Blog  ·  28 July 2026

What you shouldn't paste into a cloud chatbot

Almost everyone has hesitated for a second before pasting something into a chat box, then done it anyway. Here is a clearer way to think about that hesitation.

This is not an argument that cloud AI tools are dangerous. They are enormously useful and most of what people paste into them is harmless. The problem is that the decision is usually made in a hurry, with no framework, on text that took ten seconds to copy and could take years to un-send.

What actually happens when you paste

Your text is sent over the network to a company's servers, processed there, and an answer is sent back. Beyond that, the specifics vary by product and by your settings: how long the text is retained, whether it may be used to improve models, who inside the company can access it, and which jurisdiction it sits in. Business and enterprise tiers typically make stronger commitments than free consumer tiers.

None of that is sinister. But notice the shape of it: you are relying on a policy, and policies are a moving target. They get revised, features get added, defaults get changed, and the person most likely to misread the settings is a busy human at 11pm.

The test worth applying

Forget the policy for a moment and ask a simpler question:

If this exact text appeared in a place I did not choose, who would be harmed, and would I have to tell them?

That question sorts almost everything correctly in about two seconds, because it captures the two things that actually matter: consequence and obligation. Most text fails neither test. Some fails both.

Text that usually fails the test

Text that is usually fine

Four ways to handle the risky category

1. Redact before you paste

Often the AI does not need the names, the numbers or the company. "Rewrite this paragraph to be firmer" works fine with placeholders. This is free and takes seconds, and it is the most under-used option on the list.

2. Use a business tier with the right commitments

If your employer has an enterprise agreement, use it, and use it as configured. This is the correct answer inside most organisations — but check what was actually agreed rather than assuming.

3. Ask a general question instead of a specific one

"What usually goes in a termination clause?" gets you most of the value of "here is our termination clause" with none of the exposure.

4. Use an assistant that runs on your own device

The category-different option: if the AI runs on your phone, the text never travels. There is no retention policy to read, no setting to get wrong, and no jurisdiction question, because nothing is transmitted. This is what OnDevice LLM is for.

The honest trade-off: an assistant that fits on a phone is not as capable as a frontier cloud model. It is strong at summarising, rewriting, extracting details and answering everyday questions, and weaker at hard reasoning. For the confidential category that trade is usually worth it, because the alternative is often not "use a better AI" but "do it manually".

A rule of thumb

Use the best cloud model available for anything public or generic. Use something local for anything you would have to explain. The mistake is not choosing one over the other — it is having no rule at all and deciding case by case at the end of a long day.

Frequently asked questions

Is it safe to paste confidential documents into a cloud AI chatbot?

It depends on the product, your settings and your obligations. The text is sent to a company's servers, and retention and training use vary by tier. For anything covered by an NDA, anything containing someone else's personal data, or anything you would have to disclose if it leaked, the safer options are to redact it first, ask a general question instead, use an approved business tier, or use an assistant that runs on your own device.

What is the quickest way to decide?

Ask yourself: if this exact text appeared somewhere I did not choose, who would be harmed and would I have to tell them? If the answer is nobody, paste it. If someone would have to be told, redact it or keep it local.

Does an on-device AI assistant really send nothing?

An assistant that runs on the device processes your text on the phone and writes the answer there. Nothing is transmitted, which is why it works with no connection at all. Setup requires a connection once.

Is a local assistant as good as ChatGPT?

No. An AI that fits on a phone is good at summarising, rewriting, extracting and everyday questions, and weaker at hard reasoning and anything needing current information. The reason to use one is privacy and offline access, not raw capability.

OnDevice LLM is a private AI assistant that runs entirely on your iPhone — no account, no cloud, and nothing you type leaves the device. Free in full for three days, then a one-time purchase.

Last updated: 28 July 2026