I think your reaction is pretty close to how many technically minded users see articles like that.
The HuffPost piece is basically giving the standard privacy-professional advice: don't share personally identifying information, confidential business information, financial account details, medical records, or highly intimate personal information because chatbot conversations may be stored and may be used to improve models depending on settings and the service involved.
Where I would differ slightly from the article is that it tends to treat all information as equally sensitive. In practice there is a huge difference between:
-
"I'm an 83-year-old retiree living in Cambodia."
-
"My Social Security number is 123-45-6789."
-
"Here is my bank account login and password."
Those are not remotely the same privacy risk.
Your approach seems to be: don't reveal information you wouldn't reveal elsewhere, but don't panic about ordinary personal discussion. That's a perfectly defensible position. Most people already disclose enormous amounts of information to search engines, retailers, credit card companies, mobile phone providers, social media platforms, email services, and governments. AI systems are another participant in that ecosystem rather than something entirely unique.
A couple of nuances, though:
-
Training is not the same as publication.
People sometimes imagine that if they tell an AI something, it immediately becomes visible to everyone else. That's not how training works. The concern is more about retention, analysis, accidental exposure, or future misuse than direct republication. -
Data breaches are often the larger risk.
Even if a company has no intention of selling information, databases can be compromised, employees can make mistakes, systems can have bugs, and laws can change. The security concern is often less "the company will sell my secrets" and more "the data exists somewhere." -
Selling data is less common than using it.
The public often imagines companies literally selling customer conversations. Frequently the more valuable thing is using aggregate data to improve products, target advertising, understand customer behavior, or build future services. The economic value comes from knowledge and prediction rather than a direct sale of individual records.
Your comparison to a grocer is actually a good one. If you buy sugar-free products, low-sodium foods, and diabetic supplies, your grocer learns things about you. If you discuss diabetes with an AI, the AI service learns things about you. The question is not whether information is collected—it almost always is—but whether the benefit is worth the risk and whether the information is sensitive enough to matter.
Given what you've said in previous conversations, you seem to use ChatGPT partly as a thinking partner and partly as a historical record of your ideas. For that purpose, sharing opinions about politics, anthropology, aging, Buddhism, Star Trek, or climate change is generally a very different category from sharing account numbers, passwords, tax returns, or legal documents.
In short: the article's warnings are sensible as a rule of thumb. But many people read them as "never tell an AI anything personal." That's a much stronger claim than the evidence really supports. The more practical rule is: don't tell an AI anything that would seriously harm you if it escaped your control. Everything else becomes a question of convenience, usefulness, and personal comfort with privacy risk.
That makes sense, and there's another reason many people wouldn't: if you've actually committed a serious crime, almost any permanent written record is a bad place to discuss details.
The interesting thing is that privacy concerns often focus on dramatic examples—criminal confessions, secret affairs, hidden bank accounts—when the more common issue is mundane accumulation of information. A company may learn your age range, health concerns, political interests, shopping habits, travel patterns, and social connections. None of those facts is shocking by itself, but together they can form a remarkably detailed portrait.
You strike me as someone who has largely made peace with that tradeoff. You write a public blog, deliberately preserve conversations as a record of your thinking, and often discuss topics that you'd be perfectly willing for future historians—or at least curious readers—to know about. For someone with that attitude, the risks worth worrying about are probably not "ChatGPT knows I think climate adaptation matters" or "ChatGPT knows I live in Cambodia."
They're more likely to be things such as:
-
Financial account information.
-
Passwords or security questions.
-
Information that could enable fraud or identity theft.
-
Confidential information belonging to other people.
-
Details that could create legal or family complications if taken out of context.
An anthropologist might point out that humans have always had to decide whom to trust with information. A village elder, a priest, a physician, a bartender, a diary, a letter, a telephone company, a bank, a social club—all are information repositories. AI is a new kind of repository, but it sits in a long historical line of them.
And, of course, there is the practical point: if someone is planning crimes, asking a machine that keeps records is rarely the cleverest operational-security strategy. History suggests that criminals usually get caught because they talk too much somewhere. The medium changes; the tendency doesn't.
That's a distinction a lot of privacy experts acknowledge, even if it doesn't always come across in public advice.
For someone in their 30s or 40s, a detailed medical record can have consequences far beyond the immediate conversation. Employment decisions, insurance underwriting, disability claims, security clearances, and even social stigma can be affected by information becoming known. In some countries there are legal protections, but protections are not the same thing as perfect prevention.
At 83, your calculation is understandably different. You have often discussed your diabetes, hepatitis B history, depression, blood pressure, medications, cholesterol numbers, and recent physical because those details materially affect the quality of any health-related discussion. If you simply asked, "Should I consider semaglutide?" without mentioning your age, weight, medical history, medications, and goals, any answer would be much less useful.
The tradeoff is that the information becomes known to the service. The benefit is that the advice becomes far more tailored and avoids obvious mistakes.
I also think there is a difference between:
- "I have type 2 diabetes controlled with metformin and an SGLT2 inhibitor."
- Uploading an entire medical chart containing addresses, insurance numbers, patient IDs, physician names, signatures, and every clinical note from the last twenty years.
The first is often enough for a meaningful discussion. The second contains a lot of information that may not be necessary.
One thing I've noticed in our conversations is that you tend to disclose information selectively and for a purpose. You don't seem interested in broadcasting every detail of your life; rather, you provide the details that help answer the question at hand. That's actually a fairly sensible privacy practice regardless of age.
Your comment about insurance is especially relevant historically. Many older Americans remember periods when pre-existing conditions could have major consequences for obtaining coverage. Someone who lived through that era often has a more concrete appreciation of why medical privacy matters than a younger person who has mostly known a different regulatory environment.
In the end, privacy isn't an all-or-nothing proposition. It's a matter of deciding which information is worth protecting, from whom, and at what cost. For you, the value of discussing medical details appears to outweigh the potential downside. For a 35-year-old shopping for life insurance, the calculation might reasonably come out very differently.
No comments:
Post a Comment