Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

What Should Researchers Check in an AI Tool’s Privacy Policy?

Before giving an AI tool research material, determine what data it collects, how it uses and retains that information, who receives it, whether it may be used to improve models, and what controls apply to your account.

77
AI Privacy Policies for Researchers Guide 77 of 80
01 · The Question

What Are You Agreeing to When You Give Research Material to an AI Tool?

Researchers can place surprisingly sensitive material into an AI system with a few clicks: interview transcripts, participant responses, unpublished manuscripts, grant proposals, analysis code, proprietary datasets, peer-review material, research notes, or identifiable personal information.

The upload button tells you that the platform can receive the material. It does not tell you what happens afterward.

Before providing non-public research information, researchers should understand what data the service collects, why it processes those data, how long they are retained, who may receive them, whether information may be used to develop or improve AI systems, what controls users have, and whether those conditions are compatible with the researcher's obligations.

02 · The Short Answer

Read the Policy for the Data Flow, Not Merely for the Word “Privacy”

In Brief

Researchers should check what data an AI tool collects, the purposes for which it uses those data, whether prompts and files may be used for model improvement, how long information is retained, who receives it, where it may be processed, what user controls and rights exist, and which terms apply to the exact product and account being used.

A privacy policy alone does not determine whether a tool is appropriate for your project. You must also consider consent, ethics approval, confidentiality commitments, institutional policy, contracts, applicable law, and the sensitivity of the research information involved.

03 · What You Need to Know

Follow What Happens to the Data From Input to Deletion

Start by Identifying What the Tool Collects

Do not assume the service collects only the words you type into the prompt box.

Depending on the product, collected information may include prompts, uploaded files, generated outputs, feedback, account information, device or browser information, usage data, logs, approximate location information, cookies, integration data, or information obtained through connected services.

For researchers, the critical question is whether any of those categories can contain research information or personal data.

A transcript uploaded as a “file” may contain names, voices converted to text, health information, demographic details, institutional affiliations, or combinations of attributes that make individuals identifiable. The category label in the privacy policy may sound generic while the actual research content is anything but.

Check Why Each Type of Data Is Processed

Collection is only half the question. What does the provider do with the information?

Potential purposes can include providing the requested service, maintaining accounts, preventing abuse, monitoring security, improving products, developing or evaluating models, conducting analytics, personalizing services, complying with legal obligations, or other purposes described by the provider.

Privacy guidance from the UK Information Commissioner's Office illustrates the broader transparency principle: organisations should explain why personal data are processed, the legal basis where applicable, retention, recipients, transfers, and individual rights.

Researchers should therefore read beyond “we value your privacy” and identify the operational purposes that actually apply to prompts and uploaded content.

Find Out Whether Your Inputs May Be Used to Train or Improve AI

This is often one of the first questions researchers ask, but the terminology can vary. A provider may refer to training, model improvement, service improvement, product development, evaluation, human review, quality assurance, or similar activities.

Determine whether prompts, files, outputs, or feedback may be used for these purposes and whether the conditions differ according to product, plan, settings, API use, enterprise agreement, or institutional account.

If an opt-out or account control exists, understand what it actually changes. An option that prevents use for model training may not necessarily eliminate temporary retention, security logging, abuse monitoring, or other processing.

Watch Out

Do not reduce the privacy review to one question: “Is my data used for training?” Information can still be collected, retained, reviewed, shared, transferred, or otherwise processed even when it is excluded from model training.

Check How Long Prompts and Files Are Retained

Retention matters because deletion from your visible chat history and deletion from the provider's systems may not be the same event.

Look for stated retention periods or criteria used to determine them. The ICO identifies retention periods, or the criteria used to determine them, as core privacy information.

Researchers should ask whether retention differs for active conversations, deleted content, backups, security logs, API requests, temporary processing, or organizational accounts.

Where a research protocol promises deletion or restricted retention of participant information, these details can become methodologically and ethically consequential.

