The profile picture will always contain a URL that does not include personal information and cannot be guessed, such as https://avatars.sso.mozilla.com/30a3adbcec1fd914507f7e11.png.
This picture URL is available to all reliers (Google, Slack, and other applications). We cannot control what these services do with the picture (because we do not own them). For this reason, the picture URL will show an Identicon unless you set the visibility level of your uploaded image to Public.
This mechanism allows users to keep their privacy while retaining compatibility with applications implementing Mozilla IAM for authentication. All reliers will get a profile picture URL, which holds either an Identicon or your actual picture.