A glowing padlock icon overlaid on a dark digital grid, representing data privacy and security for AI-processed photos
AI Headshots

AI Headshot Privacy: What Happens to Your Photos After Upload?

August 6, 202619 min readBy Headshot Plus Team
Back to Blog

We make AI headshots, so we have a direct stake in whether you trust this category with your photo. That's exactly why we'd rather over-explain this than sell it to you. Below is what actually happens after upload, based on published privacy policies from real providers in this space, current biometric privacy law, and what independent researchers have found — not just what any one company's marketing page says, us included.

Jump to a section
  1. The actual data lifecycle
  2. What real providers publish
  3. The legal landscape
  4. The genuine gray area
  5. What to check before you upload
  6. FAQ
Stated deletion window range across providers reviewed
RESEARCH 7–90 days
New Illinois BIPA biometric privacy lawsuits filed in 2025
LEGAL 107+
Statutory damages per BIPA violation (per person)
LEGAL $1k–$5k

01. What "AI headshot generation" technically does with your face

Every provider in this category follows roughly the same five-step process. The differences that matter are all in steps three and five.

The five-step AI headshot data lifecycle
1 Uploadselfies 2 Processing(often 3rd party) 3 Per-user modeltraining ★ 4 Headshotgeneration 5 Storage &deletion ★
★ Steps 3 and 5 are where providers differ most — and where the important questions live.

Step three is the one most people misunderstand, and it's worth being precise about it. To generate headshots that actually look like you, the platform needs to build a temporary representation of your face — commonly a small, personalized AI model trained only on your uploaded photos. That's a categorically different thing from a company using your photos to improve its general, shared AI model that generates images for every other customer. Reputable providers are explicit that they do the first (a private, per-user model used only for your session) and not the second — but the phrase "we don't train on your data" can technically be true while still describing exactly this per-user process. It's worth reading the specific wording rather than the marketing headline.

Step two also matters more than it seems. Several providers don't run their own AI infrastructure — one plainly states that generation happens through Replicate, a third-party AI hosting platform, meaning your photo briefly passes through another company's servers. That's not unusual or inherently risky, but it does mean the provider's privacy policy only describes part of the chain. (At Headshot Plus, we use Fal.ai for generation — more on that in the table below.)

Why a face is different from a password

A password, a credit card number, even a Social Security number can all be changed if compromised. A face cannot. That permanence is the entire reason biometric identifiers sit in a stricter legal category almost everywhere they're regulated. A breach of your facial data isn't a problem you can fix by resetting a credential — which is exactly why the retention window (step five) matters as much as it does. The shorter your photo exists on a server, the shorter the window in which that permanence becomes a liability.

02. We read the privacy policies so you don't have to

We pulled the published, current privacy commitments from several AI headshot providers to show what "good" looks like in this category — and how much it varies.

Provider Stated retention Trains shared AI models? Notable detail
Aragon AI 30 days, auto-deleted States no, without permission SOC 2 Type II certified, AES-256 encryption
HeadshotPhoto.io 7 days after generation States no User-triggered deletion available anytime
ProHeadshots Not specified; third-party AI providers apply States no, intentionally Explicitly states no facial recognition or biometric profiling
Magic-Headshot Retained until deletion is requested States no Deletion via direct contact request
AIHeadshotInstant Minimum time needed; full purge within 30 days of account deletion States no shared-model training Solo-developer product; no human review of images stated
Headshot Plus (us) 90 days after session completion, auto-deleted; earlier deletion on request States no — used exclusively to generate your headshots Processing via Fal.ai (third-party AI inference, no training on transmitted images); TLS in transit, encrypted at rest; GDPR-style rights; 18+ only

Two patterns hold across every policy we reviewed, our own included. First, "we don't train on your data" is now close to a universal claim in this category. Second, exactly how long your original photos sit on a server before deletion varies enormously — from 7 days to 90 days — and a couple only delete on request rather than automatically. We're on the longer end of that range: 90 days after your session completes, specifically so your generated headshots stay accessible from your dashboard without needing to immediately redownload them. That's a real tradeoff. A longer retention window is more convenient and is also more days your photo exists somewhere it could theoretically be exposed. If minimizing that window matters more to you than dashboard convenience, delete your photos manually once you've downloaded what you need.

