Uploaded your photos for 1980s AI photo trend? Here's what happens to images sent to ChatGPT, Gemini
As millions join the viral 1980s AI photo trend by uploading selfies to ChatGPT and Gemini, a cybersecurity expert cited by Wired explains what actually happens to those photos after they are sent, how long companies store them, and why deleting a...

Uploaded your photos for 1980s AI photo trend? Here's what happens to images sent to ChatGPT, Gemini
Wired spoke to Christina Pöpper, a cybersecurity expert at NYU Abu Dhabi, who breaks down what happens to user data once it enters an AI chatbot. She explains there are four types of data involved, what a person types in, what the system figures out from that input, metadata tied to the session, and any responses or files that get saved along the way.
Why a selfie counts as sensitive data
A photo of someone's face is treated as personal data because it can identify that person. Beyond that, the image file itself can carry hidden details such as when it was taken, the device it came from and its location. Uploading a selfie for a trend does not mean it will be misused, but it does place another copy of that photo inside a company's systems, governed by that company's own rules on storage and training.
Pöpper also points out that repeated use of these tools can build a pattern over time. Even without a name attached, the topics someone asks about can reveal their habits, interests or even their profession.
How long ChatGPT, Gemini and Claude keep your data
Wired's report lays out how the major AI chatbots differ on retention. ChatGPT saves chats to a user's account until they are deleted, and even after deletion, the data can remain on OpenAI's systems for up to 30 more days. Some information can be kept longer once it has been de-identified and separated from a specific account, or if it is needed for legal or security reasons.
Gemini keeps chat data for 18 months by default unless a user deletes it sooner. Because Gemini connects with other Google services such as Drive and Photos, it can also draw on a wider pool of personal information during a conversation.
Claude follows a similar pattern to ChatGPT. Anthropic says deleted chats are removed from its back-end systems within 30 days. However, if a user allows their chats to be used for training, de-identified versions may be kept for up to five years. Chats flagged for possible policy violations can be stored for two years, and related safety scores may be kept for as long as seven years.
As Pöpper notes in the report, deleting a chat inside the app does not always mean it disappears from a company's servers right away.
The bigger privacy picture
Wired's report also touches on newer risks as AI systems grow more capable. Pöpper mentions model inversion, a method where someone tries to extract sensitive information from a trained model rather than directly accessing another user's chat. Whether this works depends on the model, the attacker's access and the data available to them.
The report also references a separate incident where Anthropic said a suspected state-backed group had misused its Claude Code tool as part of a cyber-espionage campaign, though this did not involve any exposure of user conversations.
For anyone taking part in trends like this one, Pöpper's advice is straightforward. Avoid sharing sensitive information, spread activity across different platforms, turn off model training where the option exists, use temporary or incognito modes, and delete old chats and files that are no longer needed. She also recommends being cautious about uploading photos of other people without their consent, particularly images involving children or identity documents.
The retro portrait might vanish from a feed within days. The photo that made it possible may not
The Economic Times Business News App for the Latest News in Business, Sensex, Stock Market Updates & More.
The Economic Times News App for Quarterly Results, Latest News in ITR, Business, Share Market, Live Sensex News & More.