Plainly

Guide · Your data

What happens to what you type

One of the first things anyone asks and one of the hardest to answer well, because the honest answer is three answers and they change. Here is the mechanism underneath all of them, which does not change, and where to get the specifics that do.

Published  ·  Last verified  ·  Mechanism only. Per-vendor specifics are deliberately left to the vendor

What actually leaves your device#

When you type into a hosted assistant, the text goes to the vendor's servers to be processed and comes back as more text. There is no version of this where a hosted assistant answers without your words leaving your device: the model is far too large to sit on it, and the thing on your screen is a window onto somebody else's computer. That is the whole mechanism, and every question below follows from it.

It follows that everything you paste in is sent: the document, the log file, the customer list, the draft you have not published, the code with the key still in it. An assistant that reads an attachment reads it by uploading it. This is obvious once stated and routinely forgotten in the moment, which is the only reason it is worth stating.

The one habit worth forming

Before pasting, ask whether you would be comfortable emailing the same text to a supplier you have a contract with but have never met. That is roughly the real relationship, and it is a better instinct than any settings page, because it works before you have read one.

Three questions, not one#

“Is my data private?” is not answerable, because it is three questions that have different answers, sometimes different answers for the same product on the same day.

  • Retention — how long is it kept?

    Sending is not the same as storing. Nearly everything is kept for some period, often for abuse monitoring and support, and that period is usually stated somewhere in the vendor's documentation. A conversation you deleted from your screen and a conversation deleted from their systems are different events with different timelines.

  • Training — is it used to change the model?

    A separate question from retention, with a separate setting, and the one people mean when they ask. Whether it happens by default frequently differs between a consumer account and a paid business one on the same product from the same company.

  • Deletion — what does deleting actually delete?

    Removing a conversation from the interface, closing the account, and having the data removed from backups are three different acts. What is worth finding out is which one the delete button performs, and what the other two require.

Opt-outs are a category, not a promise#

Training opt-outs exist as a category across the major assistants, and that is about as far as a durable statement goes. What varies, and varies often, is whether the default is on or off, whether the setting is per-account or per-conversation, whether turning it off also turns off history, and whether business tiers differ from consumer ones.

Two patterns are stable enough to be worth carrying with you. The first is that business and developer tiers commonly default the other way from consumer ones, so the answer you found for your personal account is not the answer for your work account. The second is that the control is often bundled with something you want — conversation history, personalisation — so opting out costs a feature, and the cost is a design decision rather than a technical necessity.

What this page will not tell you#

This page gives you no per-vendor answers, and the reason is the same one that keeps figures off every page here except one. Retention windows and default settings change without announcement, they differ by account type and by country, and a page here stating them would be a page confidently wrong in a way no reader could detect. The vendor's own privacy documentation is the only thing that is right by definition, and it is one search away.

What to look for, in their words rather than ours: the data-controls or privacy section of your account settings for the switch itself, and the product's privacy policy or trust centre for the retention period. If you cannot find a clear answer to the three questions above in the vendor's own documentation, that is itself an answer, and a fair one to weigh when choosing.

The same reasoning governs Model facts, which is the one page here carrying figures, cites each to a vendor page, and is diffed against those pages daily. Nothing on this page could be maintained to that standard, so nothing on this page pretends to be.

What to actually do#

  • Find the switch once, per account.

    Not per product — per account. If you use the same assistant personally and at work, check both; they are frequently configured differently by default.

  • Decide what never goes in, and make it a rule.

    A rule decided in advance survives a deadline. A judgement call made while you are in a hurry, with the paste already in the clipboard, does not. Credentials and anything covered by an obligation you did not personally agree to are the obvious floor.

  • Assume anything pasted may be retained.

    Not because vendors are dishonest, but because it is the assumption that stays correct when a default changes and nobody tells you. It costs you almost nothing and it is the only version of this that does not need re-checking.

Next → How to choose an assistant · All → Guides