Why your uploaded photos should not live in the cloud: 417 scans in a single day
"What happens to my photo" is not an abstract worry. This post uses the real logs from this site's first day online to show what the risk looks like, and how to judge whether a service deserves your files.
2026-08-20 作者 William Hsu
First day online: 417 scans
On the day the domain went live I pulled that day's requests out of Cloudflare: of 4,547 requests, 417 returned a 404. Those were not users mistyping a URL. They were scanners guessing where the config files are.
What they were after is very specific:
/.env,/.env.docker,/.env.staging— environment files, which usually hold database passwords and API keys/key.json,/localhost.key— certificates and private keys/rclone.conf— cloud storage credentials/.github/workflows/deploy.yml— the deployment script, which reveals the architecture/.claude/settings.json— the config file of an AI tool
I read that last one twice. The scanner dictionaries already include the config paths of AI development tools, which means somebody has pulled something out of one.
All of those requests returned 404, because this site's code only answers URLs it has registered and never serves a directory. But it makes one thing plain: anything on the internet is being rummaged through from day one. If your photos sit on a loosely configured machine, nobody has to target you personally — automated scanning is enough.
How many hands a photo actually passes through
Most "AI photo" sites do not run a model themselves; they forward your file to an upstream API. The real path of one photograph can be: your phone → the site's server → cloud storage → the model provider's API → the model provider's storage. Every leg has its own retention policy, and you only agreed to the first one.
That is also why terms of service are so hard to read. Most of them reserve the right to use what you upload "to improve the service", and that phrase covers more ground than most people assume.
The three questions worth asking
To decide whether a service deserves a photograph of your own family, three questions are enough — and the answers have to be specific:
- Is the file handed to a third party? "We value your privacy" is not an answer. The answer should be "yes, to such-and-such company's API" or "no, the model runs on our own hardware".
- How long is it kept? The answer should be a number, and it should say when the clock starts.
- Is it used for training? This is the one most services dodge, because "improving the service" can be stretched to cover training.
This site's answers
Taking the three in order: nothing is handed to any third-party AI service, because the model runs on a graphics card at home; both the upload and the finished result are deleted automatically after seven days; and no training or fine-tuning step ever reads your files — the model is downloaded and used as it is.
Two more things that rarely get mentioned but matter:
- Your history needs a login to see. An early version used the IP address to decide "is this yours", but two people behind the same connection look like one person. It now identifies by account and browser only; the IP is used solely for counting the free allowance.
- Analytics are not outsourced. Traffic statistics are counted on our own server, with no Google Analytics or similar third-party script. The site does carry ads and the ads themselves use cookies; that is written in the privacy policy rather than hidden.
Don't trust the claim, look at the details
Anybody can write "we do not keep your photos" on a web page. A more reliable test is whether the operator is willing to describe the implementation: which model, running where, how deletion is triggered, where the rejected files go. The ones who can describe the details are usually the ones who actually did the work.