How to Use AI With Your Privacy Intact

Staff
By Staff 15 Min Read

If you wanted to build a machine designed to get people to hand over the most intimate details of their lives, you probably wouldn’t need to look any further than an AI chatbot. These digital conversationalists—ChatGPT, Claude, Gemini, and countless smaller rivals—have slipped into our daily routines and become virtual therapists, sounding boards, and late-night confession booths. People type things into them that they wouldn’t say out loud to their closest friends: secret financial fears, relationship doubts, health symptoms they’re ashamed to mention, career failures they haven’t admitted to anyone. But here’s the uncomfortable part: nearly all of these AI platforms are set up, by default, to collect and store everything you say. There are generally no strict limits on whether that private data can be shared with business partners, used to train the next version of the model, sold to advertisers, or handed over to a lawyer who subpoenas it during a lawsuit or to a law enforcement agency that simply asks for it through a legal process. It’s a bit like walking into a confession booth and discovering that the priest on the other side has been recording everything and keeping notes for anyone who asks nicely. As Matt Green, a privacy-focused computer science professor at Johns Hopkins University, puts it, you’re essentially staring into an intelligent machine and telling it, one question at a time, every possible thing there is to know about your life. With every message, you’re building a huge profile of yourself, entirely from your own keystrokes, and then handing that profile to a server in a faraway data center where you no longer have any say over who might eventually read it.

This is not an entirely new problem, though the stakes have shifted in ways that are hard to appreciate. A decade ago, the most personal data most people carried in their pockets was in the form of text messages. Those messages could be intercepted, stored, leaked, or demanded by authorities, and that vulnerability bothered Moxie Marlinspike, a cryptographer and software developer, so deeply that he created Signal in 2014. Signal is an end-to-end encrypted messaging app that now has well over a hundred million users, precisely because it was built so that even its own creators couldn’t read what people were saying to each other. The math, essentially, is that the private conversation stays locked on each person’s phone, and the servers that pass the message along only ever see a scrambled package that they are unable to open. For a while, that solved one of the most urgent privacy problems of everyday digital life. But Marlinspike now says the battleground has moved. The same worries he had about messages are happening in artificial intelligence, only with far more sensitive material and on a far larger scale. People are using chatbots for something much more revealing than casual conversation. They are integrating AI into their emotional lives, telling it about their deepest insecurities, their financial struggles, their health concerns, their romantic problems, and their complicated feelings about family members. It’s not just a captured snapshot of a moment in time; it’s an ongoing, ever-growing diary that knows how you think, what you fear, and what you hope for. And unlike a text exchange with a friend, the chatbot is not a person who can decide to forget; it’s a corporate product that may be storing every word by default, and that record can be used in ways that you don’t know about and didn’t agree to, at least in any meaningful sense.

Marlinspike decided to do something about it. Earlier this year, he launched Confer, an AI chatbot with a very different design philosophy: it uses cryptography to make it technically impossible, not just policy-wise difficult, for the service’s own servers to surveil or log your conversations. This isn’t the kind of promise that depends on a friendly company spokesperson telling you to trust them. It’s a structural guarantee. When you type a question into Confer, the interaction is protected in such a way that the server can process it and send back a response without ever being able to retain a readable copy of what you asked or what the AI answered. Marlinspike explained the idea in a blog post with a bit of poetic warning: Confer is designed to let you explore ideas without having your own thoughts potentially conspire against you someday. You can ask the chatbot for advice about a career change, confess a mistake you’ve been carrying around, or brainstorm something you haven’t told your partner, and there will be no transcript lying around for an advertiser, an ex-spouse’s lawyer, a nosy employer, or a government agent to discover later. It’s like stepping into a private room where the walls are made of math rather than drywall, and the conversation evaporates the moment it ends. You still get an answer from the AI, but nobody gets to write down what you said. The point is not that you necessarily did anything wrong; the point is that you should have the right to think aloud, to question yourself, to float half-formed ideas, without leaving a permanent electronic paper trail that may follow you around for years. For anyone who has ever muttered something to a chatbot and then felt a small chill of regret, wondering if that question just became part of some corporate database, the idea is almost liberating.

