An input photo may show more than a face. It can reveal a home, workplace, another person, or location metadata. Before uploading, check what the service says it collects, how long it keeps files, and how to request deletion. This guide separates MyPhotoAI's published policy from questions that still need an operational check.
The MyPhotoAI privacy policy was updated on 24 September 2026.1 It describes account data, uploaded photos, payment processing, retention, and deletion requests. A policy describes the company's commitments; it does not, by itself, prove that every automatic deletion job has been implemented or audited.

The photo's path
| Stage | What the current policy says | What to check before making a stronger claim |
|---|---|---|
| Upload | Photos are stored so the requested AI features can run | Storage location, access roles, and whether metadata is stripped |
| Processing | Photos are processed to provide the service | Which processors receive files and under which retention terms |
| Result | Generated photos may be stored for access and purchase | Whether all intermediate outputs follow the same schedule |
| Payment | Stripe processes payment information; MyPhotoAI says it does not store full card numbers | Keep payment retention separate from photo retention |
| Deletion | Users may request account, photo, or data deletion by contacting support | Actual deletion workflow, backups, processor deletion, and completion evidence |
This table is deliberately narrow. It does not assert a model-training policy or a complete list of processors because those facts need confirmation from the product owner and current vendor agreements.
What the retention language means
The policy says reference photos, unpurchased generated photos, and other user data will be deleted within 30 days of creation or collection.1 Purchased photos are described as available for 60 days after purchase, unless the user deletes them or closes the account sooner. Authentication data remains while an account is active, and some records may be retained longer for legal obligations.
The same policy says users should contact [email protected] for deletion until automatic deletion is in place. MyPhotoAI's Help page says that the automatic schedule is not active yet and that photos may remain in the gallery until deletion or account closure.2 That qualification matters. Do not translate the stated schedule into a claim that a verified automatic purge is already running. Download purchased photos you want to keep, and ask support if you need confirmation about a particular deletion request.

Before you upload
Use photos you have the right to process. The terms prohibit uploading private photos of others without permission. Remove other people from the frame if they have not agreed to the upload. Check mirrors, badges, documents, and visible screens. If an image contains location metadata, consider removing it before sharing, especially if the original was taken at home.
For work photos, distinguish three permissions: permission to upload a person's source image, permission to create a generated result, and permission to publish the selected portrait. An employee's agreement to appear on a company directory is not automatically permission to publish their source photos or use their result in advertising.

How to request your data
The policy directs deletion and export requests to [email protected]. State the email used for the account and whether you want a photo removed, an account deleted, or an export. The policy says requests are authenticated before fulfillment, which helps prevent another person from deleting or obtaining your data.
Keep the confirmation and ask what was removed if the scope matters to you. For a workplace account, also ask the employer about copies held in its own directories or design systems; deleting a service account does not remove independent copies made elsewhere.
Questions this guide cannot yet answer
The public policy does not provide enough detail here to map every processor, backup, access log, or model-use path. A complete data-flow diagram needs an owner to verify the current code, infrastructure, vendor contracts, and deletion jobs. Until then, the policy and Help page are the sources for stated commitments and current user guidance; the unanswered items remain questions.






