What actually happens to the text you paste into an AI chat

People worry about AI chats in a vague way. The vagueness is the problem, because it produces either paralysis or shrugging, and neither is a policy.

Here is what actually happens, stated in general terms that survive the frequent changes to any individual provider's rules.

Your text is transmitted and stored

This is unavoidable and not sinister. The model runs on someone else's hardware, so your text goes over the network to reach it. It is written to disk somewhere along the way, because that is how services handle requests.

The meaningful questions are what happens next: for how long, who can read it, and whether it feeds back into training.

Retention is not zero, even when training is off

Most providers keep inputs for a period measured in weeks, for abuse detection and debugging, and this applies even when the account has opted out of training. "We don't train on your data" and "we don't store your data" are different claims, and only the first is usually being made.

Practical consequence: text you send today exists on a third party's systems tomorrow, whatever the training setting says.

Consumer and business tiers differ, and this is the distinction that matters

Consumer chat products tend to default to using conversations for improvement, with an opt-out available in settings. Business, enterprise and API tiers usually default the other way, with contractual commitments not to train on customer content.

The common mistake is assuming the company's enterprise agreement covers a personal account. If you signed in with a work email through your employer's tenancy, it likely does. If you opened a free account on your phone and pasted a customer transcript into it, it does not, regardless of what your employer negotiated.

Human review is a real possibility

Providers reserve the right to have people look at flagged conversations for safety and quality. The volume is small and reviewers are bound by confidentiality, but "no human will ever see this" is not a promise any major provider makes.

For most text this is irrelevant. For an unreleased financial figure or a client's medical detail, it is exactly the risk you were worried about.

What to do with this

The useful reframing is that pasting into an AI chat is a form of publication to a third party, similar to emailing an external contractor. Not reckless, not private, and governed by whatever agreement is actually in place.

From there the decisions get concrete:

Why we do not name specific retention windows

We would rather give you a durable mental model than a number that goes stale. Providers revise these policies regularly, and an article confidently stating "thirty days" becomes actively misleading the week it changes.

Go to the provider's own privacy documentation for the tier you use, and check the date on the page. That is the only version that is authoritative, and it is where we would send you even if we had reproduced it here.

Check the current policy

Provider rules change. Before pasting anything sensitive, check the current documentation for the product and account tier you use: