Back to blog
AI

AI Assistant Privacy: 6 Questions to Ask Before You Tell It Everything

An AI assistant is only useful if you can be honest with it. Here are the six privacy questions that matter, what good answers look like, and how to check them.

Ronkay ArslanRonkay ArslanFounder, TaseUpdated 9 min read

Before you tell an AI assistant anything personal, ask it six questions: What leaves my device, and when? Is my data used to train models? How long is it kept, and can I truly delete it? Who inside the company can see it? What happens if the company is sold? Can I use it without connecting everything? Those six cover nearly every realistic privacy failure in this category. If a vendor answers them clearly, you can make an informed trade. If it answers them vaguely, the vagueness is the answer, and you should adjust what you share accordingly.

A personal AI assistant creates a strange new category of data. It is not quite health records, not quite a diary, not quite financial data. It is all of them at once, in your own words, timestamped. The more useful the assistant, the more of your life it holds, which means asking AI assistant privacy questions is not paranoia. It is due diligence, the same kind you would apply to a bank before depositing, and this guide is the checklist we would want as users, written by a company that builds one. It applies to any product in the category, including ours.

Why assistants change the privacy math

A calendar app holds your schedule. A notes app holds your notes. An assistant holds your calendar, your notes, your medication schedule, your budget, and the questions you were too embarrassed to ask a human, all cross-referenced and searchable in plain language. Convenience here is not a feature added on top of the data. It is a direct function of how much the assistant knows, which means every privacy decision is also a usefulness decision, and the trade deserves to be made with your eyes open.

That is also why the old reflex, "just do not put anything sensitive in it", caps the product at toy level. An assistant that knows nothing about your life can remind you about meetings and little else. The assistant that knows your pharmacy, your landlord, and your mother flight is the one that can actually run point on your day. The six questions exist so you can get to the second kind without blind trust.

The six questions that matter

  1. 1

    1. What leaves my device, and when?

    Some processing must happen on servers; that is normal for AI features, and it is also normal for sync. The question is whether the app is explicit about which data travels, whether it travels encrypted, and whether anything is collected beyond what the feature needs. Vague answers like "we take privacy seriously" without a data list are a red flag. Serious products can name what they collect and why.
  2. 2

    2. Is my data used to train models?

    This is the sharpest dividing line in the category. Good answers are explicit: personal data is not used for training, or training use is strictly opt-in with a clear toggle. Look for the words "not used to train" in the privacy policy itself, not just on the marketing pages. Training on your content means your words can surface, in fragmentary form, in a stranger conversation, and no amount of anonymization promises undo that fully.
  3. 3

    3. How long is my data kept, and can I truly delete it?

    A real delete removes your content from production systems, not just from your screen. Look for account deletion inside the app itself rather than behind a support email, a stated retention window, and a clear statement about whether backups are purged on a schedule. A delete button that leaves copies in a warehouse is a hidden feature, not a deletion.
  4. 4

    4. Who can see it internally?

    Reputable products limit employee access to user content and say so in writing. Access controls, audit logs, and the phrase "we cannot read your data", where it is technically true, are what good looks like. What you are watching for is the difference between "employees may access data to improve the service" and "access is restricted, logged, and rare".
  5. 5

    5. What happens if the company is sold or shuts down?

    Data is an asset in an acquisition, and user content has changed hands under worse terms than anyone agreed to, repeatedly, across the industry. A trustworthy policy commits to notifying you before your data moves to materially different terms, and export tools mean you are never locked in. If the policy is silent on acquisition, assume your data is transferable and decide accordingly.
  6. 6

    6. Can I use it without connecting everything?

    Integrations like calendar and mail should be optional, granular, and revocable. Revoking access should actually revoke it. An assistant that demands every permission up front in order to function at all is telling you, in its very design, how it thinks about your data.

How to check the answers in two minutes

You do not need to read a full privacy policy to get most of the way there. The App Store privacy label is generated from a standardized questionnaire and shows, at a glance, what is collected and whether it is linked to your identity. The policy itself yields to search. For each of the six questions, one or two keyword searches usually surfaces the relevant paragraph, and the absence of a hit is itself an answer.

The two-minute check

Before installing: open the App Store privacy label, then search the privacy policy for the words "training", "retention", "delete", and "sell". Those four searches answer most of the six questions faster than reading the whole document.

A note on tone while you check: good privacy writing reads like an engineer explaining a system, and bad privacy writing reads like a lawyer preventing one. "We retain message metadata for 30 days" is a sentence you can act on. "We may process certain data to improve your experience" is a sentence designed to end the conversation. The six questions give vendors every chance to write the first kind of sentence. Take the chance seriously.

What the rules cover, and what they do not

Regulation is catching up, unevenly. The EU AI Act puts transparency obligations on AI systems, including disclosure duties that started phasing in for general purpose AI, and consumers in Europe get real leverage from it. Privacy law in other places, GDPR where it applies, California rules, and elsewhere, already limits collection and grants deletion rights. But the law moves slower than product categories, enforcement lags further, and most of the world has no assistant-specific protection at all. Treat regulation as a floor, not a ceiling: it sets the minimum a vendor must do, and the six questions reveal whether they chose to do more.

There is also a category question the law has not settled: when an assistant reads your messages or indexes your files to be useful, what consent standard applies, and what happens to that index if you leave. If you are weighing that specific trade, the piece on letting an AI assistant read your messages works through the on-device versus cloud distinction in detail, and it is the same decision framework these six questions come from.

Where Tase stands

Applying our own checklist: Tase syncs your content through your own account so it follows you across devices, encrypts data in transit, does not sell personal data, and does not use your personal content to train models. Deletion is available in the app and removes your content from our systems. Integrations are opt-in one by one, and the assistant works without any of them. If you want the storage specifics, where your data lives is documented rather than implied. The full details live in our privacy policy, and if something there is unclear, we treat that as a bug worth fixing.

A sane threat model for normal people

Perfect privacy is not the goal; a fair trade is. You are trading some data for a working memory, reminders that fire, and budgets that answer back. The realistic risks for most people are not movie-plot hacks but mundane ones: data sold to brokers, quiet policy changes after an acquisition, and products that never delete anything. All three are visible in advance if you ask the six questions, which is exactly why vendors who deserve your data make the answers easy to find.

One more mundane risk deserves its own sentence: oversharing by default, in the first week, before you have checked anything. You do not hand a new housemate your tax returns on day one. Start the assistant on scheduling and tasks, check the six answers while it earns familiarity, and let health and finance data in once the trade makes sense to you. Meanwhile, the data about you that no assistant holds, the stuff brokers already bought and sold, is worth a separate cleanup, and the process for deleting your data from data brokers is its own project entirely.

Is it safe to tell an AI assistant personal information?+

It can be, if the vendor is explicit about not training on your data, offers real deletion, limits internal access, and encrypts data in transit. Verify those four points in the privacy policy before sharing sensitive details, and add data gradually rather than all at once.

Do AI assistants use my conversations for training?+

Policies vary widely. Some products train on user content by default, some only with opt-in consent, and some not at all. Search the privacy policy for the word "training"; if the policy does not address it clearly, assume the default is yes.

What data should I never give an AI assistant?+

Full passwords, one-time codes, and complete card numbers do not belong in any chat with any assistant. For everything else, the six-question checklist tells you whether the specific product has earned the specific data.

How do I delete my data from an AI assistant?+

Look for account deletion inside the app settings first; products that hide deletion behind a support email tend to treat it as an afterthought. A trustworthy deletion removes content from production systems and states how backups are handled.

Does turning off permissions actually do anything?+

In a well-built product, yes: revoking calendar or mail access stops the associated processing, and the policy says so. Test it by revoking one integration and asking the assistant something only that integration could answer. A product that still knows is a product that kept a copy, and now you know.

An assistant you can be honest with

Tase is built to hold your life, so it is built to protect it: no selling your data, no training on your content, real deletion.

Get Tase free

Related guides

privacyaisecuritydatatrust