What you hand over

85 min

Listen: this lesson as a conversation

Two hosts talk the lesson through. The voices are synthetic; the script was written from this lesson and checked against it, and asserts nothing the lesson does not.

In this lesson you will learn to
  • Find out what the product you use does with what you type into it, and write down the sentence and the date you read it
  • Decide by category rather than case by case what you are willing to put in, and say what each decision rests on
  • Say what changes when the account is your employer's rather than your own, and find out which yours is

Everything so far in this course has been about what comes back. This lesson is about what goes in, and it's the shortest here because most of it is a document you can go and read in twenty minutes.

It is also the lesson most likely to stop you doing something you cannot undo, because what you have typed into somebody else's system is typed.

Three things, and you can establish all of them yourself

What the provider says it does with what you type. This is a published document with a date on it. It differs by product, by plan, and sometimes by which button you last pressed in settings.

What your employer's arrangement is. A separate document from the consumer terms, held by somebody in IT, procurement or legal, and not answered by the public page. Whether its terms differ, and how, is a thing to read rather than to assume in either direction.

What you are willing to put in. This one's yours, it's a judgement rather than a fact, and it's the only one of the three this lesson can help you make.

Notice what isn't on that list: a rule you can be told. The right answer depends on the product, the plan, the employer and the material, and a course that handed you a rule would be handing you one that is wrong for most readers.

Why this is not Digital Literacy's question

Digital Literacy asked what a service keeps about you as a by-product of your using it: what you opened, from where, on what, and when, most of it observed rather than provided.

This one's simpler. You typed something on purpose. What happens to it?

Simpler, and with an answer you can go and find, which is why the first exercise below is twenty minutes with a document rather than a lesson of argument.

There's a harder half, though, and it's the one part of this subject that doesn't depend on what any policy says this month. NIST's generative AI profile notes that these systems "may be able to correctly infer PII or sensitive data that was not in their training data nor disclosed by the user by stitching together information from disparate sources", and that "these inferences can have negative impact on an individual even if the inferences are not accurate".1 PII is the standards world's abbreviation for personally identifiable information, which is anything that picks out one person.

Read that twice. NIST says an inference may be drawn and that it can harm somebody even when it is wrong, and both halves are in the quotation. The part that is this course's own, and worth saying as such, is the practical upshot: you cannot tell in advance which details are the ones that combine, so withholding the obvious ones is not a plan.

Predict first

A parish administrator wants help drafting a reference. She takes out the name, the employer and the dates. What has she left in, and does taking those three out do what she thinks?

Show the answer

She has left in the job, the reason for leaving, the length of service, the things the person was good at and the one thing they were not, and whatever turn of phrase she uses when she is being careful about somebody.

In a parish of four hundred people, that is a description of one person, and it would be a description of one person to anybody who knows the parish even if no system ever inferred anything.

So the honest answer isn't that the inference risk is exotic. It's that she was never anonymising the document. She was removing the three fields that are easiest to remove, which are also the three that combine with everything else rather than carrying the identification on their own.

Which is why the decision has to be about the document rather than about its fields. A reference is about a person. Taking the name out leaves a reference about a person.

That is not a reason to type nothing. What it is is the reason the decision has to be made by category rather than field by field: taking the name out of a case summary changes less than it feels like it does, because a case summary is made of exactly the sort of details that combine.

Predict first

Before the exercise: write down, now, what you believe your main product does with what you type. Two sentences. Is it used to train models? Is it kept, and for how long?

Show the answer

Keep what you wrote. The interesting question is not whether you are wrong but which way.

There are two ways to be wrong and they cost different things. Assume the worse answer and you stop using the tool for work you could safely have used it for. Assume the better answer and you put things in that you would not have put in if you had read one page. NIST names both shapes elsewhere, as over-reliance and as being unnecessarily averse, and says both are real costs.3

Either way the failure is the same, which is holding a belief about a document instead of reading it, and either way the fix is the same twenty minutes.

