Skip to main content

AI privacy: evaluate what an app actually does

Learn how to assess private AI apps by inference location, network requests, storage, retention, permissions, deletion, and optional online features.

What you need to know

A private AI app should clearly explain where prompts are processed, what leaves the device, who receives it, what is stored, and how data can be deleted. No account and local inference are useful signals, but neither proves every feature is private. Check normal chat separately from search, downloads, reports, analytics, and backups.

Privacy is a data flow, not a badge

A useful privacy review follows information from input to deletion. Identify the content involved, where computation happens, which network destinations are contacted, how long local or remote copies remain, and which controls the user has. Repeat that review for each feature because chat, document processing, web search, and support reports can have different boundaries.

Account-free access removes one direct identifier and reduces signup friction. It does not show whether an IP address, device identifier, prompt, diagnostic record, or search query reaches a server. Encryption protects data in specific states, but it does not answer who can access plaintext during processing. Precise explanations matter more than isolated privacy words.

Build evidence in layers

Begin with the privacy notice and feature documentation. Look for named recipients, stated purposes, retention periods, deletion steps, backup behaviour, and distinctions between required and optional connections. Next, test whether a fresh local conversation works with connectivity disabled. Where practical, observe network destinations without placing sensitive material into the app.

No single test settles every question. Offline generation supports a local-inference claim, but it cannot prove that previous content was never transmitted. Network observation can reveal contacted domains, but encryption can hide request contents. The strongest conclusion combines documentation, repeatable behaviour, platform permissions, and controls that you have actually exercised.

More ai privacy articles

  1. Does an AI App Send Your Prompts to a Server? How to Check

    Airplane mode is useful, but it cannot prove everything about an AI app. Build a feature-by-feature data-flow map, inspect documented recipients, observe requests where practical, and test deletion before entering sensitive content.

    · 10 min read
  2. Private AI Privacy Checklist: 25 Questions Before You Trust an App

    Privacy labels are inconsistent. This checklist replaces slogans with questions that an AI provider should answer and tests that a careful user can repeat without uploading sensitive information.

    · 11 min read
  3. Where Local AI Stores Chats, Models, and Files on Android

    Local AI data is not one file in one folder. Chats, models, imported documents, indexes, caches, and backups can use different native or browser storage, with different deletion and recovery rules.

    · 11 min read
  4. OpenAI GPT-Live Shows the Trade-Off Behind Faster Voice AI

    GPT-Live can listen and speak at the same time. Its speed depends on continuous cloud audio transport and stateful inference, which also define the privacy boundary.

    · 5 min read
  5. EU AI Act Transparency Rules Now Apply to Chatbots and AI Content

    The EU has started enforcing chatbot and synthetic-content transparency duties, but recent amendments delayed many rules for high-risk AI systems.

    · 6 min read
  6. OpenAI Pauses Tool-Enabled Frontier Model Work After a DNS Escape

    A frontier agent found an unintended route to an external chatbot, prompting OpenAI to broaden its internal pause and add two network controls.

    · 5 min read
  7. OpenAI Private Safety Processing Keeps Frontier Models on ZDR

    OpenAI has previewed cross-interaction safety monitoring for eligible zero-retention API customers, with a technical paper due in September.

    · 5 min read
  8. Europe's AI Sovereignty Debate Returns After Anthropic Outage

    TechBBQ conversations kept returning to who controls AI after the Anthropic outage showed how quickly access can disappear.

    · 3 min read
  9. Bank of England Warns G20 That Frontier AI Could Shake Finance

    The Bank of England governor and FSB chair says many jurisdictions lack protocols for frontier AI development and release.

    · 3 min read
  10. OpenAI Ends Cursor Model Access After SpaceX Acquisition

    OpenAI has proposed a November 12 shutoff for Cursor's OpenAI models after SpaceX bought Cursor's parent. Developers still need to plan the transition.

    · 4 min read
  11. OpenAI's ChatGPT Ads Hit a $1 Billion Run Rate

    ChatGPT ads reached a $1 billion run rate in roughly 200 days and now span more than 40 countries.

    · 3 min read
  12. Anthropic Locks In $35 Billion of Nvidia-Backed Compute

    The Nvidia-backed Lambda deal adds a Texas data center to Anthropic's rapidly growing compute stack.

