The honest summary: it is probably fine, and you should still develop a few habits. Privacy conversations about AI tend to swing between “they’re reading everything” and “it’s completely private,” and neither is accurate.
What actually happens
When you type something into a mainstream assistant, it goes to that company’s servers to be processed. It is generally stored against your account. Depending on the provider and your settings, it may be used to improve their systems, and a small amount of content may be reviewed by staff for safety and abuse monitoring.
None of that is sinister — it’s roughly how most cloud services have always worked. But it does mean the right mental model is a work email, not a diary.
Five habits that cover most of it
- Turn off training, once. Nearly every major assistant has a setting that stops your conversations being used to train future systems. It usually lives under data controls or privacy in settings. One minute, day one, done forever.
- Strip identifying details. You almost never need the real name, the account number, or the address for the assistant to help. “A client” works as well as their name and removes most of the risk.
- Don’t paste other people’s private information. Your own risk is yours to take. Someone else’s medical situation, financial details, or private correspondence is not.
- Check your employer’s policy before work documents. Many organisations now have one, and finding out afterwards is a bad way to find out.
- Keep the genuinely sensitive out entirely. Passwords, full financial records, legal matters under privilege, anything you’d be seriously harmed by seeing leaked. Not because a breach is likely, but because the cost is asymmetric.
What’s fine to put in
Most things, honestly. Drafting a letter, understanding a document you’ve anonymised, organising your notes, learning something, working through a decision in general terms. The overwhelming majority of daily use carries very little risk, and it’s worth saying that plainly so the caution above stays proportionate.
If you need more than that
There is a version of this that runs entirely on your own computer, where nothing is transmitted anywhere. It’s slower, a little more work to set up, and genuinely private — and for most people it is unnecessary.
It becomes worth considering if you handle confidential material professionally, work under a duty of confidence, or simply want to be certain. If that’s you, ask me — it’s the kind of thing I set up, and I’ll tell you honestly whether you need it.
Common questions
Does the AI company read what I type?
Assume it could be reviewed. Most major providers state that conversations may be used to improve their systems unless you opt out, and that staff can review some content for safety. Treat a mainstream assistant roughly like a work email: probably private in practice, but not the place for things that must never be seen.
Is it safe to paste work documents in?
It depends on your employer's policy and what is in the document. Check the policy first. As a rule, remove names, account numbers, and anything identifying before pasting, and never paste someone else's private information without their knowledge.
Can I turn off training on my conversations?
Usually yes. Most major assistants have a setting that stops your conversations being used for training, often under data controls or privacy in settings. It takes about a minute and is worth doing on day one.