Short answer
Usually yes, for ordinary photos. CloudConvert and Convertio delete files within 24 hours, ezgif within an hour of last use, remove.bg within about an hour. The real differences are elsewhere: Photoroom trains its AI on uploads by default (you can switch it off), remove.bg's policy allows training, and every upload is a copy you no longer control. For ID documents, children or client work, a tool that processes the photo in your browser avoids the question.
Is it safe to upload photos to online converters and background removers? For most everyday pictures, and with the big names, the honest answer is yes: the well-known services say they delete your files within an hour or a day, and nothing suggests they do otherwise. But “safe” hides three separate questions (how long the copy exists, what else it may be used for, and who could get at it in the meantime), and the answers differ more between services than their home pages suggest.
This guide sets out what happens to a photo when you upload it, then what five popular tools actually say in their own policies: CloudConvert, Convertio, ezgif, remove.bg and Photoroom. Every summary below is in our words, with a link to the source, and was checked on 16 September 2026. Policies change, so if a decision rests on one, open the link and read the current version.
What happens when you upload a photo
Uploading means copying. When you drop a picture on a site that processes it on a server, your browser sends the whole file over the internet (encrypted in transit on any reputable site), and the service stores it long enough to work on it. The steps are nearly always the same:
- The file arrives on a server, usually rented from a cloud provider such as Amazon Web Services or Google Cloud, in a country the service chooses.
- A program converts it or runs an AI model over it and writes a result file.
- The result is stored so that you can download it, typically for minutes or hours.
- Both files are deleted on a schedule, or when you press a delete button.
- Around all of that, logs are kept: your IP address, the file type, the time, sometimes the file size. Logs usually outlive the files.
Nothing in that list is sinister, and it is how nearly every converter on the web has worked for twenty years. The risk is not that a reputable service is reading your holiday photos. It is that for a while a copy exists somewhere you cannot see, under a policy you cannot audit, and that the photo may carry more than its pixels: most phone pictures include metadata such as the date, the camera and often the GPS position where they were taken.
What five popular tools say (checked 16 September 2026)
Is CloudConvert safe?
CloudConvert’s privacy policy is one of the clearer ones. It says files are deleted immediately and irreversibly when you use the delete button, and automatically after 24 hours at the latest. Processing is done by machine with no human involvement, and the company says it does not read, mine or copy the contents of your files; the only statistics it keeps about conversions are the number of files, the number of errors and the total size. Hosting is with cloud providers in Germany (Amazon Web Services, OVH and Hetzner are named), and visitors from the US are served from US servers instead. There is nothing about training AI models, which fits a service that converts formats rather than generating anything.
In practice: a sensible choice for ordinary files, with a copy on a German or US server for up to a day unless you delete it yourself.
Is Convertio safe?
Convertio’s privacy policy says input files and temporary files are deleted as soon as a conversion finishes, and output files after 24 hours, or immediately if you click the X next to them. It says nobody reads, looks into or copies your files, that files are kept in the European Union, and that a result can only be downloaded by the IP address that started the conversion. It does keep some anonymous records (IP address, file types, conversion time, success or failure) for performance monitoring, “for a long time” in its own words.
The site shows ads through Google AdSense and other networks, and the policy is open that those advertisers may use their own tracking. That concerns your browsing, not your file.
Is ezgif safe?
ezgif’s privacy page is short. Uploaded files stay on its servers for up to one hour after they were last used with any of its tools, and are then deleted automatically. File names are not listed publicly. The site says it does not knowingly collect personal information, and uses cookies for anonymous traffic statistics, preferences and advertising.
A one-hour window is short, and for a meme or a GIF there is little to worry about. The policy simply says less than the others: nothing about where the servers are, who can access them or how deletion is done.
Is remove.bg safe?
remove.bg is run by Canva Austria GmbH, part of Canva. Its help article Is remove.bg safe? says both the uploaded image and the result are deleted at the latest about one hour after the upload, straight after processing for API calls, and that images are not shared or published. A second article, Do you use my images to train the AI?, answers no: an image is only used for improvement if you choose to contribute it, for example when you rate a result as bad and agree.
The privacy policy itself (last updated 16 July 2025) is broader. It permits analysing the content and media uploads in your account to train algorithms, models and AI products, and it says data may be stored and processed in Europe and in any other country where the company, its affiliates or its providers have facilities. Server logs are kept for up to three months. The help pages describe what the service does today; the policy describes what it is allowed to do.