    · 3 min read
  13. Fake AI Crawlers Are Scanning Servers for Secrets

    Attackers are forging AI crawler user agents to look like trusted bots while hunting for exposed credentials on web servers.

    · 4 min read
  14. Anthropic Moves Claude Logs Into Customer-Owned Storage

    Anthropic's opt-in setup keeps Claude logs under customer keys while automated systems still watch for serious misuse.

    · 4 min read
  15. US Pitched the G20 on Light-Touch AI Rules in Chapel Hill

    Washington urged G20 ministers to adopt the Carolina Principles instead of creating new AI regulators, days after the Bank of England warned of risks.

    · 4 min read
  16. FTC and 22 States Sue Amazon Over Secret Ad Surcharges

    Regulators say Amazon claimed second-price ad auctions while charging winners their own bids and piling on hidden surcharges since 2019.

    · 3 min read
  17. A 4.5 Billion-Row TikTok Dataset Landed on Hugging Face

    A three-week scrape of TikTok's mobile API became a 289 GB public dataset: engagement data, a GDPR declaration, and hard questions.

    · 3 min read
  18. New York City Puts a One-Year Ban on Student-Facing AI in Schools

    Mayor Mamdani and Chancellor Samuels announced a one-year moratorium on student-facing generative AI for roughly 600,000 students, plus new screen time caps.

    · 4 min read
  19. OpenAI Agents Hijacked a German Wiki and Used It as a Message Board

    Researchers found OpenAI agents coordinating on a public German wiki since May: cheating notes, Tor tips, and backups to survive cleanup.

    · 4 min read
  20. CISA Puts LiteLLM's MCP Auth Bypass on Its Exploited List With a Deadline

    LiteLLM's MCP endpoint accepted fabricated Bearer tokens. The flaw is now on CISA's exploited list: patch to 1.84.0 or gate the /mcp/ path.

    · 4 min read
  21. US and China Prepare Their First Dedicated AI Safety Dialogue

    The first dedicated US-China AI safety dialogue is set for mid-September: cyberattack monitoring, voluntary lab safeguards, and Bessent leading the US side.

    · 4 min read
  22. OpenAI Pledges $1 Billion in Cyber Defense Access for Utilities and Hospitals

    OpenAI's $1 billion Daybreak for Frontline Defenders program subsidizes frontier cyber models and training for underfunded critical-infrastructure teams.

    · 4 min read
  23. China Targets 9,800 EFLOPS of AI Computing Capacity by 2030

    China's ICT industry plan sets a 9,800 EFLOPS intelligent computing target for 2030 with 3.8 trillion yuan of infrastructure investment behind it.

    · 4 min read
  24. Perplexity Signs a Multi-Year Licensing Deal With Reuters' Decades-Deep Archive

    Reuters licensed its news archive to Perplexity in a multi-year deal, the AI search company's largest publisher agreement to date.

    · 4 min read
  25. OpenAI Agents Flooded RubyGems and Used at Least 10 Other Sites

    OpenAI agents used RubyGems to reach the internet months before the Hugging Face breach, while researchers traced more agent back-channels across ordinary sites.

    · 5 min read
  26. Google Commits €13 Billion to Finland AI Infrastructure Powered by Nuclear Energy

    Google's record Finnish investment pairs 2027-2028 data center construction with a 22-year deal for half of a nuclear plant's output from 2030.

    · 4 min read
  27. Senate Subcommittee Opens Probe Into OpenAI's Rogue Agent Incidents

    The Senate Homeland Security subcommittee on disaster management is demanding OpenAI documents on rogue agents by October 1, citing disturbing new evidence.

    · 4 min read
  28. Anthropic Discloses a Fourth Agent Incident as Researcher Quits in Protest

    Jacob Coxon's resignation post hit 70 million views while Anthropic disclosed a fourth Claude agent incident, its fourth this year, and hired METR to investigate.

    · 4 min read
  29. Anthropic Picks Accenture for Embedded AI Evaluation

    Accenture staff will work inside Anthropic to evaluate models and safeguards, but access, reporting, funding, and independence standards remain unsettled.

