on commercial products; the feedback exception.
- Claude Help Center, Use incognito chats. Kept 30 days for safety and not used for training.
- Claude Help Center, Upload files to Claude. Files in individual chats or in a project’s Files section for persistent reference.
- Claude Help Center, Who can view my conversations?. Training access limited to a small number of personnel; the list of sensitive material to be careful with.
- Anthropic, Compliance API: chats, files and projects. Deleting a chat deletes its attached files; images served as a processed copy.
- Microsoft, Copilot for individuals: your activity history. New app: prompts, responses and file contents not used to train foundation models.
- Microsoft, Privacy FAQ for Microsoft Copilot. Older app: files stored no longer than 18 months; Vision images not stored after the session; training on images and files with metadata removed and faces blurred; no opt out of human review.
- Microsoft Privacy Statement, updated September 2026. Images and related data, like picture metadata, collected from uploads; ads related to conversations, including files you share.
- Microsoft Learn, Copilot Chat privacy and protections, updated August 24, 2026. Uploaded files stored in OneDrive for Business.
- Microsoft Learn, Data, Privacy, and Security for Microsoft Copilot, updated August 18, 2026. No training of foundation models; abuse monitoring with human review opted out.
- FTC, Policy Statement on Biometric Information and Section 5 of the FTC Act, May 18, 2023. A photograph of a person’s face counted as biometric information.
- California Civil Code § 1798.140. Sensitive personal information in (ae), including license, state ID and passport numbers and precise geolocation; precise geolocation in (w), device data locating a consumer within a circle of 1,850 feet radius, except as regulations provide; biometric information in (c).
- 45 CFR 164.514. HIPAA’s safe harbor list, including full face photographic images and any comparable images.
Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT. No account needed, and the app does it without your files leaving your machine.
Common questions
Does ChatGPT store images you upload?
Yes. OpenAI counts uploaded images as content, keeps them with the chat for as long as the chat is saved, and on Free, Go, Plus, Pro and Business also saves uploaded files, images included, to the Library. Library files stay until you delete them yourself. Before a photo of a document goes in, cover what the AI does not need; Nonimo's browser tool does that without uploading the photo anywhere.
If I delete a ChatGPT chat, is the photo deleted too?
Not necessarily. OpenAI's help center says deleting a chat that contains files does not delete the files saved to Library. Open the Library, delete the photo there, and it goes to Recently deleted before OpenAI schedules it for permanent deletion within 30 days. Photos uploaded in a Temporary Chat are not saved to Library unless you later save that chat.
Does ChatGPT train on the photos I upload?
On personal plans it may, by default. OpenAI says it may use content such as images and files to improve model performance unless you turn off Improve the model for everyone under Data controls. A thumbs up or down can still send the whole conversation for training. On Business, Enterprise, Edu and the API, OpenAI does not train on your data by default.
How long does Gemini keep photos I upload?
As long as the activity they belong to: 18 months by default on a personal account, or 3 months, 36 months or indefinitely if you change it. With Keep Activity off or in a temporary chat, 72 hours. Chats a human reviewer has read are kept up to three years, disconnected from your account, even after you delete your activity.
Does Claude keep the images I upload?
Claude keeps a photo with the chat it was uploaded to, or with the project if you added it to project files. Deleted chats leave Anthropic's back end within 30 days. If you allow model training, Anthropic may keep data in deidentified form for up to five years, and flagged chats or chats you rate are kept longer. Incognito chats are kept 30 days for safety and are not used for training.
Does Microsoft Copilot keep my photos?
It depends on the app. Microsoft's pages for the older consumer app say uploaded files are stored no longer than 18 months and that camera images shared with Vision are not stored after the session. The pages for the app released on August 18, 2026, say file contents are not used to train foundation models, and give no retention period.
Do AI chatbots remove the location data from my photos?
None of the four says so for uploads. OpenAI says its model does not process a file's metadata, which is about what it reads, not what it keeps. Microsoft's privacy statement lists picture metadata among what it collects. Strip the location yourself before the upload: Nonimo's photo tool downloads a copy without EXIF or GPS data, and the photo never leaves your device.
Is it safe to upload a photo of my driver's license to ChatGPT?
Only if nothing readable is left on it. A license photo shows your face, signature, license number and document discriminator, and the file may hold the place it was taken. Ask whether the AI needs the photo at all; usually it needs the layout, not your details. Cover every field, remove the location, and use Temporary Chat so no copy goes to the Library.
Can someone at OpenAI or Google see the photos I upload?
Yes, in defined cases. OpenAI says a limited number of authorized staff and trusted service providers may access content for safety, support, legal reasons and, unless you opted out, model improvement. Google says human reviewers, including its service providers' reviewers, read some Gemini chats, also for safety with Keep Activity off. Both ask you not to share what you would not want reviewed.