Loading page
We're getting it ready.
We're getting it ready.
An intimate image creates a durable object from a private moment. Problems can occur without deliberate sharing: phones may embed location data, photo libraries can sync, messaging apps make previews, accounts can be compromised, recipients save copies, and a person may be identifiable from tattoos, a room, a voice, or a reflection even when their face is cropped out.
Treat digital permission as a set of separate decisions: whether to capture, what appears, whose device is used, where the file is stored, who may receive it, whether it may be edited, how long it is kept, and what happens if someone changes their mind. Agreement to sext is not automatic permission to record a call, keep every image, train an AI model, post, forward, or show another person.
By Kink Tests editorial team
Make each permission explicit enough to act on. A useful agreement might allow one still photo on one device, exclude the face and identifying marks, forbid cloud upload and forwarding, and set a deletion date. Another may allow a live video call but no screenshots or screen recording. These are operational terms, not a promise that privacy technology can enforce perfectly.
Ask again when the plan changes. Switching from a photo to video may add voice and background audio. Moving from a private message to a group chat changes the audience. Editing can reveal cropped areas, create a more identifying composite, or turn an agreed image into a different depiction. Permission for the original does not silently travel with every derivative.
There is no single recording rule for every place. The Reporters Committee's guide to US recording law distinguishes one-party and all-party consent requirements and warns that interstate calls can engage more than one state's law. In England and Wales, Crown Prosecution Service guidance on section 66B describes separate offences for sharing and threatening to share intimate photographs or films, then directs prosecutors separately to the voyeurism offences in sections 67 and 67A. These are jurisdiction-specific examples, not a global test. Check the law that applies to the people, place, and medium before recording.
Do not record someone who is asleep, unconscious, unaware of the camera, or unable to make the decision. Discovery and sleep scenarios belong in fantasy or roleplay, not covert capture. Never create, request, possess, or share sexual images of anyone under 18.
Review the whole frame and audio, not only nudity. Faces, tattoos, scars, jewellery, work badges, mail, medication labels, family photographs, mirrors, windows, distinctive furniture, a partner's name spoken aloud, and sounds from a home or workplace can identify a person. A cropped face can remain visible in a reflection or original file.
Photos and videos may contain location metadata. Apple's current Photos guidance says embedded coordinates may be available to recipients and gives separate controls for removing a saved location, stopping collection, or omitting location when sharing. Google Photos distinguishes camera, added, and estimated locations: edits made inside Google Photos do not necessarily alter the original location sent outside that service, and visible landmarks can still reveal a place.
Use the controls for the device and service you will actually use, then inspect the outgoing copy. A plain background, covered identifying marks, and no work or home objects can reduce clues. Anonymisation lowers the chance of recognition but cannot make it impossible.
A file may exist in the camera roll, a hidden album, a recently deleted folder, cloud photo sync, device backup, messaging history, notification preview, editing app, shared album, recipient download, or another linked device. Deleting the visible chat message may leave several of these untouched. Before capture, inspect backup, sync, linked-device, and shared-library settings rather than relying on the word disappearing.
Use the minimum number of devices and services needed for the agreed purpose. Avoid shared household accounts, family photo libraries, work-managed phones, automatic shared albums, and apps whose retention or AI-training terms you have not read. Signal itself says disappearing messages are for tidying history, not an adversarial contact, because a recipient can photograph the screen with another camera.
Deletion has service-specific stages. Apple keeps deleted Photos items recoverable for 30 days unless they are permanently removed sooner; with iCloud Photos, deletion also reaches devices signed into the same Apple Account. Google Photos keeps backed-up items in the bin for 60 days and unbacked items for 30, and deletion there does not automatically remove copies in Drive, Gmail, or YouTube. Provider rules can change, and neither service can erase a recipient's independent copy.
Set a review date rather than promising perfect deletion. At that date, remove agreed copies from active storage, deleted-item folders, chats, shared links, albums, editing apps, and backups where the service permits it. Tell the other person what could not be removed. A credible deletion plan names locations and limits instead of saying the file is gone.
