privacysecurity

AI Headshot Generators: What Happens to Your Face

AI headshot apps promise polished LinkedIn photos, but they require uploading dozens of your most identifiable images. Here's what happens to those photos afterward.

When AI headshot generators went mainstream, the pitch was simple: upload 20 photos of yourself, wait 15 minutes, and receive a set of polished professional portraits without booking a photographer or leaving your house. Millions of people have done exactly this. The photos they uploaded were not random selfies — they were their clearest, most face-forward, best-lit images.

Those images are now somewhere. The question is where.


What You Actually Upload

The input requirements for most AI headshot services are specific and revealing. You’re typically asked for 15–30 photos that meet a detailed checklist: different angles, multiple lighting conditions, various expressions, no sunglasses, no hats, no other people in frame. The clearer your face appears across all images, the better the output.

This set of photos constitutes a facial dataset. Not in a dramatic, sci-fi sense — in a precise, technical sense. A diverse set of photos of the same person’s face from different angles and under different lighting conditions is exactly what’s used to train facial recognition systems and to create personalized generative AI models.

The headshot service uses these photos to fine-tune a model specifically on your face. That’s how they generate new images of you that you haven’t posed for. The technical term is personalized LoRA fine-tuning or similar diffusion model adaptation. Your uploaded photos are the training data.


The Question Services Don’t Answer Clearly

Every AI headshot service answers some version of the question “are my photos private?” The answers tend to share a common structure: they explain what they do with your photos during the generation process, and they describe their security measures. What many answers omit or obscure is what happens after.

The specific questions worth asking are:

Are the photos deleted after generation is complete? Some services delete uploaded source photos after processing. Others retain them for an unspecified period. Others retain both the source photos and the fine-tuned model indefinitely, because the model is what lets you generate additional headshots later without re-uploading.

Is the fine-tuned model — trained on your face — retained? Even if the original photos are deleted, the personalized model that learned your facial features from them may persist. This model can generate new images of your face and is arguably a more refined form of the original biometric data.

Are photos or model data used to improve the base model? This is the question that cuts deepest. Some services — particularly free or low-cost ones — reserve the right to use uploaded content to improve their general AI systems. This is how free AI tools often monetize: the photos you upload to get your headshots improve the model that generates headshots for everyone else. The cost of the service is your data.

What happens to your data if the company is acquired or shuts down? A headshot startup that processes your photos under today’s privacy policy may be acquired tomorrow. The new owner inherits the data and is typically not bound by the original policy.


The Regulatory Landscape Is Shifting

In February 2026, 61 data protection authorities published a joint statement on AI-generated imagery specifically addressing privacy concerns around services that generate realistic depictions of identifiable individuals. The statement identified several practices as high-risk: retaining source photos longer than necessary, using biometric data without explicit consent, and generating imagery of people in contexts that could damage their reputation or safety.

The regulatory concern isn’t hypothetical. Your face is biometric data under GDPR, the Illinois Biometric Information Privacy Act (BIPA), and an expanding set of US state privacy laws. Processing biometric data requires affirmative consent in most of these frameworks — not just a buried clause in a terms of service agreement, but explicit, informed agreement to the specific use.

Clearview AI’s facial recognition practices — scraping public photos to build a searchable facial database — resulted in a $50 million biometric privacy settlement. While AI headshot services are distinct from facial recognition databases, they process the same type of data: high-quality images of your face collected with the intent to build a model of what you look like.

The legal exposure for services that handle biometric data carelessly is growing, not shrinking.


Free Services vs. Paid Services

The risk profile differs sharply between free and paid headshot services.

Free services have to make money somehow. If there’s no subscription fee, the data you provide is frequently the revenue model — either used directly to improve their AI systems, sold to data brokers, or made available to third-party researchers. Reading the privacy policy of a free AI headshot service carefully often reveals language like “we may use uploaded content to improve our services” or “de-identified images may be used for training purposes.” De-identified is doing heavy work in that sentence — faces are not easily de-identified.

