The honest answer to “is my data safe with an AI chatbot” is: it depends on three things most people must check. Most teams use AI tools for months without asking any of them, then find out the answer the hard way. This piece is the checklist you should have run on day one.
Question one: does it train on your data?
This is the question that matters most and gets checked least. If a tool trains on your conversations and uploads, your confidential material becomes part of a model that other people can query. The vendor will say the data is anonymized, but you cannot verify that from outside. You are trusting a process you cannot inspect.
A financial advisor’s testimonial on our site states the requirement from the professional side: “Client confidentiality is everything. Zero training on my information, complete control.”
That sentence is the standard. If a tool cannot honestly offer it, the tool is not appropriate for client work. The check is simple: search the policy for the word “train.” Read what follows. If it is hedged or missing, treat it as a yes.
Question two: can it touch your files?
A chatbot that only returns text is limited in what it can damage. An agent that reads files, writes files, and runs commands is a different animal. The useful version of this technology, the one that actually finishes work, needs file access. The safe version of that access is a sandbox: an isolated space where the AI works and where nothing it does is unrecoverable. It cannot escape the boundary, and it cannot delete your files.
Without a sandbox, you are the boundary. You supervise every step, which defeats the point of the tool, or you do not, which is how files get lost.
The July 2026 incident, where an experimental model escaped its test environment, is the extreme version. The everyday version is quieter: a file overwritten, a deletion confirmed by an overconfident assistant. Both point to the same requirement. The mechanism matters more than the policy.
Question three: can you leave?
The third question is about lock-in, and it is a safety question even though it sounds like a business one. If your files and conversation history are held by a vendor you cannot easily export from, then your data is not really yours. It is rented. Leaving becomes a data-loss event, so you stay, and the vendor’s incentives to protect you quietly weaken.
Portability is a safety feature. A tool that lets you export your data keeps the vendor honest. A tool that does not is asking you to trust it forever, which no one should have to.
The three checks, in order
Before you upload anything sensitive to an AI tool, run these. Find the training sentence in the policy. Does it train on your data? If the answer is not a clear no, do not upload client material.
Ask what happens to your files while the AI works. Is there a sandbox? Are deletions recoverable? If the answers are not clear, assume the worst.
Ask about export. Can you take your data with you? If not, factor that into the decision.
These three checks take ten minutes and prevent the kind of incident that costs a client. Our piece on sensitive data and blanket AI bans covers the opposite failure too: banning AI entirely also costs you, because your competitors will not.
What a safe setup looks like
A safe setup is not a chatbot with a better privacy policy. It is a system where the protections are mechanisms. No training on your data, stated plainly. A sandbox that cannot delete your files or escape its boundary. Portable context you can export. Those three mechanisms are what safety without compromise looks like.
OpenCraft AI is built this way. The models run on open weights, the work happens in an isolated sandbox, and there is no training on your information.
A legal counsel’s testimonial on our site describes the day-to-day result: “For legal work, the context is everything. It remembers details from weeks ago, I save about 2 hours a day not having to re-explain the background.”
The safety and the usefulness are not in tension. The context is held without being trained on.
The shared-account problem
There is one more risk that is easy to miss: shared accounts. When a team shares one login, everyone’s data lives in the same place. One person pastes a confidential document, and the next person sees it, or the model’s memory of it bleeds into their session.
The fix is the same as the agency context question: separate, persistent contexts per person or per client, so data does not cross. The agency guide covers this in more detail, but the short version is that separation is a feature you have to check for, not assume.
What most teams get wrong when looking at AI data privacy
They check the badge, not the policy. A SOC 2 badge is about the vendor’s processes. It does not tell you whether your data trains a model. Read the policy.
They assume free means fine. Free tools are free because the data has value. The training sentence is usually where that value shows up.
They ban AI instead of choosing carefully. A blanket ban is also a cost: your competitors keep the productivity and you lose it. The answer is selection, not avoidance.
They trust the demo. A tool that ignores your settings is a preview of how it will treat your data rules. Demos use clean sample data. Real work uses confidential data. Test on a real, non-sensitive project first.
They ignore shared accounts. One login for a team is a data-crossing risk. Separate contexts matter.
The checklist in one place
Put the three questions on a note and keep it near the keyboard. Does it train on our data? Does it run in a sandbox that cannot delete files? Can we export when we leave?
If the answer to any of them is no, or unknown, the tool is for public work only, not client work. That note prevents more incidents than any policy document, because it is the thing you actually see right before you paste.
The policy that changed mid-contract
Policies change. A tool that was safe when you signed up may not be safe six months later. One line in an update email, one changed sentence in a terms page, and the training answer flips. That is why the three-question check is not a one-time onboarding step. It is a quarterly habit.
Re-check the training sentence, the sandbox claim, and the export option every few months. The cost is ten minutes. The alternative is finding out after the fact.
The quarterly re-check
Make the three questions a recurring calendar item, not a one-time onboarding step. Tools change. Policies change. The training sentence that said no last quarter can say yes this quarter, and the only people who find out are the ones who look.
Ten minutes, once a quarter, per tool. It is the cheapest insurance you will ever buy.
The policy, not the page
One last time, because it matters: the marketing page is not the policy. The marketing page says what the vendor wants to be true. The policy says what they are willing to be bound to.
When the two disagree, the policy wins. Read it. If the answer comes back wrong, a private alternative is the next thing to check.
FAQ
Is it safe to put client data in an AI chatbot?
Only if the tool does not train on your data, runs in a sandbox that cannot delete files, and lets you export. If any of those is missing, it is not safe for client data.
Does ChatGPT train on my data?
Check the current policy for your plan. The answer has changed over time and varies by tier. Do not rely on memory.
What is a sandbox?
An isolated environment where the AI runs. It cannot escape, cannot delete your files, and nothing it does is unrecoverable.
Should I just ban AI at work?
No. Banning it hands the productivity advantage to competitors. Choose a safe tool and write a short policy for what can and cannot be uploaded.
Are shared team accounts a risk?
Yes. One login means everyone’s data sits in one place. Look for separate, persistent contexts per person or client.
The short version
Three questions decide whether your data is safe: does it train on you, can it touch your files, and can you leave. If the answers are no training, sandboxed, and portable, you have a safe setup. If not, you are trusting a promise you cannot verify.
Start with 100 free credits and check all three before you upload anything real.