“Private” is doing a lot of work in that question, and it hides four different ones. Here they are separately, because a tool can pass three and fail the one you actually meant.
Four questions inside one word
- •Is it private from other people? Almost always yes. Your conversation is not published and other users cannot read it.
- •Is it private from the company? Usually no, and the policies say so: conversations may be reviewed for safety and improvement, and are stored for a period the provider chooses.
- •Is it private from the model’s training? Sometimes a setting, sometimes a plan, sometimes both — and it changes. Check it rather than assume it, and check it again after a redesign.
- •Is it attached to your name? This is the one people mean and the one nobody advertises. A mainstream assistant knows exactly who is asking: the account, the email, the payment card, the device, and every other question the same account has ever asked.
The risk is rarely one question. It is a thousand of them, filed under your name.
Why the fourth one matters most
Any single question is usually harmless. What is not harmless is the collection: the symptom you looked up in March, the lawyer you asked about in June, the resignation letter you drafted in September — all under one identity, in one history, held by one company, subject to whatever happens to that company later. Nobody decided to build a profile. It accumulates because every message carries the same name.
That is the part a policy cannot fix, because it is not a policy question. It is a plumbing question: what identity does the request carry when it reaches the model?
What to check in any tool
- •What identity leaves your device. If the answer is “my account”, everything else is a promise about how that identity will be treated.
- •What is stripped before the model sees it. Names, card numbers, phone numbers, addresses — either something removes them or nothing does.
- •What happens when a component fails. A privacy step that is skipped when a service is down is a privacy step that is optional.
- •What deleting actually deletes. The conversation, or the conversation and everything derived from it?
Where Secure AI stands on each
The request that reaches a provider carries our credentials rather than your account, so two of your questions are not linkable to each other on their side. Identifying detail is removed before the message leaves — the specifics are in what a model never sees. If that step cannot run, the message is refused rather than sent unprotected.
And the limits, since a page that only lists wins is an advert: the substitution happens on a server, not on your device. Recognising other people’s names in a sentence is best-effort, which is why there is a setting to refuse rather than send when that check cannot finish. Both are stated on the privacy screen inside the app, where somebody deciding what to type can read them.
Questions
Is a local model the answer?
It is an answer, and a good one for some people: nothing leaves the machine at all. The costs are quality and hardware — the models you can run on a laptop are not the frontier ones — so the honest framing is a trade rather than a winner. Our comparison of the approaches sets them side by side.
Does paying for a plan make it private?
It often changes retention and training defaults, which are two of the four questions. It does not change the fourth: a paid account still has your name and card on it.

Try Secure AI free
Frontier AI chat — encrypted by default, with your identity stripped before any request reaches the provider.
