WORKSHOPntworldink.comAugust 2026
AI Special Topic Workshops · A One-Hour Session

Where Does Your Chat Go?
Taking Care of Your Data in AI Tools

Every prompt you type is shared with a commercial entity that may retain it, review it, and learn from it. This hour covers how we got here, what actually happens to your words, and the settings that put you back in charge.

Platform settings in this deck were checked in late 2025; privacy menus move often, so always verify against the current interface.

ntworld.inkWorkshops01 / 16
START HEREthe knowledge gapWhy it matters
The gap this hour closes

Legal complexity on one side, everyday users on the other

What you see

A friendly chat box

It feels like a private conversation; people ask AI about health worries, money troubles, relationship problems and work conflicts without a second thought.

What's underneath

A commercial data pipeline

Behind the box sit privacy policies written in dense legal language, covering retention, human review, model training and disclosure; terms most users have never read and couldn't parse if they did.

The plan for the hour: first the backstory (how a decade of data harvesting got us here), then what makes AI tools different, then the practical part: checking your settings, platform by platform, and deciding what never to type at all.
ntworld.inkWorkshops02 / 16
BACKSTORYthe business model beneath it allSurveillance capitalism
The backstory: a name for the business model

"Surveillance capitalism": your experience as raw material

Harvard economist Shoshana Zuboff coined the term for a business model built on collecting, analysing and commercialising consumer data, often without meaningful consent: human experience is translated into behavioural data, which becomes prediction products traded for profit.

·Incursion: companies quietly began harvesting and storing data from online behaviour; legal simply because nothing yet regulated it.
·Habituation: users grew accustomed to trading personal data for "free" services, while collection expanded far beyond what anyone understood.
·Adaptation: data got used to modify behaviour for profit; "selling certainty". In 2017, leaked documents showed Facebook telling advertisers it could identify teenagers in emotional distress and target advertising at them.
Rohit Chopra · former CFPB Director
"Behavioural advertising generates profits by turning users into products, their activity into assets, their communities into targets, and social media platforms into weapons of mass manipulation."
ntworld.inkWorkshops03 / 16
TRUE STORYone quiz, 87 million profilesCambridge Analytica

In 2013, a Cambridge University researcher built a Facebook personality quiz called "This Is Your Digital Life". About 300,000 people took it for a small payment. The app harvested data not just from them, but from all their Facebook friends: up to 87 million profiles; likes, locations, friendships, personal details.

The data flowed to Cambridge Analytica, a political consulting firm, which used it to build "psychographic profiles" for micro-targeted political advertising in the 2016 US presidential election. The harvesting ran quietly from 2013 to 2016; the public learned of it only in March 2018, when whistleblower Christopher Wylie went to The Guardian and The New York Times.

ntworld.inkWorkshops04 / 16
TRUE STORYwhat it costThe reckoning
What happened when the story broke

The bill for "a breach of trust"

US$5B
The FTC's record fine against Facebook (July 2019) for continued privacy violations; among the largest penalties ever assessed by the US government.
US$725M
Facebook's 2022 class action settlement over the breach; on top of the UK ICO's maximum £500,000 penalty.
May 2018
Cambridge Analytica filed for bankruptcy amid the investigations; the same month the EU's GDPR came into force.
The lessons that carry to AI: "free" services extract value through data · third parties can reach far more than you authorised · "anonymised" data can still identify you · and data certified as destroyed kept circulating anyway. Zuckerberg called it a breach of trust and his "personal mistake"; the architecture that made it possible was the business model itself.
ntworld.inkWorkshops05 / 16
THE SHIFTsocial media was the warm-upWhy AI differs
Now add AI to that history

The intimacy problem: you tell AI things you'd never post

Social media

Curated for an audience

Posts are performances; filtered, flattering, meant to be seen. Even so, the harvested profiles were rich enough to swing advertising and politics.

AI conversations

Unfiltered by design

Chats with AI are candid: health concerns, relationship problems, financial difficulties, work conflicts, half-formed thoughts. That's a far more sensitive dataset than any social feed; held by commercial entities, often overseas.

