Blog · Privacy · October 6, 2026
We Read the Privacy Policies of 4 Background Removers. Here's What They Say About Your Photos.
Every free background remover asks you to upload your photo. We opened the actual privacy policies and wrote down what each one promises about that photo — how long it keeps it, and whether it trains AI on it.
Here's a question almost nobody asks before using a free background remover: after you upload your photo, what does the company promise to do with it?
We read the privacy policies — the actual documents, not the marketing pages — of four popular background removers. Policies change, so treat this as a snapshot from early October 2026, and check the current version before uploading anything sensitive. What follows is what each policy actually says, in plain language.
The short version
| Tool | How long they keep your photo | Used to train AI? |
|---|---|---|
| removal.ai | Deleted within 1 hour, per their policy | Policy says no sharing and no further use |
| Photoroom | No fixed deletion timeframe stated | Yes — unless you opt out in account settings |
| Pixelcut | No photo-specific commitment; "as long as required" | Policy doesn't say |
| remove.bg | Couldn't verify — policy page unreachable | Couldn't verify |
| Deback | Never uploaded, so there's nothing to keep | No — nothing leaves your device |
The details matter, so here they are, tool by tool.
removal.ai: deleted within an hour
removal.ai's policy is the most specific of the four. It states that both the uploaded image and the result are deleted "an hour after the upload at the latest," that images are transferred over an encrypted connection, and that they are not shared with third parties or used for anything beyond removing the background.
That's a clear, checkable promise: one hour, then gone. If you're going to upload a photo to a server-based tool, a policy that names an actual number is what you want to see.
Photoroom: your uploads can train their AI
This is the one that surprised us. Photoroom's privacy policy includes a section on AI model training. It says that by using Photoroom, you acknowledge the company "processes and uses the images you upload to improve, train and develop" its products and models.
There is an opt-out — you can turn it off in your account settings. But the policy is explicit that opting out is not retroactive: anything already used for training stays used. And the training clause doesn't apply to images processed through their API, only the app and website.
To be fair, Photoroom also says the training images are selected and annotated without your identity attached — no name, contact details, or location. But the photo itself, the pixels, can go into the training set unless you find the setting and switch it off.
Pixelcut: no photo-specific promises at all
Pixelcut's privacy policy is a long, generic document about trackers, analytics, payments, and cookies. We read the whole thing. It says nothing specific about uploaded photos: no retention timeframe for your images, no statement about AI training, nothing.
The only retention language is generic — data is kept "as long as required by the purpose they have been collected for." That's the kind of sentence that permits everything and promises nothing. A policy that doesn't mention your photos isn't a policy that protects them.
remove.bg: couldn't verify
We'll be straight with you: when we checked in early October 2026, remove.bg's privacy policy page didn't load. That's consistent with what's happening to the site — the standalone service is being wound down ahead of its December 1, 2026 shutdown, and pages are disappearing.
Independent reporting from September 2026 noted that their policy put no duration on how long uploaded images are kept. We couldn't confirm the current state ourselves, so we won't grade what we couldn't read. If you're still using remove.bg before the shutdown, that uncertainty is worth knowing about.
Deback: the photo never leaves your device
This is our own tool, so take the pitch with the appropriate grain of salt — but the architecture is verifiable, not a promise. Deback downloads the AI model into your browser and runs the entire background removal on your device. There is no upload step. No server ever receives your photo, so there's no retention policy to trust and no training dataset to opt out of.
You can verify this yourself: load the page once, turn off your wifi, and remove a background. It still works. That's the whole privacy policy, demonstrated instead of stated.
What "deleted" doesn't cover
One caveat that applies to every server-based tool on this list, including the ones with good policies: when a company says your photo is deleted, that usually means deleted from their live systems. Backups, error logs, and analytics pipelines keep copies on their own schedules, and no privacy policy gives you a button for those.
That doesn't make a one-hour deletion promise worthless — it's still far better than no promise at all. It just means "deleted" is a company commitment, not a technical fact. The only setup where deletion is a technical fact is when the photo never left your device in the first place.
For the full routine on vetting any background remover — including the wifi test — see our guide: Is It Safe to Upload Photos to a Background Remover?
Frequently asked questions
Which background remover has the best privacy policy?
Of the server-based tools we checked, removal.ai's is the most specific: deletion within one hour, no sharing, no further use. Photoroom's policy allows AI training on uploads unless you opt out. Pixelcut's policy makes no photo-specific commitments. Tools that process on your device, like Deback, sidestep the question entirely.
Does Photoroom really use my photos to train AI?
According to their own privacy policy, yes — images you upload can be used to improve, train, and develop their models. You can opt out in your account settings, but the opt-out isn't retroactive. Images processed through their API are excluded.
Do free background removers sell my photos?
None of the policies we read said they sell uploaded photos. The realistic risks are vaguer: unclear retention, AI training clauses, and copies lingering in backups and logs. Read the retention section before uploading anything sensitive.
How do I check a background remover's privacy myself?
Open the privacy policy, search for "retain," "delete," and "train," and look for specific timeframes. Then run the wifi test: load the tool once, disconnect, and try a removal. If it works offline, your photos never leave your device.