The 1980s-style AI photo trend has quickly become a familiar sight across social media. Users upload selfies to AI chatbots, add a prompt and receive a retro-looking portrait in seconds. What appears to be a simple image transformation, however, also involves sending a personal photograph into an AI company’s systems.
A Wired report examining the privacy implications of AI chatbots spoke with Christina Pöpper, a cybersecurity expert at NYU Abu Dhabi, about what happens to information after it is submitted to these platforms. Her explanation highlights that an AI interaction involves more than the text a user enters or the image generated in response.
Why an AI-edited selfie is still personal data
A photograph showing someone’s face can be considered personal data because it may be used to identify that person. The image file can also contain additional information, including details connected to when and where it was captured and the device used to take it.
That does not mean uploading a selfie automatically results in misuse. The important point is that the image becomes another piece of data processed under the privacy, storage and training policies of the service being used.
Pöpper identifies four broad categories of information that can be involved in an AI chatbot interaction. These include what a person provides as input, what the system derives from that information, metadata associated with the session, and responses or files that may be stored.
The privacy concern can become broader when someone uses AI services repeatedly. Individual conversations may seem harmless, but a collection of questions and interactions can potentially reveal patterns about a person’s interests, habits or professional life, even when their name is not directly included.
ChatGPT, Gemini and Claude have different retention rules
The report also highlights differences in how major AI chatbots handle stored conversations.
ChatGPT keeps chats in a user’s account until they are deleted. Following deletion, the information can remain on OpenAI’s systems for up to 30 additional days. Certain data may be retained for longer when it has been de-identified or when it is required for legal, security or other specified purposes.
Google’s Gemini has a default chat retention period of 18 months, unless the user deletes the information earlier. The service’s connection with other Google products, including Drive and Photos, also means users should consider the wider set of personal information that may be involved when using connected services.
Claude has a retention approach that is broadly comparable to ChatGPT. Anthropic says deleted chats are removed from its backend systems within 30 days. There are additional retention periods for certain circumstances. If a user permits their conversations to be used for model training, de-identified versions can be retained for up to five years. Chats associated with potential policy violations can be retained for two years, while related safety scores can remain for up to seven years.
The distinction is important because deleting something from the visible chat interface does not necessarily mean the underlying data disappears from company systems immediately.
AI privacy risks go beyond stored selfies
The report also discusses emerging security concerns as AI models become increasingly capable. One of these is model inversion, a technique in which an attacker attempts to recover sensitive information from a trained model rather than directly obtaining another person’s conversation.
Whether such an attack can succeed depends on several factors, including the model involved, the attacker’s level of access and the information available to them.
The report also mentions an incident in which Anthropic said a suspected state-backed group had misused its Claude Code tool in a cyber-espionage campaign. The incident, however, did not involve the exposure of users’ conversations.
What users can do before joining the next AI trend
For people using AI tools for viral photo trends, the simplest approach is to think about what they are uploading before pressing send.
Pöpper recommends avoiding sensitive information, limiting how much personal activity is concentrated on one platform and switching off model-training options where available. Temporary or incognito modes can also be useful, while old conversations and files that are no longer required can be deleted.
Extra care is needed when uploading photographs of other people. Images involving children or identity documents deserve particular caution, especially when the person pictured has not consented to the upload.
An AI-generated 1980s portrait may only stay relevant on social media for a few days. The original selfie, however, enters a much longer data lifecycle once it is uploaded to an AI service.
Also Read: ChatGPT’s Viral 80s Photos Look Old, But Their Environmental Cost Is New
















