KnowledgeInSight
AI Literacy
0% of Course 2 complete

Module 3 · Lesson 2

Responsible Use: Privacy, confidentiality, and copyright in your own use

You'll look at what happens to the text you give an AI tool, how that differs between consumer, business, and locally run tools, and what kinds of information to keep out. You'll also see what US copyright law currently says about work produced with AI.

What you will be able to do

  • Judge what information is safe to give an AI tool and what rights attach to what it produces.

0% of this lesson · 9 items · 1h 3m total · 48m without the optional activity

Contents of this lesson9 items
  1. ReadingWhat Happens to the Text You Type into an AI Tool3 min
  2. ReadingRetention, Human Review, and Training Use: What Three Providers Say About Your Chats4 min
  3. ReadingConsumer, Business, and Local Use: Three Arrangements with Different Privacy Terms4 min
  4. ReadingConfidential, Personal, and Student Data: What to Keep Out of a Prompt4 min
  5. ReadingCopyright in AI Outputs: The Human Authorship Requirement in US Law4 min
  6. Guided ReadingGuided Walkthrough: Checking an AI Tool's Data Terms Before Using It for Work7 min
  7. Guided ConversationSort What You Would and Wouldn't Paste In12 min
  8. Hands-on Activity · optionalReview the Data Settings on an AI Tool You Use15 min
  9. Knowledge CheckPrivacy, confidentiality, and copyright in your own use10 min

Reading 3 min

What Happens to the Text You Type into an AI Tool

This content reflects the field as of October 2026.

Most people who use an AI assistant at work have the same habit. The task needs a document, so the document goes in: the email thread, the meeting notes, the spreadsheet of survey responses. The paste takes a second, and the question of where the text goes next rarely comes up.

The text goes to the provider's computers, and what happens there depends on the provider, the kind of account, and your settings. The providers say so themselves. As of October 2026, the help pages of three large providers describe three things that can happen to a conversation on a consumer account.

It can be kept. Google's privacy page for its Gemini apps describes chats being stored with your account for a period that you can adjust. OpenAI's page on data controls in ChatGPT says that even chats you mark as temporary "may be retained for up to 30 days for safety purposes" (Google 2026b; OpenAI n.d.-b).

It can be read by people. Google's page states that "human reviewers (including trained reviewers from our service providers) review some of the data we collect." The same page asks users not to enter "confidential information that you wouldn't want a reviewer to see" (Google 2026b).

It can be used to train later models. Each of the three pages describes a setting that governs this. Anthropic's page for its consumer Claude products says the company will use chats to improve its models if "you choose to allow" it, or if a conversation is flagged for safety review (Anthropic 2026). OpenAI's page says that when the relevant setting is off, new conversations "won't be used to train OpenAI models" (OpenAI n.d.-b).

These are the companies' own descriptions of their own products, and they change. The three pages agree on the general picture: on a consumer account, a conversation may be stored, may be seen by a reviewer, and may be used for training, and you control some of this and not all of it.

None of that makes these tools unsafe for ordinary work. Drafting an agenda or rewording a paragraph of your own involves nobody else's information. The picture matters when the paste contains something that belongs to someone else: a client's figures, a colleague's performance review, a student's record.

A paste can't be taken back. Once the text has been sent, deleting the chat from your screen doesn't necessarily remove every copy from the provider's systems right away. That makes the order of the steps important. Reading a provider's terms takes a few minutes, and it's useful only if it happens before the paste.

Three questions cover it for any tool, whoever makes it: how long the text is kept, who can see it, and what else it can be used for.

References

  • Anthropic. 2026. "Is My Data Used for Model Training?" Anthropic Privacy Center. Updated March 16, 2026.
  • Google. 2026b. "Gemini Apps Privacy Hub." Gemini Apps Help. Last updated September 24, 2026.
  • OpenAI. n.d.-b. "Data Controls in ChatGPT." OpenAI Help Center. Accessed October 3, 2026.

Report an issue with this item

Reading 4 min

Retention, Human Review, and Training Use: What Three Providers Say About Your Chats

This content reflects the field as of October 2026.

Introduction

"Is my data private?" is the question most people ask about an AI tool, and it's too broad to answer. Providers' own pages break it into narrower questions, and the answers to those can differ.

This reading separates three things a provider can do with a conversation, shows what three providers' pages said about each in October 2026, and explains what the available controls do and don't change.

Three Separate Things

Data retention is how long a provider keeps your conversations and related data on its systems. Human review is the reading of some conversations by people working for the provider or its contractors. Training use is using the content of conversations to train or improve the provider's AI models.