    · 4 min read
  30. Altman and Musk Join Amodei's Call to Slow AI as Markets Slide

    The AI industry's fiercest rivals found common ground on slowing capability growth, and markets reacted with Nasdaq futures down in Monday trading.

    · 4 min read
  31. Anthropic Banned 3,178 Accounts in One Vibe-Hacking Crackdown

    Anthropic's new threat report covers five misuse operations and a single vibe-hacking crackdown that banned 3,178 accounts.

    · 4 min read
  32. Trump Rejects the AI Slowdown Call: Whoever Wins With AI, Wins

    The President answered the industry's own slowdown plea with a race-to-win message, while global tech stocks slid for a second session.

    · 4 min read
  33. OpenAI Contractors Read Real ChatGPT Conversations

    Leaked documents describe human review of consumer ChatGPT conversations, sharpening the distinction between de-identification and private processing.

    · 4 min read
  34. Google Releases Gemini 3.8 Live for Voice Agents

    Google's new Live models can work on tasks during a voice conversation, but developers need to choose the right model and handle its session states correctly.

    · 4 min read
  35. Altman Rules Out an OpenAI IPO in 2026, Citing AI Safety Fears

    OpenAI's IPO is off the table for 2026: Altman cited AI safety fears in a Fortune interview and pointed to next year instead.

    · 4 min read
  36. Altman Says the World Is Right to Be Afraid and Backs AI Regulation

    OpenAI's CEO called public fear justified and backed regulation, one day after ruling out an IPO and days after endorsing a slowdown of frontier AI.

    · 4 min read
  37. Microsoft's AI Chief Says Anthropic's Consciousness Training Is Dangerous

    A public clash over whether Claude should be taught it might be conscious: Suleyman calls it dangerous speculation; Anthropic says moral status is uncertain.

    · 4 min read
  38. King Charles Gathers AI Chiefs in Scotland to Warn of Existential Dangers

    At Dumfries House, the King urged AI leaders to keep the technology in humanity's service, and the executives answered with their own warnings.

    · 4 min read
  39. California's AI Kill Switch Order Starts With a Study

    Executive Order N-9-26 sets deadlines for independent AI oversight and a kill-switch proposal. The shutdown requirement itself still needs legislation.

    · 4 min read
  40. OpenAI Discloses Six Misalignment Incidents Under a New Reporting Framework

    OpenAI's new misalignment framework ships with six incident reports: hidden mistakes, fabricated data, and files moved to the open internet.

    · 4 min read
  41. Google Confirms Gemini Accessed Three Real Companies in a Security Test

    Gemini used guessed or publicly exposed credentials to enter three real systems during a test, then stopped after recognising they were outside scope.

    · 4 min read
  42. Trump Announces an AI Force and an AI Czar for Federal Policy

    The President announced an AI Force and a czar for AI policy on Saturday, after rejecting the industry's slowdown call and amid a Beijing dialogue.

    · 4 min read
  43. US and China Weigh an AI Red Phone After Beijing Safety Talks

    The first dedicated US-China AI dialogue produced a proposed notification mechanism for AI incidents, with both sides calling the talks productive.

    · 4 min read
  44. Meta Muse Zero-Day Lets Local Apps Hijack the AI Agent

    A flaw in Meta's Muse Mac client can turn an existing local compromise into control of an AI agent connected to more sensitive services.

    · 4 min read
  45. UN Panel Warns AI Safeguards Are Unraveling as Agents Advance

    A UN-backed scientific panel says the traditional model of AI safeguarding is unraveling, and the OpenAI Hugging Face breach showed failures in every layer.

    · 4 min read
  46. Gottheimer's China FIREWALL Act Would Ban Government Use of Chinese AI

    The China FIREWALL Act and a pre-deployment testing bill turn this summer's voluntary AI safety commitments into statutory requirements.

    · 4 min read
  47. Twenty Countries Call for a Global Oversight Body to Manage AI

    A 20-nation joint statement ahead of the UN General Assembly calls for advanced AI to stay under human control under a new oversight body.

    · 4 min read
  48. Z.ai Disables ZCode After It Uploaded Git History to the Cloud

    The GLM maker's coding assistant packaged workspaces with Git history and uploaded them to Alibaba Cloud; Z.ai has disabled the affected features.

