Skip to content
Rated 4.8 out of 5 with 3,475 reviews
Log in
SnapSuited iconSnapSuited.
AI & Photography

AI Headshot Privacy: What Actually Happens to the Selfies You Upload

How to read a privacy policy for the five clauses that matter, what biometric laws like BIPA and GDPR actually give you, and the questions to ask before you hand over your face.

Elena MarshBy Elena MarshPublished 14 min read

SnapSuited makes an AI headshot product — articles stay editorial, and product mentions are clearly marked. Every factual claim is verified against a primary source before publication; read our editorial standards and AI disclosure.

A phone showing a grid of selfie thumbnails next to a printed policy document with highlighted lines and a magnifying glass

AI headshot privacy comes down to four questions: how long the service keeps your selfies, whether it also deletes the face model built from them, whether your images train anything shared with other users, and what licence you grant over your likeness. The answers are in the privacy policy and terms — and they vary enormously between tools.

What actually happens after you press upload

Almost every AI headshot service follows the same three-stage pipeline, and each stage creates a different piece of data about you. Understanding the stages is what lets you read a policy properly, because a company can truthfully say "we delete your photos" while quietly keeping something derived from them.

Stage one: upload and storage

Your selfies leave your device and land in object storage — typically Amazon S3, Google Cloud Storage, Cloudflare R2 or an equivalent. At this point they are ordinary image files sitting on someone else's infrastructure, protected by that company's access controls. Two things matter here: where the bucket physically is, which determines whose law applies, and who inside the company can open it.

Stage two: the fine-tune

The service then trains a small, personalised adapter on top of a general image model — usually a LoRA or DreamBooth-style fine-tune. This is the critical artefact. It is not a copy of your photos; it is a compact mathematical representation of what your face looks like, which is precisely why it can generate a hundred new pictures of you. Our explainer on how AI headshot generators actually work walks through this step in detail.

Stage three: generation and delivery

The fine-tuned adapter is run against a set of prompts describing wardrobe, background and lighting, producing your gallery. Those outputs are then stored in your account, usually indefinitely, so you can come back and download them. Some services also keep low-resolution previews or thumbnails on a separate schedule from the originals — a detail policies rarely spell out.

An AI-generated professional headshot with soft directional lighting and a neutral background
An AI-generated SnapSuited sample. Outputs like this come from a per-user fine-tune built on uploaded selfies, which is why what happens to that fine-tune matters as much as what happens to the photos themselves.

The five clauses that actually decide whether a service is safe

A privacy policy is a long document with maybe six sentences that matter. If you read nothing else, read for these five. A service that answers all five clearly and specifically is doing better than most of the market; a service that is vague on two or more should be treated as a service that has not decided yet.

  1. 1Retention period for input photos. Look for a number, not an adjective. Published commitments in this category span roughly 24 hours to 30 days after generation — Lensa told users its uploads were deleted automatically within 24 hours of processing, and our own policy commits to 30 days — while a great many tools state nothing at all. "We retain data only as long as necessary" is not a retention period; it is a placeholder.
  2. 2Deletion of the trained model, not just the photos. This is the clause most often missing, including from policies that are otherwise specific. Ask whether the per-user fine-tune is destroyed on the same schedule as the source images, or whether it lives on. A policy that promises to delete your uploads and says nothing about the model has answered half the question.
  3. 3Whether your images train general models. Reputable services state that your photos personalise a model used only for your session and are never folded into a shared base model or evaluation set. That sentence should exist more or less verbatim. If it doesn't, treat the door as open rather than assuming it is closed.
  4. 4Named third-party processors. Every service uses subcontractors — payment processing, hosting, GPU compute, email, analytics. A good policy names them and says what each one receives. A policy that says only "trusted partners" is telling you it does not want you to check.
  5. 5The licence you grant over your likeness. Buried in the terms of service, not the privacy policy. This is where you find out whether the company can reuse your face in marketing, pass those rights to someone else, or keep them after you cancel.

These clauses hide behind predictable wording. If you are skimming a long document, use your browser's find function on the following terms — between them they surface almost every meaningful commitment, and almost every meaningful omission:

  • "retention", "retain", "delete", "deletion", "erase"
  • "train", "training", "improve our services", "machine learning"
  • "sub-processor", "service providers", "third parties"
  • "licence" / "license", "perpetual", "irrevocable", "sublicensable", "transferable"
  • "biometric", "facial geometry", "face data"

Deleting your photos is not the same as deleting your face

This is the single most under-discussed point in the category, and it is a technical one rather than a legal one. A per-user fine-tune is a derivative of your images, but it is not a container of them — which means deleting the source files does not automatically remove the capability those files created.