Identify Who Can Receive the Information

An AI service may rely on cloud providers, subprocessors, contractors, affiliated companies, safety reviewers, analytics providers, or other third parties.

A privacy policy should help you understand recipients or categories of recipients. ICO guidance similarly identifies recipients and categories of recipients among the information that should be disclosed for personal-data processing.

For confidential research, this matters because uploading information to one interface can result in processing by more than one organization.

Check Where the Data May Be Processed or Transferred

Cloud services can process information across jurisdictions. Privacy rules, institutional requirements, contractual commitments, or research agreements may constrain international transfers or require particular safeguards.

Look for information about countries or regions of processing, international transfers, and safeguards where applicable. The ICO's privacy-information checklist includes details of transfers to third countries or international organisations when relevant.

Do not assume the company's headquarters tells you where your research data will be processed.

Look for Human Access to Content

Researchers sometimes imagine AI processing as entirely automated. Depending on the service and circumstances, authorized personnel or contractors may have access to some content for support, safety, abuse investigation, quality review, legal compliance, or other stated purposes.

Check whether the policy or supporting documentation describes human access and under what circumstances it may occur.

This can be particularly important for material subject to confidentiality commitments. “Processed by AI” does not necessarily mean “never visible to another person.”

Understand Your Deletion and Account Controls

Look for controls governing conversation history, deletion, temporary chats or equivalent modes, model-improvement settings, account deletion, file removal, and data-access requests where available.

Then determine what those controls actually mean. Does deleting a conversation remove it immediately? Is it scheduled for deletion after a defined period? Are legal, security, or backup exceptions described?

User-interface labels are useful, but the governing documentation should explain the underlying treatment of data.

Check the Rights Available to Individuals

Where privacy law applies, individuals may have rights relating to access, correction, deletion, restriction, objection, portability, consent withdrawal, or complaints, depending on jurisdiction and legal basis.

ICO guidance, for example, lists rights such as access, rectification, erasure, restriction, objection, and data portability among information that organizations may need to communicate.

Researchers should not assume that rights available to the account holder automatically resolve obligations owed to research participants whose information the researcher uploads. Your role in collecting and disclosing participant data remains relevant.

Check Whether Different Products Have Different Privacy Conditions

A provider may offer free consumer access, paid individual subscriptions, APIs, team products, enterprise services, educational arrangements, or institutionally negotiated accounts.

Do not assume one privacy statement applies identically across all of them.

Look for product-specific terms, data controls, enterprise documentation, contractual addenda, or institutional agreements. This is one reason free and paid AI services should not be compared through price alone. A different offering may change data conditions, but you must verify that rather than infer it from payment status.

A Privacy Policy Is Not the Same as a Security Assessment

Privacy and security overlap, but they are not identical.

A privacy policy primarily explains how information is collected, used, shared, and managed. Security documentation may address encryption, access controls, certifications, incident response, authentication, infrastructure, or other technical and organizational safeguards.

If your project involves sensitive or regulated information, a public privacy policy may be only one part of the assessment required by your institution.

A Privacy Policy Is Also Not the Same as the Terms of Service

Privacy documentation explains data practices. Terms of service usually govern the contractual relationship between the user and provider and may address intellectual property, licenses, permitted use, liability, account restrictions, warranties, dispute terms, and other matters.

Researchers should therefore separately examine what the AI tool's terms of service allow and require.

Your Research Obligations Can Be Stricter Than the Provider's Policy

A provider can truthfully state that it processes information according to its privacy policy while your own research protocol still prohibits the upload.

For example, participant consent may restrict disclosure. An ethics approval may specify particular storage arrangements. A data-use agreement may prohibit transfer to third parties. A collaborator may have provided confidential information under contractual conditions. Institutional policy may permit only approved services.

UNESCO's guidance on generative AI in education and research identifies data privacy as a major concern and calls for protection of personal data and institutional validation of generative AI tools. The European Commission's updated 2026 guidelines likewise maintain accountability, transparency, responsibility, and research integrity as central principles and address risks arising when AI is involved in research information management.