Confer is not the only one trying to address this epidemic of AI surveillance. A whole new generation of privacy-focused AI tools has sprung up, each with its own approach, and each with its own strengths and weaknesses. Some promise never to record conversations as a matter of policy, which is better than nothing but still depends on the promise being kept and on a legal system that can demand the data anyway. Others try to anonymize the conversations before they’re stored, so that even if someone gets access to the record, they can’t tie it to you personally—though true anonymization is notoriously difficult, especially when the content of a conversation itself may reveal your identity. A few, like Confer, aim for actual technological guardrails that restrict the service’s ability to see your secrets in the first place, which is the strongest approach. But all of these options can be deeply confusing for ordinary people who just want to use a useful tool without losing control of their private lives. The marketing language is fuzzy; the privacy policies are written by lawyers; and the technical details are hard to parse. And the biggest services, the ones that people actually use every day, are not especially interested in making this easy for you. If you open a free account with one of the major chatbots, you’re often just one click away from having everything stored indefinitely, with only the vaguest promises about how the data will be treated. Meanwhile, these companies are racing to train better models, and every conversation you give them is a small piece of free labor that improves the product for everyone else. You might very well be the user and the product at the same time, and no amount of friendly interface design can change that basic fact.

The concept to understand, if you want to stay safe, is something called zero data retention, or ZDR. It sounds abstract, but it’s actually a simple idea: a legal contract between an AI provider and a customer—often a business rather than an individual—that requires the provider to delete the record of every interaction immediately after it is processed. OpenAI, Anthropic, and Google all offer ZDR policies for their enterprise versions. When your employer signs up for a business plan and enables ZDR, the system is supposed to take your conversation, generate a response, and then destroy the transcript, leaving nothing behind to train on, sell, or surrender to a subpoena. For an individual using a free account, by contrast, the default expectation should be close to zero privacy from anyone who is determined to get at your conversation records and has a legal way to do it. That includes the company that owns the AI, the contractors who help tune the model, any business partners they might share data with, and any government agency that shows up with the right paperwork. This is not necessarily because these companies are evil; it’s because the whole model is built on centralization and retention, and changing that model is expensive and inconvenient. So if you want to use a major AI chatbot and you genuinely care about your privacy, you need to approach it the way you would approach a conversation with a stranger who has an excellent memory and a legal obligation to answer questions from authority figures: watch what you say, avoid identifying details, and don’t treat it as your personal diary. Or, if you can get your employer to sign a ZDR contract, you can enjoy a much stronger level of protection, because there is at least a legal commitment behind the promise of deletion. But even then, you need to read the actual terms, understand what’s included, and ask whether the deletion really means deletion, especially in cases where the AI provider may have already used your input to improve a model.

So what does all of this mean for the average person, who just wants to use AI without turning their deepest thoughts into a corporate asset? It means you have to be deliberate, skeptical, and informed. First, if you’re using a major free chatbot, assume that anything you type could eventually be seen by someone you didn’t intend to see it. Don’t tell it your social security number, your home address, your real name, or the specific details of a secret you wouldn’t want spread around. Use pseudonyms for people, change the details of your situation if you can, and consider the whole interaction as if it were a conversation with a journalist who is taking notes and might publish them. Second, if you’re using a chatbot for something genuinely sensitive, seek out services that have a structural commitment to privacy, not just a wordy policy page. Confer is one example, but there are others, and new ones are appearing all the time. Look for things like end-to-end encryption, local-only processing, and no-retention guarantees that are built into the architecture, not just promised in a document. Third, if you’re using AI through your workplace, ask your IT department or your manager about zero data retention arrangements, and don’t assume that your company has already opted into the strictest privacy settings. Many organizations don’t bother, and their employees end up feeding their private thoughts into a system that keeps everything. Fourth, remember that the technologists who think most deeply about this are not just warning you of vague dangers; they are building tools because they genuinely believe that an AI confidant that remembers everything is a dangerous thing. The digital world has already seen how private messages can come back to haunt people years later, and AI conversations are more intimate, more revealing, and more permanent. If you wouldn’t want your diary read aloud in a courtroom someday, don’t type it into a chatbot with weak privacy protections. There is something deeply human about talking to a machine, about being heard without being judged, about being able to ask awkward questions without making eye contact. That connection is valuable, and it shouldn’t disappear. But it should be safe. You deserve the comfort of an intelligent conversation without the anxiety of a permanent record. The technology is still young, and the rules are still being written, but one thing is becoming clear: the way we protect our inner worlds from the outside world is not just a technical problem, it’s a human one. And the tools that respect our secrets will eventually be the ones we trust with our thoughts.

Share This Article
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *