How AI Uses Your Data
When you use a chat AI product, your conversations may be used to improve the model. OpenAI and others allow you to opt out in settings. API users' data is not used for training by default. Enterprise tiers guarantee no data retention. Know which tier you are on before sharing sensitive information.
- Chat product conversations may be used to train models by default
- You can opt out of training data use in settings on most products
- API and enterprise tiers typically guarantee no training data use
Did you know? In 2023 Samsung banned employees from using ChatGPT after a developer accidentally pasted proprietary source code into a conversation — and it was sent to OpenAI's servers.
---
Privacy Best Practices
Never paste into an AI chat: passwords, private keys, personal identification numbers, sensitive client data, unreleased product details, or medical records unless you are on an enterprise plan with a data processing agreement. Treat any AI chat like an email you are CCing to a stranger.
- Never paste passwords, API keys, or client data into AI chats
- Treat AI conversations like emails CCed to an unknown third party
- Enterprise plans with DPAs offer contractual data protection
Did you know? GDPR compliance requires companies using AI with EU citizen data to have a data processing agreement — without one, using AI for customer data may be illegal.
---
RAG — Retrieval-Augmented Generation
RAG is the technique of feeding relevant documents to an LLM at query time, so it can answer questions about private or recent data without fine-tuning. Your company knowledge base, PDFs, and emails can power a custom AI assistant via RAG.
- RAG injects up to 200K+ tokens of your documents into the model context
- No model retraining needed — knowledge is injected fresh each query
- Use cases: legal doc Q&A, internal wikis, customer support bots
Did you know? Most enterprise AI products marketed as custom AI are RAG wrappers around a standard LLM — the differentiation is in which data you feed in.
---
PII and AI Privacy Risks
Sending personal data to an AI API means it may be stored, logged, or used in training. GDPR classifies AI outputs about individuals as personal data processing. Know what you share and with which providers.
- OpenAI prompts may be used for training unless API calls opt out via data controls
- Anthropic API calls are not used for training by default
- GDPR Article 22 restricts fully automated decisions about individuals
Did you know? A Samsung engineer accidentally leaked proprietary chip designs by pasting source code into ChatGPT in 2023, prompting Samsung to ban the tool internally.
Sign in to track your progress and earn a certificate.
Sign in