The compounding factor: most AI services process data on US-based servers. Australian Privacy Principles require equivalent protections for overseas transfers, but different jurisdictions grant different access powers (the US CLOUD Act among them); your midnight confession may be subject to laws you've never heard of.
ntworld.inkWorkshops06 / 16
JARGONthree different "memories"Get grounded
The distinction everything else depends on

Context, memory, training: three very different fates for your words

Context window

The conversation's scratchpad

Temporary working memory during a chat, cleared between sessions. The most benign fate; your words are used to answer you, then let go.

Memory features

The account's notebook

Some tools keep persistent memory within your account so future chats know you. Convenient; and a growing dossier that deserves an occasional audit.

Training data

Absorbed into the model

Conversations selected for training become part of future models; persistent and potentially permanent. This is the fate the settings in this session control.

Why the distinction matters: "the AI remembers my chat" and "the company trains on my chat" are entirely different events with entirely different controls; conflating them is how people opt out of the wrong thing.
ntworld.inkWorkshops07 / 16
FINE PRINTdecoding one sentence"Train our models"
Decoding the most important sentence in any AI policy

What "we may use your conversations for training" actually means

·Human eyes: your inputs and the AI's outputs may be reviewed by human contractors; real people, reading your chat.
·Permanent absorption: selected conversations can be incorporated into training datasets; once in the model, your data effectively cannot be fully removed.
·Memorisation: content appearing often enough in training data can be "memorised" and resurface in outputs.
·De-identification is not a guarantee: stripping your name doesn't ensure the content can't be reconstructed or re-linked; if you typed identifying details, they're in the text itself.
And the caveats behind the caveats: opting out of training is not opting out of retention; "deleted" chats can persist in backups; and safety reviews may retain flagged content regardless of your settings. Enterprise and API plans usually carry stronger protections than consumer accounts.
ntworld.inkWorkshops08 / 16
PRACTICALthe four-step auditCheck your settings
The practical heart of this session

The four-step privacy audit for any AI tool

1Find the settings menu: gear icon, profile picture, or "Settings"; privacy controls hide under "Privacy", "Data Controls", "Account Settings" or "Security".
2Find the training toggles: look for "Improve the model", "Help improve [product]", "Use my data for training" or "Chat history"; these are the settings that matter most.
3Check retention: how long are conversations stored? Many platforms allow auto-delete periods or manual history deletion.
4Review third-party sharing: partners, subsidiaries, connected apps and integrations that can see your conversations.
Then diarise it: settings can reset or change with policy updates. A privacy check twice a year is cheap insurance.
ntworld.inkWorkshops09 / 16
PRACTICALthe big threePlatform guide
Platform by platform: the big three

Defaults lean toward data collection; here's where to look

ChatGPT · default ON

OpenAI

Settings → Data Controls → "Improve the model for everyone". "Temporary Chat" mode keeps a conversation out of history and training. Enterprise and Team accounts are excluded from training automatically.

Claude · default ON

Anthropic

Settings → Privacy → "Help improve Claude". Since September 2025 the default is opted in (previously opt-out), and retention runs up to five years regardless of the training toggle. Work, Enterprise and API use is excluded by default.

Gemini · default ON

Google

Gemini Apps Activity in your Google Account. Retention defaults to 18 months (adjustable to 3 or 36, or off); human reviewers may read conversations, and human-reviewed chats are kept up to three years even if you delete your activity.

Settings and defaults as checked in late 2025; menus and policies change frequently. Verify against the current interface before relying on this slide.

ntworld.inkWorkshops10 / 16
PRACTICALthe other threePlatform guide
Platform by platform: the rest

Copilot, Perplexity and Grok: check which version you're on

Copilot · varies

Microsoft

The consumer version strips personal identifiers from training data; Microsoft 365 Copilot keeps data inside your organisation's tenant and out of public model training. Consumer and enterprise settings differ substantially; know which one you're using.

