Is Your Data Safe With AI Tools? The Honest Answer
Question — — by Mahmoud Zalt
What actually happens to your data inside an AI tool: who reads it, whether it trains a model, how long it is kept, and how to get it deleted.
The worry is rarely about hackers. It is quieter than that. You paste a client list into something, and a week later you cannot remember where it went, who can see it, or whether it is now part of a model that will help a competitor.
That feeling is not paranoia, it is an accurate reading of how vague most AI privacy pages are. The industry has trained people to expect a wall of legal text that never quite says yes or no. So this article says yes or no. Where the answer is uncomfortable, it says that too, because a vague reassurance is worth nothing to you.
Here is how it works on Sistava. Your data lives in your own workspace, walled off from every other customer at the database level. When your AI Employee needs to think, the relevant text is sent to a model provider to produce an answer, then the answer comes back. That call is covered by a contract that forbids training on it. Nothing about your business becomes part of anybody's model.
At a Glance
- No
- Training on your business data
- Per tenant
- How your data is separated from others
- You
- Who decides when it is deleted
- 4
- Questions to ask any AI vendor
Will my data be used to train an AI model?
No, not your business data on Sistava. The model providers we call operate under business terms that exclude training on the content sent through the API, which is a different arrangement from a free consumer chatbot where training is often the default. That difference is the single biggest thing people get wrong when they compare the two.
The honest caveat is that this is a contractual guarantee, not a law of physics. It rests on the provider honouring its own terms, the same way your accountant's confidentiality rests on their professional obligations. That is how nearly all business software works. Anyone claiming a stronger guarantee without running the model on hardware they own is overselling it.
Who at the company can read my data?
Almost nobody, almost never. Access to customer content is restricted, logged, and only used when you open a support ticket that cannot be resolved any other way. Nobody browses customer inboxes to see how the product is going. What we do look at is aggregate numbers: how many messages, how many failures, how long things took.
The part worth checking with any vendor is whether support access requires your permission or happens silently. Ask directly. A company that has thought about this will have a clear policy and will not be offended by the question. A company that has not will give you a warm sentence with no mechanism behind it.
Marcus runs a two person recruitment agency in Toronto, which means his whole business is other people's personal data. Before connecting anything he sent us four questions in an email and asked for written answers: training, access, retention, deletion. He got them, saved the reply in his compliance folder, and connected one mailbox. That folder is what he shows clients when they ask. Ten minutes of work bought him a year of easy answers.
How long is my data kept, and can I delete it?
It is kept while your account is active, because your AI Employee needs its own history to be useful. You can delete individual items at any time, and you can delete the whole workspace when you leave. Deletion removes the data from live systems immediately and from encrypted backups as those backups roll off on their normal cycle.
That backup delay is the part most vendors hide, so here it is plainly: no serious system can reach inside an encrypted backup snapshot and surgically remove one row. The honest promise is that backups expire on a fixed schedule and your deleted data goes with them. Anyone promising instant erasure from all backups either has no backups or has not thought about it.
What are the real data risks, not the imaginary ones?
The realistic risks are boring and worth taking seriously. You paste something into a free consumer chatbot out of habit and it does train on it. You connect a tool with far more access than the job needs. A teammate's account gets compromised and the AI connections come along with it. Or the AI reads a document containing text designed to manipulate it into sending information somewhere it should not.
Notice that three of those four are about your setup rather than the vendor's servers. That is the actual shape of this problem. Encryption and data centres get all the attention on marketing pages, while the things that go wrong in real life are habits, over-broad permissions, and a missing approval step.
So the practical protections are unglamorous. Use the business tool rather than the free chatbot for anything client related. Grant the narrowest access that does the job. Turn on two factor authentication on the accounts you connect. Require approval before anything leaves your company. None of that is exciting, and all of it works.
How to check any AI tool before you trust it with data
- 1. Ask the training question in writing — Does my content train your models or anybody else's? You want a plain no in an email you can keep, not a paragraph in a policy that might change.
- 2. Ask who can read it and when — Find out whether staff access requires your permission, whether it is logged, and what triggers it.
- 3. Ask where it is stored — Country matters if you have clients with location requirements. Ask for the region, not the marketing word global.
- 4. Ask how deletion actually works — You want a specific answer covering live systems and backups, including the backup window.
- 5. Connect the least sensitive thing first — Prove the tool is useful on low stakes data before it goes anywhere near a client record.
- 6. Save the answers — Keep the replies in one folder. When a client asks how you handle their data, you answer in two minutes instead of two days.
| What you are worried about | What is actually true | What you control |
|---|---|---|
| My data trains a model | Not on business API terms, which is what we use | Avoid pasting client data into free consumer chatbots |
| Staff read my messages | Restricted, logged, support only | Ask for the access policy in writing before you connect |
| It is kept forever | Kept while active, deleted on request, backups roll off | Delete items or the whole workspace whenever you want |
| Another customer sees it | Data is separated per customer at the database level | Nothing needed, this one is on us |
| It leaks through an action | Possible if permissions are too broad | Least access plus approval before anything is sent |
FAQ
Is a paid AI tool safer than a free chatbot for company data?
Usually yes, and the reason is contractual rather than technical. Business terms typically exclude training on your content and add deletion commitments, while free consumer tiers often use conversations to improve the product unless you opt out.
Where is my data physically stored?
In our own managed infrastructure in Europe, not on a general public cloud storage service. If you have a client contract that requires a specific region, ask before you sign up rather than after.
Can another customer's AI Employee reach my data?
No. Separation is enforced at the database level, so every query is bound to your workspace. This is checked in our tests rather than assumed, because it is the failure that would matter most.
What happens to my data if I cancel?
You can export what you want, then delete the workspace. Deletion clears live systems straight away, and encrypted backups containing it expire on their normal rotation.
Do you sell or share data with advertisers?
No. There is no advertising business here to feed. The only third parties that ever see content are the model providers doing the thinking, under terms that forbid training on it.