A 2024 arXiv preprint by Dixi Yao examined exactly this. It showed that an adversary with access only to shared LoRA fine-tuned diffusion weights — no prompts, no original images — can generate images containing the same identities as the private images used in training, and concluded that no existing defence, including differential-privacy-based methods, preserves the privacy of that training data without compromising the model's utility. In plain terms: a retained face adapter is a working key to your likeness, and it stays a working key after the photos are gone.

That has two practical consequences for you as a customer:

  • A retention promise that covers only "uploaded images" is materially weaker than one that covers "uploaded images and the model trained on them". Treat them as different products, because they are.
  • "Right to be forgotten" requests are genuinely harder to satisfy at the model layer than at the file layer. A company that has architected for per-user, disposable adapters can honour deletion cleanly. One that has trained a shared model on customer faces has a much messier problem — and you cannot verify from outside which situation you are in. You can only read what a company commits to, which is why the written commitment is the whole ballgame.

How to read the licence clause on your likeness

Terms of service almost always include a content licence, and some of it is unavoidable: a company cannot legally process your photos to make headshots without permission to process your photos. The question is whether the licence is scoped to that job or scoped to everything forever. Four words tell you which:

  • Perpetual — the licence never expires on its own.
  • Irrevocable — you cannot withdraw it, including after you delete your account.
  • Royalty-free — you will never be paid for any use they make of it.
  • Transferable / sublicensable — they can pass those rights to other companies, including an acquirer.

The canonical cautionary tale is Lensa AI's viral "Magic Avatars" moment in December 2022, when users noticed the app's terms granted a perpetual, irrevocable, worldwide, transferable and sublicensable licence to use, reproduce, modify, distribute and create derivative works from uploaded content — scoped in the text to operating Lensa and improving existing and new products. Prisma Labs responded that uploads personalised a temporary per-user copy of Stable Diffusion rather than training a shared model, and that user photos were automatically deleted within 24 hours of being processed. On 15 December 2022 it revised the wording to describe the rights as time-limited and revocable.

The episode is instructive precisely because the fine print and the company's stated practice had drifted apart, and only the fine print was legally binding. A well-drafted licence for a headshot service reads roughly like this: a limited, non-exclusive licence to process your images for the sole purpose of generating your headshots, terminating on deletion, with any use in marketing requiring separate opt-in consent. If you see "perpetual" and "sublicensable" in a consumer photo app, that is not boilerplate to shrug at — it is a company reserving commercial rights over your face.

What biometric privacy law actually gives you

Consumers often assume there is a general US law protecting facial data. There isn't — there is a patchwork, and where you live changes your rights substantially. Here is what the main regimes actually do, and just as importantly, what they don't do for the average person uploading twenty selfies on a Tuesday.

Illinois BIPA

The Biometric Information Privacy Act is the strongest consumer biometric law in the United States and the only one with a private right of action, meaning individuals can sue directly rather than waiting for a regulator to act. It requires informed written consent before collecting a scan of face geometry, disclosure of the purpose and the length of term, and a published retention schedule under which data is destroyed once the purpose is satisfied or within three years of your last interaction, whichever comes first. One important nuance: BIPA's definition of a biometric identifier expressly excludes photographs. A photo alone is not covered — a face geometry scan derived from it is, and courts have repeatedly allowed claims on that basis.

BIPA's teeth were partially filed down in August 2024, when Illinois enacted SB 2979. Following the Illinois Supreme Court's Cothron decision, plaintiffs had been arguing for damages on a per-scan basis; the amendment provides that repeatedly collecting or disclosing the same identifier from the same person by the same method is a single violation, with at most a single recovery. It also confirmed that an electronic signature satisfies the written-release requirement. On 1 April 2026 the Seventh Circuit held that the damages amendment is procedural rather than substantive and therefore applies retroactively to cases that were already pending. The statutory damages themselves are unchanged: $1,000 per negligent violation and $5,000 per reckless or intentional one.

Texas, Colorado and the rest of the states

Texas CUBI has no private right of action but has become the most aggressively enforced biometric statute in the country. The Texas Attorney General secured a $1.4 billion settlement with Meta, finalised on 30 July 2024, over facial geometry captured by tag suggestions — the largest ever obtained by a single state — followed by a $1.375 billion settlement with Google in May 2025 covering biometric claims alongside Chrome incognito and location history allegations. Colorado amended its privacy act via HB 24-1130, effective 1 July 2025, requiring consent before biometric collection and a publicly available written policy with a retention and destruction schedule; it is enforceable only by the state attorney general and district attorneys, with no private right of action. Washington, Oregon, Connecticut and others fold biometrics into broader consumer privacy statutes with similar regulator-only enforcement.

