privacy

AI Photo Book Services See Every Photo You've Ever Taken

Auto-generated photo books require broad access to your entire library — including photos you'd never consciously choose to hand a third party.

Photo book services have changed dramatically in the past few years. What used to require hours of manual image selection is now handled by an algorithm: connect your Google Photos or iCloud library, let the service analyze your photos, and receive a suggested layout within minutes.

The convenience is real. So is the access you’re granting to get it.

What “Connect Your Library” Actually Means

When a photo book service asks you to connect your Google Photos or iCloud library, you’re not granting access to a pre-selected folder. You’re authorizing the service to access your entire photo archive through an API.

Services that use AI curation — auto-selecting the best photos from a period or a trip — need this broad access to work. The algorithm has to see your full library to surface the “best” images. It can’t cherry-pick the good ones without first reviewing the rest.

This analysis happens on the service’s servers, not on your device. The photos that don’t make it into the final book still passed through the company’s infrastructure during the selection process.

For most users, that means years of photos — including images from medical appointments, personal documents photographed for reference, intimate moments, and private events — passing through a third-party server for a service whose primary deliverable is a physical book of vacation highlights.

The Selection Process Requires Seeing Everything

The core value proposition of an AI-curated photo book is that the algorithm sorts through thousands of images to find the best ones for your book. That sorting requires seeing all of them.

Most services are transparent about this in their privacy policies — the language “we access your library to provide our service” is accurate. What it doesn’t convey is the scope of “our service”: that providing a curated photo book of your summer vacation requires the company to process your entire camera roll, not just the summer vacation photos.

Users who have spent years accumulating photos in a library — often without thinking carefully about what’s in it — may be surprised at what falls within scope. Photos from healthcare visits. Screenshots containing passwords or financial information. Images of personal documents. The content people keep in cloud libraries tends to be much broader than the content they consciously share.

Facial Recognition and the Data That Stays Behind

AI photo book services frequently use facial recognition to identify recurring people in your library. This allows them to build books around specific family members and to ensure that certain individuals appear consistently across layouts.

This facial recognition process creates facial embeddings — mathematical representations of faces derived from your photos. These embeddings are typically stored by the service, and their retention after your order is complete is governed by the service’s privacy policy.

The legal landscape around biometric data is uneven. Illinois’ Biometric Information Privacy Act (BIPA) and similar state laws require informed consent and written retention policies for biometric identifiers. But many consumer photo services are not designed for BIPA compliance, and enforcement has been inconsistent.

What’s less ambiguous: facial embeddings derived from your photos represent real biometric data about real people — including people who appear in your photos but never consented to having their face processed by a photo book company.

What the Privacy Policies Actually Say

Reviewing terms across photo book and photo management services reveals patterns worth understanding:

AI model training. Most services retain the right to use “anonymized” or “aggregated” data from user photos to improve their AI models. Anonymization standards vary significantly across companies, and faces can often be re-identified even from supposedly anonymized datasets.

License grants. Some services include a license grant in their terms that allows the company to reproduce user content in “service-related contexts.” The scope of “service-related” is typically defined broadly and at the company’s discretion.

Data retention after order completion. Few services publish clear policies specifying how long your photos — or the derived data from them — are retained after an order is placed and fulfilled. In many cases, API access permissions granted at signup remain active until you explicitly revoke them.

Third-party processors. Virtually all photo book services use third-party infrastructure for AI processing, image storage during production, and printing. Your photos may pass through multiple third-party systems before the book is printed.

The Google Photos Integration Case

Google’s own photo book offering — available directly within Google Photos — operates under Google’s existing privacy policy. For users who have opted into Google’s personalization features, using the native Google photo book service contributes to Google’s understanding of your visual preferences, subject matter, and relationships.

For users with iCloud Advanced Data Protection enabled, connecting third-party photo book services may require temporarily downgrading Apple’s end-to-end encryption protections, because ADP prevents third-party API access. This means choosing between the convenience of an AI photo book service and the security model you’ve set up for your photos.

Subscription Services and Continuous Library Access

Some photo book services operate on a subscription model — automatically generating books from your recent photos monthly or annually. For this automatic curation to work, the service retains persistent access to your photo library, not just during the order process but continuously.

A service with persistent library access can observe your library over time: new people appearing in your photos, changes in location, events that correspond to identifiable life milestones. Whether these services use this observational capacity for anything beyond photo selection is governed by their privacy policies — documents that few subscribers read at signup and fewer revisit after updates.

Practical Alternatives

If you want a physical photo book without granting broad library access to get it:

Manually curated upload services. Many photo printing companies accept direct photo uploads — you select and upload only the images you want in the book, without any API connection to your full library. You spend more time selecting, but the service sees only what you choose.

Local photo book design software. Applications that let you design a book on-device and upload only the final layout. The service receives a print-ready file rather than access to your library.

Export-then-upload. Export a specific album from Google Photos or iCloud to your device, then upload that export to the service. This limits the service’s access to the album you’ve curated, not your full library.

Maintain a separate private library. Keeping your primary photo archive in a private storage service, separate from Google Photos or iCloud, means that even services requiring API access can only reach what’s in the connected library. daftei stores your files with AES-256 encryption and never allows third-party access to your content for AI training or advertising.

The photo book itself isn’t the problem. The mechanism that makes AI-curated photo books convenient — continuous cloud library access — is what creates the exposure. Separating those two things is straightforward, even if the default experience discourages it.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts