When you type a prompt, upload a document or paste text into an AI tool, the interaction can feel simple: send something in, receive an answer, close the chat.

Behind that interface, the service may need to transmit, process, retain or log information. Depending on the product and account, people or subprocessors may also have limited access, and some content may be eligible for model improvement.

There is no single answer to “What does AI do with my data?” The more useful question is:

What does this specific service do with our data under this specific account and configuration?

That distinction matters because training is only one possible use of data. “Not used for training” does not mean “nothing is stored, logged or processed.”

Think in stages, not one universal lifecycle

There is no fixed six-step pipeline that every AI service follows. A better mental model is a set of data-handling stages that may apply differently depending on the service.

1. Transit

Your prompt or file has to travel from your device to the service.

Business AI providers usually document how data is protected in transit, but it is worth checking what actually sits on the path. An unofficial AI wrapper, browser extension, enterprise gateway, reverse proxy or connected service may process the content before or after it reaches the model provider.

The important question is not only “Is it encrypted?” but also “Which services receive it on the way?”

2. Processing

The service processes your input to generate a response.

That may involve more than the model itself. File parsing, retrieval, web search, safety systems, connected apps and tools can all become part of the processing path.

And outputs are data too. The generated answer may itself contain information derived from private inputs or connected systems, so its retention and onward use matter just as much as the original prompt.

3. Retention and logging

A provider may retain prompts and outputs for conversation history, security, abuse monitoring, reliability, support or legal obligations. Retention periods can vary by product, account and configuration.

Deleting a chat from the interface and preventing model training are separate controls.

For example, OpenAI's current retention documentation says deleted chats are normally scheduled for deletion from its systems within 30 days, subject to exceptions such as security or legal obligations.

That is a useful reminder that “delete” is a product control, not a guarantee that every copy disappears instantly in every circumstance.

4. Human access or review

Some AI services allow limited authorised human access for purposes such as safety, support, abuse investigation or product improvement.

Whether that happens, why it happens, and whether business products are treated differently is provider-specific.

Consumer and business products from the same provider can have different commitments. Do not assume that a consumer account and a company-managed business account handle review or improvement in the same way.

If a human reviewer can see the content, removing the account name does not automatically remove sensitive details typed into the prompt itself.

5. Model improvement or training

Some consumer services may use eligible interactions to improve models unless the user changes the relevant control; many business products make different default commitments.

For example, OpenAI says data from its business products and API platform is not used to train models by default, while consumer ChatGPT users can control model-improvement use through Data Controls.

Feedback can be a separate path too. Ratings, shared conversations, bug reports or other feedback features may have their own data-use rules, so an “off” training setting does not necessarily answer every question about content submitted through those channels.

6. Subprocessors and connected services

AI services can rely on infrastructure providers and other subprocessors. Features such as web search, connectors or actions may also send data to additional services.

That means the provider’s subprocessor list and the privacy terms of connected third parties matter.

Data location needs care too. A statement about where data is stored does not automatically tell you every country from which support staff, subprocessors or connected services may be able to access it. Residency, processing location and access are related questions, but they are not identical.

Consumer and business accounts can differ - but not in one universal way

Business, enterprise and API offerings often include stronger contractual commitments or administrative controls than consumer products. That can include different training defaults, retention controls, access management, security features or data-processing terms.

But it is unsafe to generalise that all consumer products retain data indefinitely, all enterprise products prohibit human review, or every business account offers zero retention.

Those details differ by provider and sometimes by plan.

OpenAI provides a useful example of why account type matters: business/API data is not used for model training by default, consumer users have separate Data Controls, and Temporary Chats are not used to train models and may be retained for up to 30 days for safety purposes.

Those are OpenAI-specific examples, not universal AI rules.

Temporary and private modes change some controls, not every risk

A temporary or private mode may change chat history, retention or model-improvement behaviour.

It does not necessarily mean the provider performs no processing, keeps no security records, or prevents data from being sent to third parties through connected actions.

Similarly, zero-data-retention options are usually specific enterprise or API configurations with eligibility and technical conditions. Treat them as product features to verify, not assumptions about enterprise AI in general.

Six questions worth asking before sending sensitive data

These questions are not another lifecycle. They are a checklist for investigating how a particular service handles the stages above.

  1. Is our content used for model training or model improvement by default on this account?
  2. How long are prompts, files and outputs retained, including security or abuse logs?
  3. Who can access retained content, and under what circumstances?
  4. Which subprocessors or connected third parties may process the data?
  5. Where is the data processed or stored, and what contractual or data-processing terms apply?
  6. What changes when we use a business, enterprise, API, temporary or zero-retention configuration?

Why this matters for organisations

For organisations handling personal data, vendor promises about model training are only part of the picture.

The UK Information Commissioner's Office emphasises transparency about why personal data is processed, how long it is retained and who it is shared with.

That means organisations still need to understand why they are sending personal data to an AI system, how much data is necessary, who receives it and how long it is kept.

Using a personal consumer account or an AI app on a phone does not make those organisational responsibilities disappear.

For the related question of what information should be shared in the first place, see Can I paste this into AI?. For the risk of information escaping its intended audience through prompts, connectors or outputs, see Can AI leak your data without being hacked?.

Key takeaways

  • There is no single data lifecycle shared by every AI product.
  • Processing, retention, logging, human access, training and subprocessor use are separate questions.
  • “Not used for training” does not mean “nothing is stored”.
  • Prompts and outputs can be retained or processed, and feedback features may create separate data paths.
  • Consumer and business products can differ substantially, but the exact controls are provider- and plan-specific.
  • Check the current documentation for the exact service, account and configuration before using sensitive information.

A note on changing products

Vendor privacy terms, retention periods and account controls change frequently. securedby.ai re-opened and checked the sources above on 14 September 2026. Recheck the current terms, privacy documentation and trust/security materials for the exact service and account you plan to use.