California

Under the CPRA amendments to the CCPA, biometric information processed for the purpose of uniquely identifying a consumer is classed as sensitive personal information, which triggers a right to limit its use and disclosure to what is reasonably necessary to deliver the goods or services an average consumer would expect — alongside the standard rights to know and to delete. Businesses relying on sensitive data beyond that baseline must offer a mechanism to exercise the limit, commonly a homepage link or an honoured opt-out preference signal.

GDPR and the UK

In the EU and UK, Article 9 GDPR prohibits processing biometric data for the purpose of uniquely identifying a person unless an exception applies — for consumer services, that realistically means explicit consent. Recital 51 is the hinge: photographs are not systematically special-category data, and fall within the definition of biometric data only when processed "through a specific technical means allowing the unique identification or authentication" of a person. Article 17 gives you the right to erasure, and Article 12(3) obliges the controller to respond without undue delay and within one month of receipt, extendable by two further months for complex or numerous requests, with notice.

Separately, the EU AI Act's Article 50 transparency obligations became applicable on 2 August 2026, requiring providers of systems that generate synthetic images to mark outputs in a machine-readable, detectable format. One caveat worth getting right, because it is widely misreported: the runway to 2 December 2026 covers only the marking-and-detection duty in Article 50(2), and only for systems already placed on the market before August. The disclosure duties applied on schedule. That is a labelling rule rather than a privacy rule, but it belongs in the same mental file, because it governs what happens to the picture after you have been handed it. If you are weighing whether to say anything about it publicly, we have covered the etiquette side in our piece on using an AI headshot on LinkedIn.

The honest summary: unless you are in Illinois, these laws are enforced by regulators against large companies, on a timescale of years. They set a floor and they occasionally produce billion-dollar consequences, but they are not a substitute for reading the policy of the small company you are about to upload to today.

An AI-generated professional portrait with even lighting and a clean neutral backdrop
Another AI-generated SnapSuited sample. Under GDPR, an image like this is ordinary personal data; it is the identification step used to make it that brings the biometric rules into play.

What a traditional photographer does and doesn't solve

It would be convenient for us to argue that AI and film-and-lens photography carry identical privacy profiles. They don't, and pretending otherwise would be the kind of hype that erodes trust. A studio session and an upload form create genuinely different exposures, and each is safer than the other in a different respect. Here is the fair comparison.

  • A photographer genuinely does avoid the model-retention problem. Nobody builds a reusable mathematical representation of your face in a studio session. The worst case is files on a hard drive or in a client gallery.
  • But photographers are not a privacy-free zone either. Most standard contracts include a portfolio and marketing usage clause — your face on their website, their Instagram, their ads. That is a likeness licence too, just one delivered on paper rather than in a click-through.
  • Photographers are usually below the threshold of privacy law. Small studios frequently have no published privacy policy, no defined retention schedule and no deletion process. You are relying on professional norms rather than documented commitments.
  • AI services can, in principle, be more auditable. A written retention period, a named list of sub-processors and an account-level delete button are all things a one-person studio typically cannot offer. Whether a given service actually offers them is the thing you have to check.

Neither option is categorically safer; they fail in different directions. If you are weighing the two on more than privacy grounds, our honest comparison of AI headshots and a photographer covers cost, control and output quality, while what users actually report on Reddit is a useful unfiltered reality check on both.

The pre-upload checklist

Ten questions, answerable in about five minutes with the policy open in a tab. You are not looking for perfection — you are looking for specificity. Companies that have genuinely thought about this write in numbers and names; companies that haven't write in adjectives, and the difference is visible before you spend anything.

  1. 1What is the stated retention period for my uploaded photos, in days?
  2. 2Does the policy commit to deleting the trained model or face embedding, not just the source files?
  3. 3Is there an explicit statement that my images are not used to train, fine-tune or evaluate general or shared models?
  4. 4Can I trigger deletion myself, immediately, from inside the account — or must I email support and hope?
  5. 5Are sub-processors named individually, with what each one receives?
  6. 6Where is the data physically hosted, and which jurisdiction's law is named in the terms?
  7. 7Does the content licence include the words perpetual, irrevocable, transferable or sublicensable?
  8. 8Does that licence survive account deletion?
  9. 9Is marketing use of my images opt-in and separate, or bundled into the general terms?
  10. 10Is there a real business model? A service that is free with no explanation of how it earns money is being paid in something, and your face is the available currency.

Three answers should stop you outright: no retention period stated anywhere, a perpetual and sublicensable licence over your likeness, and silence on general model training. Any one of those is enough to pick a different tool. If you are evaluating no-cost options specifically, our breakdown of what "free" actually costs goes through those trade-offs in detail.

