Neurocourse

Privacy and data: what you can and can't upload

Where does what you type to an AI go? What the three companies do with your chats, how to switch off training on them, how a temporary chat differs from a normal one — and a short list of what you must never upload.

You trust an AI with emails, drafts, sometimes documents with numbers in them. Fair question: where does all that go? Let's take it in order — what actually happens to your text after you hit send, and which decisions are yours to make.

Where what you type goes

Your request travels to the company's servers (OpenAI, Anthropic or Google), the model processes it there and sends an answer back. That in itself isn't a "leak" — any email service or cloud drive works the same way. The real question is different: what happens to the text afterwards — is it stored, do humans read it, is it used to train future models?

The main fork: do they train on your conversations

The key idea is training on conversations: a company may use what you wrote to improve future versions of the model. On personal free tiers this is often on by default, but there is almost always a switch in the settings to opt out. What that means in practice: if a conversation is sensitive, go into the privacy settings and turn off "use my chats for training". Two minutes, once, and your text stays out of the training set.

Temporary chat: incognito mode

All three have a temporary chat — a conversation that isn't saved to your history and isn't used for training (the equivalent of a browser's incognito). Perfect for a one-off sensitive question: you ask, you get an answer, nothing is left behind. The downside is that the model won't remember this context later, but for one-off topics you don't need it to.

Personal tier versus corporate

An important distinction. On corporate tiers (Team, Enterprise and equivalents) companies by default do not train on your data — it's written into the contract, because businesses won't hand over their secrets. On personal tiers the protection is weaker and rests on your settings. The takeaway: work secrets are safer through a corporate account than a personal free one.

What you must never upload

The list is short, and every line is worth reading to the end — these are exactly what catches people out.

  • Passwords, one-time codes, access keys — the AI doesn't need them and the risk is pointless.
  • Card numbers, passports, national ID or social security numbers — not yours, and certainly not anyone else's.
  • Other people's personal data — messages, medical records, contacts of people who never agreed to this.
  • Trade secrets and closed source code from a personal account — that's what corporate tiers with guarantees exist for.

A simple rule: don't type anything into an AI that you wouldn't want to see on a stranger's screen. Not out of fear — out of hygiene. And notice: almost everything people actually reach for AI to do — draft emails, ideas, breaking down a public article, study questions — isn't on that list. The restriction is narrow and only covers the genuinely sensitive; for 95% of your work, upload away.

Anonymise if you're unsure

Often a sensitive document is needed for real work but you'd rather not hand it over whole. The way out is to anonymise: replace real names, addresses and numbers with "Client A", "City N", "XXX", and upload that version. The model will parse the structure of the contract or letter just as well, and nothing in it points to a specific person. It's the middle ground between "I can't upload anything" and "I'll upload it as is" — and in everyday life it's what saves you most often.

A real case: the outage inside ChatGPT itself, March 2023

You've already read about Samsung's engineers pasting secret code into a chat — but there the leak was the users' doing. It works the other way too. In March 2023 a bug in ChatGPT's own code let users see the titles of other people's conversations for several hours, and some paid subscribers had their name, email and fragments of billing details exposed. OpenAI took the service down, fixed it and published a post-mortem. The moral, without panic: even the biggest services fail, so the sensitivity of your data is your call — anonymise some of it, route some through a business tier, keep some on an open model on your own server (remember the DeepSeek lesson).

A question to check you're with me: you want to give an AI a scan of a friend's passport so it can fill in a form for them. What's the problem here? Think before reading on.

That's someone else's personal data, and you don't have your friend's consent to send it to someone else's servers. Documents like that don't get uploaded at all — not yours and certainly not another person's; fill the form in field by field yourself.

Three companies, three policies (and they change)

The details at OpenAI, Anthropic and Google differ and get rewritten several times a year, so memorising them is pointless — it'll be out of date. The durable skill is different: before a sensitive conversation, check two switches — training on chats, and temporary chat — and pick a tier that matches the level of secrecy. That works at all three and won't expire with the next version.

Do this now

Three minutes in the settings. Open the privacy section of your main AI (usually "Data controls") and find two things: the switch for training on your chats, and the temporary chat button. Decide deliberately how you want them set. Now you're not guessing what happens to your data — you know, and you're in charge.

Practice · 4 tasks

Short questions on the lesson — with an explanation for every answer.