Perplexity · check

Perplexity AI

An AI Data Retention toggle sits in settings, and an anonymous mode covers non-logged-in use. The platform updates frequently; re-check its policies periodically.

Grok · check both

xAI

Settings live within the X platform, and Grok's data handling is tied to X's policies; review both Grok and X privacy settings, since data flows between them.

The pattern across all six: consumer defaults favour collection; enterprise plans favour protection; and the burden of knowing the difference sits, as always, with you.
ntworld.inkWorkshops11 / 16
PRACTICALthe sixty-second habitBefore you type
The checklist to run before any sensitive prompt

The newspaper test, and six friends

·Would I be comfortable if this prompt appeared in a newspaper? If not, reconsider what you're sharing.
·Have I checked my privacy settings and can I strip the identifiers; names, locations, ID numbers, before typing?
·Am I sharing information about other people? Consider whether you have any right to; their consent isn't implied by your convenience.
·Work prompt? Check your organisation's AI policy first; and prefer the enterprise tool, which usually protects data better than your personal account.
·Sensitive query? Use temporary or incognito modes that keep the conversation out of history and training.
ntworld.inkWorkshops12 / 16
HARD RULESno settings make these safeNever enter
The list with no exceptions

Some things never go in the box

Credentials & identity

Keys to accounts and identity

Passwords and security credentials · credit card and bank account numbers · government identifiers: Medicare numbers, Tax File Numbers, passports.

Other people & obligations

Data you hold in trust

Confidential business information without authorisation · personal health information about others · anything classified above OFFICIAL under government frameworks · any data you're legally or contractually obliged to protect.

Why no setting fixes this: opt-outs govern training, not retention, review or breach. Once typed, the information has left your control; the only winning move is not to type it.
ntworld.inkWorkshops13 / 16
AUSTRALIAthe rules on your sideYour rights
The Australian framework, in one slide

Four privacy principles worth knowing by name

APP 1

Open and transparent management

AI providers handling Australians' data must clearly explain how they manage personal information.

APP 6

Use and disclosure

Data shouldn't be used for purposes beyond what you'd reasonably expect when you provided it.

APP 8

Cross-border disclosure

Sending your data overseas requires equivalent protections; directly relevant when your chats live on US servers.

APP 11

Security

Reasonable steps must be taken to protect your information from misuse, interference and loss.

Extra care for NT public servants: the NT Information Act 2002 adds obligations; public sector information generally cannot go to overseas commercial AI platforms without appropriate safeguards, and records management rules apply to AI-generated content used in government business. Complaints about privacy breaches go to the OAIC.
ntworld.inkWorkshops14 / 16
TAKEAWAYthe hour in five linesTakeaways
The takeaway: five habits to keep

Care for your data like it's leaving home; because it is

·Assume the default is collection; every major consumer AI tool ships with training toggles set in the company's favour, not yours.
·Know the three fates; context is temporary, memory is your account's notebook, training is forever; make sure you're adjusting the one you mean.
·Run the four-step audit on every AI tool you use, and re-run it after policy updates.
·Apply the newspaper test before sensitive prompts, and keep the never-enter list absolute.
·History is the teacher; Cambridge Analytica showed what quiet data harvesting becomes at scale. AI conversations are more intimate than anything Facebook ever held; treat them accordingly.
ntworld.inkWorkshops15 / 16
SOURCESwhere this comes fromReferences
Sources used

Where this deck's claims come from

Shoshana Zuboff on surveillance capitalism (the three-step development and "selling certainty"); the 2017 Facebook teen-targeting disclosure as reported at the time; Rohit Chopra's remarks as former CFPB Director
Cambridge Analytica: reporting by The Guardian and The New York Times (March 2018 onward), Christopher Wylie's whistleblower account, the FTC's US$5 billion order (July 2019) and December 2019 Opinion, the UK ICO's £500,000 penalty, and the 2022 US$725 million class action settlement

Prepared August 2026 for the NT World Ink AI Special Topic Workshops. Privacy policies change frequently; always verify settings against the current interface before making decisions about sensitive data.

ntworld.inkWorkshops16 / 16