AI tools have long been an integral part of today's work environment. In many teams, ChatGPT is used for research on a wide range of topics, Midjourney is used to develop campaign ideas, and Copilot helps capture meeting content. It's undeniable that these tools help people accomplish more.
At the same time, they pose a risk to privacy – especially when there's little knowledge about that risk, and usage happens without thinking about the consequences. Here are three things worth considering before sensitive data ends up in a prompt.
1. ChatGPT retains deleted conversations for 30 days
Even when a conversation disappears from the screen the moment you click “delete,” it continues to exist on OpenAI's servers. Deleted inputs are stored there for 30 days1. What most users don't know is that these prompts are also used to train ChatGPT, unless that setting is disabled.
This became a problem for Samsung in 20232, when source code and confidential meeting content were copied into ChatGPT by engineers trying to debug faster. Even though the intention was never malicious – they simply wanted to get their work done – the incident led to a company-wide ChatGPT ban. By then the data had already left the company and been fed into the AI tool.
Cloud-based AI tools like ChatGPT route your inputs through servers across national borders. Every prompt creates a compliance surface. Data sovereignty is not an abstraction here: it determines whether your data stays local or migrates to servers you cannot control.
2. Midjourney publishes all generated images by default
Every image created in Midjourney ends up in a public gallery that any user can search3. Whether concepts, presentations, or internal design brainstorming sessions – each of these visualizations is publicly searchable. Images created in Discord servers or direct messages are no exception. The only way to avoid this is an account at $60/month with Stealth Mode enabled4.
Especially for agencies that create work for their clients, this poses a major problem. Transparency with AI means being able to understand what the algorithm does and maintaining control over who has access to what has been created. With open-source tools you have that capability. With proprietary platforms you are essentially asked to trust them, without receiving any real proof.
A default that publishes your work is still a default. Most people never change it.
3. Microsoft Copilot surfaces data from misconfigured permissions
Copilot can access nearly every document your account has access to – even when that's not actually intended5. This includes files that may only be reachable because of an error when setting permissions. By asking the right question, it can happen that Copilot surfaces sensitive information such as salaries or confidential documents, even though these were never meant for the person searching.
Especially in the context of large projects, it's not uncommon for permissions to be granted broadly – sometimes far too broadly6. Once the project is completed and the next one starts, revoking those permissions is rarely the priority. So it's worth emphasizing that this problem is not caused by Copilot. It is exposed by it, and made obvious very quickly7.
Get rid of Copilot, then? Not the solution. The focus should be on managing permissions more carefully and ensuring AI systems stay under the control of the people using them, even without extensive infrastructure work.
Security should be considered from the start. Privacy-first tools like SOWA Privacy address exactly this: they anonymize sensitive information on your device before prompts ever reach a cloud model. Broken down, it means productivity remains and risk doesn't. As soon as data is processed locally or replaced with placeholders and never leaves the device, the risk of an incident drops to nearly zero. That makes it possible to use AI tools while simultaneously protecting sensitive data.
Before your next prompt: ask yourself three questions
- Is this data confidential?
- Where will it be stored – and for how long?
- Who controls access?
SOWA Privacy answers all three the same way: your device, and nowhere else.
Further reading
- Samsung's ChatGPT Leak: Lessons from a Costly Mistake – three engineers, three prompts, one company-wide ban. Why policy-only controls don't work.
- When the Sandbox Leaks: A Hidden Outbound Channel in the World's Biggest AI Chatbot – security researchers found a covert channel in an isolated ChatGPT runtime. Perimeter defenses leak.
- Why Zero-Log Is the Only Real Path to GDPR Compliance – “we delete logs after a week” is a retention policy. “We don't write logs” is architecture. Only one survives an audit.
Sources
- OpenAI Help Center: Chat and File Retention Policies in ChatGPT
- SOWA Privacy: Samsung's ChatGPT Leak: Lessons from a Costly Mistake
- Midjourney Documentation: Keeping Your Creations Private
- Midjourney Documentation: Stealth Mode
- Microsoft Learn: Data, Privacy, and Security for Microsoft 365 Copilot
- Concentric AI: Microsoft Copilot Security Concerns Explained
- Petri.com: Copilot Didn't Overshare Your Data. Your Permissions Did