Stable Diffusion — privacy & data policy
Provider: Stability AI. PromptPrivacy score: 55/100. Last verified August 26, 2026.
What happens to your data?
Stability AI collects user-provided details, usage logs, and device information to deliver, improve, and secure its services. Data is shared with contracted service providers and kept for up to one year. Users can submit requests to access or delete their personal data by contacting the company via email.
Does it train on your data?
Not specified. The policy does not explicitly mention whether user prompts, inputs, or generated images are utilized to train or fine-tune AI models.
Can you opt out?
Users can unsubscribe from promotional emails and disable device-level location tracking. For broader data processing opt-outs or exercising statutory privacy rights (such as access or deletion), users must submit an email request to privacy@stability.ai.
Data retention
Stability AI retains personal data only as long as necessary for the purposes outlined in the policy, with a maximum retention period of one year unless a longer duration is required by law. Data is deleted, anonymized, or isolated in backups when no longer needed.
Encryption & security
The policy states that technical and organizational security measures are implemented to protect personal information, but it does not specify specific encryption algorithms, at-rest/in-transit standards, or compliance certifications.
Is it safe for work?
Exercise caution when handling confidential or proprietary business information. While Stability AI supports Data Processing Agreements (DPAs) where it operates as a processor, the standard privacy policy lacks specific details regarding AI model training on inputs and concrete encryption standards.
Source policy: https://stability.ai/privacy-policy