One more thing worth knowing: according to remove.bg’s own FAQ, remove.bg (part of Canva since 2021) is migrating its background removal into the Canva platform. Canva is a cloud design platform, so pictures you work on there are stored in your Canva account rather than deleted after an hour.
Is Photoroom safe?
Photoroom is a French company based in Paris. Its privacy policy says that by using Photoroom you acknowledge that it uses the images you upload to improve, train and develop its products and models; that images used for training are kept only as long as training needs them, without your name or contact details; and that you can opt out at any time, though opting out does not undo processing that has already happened. The help article Permission for Photoroom to use your data (updated 20 October 2025) confirms training is on by default and names the switch: Improve model for everyone, under your profile’s preferences on the web and under Manage account, then Data control, in the phone apps.
Photoroom’s security page adds that its infrastructure runs on Google Cloud and Amazon Web Services in the United States, that EU-only data residency is not offered, and that images sent through the API are discarded once processed. Designs and AI images you make in the app are kept in your account (there is a help article on deleting AI image history). The policy and the security page are not worded identically about the self-service API, so API users should read both.
In practice: a capable app with serious security, and the one on this list where your photos help train a model unless you switch it off.
The five side by side
| Service | Files deleted | Used to train AI | Where |
|---|---|---|---|
| CloudConvert | on delete, at the latest after 24 hours | not mentioned; says it does not mine files | Germany, or US for US users |
| Convertio | inputs at once, outputs after 24 hours | not mentioned; says it does not read files | European Union |
| ezgif | up to 1 hour after last use | not mentioned | not stated |
| remove.bg | at the latest about 1 hour after upload | help: only if you contribute; policy: permitted | Europe and elsewhere |
| Photoroom | kept in your account; API images discarded | yes by default, opt out in settings | United States |
What a privacy policy cannot tell you
A policy is a promise, and the companies above have every reason to keep theirs: they are established businesses, several operate under the GDPR, and a leak would hurt them badly. Still, there are limits to what any policy can guarantee.
- You cannot check it. Nobody outside the company can see whether a file really was deleted after 24 hours, or whether a backup copy lingers in an archive. remove.bg’s policy openly says personal data held in backups is isolated until deletion is possible, which is honest and normal.
- Breaches happen to careful companies. The shorter a file exists, the smaller that risk, which is why a one-hour window is better than a day, and a day better than an account that keeps everything.
- Policies change. The version you agreed to is not necessarily the version that applies next year, and a product can be sold, merged or closed, as remove.bg’s move into Canva shows.
- “Improve our service” is elastic. Training a model on your picture does not publish your picture, but it is a use you did not come for, and a trained model cannot easily forget.
- Metadata travels with the file. A converter receives the whole file, including any GPS position, camera serial number or editing history embedded in it.
None of this makes uploading reckless. It means the right question is not “is this site safe?” but “is this photo one I am happy to have copied to a server for a while?”
Which photos deserve a second thought
For a picture of a mug you are selling, a meme or a screenshot of a public web page, any of the services above is fine. Think twice, or use something that keeps the file on your device, when a photo shows:
- Identity documents: passports, driving licences, ID cards, anything with a number on it.
- Children, especially with school uniforms, names or locations visible.
- Other people who did not agree to their picture going anywhere.
- Client or employer material under a confidentiality agreement, and products that have not been announced. Many contracts forbid sending such files to third-party services at all.
- Medical, legal or financial documents photographed with a phone.
- Your home, when the file carries its GPS position.
The same thinking applies when you pay a studio to cut out product photos: you are sending the pictures to another company, and it is fair to ask how long they keep them. Clipping paths and image masking covers what to ask a retoucher.
What “processed in your browser” means
There is a third way between installing software and uploading a file. A website can send your browser the program, including an AI model, and let your own device do the work. The picture is read from your disk into the browser tab, processed by your processor or graphics card, and saved back to your disk. It never travels, so there is nothing to delete, nothing to train on and nothing to leak.
This used to be too slow for anything serious. Two browser technologies changed that: WebAssembly, which runs compiled code at close to native speed, and WebGPU, which gives a web page access to the graphics card. A background-removal model that needed a server a few years ago now runs in a browser tab on an ordinary laptop or phone.
The catch is that anyone can write “private” or “secure” on a home page, and some sites that say “we respect your privacy” upload every file. The difference between the two is not something you have to take on trust: it shows in the browser’s network log, and it shows when you disconnect from the internet. How to check that a website is not uploading your photos walks through both tests in Chrome, Edge, Firefox and Safari.