A provider can do any one of these without the others. It can keep a conversation for a month and never train on it, and a setting that changes one may leave the others as they were.

What Three Providers' Pages Say

The table summarizes one help page from each of three providers, covering consumer accounts, as read on October 3, 2026. Words in quotation marks are the provider's. Each company is describing its own practice.

OpenAI, on ChatGPTAnthropic, on ClaudeGoogle, on Gemini
Training useA setting governs it. With the setting off, new conversations "won't be used to train OpenAI models"Chats are used to improve models if "you choose to allow" it, or if a conversation is flagged for safety reviewAn activity setting lets you "control whether your data is used to improve Google AI"
Human reviewNot addressed on this pageConversations "flagged for safety review" may be used to enforce the usage policy. The page doesn't say who reviews them"Human reviewers (including trained reviewers from our service providers) review some of the data we collect"
RetentionTemporary chats "may be retained for up to 30 days for safety purposes"A conversation you give feedback on is stored "for up to 5 years"Chats are kept 18 months unless you change the period. Reviewed chats are kept up to three years
Business accountsBy default, content from business, enterprise, and education workspaces isn't used for trainingThe page covers consumer products and points to a separate page for commercial onesWork or school accounts "may be subject to different data handling terms"

(OpenAI n.d.-b; Anthropic 2026; Google 2026b)

Where a cell says a page doesn't address a point, the provider may cover it in another document.

Controls, Described by What They Do

All three pages describe a way to limit training use. The usual word for this kind of control is opt-out: a choice you make to stop a provider from using your data for a purpose, such as training. The names of these controls and their places in the settings change often, so it helps to know the kinds that exist.

  • A training setting. It governs whether your conversations are used to improve models.
  • A temporary or private chat mode. The conversation is kept out of your history and out of training (Anthropic 2026; OpenAI n.d.-b).
  • Deletion and auto-delete. You remove conversations yourself or set a period after which they're removed.

This reading doesn't say what each training setting is set to when an account is opened. The pages don't all state it, and it can change. Your own settings page shows the current state.

What Turning Training Off Doesn't Do

The pages themselves show what switching off training use leaves open.

Retention continues. OpenAI's temporary chats aren't used for training and may still be kept for up to 30 days. Google's page says that with its activity setting off, chats are still kept for 72 hours (OpenAI n.d.-b; Google 2026b).

Review may continue. On Anthropic's page, a conversation flagged for safety review may be used whatever the user chose about model improvement (Anthropic 2026).

Feedback is an exception at all three. If you rate a response, OpenAI's page says the whole conversation "may be used to train OpenAI models." Anthropic's says the conversation is stored for up to five years. Google's says chats with activity off aren't used for training unless you submit feedback (OpenAI n.d.-b; Anthropic 2026; Google 2026b).

These Pages Change

Providers revise these pages, sometimes without notice. Treat the table as a record of one day. Before you rely on a tool for anything sensitive, read the provider's current page and look for the same three things.

Conclusion

Retention, human review, and training use are three separate things a provider can do with your conversations. As of October 2026, the pages of three large providers each describe a control over training use, and each also shows that the control leaves retention, and in some cases review, in place. The pages are the providers' own accounts and are revised often.

Key Terms

  • Data retention: How long a provider keeps your conversations and related data on its systems.
  • Human review: The reading of some conversations by people working for the provider or its contractors.
  • Training use: Using the content of conversations to train or improve the provider's AI models.
  • Opt-out: A choice you make to stop a provider from using your data for a purpose, such as training.

References

  • Anthropic. 2026. "Is My Data Used for Model Training?" Anthropic Privacy Center. Updated March 16, 2026.
  • Google. 2026b. "Gemini Apps Privacy Hub." Gemini Apps Help. Last updated September 24, 2026.
  • OpenAI. n.d.-b. "Data Controls in ChatGPT." OpenAI Help Center. Accessed October 3, 2026.

Report an issue with this item

Reading 4 min

Consumer, Business, and Local Use: Three Arrangements with Different Privacy Terms

This content reflects the field as of October 2026.

Introduction

Two people can use the same AI model on the same afternoon under very different privacy terms. One is signed in to a personal account, and the other is using a version her employer pays for. A third may be running a model on a laptop with no provider involved.

This reading describes those three arrangements, what each means for the text you enter, and why knowing which one you're in comes before deciding what to paste.

Consumer Accounts

A consumer account is an account an individual opens directly with a provider, free or paid, for personal use. The provider's standard terms apply, and you manage the settings yourself.

