Skip to content
Heroica — home page
All guides

Is it safe to upload a child’s photo to an AI book maker? A privacy checklist

By the Heroica editorial team6 min read

Uploading a child’s photo to an AI book maker can be reasonably safe if the service names who processes it, keeps it briefly, deletes it after use and never sells it or uses it in ads. Choose a face-only photo, remove location data and know that you can ask for deletion.

A smiling mother and daughter sit together in a child’s bedroom, holding an illustrated book with a starry night-sky cover.

What are the real risks of sharing a child’s photo with an AI service?

The main risks are the photo being kept longer than needed, passed to providers you don’t know about, reused for advertising or model training, or exposed in a data breach. Hidden location data in the file can also reveal where your child lives or plays.

The CNIL, France’s data protection authority, warns that children’s photos shared online can be copied or manipulated with AI, and that metadata can reveal places and times. Uploading a photo for a personalised book is not a public post, but the rule holds: share as little as possible, with as few parties as possible, for as short a time as possible.

What should you check before uploading?

Check who processes the photo, which third parties receive it, how long it is kept, when it is deleted, whether it may be used in ads, sold or used to train AI, and how to exercise your rights. If the policy is silent, ask before uploading.

Privacy checklist before uploading a child’s photo
QuestionWhat a good answer looks like
Who processes the photo?The company names itself and the provider that generates the images.
Is it shared with third parties?Only with named providers, only to make the book.
How long is the original kept?A stated, short retention period.
Is it deleted after use?Yes, at a clear point, such as once the character is created.
Is it used in ads or sold?An explicit “no” to both.
Is it used to train AI models?A clear statement; if there is none, ask in writing.
Can you access or delete the data?A simple way to request access, correction and deletion.
Who may upload?You confirm you are the parent, guardian or authorised.

Vague wording such as “we may share data with partners”, with no names or purposes, is a reason to ask or to choose another service. See also how to choose a personalised book.

Which photo should you choose?

A recent, sharp photo of your child alone, front-facing with the face clearly visible, against a plain background. Leave out anything that shows where they live or study: school uniform, name tags, house numbers, street signs or recognisable landmarks.

  • Face front-on, eyes open, good daylight, no filters.
  • Only your child in the frame: no siblings, friends or classmates.
  • No school logo, club kit or badge with a name.
  • No visible address, number plate or local landmark.
  • Everyday clothes; never bath or swimwear photos.
  • Crop to head and shoulders: less context, less to reveal.

How do you remove location data from a photo?

Phone photos often carry EXIF metadata such as GPS coordinates and the date taken. Remove the location before uploading, using your phone’s sharing options or your computer’s file properties, then check the file’s details to confirm it has gone.

  • Phone: many share menus can leave out location; you can also turn off location for the camera for future photos.
  • Windows: right-click the file → Properties → Details → “Remove Properties and Personal Information”.
  • Mac: open the photo in Preview, show the Inspector and use “Remove Location Info”.

Which privacy laws protect children’s photos?

In the EU, the GDPR; in the UK, the UK GDPR; in Brazil, the LGPD alongside the Statute of the Child and Adolescent (ECA); in the US, COPPA, for children under 13. All treat children’s data with extra care, but their scope differs.

Main frameworks by region (general information, not legal advice)
RegionFrameworkWhat it means for parentsRegulator
EU, incl. Spain and FranceGDPRChildren merit specific protection; rights to access, correct and erase data.AEPD (Spain), CNIL (France)
United KingdomUK GDPR and the ICO’s Children’s codeSame core rights; the code covers online services likely to be accessed by children.ICO
BrazilLGPD (art. 14) and ECA (art. 17)Processing in the child’s best interest; the ECA protects the child’s image and identity.ANPD
United StatesCOPPACovers personal information, photos included, collected online from children under 13.FTC

What rights do you have over your child’s photo?

Under the GDPR, UK GDPR and LGPD you can usually ask to see the data held, correct it, have it deleted and withdraw consent. Write to the contact named in the privacy policy and keep a copy of your request.

  • Access: what data is held, why, and who received it.
  • Correction: a misspelt name or wrong age, for example.
  • Erasure: the photo and anything derived from it.
  • Complaint: if there is no answer, contact your data protection authority.

In the UK, the ICO says organisations normally have one calendar month to respond to an erasure request.

How does Heroica handle the photo?

Heroica stores the original photo privately and sends it temporarily to its image-generation provider, KIE AI. We keep the original during production and for seven days after delivery or revision completion, with access restricted to authorized support staff. The photo is not sold or used in advertising, and you can request access, correction or deletion.

  • The original goes to KIE AI to create the character sheet; it is kept during production and for seven days after delivery or revision completion, and the other pages are drawn from the sheet, not the photo.
  • Unpaid requests are cleaned up seven days after upload; deletion is suspended while a revision is open.
  • The photo is not sold or used in advertising.
  • Whoever uploads must confirm they are the child’s guardian or have authorisation.

For anything not listed here, such as questions about AI training, read the privacy policy or write to the team before uploading. To see how the photo becomes illustrations, read how AI personalised books work.

Frequently asked questions

Is my child’s photo “biometric data” under the GDPR?

Not automatically. GDPR Recital 51 says photos count as biometric data only when processed with specific technical means that allow unique identification. Either way, a child’s photo is personal data and deserves care.

Do AI book makers use children’s photos to train their models?

It depends on the company. Look for an explicit statement in the privacy policy; if there is none, ask in writing and wait for a clear answer before uploading.

Can I upload a photo of my grandchild or niece?

Only with the parents’ permission, even for a birthday or Christmas surprise. Responsible services ask you to confirm you are the guardian or authorised; the simplest route is to let a parent upload the photo.

Should my child have a say?

Yes, as far as their age allows. France’s 2024 law asks parents to involve children in decisions about their image according to age and maturity; explaining what the photo is for is a good habit anywhere.

Can I ask for the photo to be deleted after I get the book?

Yes. Under the GDPR, UK GDPR and LGPD you can request erasure. Some services delete the original automatically; at Heroica it is deleted seven days after delivery or revision completion.

What if a company won’t answer my privacy questions?

Don’t upload. A service that cannot say who processes the photo or how long it keeps it is not a good fit for children’s data. You can also raise concerns with your data protection authority.

Sources

  1. (2016). Regulation (EU) 2016/679 (General Data Protection Regulation). EUR-Lex
  2. Your right to get your data deleted. Information Commissioner’s Office (ICO)
  3. Introduction to the Children’s code. Information Commissioner’s Office (ICO)
  4. (2025). Partage de photos et vidéos de votre enfant sur les réseaux sociaux : quels sont les risques ?. CNIL
  5. (2024). Menores, salud digital y privacidad: estrategia y líneas de acción. Agencia Española de Protección de Datos (AEPD)
  6. (2018). Ley Orgánica 3/2018, de Protección de Datos Personales y garantía de los derechos digitales. Boletín Oficial del Estado (BOE)
  7. (2018). Lei nº 13.709/2018 – Lei Geral de Proteção de Dados Pessoais (LGPD). Presidência da República
  8. (1990). Lei nº 8.069/1990 – Estatuto da Criança e do Adolescente (ECA). Presidência da República
  9. (2023). Enunciado CD/ANPD nº 1, de 22 de maio de 2023. Autoridade Nacional de Proteção de Dados (ANPD)
  10. Complying with COPPA: Frequently Asked Questions. Federal Trade Commission (FTC)

See your child as the hero — free

Create a free preview with the cover and first illustrated page. No account, no card — you only pay if you like what you see.

Create the free preview

Keep reading

All guides →