Thinking about a new headshot but want to know what happens to your photos first? You can generate a set from a few selfies in about ten minutes, and read exactly how the uploads are handled before you start.

Get your headshots →

How SnapSuited handles this, specifically

We would rather be checkable than reassuring, so here is what our published privacy policy actually commits to — you can hold us to that document rather than to this article. Where we don't have a documented commitment, we say so instead of implying one, including where that reflects badly on us.

  • Uploaded selfies are automatically and permanently deleted within 30 days of your headshot generation session.
  • Generated headshots are retained in your account indefinitely, until you delete them manually or your account is closed — that retention is yours to control.
  • Named sub-processors: Stripe for payment processing, Google Analytics 4 via Google Tag Manager for usage analytics, Resend for transactional email delivery, and Coolify-managed EU-based server hosting.
  • Uploads are used solely to produce your output images and are not shared with third parties for their own purposes. We do not sell, rent or trade personal data.
  • Hosting is in the EU, and your data does not leave the EU/EEA except in the limited cases the policy sets out — which means GDPR is the operating baseline rather than an add-on.
  • What we do not currently document. Our policy sets a deletion schedule for uploads but does not yet spell out in writing what happens to the per-user fine-tune on that same schedule. By the standard set out in this article, that is precisely the gap a reader should push us on — and it is a commitment better made in the policy than in a blog post.

For the wider question of what an AI-generated portrait is, and where it is and isn't appropriate to use one, our AI disclosure page sets out our position. And if you want to understand the input side — which selfies actually produce good results, and which ones you should think twice about uploading anywhere — our guide to input selfies covers it.

The realistic bottom line

Are AI headshot apps safe? Some are, some aren't, and the difference is almost entirely visible in writing before you upload anything. The category's genuine risk is not that a reputable tool will do something sinister with your face. It is that a large number of thinly-staffed tools have never written down what they do, which means nobody — including them — knows what happens to your data when they get acquired, breached or simply bored.

So use the boring method. Open the policy, search for five words, look for numbers and names, and decline anything that answers in adjectives. It takes five minutes, it is the only real leverage a consumer has in this market, and on any realistic timescale it protects you far more reliably than any of the laws described above.

Frequently asked questions

Are AI headshot apps safe to use?

Reputable ones are, but safety is a property of the specific tool, not the category. The reliable signal is written specificity: a numeric retention period, a commitment to delete the trained model as well as the photos, an explicit no-general-training statement, named sub-processors, and a licence limited to producing your headshots. Vagueness on any of those is the actual risk.

Does deleting my photos also delete the AI model of my face?

Not automatically, and this is the most commonly missed clause. The per-user fine-tune is a derivative of your images, not a container of them, so removing the source files leaves the model's ability to generate your likeness intact. Look for a policy that commits to destroying the trained adapter on the same schedule as the uploads.

Does Illinois BIPA protect me if I don't live in Illinois?

Generally no. BIPA is the only US biometric law with a private right of action, and it protects Illinois residents. Texas and Colorado have biometric requirements enforceable only by state officials, California treats biometrics processed to identify you as sensitive personal information under the CPRA, and most other states offer nothing specific. Your protection depends heavily on where you live.

Can I ask an AI headshot company to delete my data under GDPR?

If you are in the EU or UK, yes. Article 17 gives you a right to erasure and Article 12(3) requires the controller to respond within one month of receipt, extendable by two further months for complex or numerous requests with notice. Ask explicitly for both the source images and any model trained on them, since a generic request may only be applied to files.

What does a "perpetual, irrevocable" licence in the terms actually mean?

Perpetual means the licence never expires, irrevocable means you cannot withdraw it even after deleting your account, royalty-free means you are never paid, and transferable or sublicensable means the rights can be passed to other companies including an acquirer. In a consumer photo app, that combination reserves long-term commercial rights over your likeness.

Are free AI headshot generators riskier than paid ones?

Often, though not always. Paying does not guarantee good handling, but a service with no visible revenue model has to be monetised somehow, and user data is the obvious candidate. Apply the same checklist regardless of price: if a free tool states a retention period, names its processors and limits its content licence, price is not the deciding factor.

Put it into practice

Get your professional headshots — without booking a studio

SnapSuited turns a few selfies into 50+ studio-quality headshots: multiple outfits, backgrounds and looks, ready for LinkedIn, your CV and your company page in about 10 minutes.

  • Free to try — see your previews before paying anything
  • 50+ headshots in multiple outfits and backgrounds
  • Ready in ~10 minutes, not weeks
  • Money-back guarantee if you don’t love them