ONLINEAGENT_OPS 2026.Q3 HOMEARTICLESBLOGRECORDCRAFTSEARCH
HOMERECORDWhat Happens To What You Type
RECORD · REVISED ON A SCHEDULE

WHAT HAPPENS TO WHAT YOU TYPE

Retention, training, human review and whose data it legally is — four separate questions people collapse into one.

◈ THE ASSUMPTION THAT KEEPS YOU SAFE

Unless you have a written agreement saying otherwise, assume that what you type may be stored, may be reviewed by a person, and may be used to improve the service. That is not cynicism about any particular company — it is the industry default that most terms permit, and it is the only assumption that never gets you into trouble. Everything below is how to do better than the default.

Four separate questions

These get collapsed into "is it private?", which is why people end up confused. They have different answers, and a yes to one tells you nothing about the others.

QUESTION 01

Is it retained — and for how long?

Storing your conversation is not the same as training on it. Most services keep history so you can return to it, and hold logs for a period for abuse and debugging purposes even after you delete a chat.

WHERE TO LOOKPrivacy policy, section on retention periods. Look for whether deletion is immediate or after a defined window, and whether deleted conversations are excluded from backups.
QUESTION 02

Is it used to train the model?

The question people actually mean. It commonly differs between the free and paid tiers of the same company, and between consumer and business products from the same brand — which is why "does company X train on my data" has no single answer.

WHERE TO LOOKSettings, under privacy or data controls. Look for wording about improving models or the service. Frequently on by default on consumer plans and off by contract on business ones.
QUESTION 03

Can a person read it?

Separate again. Many services allow staff or contractors to review a sample of conversations for safety and quality, and legal process can compel disclosure. This is ordinary across software and usually disclosed rather than concealed.

WHERE TO LOOKPrivacy policy, sections on human review, service providers and legal disclosure. If the phrase "trained reviewers" appears, that is the answer.
QUESTION 04

Whose data is it, legally?

If you paste something belonging to your employer, a client, or another person, your consent is not the consent that matters. This is where most real-world harm in this area actually occurs — not from a company misusing data, but from someone pasting material they had no right to share.

WHERE TO LOOKYour contract, not theirs. See using AI at work.

Three levels of exposure

HIGHEST EXPOSURE

Free consumer accounts

Broadest permissions, training frequently enabled by default, and the least contractual protection. Perfectly fine for ordinary use; the wrong place for anything sensitive.

MIDDLE

Paid and business plans

Usually stronger commitments, often excluding training by contract, sometimes with configurable retention. The protection comes from the agreement, so it is only as good as the agreement you actually have.

LOWEST EXPOSURE

A model on your own hardware

Nothing leaves the machine, so retention, training and review stop being policy questions and become physical impossibilities. The trade is capability and convenience.See local or cloud and open or closed

What to actually do

  • Check the setting once. Find the training toggle in whichever tool you use most and decide deliberately. Five minutes, permanent effect.
  • Separate your accounts. Sensitive work on the account governed by an agreement; casual questions anywhere. Most exposure comes from using one account for both.
  • Do not paste what is not yours. Other people's personal data, client material, credentials — the one mistake on this page that cannot be undone afterwards.
  • Re-check after major updates. Defaults change, new features arrive switched on, and terms are revised. An annual look is proportionate.
  • Do not rely on this page for specifics. Policies differ and change; what belongs on a durable page is the method, not a table of company names that would be wrong within months.
◈ THE THING WORTH NOTICING

People are typing things into these systems that they have never told another human being — medical worries, marital problems, money trouble, doubts about their own competence. That is not foolish; it is what happens when something answers patiently at three in the morning. But it means the honest privacy question is not the legal one. It is: would you be comfortable if this specific conversation were read by a stranger at that company? If not, that is the conversation to have with a person instead.Related: AI companions and what the research shows

◈ WHERE THIS SITE STANDS

The industry has been better about disclosure here than it is usually given credit for — most of this is written down, if rarely read. The genuine problem is defaults: the privacy-protective option is frequently the one you have to go and find, on the tier used by the people least likely to look. That is a design decision, not an accident, and it is the fair thing to criticise.