privacydeep-dive

What Photo Printing Services Do With Your Family Albums

Uploading thousands of personal photos to Shutterfly or Snapfish for a photo book feels harmless. Here's what their privacy policies actually say.

The photo book is one of the more wholesome things the internet enables. You take a few years of family photos, drag them into a design tool, and six weeks later a hardcover book shows up at your door. No subscription required. A physical artefact of family life that doesn’t depend on any platform staying in business.

The privacy question that rarely comes up: what happens to your photos in the time between upload and delivery?

When you use a service like Shutterfly or Snapfish to make a photo book, you upload your family photos to their servers. Depending on how many photos you have and how many books you’ve ordered over the years, that collection can be substantial — thousands of images of your children, your home, family gatherings, holidays, private moments. The service stores those photos to allow you to make future orders.

The terms governing that collection, and the security history of the companies holding it, deserve more attention than most users give them.


Who Actually Owns These Services

Understanding the corporate structure behind photo printing services is a useful starting point, because it affects what happens to your data under various business scenarios.

Snapfish and Shutterfly are both owned by the same entity: Shutterfly acquired Snapfish in 2020. What appears to be two competing services is actually a single company, operating two brands, processing your photos through the same corporate infrastructure.

Shutterfly itself has changed ownership multiple times. The company was taken private in 2019 by Apollo Global Management, a private equity firm. In private equity ownership, businesses are typically managed for eventual sale or restructuring — which affects how to think about what happens to customer data if the business is sold, restructured, or wound down.

This isn’t abstract. Data-after-acquisition scenarios are a recurring feature of the photo service landscape. When a company is sold, customer data — including uploaded photo libraries — is typically a business asset that transfers to the acquirer. The privacy policy you agreed to when you uploaded photos may or may not carry over to a new owner’s practices.


The 2021 Security Incidents

Shutterfly experienced two significant security events in 2021 that are worth understanding before uploading your personal photo archive.

The Ransomware Attack

In December 2021, Shutterfly was hit by a Conti ransomware attack. The ransomware group obtained access to Shutterfly’s corporate network and encrypted systems. The attackers subsequently published approximately 7 gigabytes of stolen Shutterfly data, including employment agreements, financial documents, legal documents, and payroll data.

Shutterfly’s statement at the time indicated customer account details were part of the investigation scope, though the company’s public communications were limited. What the Conti attack demonstrated is that Shutterfly’s corporate network — the same infrastructure that holds customer photo libraries — was successfully breached by a sophisticated ransomware group.

The Illinois BIPA Settlement

In September 2021, Shutterfly settled a class-action lawsuit related to a breach of the Illinois Biometric Information Privacy Act (BIPA). The settlement totalled approximately $6.75 million.

BIPA governs the collection and use of biometric identifiers — which includes facial geometry derived from photos. The lawsuit alleged that Shutterfly was collecting biometric data from uploaded photos (through facial recognition used to identify people across photos) without the consent required by Illinois law.

The settlement is relevant for two reasons. First, it confirms that Shutterfly was running facial recognition on uploaded customer photos — a fact not prominently disclosed to users. Second, the settlement amount, while substantial, was a corporate cost of doing business rather than a deterrent that fundamentally changed the company’s technical practices.


What the Privacy Policy Actually Says About Your Photos

Shutterfly’s privacy policy (which also governs Snapfish under unified ownership) contains several provisions that most users don’t read.

Storage Duration

Shutterfly stores uploaded photos indefinitely. The policy describes “secure” online storage that enables reordering. There is no stated automatic deletion policy. Your photos can remain on Shutterfly’s servers for years or decades, accumulating across every order you’ve placed.

This differs from what users typically imagine. When people think of uploading photos “to get prints made,” they often assume the photos are used for the order and then either deleted or their presence is temporary. The reality is an indefinitely retained library of family photos that grows with each order.

Data Sharing

The Shutterfly privacy policy describes data sharing with service providers, business partners, and affiliates. Service providers are common (every major platform uses third-party infrastructure). But the breadth of the “business partners” category affects what data can be shared and with whom.

The policy also addresses legal requests: like most platforms, Shutterfly will comply with valid legal processes, which means law enforcement can potentially obtain access to your stored photos through appropriate legal procedures.

Facial Recognition and Technology Uses

The BIPA settlement established that Shutterfly was using facial recognition on uploaded photos. Automated analysis of uploaded photos for identification, categorisation, and metadata generation is standard practice for photo storage services — it’s how features like “find all photos of this person” work.

