What Actually Leaves, and Where It Goes
Tracing the path of a prompt in plain terms, because most policy is written without anybody having done it.
Foundations · Explainer
Policy arguments about AI tools are usually conducted without a clear picture of what physically happens to the text somebody types. It is worth establishing.
The recommendations in “What Actually Leaves, and Where It Goes” become easier to sustain when implementation work has visible owners, dates and review time. Teams evaluating time analytics software can use it to coordinate the operational side of AI adoption and identify where governance tasks are being missed, without treating activity data as evidence of misconduct or as a substitute for asking people why they chose a tool.
For an independent benchmark, compare the local approach with ICO guidance on AI and data protection; the useful test is whether ownership, access and recovery remain proportionate and explainable when the usual expert is absent.
The path
The user types or pastes text into a browser or an application.
It goes over the network to the provider.
The provider processes it, generates a response, and returns it.
Depending on the service and the account type, the exchange may be logged, retained for a period, reviewed by humans for quality or abuse, and used to improve models.
Each of those is a separate question with a separate answer, and the answers differ by account type more than by provider.
What goes with it
The text itself, including anything pasted without being read: a whole document, a spreadsheet region, an email thread.
Attached files, where supported, in full.
Account identity, which on a consumer service is a personal email address.
And in browser-based tools, sometimes page content the user did not intend to send — which is the extension case and is worth checking specifically.
The paste problem
The single largest practical risk and the least discussed.
People paste more than they mean to: the whole document rather than the paragraph, the full thread rather than the question.
Most data exposure in this area is not somebody deciding to send confidential information. It is somebody not reading what they selected.
Which points at training and at tooling that redacts, rather than at rules.
Where it sits afterwards
On the provider's infrastructure, in a jurisdiction that may not be yours.
For a period set by their terms, which for consumer accounts is frequently longer than enterprise ones and sometimes indefinite.
Potentially in training data, depending on account type and settings.
And in the user's own account history, accessible to anybody who gets into that account — which is an overlooked route and is worse for personal accounts with weak authentication.
The enterprise difference
Enterprise agreements typically exclude training use, shorten retention, specify processing location and provide a contract to enforce it.
That is the main practical reason to provide an approved tool rather than to ban an unapproved one.
Its own note covers the specific terms worth reading.
Doing this exercise yourself
Take one tool in use and trace it: what goes, where, kept how long, used for what.
An afternoon with the terms and a network trace.
The result is more persuasive internally than any amount of general risk discussion.
What to check
Has anybody traced the path for a tool actually in use here?
Do you know the retention period for the consumer version people use?
Are browser extensions sending page content anywhere?
And does your training mention what happens when somebody pastes a whole document?
The point
Most data exposure here is not somebody deciding to send confidential information.
It is somebody not reading what they selected.
Underlying all of this
Everything in this collection reduces to four habits: find out what people are doing and why before deciding anything, provide something good enough that the approved route is the easy one, write rules about information rather than about tools, and monitor the destination rather than the content. None requires a product, and a programme doing all four controls more than one built on prohibition.
The recurring pattern
The recurring pattern across every section here is the same: the response that feels like control reduces it. A ban removes visibility rather than use. Content inspection drives activity to personal devices. A discovery exercise with consequences produces quiet answers. In each case the organisation ends up knowing less about a risk it believes it has handled.