Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Keep credentials, customer data, and unnecessary proprietary code out of AI prompts. If your organization allows internal material to be sent to an AI service, share only the minimum sanitized context needed, use an approved account and service, and verify how that exact product handles training, retention, files, saved state, and connected tools. A promise not to train on your data does not, by itself, mean the data is never stored.

What “private” means when you use an AI model

There is no single privacy switch that answers every question about an AI service. Before sending code or security information, distinguish at least four things:

  • Training and product improvement: whether prompts and responses may be used to improve models or products.
  • Retention: whether the provider stores prompts, responses, or related data, and for how long.
  • Product state: whether chats, uploaded files, caches, or multi-turn sessions remain available after a request.
  • Access and protection: who can access the information and what administrative, contractual, and security controls apply.

These controls can differ between a consumer chat product, a business workspace, an API, and individual API features. They can also differ within one service depending on account settings and endpoint. Assess the specific product and configuration your team will use rather than treating a provider’s general privacy statement as a guarantee for every feature.

How the documented provider policies differ

The following describes the cited documentation for particular services—not a ranking of providers or a comparison of equivalent configurations. OpenAI’s sources cover business/API services and security features; Anthropic’s retention source covers commercial products; Google’s source is specifically for the Gemini Developer API.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Service and source scope Training or product improvement Retention and saved data Important limits
OpenAI business and API documentation OpenAI says business and API inputs and outputs are not used for model training by default. API abuse-monitoring logs may include prompts and responses and are retained for up to 30 days by default, subject to exceptions. OpenAI documents approved Zero Data Retention and Modified Abuse Monitoring controls for eligible customers. Eligibility, approval, endpoint, and feature limitations apply. Some endpoints or features may retain application state. The business security documentation also describes encryption at rest and in transit, Enterprise Key Management for eligible setups, and access-management features.
Anthropic commercial products; retention article dated July 1, 2026 The cited retention article does not establish every training or product-improvement rule. Check the terms that apply to the particular commercial service and contract. Commercial API inputs and outputs are automatically deleted from the backend within 30 days under the standard policy described. Saved commercial chats and coding sessions remain in-product until deleted; deletion from the backend is described as occurring within 30 days. Exceptions include services with longer retention, agreement, policy enforcement, or legal requirements. Information flagged by policy may be retained longer. The cited retention source does not establish all product security controls.
Google Gemini Developer API; documentation updated September 14, 2026 For Paid Services, Google says prompts and responses are not used to improve Google products. Storage varies by feature. Search or Maps grounding stores prompts, context, and output for 30 days. Uploaded files remain until deleted or expired; interaction state, Live API session resumption, and cached content have their own conditions. Some feature storage cannot be disabled when that feature is used. Stateful APIs and File API use require configuration or deletion to avoid data persistence. These statements apply to the Developer API documentation, not every Google AI product.

The retention durations above describe specific behaviors, not a guarantee that every kind of data is removed on the same schedule. OpenAI’s API documentation, accessed in 2026, describes up to 30 days for default abuse-monitoring logs; Anthropic’s July 1, 2026 commercial retention article describes backend deletion within 30 days for standard API inputs and outputs; Google’s Gemini Developer API documentation, updated September 14, 2026, describes 30-day storage for data associated with Search or Maps grounding. Each has its own scope and exceptions.

For a real assessment, compare the exact surface and endpoint, training use, abuse-monitoring retention, saved state, files and caches, connected tools, deletion behavior, user access, encryption, region, and contractual protections. A “zero data retention” label needs particular care: OpenAI documents eligibility, approval, and endpoint limitations, while Google documents feature-specific storage conditions that can remain when those features are used.

A safer workflow for sharing code or security data

  1. Classify the material before prompting. Check whether it contains credentials, personal or customer information, security findings, proprietary code, or information restricted by policy, contract, or law. Do not send material that is not approved for the selected service.
  2. Reduce the payload. Provide only the relevant function, error, or configuration excerpt. Replace real names, identifiers, and values with synthetic examples. Remove passwords, access tokens, private keys, connection strings, and customer details. Avoid uploading a full repository or large log when a small sanitized sample is enough.
  3. Use the approved account and service. Confirm the product, account type, organization settings, and applicable terms. A personal account should not be assumed to have the same contractual terms or administrative controls as an approved business workspace or API configuration.
  4. Trace the full data path. Check the training setting and retention policy, then check the specific behavior of conversation history, application state, file uploads, caches, grounding, session resumption, and external tools or integrations. OpenAI documents endpoint-specific state and retention limits; Google’s Gemini Developer API documentation separately describes Search/Maps grounding, Interactions API state, Live API session resumption, files, and explicit caching.
  5. Limit access and set governance. Restrict who may use the service and what repositories or data they may provide. Review the administrative and security controls enabled for your chosen product. OpenAI describes access-management features and encryption options, including Enterprise Key Management for eligible setups; confirm availability and configuration for your own service.
  6. Use repository leak prevention as a separate safeguard. GitHub secret scanning and push protection can detect or block supported credentials in repositories. GitHub says push protection blocks supported secrets before they reach protected repositories, but the feature can be bypassed and coverage depends on the enabled feature and supported secret types. It does not make pasting a credential into an AI prompt safe.
  7. Respond to accidental exposure. If a real credential reaches a prompt, tool, repository, or other unintended destination, follow your incident process. Treat credentials exposed in repositories as compromised and rotate or revoke them as appropriate; GitHub’s documentation advises remediation of real exposed secrets.
  8. Recheck after changes. Review the applicable terms and controls at procurement and after material changes to the product, endpoint, account configuration, or enabled features. Provider behavior and documentation can change.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What repository secret scanning can—and cannot—do

Repository scanning is useful for catching certain supported credentials before or after they are committed. Its coverage depends on the secret type and enabled feature, and push protection can be bypassed. It is not a prompt filter, a guarantee that every secret will be detected, or a way to undo disclosure to an AI service. Keep secret hygiene, prompt minimization, and repository controls as distinct layers.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.