The data generated by that analysis — which faces appeared in which photos, derived relationships between people in your photos — represents a layer of information about your social network and family relationships that goes beyond the photo files themselves.


What EXIF Metadata Reveals

Beyond the photo content itself, photos you upload carry EXIF metadata that reveals additional information.

GPS coordinates embedded in photos show where each image was taken. Date and time stamps establish when photos were taken and how often you visit various locations. Device information shows what camera or phone you used. This metadata is typically retained alongside uploaded photos.

A collection of family photos uploaded to print a photo book therefore contains not just visual information — faces, relationships, events — but also a time-stamped location history of where those events took place. Your home address, the school your children attend, the park you visit regularly, the hospital or clinic you’ve visited — all potentially derivable from EXIF metadata across a photo library.


The AI Training Question

Print services’ terms of service generally pre-date the current era of generative AI. They contain broad rights to use uploaded content “to provide services” — language written before using photo libraries as AI training data was a commercial practice.

Whether photo printing services are using uploaded libraries for AI training purposes is not clearly answered by their current public terms. The terms neither explicitly prohibit it nor explicitly disclose it.

This is an area where the burden is on users to ask, and on companies to answer clearly. Vague service improvement language is not an adequate substitute for explicit disclosure about whether personal photo archives are being used to train generative AI models.


Comparing the Privacy Risk of Print vs. Private Storage

There’s a meaningful difference in privacy exposure between storing photos in a service primarily designed for printing and storing them in a service primarily designed for privacy.

Print service model: Your photos are uploaded to generate a product. The business model is selling printed products. The photos are stored as a convenience for future purchases. The company’s primary obligation is to the printing business, not to the privacy of your personal archive.

Private storage model: Your photos are stored because you want to store them privately. The business model is the storage service. The company’s primary obligation is to maintain your data securely and make it available to you.

These are structurally different relationships. In the print service model, your stored photos are a secondary asset — useful for upsells and reorders, but not the core product. In private storage, your stored photos are exactly the core product, and the company’s reputation depends on their security.

This structural difference affects everything: how seriously the company takes security investment, how clearly its terms are written, how it handles breach disclosures, and what happens to your data if the business changes hands.


Practical Steps

Download Your Photos Before Each Order

Rather than leaving a permanent library at a print service, download your photos afterward. Most services allow you to delete uploaded projects after ordering. Maintaining a minimal footprint — uploading what you need for a specific order, then removing it — reduces your exposure.

This is less convenient than leaving everything uploaded for easy reordering. But it’s a reasonable trade-off if you have concerns about the security history or terms of the service.

Strip EXIF Metadata Before Uploading

If you use a photo printing service, strip EXIF metadata from photos before uploading. The print quality is entirely unaffected by metadata removal. The GPS coordinates, date-time stamps, and device information in that metadata are not needed to produce a print — but they are collected and retained.

iOS, Android, and most desktop photo editing tools can strip EXIF data before export.

Use a Separate Archive for Originals

Keep your original, full-quality photo archive separate from what you upload to print services. Upload copies or exports sized for print, not your master collection.

This ensures that your primary photo archive — with its full metadata and highest quality — isn’t sitting on a print service’s servers indefinitely. You control the originals; the print service gets a copy sufficient for their purpose.

Understand Account Deletion

If you decide to stop using a print service, understand what account deletion actually does to your stored photos. Most services have a process for deleting accounts and stored data, but the implementation and timing vary.

Read the deletion policy before trusting it. Look for explicit language about photo deletion timelines and whether derived data (metadata, analysis outputs) is also deleted.

Check What AI Features Are Available — and Opt Out

If a print service has introduced AI-powered features (smart photo selection, auto-enhancement, style transfer), understand what those features do with your uploads. Opt out of any AI training uses if the option is available.


The Core Question

The photo printing industry hasn’t faced the same level of privacy scrutiny as social media or major cloud storage providers. But the data these services hold is equivalent in sensitivity — in some respects, more so, because the collections often span years or decades and include photos of children at ages where the subjects cannot consent.

The question isn’t whether photo printing services are doing something deliberately harmful with your photos. Most aren’t. The question is whether you’ve given informed thought to what you’re uploading, how long it stays there, what the terms say about its use, and what happens to it if the company is breached, sold, or wound down.

For most people, the convenience of permanent photo library access at a print service feels like a minor technical convenience. It’s actually a data relationship that deserves the same consideration as any other service holding thousands of intimate personal photos.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts