Earlier quoted context omitted.
It would be pretty easy to do a packet inspection and see if they're telling the truth about not transmitting the photos.
And how does one do packet inspection: * if packets are only sent via carrier, not wifi * if packets are sent to aws instances, which is very common * if it all stops when phone is rooted, which is common for many apps
* Gov't is mandated to use AWS Gov instances which are quite easy to distinguish [2].
* there are ways to bypass those rootchecks to make a rooted phone seem not rooted [3].
[1] https://en.wikipedia.org/wiki/Deep_packet_inspection#United_...
[2] https://aws.amazon.com/blogs/security/aws-govcloud-earns-dod...
[3] https://stackoverflow.com/questions/68661134/root-detection-...