That gap is the whole problem. Not that the tools are dangerous, but that almost nobody has decided what belongs in them before typing.
The useful question is not whether AI is private. It is what tier you are on, what happens to what you type, and whether the answer would survive somebody asking you about it later.
The line that matters most
Nearly every provider runs two categories of product, and the difference between them is substantial.
Consumer tiers, including the free and personal paid plans, generally default to using your conversations to improve future models. You can usually turn this off in settings, and most people never do.
Business and enterprise tiers generally do not train on your data by default, offer a data processing agreement you can actually sign, and provide administrative controls over retention.
The gap between those two is not a feature difference. It is a legal posture difference, and it costs somewhere in the region of twenty to thirty dollars a month per person.
If you are handling anything that belongs to a customer, the consumer tier is the wrong tool and the upgrade is cheaper than a single awkward conversation about it.
What happened when a court got involved
This is the part worth understanding, because it disproves an assumption most people hold.
In a copyright case brought against a major AI provider, a court ordered the company to preserve conversations. That order covered free and paid consumer plans, and it explicitly included chats users had deleted and sessions users had marked as temporary. It ran for several months in 2025. Business and enterprise workspaces were not subject to it.
Two things follow from that, and both are general rather than specific to one company.
Delete does not necessarily mean deleted. It means removed from your view, and removed from their systems on a schedule, unless something overrides that schedule.
And a vendor privacy commitment exists inside a legal system that can preempt it. The promise is real, and it is not the final word.
Off is not the same as not kept
A second distinction people collapse.
Turning off training means your conversations are less likely to shape future models. It typically does not mean nothing is stored. Most providers retain content for a period, commonly around thirty days, for abuse monitoring, and legal holds or investigations extend that.
Temporary or incognito modes work the same way. They usually control what appears in your history rather than what exists on a server.
Both settings are worth using. Neither is a guarantee of absence.
Five questions before you paste
Ask these once about whichever tool you use, then apply the answers routinely.
- 01Which tier am I on, and does it train on my inputs by default
- 02Can I sign a data processing agreement, and have I
- 03How long is content retained after I delete it
- 04Who else can read it, meaning is there human review for safety or quality
- 05What happens to it if the company is acquired or subpoenaed
Question five is the one nobody asks and the one with the longest tail. Terms of service change with ownership, and data collected under one policy can end up governed by another.
Before pasting, ask whether you would be comfortable with this text appearing in a court filing with your business name attached. Not because that is likely, but because it is the right standard. It is the same test you would apply to an email. Most people already have good instincts about what belongs in an email to a stranger, and this is the same instinct pointed at a different box.
What should not go in, regardless of tier
Some material does not belong in a general purpose AI tool even on a business plan.
- Customer personal information. Names attached to addresses, dates of birth, government identifiers
- Payment details of any kind
- Health information, which carries specific legal obligations in most jurisdictions
- Anything covered by a signed confidentiality agreement, unless that agreement permits it
- Credentials, keys, or anything that grants access to something
- Employee records, complaints, or anything from a personnel file
- Unfiled legal or financial documents belonging to somebody else
For most of these, the fix is not avoidance. It is redaction. Replace the name with a placeholder, remove the account number, and paste the rest. The model does not need to know your customer is called Sandra to help you rewrite the email.
If you hold a professional obligation
Worth stating separately because the standard is higher.
If you are an attorney, an accountant, a health practitioner, a financial adviser, or anybody working under a professional confidentiality duty, a consumer chatbot does not satisfy that duty. That is not a strict reading. It is the plain consequence of a term that permits training on your inputs.
The path is a business tier, a signed data processing agreement, and a written internal rule about what may be entered. Some professional bodies have published specific guidance, and it is worth reading before rather than after.
A policy that fits on one page
Even a business of one benefits from writing this down, because the decision gets made once rather than repeatedly under time pressure.
- 01Name the tool and the tier you use for business work
- 02Confirm training is off and a data processing agreement exists where available
- 03List what may never be pasted, in specifics rather than categories
- 04Establish redaction as the default for anything involving a real customer
- 05Decide whether anything AI produced can go to a customer without review, and the answer should be no
- 06Note the date and review it annually, because these terms change
That takes twenty minutes and it converts a series of judgment calls made while busy into a single decision made while thinking.
The proportionate view
None of this is an argument against using these tools. The productive use is real and it is available to a business of one in a way it has never been before.
But the material you handle belongs to other people, and the terms governing where it goes are written by companies whose incentives are not identical to yours, inside a legal environment that can override both.
Reading the terms once, paying for the tier that matches what you handle, and redacting by habit covers nearly all of it. If you want the underlying explanation of how these systems work, start here.