You upload a photo to Canva to design a birthday card. Canva crops it, applies a filter, and places it inside a template. You export the design, send the card, and move on.
What you may not have noticed is a toggle in your account settings — enabled by default at signup — that gives Canva permission to use your uploaded content to train its AI models.
What Canva Disclosed (and When)
In early 2025, detailed coverage from photography publications surfaced that Canva had been enabling an AI training consent setting by default for users at the point of account creation. The toggle wasn’t prominently disclosed during signup. It was buried in account settings, and its existence came to light primarily through users and journalists who dug into the privacy controls.
Canva’s position was that users could opt out. The problem critics identified: an opt-out model for AI training means everyone who didn’t find the setting — which is most users — is opted in.
The setting applies not just to photos you upload but to the designs you create, the text you add, and potentially the entire interaction history within your account.
What “AI Training” Actually Means for Your Photos
When a company uses uploaded content for AI model training, it means that your images — or features derived from them — are fed into the process that teaches the model to recognize patterns, generate content, or improve its outputs.
This doesn’t mean your photo appears verbatim in someone else’s design. It means:
The model learns from the visual content of your photo. A dataset of a million uploaded birthday card photos teaches a model what birthday visuals look like, what kinds of images people use for celebrations, what composition patterns appear most often.
Your photo becomes part of a corpus that permanently influences an AI system you have no control over. Even after you delete the photo from Canva, the model’s weights have already been updated.
Depending on how the training is structured, image features from your photos can persist in the model indefinitely.
The Specifics: What Canva’s Terms Say
Canva’s terms of service grant the company a broad license to use uploaded content. The specific scope of what’s permitted for AI training purposes is governed by a combination of the main terms and a separate AI policy.
The key points users should understand:
Uploaded media. Photos, videos, and other media you upload to Canva are stored on Canva’s servers even after you delete a design. The media library retains files unless you explicitly delete them from the library itself — not just from a specific design.
Design data. The way you use Canva — what templates you choose, how you edit them, what combinations of elements you select — generates behavioral data that can inform product development and, potentially, AI training.
Third-party model training. Canva partners with AI companies and may share aggregate data or content with those partners. The terms should be read carefully to understand whether your uploads could move beyond Canva’s own systems.
The most important thing to check is whether the AI training setting has been updated since you created your account. Canva has made several policy changes, and previous opt-in states may not reflect the current policy.
How to Opt Out of Canva AI Training
If you have a Canva account, here is where to find the relevant settings:
- Go to your account settings (the profile icon in the top-right corner of the Canva editor)
- Navigate to Privacy or Account Settings
- Look for a section labeled AI features, Data and privacy, or Personalization
- Find the toggle for AI model training or content usage for AI improvement
- Disable it
The exact label and location of this setting can change between app versions. If you cannot find it, search Canva’s help center for “AI training opt out” — Canva has a support article describing the process.
Note: opting out applies going forward. Photos and designs already processed for training purposes are not retroactively removed from the training data.
Canva Is Not an Outlier
The pattern of web-based creative tools enabling AI training by default is not limited to Canva. Several major online photo editors have similar practices:
Adobe Express. Adobe’s Creative Cloud terms include provisions for using your content to train Adobe AI models (including Firefly). Adobe has updated its terms multiple times under user pressure, and the current opt-out path is in account privacy settings.
Fotor. This browser-based photo editor uses uploaded images for service improvement, and their privacy policy includes provisions that can be interpreted to allow use for AI development.
Pixlr. Pixlr’s privacy policy permits them to use uploaded files for “improving our services,” language broad enough to cover AI training.
PicsArt. PicsArt’s terms allow use of content for “machine learning and AI model development.”
The common thread: these tools exist to make editing easy and fast, and the business model often depends on training increasingly capable AI to enable that ease. Your uploads are the training data.
The Offline Alternative: Tools That Don’t Touch Your Photos
If your use case involves sensitive photos — personal memories, family images, documents — there are offline alternatives that process images entirely on your device:
Apple Preview (Mac) handles basic editing and annotation without any cloud upload.
GIMP is an open-source image editor that runs locally. No network connection required for any editing functionality.
Affinity Photo is a professional-grade desktop editor with no subscription and no cloud dependency.
Photos app on both iOS and macOS performs editing locally by default. iCloud Photos sync is a separate feature you can leave disabled.
The tradeoff is convenience. Browser-based tools are frictionless because the compute happens on their servers, and their servers require your images to function. Local tools require more setup but give you complete control.
What to Do With Photos You’ve Already Uploaded
If you have an existing Canva account with a media library of personal photos, the first step is to audit what’s there.
Go to Canva’s media library (usually accessible through the editor sidebar) and review what’s uploaded. Delete photos that you’d prefer not to be on a third-party server — not just from designs, but from the library itself.
Be aware that deletion from Canva’s media library does not guarantee immediate removal from their servers. Like most cloud services, Canva retains data for a period after deletion for backup and operational purposes. Their privacy policy should describe the retention timeline.
For your most personal photos — family moments, documents, anything you’d consider sensitive — the better practice is to avoid uploading them to web-based creative tools entirely. Use a local editor or keep originals stored in a service that explicitly commits to not using your content for AI training.
The Structural Issue
Canva’s AI training setting illustrates a broader design pattern in consumer software: the default state is always the one that benefits the company.
Opt-in consent for data collection is a meaningful protection. Opt-out consent — where you’re enrolled automatically and must actively seek out a buried setting to disenroll — functions very differently in practice. Most users don’t know the setting exists. Most never change it.
The GDPR has specific requirements about consent: it should be freely given, specific, informed, and unambiguous. A default-on AI training toggle fails the “unambiguous” test. European users who believe they have meaningful data protections under GDPR should check whether their data is in scope and whether Canva’s consent mechanism meets the standard.
Choosing Where Your Photos Actually Live
The deeper issue with web-based photo editors isn’t just the AI training toggle — it’s the architectural model.
Every time you upload a photo to a browser-based tool, you’re creating a copy of that photo on someone else’s server. That copy is subject to that company’s privacy policy, their security posture, their legal obligations, and their business model. You’re not renting temporary compute; you’re depositing data.
For casual, non-sensitive image editing, that’s probably an acceptable tradeoff.
For the photos that matter — the ones you’d be upset to see used for purposes you didn’t choose — it’s worth thinking carefully about where originals live and what tools they pass through.
daftei stores your photos and personal files with AES-256 encryption at rest and TLS 1.3 in transit. It never uses your content to train AI models — not Canva’s models, not any third-party AI system, not its own. Your files exist to serve you, not to improve someone else’s product.
That’s a different design choice from Canva’s. And it’s one that matters most precisely when the photos are personal.
The Practical Takeaway
You don’t have to stop using Canva. It’s a genuinely useful design tool.
But go check your settings today. Turn off the AI training toggle if it’s on. Audit your media library and delete personal photos you uploaded without thinking about where they’d end up. And for the photos you care about most, keep originals in a service that treats your content as yours.
The toggle exists. Most users just never knew to look for it.