Privacy-policy question What to look for Why researchers should care
What is collected? Prompts, files, outputs, account and usage information Research content may contain personal or confidential information
Why is it processed? Service delivery, security, analytics, product or model improvement The same data may be used for purposes beyond answering your prompt
Is it used for model improvement? Default treatment, opt-outs, product-specific exceptions May affect whether non-public research material is appropriate to provide
How long is it retained? Retention periods, deletion timelines, exceptions May conflict with research data-management commitments
Who receives it? Affiliates, service providers, subprocessors, human reviewers Uploading may disclose information beyond the company named on the interface
Where is it processed? International transfers and applicable safeguards Jurisdictional or institutional restrictions may apply
What controls exist? Deletion, opt-outs, temporary modes, access and privacy settings May allow researchers to reduce unnecessary processing
Which policy applies? Consumer, API, team, enterprise, or institutional conditions Different account types may have materially different data practices

Privacy Policies Change

AI services and their data practices can evolve. Privacy documentation may be revised as features, providers, laws, or business models change.

For an AI tool used materially in a long research project, record or otherwise document the policy and product conditions relevant when the decision was made, particularly where those conditions were important to ethics, governance, or data management.

Re-check them when the service changes materially or before introducing a new category of research data.

04 · A Practical Example

Before Uploading Interview Transcripts to an AI Tool

Hypothetical Example

A Researcher Wants AI Help With Qualitative Coding

A researcher has 40 interview transcripts and wants to use an AI system to suggest preliminary codes. The service allows document uploads, and the researcher already has a paid personal account.

1. Identify the data The transcripts contain participant experiences, occupations, institutions, and contextual details that could potentially identify individuals even after names are removed.
2. Check the research obligations The researcher reviews participant consent, ethics approval, the data-management plan, institutional policy, and any commitments about third-party processing.
3. Read the applicable privacy documentation The researcher checks whether uploaded content is retained, whether it may be used for model improvement, what controls apply to the personal paid account, who may process the data, and whether relevant international transfers occur.
4. Compare the conditions The researcher discovers that paying for the account does not, by itself, establish the institutional safeguards required for these transcripts.
5. Change the plan Instead of uploading the transcripts immediately, the researcher consults the relevant institutional guidance and considers an approved system or another analysis workflow compatible with the project's data requirements.

The privacy review does not ask merely whether the provider behaves responsibly. It asks whether the provider's conditions are compatible with the obligations attached to these particular research data.

05 · What Researchers Often Get Wrong

Common Mistakes When Reading AI Privacy Policies

Misconception

If My Data Are Not Used for Training, They Are Not Stored

Training and retention are different issues. Content may still be retained temporarily or processed for security, abuse monitoring, service delivery, legal obligations, or other purposes described by the provider.

Misconception

A Paid Account Means My Research Is Confidential

Payment status alone establishes no universal privacy condition. Check the exact product, plan, settings, documentation, and any applicable organizational agreement.

Misconception

Removing Names Makes Participant Data Safe to Upload

Removing direct identifiers may reduce risk without necessarily making information anonymous. Combinations of demographic, occupational, geographic, narrative, or other details can still permit identification, depending on the data and context.

Misconception

If the Company Has a Privacy Policy, the Tool Is Approved for Research

A privacy policy describes the provider's practices. It does not establish compatibility with your ethics approval, participant consent, institutional requirements, contractual duties, or applicable data-protection obligations.

Misconception

Deleting the Chat Means Every Copy Disappears Immediately

Visible deletion and backend deletion may follow different timelines, and providers may describe limited exceptions. Check the service's actual retention and deletion documentation rather than inferring backend behavior from the interface.

06 · What This Means for You

Classify the Data Before You Read the Policy

Privacy review becomes much easier when you first know what you intend to provide. A prompt containing a generic methodological question and a file containing identifiable participant interviews do not deserve the same level of scrutiny.

