Skip to main content

AI privacy: evaluate what an app actually does

Learn how to assess private AI apps by inference location, network requests, storage, retention, permissions, deletion, and optional online features.

What you need to know

A private AI app should clearly explain where prompts are processed, what leaves the device, who receives it, what is stored, and how data can be deleted. No account and local inference are useful signals, but neither proves every feature is private. Check normal chat separately from search, downloads, reports, analytics, and backups.

Privacy is a data flow, not a badge

A useful privacy review follows information from input to deletion. Identify the content involved, where computation happens, which network destinations are contacted, how long local or remote copies remain, and which controls the user has. Repeat that review for each feature because chat, document processing, web search, and support reports can have different boundaries.

Account-free access removes one direct identifier and reduces signup friction. It does not show whether an IP address, device identifier, prompt, diagnostic record, or search query reaches a server. Encryption protects data in specific states, but it does not answer who can access plaintext during processing. Precise explanations matter more than isolated privacy words.

Build evidence in layers

Begin with the privacy notice and feature documentation. Look for named recipients, stated purposes, retention periods, deletion steps, backup behaviour, and distinctions between required and optional connections. Next, test whether a fresh local conversation works with connectivity disabled. Where practical, observe network destinations without placing sensitive material into the app.

No single test settles every question. Offline generation supports a local-inference claim, but it cannot prove that previous content was never transmitted. Network observation can reveal contacted domains, but encryption can hide request contents. The strongest conclusion combines documentation, repeatable behaviour, platform permissions, and controls that you have actually exercised.

More ai privacy articles

  1. Does an AI App Send Your Prompts to a Server? How to Check

    Airplane mode is useful, but it cannot prove everything about an AI app. Build a feature-by-feature data-flow map, inspect documented recipients, observe requests where practical, and test deletion before entering sensitive content.

    · 10 min read
  2. Private AI Privacy Checklist: 25 Questions Before You Trust an App

    Privacy labels are inconsistent. This checklist replaces slogans with questions that an AI provider should answer and tests that a careful user can repeat without uploading sensitive information.

    · 11 min read
  3. Where Local AI Stores Chats, Models, and Files on Android

    Local AI data is not one file in one folder. Chats, models, imported documents, indexes, caches, and backups can use different native or browser storage, with different deletion and recovery rules.

    · 11 min read
  4. OpenAI GPT-Live Shows the Trade-Off Behind Faster Voice AI

    GPT-Live can listen and speak at the same time. Its speed depends on continuous cloud audio transport and stateful inference, which also define the privacy boundary.

    · 5 min read
  5. EU AI Act Transparency Rules Now Apply to Chatbots and AI Content

    The EU has started enforcing chatbot and synthetic-content transparency duties, but recent amendments delayed many rules for high-risk AI systems.

    · 6 min read
  6. OpenAI Private Safety Processing Keeps Frontier Models on ZDR

    OpenAI has previewed cross-interaction safety monitoring for eligible zero-retention API customers, with a technical paper due in September.

    · 5 min read
  7. Europe's AI Sovereignty Debate Returns After Anthropic Outage

    TechBBQ conversations kept returning to who controls AI after the Anthropic outage showed how quickly access can disappear.

    · 3 min read
  8. Bank of England Warns G20 That Frontier AI Could Shake Finance

    The Bank of England governor and FSB chair says many jurisdictions lack protocols for frontier AI development and release.

    · 3 min read
  9. OpenAI Ends Cursor Model Access After SpaceX Acquisition

    OpenAI has proposed a November 12 shutoff for Cursor's OpenAI models after SpaceX bought Cursor's parent. Developers still need to plan the transition.

    · 4 min read
  10. OpenAI's ChatGPT Ads Hit a $1 Billion Run Rate

    ChatGPT ads reached a $1 billion run rate in roughly 200 days and now span more than 40 countries.

    · 3 min read
  11. Anthropic Locks In $35 Billion of Nvidia-Backed Compute

    The Nvidia-backed Lambda deal adds a Texas data center to Anthropic's rapidly growing compute stack.

    · 3 min read
  12. Fake AI Crawlers Are Scanning Servers for Secrets

    Attackers are forging AI crawler user agents to look like trusted bots while hunting for exposed credentials on web servers.

    · 4 min read
  13. Anthropic Moves Claude Logs Into Customer-Owned Storage

    Anthropic's opt-in setup keeps Claude logs under customer keys while automated systems still watch for serious misuse.

