AI School · Level 1 · Lesson 2

What happens to what you type: memory and history

Léelo en español →

The previous lesson was about what you may write: nothing that identifies anybody. This one is about what happens after you hit send with something that already meets that rule. They are two different questions, and confusing them is the most expensive mistake in this lesson: a text with no name and no ID number still travels to a private company's server, and that is where an entirely different story begins.

The whole thing in one sentence. A text that identifies nobody is not automatically harmless to send. Where it goes, how long it is kept, and who else inside the company that runs the model can read it are three questions with different answers depending on the account you are logged into — and almost nobody checks any of them before pasting the first piece of text.

The three questions, and why the answer is not always the same

QuestionWhy it changes with the account
Is it used to train the next model? On most free tools, yes, unless you switch it off by hand in the privacy settings. On a paid business account it is almost always no — that is literally part of what you are paying for — but "almost always" is not "always": you have to read it for that specific account rather than assume it from the price tag.
How long is the history kept? By default, indefinitely for as long as the account exists. Some tools offer a "temporary" or incognito chat mode that never enters the visible history — but that does not always mean nothing at all is kept on the servers during a short retention window, kept for security and abuse-prevention reasons.
Who inside the company can read it? Almost no conversation is ever read by a person. But the policies of the main tools allow for a sample to be reviewed by human moderation if it trips some safety filter — and you do not get to decide what trips that filter.
Why this is not theoretical. Switching on temporary or incognito mode is not a whim when you paste something from the pharmacy: it is the difference between a draft that is forgotten in twenty-four hours and a text permanently tied to your work email address. The text does not need to identify anybody for that difference to matter — it matters just as much with a perfectly anonymous text, because what is at stake is not the patient's identity: it is what a company you never signed a confidentiality agreement with now knows about your pharmacy.
The cheap way to fix this. You do not need to read an entire privacy policy to be reasonably covered: two habits do most of the work. One, always log in with the business account when one exists, rather than the personal one on your phone out of convenience. Two, if you only have the free tier, switch on temporary or incognito mode every time the query has anything to do with the pharmacy — even an already de-identified case. Both are decisions you make once, at the start of the conversation, and never have to think about again for the rest of the day.

A full example, and what is wrong with it

The same query, asked twice, both times following the privacy lesson to the letter — no name, no ID number, no date of birth, nothing that identifies anybody. The difference is in how it was asked, not what was asked.

The query, identical both times: "Woman in her seventies, hypertensive, on enalapril, says she has been feeling dizzy on standing for two days. What do I ask before deciding whether to refer?"

What happens in each version

Version A, in the normal chat, on your personal phone account. The answer arrives just as good in both versions — that is not what is wrong here. What happens is that this exchange stays in that account's history indefinitely, until somebody deletes it by hand; and if that free account's policy is to train on conversations — which is the default on most of them — this text becomes part of the material used to fine-tune the next version of the model.

Version B, in temporary mode, on the pharmacy's business account. The exchange disappears from the visible history when the window closes, and the business account carries a contractual no-training clause. There is still a short retention window on the server for security reasons — no mode avoids that — but it is a window of days, not an indefinite permanence tied to your name.

And now, what is wrong with taking version A for granted:

  1. Meeting the privacy lesson is not the same as meeting this one. They are two different axes, and both questions have to be asked: "does it identify somebody?" and "what happens to this after I send it?" A text can pass the first question and fail the second without you noticing, because nothing on screen warns you at the moment you are typing.
  2. The account you are logged into matters more than what you write. The same text, typed on the personal account or on the business one, ends up in a different place. And nobody asks you before letting you type: the tool works exactly as well either way, so there is no signal at all telling you that you logged in with the wrong one.
  3. Deleting from the visible history is not the same as deleting from the servers. Security retention windows are common even with the deletion already done, and they usually run around thirty days. This is not a leak, it is a policy written in the small print — but it changes what you can honestly promise if somebody asks "and where does this end up?".
  4. An uploaded file is not always treated like typed text. A PDF or a photo dragged into the conversation can go through a different analysis pipeline — at times with the file itself stored separately from the conversation about it. If the document itself carried something that needed de-identifying, that step has to happen before uploading it, not after asking a question about it.

And if your pharmacy is not like that

If you already pay for a business account. Then the work is not convincing anybody to pay: it is checking that the whole team logs in with that account and not with the personal one on their phone when the business one is slow to load or asks to sign in again. The no-training clause protects nothing if half the counter queries are done from a free account because it happened to already be open.
If several of you share a single account. The risk does not change in kind, but it does in size: that account's history accumulates queries from the whole team in one place, so one person's slip — pasting something they should not have — ends up mixed with everybody else's work and is harder to trace afterwards. It is worth every person having their own log-in, even inside the same business plan.
If you use a personal phone for quick counter queries. This is the most common case and the easiest one to overlook: the phone is yours, so it feels private, but the account installed on it is usually the same old free one. The cheap fix is to also install the app with the business account and get used to choosing which one opens — two seconds that change everything else in this lesson.
If the pharmacy runs on a VPN or a corporate network. That protects the connection leg — stopping anybody intercepting the traffic on its way to the server — but it changes nothing about what happens once the text has arrived at the company running the model. They are two different layers of security and neither replaces the other: a VPN with the wrong account still sends the text off to train the next model.
If you have never checked this and do not know which account you have. Start with the cheapest thing to check: open the privacy settings of the tool you use and look for "use my conversations to improve the model" or its equivalent. If it is switched on and nobody has ever touched it, you are almost certainly on the free default plan, and now you know what to ask before the next query.

When it does not work first time

I deleted the conversation from my history — is that it, then?
It is deleted from what you can see, which is what matters for day-to-day work. What you cannot honestly promise is that nothing at all remains on the servers during the security retention window, which is usually days or weeks. For normal counter use this is rarely a practical problem; what changes is what you can say if somebody asks you directly "does this stay stored forever?". The honest answer is "not in what I can see, and only briefly on the server".
My boss or our accountant gave the whole team one shared account.
It works, and it is better than nothing — but check whether that account allows individual log-ins within the same plan, which is standard on paid business accounts. If it does not, agree on a simple rule at least: nobody pastes anything they would not paste with the whole team reading over their shoulder, because literally anybody with access to that account can open the history.
We use the free version on the pharmacy computer because nobody has asked for the paid one.
That is the normal situation, not an exception. The step that actually changes things is not "ask for the paid one" in the abstract: it is comparing its monthly cost with what you already spend on other business subscriptions, and taking that specific figure to whoever decides, instead of the vague idea that "we should probably have the business one".
I do not know whether our account is paid or free, or who set it up.
More common than it sounds, especially in pharmacies where the account was set up by somebody who has since left, or by an outside supplier. Check the billing email tied to the account — a recurring monthly charge on the pharmacy's card means paid; no charge at all means free — and from there you can decide with facts instead of guesses.
I uploaded a photo of a pack to ask something, and I do not know what happens to that image.
Treat it with the same criterion as text: if the photo shows nothing that identifies a specific person — no label with a name, no recognisable background of your counter with something visible on it — the risk is the same as any other content you upload to that account. If the photo does have something in the background that should not be there, crop it before uploading rather than trusting the model to ignore it: a model that reads images literally reads everything in the frame, not just what you ask about it, and has no way of knowing which part of the background was there by accident and which part you just forgot to move out of shot before pressing the shutter.

Before moving on

← Revisit: patient data and privacy
Next: what generative AI is, and what it is not →
← Back to the AI School