All guides

Safety · Beginner

AI Privacy Basics — What Happens to What You Type

Where your messages actually go, what "we don't train on your data" does and doesn't mean, a clear list of what never to paste, and the questions worth asking any AI provider.

Simanta Pratim DasPublished 6 min read

Most people use AI assistants without a clear picture of where their text goes. That is understandable — the interface looks like a private notes app and behaves like a conversation. It is neither.

This guide explains the actual data path, what common privacy claims mean in practice, and gives you a concrete list of what not to paste.

Where your message actually goes

A typical AI assistant request touches more systems than people expect:

  1. Your browser or app — the text may be cached locally, in drafts, or in browser storage.
  2. The product's servers — the assistant you are using. It usually stores your conversation so you can return to it.
  3. A model provider — often a different company. Many AI products do not run their own models; they send your text to a provider's API.
  4. Infrastructure in between — hosting, logging, error tracking, analytics.
  5. Any tool the assistant calls — if it searches the web, some part of your query may reach a search provider.

The important implication: the company whose interface you are using is often not the only company processing your text. This is not sinister — it is how most AI products are built — but it means "is this private?" has more than one answer, and a privacy policy that only describes the front-end company is incomplete.

What common privacy claims actually mean

These phrases appear everywhere and are easy to over-read.

ClaimWhat it usually meansWhat it does not mean
"We don't train on your data"Your conversations are not used to update model weightsNot that they aren't stored, logged, or readable by staff
"Your data is encrypted"Encrypted in transit and at rest on diskNot end-to-end encrypted — the service can read your text; it must, to answer
"We don't sell your data"No direct sale of personal informationNot that no third parties process it
"Conversations are private"Other users cannot see themNot that nobody at the company can, under any circumstances
"You can delete your data"Deletion from the primary storeBackups and logs may persist for a retention period

The one worth internalising is the second row. AI assistants cannot be end-to-end encrypted in the way a messaging app can. The model must process your text as readable text to respond to it. Any product claiming both "end-to-end encrypted" and "AI reads your messages" is describing something other than what those words normally mean.

What not to paste into any AI assistant

A practical list. Not paranoia — each item has a specific reason.

Never:

  • Passwords, API keys, tokens, private keys. Assume anything pasted is in a log somewhere. Rotate immediately if you have already done this.
  • Full payment card numbers, bank details, government ID numbers. These carry regulatory weight and outsized fraud value.
  • Other people's personal data — medical details, addresses, private messages, employee records. Consent was not yours to give, and in many jurisdictions this is a legal issue rather than an etiquette one.
  • Confidential work material unless your employer has approved that specific tool. Source code, unreleased financials, customer lists, legal strategy, unpublished research. "Shadow AI" use is one of the most common ways proprietary information leaves companies.
  • Anything under a confidentiality agreement. An NDA does not make an exception for tools you find convenient.

Think carefully before:

  • Your own medical or mental-health details. Legitimate reasons exist to discuss these, but an AI product is generally not covered by health-data protections the way a clinician is.
  • Legal matters in progress. Conversations with an AI carry no privilege.
  • Identifiable details about children.
  • Anything you would not want associated with your account if the account were ever accessed by someone else.

The redaction habit

Most of the value of pasting real material survives removing the identifying parts. Instead of a real contract, paste it with names replaced by [CLIENT] and [VENDOR]. Instead of a production log, replace real user IDs with user_1, user_2. Instead of a patient case, remove name, date of birth, and location.

The model does not need the identifiers to help with the structure, and you have removed almost all the risk for almost no loss of usefulness. This single habit handles most real-world situations better than a blanket rule against pasting anything.

Questions worth asking any AI provider

Before trusting a tool with anything sensitive, these are answerable from a decent privacy policy. If they are not answerable, that is itself information.

  1. Who processes my text besides you? Named model providers and sub-processors.
  2. Is my content used to train models? Yours, or a third party's.
  3. How long are conversations retained after I delete them? Including logs and backups.
  4. Can staff read my conversations, and under what conditions?
  5. Where is data stored geographically? This determines which laws apply.
  6. What happens to my data if the company shuts down or is acquired?
  7. Is there a way to use the product without conversation history?

Question 1 is the one most policies handle vaguely and the one that matters most, because it determines how many organisations hold your text.

Browser and account hygiene

Less discussed, and often the weakest link:

  • Your conversation history is as protected as your account password. Use a unique password and two-factor authentication. An AI history can contain more sensitive detail than most email accounts — people paste things into it they would never send.
  • Shared or public devices: log out. Conversation history typically persists in the session.
  • Browser extensions can read page content, including AI conversations. Audit what you have installed.
  • Screenshots of AI conversations often include more of the thread than intended before sharing.

PhantomAI's actual data path

Applying the questions above to this product, honestly:

  • Authentication is handled by Clerk. Your login credentials are managed there, not by us.
  • Conversations are stored in a MongoDB database so your chat history persists between sessions. They are not end-to-end encrypted — as explained above, that is not possible for a product where a model must read your text.
  • Model inference runs through Groq, serving openai/gpt-oss-120b and openai/gpt-oss-20b. This means your messages are transmitted to a third-party inference provider to generate a response. That is the single most important sentence on this page for PhantomAI specifically.
  • Web search sends a search query derived from your message to a search provider when a question needs current information.
  • Uploaded documents are processed to extract text so the assistant can answer questions about them.
  • We do not train models on your conversations. We do not have a training pipeline; the models are third-party open-weight models we do not modify.
  • PhantomAI is operated by one person, not a company with a dedicated security team. This is worth stating plainly: the practical implication is that you should treat it as you would any small independent service, and not as an enterprise-grade system with formal certifications. There are none, and claiming otherwise would be dishonest.

Given all of that, our own recommendation is the redaction habit above. Use PhantomAI freely for learning, drafting, coding help, and thinking through problems. Do not paste credentials, other people's personal data, or material your employer has not cleared. The privacy policy has the formal detail, and our limitations page covers what the product cannot do.

A reasonable default posture

You do not need to be paranoid to be sensible. A workable rule:

Treat an AI conversation like a message to a competent contractor at another company: useful, professional, and not the place for secrets.

That framing gets most decisions right. You would send a contractor a redacted document, a code snippet with keys removed, or a question about an approach. You would not send them your password or a colleague's medical history.

Continue

Simanta Pratim Das

Founder & Developer

Simanta is an independent AI engineer based in Guwahati, India, building PhantomAI as a solo project — designing the product, the interface, and the AI pipeline end to end.

Related guides

Try these techniques in PhantomAI

PhantomAI is free to use, and the workflows in this guide work best when you paste in your own material rather than relying on the model's memory. Before you start, it's worth reading what it can't do.