The boom in AI profile pictures is fun, but it has a quiet cost most people never see. Behind a playful cartoon filter sits a pipeline of model training, cloud servers, and third-party vendors — and your biometric face is the raw material. This guide explains, in plain English, what actually happens to your photo when you tap "upload," where the real risks are, what "local" generation means, and how LumTale's Door 1 keeps your face on your own device. By the end you'll have a simple checklist to vet any avatar app before you share a single pixel.
What really happens to your photo when you upload it
When you hand a selfie to a typical cloud-based avatar app, three things usually happen — whether or not the privacy policy makes them obvious.
1. Training (sometimes on your face)
Many apps fine-tune or personalize a model on your uploaded images so the output "looks like you." That means your photos are used as training data. Some services explicitly reserve the right to use your images to improve their models — which can include feeding them back into the system that powers other users' results. Unless a policy says otherwise in writing, assume your face can become part of someone else's product.
2. Storage and retention
Your image has to land somewhere: an upload bucket, a processing queue, a temporary cache while the GPU renders your portrait. Even if the app deletes it "after 24 hours," that window is long enough for a backup, a log, or a partner integration to copy it. Storage is the part users forget — the photo may outlive your interest in the app by months.
3. Third parties and sub-processors
Few avatar apps run their own GPUs. They often forward your photo to inference partners, content-moderation vendors, and analytics tools. Each one becomes a new place your face lives. A privacy policy might disclose these sub-processors in legalese, but it rarely tells you which company holds your biometric data right now, or for how long.
The real risks you're taking on
This isn't abstract. A face is uniquely sensitive data, and the downsides of a leak are harder to undo than a leaked password.
Deepfakes and identity theft
A high-quality model of your face is exactly what a fraudster needs to spoof a video verification step or impersonate you. The more copies of your biometric face exist across vendors, the larger the attack surface. Unlike a credit card, you can't cancel your face.
Biometric data laws
Regions with laws like Illinois' BIPA or the EU's GDPR treat facial data as a special category that needs explicit consent. Apps that scrape or retain faces without clear opt-in can land in legal trouble — and you, as the data subject, may have limited control once your image is in their pipeline.
The "free app" business model
If an app is free and built on your photos, you are often the product. Some monetize by licensing datasets, running ads off your engagement, or quietly training future models. A flashy "free trial" can be the most expensive thing you upload all year.
What "local / on-device" generation actually means
"On-device" or "local" generation means the AI model runs inside your browser, on your own computer or phone. Your photo is never sent to a server. It's loaded into the page, transformed by a model that lives in your device's memory, and the result is drawn right back to you. Close the tab and the input is gone — there was no upload, no cloud, no third party in the middle.
WebGPU and ONNX, explained plainly
Two technologies make this possible without you installing anything. WebGPU lets a web page tap into your device's graphics chip (the GPU) for fast math — the same chip that renders games. ONNX is an open format for AI models, and ONNX Runtime Web is the engine that runs those models right in the browser. Together they let a serious portrait model execute locally, in seconds, with your photo never leaving the tab. The privacy win is total: there is simply no network request carrying your face.
How LumTale does it — two honest doors
We built LumTale around a single rule: you should always know where your photo goes. That's why we split the experience into two doors, and we're upfront about both.
Runs 100% on your device
Door 1 uses WebGPU + ONNX Runtime Web to generate your Lumling portrait entirely in your browser. Your photo is loaded locally, transformed locally, and never transmitted. There is no upload endpoint, no server copy, and nothing to delete later — because nothing ever left your machine.
It's our promise made technical: fair, identity-preserving, and genuinely private.
An honest, vetted partner
For a more illustration-rich Lumling Dream or Lumling Toon render, Door 2 sends your photo to a vetted GPU partner (Replicate). We link you to their data-use policy before you upload, we never store or train on your images, and your features stay faithfully yours — no whitening, no warping.
The difference is honesty: with Door 2 you know the photo leaves your device, and why.
A practical checklist: how to vet any AI avatar app
Before you upload your face anywhere, run through these seven questions. If an app can't clear them, your face is probably the price.
-
Does it offer a local / on-device option?
Apps like LumTale's Door 1 that run in-browser (WebGPU/ONNX) eliminate upload risk entirely. Prefer them whenever quality is acceptable.
-
Does the policy say it will NOT train on your photo?
Look for explicit language: "we do not use your images for model training." Vague "to provide and improve the service" can mean training. Walk away if it's ambiguous.
-
Who actually receives your image?
Check for named sub-processors (e.g., a GPU partner). If the policy hides them behind "affiliates and service providers," assume broad sharing.
-
How long is it stored, and can you delete it?
A trustworthy app states a retention window and gives you a delete control. "We may retain as needed" is a red flag.
-
Is biometric consent explicit?
You should actively opt in to facial processing, not have it buried in a 40-page ToS. Clear consent is a sign of a careful operator.
-
Is the business model transparent?
If it's free, ask how they pay for GPUs. Paid, honest apps with clear pricing are usually safer than "free" apps that monetize your data.
-
Does it refuse to whiten or warp faces?
Fairness is privacy-adjacent: apps that reshape non-white faces toward a template are manipulating your identity. LumTale never does this — read our Privacy Policy for the full stance.
Start private with LumTale
You don't have to choose between a great avatar and your privacy. With LumTale you pick the door that fits: Door 1 for a 100% on-device Lumling portrait that never leaves your browser, or Door 2 when you want a richer cloud render from a partner we've vetted and disclosed. Either way, your face stays your face.