The trend cycles through every few months: a new AI portrait app goes viral, your social feed fills with illustrated versions of people’s faces, and millions of users upload batches of selfies to see themselves rendered as an oil painting or fantasy character. The output is genuinely impressive. The privacy implications are worth examining before you participate.
These apps don’t just process your photos and return results. They upload facial data to remote servers, build models from your images, and operate under terms of service that most users have never read. Understanding what you’re actually sharing when you join a viral photo trend is worth the few minutes it takes.
What Happens When You Upload Your Photos
At a minimum, AI avatar apps transfer your photos to remote servers. The generation process is computationally intensive enough that it can’t run meaningfully on a mobile device — your images travel to a cloud environment, are used to prompt or fine-tune a generative model, and the portrait outputs are returned to your screen.
That transfer involves more than the images themselves.
Facial geometry. To generate a convincing likeness, these systems analyze the structure of your face — the proportions and distances between features, the contours of your eyes, nose, and mouth. In Illinois, this data is classified as biometric information under the Biometric Information Privacy Act (BIPA), which requires companies to obtain written informed consent before collection and imposes strict limits on how long the data can be retained and whether it can be shared.
A class action lawsuit against Prisma Labs — the company behind Lensa AI — alleged that the app collected users’ facial geometry data in violation of BIPA. The complaint specifically noted that the company’s privacy policy at the time made no reference to facial geometry, despite the fact that analyzing facial geometry is precisely what enables the portrait generation. A Northern California court sided with Prisma on the procedural question of arbitration, but the underlying data practices that prompted the lawsuit are common across apps in this category.
The photo batch itself. What happens to your 20-photo upload after the portraits are generated varies by service and by the terms you agreed to. Some apps claim photos are deleted within a defined window after processing — Lensa’s stated policy at the time of the lawsuit was 24 hours. Others retain images for longer periods, use them for model training, or pass them to third-party model providers. The specifics are in the terms, not in the interface.
Metadata and identifiers. Beyond the images, apps collect device identifiers, usage patterns, account data, and metadata that persists and can be linked back to you even after photos are deleted.
The Terms of Service Few People Read
The terms for AI avatar apps are written broadly, and that breadth matters when the content being uploaded is your face.
Common language in this category includes grants of rights to use submitted content for purposes beyond the immediate task — which can include improving AI models, training datasets, and in some cases commercial applications. The specific language varies by service and evolves over time. But the pattern is consistent: broad rights, extensive scope, and the critical details buried in dense policy documents that users agree to with a tap.
The fact that the interface shows you a delightful portrait doesn’t change what the terms describe in the fine print. When you upload photos to an app under a terms-of-service model that grants the company broad content rights, you’re not just getting a portrait. You’re granting rights to your facial images that extend beyond the transaction you thought you were making.
Why Facial Data Is a Different Category
The difference between uploading a photo of a landscape and uploading 20 photos of your face isn’t just a matter of degree. Facial biometric data is structurally distinct from other personal information.
It can’t be reset. Unlike a password, a credit card number, or even an address, your facial geometry is fixed. If facial biometric data is exposed, compromised, or misused, you don’t get a replacement. You can’t change your face the way you can rotate an API key.
It enables identification. A set of photos of your face, used to fine-tune a model, could make it easier for systems to identify you across other images — photos from public cameras, images uploaded by others, footage you had no awareness was being captured. The value of a facial biometric dataset grows with scale, and companies that accumulate large collections of facial data hold something useful beyond the portraits they’re selling.
It’s uniquely persistent. The facial geometry of an adult changes slowly over time. Data collected now about your face retains its utility for identification for years.
State protections are uneven. Illinois’s BIPA provides real legal teeth — statutory damages per violation and a private right of action, which is why most facial biometric lawsuits are filed there. A handful of other states have passed similar laws. But most U.S. states, and most of the world, have no specific legal framework governing facial biometric data from consumer apps. Outside those jurisdictions, companies can collect and use facial data with minimal specific legal restriction.