Check any tool in two minutes
- Open the tool’s page and process one picture while you are online, so that anything the tool needs (an AI model, for instance) is already in the browser.
- Keep the tab open, without reloading it, and turn on airplane mode, or switch off Wi-Fi and unplug any network cable.
- Drop or choose a photo and start the conversion or background removal.
You should see: if the result appears with the connection off, the work was done on your device and the photo cannot have been uploaded at that moment.
If you do not: an error, a spinner that never finishes or a message about the connection means the tool needs a server, so it uploads the file. That is not wrong, but it means the policy above is the one that matters.
How getPNG handles your photo
getPNG is a background remover built the in-browser way. When you drop a photo, the AI model runs inside your browser, on your graphics card through WebGPU where the browser has it and on the processor through WebAssembly otherwise. The edges are refined and the transparent PNG is saved without the picture leaving your device, and there is no server-side processing: the site has no server that could receive an image.
What does travel is stated on the privacy page. The first time, your browser fetches the AI model from getpng.app and keeps it in its cache; your picture is not part of that request. After each cutout the page adds one to a daily counter, with a request that carries nothing about the picture. The site also uses Google Analytics to count visits, and its security policy stops the page from sending data to any host other than getpng.app and Google Analytics. After your first picture, the tool keeps working with the connection off, which is the easiest proof.
The free way
Cut out a photo without uploading it
Drop a JPG, HEIC, PNG, WebP, AVIF, GIF or BMP on getPNG and download a transparent PNG at the full resolution of the original. Free, no account, no watermark, and it works offline once the model is in your browser’s cache.
How to decide
A short way to choose, whatever tool you are looking at:
- Is the photo sensitive? If it shows an ID, a child, someone else or confidential work, prefer a tool that processes it on your device, or an app installed on your computer.
- Does the tool need your photo on a server? Try it offline. If it works, the question of uploads does not arise.
- If it uploads, how long does it keep the file? An hour is better than a day; a day is better than an account that stores everything.
- Does it train on uploads? Look for the words “train”, “improve” or “develop” in the policy, and for an opt-out switch in your settings.
- Where are the servers, and who runs them? For work under the GDPR or a client contract, that can decide the matter by itself.
- Strip what you do not need to send. Removing location data before uploading costs nothing and protects against the least visible leak.
Uploading a photo to a well-run service is not automatically unsafe, and the five services above are not careless with files. But the safest copy of a photo is the one that was never made, and for a background removal you no longer need a server to get a good result. For the formats you might be converting between, how to make a transparent PNG covers the options, including the ones that stay on your machine.
The test in checking that a website is not uploading your photos is not specific to background removal, and it is worth pointing at anything that claims to work on your device. Our sibling site getSVG, which traces a picture into a vector, is built on the same promise and explains how it keeps it; the network tab is the only proof that counts, on either of them.
Questions
Is CloudConvert safe?
By its own privacy policy, CloudConvert deletes your files when you press delete and automatically within 24 hours at the latest, processes them by machine with no person looking, and hosts them in Germany (or the US for US visitors). It is a long-running, paid business with a clear policy. The residual risk is the one every upload carries: a copy exists on a server for up to a day.
Is remove.bg safe?
remove.bg says it deletes the uploaded image and the result at the latest about an hour after upload, and its help centre says images are not used to train the AI unless you choose to contribute one. Its privacy policy is broader and permits training on account uploads. Note that remove.bg says it is moving its background removal into Canva, which owns it.
Is Convertio safe?
Convertio's privacy policy says input files are deleted straight after conversion and output files after 24 hours, or at once when you delete them, that files are kept in the European Union, and that nobody reads or copies them. The site also runs third-party advertising, which sets its own cookies but does not touch your files.
Is ezgif safe?
ezgif says uploaded files stay on its servers for up to one hour after they were last used with its tools, then are deleted automatically, and that file names are not listed publicly. It is a free, ad-supported site with a very short policy, so there is little detail about anything beyond that.
Does Photoroom use my photos to train its AI?
Yes, by default. Photoroom's privacy policy says images you upload are used to improve and train its products and models, and its help centre says you can turn this off with the Improve model for everyone switch in your account settings. Switching it off does not undo training that has already happened.
Can a website remove a background without uploading my photo?
Yes. The website sends your browser the program and the AI model, and your own processor or graphics card does the work. The photo never has to leave the device. You can confirm it with the browser's network log or by going offline, as described in the guide on checking a website yourself.