How Long Undress Apps Keep Your Photos: 15 Policies Compared
What each provider’s privacy policy actually says about uploaded and generated images, which claims we could verify, and how the gaps affect the privacy score.
Data retention in an undress app is the period a provider keeps uploaded and generated images; documented terms range from 24-hour deletion to no stated period. All 15 catalog tools have a published review; eight policies name a deletion window for images, from 24 hours to 7 days, and the rest state no period at all. Policies were re-checked on September 3, 2026. Consent rules are in our Responsible AI policy.
What do the 15 policies say about images?
Privacy carries 30 percent of every score under How we rate, and retention is the largest part of it. The table reflects the policy text as read during each tool’s test; “stated” means the provider claims it and we could not confirm it from the interface.
| Tool | Retention of images | Account and technical data | Deletion route | Policy status |
|---|---|---|---|---|
| Pornworks | No stated period | Account data until deletion; usage and technical data up to 12 months | Content-removal form | Read Aug 12, 2026 |
| Ainudez | “As long as reasonably necessary”; private media library | Card numbers not stored | Erasure on request; abuse mailbox with 48-hour commitment | Updated June 10, 2026 |
| Deep Undress | Not publicly documented | Terms shown only after sign-up | In-account deletion, contact form | Provider pages did not respond Sep 3, 2026 |
| Undresswith AI | Deleted after 24 hours (stated, unverified) | Policy contains a “[Your Country]” placeholder | Support email | Read Aug 28, 2026 |
| Wavespeed | Generated media expire within 7 days | Singapore-registered operator; age threshold 13 | Account controls | Read Aug 16, 2026 |
| UndressHer | Files removed after processing (stated, unverified) | One-time card purchases | Contact form | Read Aug 17, 2026 |
| Dreemy AI | No stated period for uploaded or generated images; inputs and outputs used to improve models | Personal data while the account is active | Contact email in the policy | Policy effective Jan 1, 2026; read Sep 3, 2026 |
| OpenArt | Subscribers: until deleted; non-subscribers: unpublished creations deleted after 7 days | Uploads not used for training; inputs may be shared with model providers | Gallery or account deletion; DMCA agent | Read Sep 3, 2026 |
| AILabTools | Uploaded and generated files deleted within 24 hours (stated, unverified) | No training statement; card data with Paddle | Support email or ticket | No “last updated” date; read Sep 3, 2026 |
| Undress.app | “No media is stored”; working files cleared within 1 hour to 1 day (stated, unverified) | Email address kept for the account | Support email, acknowledged within 24 hours | Last updated July 27, 2023; read Sep 3, 2026 |
| MyImg AI | Uploads and outputs deleted within 24 hours, no backups (stated, unverified) | Facial landmarks discarded; no model training | Content-policy contact, 7 business days | Policy dated Jul 3, 2026; read Sep 3, 2026 |
| UndressMe AI | Uploads and results encrypted and deleted after 24 hours (stated, unverified) | Account data until deletion; logs of attempted minor uploads up to 6 years | Take-it-down page or email; 48-hour pledge | Read Sep 3, 2026 |
| Cling AI | No stated period for uploaded or generated images | Personal data while the account is active; card data with processors | Account settings or support email | Read Sep 3, 2026 |
| Joyfun AI | “As long as reasonably necessary”; 48 hours per the face-swap page | Google Analytics; no named operator | Support email | Read Sep 3, 2026 |
| Pixaryai | “Temporarily stored for processing”; no period stated | Advertising identifiers (IDFA, GAID) shared with ad partners; Hong Kong operator | Email only | Policy dated Feb 2026; read Sep 3, 2026 |
Among the six partner tools, only Wavespeed puts a number on generated media and backs it with a data-retention policy; two providers make deletion claims we could not check, and Deep Undress publishes nothing usable before sign-up. The nine reviews published on September 3, 2026 add five more stated windows — 24-hour deletion at MyImg AI, UndressMe AI and AILabTools, 7 days for non-subscribers at OpenArt, and a “no media stored” claim at Undress.app — none verifiable from outside. Dreemy AI, Cling AI, Pixaryai and Joyfun AI name no period for images, so treat their uploads as retained.
Why does “reasonably necessary” tell you so little?
Phrases like “as long as reasonably necessary” are standard in privacy policies because they satisfy the purpose-limitation language of the GDPR and the CCPA without committing to a date. For an image tool they leave the two questions that matter unanswered: whether the uploaded source is kept after processing, and whether outputs sit in a library until the account is closed. Ainudez, which uses the phrase, at least pairs it with a private library and an erasure route; a policy that uses the phrase and offers no deletion control scores lower. Our digital consent entry explains why retention of a third party’s photo is a consent problem as well as a privacy one.
Consider, too, how to give individuals without an account on your platform an easy way to submit a TIDA removal request. TIDA’s protections are not limited to individuals who hold an account on your platform.
