Field notes / 01 · Privacy in practice
Who Can Read AI Chats? Map Five Access Routes
A chat can be hidden from other users while still being processed by the company running it. Decide whose access matters to you before accepting a “private” label.

Start with the person you want privacy from
| Audience | What to inspect | Your next step |
|---|---|---|
| Someone using your device | Unlocked sessions, notification previews, downloads | Review screen-lock and notification settings; locate exported files. |
| Someone with a shared link | Public visibility, link revocation and copied content | Revoke unwanted links if supported; removal cannot recall someone’s screenshot. |
| A character creator | The creator’s role and any conversation access | Look for a creator-specific answer; employee rules do not answer this question. |
| Operator staff or contractors | Support, moderation, review and access conditions | Ask which events allow access and which messages a report includes. |
| Model or feature providers | Text, voice and image processing destinations | Identify recipients and distinguish reply generation from training. |
Turn a promise into an evidence record
Write one sentence per audience: “This party may receive this category for this purpose, according to this source.” Add the source date and any unanswered question. If you have not checked the relevant documentation, use not assessed. If you checked a defined set of sources and found no answer, record not disclosed in those sources. Neither label is a safety score.
For example, Replika’s policy, sections 2–3, describes third-party models generating responses under contractual restrictions on training their own models. That answers a processing question; it does not establish that only you can read the conversation. This is a policy observation, not a test of its systems.
A useful test without a personal conversation
Suppose your concern is a family member seeing a lock-screen preview. A provider’s training opt-out does not address that route. Use a harmless test message, lock your device, and inspect what appears. Record the device and setting you actually observed. Do not extend that result to staff access or server retention.
If the concern is reporting a harmful reply, inspect the reporting explanation first. Ask whether the report includes a selected message, surrounding context, attachments or account details. A support ticket can create a separate copy of content, so send only what is needed.
What an encryption badge leaves unanswered
Ask whether encryption applies during transmission, while stored, or end to end, and who holds the keys. An unspecified badge does not answer whether an operator can access readable content. If this distinction changes what you are willing to share, wait for a specific explanation before adding the sensitive detail.
Keep your worksheet outside public notes or shared cloud folders. Record categories and policy links, not the intimate conversation itself. Continue with history, memory and training when the open question concerns what happens after processing.
Make it practical
Keep your own record
Download the blank worksheet and fill it in privately. No account or upload is needed; nothing you write in the downloaded file is sent to this site.
Download worksheet · TXTScope: editorial guidance and official documentation checked on September 18, 2026. No in-app deletion tests or infrastructure audit were performed. Illustrative scenarios are fictional. Evidence method · Website privacy