Judgment in the Age of AI · Article 15
Many people begin chatting and search for privacy settings only after uploading material. A better order is a five-minute inspection before real use. You need not read every clause, but you should know where data goes, who can access it and how to stop.
Minute one: confirm what you are using
Check the developer, official website, app-store publisher and URL. Similar names on plugins, browser extensions or imitation apps may conceal very different permissions.
Minutes two to four: inspect four groups of controls
| Setting | Question to answer |
|---|---|
| History | Are conversations stored, and can storage be disabled or deleted? |
| Training and improvement | Are inputs used to train models, and can you opt out? |
| Connections | Which files, email, calendar, contacts or cloud drives can it read? |
| Sharing and retention | Who processes the data, for how long and in which region? |
Minute five: design the exit
- Locate conversation and account deletion
- Know how to revoke third-party connections and tokens
- Record subscription cancellation and data-export options
If this information is missing, vague or the requested permissions greatly exceed the task, do not supply real data. Testing with non-sensitive content is the cheapest form of due diligence.
References
- OAIC: Privacy and Commercially Available AI Products
- Cyber.gov.au: Guidelines for Secure AI System Development
Discover more from Geoffrey Chen
Subscribe to get the latest posts sent to your email.