The Assurance That Photos Are “Deleted in 24 Hours”
Several AI avatar apps have addressed privacy concerns with automatic-deletion claims — photos are processed and then removed within hours, and the only thing retained is the portrait output you downloaded.
This deserves scrutiny on multiple levels:
Self-reported, not verified. There’s no independent auditing body confirming that photo deletion actually occurs on the claimed timeline. The assurance is the company’s word. For data as sensitive as a biometric, “trust us” is a weak foundation.
Fine-tuning embeds information in the model. The process of fine-tuning a generative model on a set of your photos can embed information about your facial appearance in the model’s parameters — information that persists after the source photos are deleted. This is a technical property of how these models work, not always something that’s clearly explained in the deletion assurance. The photos are deleted; the model’s internals may not be.
Terms change. A company that deletes photos within 24 hours today may update its policy later. Data practices at AI companies have shifted repeatedly as the business landscape has evolved. The policy in place when you uploaded doesn’t bind the company indefinitely.
Third-party pipelines. Many avatar apps are built on foundational models from major AI companies. Your photos and the derived processing data may pass through infrastructure operated by entities other than the app you opened. The full data flow is rarely disclosed in the interface.
What to Check Before Uploading to an AI Photo App
If you want to participate in AI portrait trends without handing over facial biometric data unnecessarily:
Look specifically for biometric disclosure. Does the app’s privacy policy use the words “facial geometry,” “biometric identifier,” or “facial features”? A company with good practices names what it collects and how long it keeps it. The absence of explicit biometric disclosure when the product clearly analyzes your face is a signal worth noting.
Check whether your jurisdiction has facial biometric protection. Illinois, Texas, Washington, and a growing number of states have enacted laws that give users rights over facial biometric data. If you’re covered, you may have consent and deletion rights that the company is legally obligated to honor.
Look for a deletion request mechanism. Can you explicitly request deletion of your data after the portrait is generated? Services that make this easy — or build it into their standard post-generation flow — are operating under a different philosophy than those that bury or omit it.
Be cautious about large photo batches. The more images you upload, the more complete the facial biometric dataset the service builds from your face. Some legitimate portrait generators can work from one or two photos. Apps requiring 15-20 images for their base case are building a denser model from your appearance.
Search for the app’s name plus “privacy” or “lawsuit.” A two-minute search often surfaces information about past incidents, regulatory inquiries, or lawsuits that you won’t find in the app’s own marketing.
The Deeper Pattern: Convenience and Permanence
There’s a mismatch at the heart of these trends. The experience is ephemeral — you participate, you get portraits, you share them, the trend fades. But the data collected in that window is permanent in ways that the experience doesn’t communicate.
Biometric data doesn’t expire. A company that processed your photos under one set of terms may be acquired, change its business model, change its data practices, or face a breach — and the biometric record of your face, collected during a viral portrait trend several years ago, remains relevant to whatever comes next.
This isn’t an argument that AI portrait apps are universally malicious. It’s an argument that the terms governing your most identifying personal data deserve more than a tap-through agreement, and that the “deleted in 24 hours” assurance answers one specific question while leaving others open.
Where Your Ongoing Photos Should Live
For photos you care about — family archives, personal memories, images you want to be able to find years from now — the relevant question is where those files live and under what terms.
A storage service whose business model is the subscription rather than the data operates differently from one whose revenue depends on extracting value from your content. The questions to ask are the same ones worth asking about AI portrait apps: what does the company actually collect, who does it share data with, is your content used to train AI models, and what happens to your files if you stop paying or the company changes direction?
daftei stores files encrypted at rest with AES-256 and in transit with TLS 1.3. It doesn’t use your photos to train AI models, doesn’t share content with third-party AI providers, and doesn’t run advertising. Revenue comes from the subscription. A 5 GB free tier is available on iOS, Android, and at /app, with unlimited storage on Pro at $5.99/month or $44.99/year.
The portrait you generate from a viral app may last an afternoon. The data you hand over to generate it may outlast the company that processed it.