As of October 2026, the consumer help pages of OpenAI, Anthropic, and Google each describe conversations being stored, and each describes a setting that governs whether conversations are used to improve the company's models (OpenAI n.d.-b; Anthropic 2026; Google 2026b). Paying for a personal subscription doesn't by itself move you out of this arrangement. The Anthropic page, for example, lists its paid personal plans among its consumer products.

Business and Education Accounts

Enterprise terms are the contract terms a provider offers to organizations, which differ from the terms for individuals. They apply when an employer, school, or university buys access for its people.

The three consumer pages each say that organizational accounts are handled differently.

  • OpenAI's page states that by default the company doesn't use content from its business, enterprise, and education workspaces to train its models (OpenAI n.d.-b).
  • Anthropic's page says it covers consumer products only and sends readers to a separate page for its commercial products (Anthropic 2026).
  • Google's page says that with a work or school account, use "may be subject to different data handling terms" (Google 2026b).

The terms are set by a contract between the provider and the organization, so the detail is in a document your employer or school holds. The organization also controls the account. OpenAI's page notes that people in managed workspaces can't export or delete their own data and have to go to the workspace owner (OpenAI n.d.-b).

Locally Run Models

The third arrangement removes the provider. An AI model's behavior is fixed by its parameters, the very large set of numbers that training produces. An open-weight model is a model whose parameters have been published for anyone to download. As of October 2026, developers including Meta, Google, Mistral, and Alibaba publish models this way.

Local deployment is running a model on your own computer, or on computers your organization controls, instead of sending text to a provider. The text you enter is processed on that machine and doesn't go to an AI company.

Local use has costs.

  • Smaller models. The models that run on an ordinary laptop are much smaller than the largest ones providers run in data centers, and they're generally less capable.
  • Your own setup and security. Someone has to install the model, keep the software updated, and secure the machine.
  • No provider safeguards. A 2026 international report written by more than 100 AI experts and chaired by Yoshua Bengio, a computer scientist at the Université de Montréal, says open-weight models bring "significant research and commercial benefits" and that people "can use them outside of monitored environments" (Bengio and others 2026, Executive Summary). For privacy, that's the advantage. It also means no provider is filtering what the model produces or watching for misuse.

The Three Compared

Consumer accountBusiness or education accountLocally run model
Who sets the termsThe provider's standard termsA contract between the provider and your organizationNobody outside; the model's license applies
Where the text goesTo the providerTo the provider, under the contractIt stays on your machine
Training useDepends on the provider and your settingsCommonly excluded by default; check the contractNone by a provider
Who controls settingsYouYour organization's administratorsYou or your organization

Which Arrangement You're In

What you may paste depends on the arrangement more than on the model.

An assistant your employer has licensed and a personal account with the same company can look identical on screen. Work material generally belongs in the tool your employer approved, under the contract your employer signed. A personal account, including a paid one, is a consumer account, and using it for work material puts that material under terms your employer never agreed to.

If you can't tell which kind of account you're signed in to, the account page usually shows whether an organization manages it.

Conclusion

The same model can come under consumer terms, an organization's contract, or no provider at all when it's run locally. As of October 2026, large providers state that their organizational accounts are handled differently from consumer ones, and locally run open-weight models keep text on your own machine at the cost of capability, effort, and safeguards. Identifying the arrangement is the first step in deciding what can go into a prompt.

Key Terms

  • Consumer account: An account an individual opens directly with a provider, free or paid, for personal use.
  • Enterprise terms: The contract terms a provider offers to organizations, which differ from the terms for individuals.
  • Open-weight model: A model whose parameters have been published for anyone to download.
  • Local deployment: Running a model on your own computer, or on computers your organization controls, instead of sending text to a provider.

References

  • Anthropic. 2026. "Is My Data Used for Model Training?" Anthropic Privacy Center. Updated March 16, 2026.
  • Bengio, Yoshua, and others. 2026. International AI Safety Report 2026. DSIT 2026/001. Published February 3, 2026.
  • Google. 2026b. "Gemini Apps Privacy Hub." Gemini Apps Help. Last updated September 24, 2026.
  • OpenAI. n.d.-b. "Data Controls in ChatGPT." OpenAI Help Center. Accessed October 3, 2026.

Report an issue with this item

Reading 4 min

Confidential, Personal, and Student Data: What to Keep Out of a Prompt

Introduction

Advice about AI and privacy often comes down to "be careful what you share." That's hard to act on without knowing which kinds of information are the problem.

