The previous lesson was about what you may write: nothing that identifies anybody. This one
is about what happens after you hit send with something that already meets
that rule. They are two different questions, and confusing them is the most expensive
mistake in this lesson: a text with no name and no ID number still travels to a private
company's server, and that is where an entirely different story begins.
The whole thing in one sentence. A text that identifies nobody is not
automatically harmless to send. Where it goes, how long it is kept, and who else
inside the company that runs the model can read it are three questions with
different answers depending on the account you are logged into — and almost nobody checks
any of them before pasting the first piece of text.
The three questions, and why the answer is not always the same
| Question | Why it changes with the account |
| Is it used to train the next model? |
On most free tools, yes, unless you switch it off by hand in the privacy settings.
On a paid business account it is almost always no — that is literally part of what
you are paying for — but "almost always" is not "always": you have to read it for
that specific account rather than assume it from the price tag. |
| How long is the history kept? |
By default, indefinitely for as long as the account exists. Some tools offer a
"temporary" or incognito chat mode that never enters the visible history — but that
does not always mean nothing at all is kept on the servers during a short retention
window, kept for security and abuse-prevention reasons. |
| Who inside the company can read it? |
Almost no conversation is ever read by a person. But the policies of the main
tools allow for a sample to be reviewed by human moderation if it trips some safety
filter — and you do not get to decide what trips that filter. |
Why this is not theoretical. Switching on temporary or incognito mode is
not a whim when you paste something from the pharmacy: it is the difference between a draft
that is forgotten in twenty-four hours and a text permanently tied to your work email
address. The text does not need to identify anybody for that difference to matter — it
matters just as much with a perfectly anonymous text, because what is at stake is not the
patient's identity: it is what a company you never signed a confidentiality agreement with
now knows about your pharmacy.
The cheap way to fix this. You do not need to read an entire privacy policy
to be reasonably covered: two habits do most of the work. One, always log in with the
business account when one exists, rather than the personal one on your phone out of
convenience. Two, if you only have the free tier, switch on temporary or incognito mode
every time the query has anything to do with the pharmacy — even an already de-identified
case. Both are decisions you make once, at the start of the conversation, and never have to
think about again for the rest of the day.
A full example, and what is wrong with it
The same query, asked twice, both times following the privacy lesson to the letter — no
name, no ID number, no date of birth, nothing that identifies anybody. The difference is in
how it was asked, not what was asked.
The query, identical both times: "Woman in her seventies, hypertensive,
on enalapril, says she has been feeling dizzy on standing for two days. What do I ask before
deciding whether to refer?"
What happens in each version
Version A, in the normal chat, on your personal phone account. The
answer arrives just as good in both versions — that is not what is wrong here. What
happens is that this exchange stays in that account's history indefinitely, until somebody
deletes it by hand; and if that free account's policy is to train on conversations — which
is the default on most of them — this text becomes part of the material used to fine-tune
the next version of the model.
Version B, in temporary mode, on the pharmacy's business account. The
exchange disappears from the visible history when the window closes, and the business
account carries a contractual no-training clause. There is still a short retention window
on the server for security reasons — no mode avoids that — but it is a window of days, not
an indefinite permanence tied to your name.
And now, what is wrong with taking version A for granted:
- Meeting the privacy lesson is not the same as meeting this one. They
are two different axes, and both questions have to be asked: "does it identify somebody?"
and "what happens to this after I send it?" A text can pass the first question and fail
the second without you noticing, because nothing on screen warns you at the moment you are
typing.
- The account you are logged into matters more than what you write. The
same text, typed on the personal account or on the business one, ends up in a different
place. And nobody asks you before letting you type: the tool works exactly as well either
way, so there is no signal at all telling you that you logged in with the wrong one.
- Deleting from the visible history is not the same as deleting from the
servers. Security retention windows are common even with the deletion already
done, and they usually run around thirty days. This is not a leak, it is a policy written
in the small print — but it changes what you can honestly promise if somebody asks "and
where does this end up?".
