That birthday party album you posted publicly six years ago — balloons, cake, your kid’s face mid-laugh — didn’t just sit on a server waiting for family to click the heart button. It became training data. A 2025 ruling by Germany’s higher regional court in Schleswig-Holstein found that Meta’s AI systems “inevitably capture minors’ information” whenever adults share content featuring children on Facebook or Instagram. The kids never had accounts. They never consented. Didn’t matter.
Meta’s own privacy documentation confirms that public posts, photos, captions, comments, and Stories shared with a “public audience” feed into its generative AI models. “Public” covers more ground than most people assume — anything not actively locked down, including years of posts from an era when nobody thought twice about privacy settings.
Once It’s in the Model, It Doesn’t Come Out
The irreversibility of AI training is the detail Meta would prefer you gloss over.
Here’s where it gets permanent. In those same German court proceedings, Meta acknowledged that while its models are designed not to output personal data, “it is not entirely impossible for such data to be released.” That’s Meta’s own words, in formal court proceedings, describing its own product’s limits — not a privacy advocate catastrophizing on a podcast.
Brazil’s national data protection authority suspended Meta’s revised privacy policy for AI training entirely, citing these privacy risks. Regulators can slow the intake pipe. But nobody can reverse-engineer a trained model and surgically remove your child’s face from its parameters. Think of it like a tattoo that belongs to someone else — except they’re not the ones who’ll live with it for the next five decades.
Removing or locking down public posts now — before more training rounds happen — is the only realistic intervention available to regular users:
- Children’s faces and names enter training datasets via adults’ accounts, regardless of whether the children have profiles of their own
- Investigative reporting from Australia confirmed that Facebook scrapes public photos of children directly from adult profiles to train its AI
- Deletion before ingestion is the only effective move; once a model trains on content, that process cannot be cleanly reversed
- Old public posts from years ago remain eligible training material even if your account is set to private today
- Brazil suspended Meta’s AI training policy over exactly these concerns — users in most other countries have no equivalent protection
One more data pipeline worth knowing about: OpenAI’s Apple Messages plugin for Mac requires Full Disk Access, reads years of iMessage history from your local database, and for Free, Plus, and Pro accounts, that content is eligible to train OpenAI’s models by default unless you change your settings. iMessage’s end-to-end encryption offers no protection once an app can read the local database directly. Messages from contacts who never installed ChatGPT are included in what gets processed.
Locking down or deleting public posts — especially anything featuring kids — is not overcaution. It’s the one lever regular users actually control. Even partial action, like restricting old albums or tightening audience settings on past posts, meaningfully reduces the chance those images get quietly absorbed into the next training run. Regulators in Brazil and Europe are fighting this battle with legal tools that work slowly and imperfectly, much like a surveillance app that operates beneath users’ awareness. Your privacy settings work right now.





























