BelltoAn AI agent that takes a brand's POP campaign from brief to shop drawings.The AI agent for POP campaigns.Get on the waitlist
← back to blog

Can I Put My Client's Artwork Into an AI Display Tool?

September 25, 2026··9 min read

The question that stops most manufacturers before they try an AI tool isn't about image quality. It's whether they're allowed to. The brief on the desk is for a launch that doesn't exist publicly yet. The pack shots are unreleased, the key visual is under embargo, and there's an NDA with the brand sitting in a drawer. Uploading any of that to a website feels like leaking it.

The short answer is yes, you can, when the tool's terms say in writing that your uploads aren't used for training, aren't shown to anyone else and aren't licensed back to the vendor. And the part almost nobody tells you is that this depends on the account type far more than on the brand. The same vendor can train on what you upload with a personal account and contractually exclude it on a business one.

I've worked in point-of-purchase for close to four years and I build AI POP Displays, so I've had this conversation many times. Below is what each kind of tool does with an upload, as its own terms describe it today, and what to ask for first.

What actually happens to an image when you upload it?

Five different things can happen to a file you upload to an AI tool, and the privacy question is really five questions.

It gets stored. Almost every tool keeps your upload and its output to show them back to you.

It gets logged for abuse monitoring. Even vendors that promise not to train keep inputs for a limited time to detect misuse. That's normal and usually fine under an NDA, as long as the period and the purpose are written down.

Humans can read it. Some tiers let reviewers look at inputs and outputs to improve the product. For unreleased packaging, that's the one that matters most, because a person outside the NDA sees the artwork.

It trains the model. Your client's key visual becomes a small part of what the model learns from. It won't come back as a copy in someone else's render, but it has left the circle of people bound by the NDA.

It becomes visible or licensed. Some tools publish what you make by default, or take a broad license over your inputs. That turns a confidentiality problem into a disclosure problem.

When you read a vendor's terms, you're looking for their answer to each of those five, for the plan you're actually on.

Why does the account type matter more than the brand?

Because the big vendors write different rules for different tiers, and the defaults run in opposite directions.

Google Gemini. The Gemini API terms split into unpaid and paid services. On unpaid services, Google uses the content you submit and the responses to provide, improve and develop its products, and human reviewers may read, annotate and process your input and output. On paid services, Google doesn't use your prompts or responses to improve its products and logs them for a limited period only to detect policy violations. The consumer Gemini app is a third set of rules. Keep Activity is on by default for users 18 and over, uploads can then be used to improve Google's services with human reviewers, and conversations that get reviewed are kept for up to three years. Google Workspace accounts are covered by a separate commitment not to use Workspace data to train the models behind Gemini.

OpenAI. On personal ChatGPT accounts, OpenAI may use your content to train its models, and the opt-out is a toggle called Improve the model for everyone that you have to switch off yourself. Temporary Chat keeps a conversation out of training, though OpenAI may hold a copy for up to 30 days for safety. ChatGPT Business, Enterprise and the API are excluded from training by default, and API inputs and outputs are retained for up to 30 days for abuse monitoring.

So a designer on a personal ChatGPT or Gemini account and one on a company business account are in different positions with identical files, and most never check which one they're in.

What do design and image platforms do with your uploads?

The creative tools split along the same line between free and paid, and a couple add a visibility problem on top.

Midjourney. Its terms say your content is publicly viewable and remixable by default. Stealth mode, which controls who can see your images on the Midjourney website, is only on the Pro and Mega plans, and Midjourney's own docs note that anything made in public Discord channels stays visible even with it on. The terms also grant Midjourney a perpetual, worldwide, irrevocable license over the content you input, uploaded images included, and the assets you produce.

Vizcom. On the free Starter plan, Vizcom's terms say it retains all right, title and interest in the designs you create, and that Starter content may be used to train its services. Paid accounts are excluded: the terms state that Vizcom doesn't use your content or designs to train its AI models. The cheapest paid plan is $49 per user per month, so on Vizcom privacy is a paid feature. I went through that in detail in AI POP Displays vs Vizcom.

Krea. Its terms say that if your subscription tier doesn't include private mode, some of what you submit may be viewable by other users. The explicit no-training clause on its pricing page sits on the Business plan.

Adobe Firefly. Adobe's Firefly FAQ says it doesn't train on Creative Cloud subscribers' personal content. Separately, it runs content analysis for product improvement, which you can switch off, with listed exceptions such as beta programs.

None of these tools is built for POP displays or POP materials, and the pattern repeats. The free or entry tier is where training, public visibility or broad licenses tend to live, and privacy arrives with a paid plan.

That's the pattern I didn't want for display work. If a client's unreleased launch is on your desk right now, AI POP Displays starts free and the free plan carries the same no-training rule as the paid one.

What should you ask a vendor for in writing?

This isn't legal advice, and your NDA is the document that decides. But these are the questions I'd want answered in the terms of service for the exact plan, not in a banner on the homepage.

  1. Training. Are my uploads and outputs used to train or improve any model, yours or a provider's? Does the answer change by plan?
  2. Human review. Can anyone at the vendor, or at a model provider they call, read my inputs and outputs? Under what conditions?
  3. Retention. How long do you keep inputs, outputs and logs, and for what purpose? What happens when I delete them or close the account?
  4. Visibility. Is anything I make public, remixable or shown in a gallery by default? What does private cost?
  5. License. What rights do I grant you over my inputs and outputs? Is it limited to delivering the service, or is it perpetual and sublicensable?
  6. Subprocessors. Which model providers receive my files, and on what terms (paid API, consumer, business)?

