Read an AI service's privacy policy to answer specific questions about your information, not simply to find the word “secure”. A useful reading starts with who receives your data, what they do with it and how to contact them about that use.
The document is evidence of what the organisation says. It is not, on its own, an independent inspection of the organisation's systems. Keep that distinction in mind when a review repeats a provider's privacy promises.
Confirm that the notice applies to your product
Look for the operator's name, the covered service and the notice's effective date. A company may offer several products with different account arrangements. A policy for one product or business tier should not automatically be applied to another.
Check the domain as well. An information website can link to a separate application without sharing its operator. The guide to xNude AI and third-party apps explains why the destination service's documents matter when you register or upload a file.
Read by question rather than by reassuring phrase
Find the sections describing collected information, processing purposes, recipients and retention. The ICO's right-to-be-informed guidance identifies these as important elements of privacy information under the UK GDPR. This offers a useful reading framework while legal requirements elsewhere may differ.
For an image service, distinguish submitted files from account details, written instructions and usage records. A statement about one category may not cover the others. If the policy says that information is retained “as necessary”, look for an explanation of the criteria rather than inventing a specific number of days.
Examine broad terms closely
Phrases such as “improve services” or “trusted partners” need context. Ask what activities are included and what role another organisation performs. Hosting a file, processing a payment and developing a model are different functions.
Also distinguish access controls from limits on purpose. A promise not to display uploads publicly does not automatically answer who can review them internally. A statement about encryption does not tell you the retention period. For one particularly important purpose, see whether uploads are used for model training.
Look for usable controls and contact routes
Find any explanation of access requests, deletion, objections or relevant preferences. Check whether the notice identifies a contact route and explains what information is needed to locate your account. Do not assume that a general support form handles every privacy request in the same way.
If a setting is described, compare that description with the explanation shown in your account. A discrepancy deserves clarification. Save the applicable wording and date so that your enquiry is concrete rather than based on a remembered phrase.
Write down what remains unknown
Imagine a hypothetical notice that identifies the operator and processing purpose but does not clearly explain image retention. An accurate note would say that the retention criteria were not clear in the document examined. It would not say that the provider definitely keeps images forever.
Ask a focused question before submitting sensitive material. If you are considering leaving, upload deletion and account deletion need separate attention. For an unresolved rights issue, consult the regulator or adviser relevant to your location.
You do not need to complete a technical audit to make a cautious decision. If the information necessary for your particular use is missing, choosing not to upload is a reasonable response.
Related reading
What Happens to Photos Uploaded to an AI Service?



