Short answer: Your prompts travel to a provider’s servers, where they are usually stored and occasionally reviewed by staff. In consumer products they may also train future models. Business tiers normally promise otherwise. Keep credentials, identity numbers and other people’s data out entirely, anonymise the rest, and check your settings twice a year.

Every message you type into an AI assistant leaves your device. It travels encrypted to a data centre, where a model reads it and writes a reply. The exchange is then usually saved to your account. What happens after that depends on the product, the tier and settings you have probably never opened.

A chat box feels private in the way a diary feels private. It is not a diary. It is one end of a connection to a company, governed by a policy you have not read. The law of a country you may not have considered decides what that policy must contain.

None of that makes assistants dangerous. The same description fits email, cloud storage and every search engine you have ever used. It does make them worth understanding, because the interface invites confidences no inbox ever did.

What happens after you press enter

The path is short and worth knowing. Your text is encrypted in transit using TLS, the transport layer security protocol that also protects online banking. It reaches a server, where the model turns it into tokens and generates a reply piece by piece.

The reply is not the end of the story. The exchange is normally written to a conversation history tied to your account. Alongside it sit metadata such as timestamps, device type and approximate location. The model itself is described in how AI chat assistants work. Privacy questions concern the service built around it.

Storage, retention and training are three different things

Most people collapse these into a single worry, and the confusion costs them the setting they actually wanted.

  • Storage means your chats are saved so you can return to them later. Turning history off usually stops this.
  • Retention means how long a provider keeps a copy after you delete it, including in backups and abuse logs.
  • Training means your text may become material for improving future models. In most products this is a separate switch.

Deletion is a process rather than a moment. Removing a conversation from your screen starts a clock. The privacy policy states how long that clock runs before every copy is gone.

Who can actually read a conversation

Very few people, and almost never at random. Most providers permit limited human review for two purposes: investigating suspected abuse, and checking quality on sampled or flagged conversations. Some also read chats that users report themselves.

Automated safety systems scan far more than humans ever do. That is a machine matching text against policy rules, not a person browsing your evening. Keeping the two apart keeps the worry proportionate.

Four myths worth retiring

Most anxiety about AI privacy attaches to the wrong thing. These four beliefs are common, and each is wrong in a way that matters.

  • Myth: the model memorises what I type and repeats it to the next user. Training happens in large, occasional runs, not live. Your sentence does not enter the model as you type it.
  • Myth: deleting the chat removes every copy at once. Deletion clears it from your view and starts a retention countdown. Backups and safety logs may hold a copy for a stated period.
  • Myth: paying for a plan guarantees privacy. Price and data handling are related but not the same. Contracts carry the strong promises, not price tags.
  • Myth: anonymising ruins the answer. Assistants reason over patterns, not identities. Swapping a named client for a client in retail changes almost nothing about the reply.

One genuine risk is easier to overlook. What you do with the output matters more, day to day, than what happens to the prompt. A fluent falsehood acted on without checking causes real harm, a failure anatomised in why chatbots make things up.

The do-not-paste list

A short list held firmly protects you better than a long policy skimmed once. Five categories cover nearly everything worth refusing.

  • Credentials and keys. Passwords, recovery codes and API keys. No good question requires them, and no answer improves because they are present.
  • Identity numbers and documents. Passport numbers, national insurance or CPR numbers, and full payment card numbers. These exist to unlock things.
  • Other people’s personal data. A colleague’s diagnosis, a friend’s address, a customer list. Consent does not transfer because the reader is a machine.
  • Confidential work material. Unreleased figures, client names and anything covered by a non-disclosure agreement.
  • Raw health and legal detail. These questions are legitimate and often useful. Ask them stripped of names, dates and identifying particulars.

How to anonymise a question without ruining it

Three substitutions do most of the work. Replace names with roles, exact figures with rounded ones, and specific dates with relative ones such as last quarter.

Then apply a simple test. If rebuilding the real situation from your prompt would take a detective, the prompt is safe enough to send. The same discipline governs sensitive audio, as described in privacy and security in AI transcription.

Tip: Before pasting a document, delete the signature block, phone numbers and client names. Ten seconds of editing removes most of the personal data in a typical work file.

The strongest privacy setting is the sentence you decided not to type.

Free, paid and business tiers are not one product

The same brand can offer very different data terms at different tiers. The pattern below holds across most major assistants, though every contract sets its own detail. Read the terms attached to the plan you are actually on.

TierTraining on your chatsRetentionWho sets the rules
Free consumerOften on by default, with an opt-outStated in the published policyYou, through account settings
Paid consumerFrequently the same terms as freeStated in the published policyYou, through account settings
Business or enterpriseNormally excluded by contractUsually shorter and configurableYour organisation’s administrator
Developer APINormally excluded by defaultShort, kept mainly for abuse checksThe developer, set in code

The gap between tiers is as much about data handling as about capability. That trade sits at the centre of our comparison of free versus paid AI tools. It is also why many employers buy staff a seat rather than allow personal accounts at work.

