The invisible cost of convenience

In the past two years, AI chatbots have become a fixture of daily work. People use them to draft emails, summarise documents, debug code, and work through personal decisions. The experience feels private — it's just you and a text box. But that text box is a window into a server farm, and everything you type travels across the internet, gets processed by machines, and is stored by a company operating under policies that may not prioritise your interests above their own.

This is not a reason to stop using AI tools. It is a reason to be deliberate about what you type into them.

What AI companies actually collect

When you use a cloud-based AI chatbot, here is what typically gets transmitted and stored: your message text, the AI's response, metadata about your session (device type, timestamp, approximate location), and in some cases, the files or images you attach. How long this data is retained, and what it is used for, varies dramatically between providers.

Training data inclusion

Many AI providers — especially free tiers — explicitly reserve the right to use your conversations to improve their models. That message you typed may become part of a training dataset.

Human review

For safety and quality purposes, a percentage of conversations are reviewed by human contractors. If you've typed your social security number or a confidential business strategy, a real person may have read it.

Server-side storage

Your conversation history is stored on servers you don't control, governed by privacy policies that can change, and subject to legal requests such as subpoenas.

Third-party data sharing

Some providers share usage data with advertising, analytics, or business intelligence partners. The exact chain of data custody is often opaque.

Breach exposure

Even providers with strong security practices can be breached. Data you shared six months ago could surface in a future incident.

What you should never send to an AI chatbot

The following categories of information should be treated as strictly off-limits for any cloud AI service, regardless of how trustworthy the provider seems:

  • Passwords, PINs, or security question answers
  • Social security or national identity numbers
  • Bank account or credit card details
  • Medical records, diagnoses, or prescriptions
  • Legal or attorney-client privileged documents
  • Confidential business plans, source code, or trade secrets
  • Personal information about someone else without their consent
  • Immigration status or other legally sensitive personal data

A useful rule of thumb: if you would be uncomfortable reading that message aloud in a public place, do not put it in an AI chatbot.

How to use AI tools safely

This isn't about fear — it's about calibration. Here are practical steps that let you benefit from AI without unnecessary exposure:

  1. 01
    Read the privacy policy before you type anything sensitive. Most major providers have a toggle to opt out of training data usage — but it is often off by default, buried in account settings.
  2. 02
    Anonymize before you paste. If you need help with a contract, replace the real names and numbers with placeholders before sending it. The AI can help with the structure without seeing the real data.
  3. 03
    Use on-device AI where it matters. A growing number of apps — including some from Curvachip — process AI requests locally on your device, meaning your data never touches an external server.
  4. 04
    Regularly delete your conversation history. Most platforms offer a way to clear your chat history. Do it. Especially before you forget what you typed three months ago.
  5. 05
    Treat AI as a colleague, not a vault. You would not hand a stranger your medical history to help draft an email. Apply the same instinct here.

How we handle it differently

We build apps for Apple platforms, and several of them use AI. We think that earns us a responsibility to be explicit about what happens to your data when you use them.

On-device by default

Apps like Shadow Task process and store all data locally. Nothing leaves your device. There are no accounts, no sync servers, and no analytics.

Explicit AI disclosure

When an app uses AI — like StoneClip or BugClip — the App Store listing says so clearly and the privacy policy explains exactly what data is sent, to whom, and why.

Minimal collection

We don't collect what we don't need. If a feature can be built without touching your data, it is built that way — full stop.

No advertising

Curvachip apps are not ad-supported. Your data is never sold, shared with advertisers, or used to build a profile of you.

Each of our apps has its own privacy policy, linked directly from its App Store listing. If you ever have questions about what a specific app does with your data, email us — we will answer.