Paid services that charge a flat fee per generation session have less structural incentive to retain your data. Some explicitly advertise automatic deletion of source photos after a specified period (24 hours, 7 days) as a feature. This is worth verifying in the privacy policy rather than taking at face value in marketing copy.

Enterprise-facing services that sell to corporations for employee headshots have stronger compliance incentives. These services often publish explicit data processing agreements, list their subprocessors, and specify retention and deletion schedules — because their enterprise customers require it as a condition of the contract.

If you must use a consumer-facing service, a paid service with an explicit deletion commitment in its privacy policy (not just marketing materials) is meaningfully less risky than a free one.


What the Output Photos Reveal

There’s a less-discussed risk on the output side. AI-generated headshots are created images, but they’re derived from real photos of you. The output images may embed metadata that reveals the generation source. Some services add watermarks or steganographic markers to indicate AI origin.

More practically: the output photos are high-quality, professional-looking images of your face that you’re likely to use on LinkedIn, a personal website, or a professional bio. This is a set of uniform, high-quality images of your face that could be used for facial recognition, reverse image search, or identity theft in ways that a diverse set of casual photos might not.

A professional headshot from a human photographer presents the same surface risk, but with an important difference: the photographer didn’t create a personalized AI model of your face in the process.


How to Evaluate a Service Before Using It

If you’re weighing an AI headshot service, the privacy policy — not the marketing — is the document that matters. Look for specific answers to these questions:

Is the privacy policy explicit about deletion? Look for specific time frames: “source photos are deleted within X days of generation.” Vague language like “we retain data for as long as necessary” is not a commitment.

Is the fine-tuned model mentioned separately? The model is different from the photos. A service that deletes source photos but retains a personalized model of your face has not actually minimized your data exposure.

Does the service distinguish between processing and training? Using your photos to generate your headshots is processing. Using your photos or the derived model to improve outputs for other users is training. The latter is a fundamentally different use and should require separate, explicit consent.

What’s the jurisdiction? GDPR enforcement in the EU provides stronger backstops than most US state laws. A service incorporated in a GDPR jurisdiction faces meaningful penalties for mishandling biometric data.

Is there a data subject rights mechanism? Under GDPR, CCPA, and similar laws, you can request deletion of your data. A legitimate service will have a process to honor this request, including deletion of any retained models.


Where This Fits in a Broader Privacy Picture

The specific risk of AI headshot services is a combination of factors that rarely appear together: the data is biometric (your face), the quantity is high (15–30 photos), the quality is high (your clearest images, optimized for facial recognition readability), and the processing creates a derivative dataset (the fine-tuned model) that may persist after the source photos are deleted.

This combination makes AI headshot photos among the most sensitive images you can upload to a third-party service. The output — a polished LinkedIn photo — feels low-stakes. The input process is not.

For sensitive personal files and memories that don’t need to be processed by a third-party AI, storing them in a service that doesn’t use your content to train any external systems is the baseline. daftei’s model is straightforward on this: your files and photos are never used to train AI systems that benefit anyone other than you, and the service runs no advertising. For professional headshots specifically, the choice of provider still carries weight — and that choice deserves more scrutiny than most people give it.


A Practical Default

You don’t have to avoid AI headshot services entirely. If the output is genuinely useful to you, the risk is manageable with the right precautions:

  • Use a paid service, not a free one.
  • Read the privacy policy’s data retention section, not just the marketing.
  • Confirm source photo deletion timelines in writing (ideally in the policy, not in a chat window).
  • Avoid services incorporated in jurisdictions with weak privacy frameworks.
  • After generation, submit a data deletion request if the service supports it.
  • Don’t reuse the same set of source photos across multiple services.

The technology will improve and the regulatory framework will clarify. For now, uploading three dozen clear photos of your face to an unfamiliar startup is a decision worth thinking through before you press submit.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts