News · New this week

Chatbot photo uploads: where your image goes and how safe it is

A photo you upload passes through a gateway, storage, a vision encoder and chat logs. Here is each step and what you can control.

"What happens to a photo you upload to a chatbot?" is a fair interview question, and a good system design exercise. The answer is a pipeline, and each stage has its own privacy angle.

This is a typical setup. Exact behavior varies by app.

Start with the phone

Your photo often carries hidden EXIF data. That can include the camera, the time and often GPS, so your exact location can travel with the image.

Some apps strip it. Don't count on it.

Upload, gateway and storage

The photo goes up over TLS. That protects it in transit, but the company still sees it. TLS keeps other people off the wire, and it doesn't hide anything from the service you're sending it to.

Next is the API gateway. It takes the TLS connection and checks your login.

After that the image lands in an object store, which keeps it for a set window. Think of a photocopy shop. You handed over the original, and the shop keeps a copy.

How long depends on the app. Temporary chats are usually deleted within 72 hours to 30 days.

From pixels to an answer

A vision encoder cuts the image into patches. Each patch becomes a token. These are the patch tokens the model actually works with.

The model then reads those image tokens together with your text question, and answers. That's the part most people picture when they think of "the AI looking at my photo". It's the middle of the pipeline, not the end.

Logs, review and training

After the answer, the chat gets logged. Logs can be used for abuse review, and they may also be used to train future models.

You do have some control here. Most big chatbots have a training opt-out in settings, plus temporary chats.

What to do with this

Three habits cover most of it. Strip GPS from the photo before you upload, opt out of training in settings, and use temporary chats.

Then there's what you shouldn't upload at all. Keep Aadhaar, PAN and bank screenshots out of chatbots. Don't upload other people's faces without their consent.

Next time you upload something, check the settings page first and turn off training. Then, if the photo was taken on your phone, strip the location before it leaves. If you're prepping for system design interviews, practice walking through the stages in order: phone, gateway, object store, vision encoder, model, logs.

  • #systemdesign
  • #dataprivacy
  • #multimodalai
  • #cybersecurity

More reels

All news →