How to Use AI With Your Privacy Intact
New AI chatbots offer privacy protections, with some using cryptography to prevent data logging.
Summary
Interactions with popular AI chatbots like ChatGPT, Claude, and Gemini can expose highly personal data, as these services often collect and store conversations by default. Privacy advocates are concerned about the potential for surveillance and data misuse. In response, new tools like Confer are emerging, utilizing cryptography to ensure conversations are not logged or surveilled by the service provider, offering users a more private way to interact with AI.
Full text
CommentLoaderSave StorySave this storyCommentLoaderSave StorySave this storyIf the tech industry sought to create a method of seducing users into sending their deepest, most sensitive secrets to a server in a faraway data center, it would be hard-pressed to create a better honeypot than an AI chatbot.OpenAI’s ChatGPT, Anthropic’s Claude, Google’s Gemini, and their countless smaller competitors have become therapists, sounding boards, and virtual confession booths for millions of people around the world. Almost all of those AI models are set by default to collect and store that highly private data with, in many cases, no restrictions on how it’s shared or sold, used to further train the tools, or handed over to any lawsuit plaintiff or law enforcement agency that demands it through a legal process.“You have this intelligent thing staring back at you, and you’re basically telling it, one question at a time, every possible thing there is to know about your life,” says Matt Green, a privacy- and security-focused computer science professor at Johns Hopkins University. “You're giving it this huge profile on you.”A decade ago, text messages represented perhaps the most personal, sensitive data that most people shared from their devices, says cryptographer and software developer Moxie Marlinspike. The surveillance dangers invited by unprotected texting are what pushed him in 2014 to create Signal, the end-to-end encrypted messenger now used by well over a hundred million people. Now, he says, that critical point of privacy vulnerability has shifted to people’s interactions with AI.“Those same things I was concerned about with messaging are happening in the AI space, but several orders of magnitude more significantly,” says Marlinspike. “People are integrating AI into their personal lives. They talk with it about their deepest insecurities, their finances, their health, their relationships.”So earlier this year, Marlinspike launched Confer, an AI chatbot designed to allow users to ask it anything while preserving their privacy, using cryptography to technically prevent the service’s own server from being able to surveil or log their conversations. “Confer is designed to be a service where you can explore ideas without your own thoughts potentially conspiring against you someday,” he wrote in a blog post introducing it.Marlinspike’s private AI tool is, in fact, just one standout among a new generation of AI services that promise to remedy the pervasive privacy invasion that these chatbots represent. Some advertise that they never record conversations as a policy. Others offer to anonymize them. A few, like Confer, seek to create actual technological guardrails that restrict their own access to users’ secrets.The result of that nascent competition to create less surveillance-prone AI is a growing crowd of tools, often ones that offer confusing assurances for users as they seek to adopt an increasingly unavoidable technology without losing control of their secrets. Here’s WIRED’s guide to using AI with your privacy intact.Zero Data RetentionWhen you start typing into one of the big three AI chatbots—ChatGPT, Claude, or Gemini—it’s safest to start with a baseline expectation of approximately zero real privacy from anyone who is determined to access your conversation records and has a legal path to obtaining them. That includes the owner of the service, advertisers or other companies they partner with, contractors who help fine-tune the systems, law enforcement agencies, or even someone who manages to subpoena the records as part of a civil lawsuit.The simplest, strong exception to that rule is a contract between you—or more likely, your employer—and an AI provider that legally prevents them from retaining those records, a provision that’s come to be known as zero data retention, or ZDR. OpenAI, Anthropic, and Google all offer ZDR policies for their enterprise versions, which when enabled generally require that they immediately delete records of users’ interactions with a chatbot as soon as they’re processed.Even these ZDR policies, which are only available for paid enterprise and developer accounts rather than for average users, have significant exceptions. Anthropic, for instance, doesn’t offer ZDR for its most sophisticated “Mythos-class” models like Fable 5.1, due to what it describes as the potential for misuse like scamming or hacking and even “autonomous misbehavior,” such as AI agents independently hacking targets to carry out their unwitting users’ requests, as has occurred in several high-profile AI-driven breaches.OpenAI also announced last month that its ZDR implementations will analyze user activity prior to deletion—on the customer’s systems rather than its own, it says—and, if it detects abuse, flag it for the customer organization. OpenAI says its system, known as Private Safety Processing, will even alert OpenAI’s staff if it detects abuse in some cases, though without revealing the content of the conversation to them. Google, too, warns that it logs some Gemini prompts for abuse monitoring even with ZDR enabled, but without the user’s Google ID or IP address included—though that “sanitized” data can in some cases still pinpoint a particular person when the request itself includes identifiable information.Policies, Promises, and ProxiesRegardless of those protections and exceptions, the paid, enterprise-level, contractual promises of ZDR are out of reach for the vast majority of non-corporate AI users. Instead, many consumer-targeted AI services ask us to settle for the far weaker, pinky-swear promises they’ve made not to log our conversations.Privacy-focused cloud services company Proton, for instance, offers the AI chatbot Lumo, which it describes as “AI where every conversation is private.” That privacy, however, isn’t based on the technical guarantees of end-to-end encryption, like Proton’s other services such as Proton Mail and Proton Drive. Instead, it simply promises not to log users’ conversations, and users have to trust that Proton will adhere to that privacy policy—which, in Proton’s case, is at least backed by the company’s long track record as a privacy-focused company. “A promise is not as good as a mathematical guarantee,” Yen told WIRED in an interview last month, “but a promise made by the right people is still actually quite substantial.”Other privacy-focused AI services like Venice.ai and Duck.ai, the AI chatbot offered by long-running private search engine DuckDuckGo, offer similar vows about keeping no logs of your conversations. Both services, however, relay your chat requests to other services such as Claude or ChatGPT, essentially acting as a proxy for your conversation that limits what information the underlying AI model can collect about you.(Duck.ai lets the user choose which third-party model they’re using. Venice.ai appears to automatically route conversations to different services based on the request, without always making clear to the user which one it’s using, as well as answering queries with an AI model hosted on its own infrastructure in some cases. Venice.ai also touts other privacy features, like using “trusted execution environment” systems to cryptographically prevent logging of conversations—more on that below—but when WIRED attempted to reach out to Venice.ai’s staff to ask more questions about these privacy features, its AI response bot only repeatedly referred us to a nonworking email address.)Using an anonymity proxy offers some privacy protection compared with using ChatGPT or Claude directly. Yet when they relay your requests to those services, Duck.ai and Venice.ai’s own promises about their retention of data become significantly less meaningful, points out Johns Hopkins’ Green. That’s because your chat messages can still be collected by that underlying AI model and, even stripped of any identifying metadata, those messages can often contain identifiable information.Ask about the best coffee shops