AI privacy
Not a legal course on data protection law — the practical question almost nobody stops to ask: what actually happens after you hit send?
The question worth asking before you paste something in
Most people think about AI privacy the moment they're typing, and never again. The more useful question comes after: where does this go once it's sent, how long does it stay somewhere, who else at the company behind the tool can potentially see it, and could it ever end up shaping how the underlying model responds to someone else entirely. Different tools answer these questions differently, and the honest answer is usually buried in a settings page or a privacy policy nobody reads — which is exactly why it's worth knowing what to look for.
What "AI privacy" actually covers
In plain terms: how personal and sensitive information is collected, stored, used, and protected specifically in the context of an AI tool — from the moment you type something in, through however long it's retained, to whatever happens to it afterward.
Why it actually matters
AI tools tend to get fed exactly the kind of information people are usually more careful with elsewhere — draft contracts, internal strategy, health questions, financial details, other people's personal information pasted in for context. The convenience of a chat box makes it easy to forget that the same sensitivity rules that apply to email or a shared document still apply here.
What data AI tools typically touch
What you type
The actual content of a prompt or upload.
Account information
Email, usage history, billing details tied to an account.
Usage patterns
How often and how a tool gets used, even without reading the content itself.
The risks worth actually knowing
Oversharing
- Pasting more sensitive context than the task actually required
Retention you didn't expect
- Data kept longer, or used more broadly, than assumed
Third-party exposure
- Information flowing to a vendor or partner nobody flagged
What individuals can actually do
What organizations need to manage deliberately
Which tools are even approved for use with customer or employee data is itself a governance decision — see AI Governance for the policy layer this sits inside. On top of that: contractual guarantees about data handling, and a clear answer for employees about what's actually safe to paste into which tool.
Common privacy mistakes
Pasting a client contract into a free public tool to "just get a quick summary." Assuming a company AI subscription automatically means enterprise-grade data handling, without checking. Never reading the one setting that would have turned off data use for training. Small, avoidable, and depressingly common.
What "privacy by design" actually means
Building privacy protection into a system from the start — data minimization, clear retention limits, opt-outs that are easy to find — rather than bolting protection on after a problem surfaces. It's a design philosophy, not a checklist added at the end.
The short version
Treat every AI tool the way you'd treat a new coworker with an unknown track record: don't share more than the task genuinely requires until you actually understand where it goes. Check the settings, strip what's identifiable, and default to caution with anything free and consumer-facing. Nothing here requires legal expertise — mostly just remembering to ask the question before pasting, not after.