- An uploaded file is not always treated like typed text. A PDF or a
photo dragged into the conversation can go through a different analysis pipeline — at
times with the file itself stored separately from the conversation about it. If the
document itself carried something that needed de-identifying, that step has to happen
before uploading it, not after asking a question about it.
And if your pharmacy is not like that
If you already pay for a business account. Then the work is not convincing
anybody to pay: it is checking that the whole team logs in with that account
and not with the personal one on their phone when the business one is slow to load or asks
to sign in again. The no-training clause protects nothing if half the counter queries are
done from a free account because it happened to already be open.
If several of you share a single account. The risk does not change in
kind, but it does in size: that account's history accumulates queries from the whole team in
one place, so one person's slip — pasting something they should not have — ends up mixed
with everybody else's work and is harder to trace afterwards. It is worth every person
having their own log-in, even inside the same business plan.
If you use a personal phone for quick counter queries. This is the most
common case and the easiest one to overlook: the phone is yours, so it feels private, but
the account installed on it is usually the same old free one. The cheap fix is to also
install the app with the business account and get used to choosing which one opens — two
seconds that change everything else in this lesson.
If the pharmacy runs on a VPN or a corporate network. That protects the
connection leg — stopping anybody intercepting the traffic on its way to the server — but it
changes nothing about what happens once the text has arrived at the company running the
model. They are two different layers of security and neither replaces the other: a VPN with
the wrong account still sends the text off to train the next model.
If you have never checked this and do not know which account you have.
Start with the cheapest thing to check: open the privacy settings of the tool you use and
look for "use my conversations to improve the model" or its equivalent. If it is switched on
and nobody has ever touched it, you are almost certainly on the free default plan, and now
you know what to ask before the next query.
When it does not work first time
I deleted the conversation from my history — is that it, then?
It is deleted from what you can see, which is what matters for
day-to-day work. What you cannot honestly promise is that nothing at all remains on the
servers during the security retention window, which is usually days or weeks. For normal
counter use this is rarely a practical problem; what changes is what you can say if
somebody asks you directly "does this stay stored forever?". The honest answer is "not in
what I can see, and only briefly on the server".
My boss or our accountant gave the whole team one shared account.
It works, and it is better than nothing — but check whether that
account allows individual log-ins within the same plan, which is standard on paid business
accounts. If it does not, agree on a simple rule at least: nobody pastes anything they
would not paste with the whole team reading over their shoulder, because literally anybody
with access to that account can open the history.
We use the free version on the pharmacy computer because nobody has
asked for the paid one.
That is the normal situation, not an exception. The step that actually
changes things is not "ask for the paid one" in the abstract: it is comparing its monthly
cost with what you already spend on other business subscriptions, and taking that specific
figure to whoever decides, instead of the vague idea that "we should probably have the
business one".
I do not know whether our account is paid or free, or who set it up.
More common than it sounds, especially in pharmacies where the account
was set up by somebody who has since left, or by an outside supplier. Check the billing
email tied to the account — a recurring monthly charge on the pharmacy's card means paid;
no charge at all means free — and from there you can decide with facts instead of guesses.
I uploaded a photo of a pack to ask something, and I do not know what
happens to that image.
Treat it with the same criterion as text: if the photo shows nothing
that identifies a specific person — no label with a name, no recognisable background of
your counter with something visible on it — the risk is the same as any other content you
upload to that account. If the photo does have something in the background that should not
be there, crop it before uploading rather than trusting the model to ignore it: a model
that reads images literally reads everything in the frame, not just what you ask about it,
and has no way of knowing which part of the background was there by accident and which part you
just forgot to move out of shot before pressing the shutter.
Before moving on
- I can tell "does it identify somebody?" apart from "what happens to this afterwards?".
- I know which account I am logged into — personal or business — before typing anything
about the pharmacy.
- I use temporary or incognito mode when the account is not the business one.
- I know that deleting from the visible history is not the same as deleting from the
servers.
← Revisit: patient data and privacy
Next: what generative AI is, and what it is not →
← Back to the AI School