— FTC, Complying With the Take It Down Act, accessed Sep 3, 2026
Which claims could we verify, and which not?
Verification means the interface or a dated policy page confirmed the claim during the test. Wavespeed’s 7-day expiry appears in its data-retention policy and matched the behavior we saw. Pornworks’ 12-month window for technical data is explicit in its policy. Undresswith AI’s 24-hour deletion and UndressHer’s post-processing removal are provider statements with no visible confirmation, so both reviews mark them unverified and the privacy sub-scores of 8.6 and 8.1 reflect that. Deep Undress scored 8.5 on privacy largely because nothing could be checked before sign-up. We re-request policies at each test date; the privacy check on Ainudez shows the process in detail.
What rights do US users have over stored photos?
No single federal statute grants a deletion right for adults, but several routes exist. California residents can use the CCPA to request deletion and to know what categories of data a business holds; our CCPA entry lists the steps, and comparable laws apply in a growing number of states. Anyone depicted in a non-consensual intimate image can use the TAKE IT DOWN Act notice process, enforced by the FTC since May 19, 2026, which covers the source and known copies. For a tool operated from the EU or serving EU users, the GDPR right to erasure applies regardless of where the requester lives; see the GDPR entry. This site’s own privacy policy applies the same standards to the little data it collects.
How should retention change which tool you pick?
Rank a short retention window above any other privacy feature. A tool that expires media in days limits what a breach, a subpoena or a change of ownership can expose. Then look for an account-level delete control, a named deletion channel and a policy with a date; the red-flags checklist treats missing dates as a warning sign. If a provider’s age threshold is 13 rather than 18, as in Wavespeed’s general policy, the service was not designed around adult imagery, which is a separate consideration. Finally, keep your own copy of the policy as read on the day you pay.
Sources and verification
Primary sources checked for this article. Service facts come from the linked editorial reviews and their dated test notes.
- FTC — Complying With the Take It Down Act — accessed Sep 3, 2026
- California Attorney General — CCPA overview — accessed Sep 3, 2026
- Regulation (EU) 2016/679 (GDPR), Article 17 right to erasure — accessed Sep 3, 2026
- FTC — Children’s privacy (COPPA) — accessed Sep 3, 2026
This article is editorial research, not legal advice. Laws change; statutes and agency pages were checked on September 3, 2026. For a specific situation, consult a licensed attorney in your state.
Consent and reporting
Related reading
Our privacy policy
How this editorial site handles the limited data it collects, under the same standards we apply to tools.
Read the policy →Digital consent
Why storing another person’s photo is a consent question, not only a privacy one.
Read the entry →How to get an image removed
Removal routes and notice templates for every reviewed tool.
Read the article →Undress apps catalog
Privacy sub-scores and retention notes for every reviewed tool.
See the catalog →Frequently asked questions
Which undress app has the shortest documented retention?
Wavespeed states that generated media expire within 7 days, the only documented time limit among the six partner tools. MyImg AI, UndressMe AI and AILabTools state 24-hour deletion, which we could not verify from outside. Undresswith AI claims 24-hour deletion and UndressHer removal after processing; neither was verifiable, so both stay marked unverified.
Does any reviewed tool keep photos indefinitely?
Pornworks states no retention period for images and keeps account data until you delete the account, so stored outputs persist until you act. Ainudez keeps a private media library “as long as reasonably necessary” with erasure on request. Deep Undress does not publish a policy before sign-up, so its practice is unknown.
How do I request deletion of my uploads?
Use the route recorded in each review: Ainudez has an abuse mailbox with a 48-hour commitment, Pornworks a content-removal form, Undresswith AI a support email, and Deep Undress and UndressHer in-account deletion plus a contact form. Write a dated request naming the account and the files, and keep the confirmation.
Can a US resident use the GDPR against an undress app?
Only if the provider is established in the EU or offers services to people in the EU, in which case the right to erasure applies to any data subject it processes. Otherwise rely on state privacy laws such as the CCPA and on the TAKE IT DOWN Act notice process for non-consensual intimate images.
Why does a 13-year age threshold in a policy matter?
It signals a general-purpose platform whose privacy policy was not written for adult image tools. Wavespeed’s policy uses 13, the COPPA threshold, while its clothing-changer model is adult-only in practice. The mismatch does not change your rights but suggests checking the specific model’s terms and the site’s age gate before relying on the policy.
Are all 15 catalog tools covered in this comparison?
Yes, as of September 3, 2026. The nine reviews published that day added their retention terms to the table: MyImg AI, UndressMe AI and AILabTools state 24-hour deletion, OpenArt deletes non-subscribers’ unpublished creations after 7 days, Undress.app claims to store no media, and Dreemy AI, Cling AI, Pixaryai and Joyfun AI name no period for images. Each change is logged in the transparency report.