There is a category of question people research constantly and almost never say aloud. What this symptom might mean. Whether they can afford to leave the job. What happens legally if they do the thing they’re considering. How to raise something with a partner. What a diagnosis actually means for someone they love.
These are exactly the questions where an AI assistant helps most — patient, available at 2am, willing to explain something four times without judgement. They are also the questions where what you type is most revealing.
This article sits under What People Actually Use Private AI For.
Why these questions are different from search
People have researched sensitive topics online for thirty years. AI queries are a meaningfully different artifact, for three reasons.
They contain context, not keywords. Search gets “chest pain left side.” An AI assistant gets “I’m 34, I get a tight pain on my left side when I’m stressed, my father had a heart attack at 52, and I’m scared to book an appointment in case they find something.” The second is a paragraph about a person. The first is a fragment.
They contain your reasoning. People explain why they’re asking. That reveals fears, plans, and circumstances that a keyword never does.
They’re conversational. One question becomes fifteen, each adding detail, over an hour. The transcript is closer to a session than a search log.
The result is that a year of AI conversation history is one of the more revealing records a person generates about themselves — often more so than search history, messages, or location data. Why Your AI Conversations Are More Sensitive Than You Think covers this in depth.
The four categories
Health. Symptoms, results, medications, prognoses, what to ask a doctor, what a letter means, how to care for someone. People research health intensively and are right to treat it as sensitive: health information is permanent, consequential, and valuable to more parties than most data. Photographing a results page or a prescription label and asking about it works well with on-device vision, where EXIF and GPS are stripped locally.
Money. Real income, real debt, real rent. Whether an offer is good. What a pension statement means. Whether a business can survive another quarter. Useful answers require the actual numbers.
Legal. What a clause means. Rights in a dispute. Whether something is worth pursuing. What to expect from a process. Often involving a live matter and named parties.
Personal. Relationships, family, identity, grief, conflict, the conversation you’re dreading. Frequently involving other people who never agreed to be discussed.
The self-censorship tax
Watch someone type a sensitive question into a cloud assistant and you’ll see them edit it. Name removed. Figures rounded. “My daughter” becomes “a family member.” The situation described one layer more abstract.
They almost never notice doing it. And it has a real cost, because specificity is what makes an answer useful.
Ask abstractly and you get an encyclopedia entry. Ask concretely — with the actual timeline, the actual numbers, the actual family history — and you get something that addresses your situation.
So the trade-off with cloud AI is genuine and unavoidable: the more useful your question, the more exposing it is. Every sensitive query sits somewhere on that line, and most people resolve it by asking a worse question.
On-device inference deletes the line. Nothing is transmitted, so specificity costs nothing. That is the single largest practical difference in this category, and it has nothing to do with model quality.
Asking well, in either setup
If you’re using a cloud model, be deliberate. Generalise names and round numbers. Use temporary or incognito modes where offered — they reduce retention, though they don’t eliminate transmission. Split a sensitive topic across separate conversations rather than building one detailed profile. And apply the standing test: would you be comfortable with this text existing on someone else’s infrastructure indefinitely?
If you’re using a local model, ask the real question. Include the timeline, the numbers, the family history, the actual wording of the letter. Attach the photo of the document. Use a project so the context persists across conversations without needing to re-explain. This is what the architecture is for.
In both cases, know what a model is for here.
What a model can and can’t do with these questions
Good at: explaining terminology, describing how a process usually works, helping you structure what to ask a professional, translating documents into plain language, laying out options and trade-offs, and rehearsing a difficult conversation.
Unreliable at: anything requiring precision or current knowledge. Specific dosages. Current law in your jurisdiction. Exact figures. Anything that changed after the model’s training cut-off. Smaller models are more prone to confident errors — see Is Local AI Good Enough Yet? for an honest read on where the limits sit.
Not a substitute for: a doctor, a lawyer, an accountant, or a therapist. A model has no accountability, no duty of care, no license, and no way to examine you or your documents properly. It cannot tell when something is urgent.
The productive framing is preparation, not decision. Use it to walk in better informed and with better questions. That is genuinely valuable — a lot of bad professional outcomes come from patients and clients who didn’t know what to ask.
Why the record matters even when nothing is wrong
The usual objection is “I’ve got nothing to hide,” and it misreads the risk.
The concern isn’t that someone is reading your conversations today. It’s that stored data persists, and its future handling isn’t fixed. A record created under today’s terms may be governed by tomorrow’s. Companies are acquired. Policies are revised. Breaches happen to organizations that were being careful. Legal processes can compel production of records that exist.
None of that requires anyone to behave badly. It requires only time.
A conversation that was never transmitted has none of these exposures — not because it’s well protected, but because there is no record to protect. That’s the whole difference between “we won’t” and “we can’t,” and for this category of question it is the one that matters.
Download Cloaked on the App Store — ask the actual question, with the actual details, on a model that runs entirely on your device.
Frequently asked questions
Is it safe to ask AI about health symptoms?
It depends where the model runs. With a cloud assistant, symptom queries are transmitted and retained under a policy that can change, and health information is unusually sensitive and permanent. With an on-device model nothing is transmitted. In both cases a model is not a doctor and should not be treated as one.
Can AI conversations be used against me?
Stored conversations can be disclosed under legal process, exposed in a breach, or transferred if a company is sold. This is a property of stored data generally, not evidence of bad intent. Conversations that were never transmitted cannot be disclosed, because no record exists.
How do I ask a sensitive question without giving away too much?
With a cloud model, generalise: remove names, round the numbers, describe the situation one layer more abstract. Accept that the answer will be less useful. With an on-device model this trade-off does not exist, so ask the real question with the real details.
Should I trust AI advice on medical or legal matters?
Use it to understand, not to decide. Models are good at explaining terminology, structuring what to ask a professional, and making sense of a document. They are unreliable on specifics, can be confidently wrong, and carry no accountability. Consult an actual professional for decisions.