Before putting your child's photo into an AI app

An app wants to turn your child into a cartoon astronaut. You can already see the sort of thing it makes. It's cute. It would take about thirty seconds. The upload button is right there.
The part I want to slow down is the original photo.
Because the cartoon is what you get back. What you give the service may be a clear, identifiable picture of your child. And the decision about where that picture goes happens before you've even seen whether the result is any good.
I don't think that means we need to treat every AI app as the same company with the same practices. It means we need to look at the particular feature we're about to use. “AI” doesn't tell us whether a photo stays on the device, gets sent to the company's computers, or is kept afterwards.
A no-training promise is only part of the answer
Training means using examples to develop or improve an AI system. Using your photo to make the image you asked for is another job. Keeping the file, allowing someone to review it and sending it to another provider are separate decisions again.
So a company can say it doesn't train on your photos without that sentence telling you how long it keeps them. The finished cartoon can be private while the original photo is still sent to another company to make it. These are possibilities to check in the terms for the feature, not assumptions to make about every app.
The privacy page may describe different rules for different accounts, regions or settings. Read the part that covers the actual upload you're considering. I know that's a lot of reading for a cartoon astronaut. Which is partly the point: the size of the joke and the size of the decision aren't necessarily the same.
| Before uploading, ask | What you're looking for |
|---|---|
| Where does the original go? | Does it stay on your device, or go to this company or another service? |
| Is my photo used for training? | Which setting controls it and when a change takes effect. |
| How long is it kept? | A stated length of time, and any reasons they may keep it longer. |
| Who can see it? | Whether staff, people checking the results or other companies can receive the file. |
| Will anything become public? | Automatic galleries, share links or public profiles. |
| What does deleting it do? | What disappears from your account and what may remain elsewhere. |
If you can't get a plain answer, you don't have to complete the upload while you investigate.
Why I'm concerned about the original
Children's ordinary photographs have already turned up in datasets, the collections of examples used to build AI systems. In June 2024, Human Rights Watch reported finding links to identifiable Brazilian children's photos in a dataset called LAION-5B, sometimes with information that made it possible to identify or locate them.
That is a documented example of reuse. It doesn't establish that every private photo is used by every AI company. Human Rights Watch's original investigation
And training is only one possible use of an image. Australia's eSafety Commissioner, in its July 2026 advisory on school imagery, described reports of altered images and urged schools to consider why they were sharing an image, whether they had permission, who would see it and what it revealed about the people in it. An image can be misused without somebody training a new model on it first. eSafety's school imagery advisory
For me, that leads to a fairly practical decision. Give identifiable originals to fewer services, and don't make them public unless there's a reason to. We can't predict every future use of a file. We can be more selective about who receives it now.
Does the effect need your child's real face?
If you want a drawing of a child on the moon, try describing one. If you're explaining a movement, an illustration or a photo taken from behind may do the job. You haven't lost much by keeping the actual face out of that exchange.
Some effects do need a recognisable face to work. Then you can decide whether the result is worth giving that provider this particular picture. There isn't an obligation to try every feature just because it's there.
The underlying idea has a dry name, data minimisation: provide only what the job needs. The UK Information Commissioner's guidance asks services used by children to limit collection to what's necessary and consider how long to keep it. As parents, we can ask the same question before choosing a photo. ICO guidance on data minimisation
A crop might remove a school badge or another child. A cover can remove a face if the task doesn't need it. Check what remains, though. The privacy beyond face blur guide looks at names, locations and other clues that a face edit doesn't address.
If you've already uploaded the photo
Start with the service that received it. Write down the app or website, the account you used and roughly when you uploaded it. Keep track of the original photo and the result it made; a cartoon disappearing from your profile doesn't tell you what happened to the original.
First, check whether you published the result or created a share link. Remove the public copy you control if you no longer want it there. Then use the service's deletion controls and read what they say will be deleted. If that leaves the original's fate unclear, ask:
I uploaded a photo on [date] using [feature]. I'd like to delete both the uploaded original and the generated result. Does the deletion control remove both? What remains in backups or with other providers, for how long, and can you confirm when the request is complete?
Use the provider's official support or privacy contact. You don't need to attach your child's photo again just to ask what its deletion policy covers. Save the reply with the request, including anything it leaves unanswered.
That gives you three things you can track: public copies removed, deletion requested, and the answer about what remains. None, on its own, proves that earlier use has been undone. If a relative made the upload, ask them to do this from the account they used; your own app settings won't reach their copy.
Include photo effects in the family agreement
“Please don't post the kids” may make perfect sense to a relative who then uploads a private photo to make a birthday animation. In their mind, they haven't posted it anywhere. They've made you something nice.
Be explicit about the extra step you're asking them to check:
Please ask us before uploading the kids' photos to AI apps or photo effects, including pictures we send privately. We want to choose which services receive their faces.
The family photo-sharing scripts can help you introduce this without making it an accusation. As children become able to understand an edit, bring them into the decision too. If they don't like the idea, that deserves attention before anyone presses upload.
Decide before the file leaves
The guide to AI “unblurring” explains why a realistic generated face may be imaginary, while weak blur can still leave details that help identify someone. Both are reasons to think about the photo you're giving the app.
Before the next effect, find out who gets the original and how long it stays there. Then decide whether they need that picture at all. It's much easier to choose another image before uploading than to investigate where the first one went afterwards.
Sources reviewed 5 September 2026. Source links appear alongside the relevant advice.