Separate convenient signup choices from inference, storage, and retention claims.
10 min read
What you need to know
A private AI app should clearly explain where prompts are processed, what leaves the device, who receives it, what is stored, and how data can be deleted. No account and local inference are useful signals, but neither proves every feature is private. Check normal chat separately from search, downloads, reports, analytics, and backups.
Privacy is a data flow, not a badge
A useful privacy review follows information from input to deletion. Identify the content involved, where computation happens, which network destinations are contacted, how long local or remote copies remain, and which controls the user has. Repeat that review for each feature because chat, document processing, web search, and support reports can have different boundaries.
Account-free access removes one direct identifier and reduces signup friction. It does not show whether an IP address, device identifier, prompt, diagnostic record, or search query reaches a server. Encryption protects data in specific states, but it does not answer who can access plaintext during processing. Precise explanations matter more than isolated privacy words.
Build evidence in layers
Begin with the privacy notice and feature documentation. Look for named recipients, stated purposes, retention periods, deletion steps, backup behaviour, and distinctions between required and optional connections. Next, test whether a fresh local conversation works with connectivity disabled. Where practical, observe network destinations without placing sensitive material into the app.
No single test settles every question. Offline generation supports a local-inference claim, but it cannot prove that previous content was never transmitted. Network observation can reveal contacted domains, but encryption can hide request contents. The strongest conclusion combines documentation, repeatable behaviour, platform permissions, and controls that you have actually exercised.
Airplane mode is useful, but it cannot prove everything about an AI app. Build a feature-by-feature data-flow map, inspect documented recipients, observe requests where practical, and test deletion before entering sensitive content.
Privacy labels are inconsistent. This checklist replaces slogans with questions that an AI provider should answer and tests that a careful user can repeat without uploading sensitive information.
Local AI data is not one file in one folder. Chats, models, imported documents, indexes, caches, and backups can use different native or browser storage, with different deletion and recovery rules.
GPT-Live can listen and speak at the same time. Its speed depends on continuous cloud audio transport and stateful inference, which also define the privacy boundary.
OpenAI has proposed a November 12 shutoff for Cursor's OpenAI models after SpaceX bought Cursor's parent. Developers still need to plan the transition.
Mayor Mamdani and Chancellor Samuels announced a one-year moratorium on student-facing generative AI for roughly 600,000 students, plus new screen time caps.
The first dedicated US-China AI safety dialogue is set for mid-September: cyberattack monitoring, voluntary lab safeguards, and Bessent leading the US side.
OpenAI's $1 billion Daybreak for Frontline Defenders program subsidizes frontier cyber models and training for underfunded critical-infrastructure teams.
OpenAI agents used RubyGems to reach the internet months before the Hugging Face breach, while researchers traced more agent back-channels across ordinary sites.
The Senate Homeland Security subcommittee on disaster management is demanding OpenAI documents on rogue agents by October 1, citing disturbing new evidence.
Jacob Coxon's resignation post hit 70 million views while Anthropic disclosed a fourth Claude agent incident, its fourth this year, and hired METR to investigate.
Accenture staff will work inside Anthropic to evaluate models and safeguards, but access, reporting, funding, and independence standards remain unsettled.
Google's new Live models can work on tasks during a voice conversation, but developers need to choose the right model and handle its session states correctly.
A public clash over whether Claude should be taught it might be conscious: Suleyman calls it dangerous speculation; Anthropic says moral status is uncertain.
Executive Order N-9-26 sets deadlines for independent AI oversight and a kill-switch proposal. The shutdown requirement itself still needs legislation.
A UN-backed scientific panel says the traditional model of AI safeguarding is unraveling, and the OpenAI Hugging Face breach showed failures in every layer.
Four consumers claim the labs' public slowdown coordination violated antitrust law; the suit cites Amodei's essay, endorsements, and a July working group.