ARCANAI
All articles
Privacy3 June 2026

What Actually Happens to Your Data When You Use AI

Most people have a vague sense that AI tools 'might use your data for training.' Few understand exactly what happens between clicking send and getting a response. This is that explanation.


Reading time: 5 min | Published: June 2026 | Category: Privacy, AI Security, Data


Most people have a vague sense that AI tools "might use your data for training." Few understand exactly what happens between clicking send and getting a response. This is that explanation.


Step 1: Your text leaves your device

When you paste a document into ChatGPT, Claude, or Gemini, that text is sent over the internet to the provider's servers. It is transmitted as data, encrypted in transit via HTTPS, but fully readable by the receiving server.

At this point, the text — including every name, number, address, and identifier it contains — is on infrastructure you don't control.


Step 2: The model processes it

The AI model reads your input and generates a response. During this process, your text is held in the server's memory. The model has access to the full content of what you sent.

This is where the "the AI sees everything" concern comes from. It's not metaphorical. The model literally processes every token in your input — including the ones that contain personal data.


Step 3: The response is sent back

Your response comes back over an encrypted connection. But the original input — your document, your text, your data — has already been processed on the provider's servers.


Step 4: What happens after

This is where provider policies vary significantly.

OpenAI (ChatGPT): by default, conversations may be used to train models. Users can opt out in settings. Enterprise customers get stronger guarantees through a DPA.

Anthropic (Claude): similar structure — default usage, opt-out available, enterprise agreements with stronger protections.

Google (Gemini): varies by product tier and workspace configuration.

All three providers offer enterprise plans with stronger data processing terms, dedicated infrastructure, and commitments not to train on customer data. These plans cost significantly more than the consumer products most people actually use.


The training question

Whether your data is used for training is one concern. But it's not the only one.

Even if a provider commits never to train on your data, your data has still been sent to their servers, processed by their systems, and is subject to their security practices, their jurisdiction, and their response to legal requests.

For personal use, this may be an acceptable tradeoff. For professional use with client data, it raises questions that "we don't train on your data" doesn't fully answer.


The alternative: anonymize before sending

What if the AI never received the sensitive parts in the first place?

This is the approach ArcanAI takes. Before any text reaches an AI model, personal data is detected and replaced with tokens in your browser. The AI receives an anonymized version — sufficient to do its job, stripped of what it doesn't need.

The token map that links real values to their replacements is stored only in your browser's memory. It is never transmitted. After your session ends, it disappears.

The result: the AI does the analysis. Your data stays yours.

Try it at arcanai.co — free, no credit card required.

Try it free

Analyze documents with complete privacy

PII anonymized in your browser before any AI model sees it. Zero storage. Free to start.

Try ARCANAI for free →