What happens to your photos when you make an AI headshot?

Check what MyPhotoAI says about uploaded photos, retention, and deletion. The public policy describes a schedule; the Help page says automatic deletion is not active yet.

Illustration of a person reviewing portrait images privately on a laptop
Illustrative scene. It does not show a MyPhotoAI user or a verified data workflow.

An input photo may show more than a face. It can reveal a home, workplace, another person, or location metadata. Before uploading, check what the service says it collects, how long it keeps files, and how to request deletion. This guide separates MyPhotoAI's published policy from questions that still need an operational check.

The MyPhotoAI privacy policy was updated on 24 September 2026.1 It describes account data, uploaded photos, payment processing, retention, and deletion requests. A policy describes the company's commitments; it does not, by itself, prove that every automatic deletion job has been implemented or audited.

Illustrative sequence showing a home selfie, a tighter source crop, and a person reviewing a portrait before posting.
Illustration: check what a source photo reveals, then review the final portrait before sharing.

The photo's path

Stage What the current policy says What to check before making a stronger claim
Upload Photos are stored so the requested AI features can run Storage location, access roles, and whether metadata is stripped
Processing Photos are processed to provide the service Which processors receive files and under which retention terms
Result Generated photos may be stored for access and purchase Whether all intermediate outputs follow the same schedule
Payment Stripe processes payment information; MyPhotoAI says it does not store full card numbers Keep payment retention separate from photo retention
Deletion Users may request account, photo, or data deletion by contacting support Actual deletion workflow, backups, processor deletion, and completion evidence

This table is deliberately narrow. It does not assert a model-training policy or a complete list of processors because those facts need confirmation from the product owner and current vendor agreements.

What the retention language means

The policy says reference photos, unpurchased generated photos, and other user data will be deleted within 30 days of creation or collection.1 Purchased photos are described as available for 60 days after purchase, unless the user deletes them or closes the account sooner. Authentication data remains while an account is active, and some records may be retained longer for legal obligations.

The same policy says users should contact [email protected] for deletion until automatic deletion is in place. MyPhotoAI's Help page says that the automatic schedule is not active yet and that photos may remain in the gallery until deletion or account closure.2 That qualification matters. Do not translate the stated schedule into a claim that a verified automatic purge is already running. Download purchased photos you want to keep, and ask support if you need confirmation about a particular deletion request.

Illustrative source selfie with a work badge and family photo in view, beside a tighter crop that leaves those details out.
Illustration: check the room and crop out private details before uploading a source photo.

Before you upload

Use photos you have the right to process. The terms prohibit uploading private photos of others without permission. Remove other people from the frame if they have not agreed to the upload. Check mirrors, badges, documents, and visible screens. If an image contains location metadata, consider removing it before sharing, especially if the original was taken at home.

For work photos, distinguish three permissions: permission to upload a person's source image, permission to create a generated result, and permission to publish the selected portrait. An employee's agreement to appear on a company directory is not automatically permission to publish their source photos or use their result in advertising.

Illustration of a person reviewing a remote team's portrait grid and one individual portrait before publication.
Illustration: review individual portraits and get consent before a team uses them publicly.

How to request your data

The policy directs deletion and export requests to [email protected]. State the email used for the account and whether you want a photo removed, an account deleted, or an export. The policy says requests are authenticated before fulfillment, which helps prevent another person from deleting or obtaining your data.

Keep the confirmation and ask what was removed if the scope matters to you. For a workplace account, also ask the employer about copies held in its own directories or design systems; deleting a service account does not remove independent copies made elsewhere.

Questions this guide cannot yet answer

The public policy does not provide enough detail here to map every processor, backup, access log, or model-use path. A complete data-flow diagram needs an owner to verify the current code, infrastructure, vendor contracts, and deletion jobs. Until then, the policy and Help page are the sources for stated commitments and current user guidance; the unanswered items remain questions.