Privacy

Everything you type into a cloud AI becomes a copy

Privacy · · 5 min read

Short answer: when you send a message to a cloud AI, that text becomes a record on infrastructure you don't control — typically retained for some period, often reviewable by staff for abuse and quality purposes, and subject to whatever the provider's policy says today rather than what it said when you signed up. That's usually fine. The cost isn't a breach; it's that people learn to route around it, and stop asking the questions they most needed help with.

This isn't an argument that cloud AI providers are careless. Most of the major ones take security seriously and publish detailed policies. It's an argument about what a copy is, and what having one somewhere does to how you use a tool.

What actually happens to the text

Mechanically, when you hit send:

  1. Your message travels to a data center. Encrypted in transit, but it arrives as readable text — it has to, because a model has to process it.
  2. It's usually retained. Conversation history is a product feature, so the default in most consumer products is that your messages are stored against your account.
  3. It may be reviewable. Most providers reserve the ability for staff or automated systems to review content for safety, abuse, and quality. This is legitimate and it's in the terms.
  4. It may inform training. Consumer tiers often default to allowing your content to improve the service, with an opt-out somewhere in settings that a lot of people never find.
  5. It's subject to legal process. Data a company holds can be compelled. Data that never existed on their systems can't be.

None of that is scandalous. All of it is the ordinary consequence of the architecture: to use a model on someone else's computer, your words have to go to someone else's computer.

The policy moves and you don't get a vote

The subtler issue is time. You agree to a set of terms in year one. In year three, the company has been acquired, or has pivoted, or has changed its retention window, or has launched a feature that surfaces old conversations in a new way. Your data from year one is still there, now governed by the current policy.

You're not just trusting a company's present behavior. You're trusting every future version of it, and every organization that might eventually own it.

The cost nobody measures: the questions you stop asking

Here's the effect that actually matters day to day, and it's behavioral, not technical.

People self-censor with cloud tools. Not dramatically — they just quietly don't ask certain things:

Every one of those is a case where help would be worth a lot. They're also exactly the cases people route around. So the practical privacy cost isn't an abstract risk profile — it's that the tool is least available precisely when it would be most useful.

What "on-device" changes

When the model runs on your phone, there's no request. Nothing is transmitted, so there's nothing retained, nothing reviewable, nothing to compel, and no future policy change that reaches backward into what you already typed.

That's the entire pitch for Vault AI: it runs the Apple Intelligence model already on your iPhone. No account, no sign-in, no server. Turn on airplane mode and everything still works — which is the simplest possible proof that nothing is leaving.

Vault AI running with no network connection, showing that nothing leaves the device

How to tell what an app is really doing

  1. Turn on airplane mode and use it. The single most reliable test. Whatever breaks was going somewhere.
  2. Check whether an account is required. Accounts exist so a server can associate data with a person. No server copy usually means no reason for one.
  3. Read the App Store privacy card. "Data Not Collected" is a meaningfully different claim from "Data Not Linked to You."
  4. Look for a training opt-out. If one exists, your content was in scope by default.

The reasonable position

Cloud AI is worth using for hard problems that need frontier models or live data — we said as much in what on-device AI can actually do. The mistake is defaulting to it for everything, including the material you'd never put in an email.

Use the big models for the big questions. Keep the personal ones on the phone, where the question of what happens to them never comes up.

Ask the questions you've been avoiding

Free to download · $2.99 one-time unlock · Nothing leaves your iPhone

Download Vault AI on the App Store