Use a strong device passcode and protect every account that can reach intimate material. The UK National Cyber Security Centre's current account advice recommends passkeys where available, or a unique password plus two-step verification, and calls for a separate password on the email account. Protect the primary email especially carefully because it can reset access to other accounts.
Review signed-in devices, recovery addresses, app permissions, shared albums, link access, and old sessions. Store recovery codes where another account user cannot reach them, and remove access that is no longer needed. A locked album inside an unlocked account is not a complete boundary.
Turn off sensitive notification previews on lock screens and shared computers. Check whether voice assistants, smart displays, casting, or desktop message mirroring can surface images to other people. Keep intimate media off employer or school systems, where administrators, retention rules, monitoring, or device return can put control elsewhere.
Someone may withdraw permission to keep or share an image even if capture was originally agreed. Respond without bargaining: stop new sharing, identify every copy you control, follow the deletion plan, revoke links, empty deleted folders, and confirm what was done. Withdrawal changes what the person permits; it cannot by itself guarantee technical erasure or establish the same legal remedy everywhere. If another recipient already has a copy, disclose that limit and ask them directly.
A breakup is not a new licence. Neither is anger, debt, infidelity, public posting by the subject, or previous permission to send the same image elsewhere. Do not use possession of intimate material to demand contact, money, sex, silence, or any other action. Preserve written boundaries about capture and distribution where that helps prevent later ambiguity, but do not turn the record itself into coercion.
If an account is compromised, change the password from a trusted device, secure the email and recovery methods, end other sessions, enable or reset MFA, revoke public links, and contact the platform. Tell affected people promptly and factually which files or messages may have been accessed.
If an intimate image is posted or threatened, preserve useful evidence before it disappears. Australia's eSafety Commissioner advises recording usernames or platform IDs, URLs, dates, messages, and earlier report details. Its formal report route applies when either the depicted person or the person who shared or threatened ordinarily lives in Australia. Avoid downloading or redistributing the intimate file itself more than necessary. Use the platform's intimate-image report route and keep the case number.
For adults who still have the image or video, StopNCII creates a hash on the user's device and sends the hash, not the file, to participating platforms. Those platforms can look for matches under their own policies. StopNCII cannot remove material from the whole internet or from services that do not participate.
In the United States, the Federal Trade Commission's May 2026 guidance says covered platforms must provide a request process and remove the reported nonconsensual intimate image and known identical copies within 48 hours of a valid request. A person can report a missing or failed process to the FTC. This is a US platform remedy, not a promise that search results, private messages, recipient devices, or every online copy will disappear.
If there are threats, extortion, stalking, account intrusion, or immediate danger, contact the relevant emergency or law-enforcement service and a local support organisation. Secure accounts before confronting a suspected intruder when confrontation could trigger more distribution. The person depicted did not cause the abuse by making or sending an image.
The privacy check below tests whether you can separate permission to capture, store, edit, and share; recognise identity and location clues; map cloud copies; and respond to a breach. It cannot guarantee that a recipient, platform, backup, or compromised account will behave as planned.
Before taking it, make sure you can name where the file may be copied, who controls each copy, which metadata and background clues need review, how access is protected, when deletion will be revisited, and what evidence to preserve if distribution occurs.
Use these questions to check how capture, storage, identity clues, and breach response differ. The review panel links back to any point you missed.
Answered 0 of 4
No. Receiving a message and making a new stored copy are separate actions. Ask explicitly about screenshots, screen recording, downloads, backups, editing, and showing anyone else.
Not necessarily. Tattoos, voice, room details, reflections, jewellery, clothing, metadata, landmarks, and context can identify a person. Review the complete file and acknowledge that de-identification reduces rather than eliminates recognition risk.
No. You can delete copies and links you control, but recipients, backups, synced devices, caches, or prior downloads may remain. A responsible deletion process maps those locations, removes what is controllable, and states any known limits honestly.