Does This App Train on Your Photos? The 3 Lines of Every Privacy Policy You Should Actually Read
You don't need a law degree. You need three search terms.

Privacy policies are long on purpose. You only actually need to find three specific things in them.
Key takeaways
- You don't need to read an entire privacy policy end to end — three specific things determine most of what matters for an AI photo app: training language, retention period, and third-party sharing.
- Training language: search for whether the policy says your content is used to "improve," "train," or "develop" the company's models or products, versus only to "provide" or "operate" the service you requested.
- Retention: look for how long uploaded photos and generated outputs are kept, and whether there's a specific deletion process — not just a vague "as long as necessary" statement.
- Third-party sharing: check whether your content can be shared with unrelated third parties for their own purposes, versus only with narrowly scoped "service providers" bound to a specific task.
- An app's privacy policy not mentioning training at all is different from a policy that explicitly states your content isn't used for it — the second is a meaningfully stronger commitment than the first.
- Deleting the app from your phone doesn't delete your data from a company's servers. You typically need an in-app deletion option or a formal data-deletion request, which most current US privacy laws require companies to honor.
Privacy policies are long by design, and most people's actual strategy for dealing with them is not reading them at all. For an AI photo app specifically, that's a worse trade-off than usual, because what's being handled isn't generic account data — it's a photo of your face, and as we covered in our piece on app permissions and biometric privacy, that photo can be used to derive a biometric identifier. The good news: you don't need to read the whole document. You need to find three specific things.
Line 1: What happens to your content, in the company's own words
Search for: "train," "improve," "develop"This is the single most important distinction, and it's the one we walked through in detail in our earlier piece on how AI face swap actually works: using your photo to generate one output for you is a fundamentally different thing from using it to train or improve the underlying model. A policy that limits itself to language like "process your content to provide the requested output" is describing the first, narrower use. A policy that includes phrases like "to improve our services," "to train our models," or "to develop new features" is reserving the right to do the second — and once a photo has been used to train a model, there's generally no way to meaningfully undo that afterward.
Some companies split the difference by making training use opt-in or opt-out, often buried in account settings rather than the policy text itself — worth checking for a toggle labeled something like "help improve our AI" or "contribute to model training" in the app's actual settings menu, not just the policy document.
Line 2: How long they keep it, and whether you can make them stop
Search for: "retain," "retention," "delete"A policy that says content is retained "for as long as necessary to provide the service" is telling you almost nothing concrete — "necessary" is defined entirely by the company. Look instead for a specific retention period (a stated number of days after your last use, for example), and specifically for a described deletion process: can you delete your uploaded photos and generated outputs from within the app itself, and does the policy commit to actually removing them from their servers, not just hiding them from your account view.
It's worth knowing that deleting the app from your phone does nothing to data already on a company's servers — those are two entirely separate actions. Most comprehensive US state privacy laws that have passed since California's CCPA now require companies to honor a specific data-deletion request from a user, so a legitimate app should have some documented way to actually submit one, not just a general promise.
Line 3: Who else gets to see it
Search for: "third parties," "service providers," "share"
Almost every privacy policy allows some sharing — the meaningful distinction is who with and under what constraint. "Service providers" or "processors" are typically vendors performing one specific task on the company's behalf (cloud storage, payment processing, customer support), generally bound by contract to use the data only for that task and not repurpose it. "Third parties" used more broadly — especially combined with phrases like "for their own marketing purposes" or "affiliated companies" — describes a much looser arrangement, where your content or data about you can end up used for things entirely unrelated to why you uploaded it.
The specific phrase to watch for is any mention of sharing with "AI partners," "model providers," or unspecified "third-party processors" for anything beyond narrowly defined technical operation of the service — that's the sharing category most likely to functionally overlap with the training question from Line 1, even if it's not phrased as training.
| What you're checking | Weaker language (worth questioning) | Stronger language (worth trusting more) |
|---|---|---|
| Training use | "To improve our services and products" | "Your content is not used to train our models" |
| Retention | "As long as necessary to provide the service" | A specific time period plus a described deletion process |
| Sharing | "With third parties, including for marketing" | "Only with service providers under contract, for the specific purpose of operating the app" |
The strongest privacy commitment isn't a policy that avoids the subject of training. It's one that brings it up specifically, just to rule it out.
What this looks like in practice
Reading for these three lines takes a few minutes with a simple browser search (Ctrl+F or Cmd+F) for "train," "retain," and "third part" rather than reading the whole document top to bottom. It's a habit worth applying to any app that touches your face, not just ours — Movcl's own privacy policy is written specifically to address all three of these points directly, precisely because "trust us" isn't something a policy document should ask for without being checkable.
A quick glossary
- Service provider / processor
- A vendor that handles data on a company's behalf for a specific, contracted task, generally not permitted to use it for the vendor's own separate purposes.
- Data retention period
- The specific length of time a company keeps your data before it's deleted or anonymized, ideally stated as a concrete duration rather than an open-ended phrase.
- Right to delete
- A right, established under several current US state privacy laws, allowing a person to request that a company delete their personal data, subject to certain exceptions.
Frequently asked questions
What's the fastest way to check if an app trains on my photos?
Open the privacy policy and search (Ctrl+F or Cmd+F) for the word "train." If it's not mentioned at all, look for broader phrases like "improve our services" or "develop new features," since some policies describe training without using the word directly.
If a privacy policy doesn't mention training at all, does that mean it doesn't happen?
Not necessarily. An absence of the topic is different from an explicit statement that your content isn't used for training. A policy that specifically addresses and rules out training use is a stronger signal than one that simply doesn't bring it up.
Does deleting the app delete my photos from their servers?
Not automatically. Deleting an app only removes it from your device; it doesn't trigger deletion of data already uploaded to a company's servers. You typically need to use an in-app deletion feature or submit a specific data-deletion request, which most US privacy laws now require companies to honor.
What does it mean if a policy allows sharing with "service providers"?
Service providers are usually vendors performing a specific task on the company's behalf, like cloud hosting, bound by contract to use the data only for that purpose. This is generally a narrower and lower-risk category than sharing with unrelated "third parties" for their own separate purposes, though the exact obligations depend on the specific contract language, which you as a user can't see.