Skip to content
privacy · 5 min read

How to Read an AI Privacy Policy: What the Terms Actually Permit

A field guide to the standard clauses in AI privacy policies — what 'we don't sell your data' leaves open, how training opt-outs really work, and the five questions that matter.

AI privacy policies are not written to be read. They are written to be accurate, legally defensible, and unobjectionable at a glance — three goals that produce documents most people close after two paragraphs.

They are also the only place a cloud provider states what it is actually permitted to do with what you type. This is a field guide to reading them efficiently: which questions matter, where the answers hide, and what the standard phrases leave open.

This article sits under Private ChatGPT Alternatives.


Read the policy, not the page

Start with the right document. Most AI companies maintain two:

  • A privacy page — headings like “your data is yours,” reassuring, non-binding.
  • A privacy policy — long, dated, versioned, and the thing that actually governs.

Only the second matters. Look for a “last updated” date; if the document doesn’t have one, you are on the marketing page.

Useful primary sources, all worth reading yourself rather than taking anyone’s summary of: OpenAI’s privacy policy, Anthropic’s privacy policy, and Google’s privacy policy. Terms change, so the date on the version you read matters more than any third-party description of it — including this one.


The five questions

Everything that matters reduces to these. Search the document for each.

1. Is my conversation content retained, and for how long?

Search for retain, retention, store, delete.

You are looking for a specific duration attached to conversation content — not account metadata, not billing records. Common patterns:

  • A stated period after which content is deleted
  • “As long as necessary to provide the service” — indefinite in practice
  • A shorter period for enterprise tiers than consumer ones
  • A separate, usually longer, period for abuse and safety monitoring

That last one matters and is easy to miss. Many services delete conversations from your visible history immediately on request while retaining a copy for a further period for safety review. Both statements are true simultaneously.

2. Is my content used to train models?

Search for train, improve, model development.

Three tiers are typical: consumer tiers default to training-enabled with an opt-out; business and enterprise tiers default to training-disabled contractually; API access is usually excluded from training by default.

Two things to check carefully. Opting out is usually not retroactive — content already used in a completed training run cannot be extracted from the resulting model. And opting out of training is not deletion; they are separate controls, and turning off one does not trigger the other.

3. Who else can access it?

Search for third party, sub-processor, affiliate, service provider, human review.

Standard permitted access typically includes cloud infrastructure providers, employees and contractors under confidentiality obligations, human reviewers sampling for safety and quality, corporate affiliates, and acquirers in a merger or sale.

The acquisition clause deserves attention. Nearly every policy permits transferring data in a merger or asset sale. Your data is governed by whoever ends up owning it, under whatever policy they subsequently adopt.

Search for law enforcement, legal, subpoena, disclose.

Every provider complies with valid legal orders. This is not a criticism — it is a legal requirement, and refusing is not an option. It is simply a property of stored data: data that exists can be compelled.

5. Can this change?

Search for modify, amend, changes to this policy.

Nearly all policies reserve the right to revise terms with notice, and data collected under earlier terms is commonly governed by the revised version. Continued use constitutes acceptance.

This is the structural point. A policy describes present intentions of a present company under present ownership. All three can change, and none of the changes require bad faith.


Phrases that mean less than they appear to

“We don’t sell your data.” A narrow claim about one transaction type. Compatible with retaining it indefinitely, analysing it, training on it, sharing it with affiliates and sub-processors, and disclosing it under legal process. Almost universally true and almost never informative.

“Your data is encrypted.” Encryption protects against third parties in transit and at rest. The provider decrypts your conversation to process it — it has to, in order to answer. Encryption addresses who else can read it.

“We take your privacy seriously.” Contains no commitment.

“Anonymised” / “de-identified.” Weaker than it sounds for conversational text. Removing a name doesn’t remove the content, and free text about your job, city, family, and health is frequently re-identifiable on its own.

“Temporary chat” / “incognito mode.” Usually means excluded from visible history and from training. Usually does not mean never transmitted or never retained. Read the specific description.

“Enterprise-grade security.” Describes how data is protected. Says nothing about whether it is collected.


What is genuinely improving

It is worth being fair here, because the direction of travel is real.

Training opt-outs are now standard and easy to find. Enterprise tiers offer meaningful contractual guarantees. Retention periods have shortened. Transparency reports are more common. Regulation — the GDPR in Europe, and increasingly elsewhere — has forced clearer disclosure and real deletion rights.

These are substantive improvements and they make cloud AI meaningfully better than it was. Anyone claiming nothing has changed is not paying attention.


The limit that improvement can’t cross

All of these improvements share a shape: they are commitments about the handling of data that has already been received.

That leaves a residue no policy can remove. Stored data can be breached. It can be compelled. It can be transferred in an acquisition. It can be reprocessed under revised terms. None of that requires anyone to behave badly — it requires only time and ordinary corporate events.

Which is why the most useful question about an AI service is not “what does the policy permit” but “what would be exposed if the policy stopped being honoured tomorrow.”

For a cloud service, the answer is every conversation it retains. For an app running models on your device, the answer is nothing, because nothing was transmitted. There is no policy to break.

That is the whole argument for on-device inference, and it is why Cloaked’s privacy policy is unusually short. There is very little to disclose when there is no server. AI Apps That Don’t Collect Your Data covers how to verify that claim rather than trust it.


A ten-minute routine

For any AI service you are considering:

  1. Find the dated policy, not the marketing page.
  2. Search: retain, train, third party, law enforcement, modify.
  3. Read the paragraph around each hit.
  4. Check whether opt-outs are on by default or require action.
  5. Ask what would be exposed if the policy changed tomorrow.
  6. Decide what you are willing to type into it.

Step 6 is the one that actually protects you. Everything before it is just gathering the information to make it well.


Download Cloaked on the App Store — the conversations never leave your device, so there is no retention policy to read.

Frequently asked questions

Does 'we don't sell your data' mean my conversations are private?

No. It is a narrow statement about one specific transaction. It says nothing about retention, employee access, use for training, sharing with sub-processors and affiliates, or disclosure under legal process — all of which are ordinary and permitted under most policies.

If I opt out of training, is my data deleted?

Usually not. Opting out of training and deleting data are separate controls. Most providers retain conversation content for some period regardless of training preferences, commonly citing abuse monitoring, safety review, and legal obligations.

Do AI providers read my conversations?

Most policies permit human review of a sample of conversations for safety and quality purposes, and permit access by staff and contractors under confidentiality terms. This is generally disclosed, but rarely prominently.

Can a privacy policy change after I've used a service?

Almost all reserve the right to amend terms with notice. Data already collected under an earlier policy is frequently governed by the revised one. This is the structural weakness of any policy-based privacy guarantee.