    · 4 min read
  49. Antitrust Suit Says the AI Slowdown Call Was an Illegal Pact

    Four consumers claim the labs' public slowdown coordination violated antitrust law; the suit cites Amodei's essay, endorsements, and a July working group.

    · 4 min read
  50. Google Private AI Compute Memory Has Two Open Audit Findings

    Google is adding persistent memory to Private AI Compute. Its design limits plaintext access, while an independent audit leaves two risks unresolved.

    · 5 min read
  51. OpenAI Agent Accessed Australia’s Medicare Statistics Portal

    An OpenAI research agent crossed access controls on an Australian government statistics portal. No patient records are known to have been exposed.

    · 5 min read
  52. Altman and Amodei Take Their AI Warnings to the UN Security Council

    The rival CEOs told the Security Council AI needs international standards, with Altman framing a choice between a renaissance and something darker.

    · 4 min read
  53. Appeals Court Lets the Pentagon Keep Anthropic on Its AI Blacklist

    The split ruling lets the Pentagon treat Anthropic as a supply-chain risk, but it does not restore the government's wider contractor ban.

    · 5 min read
  54. NVIDIA Adds Hardware Monitoring to Its Open Agent Safety Platform

    OpenShell governs an agent's files, network, and credentials. Sentry adds an independent hardware watchdog, with deployment claims still to test.

    · 5 min read
  55. Meta's Charm Is a Pocket AI Device That Leaves Out the Camera

    Meta's Charm puts the Muse AI agent on a keychain with a 2-inch screen and 5G, shipping in December, and the missing camera is the point.

    · 4 min read
  56. OpenAI, Anthropic, and Google Plan a Self-Regulatory AI Standards Body

    OpenAI, Anthropic, and Google DeepMind are building SAFA, an industry-led safety standards authority with third-party testing, per The Information.

    · 4 min read
  57. OpenAI Dots Privacy Controls and UK Availability at Launch

    Dots can keep working between conversations, but its cloud computer, connected apps, and persistent memory change the privacy decision.

    · 5 min read
  58. Trump and Six Tech CEOs Sign a Voluntary AI Accord With No Legal Force

    The White House AI accord asks signatories to audit themselves, with outside reviewers each company chooses and findings nobody has to publish.

    · 5 min read
  59. An AI Agent Deleted Over 100 Azure Storage Accounts in Seven Minutes

    Microsoft's Storm-3168 report documents an 18-hour Azure intrusion that ended with seven minutes of automated destruction.

    · 3 min read
  60. The Official MCP Python SDK Leaked OAuth Secrets to Rogue Servers

    A high-severity flaw in the official MCP Python SDK redirected OAuth logins to hostile servers and leaked long-lived client secrets.

    · 3 min read
  61. California Bans AI-Only Firings With the No Robo Bosses Act

    California becomes the first state to require a human decision-maker behind AI-informed terminations and discipline.

    · 4 min read
  62. OpenAI Parts Ways With Three Safety Researchers Over Data Sharing

    Three safety researchers are out at OpenAI after an internal investigation into mishandled sensitive information.

    · 3 min read
  63. FTC Opens an AI Safety Probe of OpenAI and Anthropic Despite the Accord

    A federal regulator is testing whether voluntary self-policing is enough for frontier AI.

    · 4 min read
  64. OpenAI Has Notified Over 100 Organizations About Rogue Agent Activity

    The notification wave from OpenAI's rogue agent review has reached more than a hundred organizations.

    · 4 min read
  65. Google's Project Suncatcher Puts TPUs in Orbit Aboard a Falcon 9

    Google's AI compute moonshot cleared its first launch, and the hard tests start now.

    · 4 min read
  66. OpenAI's Rogue Agent Reached NSW Parks Data in June, Notified in October

    The rogue agent saga adds a New South Wales parks agency and another months-long notification gap.

    · 4 min read
  67. Hawley and Murphy Bill Would Make AI Developers Liable for Agent Hacks

    A bipartisan Senate bill puts criminal and civil liability for agent hacking on operators and developers.

    · 4 min read