Md. Himel Hasnat Rafi

Fellow, Dismislab
What to keep in mind before making an AI retro photo

What to keep in mind before making an AI retro photo

Md. Himel Hasnat Rafi

Fellow, Dismislab

Open Facebook or Instagram these days, and a familiar kind of image keeps turning up in the newsfeed: a young man in jeans and a denim jacket standing beside a motorcycle, a young woman in a sari smiling beside him; or elsewhere, a young man in a tie and suit walking beneath a row of trees with his girlfriend. They look as though they were pulled straight out of an old photo album from the 1980s, but in reality these images are being generated using artificial intelligence (AI). Upload a single ordinary photo or selfie, and within about a minute you get this nostalgic look. Also, in Bangladesh, this trend has now gone thoroughly viral.

But behind these fun images, one question is almost entirely left out of the conversation. What actually happens to a photo after it is uploaded? Where is it stored, who keeps it, and for how long? Dismislab went through the findings of multiple cybersecurity organizations around the world in an attempt to answer these questions.

A selfie carries more than just a face

A photo itself carries a great deal. The human face in a photo is itself a form of personal data, since it can be used to identify a person. Hidden alongside it can be metadata called EXIF, which reveals when the photo was taken, on which device, and exactly where it was taken, even the GPS location.

In a report by the international technology magazine Wired, Christina Pöpper, a cybersecurity expert at New York University Abu Dhabi in the UAE, explains that four main types of data accumulate on AI chatbots or apps: what the user themselves types or uploads; what the system infers from that data; session-related metadata; and stored responses or files. Pöpper says,

“Uploading a selfie doesn’t mean it will necessarily be stolen or used to make a deepfake. But it does mean another copy of the photo is going to another company, subject to their own retention and training policies.”

An analysis by the South Africa-based legal organization, the Gawie le Roux Institute of Law, notes that when AI fails to properly recognize a photo on the first upload, users often keep adding extra information- workplace, education, family details- to get a more accurate result. Each piece of information may seem harmless on its own, but combined, it builds a far clearer picture of a person.

Repeated use of an AI tool also allows it to a ascertain patterns in the questions or prompts themselves. Even without knowing someone’s name, what they ask about and how they ask it can reveal their interests, habits, and even their profession. Beyond this, as with ordinary online services, the user’s IP address, device type, operating system, and general location data are also collected.

How long does this data stay on the server

Exactly how long this data is retained depends on which service is being used. Reviewing the policies of three widely used AI chatbots, Wired found considerable differences in the rules even among these three services.

On OpenAI’s ChatGPT, chats remain stored on the account until the user deletes them. Even after deletion, they can remain in the company’s systems for up to 30 days. Beyond that, data that has been “de-identified” or disconnected from the account, or data retained for legal or security reasons, can remain for a longer period.

A report by the technology news outlet How-To Geek adds another layer to this picture: because of the New York Times v. OpenAI lawsuit, data uploaded between April and September 2025 may remain stored even if the chat was deleted or a temporary chat was used.

Google’s Gemini retains chat data by default for up to 18 months unless the user deletes it themselves. Because Gemini can be linked to other services such as Google Drive or Google Photos, it gains access to a much larger volume of personal data at once.

Anthropic’s Claude also stores chats on the account, which are removed from backend systems after 30 days of deletion. However, if a user permits their chats to be used to improve Claude, a de-identified copy can remain in the training pipeline for up to five years. Conversations flagged for suspected policy violations can be retained for up to two years, and related safety scores can be retained for up to seven years.

Pöpper points out that deleting a chat within the app does not always mean it is immediately erased from the company’s servers as well. As AI models become more advanced, the nature of the risks is also changing. She mentions a type of attack called “model inversion,” in which an attacker attempts to infer or reconstruct sensitive information from a machine learning model. This is not a simple process, and its effectiveness depends on the model, the attacker’s level of access, and the availability of data. However, as AI gains access to more of people’s connected services, including email, shopping, and others, the scope of the risk also grows.

Two real incidents

Real-world data leaks have occurred multiple times as well. In February 2026, an investigative report by the cybersecurity research firm Cybernews was published in the US technology outlet PetaPixel. The investigation found that an AI photo-and-video editing app called Video AI Art Generator & Maker, downloaded more than 500,000 times on the Google Play Store, had a Google Cloud storage bucket left open without any authentication. As a result, anyone in the world could have accessed that storage. It contained more than 1.5 million photos and nearly 350,000 videos uploaded by users, alongside roughly 2.87 million AI-generated photos, a similar number of videos, and about 386,000 audio files. In total, there were about 8.27 million media files, amounting to more than 12 terabytes. According to Cybernews researchers, such incidents show that many AI apps, in their rush to launch quickly, skip even basic security measures. Among the several hundred Google Play apps they analyzed, roughly 72 percent had similar security flaws.

Another Cybernews investigation reported by the US news outlet Fox News showed that in August 2025, a server run by an AI-companion app operated by the Hong Kong-based company Imagime Interactive Limited was found open without any protection. As a result, real-time chats between users and their AI companions, links to private photos and videos, and AI-generated images were exposed. Data belonging to nearly 400,000 users across iOS and Android was left exposed.

In both incidents, the root cause was the same: backend storage that was not properly secured. Regardless of what an app’s privacy policy states, the risk of data leaking due to a technical flaw is far from hypothetical.

According to an analysis by ISACA, the international IT governance organization, the risk associated with biometric data such as facial features is more serious than a password leak, because while a password can be changed, facial features cannot. As a result, once facial data is leaked, its impact can be long-lasting.

Familiar photos, unfamiliar risks: What to do

So does this mean AI-generated photos should be avoided altogether? Experts say not necessarily. What matters, instead, is using them with awareness.

A report by the global cybersecurity firm Bitdefender states that the real risk with AI-generated photos lies not in the AI-generated image itself, but in the information contained in the original photo. Faces, background scenes, metadata, the presence of children, or clues pointing to an address: all of this remains in the original photo. Experts therefore advise removing unnecessary personal details from a photo before uploading it, and deleting EXIF metadata where possible. The Wired report also advises against uploading photos of other people without their permission, exercising extra caution with photos of children, and never uploading photos containing ID documents or unnecessary personal information.

Pöpper’s advice is to avoid giving any sensitive information to a chatbot or app, and to spread usage across platforms rather than relying entirely on one, in order to reduce risk. Where possible, it is also important to turn off the option allowing data to be used for model training, use temporary or incognito modes, delete chats or files once they are no longer needed, and periodically review which services are connected to one’s AI assistant.

Extra caution is also needed when uploading photos to apps from unfamiliar or lesser-known developers. A high download count on the Play Store does not necessarily mean an app is safe; the two incidents above prove exactly that. Simply uninstalling an app is not enough either; once you stop using it, you should also try to delete the associated account, because removing the app from your phone does not automatically delete the copy stored on the server.

That 1980s-style portrait of yours may well get lost in the flood of the feed within a few days. But the photo used to create it may remain on some company’s server for a much longer time. So the real question is not whether one should use AI at all; the question is having a clear understanding of exactly what one is giving away while using it.