Are Your AI Image Prompts Private? Training, Storage and Data Risks

A designer uploads an unreleased client logo to generate a quick mock-up. The prompt contains the secret campaign tagline, the product launch date, and an internal project code name.
Two minutes later, the visual is ready. But where did those words and source files actually go? Did the prompt get logged into a 30-day abuse database? Did the client's asset feed the next generation of a foundation model? Or did the generation immediately publish to a searchable public gallery where anyone can find it?
Here's the truth: when teams ask "are AI image prompts private," they usually collapse three entirely different questions into one bucket. A platform can honestly promise that it never trains on your data while still keeping readable text logs of every word you type. Another tool might delete your prompt after 24 hours while publishing your visual to a community feed by default.
To make an informed decision for your team or agency, you need to separate the marketing promises from the operative contracts. We break down the privacy policies across eight major providers into a clear framework:
- The three diagnostic questions that actually determine AI privacy.
- Provider-by-provider comparison checklist (Google, OpenAI, Recraft, Midjourney, Adobe, and more).
- The free-tier trap: why your billing plan dictates data handling.
- Biometric thresholds: when uploading a reference photo changes the legal stakes.
- Real-world leaks: what the GenNomis breach taught the industry.
- File metadata: why your prompt might travel with your downloaded image.
- Regulatory reality: what current data protection laws do and do not protect.
- A practical two-minute audit you can run before uploading sensitive assets.
The three questions that actually determine AI image generator privacy
Before opening any vendor's privacy policy, you must discard the idea that a tool is simply "private" or "not private." Trust is not a single setting. It is the intersection of three mechanical boundaries.

Three distinct questions: training, retention, and visibility.
Question 1: Does the provider retrain foundation models on your inputs?
This is what most creators worry about: will your custom prompt or reference image become part of the weights that generate someone else's visual tomorrow?
Foundation model retraining means the vendor takes your uploaded assets, pairs them with your text prompts, and runs them through backpropagation to update the model. If a provider trains on your data, your confidential visual style or proprietary product features can theoretically be extracted by other users through targeted prompting.
Question 2: Does the provider retain logs, even without training?
Training and retention are completely different promises. A vendor can swear off model training while still keeping a plain-text record of your prompts and rendered images on an unencrypted server for abuse monitoring, compliance checks, or manual quality inspection.
If a service keeps 30 days of prompt logs for "security monitoring," those prompts exist in a database. If that database is compromised, your prompts are compromised, regardless of whether a machine learning algorithm ever parsed them for weights.
Question 3: Who can see your generation right now?
This is a product architecture choice, not a machine learning policy. Several consumer AI tools operate as social platforms first and creative tools second. When you hit generate, your output and the prompt that created it immediately drop into a public community feed, searchable by anyone on the internet, unless you pay extra to hide it.
A model that does not train on your inputs can still log your prompt for a month and display your image on its front page. That is why evaluating AI image generator privacy requires auditing all three vectors simultaneously.
The privacy checklist: provider by provider
To see how the industry handles these three questions as of September 2026, we audited the active Terms of Service and Privacy Policies across the leading generative platforms and underlying API providers.
Provider / Tool | Trains on Free/Consumer? | Trains on Paid/API Tier? | Default Safety Retention | Zero Data Retention (ZDR) Available? | Public by Default? | Verified Date |
|---|---|---|---|---|---|---|
OpenAI (API) | Yes (ChatGPT Free/Plus default) | No (API excluded since Mar 2023) | Up to 30 days | Yes (Enterprise approval required) | No | Sep 2026 |
Google (Gemini API / Vertex) | Yes (AI Studio / Free tier) | No (Paid API & Vertex excluded) | Brief abuse logging | Yes (Eligible Cloud projects) | No | Sep 2026 |
Recraft | Yes (Free web tier) | No (Paid & API traffic excluded) | Deleted in 24h (API) | No formal ZDR tier needed | Yes (Free) / No (Paid) | Sep 2026 |
Midjourney | Yes (All tiers implicitly covered) | Yes (No training opt-out) | Indefinite account history | No | Yes (Stealth mode extra cost) | Sep 2026 |
Adobe Firefly | No (Trained on Stock/public domain) | No (Enterprise content isolated) | Transient processing logs | Standard enterprise controls | No | Sep 2026 |
Leonardo AI | Yes (Free tier) | No (Paid 'Private Content') | Standard account logs | No | Yes (Free) / No (Paid) | Sep 2026 |
Canva (Magic Studio) | Disputed toggle default | No (Teams & Enterprise excluded) | Account lifecycle | Enterprise governance | No | Sep 2026 |
Ideogram | Yes (Web consumer tiers) | No (API excluded by contract) | Account lifecycle | No | Yes (Free tier) | Sep 2026 |
Krea AI | Ambiguous standard terms | No (Enterprise tier contract) | Standard server logs | Enterprise only | Yes (Free) / No (Paid) | Sep 2026 |
JammyJar | No | No (All generation traffic excluded) | Minimal operational routing | Managed via secure hub | No (Private workspaces) | Sep 2026 |
Google: the AI Studio vs. Vertex AI split
Google offers the clearest example of why account type dictates data handling. Independent developer Simon Willison highlighted the structural split in Google's Gemini API Additional Terms of Service: on the free tier of the Gemini Developer API and Google AI Studio, submitted content and generated responses are used to improve Google products, and human reviewers may read, annotate, and process that text.
Switch to a paid Gemini API billing key or run the model through Vertex AI, and the terms invert. Google contractually commits that your prompts, responses, and uploaded images are never used to train base models. The difference between a human contractor reviewing your client prompt and your prompt staying strictly confidential is simply whether you attached a credit card to the project.
OpenAI: the March 2023 API boundary
OpenAI's platform documentation draws a firm line at its API boundary. Since 1 March 2023, data sent to /v1/images/generations or /v1/images/edits is not used for model training unless a customer explicitly chooses to opt in. However, OpenAI retains logs of your prompts and generated images for up to 30 days to monitor for abuse and policy violations.
Organizations handling strict confidentiality can apply for Zero Data Retention (ZDR) or Modified Abuse Monitoring. But note the non-negotiable exception: automated Child Sexual Abuse Material (CSAM) classifier hits are retained for manual review regardless of any ZDR agreement in place.
Midjourney: public by default and perpetual licenses
Midjourney remains popular for artistic ideation, but its contractual terms make it challenging for sensitive enterprise work. Under Midjourney's Terms of Service (effective 27 May 2026), user content is publicly viewable and remixable by default. Furthermore, users grant Midjourney a perpetual, worldwide, sublicensable, irrevocable copyright license to reproduce and display submitted content, a grant that survives account termination.
While Pro and Mega subscribers get access to "Stealth Mode" to hide generations from the web showcase, Midjourney's terms state plainly that images created in public Discord channels remain visible to everyone in that channel, regardless of Stealth status. In a privacy audit by legal platform terms.law, Midjourney ranked near the bottom of evaluated AI services specifically because of this public-by-default architecture.
Adobe Firefly: commercial clearance vs. content analysis
Adobe built Firefly around enterprise safety, training its generative models exclusively on licensed Adobe Stock and out-of-copyright public domain assets. Many creators confuse Adobe's general "Content Analysis" toggle with Firefly training. Adobe's documentation (updated 4 June 2026) clarifies that while Content Analysis is turned on by default for individual Creative Cloud accounts to improve non-generative machine learning features, it is not used to train generative Firefly models.
How JammyJar handles prompt and asset privacy
When evaluating a multi-model generative hub like JammyJar, the same strict criteria apply. Prompts routed through JammyJar to engines like Google, OpenAI, or Recraft are processed under paid API agreements that contractually prohibit model training on user inputs.
Assets, styles, and prompt histories reside in private, multi-seat workspaces hosted on privacy-conscious infrastructure in Frankfurt, Germany. Visuals are never shared to a community feed unless an authorized team member explicitly clicks "Publish." Review our full data-handling architecture in our published Terms and Privacy Policy.
The free-tier trap: why the plan matters more than the company
If you take one lesson from reading vendor terms of service, let it be this: the name on the homepage matters far less than the subscription tier you are logged into.
Generative AI models are computationally expensive to run. When a service offers free, unlimited image generation, the business model usually extracts value in one of two ways: using your prompts and outputs to train future iterations of the model, or displaying your work publicly to drive viral sign-ups.

The free tier and the paid tier operate on entirely different privacy contracts.
Consider the contrast between tiers across the landscape:
- Leonardo AI: Free-tier generations feed the training pipeline and sit in the public search index. Paid subscribers receive "Private Content" controls that disable public visibility and exclude data from training.
- Ideogram: Standard web generation feeds the models that power the service. API traffic, by contrast, is contractually protected from training use under its Developer Terms.
- Recraft: Free-plan images remain public community assets. Paid subscription plans turn generations private, while all API traffic is excluded from model training and purged from processing servers within 24 hours.
If an agency designer uses a personal free account to prototype concepts using unreleased client packaging, they have likely bypassed the company's non-disclosure agreements. If you are comparing platforms, check our breakdown of the best free AI image generators and their catches to see how visibility models differ.
When a photo becomes a bigger deal than a prompt
Typing a descriptive text prompt carries standard commercial confidentiality risks. Uploading reference photographs of real human beings introduces an entirely different regulatory dimension.
Under the European Union General Data Protection Regulation (GDPR), an ordinary photograph of a person is considered standard personal data. Recital 51 clarifies that photographs are not systematically treated as sensitive special-category data simply because they depict an individual.
However, the classification changes under Article 9 the moment that image is processed through specific technical means to extract unique physical or behavioral characteristics: biometric data used for unique identification.
When you upload an employee headshot or a model reference photo to an AI engine to extract facial consistency or generate character poses, does that feature extract facial geometric embeddings? If the processing pipeline maps facial landmarks to maintain identity across shots, data protection authorities may treat that operation as biometric processing.
For enterprise teams, the rule of thumb is straightforward: uploading a synthetic product rendering, a landscape, or an abstract vector sketch for style transfer carries basic contract risk. Uploading real human faces requires verifying whether your AI vendor processes biometric identifiers and whether you hold explicit consent from the subject.
What happens when it goes wrong: the GenNomis breach
Many practitioners treat prompt storage risks as theoretical legal edge cases. They assume that even if a vendor stores prompt logs, those logs will remain locked behind enterprise security perimeters.
In March 2025, independent cybersecurity researcher Jeremiah Fowler uncovered an unprotected, unencrypted database owned by South Korean AI image firm GenNomis (operated by AI-NOMIS). The exposed database contained between 93,485 and 95,000 generated image files paired with raw JSON logs of the exact text prompts used to create them, totaling roughly 48 GB of data.
Because the database lacked password protection or basic authentication controls, anyone with the storage URL could view the images and read the exact text instructions submitted by users. Both associated websites went offline within hours of Fowler's disclosure to WIRED.
While GenNomis was a smaller, consumer-focused operation, the incident provides empirical proof of how prompt leakage functions in practice. When an AI image platform logs requests, it creates a relational map linking user identifiers, proprietary prompt text, and rendered outputs. If that storage layer is misconfigured, your prompts do not disappear into the ether; they sit exposed in plain text.
The metadata you are not thinking about
Assume you selected a zero-retention API, disabled model training, and kept your generations inside a private workspace. You download the final PNG and send it to an external client via Slack or upload it to a public drive.
Is your prompt still private?
It might not be. Under the EU AI Act's Article 50 transparency obligations, which took effect on 2 August 2026, generative AI providers must ensure that synthetic visual outputs are marked with machine-readable provenance metadata. Many providers comply by embedding Coalition for Content Provenance and Authenticity (C2PA) manifests or structured EXIF/XMP tags directly into the exported file.
These provenance manifests are designed to travel with the image file wherever it is copied. Depending on how the provider configures its export pipeline, that embedded metadata can include:
- The full text prompt used to generate the visual.
- The underlying model version and generation timestamp.
- Seed numbers, sampler settings, and guidance scales.
- Unique software application identifiers.
If you hand an exported AI visual directly to a client or post it online, anyone using a standard open-source metadata inspector or EXIF viewer can read the manifest embedded inside the binary file. What was private on the server became public in the file attachment.

Metadata travels with your export unless you deliberately strip it.