Six questions to put to any privacy policy

You do not need to read a policy the way a lawyer would. Search the document for six answers. It takes about five minutes.

  1. Training. Are my conversations used to train models, and can I opt out?
  2. Retention. How long is data kept, and what does deletion actually remove?
  3. Human review. When may staff or contractors read a conversation?
  4. Sharing. Which third parties receive data, and for what purpose?
  5. Location. Where is data stored, and which country’s law governs it?
  6. Notice. How will I be told when any of this changes?

A policy that hides these answers has told you something useful. For a plain-English grounding in your rights over personal data, the UK Information Commissioner’s Office maintains readable guidance for the public.

Settings worth changing today

Five minutes in the account menu removes most of the exposure this article describes. Look for these controls under privacy, data or personalisation.

  • Training or improve the model. Switch it off if you paste work material. Answer quality does not change when you do.
  • Chat history. Decide whether conversations are saved at all. Temporary chats suit one-off sensitive questions.
  • Memory or personalisation. Some assistants store facts about you across sessions. Read what has been saved and delete anything you did not intend.
  • Connected apps. Calendar, email and file storage integrations grant real access to real data. Remove any you no longer use.
  • Export and deletion. Find both before you need them, and note the timeline the provider states.

Tip: Put a twice-yearly reminder in your calendar to reopen these settings. Defaults move as products change, and a switch you set last year may have been renamed or reset.

At work, and with other people’s data

The moment a prompt contains information about someone else, you become a custodian and the standard rises. In Europe that duty has a name. The General Data Protection Regulation treats personal data as something you process on a lawful basis, not something you simply hold.

What your employer’s policy probably says

Many organisations now publish an AI-use policy. It usually names approved tools, forbids client and personnel data in prompts, and requires a human review before anything is published or sent.

If your employer has such a policy, it outranks any general advice, including this article’s. If there is none, the habits here are a defensible default. Regulated professions in medicine, law and finance carry confidentiality duties that no tool’s convenience suspends.

Recordings deserve their own rule. Meeting audio, interviews and voice notes contain other people’s words, so ask before you process them. Our own procedure for transcribing an interview treats consent as step one rather than a formality.

Institutions are converging on the same themes. The US standards body NIST publishes an AI Risk Management Framework for organisations deploying these systems. Dozens of governments have adopted the OECD AI Principles, and the European Union’s AI Act is phasing in duties for providers.

You need not read any of them to use an assistant well. Their existence still matters, because published standards are how an industry turns promises into checkable claims. That is the same logic we trace in what a Swiss Made label teaches about quality standards.

Habits that survive a busy week

Rules fade under deadline pressure. Habits hold. These six take moments each and cover almost every risk named above.

  1. Minimise by default. Share the least context that still produces a good answer. Most questions need far less than we instinctively give.
  2. Anonymise before you paste. Roles instead of names, rounded figures instead of exact ones, relative dates instead of real ones.
  3. Separate your accounts. Work questions through work tools, personal questions through personal ones. Mixing them lets one set of terms govern both lives.
  4. Verify what matters. Trace names, numbers, citations and legal claims back to a source that can be held to account.
  5. Ask consent for other voices. Recordings and message threads belong to more than one person.
  6. Keep a human in the decision. An assistant may inform a choice about money, health or law. It does not get to make it.

These habits sit alongside the practical uses, not against them. The inventory in everyday tasks an assistant can do today assumes exactly this discipline, and more of the subject is gathered under AI privacy.

Key takeaways

  • Know which switch you need. Storage, retention and training are three separate things, controlled separately in most products.
  • Hold the do-not-paste list. Credentials, identity numbers, other people’s data, confidential work material and raw personal detail stay out.
  • Anonymise instead of avoiding. Roles, rounded figures and relative dates keep almost any question askable.
  • Interrogate the policy for six answers. Training, retention, human review, sharing, location and change notice.
  • Read the tier, not the brand. Business contracts, not price, carry the strong data promises.

The ground under these tools is firming. Regulators are engaged, standards bodies have frameworks in print, and providers now compete on privacy controls as openly as on capability. For broader technique, the Electronic Frontier Foundation’s Surveillance Self-Defense guides remain the standard reference.

None of that replaces the decision you make in the second before pressing enter. A chronometer earns its certificate through days of observed testing, then keeps that trust through routine. Extend your tools the same deal, whether on a free service such as ASKAI.FREE or a paid one.

Let them earn confidence task by task. Verify what matters as you go, and keep the consequential choices where they have always belonged. Everything else in the AI Assistants hub assumes that habit is already in place.