Source-first safety checklist

AI Companion Media and Upload Privacy Checklist

An upload can contain much more than the visible subject. A photo may show a face, document, reflection, location clue, or embedded metadata. Audio may reveal names and background conversations. This page does not claim that a provider strips metadata or limits reuse. It helps you inspect current upload terms and reduce what leaves your control before pressing the upload button.

Check the live source before acting. Policies, prices, credit rules, feature limits, labels, and account screens can change. Recheck the provider's current terms, privacy notice, checkout, help pages, and account interface. This site does not claim to have tested paid accounts and does not promise security, compliance, deletion results, fixed costs, or medical outcomes. Page updated 2026-07-26.

Fast evidence screen

What to verify before continuing
AreaUseful current evidenceReason to pause
Upload purposeThe interface explains what the file will be used forA broad upload prompt has no purpose or audience
File contentsYou reviewed subject, background, text, reflections, and metadataThe file contains hidden or incidental identifiers
Policy languageCurrent terms address uploaded content and service usePromotional copy substitutes for actual terms
Removal routeYou can locate file, conversation, account, and request controlsA thumbnail delete is presented as every possible removal

Question the need to upload

Question: Can the task work with text, a generic image, or a newly created non-identifying sample?

Action: Choose the least revealing input that still serves your purpose. This action reduces guesswork; it does not prove anything beyond the current source and account state you actually observed.

Evidence: A short purpose note explaining why each included detail is necessary. Keep the access date and enough context to understand the wording later.

Worked example: A generic color-and-style reference may replace a personal portrait when identity is not needed.

Pause when: The service pressures you to upload identity documents, intimate media, or financial records for an unrelated feature. A pause is a useful result when proceeding would require an assumption.

Inspect visible details

Question: What can another viewer infer from the subject and background?

Action: Crop names, addresses, screens, badges, reflections, landmarks, and other people before upload. This action reduces guesswork; it does not prove anything beyond the current source and account state you actually observed.

Evidence: A local preview at full size, checked without sending it to another service. Keep the access date and enough context to understand the wording later.

Worked example: A mirror or window reflection can reveal more of a room than the main subject.

Pause when: You cannot remove an identifying detail without making the file unusable. A pause is a useful result when proceeding would require an assumption.

Review hidden file information

Question: Could the file include location, device, author, filename, or creation metadata?

Action: Use trusted local tools or export a clean copy, then verify the resulting file before upload. This action reduces guesswork; it does not prove anything beyond the current source and account state you actually observed.

Evidence: A local metadata check and a neutral filename; do not upload merely to discover what the service reads. Keep the access date and enough context to understand the wording later.

Worked example: A filename containing a full name can expose identity even when the image itself is generic.

Pause when: You cannot verify or remove sensitive metadata and the upload is optional. A pause is a useful result when proceeding would require an assumption.

Read current upload terms

Question: What does the current policy say about processing, moderation, reuse, retention, and requests?

Action: Compare the upload dialog, terms, privacy notice, and relevant help page on the same date. This action reduces guesswork; it does not prove anything beyond the current source and account state you actually observed.

Evidence: Dated excerpts or links with the exact section headings. Keep the access date and enough context to understand the wording later.

Worked example: A checkbox beside the uploader may add a condition not summarized on the marketing page.

Pause when: Terms are missing, contradictory, or grant uses you are not comfortable accepting. A pause is a useful result when proceeding would require an assumption.

Plan removal and local cleanup

Question: Where will copies remain after upload?

Action: Locate in-account removal and request paths, then check local exports, edited copies, backups, and synchronized folders. This action reduces guesswork; it does not prove anything beyond the current source and account state you actually observed.

Evidence: A file-location inventory and any provider confirmation, without attaching the sensitive file. Keep the access date and enough context to understand the wording later.

Worked example: Deleting a thumbnail may remove it from view while policy describes other retention; ask about the difference.

Pause when: There is no understandable path to remove the upload from the account or ask about its handling. A pause is a useful result when proceeding would require an assumption.

Copyable checklist

Complete each line from the provider's current interface or published documents. A blank or unclear answer should remain visible in your notes.

Worked situations

Personal photo for an avatar

Create a less identifying version: crop the background, remove metadata locally, use a neutral filename, and consider whether a non-personal avatar works instead. Then read the live upload terms; local cleanup does not control provider handling.

Record what the current source shows, keep personal details out of the worksheet, and mark unresolved questions rather than filling them with an assumption.

Audio with background voices

Listen with headphones from start to finish. Names, addresses, notifications, television audio, or another person's conversation may be audible. Re-record in a quiet setting or use a synthetic non-identifying sample when appropriate.

Record what the current source shows, keep personal details out of the worksheet, and mark unresolved questions rather than filling them with an assumption.

How to record a reliable answer

Use a dated worksheet with four columns: the question, the current source, the exact answer, and what remains unknown. Prefer a live detailed policy or account control over a promotional summary. Preserve enough surrounding wording to avoid changing the meaning, but cover names, addresses, payment values, conversation text, and other personal details. A screenshot records one interface at one moment; it is not proof that the same rule applies later, in another region, or to another account.

When two sources disagree, do not choose the answer you prefer. Record the conflict and ask the provider through a contact route reached from its current account, terms, or privacy page. Keep the case number and exact response. If the answer affects payment, an upload, account access, or sensitive disclosure, wait until the conflict is resolved or choose not to proceed. Unknown is a valid worksheet result.

A calm stop rule

Pause when a required term is missing, the final confirmation differs from the earlier page, a request moves outside the documented account route, or support asks for secrets that normal support should not need. Do not send passwords, one-time codes, full payment credentials, recovery secrets, or unrelated private conversation content. Do not install unknown software or grant remote control. Return through a known official address and verify the account state independently.

Related safety checklists

Frequently asked questions

Does the service remove photo metadata?

This site does not assert that. Check the provider's current documentation and remove sensitive metadata locally before upload when possible.

Is deleting the thumbnail enough?

Do not treat visual removal as proof of every backend result. Read the current policy and ask about scope, retention, backups, and request options when needed.

Can I upload another person's image?

Consider consent, rights, the provider's current rules, and possible harm. The safer default is not to upload someone else's identifiable media without clear permission and a valid reason.

What is the safest upload?

No upload is risk-free. Prefer the least identifying file that accomplishes the task, after checking visible details, metadata, terms, and removal controls.