1. Is Your Data Used for Training?
One of the most significant privacy concerns is whether your data is used to train the AI model. Many companies use customer inputs to improve future versions of their AI. While this helps the model become more capable, it means your notes—even if stripped
of direct identifiers—could be absorbed into the system. Some services, especially free consumer versions, have model training enabled by default. It is essential to check the platform's privacy settings and see if you can opt out of having your data used for training. Remember, opting out usually only prevents future data from being used; what's already been processed may be part of the model indefinitely.
2. Where Does Your Data Actually Live?
When you upload a document, it doesn't just vanish into a conceptual 'cloud.' It's stored on physical servers in specific locations. The jurisdiction where your data is stored matters, as it dictates which laws and government agencies can potentially access it. Some AI platforms may use third-party cloud services, adding another layer of complexity to your data's journey. Review the terms of service to understand where the company's servers are located and if they have clear policies on data residency. This is particularly important if you are handling sensitive information subject to regulations like GDPR or HIPAA, which have strict rules about cross-border data transfers.
3. Who Else Might See Your Information?
Your data might be accessible to more than just an algorithm. In some cases, human reviewers are employed to check AI outputs and inputs for quality control, meaning your sensitive notes could be read by an employee or contractor. Furthermore, privacy policies often contain clauses that allow data sharing with third-party partners or in response to legal requests from government bodies. It's crucial to understand the company's policies on employee access and third-party data sharing. If a company's terms are vague about who can view your data, it's a significant red flag.
4. How Secure Is the Platform?
Any platform that stores data is a potential target for hackers. Data breaches are a constant threat, and AI systems are no exception. A weak security posture could expose everything you've uploaded, from personal thoughts to confidential business strategies. Look for platforms that take security seriously by implementing measures like end-to-end encryption, multi-factor authentication, and regular security audits. A company's commitment to security should be clearly stated. If they aren't transparent about how they protect your data, you should be cautious about entrusting them with it.
5. Can You Truly Delete Your Data?
Deleting a file from your interface doesn't always mean it's gone forever. Data retention policies define how long a company holds onto your information, and these can vary wildly. Some services may retain your data for a set period (e.g., 30-90 days) for debugging or other purposes, even after you've 'deleted' it. If data has been used for model training, removing it from the underlying model can be nearly impossible. Look for services with clear data retention schedules and a straightforward process for permanent data deletion. Some privacy-focused platforms even offer a 'zero data retention' policy, ensuring your inputs are discarded immediately after processing.














