Tallis

Guide

Private AI assistant: what actually happens to your data

Every assistant calls itself private. The word covers four separate promises, and a product can keep one while failing the rest.

Written by Tallis. Last updated 2026-09-18.

"Private" is four different promises

Almost every assistant calls itself private. The word covers at least four separate things, and a product can honestly claim one while failing the other three. Sort them before you compare anyone.

1. Not used for training

Your messages and files are not fed back into a model. This is the promise most people mean, and the easiest to state. Ask whether it covers the model provider too, not only the product you are paying.

2. Not mixed with other customers

Your memory, files, credentials and logged-in browser sessions are separated from everyone else's. A single shared workspace behind many customers is a different risk from a private space for each one. This is the promise people forget to ask about, and the one that hurts most when it fails.

3. Not kept longer than needed

There is a retention period, it is written down, and deletion actually deletes rather than hides. Ask about backups: a record removed from the product but alive in a backup for a year is still a record.

4. Not readable by the people running it

This is the strongest claim and the rarest. Be suspicious of any assistant that claims it while also offering human support on your content, because someone has to be able to look in order to help.

Where your data actually goes

An assistant that does real work touches more than a chat log. Picture one instruction, "reply to that customer and update the sheet", and follow it.

  • Your message reaches the product's servers. Whoever runs them can read it.
  • The model call sends the relevant part of your message, and often your recent context, to a model provider. Ask which providers, in which countries, and under what retention terms.
  • The connected account, your mail, your calendar, your store, gets read with a token the assistant holds. Ask where that token is stored and what else it could do.
  • The memory keeps something about you so the next instruction is better. Ask to see it, and ask whether you can correct or delete an entry.
  • The logs record what happened for support and debugging. Ask how long they live and whether they contain message bodies.

Five places, not one. A privacy page that only talks about the first is not describing the product.

Six questions worth asking before you connect anything

  1. Is my content used to train any model, including the model provider's?
  2. What separates my workspace from another customer's? Name the boundary.
  3. Which model providers see my content, and where are they?
  4. How long are messages, files and logs kept, and what happens in backups?
  5. Can I see what the assistant remembers about me, correct it, export it and delete it?
  6. If I cancel, what happens on day one, day thirty and day ninety?

A good answer looks specific

"No training, ever" is a claim. "No training; your workspace is separate per customer; messages are kept until you delete them; here is the export button; here is the deletion request address" is an answer. Written specifics are what you can hold someone to later.

Where Tallis stands

Each subscriber gets a private space of their own: its own memory, files, schedules, credentials and browser session. Nothing is shared between customers, and your conversations are not training data.

You can inspect what Tallis remembers, correct it, export your data, disconnect an account, cancel and ask for deletion. The binding version of all of that is the privacy notice, not this page.

What we do not claim: your messages reach our servers and a model provider, and people running the service can see enough to support you. Any assistant that carries out real work has that property. Treat the ones that deny it with more suspicion, not less.

Common questions

Is an assistant in a chat app end to end encrypted?

Not when a bot is in the conversation. A bot is a participant, so it reads what you send it. Privacy comes from how the operator stores and separates that content, not from the chat app's badge.

Does "we don't train on your data" cover the model provider?

Only if the product says so. Ask specifically. Enterprise model terms usually forbid training on customer content, but the product has to be on those terms for the promise to reach you.

What is the highest-risk thing I can connect?

Anything that can send on your behalf, and anything holding money. Connect reading before writing, and keep approval on every send while you learn what the assistant gets right.

How do I test a deletion promise?

Ask for deletion of one specific item, then ask the assistant to recall it. If it still knows, the promise covers a different system than you thought.

A private space of your own.

Your memory, your files, your logged-in sessions, separated from every other customer. Join the waitlist to try it.

Join the waitlist