Is your AI app actually private?
Six questions, about five minutes, and a straight read on whatever app you are weighing up. Answer them from the product's own privacy policy. Nothing here is stored or sent anywhere — the answers live in your browser and vanish when you reload.
Most coverage of AI privacy ends at "be careful." This is the part that usually goes missing: what to actually look for, and how to read what you find. Open the privacy policy of the app you are considering and work down the list.
If you cannot find an answer in a minute or two, answer "Can't tell" — and treat it as a no. That is not a trick to inflate the failures. A company that has built a real protection says so plainly, because the engineering cost is only worth paying if customers hear about it. On a document lawyers have reviewed, silence is rarely an accident.
The six checks
1. Does it name the specific company that processes your words?
Every AI product sends your text to a model provider. That is the mechanism, not a leak — the question is whether they will tell you whose infrastructure reads it.
2. Does it state plainly that it does not train models on your conversations?
Many general-purpose chatbots use conversations to improve models by default, with the opt-out some distance into settings.
3. Can you stop it keeping your history on their servers?
"Encrypted" describes how something is stored. It does not tell you whether it is stored at all — a different and larger question.
4. Does the encryption key never leave your device?
If the company derives or holds the key, it can decrypt your data. That still protects you from theft and outside access — but not from the company, and not from a court order.
5. Can you delete everything yourself, without emailing support?
Deletion that requires a human on the other end is a policy. Deletion behind a button is a feature someone actually built.
6. Do you pay for it, rather than it being free and ad-supported?
Not a moral point — a structural one. Ads and data brokerage create a permanent commercial pull against your privacy that no policy page fully offsets.
Your running tally
0 of 6 checks passed
Answer all 6 to see where this app lands.
What the result does and doesn't tell you
This is a read on a product's posture — how much it collects, how much control it hands you, and how straight it is about both. It is not a security audit, and it cannot tell you whether a company honours its own policy. No checklist can.
It also cannot give you confidentiality, because no consumer app can. Conversations with an AI carry no legal privilege regardless of how well a product scores here — a company can still be compelled to produce what it holds. That is a separate question, and whether AI therapy is private is where it gets answered properly.
How Haven scores on its own checklist
Publishing a checklist and dodging it would be worth nothing, so: Haven passes five of these six and fails check 4. Our encryption key is derived by our server, so your data is encrypted at rest rather than end-to-end — meaning we could decrypt it, and a court could require us to. A fully offline journaling app beats us there, and if that is your priority you should use one.
The full walkthrough, including what we cannot protect you from, is on how private Haven is, in detail. Haven is a private space to think out loud — it is deliberately not therapy, not a therapist, and not a crisis service.
Common questions
How do I know if an AI app is actually private?
Check six things in its privacy policy: whether it names the company that processes your words, whether it trains models on your conversations, whether you can stop server-side storage, who holds the encryption key, whether you can delete everything yourself, and how the company makes money. A product that has done this work usually states all six plainly, because each one was expensive to build and is worth advertising.
What if the privacy policy does not answer these questions?
Treat that as the answer. Companies that have built real privacy protections describe them specifically, because the engineering cost is only worth paying if customers know about it. Vagueness is rarely an oversight on a document that lawyers reviewed — and "we take your privacy seriously" is a sentence, not a protection.
Is encrypted the same as private?
No, and the gap between them is where most confusion lives. Encryption describes how data is stored, not whether it is stored, and not who holds the key. If the company holds the key, encryption protects you from hackers and outside access but not from the company itself or from a valid court order. Only end-to-end encryption, where the key never leaves your device, protects against those.
Does this tool store my answers?
No. Nothing is saved, sent, or logged — the answers exist in your browser for the length of the visit and disappear when you reload the page. There is no form submission and no analytics event attached to any answer. You can verify that by opening your browser developer tools and watching the network tab while you use it.