Guide · privacy-security
What to Check Before Trusting an AI Tool With Your Data
Before you paste sensitive information into an AI tool, a short checklist for understanding what happens to your data, who can see it, and how to reduce your exposure.
Assume nothing, read the policy
The convenience of AI tools makes it easy to paste in whatever you are working on without thinking about where it goes. Before you do that with anything sensitive, spend a few minutes understanding the tool's data practices. The relevant details live in the privacy policy, terms of service, and any documentation aimed at businesses, and they are worth reading rather than assuming the defaults are in your favour.
Is your input used to train models?
The first question is whether the content you submit is used to improve the provider's models. If it is, fragments of your input could, in principle, influence future outputs seen by others, and you have effectively contributed your data to the product. Many providers now let you opt out of training, and business tiers often disable it by default, but you should confirm rather than hope. If a tool trains on your inputs and offers no way to stop it, treat everything you type as potentially non-private.
How long is data kept, and where?
Retention matters as much as training. Find out how long your inputs and outputs are stored, whether you can delete them, and where they are physically held. Data location can carry legal implications depending on your jurisdiction and the nature of the information. Short, controllable retention is preferable; indefinite storage with no deletion option is a reason for caution with anything sensitive.
Who can access it?
Understand who inside the provider can view your data and under what circumstances. Some services allow staff to review content for safety or debugging, which may be reasonable but is worth knowing. Look for encryption in transit and at rest, access controls, and independent security assessments. For business use, features like single sign-on, audit logs, and role-based permissions indicate a tool built with organisational security in mind.
Match the tier to the sensitivity
Free and personal tiers frequently have weaker data guarantees than business or enterprise tiers of the same product. If you intend to handle confidential material, the consumer version may not be appropriate even if the underlying capability is identical. Providers often reserve stronger contractual commitments, such as agreements about data handling and processing, for paid business plans.
Regulatory and contractual obligations
If you operate under privacy regulations or handle categories of data with special protections, your obligations extend to the tools you use. Check whether the provider will sign the agreements you need, whether it offers the certifications your industry expects, and whether its practices are compatible with your commitments to your own customers. When in doubt, involve the people responsible for compliance before adopting a tool widely.
Reduce exposure by habit
Whatever a tool promises, you lower your risk by sending it less. Remove names, identifiers, and secrets from inputs when they are not needed, avoid pasting credentials or regulated data into general-purpose tools, and prefer tools that keep data within your control for your most sensitive work. A simple internal rule about what may and may not be entered into AI tools protects you more reliably than any single policy you read. The goal is not fear, but informed choices: know what happens to your data, then decide deliberately what you are comfortable sharing.