The trap to avoid is reading a vendor's marketing page and stopping there. A line like we never train on your designs can be true of the paid plans and not of the free one, as the Vizcom terms above show, and only the terms tell you which.

What does AI POP Displays do with your client's artwork?

Almost every display concept is client work under NDA, so these answers are fixed for every account, on every plan, including the free one.

No training, ever. Briefs, reference images, pack shots and renders are never used to train AI models, on any plan.

Private by default. Uploads go into storage scoped to your account, hosted in the EU. Images are served through signed links that expire within hours, and a render is visible only to you.

Sharing is yours to control. A client sees a render only through a share link you create for it, and you can revoke that link at any time. We store only a hash of the link, so a revoked link stays dead.

Paid API terms for generation. AI POP Displays runs on Google's Nano Banana Pro, and our model calls go through paid API terms, where Google's terms say content isn't used to improve its products and OpenAI's say API data isn't used for training by default.

Deletion that means it. Our terms limit the license you grant us to storing, processing and showing your files back to you. Request deletion and your account data goes within 30 days, except tax records the law makes us keep.

That's where privacy sits in the product. The work sits in the layer on top of the model: display formats with real proportions, materials that behave, product load from the real packs, references labeled by role with the sketch last, and a briefing step that reads the client's email. The how is in Nano Banana Pro for retail display design. If the brief on your desk is the confidential one, put it through the free plan with the same protections a paying account gets.

What should go into the client contract?

The NDA with the brand was probably written before anyone thought about AI tools. Say which tools you use and on which account type. A line stating that concept renders are produced with an AI tool whose terms exclude training on client materials, and naming it, answers the question before the brand's legal team asks. Ask whether the client has its own AI policy. If it has one, check where it draws the line between consumer accounts and business tools with written terms. And keep the terms page you relied on, dated, with the project file. If a question comes up a year later, you want the version that was in force when you uploaded.

The ChatGPT comparison covers the consumer versus business split for one vendor in more depth, if your team is still on personal accounts.

Where to go from here

Uploading a client's artwork is fine with a tool whose terms, for the plan you use, rule out training and public visibility and limit the license to delivering the service.

The concept is only the first place a client's artwork goes during a launch. What we're building next is Bellto, an AI agent for brands and agencies that takes a POP campaign from brief to shop drawings. You tell it what you're launching (brand, product, channel, stores, budget, date) and it asks for what's missing, proposes the campaign mix and materials with the budget split per store, and designs every piece with you at real scale in parametric 3D, with proportions derived from the product and the facings. Every approved piece comes out as a 3D model, a part-by-part cutlist, dimensioned drawings, a STEP of the assembly and a cut DXF per part, a package a workshop can quote without redrawing, and it suggests manufacturers that fit by material, format and volume. We're building it now. The waitlist is open to any brand, we're contacting the first ones soon to run the first real campaigns end to end, and it opens by invitation, in small groups, with the campaign you describe when you sign up setting your place. Pricing goes first to the people on the list, and there's no card.

For the display concept on your desk this week, AI POP Displays is free to start with 15 one-time credits and no card required, then Pro Beta is $49 a month for 150 concept generations at the founding price, with the $69 list price stated openly. The no-training rule is the same on both. Start with the confidential brief, and if the campaign behind it has to reach a workshop, put it on the Bellto list.

Frequently asked

Is it safe to upload a client's artwork to an AI image tool?

It depends on the account, not on the brand. Google's Gemini API terms say content sent through unpaid services is used to improve Google's products and may be read by human reviewers, while paid services content isn't used to improve them. OpenAI trains on consumer ChatGPT content unless you opt out, and doesn't train on Business, Enterprise or API data by default. Midjourney makes content publicly viewable by default. Check the terms of the exact plan you're on before a client's unreleased packaging goes in. AI POP Displays doesn't train AI models on anything you upload or render, on any plan.

Does ChatGPT or Gemini train on images I upload?

On personal accounts, by default, yes for both. OpenAI's help center says it may use content from ChatGPT to train its models unless you turn off Improve the model for everyone. Google says Keep Activity is on by default for Gemini app users 18 and over, and that uploads can then be used to improve its services with the help of human reviewers, with reviewed chats kept for up to three years. Business, Enterprise and API accounts from both vendors are excluded from training by default.

What should I ask an AI vendor for before using it on NDA work?

Five things, in writing, for the plan you'll actually use. Whether uploads and outputs are used to train or improve models. Whether humans can review them. How long they're retained and for what. Whether anything you make is visible to other users by default. And what license you grant the vendor over your inputs and outputs. A marketing page that says we never train on your data isn't enough; the answer lives in the terms of service for your tier.

Where does my client's artwork go in AI POP Displays?

Into private storage scoped to your account, hosted in the EU. Image links are signed and expire within hours, renders are visible only to you, and a client sees one only through a share link you create and can revoke. Generation runs on paid API terms, and nothing you upload or render trains AI models, on any plan including the free one. On a deletion request, account data and renders go within 30 days, except tax records the law makes us keep.


Start generating Get on the Bellto waitlist
Can I Put My Client's Artwork Into an AI Display Tool? — AI POP Displays