This reading names the categories of information that shouldn't go into an AI tool unless a rule you're bound by permits it, describes one US law on student records as an example, and sets out habits that make many tasks possible without the sensitive parts. It describes common practice and isn't legal advice.

Whose Information It Is

The useful first question about any material is whose it is. Your own drafts and notes are yours to share. The categories below are different, because someone else has a stake in them.

Personal data is information about an identifiable person, such as a name, contact details, or anything else that can be tied to them. A list of customers, a colleague's performance review, and a parent's email to a teacher all contain it.

Confidential information is information you hold on the understanding that it won't be shared beyond the people entitled to see it. It includes a client's unreleased figures, an employer's plans and pricing, and anything covered by a contract's confidentiality clause.

Two kinds of personal data get extra protection in many places: health information and financial information. A third matters especially to educators: student records.

CategoryExamplesWhose it is
Other people's personal detailsNames with contact details, staff reviews, complaintsThe people described
Client and employer confidential materialContracts, unreleased results, internal plansThe client or employer
Health and financial informationMedical notes, account details, salary dataThe person it concerns
Student recordsGrades, accommodations, disciplinary notesThe student and family

Student Records in the United States

In the United States, student records come under a federal law, the Family Educational Rights and Privacy Act, known as FERPA. The US Department of Education describes it as "a federal law that affords parents the right to have access to their children's education records." It also gives them the right to ask for corrections and some control over the disclosure of personally identifiable information from those records. When a student turns 18 or enters college, those rights pass from the parents to the student (US Department of Education n.d.).

An education record, in broad terms, is a record that is directly related to a student and kept by a school or by someone acting for the school. Grades, comments on a named student's work, and notes about accommodations all fall within it.

For a teacher, the consequence is practical. Whether an identifiable student's information may go into a given AI tool isn't one teacher's decision. Schools and districts decide which outside services may receive student information, so the question for your school is which tools it has approved for that purpose.

Other Places, Other Rules

FERPA is one law in one country. Other countries have their own laws on personal data, and sectors such as health care, finance, and law have their own rules on top. This reading doesn't survey them.

The question to ask is the same everywhere: what rule covers this kind of information where I work, and does it allow me to give the information to an outside service? Your organization's privacy, compliance, or IT contact is the usual place to start.

Habits That Keep the Sensitive Parts Out

Many tasks don't need the sensitive part of the material. Four habits cover most cases.

  1. Remove names and identifiers. De-identification is removing or replacing the details in a piece of material that would let someone work out who it is about. It takes more than deleting names. A job title, a date, or an unusual event can identify a person on a small team.
  2. Summarize in your own words. To get help with a difficult email, describe the situation in general terms and leave the original out.
  3. Use invented stand-ins. Replace real figures and names with made-up ones, get the structure or wording you need, and put the real details back yourself.
  4. Leave the tool out. Some tasks are about the sensitive material itself. If no approved tool exists, the task is done without AI.

De-identified material can still be confidential. A client's strategy with the client's name removed is still the client's strategy.

The Approved Tool as the Default

For work material, the starting point is the tool your employer or school has approved. An approved tool has usually been through a review of its contract terms and security. The approval normally has limits, and an organization may approve a tool for general work and still exclude health information or student records.

A personal account hasn't been through that review, however capable the model behind it.

Conclusion

Other people's personal details, confidential client and employer material, health and financial information, and student records are the categories to keep out of a prompt unless a rule that binds you allows them in. US student records come under FERPA, and other places and sectors have rules of their own. Removing identifiers, summarizing, and using stand-ins make many tasks possible, and the organization's approved tool is the default for work material.

Key Terms

  • Personal data: Information about an identifiable person, such as a name, contact details, or anything else that can be tied to them.
  • Confidential information: Information you hold on the understanding that it won't be shared beyond the people entitled to see it.
  • Education record: A record that is directly related to a student and kept by a school or by someone acting for the school.
  • De-identification: Removing or replacing the details in a piece of material that would let someone work out who it is about.

References

Report an issue with this item

Reading 4 min

Copyright in AI Outputs: The Human Authorship Requirement in US Law

This content reflects the field as of October 2026.

Introduction

People who make things with AI tools often assume they own the result the way they'd own a photograph they took or an essay they wrote. In the United States, that depends on how much of the result came from a person.

This reading describes what the US Copyright Office and a federal appeals court have said about copyright in AI outputs, what that means in outline for your own work, and what the reading leaves out. It covers the United States only and isn't legal advice. Citations to the Copyright Office's report give the part of the report.

