The Cat-Photo App Is Not the Story. The Data-Retention Answer Is.
Every few weeks a novelty AI app hits Product Hunt, gets a few hundred upvotes, and disappears from the collective memory of the e-commerce crowd. Most of them deserve that fate. But Humans Not Invited — a small “what would you look like as a cat” generator launched by maker Damjanski — is worth ten minutes of your attention, not because you should build a cat filter, but because of one exchange buried in its comment thread. A commenter asked how long uploaded photos stick around. The maker answered that source images are deleted immediately and no data is saved. That single sentence is the difference between a viral toy and a compliance liability — and it is exactly the question most cross-border sellers are not asking about the AI tools they already have wired into their storefronts.
If you sell on Shopify, run ads on TikTok Shop, or manage listings inside Amazon Seller Central, you are already running customer photos, UGC, and AI-generated creative through third-party pipelines. The regulatory surface under those pipelines is shifting fast, and the operators who understand data-retention semantics will be the ones who don’t get caught flat-footed. This essay is about what this tiny launch accidentally teaches about that.
What This Product Actually Does — And Why the Boring Part Matters
Humans Not Invited is a consumer-facing image generator. You upload a photo, it produces a “Purrtrait” of you (or a friend) as a cat. That’s it. No dashboard, no API, no seller tooling. The maker’s own framing in the thread is playful — ASCII cats and emoji replies throughout.
So why am I writing about it in a cross-border context? Because the product’s operational decisions are the interesting part, and they map directly onto decisions you make at scale.
Three things stand out:
First, the retention model. When Gal Dayan — who builds Dial — asked specifically whether the source photo is “deleted right after processing, or kept for anything else like improving the model,” the answer was unambiguous: deleted right away, nothing saved. Dayan’s reply is the tell: “that’s the answer that would make me comfortable actually uploading a friend’s photo instead of just my own.” Consent to upload someone else’s face hinges entirely on that answer.
Second, the social-sharing loop. Multiple commenters, including Christian Onochie and Oren Reuveni, flagged the same thing: this is the kind of product people send to friends. Reuveni called it “fun, clear, and sticky.” That’s a distribution mechanic, not a feature.
Third, the low-friction input. One image in, one image out. No account wall described, no onboarding described.
For a cross-border seller, each of these is a transferable design principle. Let me take them one at a time.
Why Amazon sellers should care more than Shopify ones
Here’s my judgment call, and it’s a strong one: if you sell on Amazon, this category of tooling matters to you more than to a standalone DTC operator, not less.
The reason is structural. A Shopify merchant controls their own data-processing agreements, their own privacy policy, their own consent flows. An Amazon seller operates inside a platform that already imposes its own data-protection requirements on how you handle buyer information, and where any customer photo you touch — for a review request, a UGC ad, a packaging insert QR flow — sits inside someone else’s compliance perimeter. When you then push that photo through a third-party AI tool, you’ve added a processor to a chain you don’t fully control.
TikTok Shop operators face a similar squeeze, compounded by the fact that TikTok’s own ad creative tools increasingly generate synthetic variants of user content. The retention question isn’t academic there either.
The cat app’s maker got the right answer out in public, in a comment thread, before anyone had to file a request. Most B2B SaaS vendors you’re paying won’t volunteer it. That asymmetry is the whole point.
How It Differs From the Incumbents You’re Actually Using
Let’s be concrete about the comparison set, because “AI image tool” is meaningless as a category.
If you’re generating product creative today, you’re probably touching one of: Canva with its Magic Studio features, Adobe Firefly, Midjourney, or one of the e-commerce-specific players like Photoroom or Flair.ai. On the listing-optimization side you might be running Helium 10 for research and something else entirely for creative. On the retention side, Klaviyo holds your email and SMS data, and your ESP’s data-processing addendum is a document you probably signed without reading.
Here’s how Humans Not Invited differs from that entire stack, in ways that are instructive:
- It’s a single-purpose tool with a stated deletion policy. Most creative suites bury retention in a DPA. This one put it in a comment.
- It optimizes for virality, not workflow. Canva and Photoroom optimize for repeat professional use. This optimizes for one-shot shareability.
- It has no account layer described. That’s a friction decision, and it’s the opposite of what B2B SaaS does.
The lesson isn’t “be like the cat app.” The lesson is that a clear, publicly stated data-handling posture is now a marketing asset, not just a legal checkbox. Dayan literally said it changed his upload behavior. That’s conversion impact.
Where the math breaks
Before anyone gets excited about building a UGC-driven viral loop off this model, run the numbers honestly.
Viral consumer apps monetize through ads or one-off purchases, and the unit economics are brutal: you need enormous volume to cover inference costs on image generation. The maker hasn’t disclosed pricing, revenue, or user numbers — and I’m not going to invent them. But structurally, a free or near-free one-shot generator with immediate deletion has no data moat, no retention hook, and no upsell surface. It’s a delightful toy with a clean privacy story and almost no defensibility.
For a seller, that’s fine — you’re not trying to build this, you’re trying to borrow from it. For an investor or a founder, the math is much worse than the launch-day enthusiasm suggests.
What Cross-Border Sellers Should Actually Borrow
Strip away the cats and there are four transferable moves here.
1. Turn your data-retention policy into customer-facing copy. If you collect UGC, run a “see it on you” AR feature, or ask buyers to submit photos for a review-with-image incentive, say plainly what happens to those photos and when they’re deleted. Put it next to the upload button, not twelve clicks deep in a privacy page. The Dayan exchange proves this changes behavior.
2. Default to immediate deletion for any image you don’t need. Your returns workflow, your QC photos, your packaging-inspection shots — most of these have no reason to persist. Build the deletion into the pipeline rather than relying on a policy document.
3. Treat third-party AI vendors as processors, and demand the answer in writing. When you evaluate the next creative tool, the next listing optimizer, the next chatbot for your Etsy or eBay store, ask the retention question before you sign. If the vendor can’t answer in one sentence, that’s your answer.
4. Design for the share, not the session. Reuveni’s “people actually send to friends” observation is the growth mechanic. Whatever tool you build or buy, ask whether the output is inherently shareable. A generated product mockup isn’t. A personalized “here’s you as X” is. That’s a creative brief, not a technical one.
The compliance angle nobody wants to hear
Cross-border adds a layer most US-only operators ignore: GDPR retention-minimization principles, CCPA deletion rights, and the patchwork of marketplace-specific rules. If you’re selling into the EU from a Temu or SHEIN storefront, or running SHEIN Marketplace listings, your buyer-photo handling is squarely in scope.
The cat app’s approach — delete immediately, save nothing — is the simplest possible compliance posture. It’s also the cheapest to defend. You don’t need a data-retention schedule if you have no data to retain. That’s not a legal strategy I’d recommend for your order database, but for peripheral creative inputs, it’s genuinely elegant.
Where My Judgment Says It Falls Short
I want to be fair to the product and honest about the category.
The privacy answer is only as good as the implementation. “We delete it right away” is a claim, not an audit. There’s no third-party verification described, no SOC 2 mention, no independent review. For a consumer toy, fine. For anything you’d wire into a commercial pipeline, you’d need more than a maker’s comment-thread assurance.
The product has no cross-border story. Nothing in the launch suggests localization, regional data residency, or multi-language handling. If you’re an operator in Southeast Asia or LATAM, this isn’t built for you, and that’s a gap the maker may or may not care about.
The virality is assumed, not proven. Commenters say they’d share it. That’s not the same as sharing. Launch-day enthusiasm on Product Hunt is a notoriously poor predictor of retention, and there’s no disclosed metric here to contradict that.
And the bigger miss: the maker had a genuinely differentiated privacy stance and buried it in a reply to one commenter. If deletion-on-processing were the headline — not the cat — this would be a more interesting launch. That’s a positioning lesson for every seller reading this: your best differentiator is often the thing you treat as a footnote.
What I’d Watch / Test Next
This week, do three things.
First, pull the data-processing addendum from your top three SaaS vendors — your ESP, your creative tool, your chatbot — and find the retention clause. If you can’t find it in under five minutes, email support and ask. Log the answers in a spreadsheet. You’ll be surprised how many say “indefinite.”
Second, if you run any UGC or photo-upload flow, add a one-line deletion statement next to the upload button and A/B test it. Dayan’s comment is your hypothesis: clarity increases uploads. Measure it.
Third, when you evaluate your next AI creative tool, add “immediate deletion of source inputs” as a scoring criterion alongside price and output quality. Watch how many vendors fail that filter.
The cat app will be forgotten by next month. The retention question it accidentally surfaced won’t be. Operators who internalize that now will be running cleaner, more defensible stacks when the next round of platform audits lands — and they’ll have the vendor answers already on file.






