For your own documents, usually yes. The question changes completely when the file is about somebody else — and that is almost always the file people are nervous about.
When it is genuinely fine
Most uploads are not the problem, and it is worth saying so plainly:
- •Your own CV, your own draft, your own notes
- •A published document — a standard, a public filing, a manual
- •Something you wrote that mentions nobody else
- •A file where every name and number has already been changed
In those cases the realistic risk is a breach at the provider, which is the same risk you accept with every other service you use. Reasonable people accept it daily.
What actually happens to the file
It leaves your machine. It is stored, associated with your account, and available to the provider — and depending on your settings and plan, it may be used to improve the model.
- •Consumer accounts. Uploads can be used for training by default. There is a setting to turn it off, and it is not on in your favour to begin with.
- •Business and enterprise. Inputs are excluded from training by contract, with a processing agreement behind it.
- •Deletion. Removing a chat removes it from your view. Retention of the underlying data follows the provider’s policy, not your delete button.
The file is not the risk. Everybody the file identifies is the risk.
The question that actually matters
Not is this provider secure. They are large companies with real security teams, and for most documents that is enough.
The question is was I entitled to send this. A client file, a patient letter, a payroll run, a tenancy agreement, a grievance — these contain people who did not agree to be uploaded anywhere, and the duty not to disclose them sits with you. A provider’s security posture does not transfer that duty, and a business plan does not either. It governs what happens after the file arrives.
What people get wrong
- •Deleting the name. A date of birth, a postcode, an account number or an unusual set of facts identifies somebody on its own. A file with the name removed is a file with the name removed.
- •Trusting the delete button. It clears your view. It does not reach back through the sending.
- •Assuming a paid plan settles it. It settles half — the half about the provider, not the half about you.
The arrangement that works
Read the file on your own machine, take the people out of it before anything is sent, and put them back into the answer.
That is what Secure AI does. PDFs, Word documents, spreadsheets and photographs are opened on your device and never uploaded. The names, numbers and addresses inside them are replaced with plausible stand-ins before the question goes out, and the real values are restored in the reply — so the model works on a coherent document and never receives a real person.

Try Secure AI free
Frontier AI chat — encrypted by default, with your identity stripped before any request reaches the provider.
Common questions
What about a photograph of a document?
A photograph has no text until something reads it. If that reading happens on a server, the document was uploaded in order to be read — which is the thing being avoided. It should happen on your own machine.
Does the file get seen by a human?
Possibly, and that is normal rather than sinister: providers sample content for abuse and safety review, and staff can access data under controls. It is one more reason the question is what you sent rather than how well it is guarded.
Is a local model safer?
Nothing leaves at all, which is as safe as this gets. The trade is that a model you can run on a laptop is meaningfully behind one you cannot, and for the documents most people are asking about that gap is the reason they wanted a model.