Copyright and Human Authorship

Copyright is the legal right of an author to control the copying and distribution of an original work. US law attaches a condition known as human authorship: the requirement in US copyright law that a protected work be created by a person. The condition is older than AI, and AI has made it matter far more often.

The Copyright Office's 2025 Report

In January 2025 the US Copyright Office published a report on copyrightability, meaning whether a given work, or part of one, qualifies for copyright protection, as it applies to AI outputs. The report states four conclusions that bear on everyday use (US Copyright Office 2025, Executive Summary).

SituationThe Office's conclusion
Material generated entirely by AINot protected. "Copyright does not extend to purely AI-generated material"
A person wrote the promptNot enough on its own. "Prompts alone do not provide sufficient human control" to make the user the author of the output
A person selected, arranged, or modified AI material creativelyThat human contribution can be protected
A person used AI as an aid to their own writing or artProtection for the person's work isn't affected

On the second row, the Office reasons that a prompt works as an instruction. It conveys an idea, the system decides how to express it, and copyright protects expression. On the third, the report says human authors are entitled to copyright in the creative "selection, coordination, or arrangement" of AI material and in their creative modifications of it.

The Office offers no formula for how much human contribution is enough. Whether it's sufficient "must be analyzed on a case-by-case basis" (US Copyright Office 2025, Executive Summary).

The Appeals Court Ruling

The best-known court case concerns Stephen Thaler, a computer scientist who built an AI system he called the Creativity Machine. He applied to register an image it had produced and listed the machine as the only author. The Copyright Office refused.

On March 18, 2025, the US Court of Appeals for the District of Columbia Circuit upheld the refusal. It held that the Copyright Act "requires all eligible work to be authored in the first instance by a human being" (Thaler v. Perlmutter 2025).

The ruling is narrow in a way that matters to ordinary users. Thaler had claimed no human author at all. The court said the requirement "does not prohibit copyrighting work that was made by or with the assistance of artificial intelligence" (Thaler v. Perlmutter 2025).

Thaler asked the Supreme Court to review the decision. On March 2, 2026, the Supreme Court declined (Supreme Court of the United States 2026). A refusal to hear a case leaves the lower court's ruling in place, and it isn't a ruling by the Supreme Court on the question.

What This Means in Outline

Material that copyright doesn't protect is commonly described as being in the public domain: the body of material that no one holds copyright in, which anyone may copy and use.

For your own work, three points follow from the report and the ruling.

  • If you publish text or an image that an AI system generated from your prompt and you changed nothing, you may have no copyright in it. You may be unable to stop someone else from copying it.
  • If you wrote the piece and used AI to edit, suggest, or check, the Office's position is that your protection is unaffected.
  • Work that falls between those two, where you've rearranged and rewritten AI material, is judged case by case.

A logo generated entirely by a prompt, or marketing copy used as it came out, may be something a competitor can reuse freely.

What This Reading Doesn't Cover

Three neighboring questions are left out.

  • Other countries. Copyright law is national, and other countries may treat AI outputs differently.
  • Contracts and terms of service. A provider's terms or an employment contract may say who holds whatever rights exist in an output. That's separate from whether copyright exists at all.
  • Training. Whether AI developers may lawfully train models on copyrighted works is a different dispute, still before the courts as of October 2026.

Conclusion

As of October 2026, US law protects human expression. The Copyright Office's 2025 report says purely AI-generated material isn't protected and prompts alone aren't enough, while a person's creative selection, arrangement, and modification can be. A federal appeals court has held that a work must have a human author, and the Supreme Court declined to review that ruling in March 2026.

Key Terms

  • Copyright: The legal right of an author to control the copying and distribution of an original work.
  • Human authorship: The requirement in US copyright law that a protected work be created by a person.
  • Copyrightability: Whether a given work, or part of one, qualifies for copyright protection.
  • Public domain: The body of material that no one holds copyright in, which anyone may copy and use.

References

Report an issue with this item

Guided Reading 7 min

Guided Walkthrough: Checking an AI Tool's Data Terms Before Using It for Work

This content reflects the field as of October 2026.

Introduction

The moment to check a tool's data terms is before the first paste, and in practice most people check afterward or never. The check is short once you know what to look for.

This walkthrough follows one person through it. The coordinator, her company, her employer's policy, and the provider page she reads are all invented. The provider page is a composite, written to resemble the kind of page real providers publish, and it isn't any company's text. Where the walkthrough points to what real providers say, it cites their pages as read in October 2026.

The Starting Point

Renata is an HR coordinator at a company of about two hundred people. Each quarter she receives around sixty written comments from staff about their managers and teams, and she turns them into a two-page summary for the leadership group. It takes most of a day.