One product, two accounts, worked

A manager uses the same product at home and at work. The case below is constructed and so is every sentence attributed to a document in it. No real product's terms are quoted, and the reason for making them up rather than looking them up is the whole of footnote 4: whatever any product says today is not what this lesson can teach you. What it can teach you is the shape of the difference and how to go and find it.

Her home account, read on 14 September. She finds the privacy page and looks for three sentences.

  • Training: conversations may be used to improve the models unless the setting is turned off. There is a setting. She turns it off and writes down what it was set to before she touched it.
  • Retention: conversations are kept until she deletes them.
  • After deletion: removed from her account within thirty days.

Her work account, read the same afternoon. The public page doesn't mention organisational plans at all, so she asks IT for the agreement. Three sentences in it matter.

  • Training: conversations from organisational accounts are not used to train models.
  • Retention: ninety days, and she cannot change it.
  • Access: a workspace administrator can export them.

Three differences, and only one of them is the one she went looking for.

She expected the work account to be the riskier one on training, and on training it's the safer one. She expected the home account to be the exposed one, and on the question of who else can read it, the home account is the private one. And the difference that matters most to her is the third, which was not on her list of questions at all: at work, a named colleague can export what she types.

That is why the first exercise asks for both, and why, if you only do one, you should do the work one. It's the account with other people's information in it, and it's the one whose answers you didn't choose.

Check yourself

She now wants to draft a grievance letter about her own line manager. On the three differences above, which account, and which difference settles it?

Show the answer

The home account, and it is the third difference that settles it. Administrators are colleagues.

Not training, which is the question she started with and the one where the work account is better. Not retention: ninety days would be fine if nobody could read them. The whole decision turns on export, because the document is about a person in the organisation and the account is the organisation's.

Notice that this has nothing to do with the technology. It's the same reasoning that says not to draft that letter in a shared folder or on a work laptop that IT images. What the lesson adds is remembering that a chat window is one of those places.

And notice what it does not say. It does not say she should use a system for the letter at all. Her home account is the better of the two available, which is a different claim from its being a good idea, and that judgement is hers to make with the document in front of her.

Five beliefs, all checkable in fifteen minutes

"Anything I type is used to train it." It is a fact about your product, your plan and your settings, on the date you read them, and it is written down. Assuming either way is a way of not reading the sentence that would've told you.

"Nothing I type is used to train it." The same belief-instead-of-a-document, pointing the other way, and the more expensive of the two, because the first costs you some use of a tool and the second can cost somebody else their privacy.

"Deleting the conversation removes it." It removes it from your view. What happens to any other copy, and over what period, is a separate question with a separate answer, and the document is where that answer is.

"A paid plan means it is private." Paying may put you on a different contract, and being on a different contract is not the same as being on a more protective one. Read the one you're on and see.

"It is fine because I did not give my name." NIST's sentence about inference from disparate sources is the answer.1 A name is the easiest thing to take out, and this course's reading of that sentence is that taking it out does less than it feels like it does.

Rights, and which jurisdiction they belong to

If you are in the United Kingdom, the Information Commissioner's Office publishes guidance on AI and data protection, organised around the data protection principles: accountability, transparency, lawfulness, accuracy, fairness, security and minimisation, and individual rights.2

Two honest notes about it. It is written for organisations building or deploying these systems rather than for an individual using one, so it won't tell you what to type. And it is guidance for one jurisdiction. This course names the jurisdiction every time it names a right, because a reader in another country following a rule that doesn't apply to them is worse off than a reader with no rule at all.

What it is good for: if you are the person deciding what your organisation does, rather than the person typing, that is the document to start from.

This course is education, not advice

Nothing in this lesson is legal advice, and nothing in it is advice about your own employment.

What it gives you is a way to find out what's true for your account, on a date, from documents you can read yourself. What you should then do with a particular document, in a particular job, under a particular contract, is a question for somebody who can see all three, and sometimes for somebody qualified to read them.

The reason to say this here rather than nowhere is that this is the lesson that touches rights, contracts and an employment grievance, and a reader who takes a course's worked example as a ruling on their own case is worse off than one who was told plainly that it is not.