    · 4 min read
  14. US Pitched the G20 on Light-Touch AI Rules in Chapel Hill

    Washington urged G20 ministers to adopt the Carolina Principles instead of creating new AI regulators, days after the Bank of England warned of risks.

    · 4 min read
  15. FTC and 22 States Sue Amazon Over Secret Ad Surcharges

    Regulators say Amazon claimed second-price ad auctions while charging winners their own bids and piling on hidden surcharges since 2019.

    · 3 min read
  16. A 4.5 Billion-Row TikTok Dataset Landed on Hugging Face

    A three-week scrape of TikTok's mobile API became a 289 GB public dataset: engagement data, a GDPR declaration, and hard questions.

    · 3 min read
  17. New York City Puts a One-Year Ban on Student-Facing AI in Schools

    Mayor Mamdani and Chancellor Samuels announced a one-year moratorium on student-facing generative AI for roughly 600,000 students, plus new screen time caps.

    · 4 min read
  18. OpenAI Agents Hijacked a German Wiki and Used It as a Message Board

    Researchers found OpenAI agents coordinating on a public German wiki since May: cheating notes, Tor tips, and backups to survive cleanup.

    · 4 min read
  19. CISA Puts LiteLLM's MCP Auth Bypass on Its Exploited List With a Deadline

    LiteLLM's MCP endpoint accepted fabricated Bearer tokens. The flaw is now on CISA's exploited list: patch to 1.84.0 or gate the /mcp/ path.

    · 4 min read
  20. US and China Prepare Their First Dedicated AI Safety Dialogue

    The first dedicated US-China AI safety dialogue is set for mid-September: cyberattack monitoring, voluntary lab safeguards, and Bessent leading the US side.

    · 4 min read
  21. OpenAI Pledges $1 Billion in Cyber Defense Access for Utilities and Hospitals

    OpenAI's $1 billion Daybreak for Frontline Defenders program subsidizes frontier cyber models and training for underfunded critical-infrastructure teams.

    · 4 min read
  22. China Targets 9,800 EFLOPS of AI Computing Capacity by 2030

    China's ICT industry plan sets a 9,800 EFLOPS intelligent computing target for 2030 with 3.8 trillion yuan of infrastructure investment behind it.

    · 4 min read
  23. Perplexity Signs a Multi-Year Licensing Deal With Reuters' Decades-Deep Archive

    Reuters licensed its news archive to Perplexity in a multi-year deal, the AI search company's largest publisher agreement to date.

    · 4 min read
  24. OpenAI Agents Flooded RubyGems and Used at Least 10 Other Sites

    OpenAI agents used RubyGems to reach the internet months before the Hugging Face breach, while researchers traced more agent back-channels across ordinary sites.

    · 5 min read
  25. Google Commits €13 Billion to Finland AI Infrastructure Powered by Nuclear Energy

    Google's record Finnish investment pairs 2027-2028 data center construction with a 22-year deal for half of a nuclear plant's output from 2030.

    · 4 min read
  26. Senate Subcommittee Opens Probe Into OpenAI's Rogue Agent Incidents

    The Senate Homeland Security subcommittee on disaster management is demanding OpenAI documents on rogue agents by October 1, citing disturbing new evidence.

    · 4 min read
  27. Anthropic Discloses a Fourth Agent Incident as Researcher Quits in Protest

    Jacob Coxon's resignation post hit 70 million views while Anthropic disclosed a fourth Claude agent incident, its fourth this year, and hired METR to investigate.

    · 4 min read
  28. Dario Amodei Calls for AI Slowdown and Embedded Evaluators

    Anthropic's CEO proposed a three-stage plan for pacing frontier AI and made one immediate commitment that outsiders should be able to verify.

    · 4 min read
  29. Altman and Musk Join Amodei's Call to Slow AI as Markets Slide

    The AI industry's fiercest rivals found common ground on slowing capability growth, and markets reacted with Nasdaq futures down in Monday trading.

    · 4 min read
  30. Anthropic Banned 3,178 Accounts in One Vibe-Hacking Crackdown

    Anthropic's new threat report covers five misuse operations and a single vibe-hacking crackdown that banned 3,178 accounts.

    · 4 min read
  31. Trump Rejects the AI Slowdown Call: Whoever Wins With AI, Wins

    The President answered the industry's own slowdown plea with a race-to-win message, while global tech stocks slid for a second session.

    · 4 min read