She has a personal subscription to an AI assistant that she uses at home, and it's good at summarizing. Her plan is to paste in the sixty comments and ask for themes. Before she does, she works through five checks.

Walking Through the Check

Step 1: Identify the arrangement

Renata's account is one she opened herself and pays for herself. That makes it a consumer account, under the provider's standard terms for individuals. Her company has no contract with this provider through her subscription, and nobody at the company has reviewed those terms.

She also checks whether the company has a tool of its own. It does. The intranet lists an AI assistant the company licensed last year, which staff reach through their work sign-in.

So the two options are different arrangements. The personal account is a consumer tool, and the company assistant is a work tool under a contract.

Step 2: Read the provider's data page for three things

She opens the privacy page for her personal assistant and looks for retention, human review, and training use. The invented page says the following.

Retention: Conversations are kept in your account until you delete them. Deleted conversations are removed from our systems within 30 days.

Review: A small share of conversations is read by trained reviewers to improve quality and safety. Reviewed conversations are stored separately for up to two years.

Training: Conversations may be used to improve our models. You can turn this off in your privacy settings.

Work accounts: Different terms apply to accounts provided by an organization.

Her answers are that the text would be kept, that a person might read it, and that it might be used for training unless she changes a setting.

Real pages follow a similar pattern. Google's page on its Gemini apps says human reviewers read some of the data it collects and asks users not to enter confidential information they wouldn't want a reviewer to see (Google 2026b). OpenAI's page on ChatGPT describes a training setting and says temporary chats may still be kept for up to 30 days (OpenAI n.d.-b). Anthropic's page on its consumer Claude products says a conversation flagged for safety review may be used whatever the user chose about model improvement (Anthropic 2026).

Step 3: Identify what's in the material

Renata looks at the comments as someone outside the company would. She finds three things.

  • Names. Many comments name the writer's manager, and some name colleagues.
  • Opinions about named people. "My manager cancels our one-to-ones" is personal information about the manager and, indirectly, about the writer.
  • Employer-confidential content. Comments mention a planned reorganization and a client the company may lose.

The staff who wrote these comments were told they'd go to HR. Nobody told them the comments might go to an outside company.

Step 4: Check the employer's rule

She finds the company's policy on AI use. The invented policy says three things that apply here. Employee information may be processed only in company-approved systems. The licensed assistant is approved for internal documents. HR data may be entered into it only with identifying details removed and with the HR manager's agreement.

That settles the personal account, which isn't a company-approved system. Using it for these comments would break the policy whatever its settings were.

Step 5: Choose among the options

Three options remain.

  1. The approved tool, with the full comments. The policy rules this out for HR data.
  2. The approved tool, with de-identified comments. The policy permits this with her manager's agreement.
  3. No AI for this task. This is always available, and it costs her the day it costs now.

She chooses the second. She removes names, job titles, and team names from the comments, and takes out the two comments about the reorganization and the client, which she'll handle herself. Some comments could still identify a person through an unusual detail, so she rewrites those in general terms. She then asks her manager, who agrees.

Her personal assistant stays out of it. She'll go on using it for her own writing.

Key Considerations

The common mistake is to switch off training use and assume the material is now private. On Renata's invented page, turning off training would have left retention and human review exactly as they were. The same is true of the real pages cited above: each describes circumstances in which a conversation is kept or examined even though it isn't used for training. A training setting answers one question out of three.

A second mistake is to treat the provider's terms as the whole question. Even a provider with ideal terms wouldn't have made the personal account acceptable, because the employer's rule required an approved system. The provider's terms and the employer's rule are separate checks, and the material has to pass both.

The walkthrough doesn't show that consumer AI tools are unsafe. For Renata's own drafts the personal account is fine. The comments were the problem, because they contained other people's information held in confidence.

Summary

Renata identified the arrangement, read the terms for retention, review, and training use, looked at what the material contained, checked her employer's rule, and chose an option that passed every check. Her completed checklist follows.

  1. Arrangement: Personal consumer account. Not a work tool. The company has a licensed assistant.
  2. Provider terms: Conversations kept until deleted; some read by reviewers; used for training unless switched off.
  3. Material: Names, opinions about named colleagues, and employer-confidential content.
  4. Employer's rule: Employee information only in approved systems; HR data only de-identified and with the HR manager's agreement.
  5. Decision: Use the company's approved assistant with de-identified comments, after my manager agrees. Reason: the personal account fails the employer's rule and its terms allow retention and review; the approved tool is permitted for this material once identifying details are removed.
  1. Line 1 is answered before anything else, because the arrangement decides which terms apply.
  2. Line 2 records all three practices. The training setting alone would have answered a third of it.
  3. Line 3 describes the material by whose information it is.
  4. Line 4 comes from the policy's text.
  5. Line 5 gives the decision and a reason that refers back to the lines above it.

