Skip to main content

AI privacy: evaluate what an app actually does

Learn how to assess private AI apps by inference location, network requests, storage, retention, permissions, deletion, and optional online features.

What you need to know

A private AI app should clearly explain where prompts are processed, what leaves the device, who receives it, what is stored, and how data can be deleted. No account and local inference are useful signals, but neither proves every feature is private. Check normal chat separately from search, downloads, reports, analytics, and backups.

Privacy is a data flow, not a badge

A useful privacy review follows information from input to deletion. Identify the content involved, where computation happens, which network destinations are contacted, how long local or remote copies remain, and which controls the user has. Repeat that review for each feature because chat, document processing, web search, and support reports can have different boundaries.

Account-free access removes one direct identifier and reduces signup friction. It does not show whether an IP address, device identifier, prompt, diagnostic record, or search query reaches a server. Encryption protects data in specific states, but it does not answer who can access plaintext during processing. Precise explanations matter more than isolated privacy words.

Build evidence in layers

Begin with the privacy notice and feature documentation. Look for named recipients, stated purposes, retention periods, deletion steps, backup behaviour, and distinctions between required and optional connections. Next, test whether a fresh local conversation works with connectivity disabled. Where practical, observe network destinations without placing sensitive material into the app.

No single test settles every question. Offline generation supports a local-inference claim, but it cannot prove that previous content was never transmitted. Network observation can reveal contacted domains, but encryption can hide request contents. The strongest conclusion combines documentation, repeatable behaviour, platform permissions, and controls that you have actually exercised.

More ai privacy guides

  1. Does an AI App Send Your Prompts to a Server? How to Check

    Airplane mode is useful, but it cannot prove everything about an AI app. Build a feature-by-feature data-flow map, inspect documented recipients, observe requests where practical, and test deletion before entering sensitive content.

    10 min read
  2. Private AI Privacy Checklist: 25 Questions Before You Trust an App

    Privacy labels are inconsistent. This checklist replaces slogans with questions that an AI provider should answer and tests that a careful user can repeat without uploading sensitive information.

    11 min read
  3. Where Local AI Stores Chats, Models, and Files on Android

    Local AI data is not one file in one folder. Chats, models, imported documents, indexes, caches, and backups can use different native or browser storage, with different deletion and recovery rules.

    11 min read
  4. OpenAI GPT-Live Shows the Trade-Off Behind Faster Voice AI

    GPT-Live can listen and speak at the same time. Its speed depends on continuous cloud audio transport and stateful inference, which also define the privacy boundary.

    5 min read
  5. EU AI Act Transparency Rules Now Apply to Chatbots and AI Content

    The EU has started enforcing chatbot and synthetic-content transparency duties, but recent amendments delayed many rules for high-risk AI systems.

    6 min read