Is Your Data Safe With AI Tools? Privacy Basics
Every time you paste text into an AI chatbot, that data goes somewhere. Most free AI tools store your inputs, and some use them to train future models. Understanding ai tools data privacy is not optional if you handle client information, financial records, or personal details at work. Here is what to know and what to do about it.
Every time you paste text into an AI chatbot, that data goes somewhere. Most free AI tools store your inputs, and some use them to train future models. Understanding ai tools data privacy is not optional if you handle client information, financial records, or personal details at work. Here is what to know and what to do about it.
How AI tools actually handle your data
When you type a prompt into ChatGPT, Claude, Gemini, or any other AI assistant, your input travels to a server (usually outside Kenya), gets processed, and a response is generated. What happens to your input after that depends on the tool, your account type, and your settings.
Most free-tier AI tools retain your conversations. OpenAI, for example, stores your ChatGPT conversations and may use them to improve their models unless you opt out. This means that a prompt you wrote containing a client's financial details could, in theory, become part of the data used to train the next version of the model. That data might then influence outputs shown to other users.
Paid business plans typically offer stronger protections. OpenAI's ChatGPT Team and Enterprise plans, Anthropic's Claude business plans, and Google's Gemini for Workspace plans generally commit to not using your data for model training. But "generally" is doing a lot of work in that sentence. You need to read the actual terms.
The core principle is simple: assume everything you paste into an AI tool could be seen by others, unless you have verified specific privacy protections in your plan's terms of service.
What you should never paste into an AI chatbot
This is the most practical section of this guide. We keep this list on a sticky note next to our screens, and we recommend you do the same.
Client personal data
National ID numbers, passport numbers, phone numbers, email addresses, physical addresses, or any combination of information that identifies a specific person. If a client sent you their KRA PIN to help with a tax filing, that PIN does not belong in a ChatGPT prompt.
Financial information
Bank account numbers, M-Pesa statements, credit card details, salary figures for specific individuals, or unpublished company financial results. Even if you are asking the AI to "help analyse this data," the data itself becomes part of the conversation log.
Passwords, API keys, and access credentials
This seems obvious, but it happens constantly. Developers paste code containing API keys. Administrators paste configuration files with database passwords. If you are asking an AI to debug code, strip out any credentials first and replace them with placeholder values.
Confidential business information
Unreleased product plans, proprietary pricing strategies, merger discussions, legal case details, or internal HR matters. If the information would cause problems if a competitor saw it, do not put it into an AI tool without verified enterprise-grade protections.
Medical or health records
Patient information, lab results, prescription details, or any data covered by professional confidentiality obligations. If you work in a Kenyan clinic or hospital, this applies to everything in your patient management system.
Unpublished creative or intellectual property
If you are working on a manuscript, a business plan you intend to patent, or proprietary research, pasting the full text into a free AI tool means you have effectively shared it with the tool provider. There is no guarantee that fragments of your content will not influence future model outputs.
The settings that actually matter
Most AI tools offer some privacy controls. Here are the ones worth finding and adjusting.
ChatGPT (OpenAI)
Go to Settings > Data Controls > Improve the model for everyone and turn it off. This tells OpenAI not to use your conversations for model training. Note that OpenAI may still retain your data for abuse monitoring and legal compliance for up to 30 days, but it will not feed your prompts into training datasets.
If you use ChatGPT through the API (for building applications), data submitted through the API is not used for training by default. This is a meaningful distinction for developers.
Claude (Anthropic)
On the free plan, Anthropic may use your conversations to improve their models. On paid plans (Pro and Team), Anthropic commits to not training on your data. Check the current terms at anthropic.com/privacy, as these policies evolve.
Google Gemini
Gemini conversations on the free tier can be reviewed by human reviewers and used for model improvement. In Google Workspace plans with Gemini, Google states that Workspace data is not used for training. If you are using Gemini through a personal Google account versus a Workspace account, the protections differ significantly.
General rule for any tool
Look for these specific settings or policy statements: "Do not use my data for training," "Data is not retained after the session," and "Conversations are encrypted at rest." If you cannot find these, assume the tool is using your data.
Practical steps for Kenyan professionals
Create a personal data policy
You do not need a 50-page document. Write down three rules and stick them where you work. Something like: "I will not paste client names, ID numbers, or financial data into any AI tool. I will review AI tool privacy settings monthly. I will use the company's approved AI tools for work, not my personal accounts."
Use local files for sensitive work
If you need AI to help with a document containing sensitive information, consider using AI tools that run locally on your device rather than sending data to cloud servers. Tools like Ollama allow you to run AI models on your own laptop. The outputs will be less capable than cloud-based tools, but your data stays on your machine.
Separate personal and work AI accounts
If you use ChatGPT for personal curiosity (recipes, travel planning, homework help) and also for work tasks, use separate accounts. Your personal account's conversation history should not contain work data, and your work account should be on a plan with appropriate privacy protections.
Be careful with screenshots and copy-paste chains
Sometimes the privacy risk is not the AI tool itself but how you get data into it. Copying text from a confidential document, pasting it into a chatbot, and then forgetting to clear the conversation creates a record. If you share your screen in a meeting later, that conversation might be visible.
Check what your employer allows
Many Kenyan companies and organisations are developing AI usage policies. If your employer has one, read it. If they do not, ask about it. Using an AI tool in a way that violates your employment terms or professional regulations is a risk that no productivity gain justifies.
Kenya-specific considerations
Kenya's Data Protection Act (2019) and the regulations enforced by the Office of the Data Protection Commissioner (ODPC) apply to how you handle personal data, including when you input that data into AI tools. If you are a data controller or processor under the Act, using an AI tool to process personal data without appropriate safeguards could constitute a violation.
For businesses that handle customer data (medical clinics, law firms, financial advisors, HR departments), the question of ai tools data privacy is not just about convenience. It is a compliance issue. The ODPC has been increasingly active in enforcement, and "I did not know the AI tool stored the data" is not a defence.
If your organisation processes personal data and wants to use AI tools, consider conducting a Data Protection Impact Assessment (DPIA) for the specific tools you plan to use. This is already a requirement under the Act for high-risk processing.
The honest trade-off
AI tools are genuinely useful. We use them daily for research, drafting, brainstorming, and analysis. The goal is not to avoid AI tools entirely. That would mean missing out on real productivity gains. The goal is to use them with clear boundaries.
Think of it like M-Pesa. You would not send your entire savings to an unverified number just because M-Pesa is convenient. You verify the recipient, check the amount, and confirm before sending. Apply the same discipline to AI tools. Verify what the tool does with your data, check the settings, and confirm you are comfortable before pasting.
Our AI and Automation for Beginners course includes a module on responsible AI use that covers these privacy practices in detail, with exercises you can apply to your own work immediately.
FAQ
Can my employer see what I type into AI tools?
If you are using a company-managed account (such as ChatGPT Team or Enterprise, or Gemini through Google Workspace), your administrator may have access to usage logs or conversation data. If you are using your personal account on a work computer, your employer may be able to see that you accessed the tool through network monitoring, though they likely cannot see the specific conversation content. Check your company's IT and AI policies.
Is it safe to use AI tools for KRA tax filing help?
You can safely ask general tax questions ("What is the VAT rate for digital services in Kenya?" or "How do I file a nil return?"). Do not paste your actual KRA PIN, income figures, or tax return details into a free-tier AI tool. If you need AI to help with your specific tax situation, use a paid plan with verified data protections, or remove identifying details before pasting.
Do AI tools comply with Kenya's Data Protection Act?
Most major AI tools are built by companies based in the US or Europe. They comply with GDPR and their own jurisdiction's laws. Whether they fully comply with Kenya's Data Protection Act depends on the specific tool, plan, and how you use it. As the data controller, you are responsible for ensuring the tools you use meet Kenyan legal requirements for the data you process through them.
What happens to my data if an AI company gets hacked?
Data breaches are a real risk. In 2023, OpenAI experienced a bug that briefly exposed some users' conversation histories to other users. If an AI provider is breached and your conversations contain sensitive data, that data could be exposed. This is another reason to avoid putting sensitive information into AI tools in the first place. The less sensitive data in the system, the less damage a breach can cause.
Frequently Asked Questions
### Can my employer see what I type into AI tools?
If you are using a company-managed account (such as ChatGPT Team or Enterprise, or Gemini through Google Workspace), your administrator may have access to usage logs or conversation data. If you are using your personal account on a work computer, your employer may be able to see that you accessed the tool through network monitoring, though they likely cannot see the specific conversation content. Check your company's IT and AI policies.
Is it safe to use AI tools for KRA tax filing help?
You can safely ask general tax questions ("What is the VAT rate for digital services in Kenya?" or "How do I file a nil return?"). Do not paste your actual KRA PIN, income figures, or tax return details into a free-tier AI tool. If you need AI to help with your specific tax situation, use a paid plan with verified data protections, or remove identifying details before pasting.
Do AI tools comply with Kenya's Data Protection Act?
Most major AI tools are built by companies based in the US or Europe. They comply with GDPR and their own jurisdiction's laws. Whether they fully comply with Kenya's Data Protection Act depends on the specific tool, plan, and how you use it. As the data controller, you are responsible for ensuring the tools you use meet Kenyan legal requirements for the data you process through them.
What happens to my data if an AI company gets hacked?
Data breaches are a real risk. In 2023, OpenAI experienced a bug that briefly exposed some users' conversation histories to other users. If an AI provider is breached and your conversations contain sensitive data, that data could be exposed. This is another reason to avoid putting sensitive information into AI tools in the first place. The less sensitive data in the system, the less damage a breach can cause.
7-minute Welcome lesson, no purchase required
Bonaventure Ogeto
Founder, Mctaba Labs
Software engineer building products for the African market. Teaching 10,000+ students across multiple platforms. BSc Mathematics & Computer Science from JKUAT.