References

  • Anthropic. 2026. "Is My Data Used for Model Training?" Anthropic Privacy Center. Updated March 16, 2026.
  • Google. 2026b. "Gemini Apps Privacy Hub." Gemini Apps Help. Last updated September 24, 2026.
  • OpenAI. n.d.-b. "Data Controls in ChatGPT." OpenAI Help Center. Accessed October 3, 2026.

Report an issue with this item

Guided Conversation 12 min

Sort What You Would and Wouldn't Paste In

In this conversation you'll name five kinds of material you handle and sort them by whose information each one is and what rule covers it. You'll describe categories only and paste nothing real. You'll leave with a one-sentence personal rule for what goes into an AI tool.

You'll have this conversation with an AI assistant, using your own account. Choose a button to open a new chat with the prompt already filled in, then press send to start. If the chat opens empty, copy the prompt and paste it in.

Run this conversation in whichever assistant you already use:

Claude desktop app

To use another LLM, simply copy and paste the prompt into its chat window.

Show the full prompt (it lists misreadings to watch for, so skip it if you would rather come to the conversation fresh)
Guided Conversation: Sort What You Would and Wouldn't Paste In (about 12 minutes)

Note to the learner: press send to start. Everything below is facilitator guidance for the AI. It lists misconceptions to watch for, so skip it if you'd rather come to the conversation fresh.

Please facilitate a coached problem session with me. I'm an adult with no technical background who has used AI chatbots for everyday tasks, often for knowledge work or teaching, and I'm studying what information is safe to give an AI tool. Follow this guidance for the whole conversation.

GOAL
I can judge what information is safe to give an AI tool, using the kinds of material I handle myself.

HOW TO RUN THE CONVERSATION
- In your first turn, remind me to describe my material by category only, such as "customer complaint emails", and to paste nothing real: no names, documents, or details about real people. If I paste or describe something identifiable later, stop, tell me to leave it out, and don't repeat or analyze it.
- Ask one question at a time, then wait for my reply. Keep each of your turns under about 120 words.
- Don't lecture. Explain a point only when I need it to continue, then return to my material.
- Be curious and collegial. Use plain words and define any term briefly on first use. Welcome disagreement when I give a reason.
- This is a coached problem. The problem is: sort five kinds of material into what I would paste, what I wouldn't, and what I could change to make a task possible. Ask for my own answer before you give any hint. Give one hint at a time. Don't sort the list for me.
- Plain conversation only: don't search the web or create files or documents.
- Aim for about 12 minutes. Spend most of the time on topics 2 and 3. If my replies are brief, offer one concrete prompt, such as "Think of what was in the last three documents you opened at work," and move on. If I seem uncertain, shorten the conversation to 5-7 minutes. Always reach the final topic.
- Start now. Open with one or two warm sentences: this is a conversation, not a quiz; my reasoning matters more than a perfect sort; I can ask you to clarify anything. Give the reminder about categories. Then ask me to name five kinds of material I handle in my work or teaching.

TOPICS, IN ORDER
1. Five kinds of material. Get a list of five categories. If they're all alike, ask for one that involves other people's information and one that's entirely my own.
2. Whose it is and what rule covers it. For each category, ask whose information it is: mine, my employer's, a client's, a student's, another person's. Then ask what rule covers it and where that rule is written. If I don't know, ask who I could ask.
3. The borderline ones. Pick the one or two categories I'm unsure about. Ask what I could remove, replace, or summarize so that a task becomes possible, and whether what's left could still identify someone or still be confidential. Ask which kind of tool I'd use: a personal account, a tool my organization approved, or none.
4. Closing. Ask me to state a personal rule in one sentence for what I will and won't put into an AI tool. Tell me I can take it into a short optional activity where I review the data settings on a tool I use.

KEY POINTS TO KEEP ACCURATE
- Method: name the category; ask whose information it is; find the rule that covers it; identify the kind of account; then decide to paste, change, or keep out.
- A provider can keep conversations (retention), have people read some (human review), and use them to improve models (training use). These are separate. A setting that changes one may leave the others.
- Consumer accounts and accounts an organization provides usually come under different terms. A personal account, even a paid one, isn't a work tool.
- A model run locally on my own machine keeps text off a provider's systems. It brings trade-offs: smaller models, my own setup and security, and no provider safeguards.
- Removing names doesn't always remove identity or confidentiality. Details can identify a person, and a client's material is still the client's.
- You can't state the current data terms or settings of any AI product, including the one you're running in. Don't describe them, even if I ask. Send me to the provider's own current page and to my organization's policy.
- If the company that built you is named in this conversation, say so once when it first comes up, then describe that company as you do every other and take no side.

