privacysecurityintellectual-propertyfile-sharingcompliance

Can Your File Sharing Service Train AI on Your Files?

·7 min read·Comfyfile
Can Your File Sharing Service Train AI on Your Files?

In July 2025, WeTransfer updated its terms of service in a way that read as if the company could train AI models on uploaded files. The clause granted WeTransfer the right to "reproduce, distribute, modify" or "publicly display" files, and referenced using content to "improve performance of machine learning models that enhance our content moderation process." Creatives on social media read that as a quiet attempt to feed user work into AI training, and the backlash was immediate. Illustrators and actors who relied on the service to send client work said they were looking elsewhere.

WeTransfer moved quickly. A spokesperson confirmed to the BBC that the company "don't use machine learning or any form of AI to process content shared via WeTransfer, nor do we sell content or data to any third parties," and explained the clause was originally added to cover AI-assisted content moderation. Within days the wording was rewritten to a narrower royalty-free licence for "operating, developing, and improving the Service," with the machine learning and derivative works language removed. You can read the full BBC coverage of the WeTransfer AI backlash for the details.

In this particular case, no files were used to train anything. The clause was withdrawn and clarified. But the episode surfaced something that lasts longer than any one news cycle, and it applies to every file sharing service on the market. Almost nobody knows what rights they have handed over to the tools they use every day. The wording that decides it is usually written to be skimmed past.

Why this clause exists at all

It is tempting to call this a story about companies being sneaky. It is more complicated than that.

Every service that stores your file needs some kind of licence from you to do its job. To store a file, the company technically needs the right to make a copy. To show you a thumbnail, it needs the right to create a derivative. To send the file to your recipient, it needs the right to distribute it. Without that licence, running the service would amount to copyright infringement.

So a clause that grants the provider rights over your content is not automatically sinister. It is necessary. The real question is about scope.

A well-drafted clause is narrow. The rights are granted only to the extent needed to provide the service, and they end when you delete the file. A badly drafted clause is broad. It is perpetual, irrevocable, sublicensable, worldwide, and for any purpose. Often that second kind is just lazy legal boilerplate copied from a template. The problem is that it reads exactly like a deliberate rights grab, and you have no way to tell which one you are looking at.

The four phrases to look for

You do not need to read the whole document. Open the terms, search for the content or licence section, and look for these four phrases.

"Perpetual" or "irrevocable." These words mean the rights survive after you delete your files and close your account. A licence that ends when you delete the content is normal and reasonable. One that never ends is not.

"Sublicensable" or "transferable." This lets the company pass your rights to someone else, including a company that buys them later. Given how often file services change hands, this matters more than it used to.

"Derivative works." Necessary for thumbnails and format conversion. Also the phrase that covers training a model on your content. Context is everything, and vague context tends to favour the drafter.

"For any purpose" or "including but not limited to." This is open-ended scope. A clause that ties the licence to "providing and improving the service" is bounded. One that does not tie it to anything is not.

Then check two more things: how a change of ownership is handled, and how you get notified of terms changes. Both matter more and more in a market where file sharing companies get acquired on a regular basis.

Two people reviewing and signing printed documents at a desk

What good wording looks like

For contrast, a reasonable content clause says something close to this:

You retain all rights to the content you upload. You grant us a limited, non-exclusive licence to store, process and transmit your content solely for the purpose of providing the service. This licence ends when you delete the content or close your account.

Four features make that acceptable. The licence is limited rather than unrestricted. It is tied to a specific purpose. It terminates. And it does not mention sublicensing.

If the terms you are reading contain something recognisably like that, you are fine. If they run four paragraphs and include the word "worldwide" three times, slow down.

Why this matters more for some files than others

Be proportionate about this. If you are sending holiday photos to your sister, the licence terms genuinely do not matter.

They matter a great deal in a few specific situations.

Client work under NDA. If you have signed an agreement promising to protect a client's confidential information, uploading it to a service with unlimited content rights arguably conflicts with that promise. Your client's lawyer, not yours, is the one who will care.

Unpublished creative work. Illustration, photography, music, unreleased campaigns. The value is in the exclusivity.

Anything patentable. Public disclosure can affect patent rights in ways that are difficult to reverse. Technical drawings and prototype documentation belong in a service whose terms you have actually read.

Personal data belonging to other people. Your obligations here come from data protection law, not from the vendor's terms, and you cannot outsource them. Our guide to GDPR considerations in file sharing covers what that means in practice.

For everything else, use whatever is convenient. Not every decision needs to be a security decision.

The structural answer: reduce what you are trusting

Reading terms carefully is worth doing. It is also fragile, because terms change and companies get sold.

The more durable approach is to reduce how much the vendor's promises matter in the first place.

Encrypt before uploading. A password-protected 7-Zip archive is unreadable to the provider regardless of what their terms permit. This is the single most effective step available to you, it takes thirty seconds, and it works with every service. Send the password through a separate channel.

Use end-to-end encrypted services for the most sensitive material. With true end-to-end encryption, the provider is technically unable to read your files, which makes the licence question mostly academic. Zero-knowledge file sharing explains how that architecture works and what it costs you in convenience. Comfyfile does not offer end-to-end encryption, so if that is your requirement, look at Proton Drive or a similar provider.

Set short expiry windows. A file that no longer exists cannot be used for anything. Auto-expiry is a privacy control, not just a housekeeping feature.

Keep sensitive work off free ad-supported tiers. The economics of a free service have to work somehow, and understanding how is part of the decision. We looked at that in the hidden costs of free file hosting.

What the episode should actually teach us

The 2025 story ended reasonably. The clause was withdrawn quickly, the company explained itself, and no customer content was used to train a model.

So the lesson is not that any particular service is untrustworthy. It is that a two-sentence edit to a document nobody reads can change the status of every file you have ever uploaded, and that most professionals had no idea what rights they had already granted to the tools they use daily. That is true across the category, not at one company.

Fifteen minutes with the terms of the three services you use most is a genuinely good use of your time. Search for "licence", read that section, and note whether the word "perpetual" appears. That is the whole exercise.

How Comfyfile Can Help

Comfyfile's design reduces how long your files exist in the first place. Every share carries an expiry you set, up to 7 days on a free account and up to six months on Pro, after which files are removed rather than retained indefinitely. Files are stored on EU-based servers with private access control, and downloads run through short-lived links rather than permanently public URLs. For genuinely sensitive material, encrypting the archive before upload remains worth doing on any service, including this one.

Related Reading

Share this article

Ready to share files securely?

Experience password protection, auto-expiry, and download limits with Comfyfile

Start Sharing Free