Before publishing proprietary client work, inspect your exported files with a metadata utility. If your pipeline embeds sensitive prompt text into C2PA or XMP manifests, pass the exported assets through a metadata-stripping build step to clean the header blocks.
Does the law protect you? What is settled and what isn't
Legal protections around AI prompts and training data remain deeply unsettled across global jurisdictions. Do not assume that data protection regulations provide automatic air cover.
In the European Union, data protection authorities do not agree on foundational definitions. The European Data Protection Board (EDPB) adopted Opinion 28/2024 in December 2024, maintaining that an AI model trained on personal data cannot automatically be treated as anonymous and must be assessed on a case-by-case basis. In contrast, discussion papers from regional authorities, such as Germany's Hamburg data protection commissioner, have explored arguments that trained model weights do not "store" personal data in a manner that triggers standard individual data-subject deletion rights.
Regulatory enforcement has also shown volatility. In November 2024, Italy's Garante fined OpenAI €15 million over GDPR training data legal bases. In March 2026, the Court of Rome annulled that fine.
Meanwhile, technical memorization research complicates the legal picture. A peer-reviewed study by Carlini et al. (published at USENIX Security by researchers from Google, DeepMind, ETH Zürich, Princeton, and UC Berkeley) demonstrated that diffusion models can memorize specific training images. Under targeted black-box querying, researchers successfully extracted over 1,000 near-identical training images from production diffusion models, including identifiable portraits of individuals and company logos.
This research proves that "models do not store images" is an oversimplification. Machine learning models can replicate training artifacts under specific prompt conditions, which is why strict contractual no-training clauses remain your primary defense.
A two-minute privacy test you can run on any tool
Before your team writes its next campaign prompt or uploads an internal reference asset, run this two-minute operational audit on your generative workflow:
- Check the account tier: Are you using a consumer free account or a paid enterprise workspace? If you are on an unpaid tier, assume your prompts feed future model training.
- Verify the training clause: Open the provider's developer terms or privacy settings. Look for an explicit contractual commitment stating that API inputs and outputs are excluded from model training.
- Audit the default visibility: Generate a test asset with a generic prompt. Does the image immediately appear in an explore feed or community gallery? If yes, ensure your team has Stealth or Private Workspace toggles locked.
- Confirm the retention window: Determine whether the vendor logs prompts for 24 hours, 30 days, or indefinitely. For sensitive NDA deliverables, apply for Zero Data Retention programs.
- Inspect the downloaded file: Download an image and run it through an EXIF/C2PA reader. If your prompt text is stamped into the file header, strip the metadata before sharing the asset externally.
Privacy in generative AI is not a brand attribute. It is an engineering and contractual reality. Know which models you are routing to, lock down your team workspaces, and never rely on marketing copy when a formal Terms of Service is only a click away.
Frequently asked questions
Are AI prompts private by default?
No. Most free and consumer-tier AI image generators use submitted prompts and uploaded images to train their models or display outputs in public community galleries. Paid business plans and direct developer API endpoints are typically required to contractually exclude your prompts from model training and ensure private generation.
Does OpenAI train its image models on API prompts?
No. Since 1 March 2023, OpenAI's API terms state that data submitted to its endpoints (including /v1/images/generations) is not used to train models unless a customer explicitly opts in. However, OpenAI retains logs for up to 30 days for abuse monitoring unless an organization is approved for Zero Data Retention.
Does Google train Gemini on my image prompts?
It depends on the tier. If you use Google AI Studio or unpaid Gemini API tiers, Google uses inputs and outputs to improve products, and human reviewers may inspect them. If you use paid Gemini API keys or Vertex AI, Google contractually commits not to use your prompts or generated images for model training.
Can people see what I generate in Midjourney?
Yes, by default. Midjourney is built around an open community gallery, and user generations are public and remixable. Even with the paid Stealth Mode add-on, any images generated inside shared Discord servers remain visible to other members of that channel.
Can my prompt be extracted from an exported AI image?
Yes. Many AI image tools embed C2PA Content Credentials, EXIF, or XMP metadata directly into downloaded image files to comply with provenance regulations. These tags often include the full generation prompt, seed values, and model versions, which anyone can inspect using standard metadata tools unless stripped before distribution.