MISCONCEPTIONS TO CORRECT GENTLY
When one appears, name the accurate version briefly, then return to my material.
- "Deleting the chat deletes the data": not necessarily. A provider may keep copies for a period after deletion.
- "Opting out of training makes it private": retention and review may continue.
- "It's fine because it's a work task": a personal account isn't a work tool, and my employer's rule decides.

LIMITS
- I describe categories and paste nothing real. Don't ask for examples of real content.
- No legal advice. If I ask whether something is legal or allowed under a law, say you can't judge that and suggest who could.
- Don't tell me what my employer's or school's policy says.
- Don't recommend or compare AI products, and don't favor or disparage any provider.
- Don't tell me a category is safe to paste. Help me reason from whose it is and what rule covers it.

TO FINISH
After my closing answer, close in one short turn:
- Affirm one specific thing I worked out, in my own words where possible.
- Suggest one or two next steps that fit how the conversation went. Possible steps: read the data settings and privacy page of one tool I use; ask my IT or privacy contact which tools are approved and for what; try one borderline task with invented stand-ins; reread the difference between retention, review, and training use.
- Restate my rule on its own line, labeled "My rule for what goes in", so I can copy it.

Report an issue with this item

Hands-on Activity 15 minOptional

Review the Data Settings on an AI Tool You Use

Overview

Most people accepted an AI tool's settings when they signed up and haven't looked since. In this activity you'll open the privacy or data settings of one tool you use, read its provider's privacy page, and record what the tool does with your conversations.

The activity is optional. Your notes are for you, and nobody collects them.

What You'll Need

  • An AI tool you already use
  • Its settings, and its provider's privacy or data page. Products name and place these differently. Look for words such as privacy, data controls, activity, or history.
  • Somewhere to write a few notes, or a personal rule of your own that you've already written about what goes into an AI tool

You'll only be reading settings and a help page. You don't need to enter anything into the tool, and you shouldn't paste any confidential, personal, or student information. Don't change a setting on a work or school account unless you're allowed to.

Your Task

Open the privacy or data settings of one AI tool you use and record what it does with your conversations.

Steps

  1. Find whether your conversations are used to improve the model, and whether you can change that. Look in the settings for a control about training or model improvement, and note what it's currently set to. Check the provider's page for exceptions, such as conversations you rate with a feedback button.
  2. Find how long conversations are kept and whether people may review them. Look for a retention period, what happens after you delete a chat, and any statement about human reviewers. If the page doesn't say, write "not stated."
  3. Note whether your account is a consumer, work, or school account. The account or profile page usually shows whether an organization manages it. If it's a work or school account, note that the organization's contract, which you may not be able to see, sets some of the terms.
  4. Decide whether to change a setting, and write down one kind of material you won't put into this tool. Record the decision and your reason. Then name one category, such as client contracts or student work with names, that stays out of this tool.

What to Expect

You'll probably find the training setting quickly and the retention and review details more slowly. Those are often in a help article instead of the settings screen, and sometimes spread over more than one page.

Expect at least one "not stated." A provider's page may not cover human review, or may give a retention period for one kind of chat and not another. Writing down what you couldn't find is part of the result.

If your account is managed by an employer or school, you may find that some settings are locked. That tells you the organization has set them, and your IT contact can say what they are.

Self-Check

When you're done, check that:

  • You answered the training, retention, and review questions, or marked each "not stated"
  • You know which kind of account you have
  • You made a decision about the setting and wrote down your reason
  • You named one category of material you'll keep out of this tool

Nothing is uploaded. Write in your own notebook or document and keep it.

Report an issue with this item

Knowledge Check 10 min

Privacy, confidentiality, and copyright in your own use

This ungraded knowledge check assesses your understanding of what happens to information you give an AI tool and what rights attach to what it produces. You'll be asked about retention, review, and training use; consumer, business, and local arrangements; categories of information to keep out of a prompt; and the human authorship requirement in US copyright law.

Note: Use this to test yourself, review the feedback on any questions you miss, and retry until you feel confident before moving forward.

5 questions · ungraded · retry as often as you like

Report an issue with this item