There is not enough evidence for breaking news
Privacy in AI assistants is an important subject, but that does not make every explanation of their policies a news story. To support a current-affairs article, it is necessary to identify a specific change—for example, a change to a feature or policy—and verify when it happened, whom it affects and what documentation confirms it. The information gathered for this article does not provide sufficient evidence of a recent change of that kind. The responsible approach is therefore a fact-checking guide, not an announcement of new developments.
The distinction matters because a general policy, a help page and a community post do not carry the same evidentiary weight. OpenAI’s pages on privacy and ChatGPT controls document the terms and options the company attributes to its own services; the European Data Protection Board (EDPB) page brings together information about its work on artificial intelligence and data protection. None of these references, on its own, proves that a provider has recently changed its practices. Not presenting as new what the sources neither date nor describe as a change is part of verification, not an absence of analysis.
Which documents to consult and what to ask
Start with the privacy policy that applies to the service and the place where it is used. Check its date or version, the provider that publishes it, and whether it covers a consumer app, a work account or another product. A company’s general page may not answer every question about a particular feature. It is also worth checking the product’s official help pages, since they may describe controls that are not explained on a concise corporate information page.
Read for specific answers, rather than relying only on broad claims such as “we protect your privacy.” For each piece of information you are considering entering, try to establish what information the service processes, for what purpose, who can access it, how long it is retained, and what options exist to delete it or limit its use. If the documentation does not say clearly, record that as an unanswered question: do not infer an answer from marketing language. Retention can refer to different types of data and different periods; do not assume that one deletion option addresses all of them.
Controls are not a complete policy
A privacy setting may allow users to change one aspect of how their data is used, but its existence does not, by itself, explain all data processing. Check exactly what it controls, whether it applies to future conversations or also to ones already saved, and whether the change covers every feature in the service. Before claiming that an option “turns off training” or “deletes the data,” verify that the documentation uses that scope and specifies the relevant conditions. If only a partial description is available, state the conclusion with that limitation.
OpenAI’s official pages distinguish between consumer privacy information, its privacy policy and enterprise privacy. This range of documentation illustrates why it is unwise to transfer a rule from one offering to another without checking which one it concerns. In practical terms, users should locate the documentation for their account and feature, and save the link or date consulted if they may need to compare changes later. A control visible on screen should not be mistaken for a universal guarantee covering all data, purposes or time periods.
How to cross-check what the provider says
The provider’s documentation is the primary source for learning what it says about its own service. It is not, however, an independent assessment of how that statement is applied in every case. The EDPB explains that artificial intelligence can raise data-protection issues and presents the work and resources of European authorities in this area. That reference provides regulatory context, but it does not automatically confirm a violation or validate a specific claim about a particular assistant.
For a sound editorial check, separate three layers: what the provider documents, what an authority or independent investigation has established, and what remains unverified. A question in a user forum or an informal answer may point to an issue worth investigating, but it does not replace an official policy or an authority’s decision. Likewise, a commercial guide or comparison article may offer context, but should not be treated as conclusive proof of a service’s practices. Cross-checking means verifying the scope and date of each source, not assuming that two texts refer to the same version.
A practical checklist before sharing information
Documentation can be lengthy, but a quick review can focus on concrete decisions. Before using an assistant for a sensitive task, check:
- Which service and offering you use: a personal account, an enterprise product or an integrated feature; do not assume they share the same terms.
- What data you plan to enter: remove identifiers, credentials, medical information or other people’s data that is not necessary.
- What official sources say: look for processing, purpose, retention, deletion and controls, and check the page date.
- What remains unanswered: if the duration or scope of a control is ambiguous, do not fill the gap with an assumption.
- What alternative you have: if you cannot verify how sensitive data will be handled, avoid sharing it or consult the appropriate channel in your organisation.
These guidelines do not replace legal advice or a security review for a company. They are a way to reduce the risk of reading too much into an interface or general text. If an assistant’s response would be useful but depends on confidential information, consider whether you can rephrase the request using fictional or minimal data; the decision depends on the context and applicable rules. Privacy is not assessed only by what the user sees in a conversation: the service terms and account type also matter.
Conclusion: report with clear limits
The evidence reviewed supports a general recommendation: check the service’s official documentation, distinguish consumer policies from enterprise policies, and seek guidance from the relevant authorities. It does not support claiming that a provider has just announced a specific change to retention or controls. The headline and approach should therefore describe a useful guide, not breaking news.
If a dated and verifiable change is found later, a specific news article can be prepared using the old and new wording, its effective date, the accounts affected and an independent source where available. Until then, the conclusion must remain limited: the available documentation cannot resolve how every item of data is handled or support a rigorous comparison of all assistants. That caution does not make the guide useless; it helps readers know what to check and what not to treat as confirmed.