The free-tool red flag

One pattern worth extra scrutiny: free or unusually cheap AI photo tools that don't clearly state a business model. A paid product has an obvious revenue source, which makes "we don't sell your data" a believable claim. A free tool with no visible paid tier has to fund its infrastructure somehow — and if a privacy policy doesn't explain how, that's a reasonable thing to ask before uploading a photo of your face to it.

03. What the law actually says about a photo of your face

Three legal frameworks come up constantly in this space, and each one answers a slightly different question.

European Union

GDPR — and the nuance almost everyone gets wrong

Under GDPR Article 9, biometric data is a "special category" requiring stronger legal justification than ordinary personal data — but a photograph isn't automatically biometric data just because it shows a face. Per Article 4(14), it only qualifies when it's been through "specific technical processing" for the purpose of uniquely identifying or authenticating a person. A headshot sitting in an employee directory is not that. The UK's data protection regulator has stated this directly: the same photo can cross from ordinary personal data into special-category biometric data depending on what technical process is applied to it, not on the image itself.

Illinois, United States

BIPA — the law that actually has teeth

The Illinois Biometric Information Privacy Act (in force since 2008) requires written notice and consent before collecting a "biometric identifier" — including a scan of face geometry — from an Illinois resident, and requires that data be destroyed once its purpose is fulfilled or within three years. What makes BIPA unusual is that it gives individuals a private right to sue directly, rather than requiring a regulator to act. That's produced some of the largest privacy settlements on record: Meta/Facebook paid $650 million over facial-tagging features, Clearview AI settled for $51.75 million in equity, and Google/YouTube settled for $6 million. More than 107 new BIPA lawsuits were filed in Illinois in 2025 alone.

Elsewhere in the US

A patchwork that's actively expanding

Texas (CUBI) and Washington (HB 1493) both have their own biometric privacy statutes, though neither currently gives individuals the same direct right to sue as Illinois — enforcement runs through the state Attorney General instead. California's CCPA/CPRA gives residents broad rights to know what personal data a company holds, request deletion, and opt out of certain sharing. The practical result: companies serving a national US customer base tend to build their consent and deletion processes to satisfy Illinois' stricter standard by default, since doing so tends to clear the bar in every other state.

Put all three frameworks side by side and a pattern emerges: none of them treat "having a photo of a face" as automatically regulated. All three care about what happens to that photo next — whether it's processed to extract identifying characteristics, how long it's kept, and whether the person was told and asked first. That's a useful mental model: the question was never "is a selfie dangerous," it's "what does this specific platform do with it after upload."

04. Does generating an AI headshot count as "biometric processing"?

This is the honest, unresolved question sitting underneath this entire topic — and anyone who gives you a confident one-word answer is oversimplifying.

Why this isn't settled

To generate a headshot that looks like you specifically, an AI headshot platform has to derive some representation of your distinguishing facial characteristics from your uploaded photos — that's arguably the "specific technical processing" GDPR's biometric definition describes, and arguably the kind of "face geometry" scan BIPA regulates. Whether a court would actually classify a temporary, per-session model built to generate a portrait the same way it would classify a facial-recognition matching system is a real, open legal question. Companies in this category have generally structured their policies — short retention, no shared-model training, explicit no-biometric-profiling language — as if the stricter interpretation might apply, which is a cautious posture rather than an admission that it definitely does.

We're not a law firm, and nothing here is legal advice. If this question matters to a specific decision you're making — especially for a business deploying this at scale — it's worth a conversation with an actual privacy attorney.

What's not gray, though, is the practical takeaway. Regardless of how a court would eventually classify the technical process, every provider worth using already behaves as though the stricter standard might apply: short retention windows, explicit no-training language, deletion controls. That convergence didn't happen by accident. The legal risk of getting this wrong, especially in Illinois, is high enough that "behave cautiously regardless of the exact legal classification" became the sensible default for the whole category.

05. What to check before you upload

Most privacy policies are long and nobody reads one end to end before uploading a photo. The table below is built for skimming: five specific things worth searching for with your browser's find function.

Check for… Why it matters
A specific retention window (not "as needed") 7–90 days is typical; vague language is a yellow flag
Explicit language about shared-model training Look for "we do not train our models on your photos," not just "we protect your data"
A stated deletion or account-removal option You should be able to trigger deletion yourself, not just wait it out
Encryption in transit and at rest Standard practice; its absence from a policy is worth noticing
Disclosure of third-party processors Know if your photo passes through another company's infrastructure

Your part of the process

  • Read the retention and training sections of the privacy policy before uploading, not after
  • Use recent, varied selfies rather than photos that reveal more than necessary (location metadata, other people, sensitive settings)
  • Download your results as soon as they're ready rather than leaving them on the platform indefinitely
  • Manually delete your uploads and account if the platform offers that control and you don't plan to return
  • If you're an Illinois resident, confirm the provider's consent flow actually satisfies BIPA's written-notice requirement
  • For business or team use, loop in whoever handles data privacy before uploading anyone else's photos on their behalf

Do AI headshot generators use my photos to train their AI models?

Most reputable providers state they do not use your photos to train their shared, general-purpose models. Nearly all of them do create a temporary, per-user model or representation of your face to generate your specific headshots — that's a different, narrower kind of processing. The important question is whether it's deleted afterward.

How long do AI headshot companies keep my photos?

Published policies among providers we reviewed range from 7 to 30 days for source selfies, with several offering on-demand deletion. There's no single industry standard, so the only reliable answer is whatever a specific vendor's own privacy policy states at the time you upload.

Is my face considered biometric data under the law?

Not automatically. Under GDPR, a photograph only becomes regulated biometric data when it's processed through specific technical means to uniquely identify or authenticate a person. A photo sitting in a directory isn't biometric processing, but extracting a facial geometry template to personalize an AI model plausibly is. This is a genuinely unsettled legal question, not a simple yes or no.

Can I sue an AI headshot company for mishandling my photo?

It depends heavily on where you live. Illinois' BIPA is unusual in giving individuals a private right of action, which is why it has produced large settlements like Clearview AI's $51.75 million and Facebook's $650 million. Most other US states don't currently give individuals that same direct right to sue over biometric mishandling.

What's the safest way to use an AI headshot generator?

Read the privacy policy specifically for retention window and training language before uploading, use a provider that states photos are deleted after a defined period, download your results promptly, and manually delete your photos afterward if the platform gives you that option.

What does Headshot Plus do with my photos?

Per our current privacy policy: uploaded photos are used exclusively to generate your headshots, are not used to train any AI model, and are retained for 90 days after your session completes before automatic deletion — you can request earlier deletion at any time. Generation runs through Fal.ai, a third-party AI inference provider that processes images transiently and doesn't train on them. Data is encrypted in transit (TLS) and at rest, and the service is for users 18 and over. Our 90-day window is longer than some competitors' — it trades a slightly longer retention period for keeping your results accessible in your dashboard. If you'd rather not wait, deletion is available on request via our privacy policy page.

Does Headshot Plus have a stated refund policy?

Yes — see our refund policy for the current terms. We'd rather point you to the primary source than paraphrase it here: policy pages get updated, and a blog post summarizing one is only ever a snapshot.

Share this article

Ready to level up your LinkedIn photo?

Get studio-quality AI headshots from a single selfie in under 30 minutes. No photographer, no studio, no scheduling.