By the end of this lesson you will be able to
- Explain the difference between consumer, business, and API data handling
- Decide what may and may not be pasted into a general AI tool
- Run a short due-diligence check before adopting a tool
"Does the AI company read my stuff?" is the right question, asked slightly wrong. The answer depends almost entirely on which tier you are paying for — and the gap between tiers is much bigger than most people realise.
Three very different tiers
| Free / consumer | Business / team | API | |
|---|---|---|---|
| Used to train models | Often, by default | Typically not | Typically not |
| Human review | Possible, for safety and quality | Limited | Limited |
| Retention | Often indefinite | Configurable | Short, sometimes zero |
| Admin controls | None | Yes | Yes |
| Contractual commitments | Consumer terms | Business agreement | Business agreement |
The practical implication is stark: the free tier your team signed up for individually and the business tier you would buy deliberately are not the same product wearing different price tags. They have materially different data commitments.
Definition Zero data retention- A configuration where prompts and outputs are not stored after the request completes. Usually available on business and API tiers, sometimes only on request. Full definition
The problem you probably already have
In most businesses, staff started using AI before anyone made a decision about it. That means client material has likely already been pasted into personal free-tier accounts, under consumer terms, with no admin visibility and no record of what went where.
What should not go into a general AI tool
Regardless of tier, unless you have specifically confirmed it is permitted:
- Anything covered by a confidentiality agreement that names permitted systems
- Personal health information, or anything under a specific regulatory regime
- Full identity documents, banking details, or credentials — ever, on any tier
- Client data where your own contract restricts sub-processing
- Material you could not defend having shared if a client asked directly
That last one is the most useful test in practice. "Could I explain this to the client without wincing?" catches nearly everything the formal rules would.
A short due-diligence check
Before adopting a tool for real work, get answers in writing to five questions.
Is our data used to train models?
The single most important question. The answer should be a clear no on any business tier, stated in the terms rather than in marketing copy.
How long is it retained, and can we change that?
Ask for the actual retention period and whether zero-retention is available. "We take privacy seriously" is not an answer.
Where is it processed and stored?
Matters for Canadian and EU obligations, and for anything with a data-residency clause in your own client contracts.
Who can see it internally?
Some human review for safety is normal and reasonable. You want to know the scope, not to be told it never happens.
Is this a reseller or the provider?
Many AI products are wrappers around someone else's model. That adds a party to the chain, and their terms may be weaker than the underlying provider's.
The one-page policy that covers most of it
You do not need a governance framework. You need these five lines, written down and circulated:
- These are the approved tools. Use these, on the company account, not personal ones.
- This is what must never be pasted in, in specific terms rather than general ones.
- This is what must be checked by a person before it leaves the building.
- This is when we tell a client that AI was involved.
- This is who to ask when you are not sure — with a real name on it.
Is it safe to paste a client contract in to summarise it?
On a business tier with training disabled, this is a normal and common use. On a personal free account, you are likely in breach of your own confidentiality obligations. The tier is the whole answer.
Do we have to tell clients we used AI?
Depends on your contracts, your profession's rules, and what you promised. Using AI to draft an email you then edited is rarely disclosable. Using it to produce advice a client relies on usually is. When unsure, disclose — the cost of over-disclosing is much lower.
What about AI features inside tools we already use?
Same questions, and they are easy to miss because nobody made a purchasing decision. The AI feature in your CRM or email may operate under different terms than the base product. Ask specifically.
Key takeaways
- Free, business, and API tiers have materially different data commitments. The tier is usually the whole answer.
- Staff using personal free accounts is the most common real exposure, and the cheapest to fix.
- Never paste credentials, identity documents, or regulated personal data into a general tool.
- Get five answers in writing before adopting a tool — especially "is our data used for training?"
- A one-page policy naming approved tools and forbidden data covers most of the risk.
