What AI Knows About You — And What Protects You
- M. Wang
- Jun 29
- 3 min read

(Hint: Less Than You Think)
If you've ever hesitated before typing something personal into an AI chatbot, that instinct deserves respect. Not because AI is dangerous in the way science fiction imagines, but because the protections most of us assume exist often don't.
This is worth understanding clearly, especially if you're someone who already navigates sensitive information carefully in your professional or personal life.
The HIPAA Assumption
Many people assume that privacy protections follow them wherever they go online. They don't.
HIPAA — the Health Insurance Portability and Accountability Act — protects your medical information when it's handled by healthcare providers, insurers, and their direct partners. It was designed for a world of medical records and insurance claims. It was not designed for a world where someone types their anxiety symptoms into a chatbot at midnight.
When you share personal health information with an AI platform, HIPAA almost certainly does not apply. The AI company is not your healthcare provider. Your conversation is governed by their terms of service — a document almost nobody reads — not by federal health privacy law.
That gap is real and it matters.
What AI Platforms Actually Do With Your Conversations
Most major AI platforms, including ChatGPT, Claude, Gemini, etc., are transparent that conversations may be used to improve future versions of their models. This is how AI gets better over time — it learns from real human interactions.
For general consumer use, this typically means:
Conversations may be reviewed and used for training
You can often opt out in privacy settings, but the default may not protect you
Anonymization processes exist but vary in thoroughness
Data is retained for periods that aren't always clearly communicated
This is meaningfully different from telling something to your doctor, your therapist, or even a trusted friend. Those conversations carry legal and ethical protections built over decades. AI conversations largely do not — yet.
What This Doesn't Mean
This is not an argument to avoid AI. It's an argument to use it with the same awareness you'd bring to any tool.
You wouldn’t take medical advice from a random YouTube video and act on it without checking it against other sources first. (Many people already do, of course — which is part of why this matters.) AI deserves the same instinct. The question isn’t whether to engage with these tools. It’s whether you understand what they can do, what they can’t, and what happens to what you tell them.
Some practical awareness helps:
Be thoughtful about specifics; There's a difference between asking an AI to help you understand anxiety in general versus sharing detailed personal history. The former is low risk. The latter deserves more consideration.
Check privacy settings: Most platforms offer opt-out options for training data use. They're usually not prominently displayed, but they exist.
Understand the context: AI used within a healthcare system, by a licensed provider, under a business agreement — that's a different situation with different protections than a general consumer chatbot.
The Larger Point
We are at an early moment in AI development where the technology has moved faster than the regulations designed to protect people who use it. The frameworks — legal, ethical, institutional — are still catching up.
That's not unique to AI. It happened with social media, with smartphones, with the internet itself. Protections eventually develop. They tend to arrive after enough people understand what they're navigating.
Understanding it now — clearly, without either panic or naivety — is genuinely useful. It lets you make informed choices rather than either avoiding tools that could help you, or sharing more than you'd consciously choose to.
Awareness isn't anxiety. It's just good navigation.
This blog is for informational and educational purposes only and does not constitute medical or clinical advice, diagnosis, or treatment. Use of this site does not establish a therapist-client relationship. The information provided is not a substitute for professional care. If you are experiencing a mental health emergency or are in crisis, please call or text 988 or go to the nearest emergency room immediately.


Comments