Practice

Read the page, both pages

Take 20 minutes, with the product's own documentation open rather than an article about it.

  1. Your own account first. Find the page where the product says what it does with your conversations. Look for "data", "privacy", "training" or "controls" in its help or settings, if it has them; a product provided by your employer may have none of those and a policy document instead.

  2. Answer three questions in writing, quoting the sentence that answers each. Is what I type used to train models? How long is it kept? Can I change either, and what is it set to right now?

  3. Write the date beside each answer.

  4. Now the work account, if you have one, and expect different answers. If the public page doesn't cover an organisational plan, the document you want is your employer's agreement, and the person who has it is usually in IT, procurement or legal.

  5. Compare with the two sentences you wrote in the predict block earlier. Which way were you wrong?

Keep this. Lesson 3 sent you to one page with one question; this is the whole of it, on two accounts, and the course project deliberately does not ask for it. This one is for you rather than for a marker.

Three lists, decided once

Take 20 minutes. This is a threat model, which Digital Literacy taught you to build in its first lesson, applied to one narrow question.

Three headings.

Will. Things you are content to type in. Public documents, your own drafts, work with nothing in it about anybody.

Will not. Things you will not, whatever the plan says. Other people's medical or financial details, anything under a confidentiality obligation, material about a colleague.

Depends, and on what. Usually the longest of the three, and the one worth the time. Beside each entry, name the condition: which account, which plan, whether the person could be identified by combination, whether you would be content for it to appear in an administrator's export.

Two rules for the exercise. Every entry in the third list needs its condition written out, or it belongs in one of the other two. And decide it now rather than in the moment, because the moment is when you are busy and the material is in your clipboard.

Then the prediction, before you start writing the lists: how many entries do you expect in each? Write three numbers down. Most people expect the first two lists to be the long ones, and the gap between what you predicted and what you wrote is worth a sentence of its own.

Then put a reminder in your calendar for a year from now to read all three lists and the dates from the first exercise, because every one of those answers can change.

Connections

Back. Lesson 3 asked what the system can see within a conversation and sent you to your product's page for a narrower question; this is the full version. Digital Literacy supplies both the threat model in the second exercise and the habit of quoting a provider's own sentence with the date you read it.

Forward. Lesson 11 is the last lesson, and it turns the course's habits on the claims people make about these systems. The move it teaches is the one this lesson has just used on a provider's page: find the sentence, note what it does and does not say, and write the date beside it.

Go deeper

  • Your own product's data and privacy pages, and your employer's agreement. Between them they are the only documents in this lesson that are about what you actually use. An hour a year on the pair of them is the whole of the discipline this lesson teaches.
  • NIST AI 600-1, section 2.4 on data privacy. Short, and the passage on inference from disparate sources is the part worth the time.
  • The ICO's guidance on AI and data protection. United Kingdom only, and written for organisations rather than individuals. This course has read its structure and not its chapters, so treat this as a pointer.

Sources

  1. NIST AI 600-1, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, July 2024, section 2.4. Read in part. Supports: the quoted sentence about correctly inferring sensitive data by stitching together information from disparate sources, and the quoted sentence that such inferences can have negative impact even when they are not accurate.
  2. Information Commissioner's Office, Guidance on AI and data protection. Read at structural level only: the contents and framing were fetched and no chapter was read. Supports: the existence of the guidance, the list of principles it is organised around, and the statement that it is written for organisations rather than for individuals. United Kingdom jurisdiction, named as such wherever it appears.
  3. NIST AI 600-1, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, July 2024, section 2.7. Read in part. Supports: that over-reliance and being unnecessarily averse are both named as real costs, which lesson 9 quotes in full and this lesson uses in summary.
  4. What any particular product does is not sourced in this lesson and cannot be. It changes, it differs by plan and account, and the reader is the only person who can establish it for their own case, which is why both exercises are about reading a document and dating it rather than about believing this lesson.

Check your understanding

This lesson has a 6-question quiz. Pass it and the questions come back on a schedule in Review, so what you learned stays learned. Your progress is saved in your browser; no account needed.