🦆 Welcome

A few years ago we were on a cruise, and someone handed my son a little yellow rubber duck. Turns out this is a whole thing. Cruising Ducks. The duck comes with a tag. You join the Facebook group, you post where you found it, and on your next cruise you hide it for someone else to find.

I loved it. That duck had a tag on it. Every single person who picked it up knew they were joining a chain.

The things you type into AI travel the same way. The only thing is, nobody hands you the tag. And there's no Facebook group where you can watch where it went.

🤯  WAIT, WHAT?

The waiter forgets you. The ticket doesn't.

Imagine you're at a restaurant.

You order. The waiter writes it down, the ticket goes to the kitchen, and you get your food. But the ticket he wrote has a whole life after you leave.

That order ticket is your AI chat.

The waiter is the model. It reads your message, answers, and moves on to the next customer. It is not building a file on you.

The ticket is what travels. Your AI chat makes nine stops, and here they are.

1. It leaves your computer sealed. Nobody in between can read it.
2. It becomes a record. Logged with your account and the time.
3. The model answers, then forgets you. It is not adding you to a file.
4. A scanner checks it. Automated, looking for serious harm. Most chats pass straight through.
5. Sometimes a person reads it. Reviewers rate real conversations so the answers get better.
6. Memory keeps notes on you. A short file of facts, pulled out of your chats.
7. You delete it. Gone from your side right away, off their systems within 30 days.
8. It trains the next model. Your words help build the next version, unless you say no.
9. The side doors. Share links, the thumbs, browser extensions, your employer.

Now, you've never worried about a manager reading your restaurant order. A white wine, salmon with a side of rice. Who cares if that's public. Read away.

Your AI chat is a different ticket. Somewhere in there is the thing you asked about your kid. The contract you pasted at 11pm. The email you needed help writing because you were too angry to write it yourself.

Same ticket. Different order.

Good news. Three of those nine stops have a switch on them, and you can flip all three tonight.

Memory. The training toggle. And the share button, which is the one that gets everybody, because it does not send a chat to a friend. It makes a web page public.

⚡  TRY IT TONIGHT

Change three settings tonight. The fourth one isn't a setting.

1. The share button

Every time you hit share on a chat, you create a live web page. Anyone who has that link can open it with no account and no login. This summer people started finding shared chats from both ChatGPT and Claude sitting in Google results, which is how most of us learned what that button actually does.

So go look at yours. In Claude it's Settings, then Privacy, then Shared Chats. In ChatGPT it's Settings, then Data controls, then Shared links, then Manage.

You might find a chat you dropped into a Slack thread two years ago, a cover letter, a question about a doctor's appointment. Delete anything you wouldn't post.

I should say that deleting a link only closes the door going forward, and it won't reach into someone's bookmarks and pull back a copy they already saved. Do it anyway, and do it tonight.

2. What it remembers

Open a new chat and paste this in:

❝

What do you remember about me? List everything you have stored, and tell me where each piece came from.

The first few will be obvious. Keep reading until you hit one you don't remember ever saying out loud.

You can edit or clear any of it in Claude under Settings, then Memory, and in ChatGPT under Settings, then Personalization, then Memory.

3. The training toggle

This one takes ten seconds, and it decides whether your chats join the pile that teaches the next model. In Claude you'll find it under Settings, then Privacy, then Help improve our AI models. In ChatGPT it's under Settings, then Data controls.

Turning it off works going forward, so whatever is already in the pile stays in the pile. That's not a reason to skip it, it's a reason to do it tonight instead of next year.

4. The thumbs

This is the one I didn't know, and it's why I saved it for last.

That little thumbs up 👍🏼 and thumbs 👎🏻 down under every answer isn't a rating. It's a door. Both companies say that when you leave feedback, the whole conversation attached to it can be used to train the model, and OpenAI spells out that this holds even if you turned off the setting in number three. Anthropic's own retention page adds the part that made me sit up. Feedback submissions are kept for five years.

I’m not telling you never to give feedback. But if you wouldn't want that particular conversation read closely by a stranger, leave the thumbs alone.

💬 YOU ASKED

What if I work with people's personal information?

Start with the question I ask myself first. Do you actually need the name? "Summarize the risks in this contract" works exactly the same whether the client is Bianca Rossi or Client A. Strip the names, the numbers, the addresses, and most of the problem is gone before you touch a single setting.

If you truly can't strip it, use your company's paid work account, or run a model that lives on your own computer so nothing leaves the machine at all. And if you handle health records, legal files, or anything regulated, your organization already has a rule about this, and that rule outranks every setting in this issue. Go find out what it says.

📱  THIS WEEK IN AI

Good Stuff From Around the Internet

🧠 Hundreds of people were hired to read ChatGPT conversations 404 Media reported that OpenAI has brought on hundreds of contractors to read real user chats and score them, under a program called Project Lily. OpenAI says it strips personal details out first, and admits that doesn't always work. → Read it here

☎️ A mathematician solved a million-dollar problem, and then watched someone else publish it Tristan Buckmaster at NYU spent a year on Navier-Stokes, one of seven problems with a million-dollar prize attached, working through an AI subscription he paid for himself. He had his answer on August 15. OpenAI published its own solution on September 8 and now the two sides are arguing about how that happened. OpenAI says nobody read his chats, and there's no evidence yet that anyone did. What OpenAI does confirm is that it learns from de-identified user data, and in its own words, stripping a name off something does not strip out the idea inside it.. → Read it here

📱 OpenAI's newest model can use your computer. GPT-6, which OpenAI calls Astra, started reaching paid accounts this month. The headline feature isn't that it answers better. It's that it operates things. It moves through spreadsheets, fills in forms and clicks around web pages for you, and OpenAI says it does all of that faster than a person can. It's useful, and it also changes the question this whole issue is built on. Until now the thing to think about was what you type in. Once a model is driving, the thing to think about is what it can see while it works.. → Read it here

🌟  BEFORE YOU CLOSE THIS TAB

Use It Anyway

Our duck is out there somewhere and I'm fine with that, because we knew it had a tag on it when we handed it over.

None of this is about using AI less. I'm not slowing down. It's about knowing which of your chats have a tag before you hand one over.

Most of what's in this issue I learned from Ruben Hassid, who followed a single prompt through every stop it makes and published the whole route earlier this month. If you want the long version with all nine stops, his piece is worth your time.

Now the ask. Share this issue with someone, the more we know about privacy the better off we will all be.

Your unfair advantage, one week at a time.

Got a question, a topic request, or just want to say hi? Just reply to this email. I read everyone.