What happens to the words you type into an assistant

You will be able to explain where a prompt goes, what is stored, and which settings control it.

Most people type into an AI assistant the way they type into a search bar or a notes app. A question, a pasted email, a spreadsheet dropped in to be tidied. It feels private because the conversation is just you and a text box. It isn't quite that, and the details matter more at work than at home.

When you press send, your message leaves your device and goes to the company that runs the assistant. Their servers run the model, write the reply and send it back. Along the way your message and the reply are usually stored, at least for a while, as your chat history. That history is what lets you scroll back to yesterday's conversation. It also means a copy of what you typed now sits on someone else's computer.

What happens next depends on the provider, the type of account and your settings. Three questions cover most of it. Is the conversation kept, and for how long? Can people at the company read it, for example to investigate abuse or check quality? And can it be used to train future versions of the model? The answers differ between ChatGPT, Claude, Gemini, Copilot and the rest, and they change over time, so the only reliable source is the provider's current privacy policy and the settings page in your own account.

As a pattern, free and personal accounts give the provider more room to use your conversations, often with a switch you can turn off. Business and enterprise plans usually come with a contract saying the provider won't train on your data, plus controls your employer manages. That's why the same assistant can be fine for a work task on your company's account and a problem on your personal one.

Training is the step people worry about most: using conversations as material to build the next version of a model. A trained model doesn't keep your chats as files, but researchers have shown that models can sometimes repeat fragments of the text they were trained on. Separately, anything stored can be exposed in a breach, seen by a reviewer, or requested in a legal case. You don't need to work out which risk is most likely. Once text leaves your device, you no longer fully control it.

Then come the extras. An assistant with memory keeps facts about you between conversations so it can tailor its answers. Connectors let it read your email, calendar or files. Custom assistants and plug-ins built by other companies may pass your text on to yet another server. Each one is useful, and each one widens the circle of places your data goes.

None of this means you should stop using AI. It means you sort what you type into three groups. Some things are fine to paste almost anywhere: public information, general questions, your own writing with nothing sensitive in it. Some are fine only on an account your employer has approved, such as internal documents and plans. And some should never go into any assistant: passwords, one-time codes, NRIC numbers, bank details, other people's health or financial information, and anything a client told you in confidence.

At work, that last group overlaps with the law. A customer's name, phone number and NRIC number are personal data under Singapore's Personal Data Protection Act. Pasting them into a tool your company hasn't approved can be a disclosure the company is answerable for, even if you meant well. Module 2 covers what the Act asks of you.

Your task: open the settings of the assistant you use most and find three things. Are your chats used for training? How long is history kept? Is memory switched on? Write the answers down, then change anything you aren't comfortable with.

Open your most-used assistant's settings and record whether chats train the model, how long history is kept and whether memory is on.

Course

Junxiong-WFG Organisation is an authorised representative of AIA Financial Advisers Private Limited (Reg. No. 201715016G).