A simple decision framework

If the material is public, non-sensitive, and easily replaceable
A basic privacy review may be sufficient, subject to applicable project and institutional requirements.
If the material is unpublished, confidential, proprietary, or personally identifiable
Review the applicable privacy conditions and your research obligations before providing it to the service.
If the policy is unclear about a processing activity that matters to your project
Do not assume the most favorable interpretation. Seek authoritative clarification or use an alternative whose conditions can be established.
If your institution provides or approves a different version of the tool
Determine whether that specific arrangement offers the conditions required for your research rather than assuming your personal account is equivalent.
If the provider's policy conflicts with your research obligations
Do not upload the affected information merely because the tool is technically capable of processing it.

Where sensitive research information is involved, institutional approval may materially affect which AI tools you can use. Privacy is therefore part of tool selection and research governance, not a box to tick after the data have already been uploaded.

07 · A Quick Checklist

What to Check in an AI Tool's Privacy Policy

Before providing research information to an AI service, check:
Collection: What prompts, files, outputs, metadata, account information, and usage data are collected?
Purpose: Why does the provider process each relevant category of information?
Model improvement: Can prompts, files, outputs, or feedback be used to train, evaluate, or improve AI systems?
Retention: How long is information retained, including after deletion where relevant?
Recipients: Which affiliates, service providers, subprocessors, contractors, or other parties may receive or access the information?
Transfers: In which jurisdictions may the information be processed or transferred, and what safeguards are described?
Human access: Under what circumstances may authorized people review content?
Controls: What deletion, opt-out, history, temporary-processing, or privacy settings are available?
Account type: Does the policy differ for consumer, paid, API, team, enterprise, educational, or institutionally managed use?
Compatibility: Do these conditions comply with consent, ethics approval, institutional rules, contracts, data-management commitments, and applicable law?
08 · Frequently Asked Questions

Questions Researchers Ask About AI Privacy

Can I upload confidential research data if the AI provider says it does not train on my data?

Not on that basis alone. Training is only one form of processing. You also need to consider retention, access, sharing, transfers, security, contractual conditions, ethics requirements, consent, institutional policy, and any other obligations attached to the data.

Does paying for an AI tool give me better privacy?

Possibly, if the specific paid product provides materially different data conditions or controls. Do not infer those protections from payment itself. Verify the documentation governing the exact plan or organizational arrangement.

Can I upload anonymized participant data to an AI tool?

That depends on whether the data are genuinely anonymized, the possibility of re-identification, your research protocol, applicable law, institutional requirements, and the provider's conditions. Removing names alone does not necessarily constitute anonymization.

What is the difference between data retention and model training?

Retention concerns how long information is stored. Model training or improvement concerns whether information may be used to develop or evaluate AI systems. A provider can retain information without using it for model training, so both questions should be checked separately.

Should I check the privacy policy every time I use AI?

Not necessarily. Revisit it when adopting a new service, changing account types, introducing more sensitive information, beginning a consequential workflow, or when the provider materially changes its policies or product.

Is the privacy policy enough to determine whether an AI tool is safe for research data?

No. Depending on the project, you may also need security documentation, contractual terms, institutional approval, ethics requirements, data-processing agreements, consent conditions, or other governance information.

What if I cannot understand the privacy policy?

If a material data practice remains unclear, do not fill the gap with an assumption. Consult authoritative provider documentation, your institution's privacy or research-governance specialists where available, or use a tool whose conditions can be established sufficiently for the proposed use.

09 · The Bottom Line

Know Where Your Research Data Go Before You Send Them

The Bottom Line

Before giving an AI tool non-public research information, determine what it collects, why and how long it processes the information, whether the data may contribute to model improvement, who can receive or access them, where they may be processed, and what controls apply to your exact account.

Then compare those conditions with the obligations attached to the research itself. A privacy policy can tell you what the provider says it will do with the data. It cannot grant permission that your participants, ethics approval, institution, collaborators, contracts, or applicable law never gave you.

10 · Sources and Further Reading

Sources and Further Reading

11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes