# The Free-Tier AI Privacy Firewall: A Solo Founder's Data-Safety Checklist (August 2026)

Keep using free AI tools without quietly handing your client data to someone else's training run.

## Why this got sharper in 2026

- The free tier is not a demo any more. Most solo founders now push drafting, research, bookkeeping notes and customer replies through consumer AI accounts. The volume of sensitive text moving through free plans is far higher than it was two years ago.
- Consumer defaults moved in one direction: on. Across the major assistants, personal and free plans generally train on your conversations unless you switch it off, while business, enterprise and API tiers are off by default. The dividing line is the plan type, not the price.
- Paying does not automatically buy privacy. A personal premium subscription usually inherits the consumer data policy. Only the business or workspace product changes the terms.
- Opting out is forward-looking. Turning a toggle off stops future training and usually shortens retention. It does not pull text you already sent back out of a model.

## The five defaults worth memorising

- Training toggles live in different rooms. Roughly: ChatGPT under Settings then Data Controls, Claude under Settings then Privacy, Gemini under Gemini Apps Activity in your Google account, Copilot under profile privacy, Perplexity under Preferences then AI data retention, Grok under privacy on the standalone site.
- Retention differs wildly. One provider's consumer opt-in path can stretch retention to years, while opting out drops it to roughly a month. Another keeps human-reviewed samples far longer than your visible chat history suggests, detached from your account so you cannot delete them yourself.
- Temporary or incognito modes are the fastest safe path for a one-off sensitive prompt. They are usually excluded from training and deleted quickly, at the cost of losing history.
- Thumbs up and thumbs down can override your opt-out. Rating a response often flags that conversation for review even on an opted-out account.
- Assistants embedded in social platforms are the loosest. They run under the platform content licence, which tends to be broad and effectively unopt-outable for anything posted on-platform. Treat them as public.

## Step 1 - The 20 minute settings sweep

Do this once, then stop thinking about it for 90 days.

1. List every AI tool you actually used in the last 30 days. Include browser extensions, note-takers, meeting recorders, and the AI features inside tools you do not think of as AI tools: design, CRM, email, accounting.
2. For each one, open settings and search for the words privacy, data, training, or activity.
3. Switch training off. Screenshot the setting after you change it and drop every screenshot into one folder called ai-privacy-evidence.
4. Write down the retention period the provider states, next to the tool name.
5. Check whether you already pay for a workspace or business plan that covers the same job. If you do, use that login instead of your personal one.
6. Sign out of personal AI accounts on any device you use for client work.

## Step 2 - Classify before you paste

Three buckets. Decide once, not per prompt.

- Green, safe anywhere: published marketing copy, public pricing, blog drafts, generic code with no keys, agendas with no names.
- Amber, anonymise first: financial projections, internal strategy, unreleased product plans, meeting notes containing client names, customer emails. Replace names with Client A, amounts with Unit 1, domains with example.com.
- Red, never in a consumer tier: API keys and credentials, customer personal data, contracts under NDA, health or payment data, anything covered by a data processing agreement you signed.

## Step 3 - Routing rules

- Red work goes only to a no-training path: a business or workspace plan, an API key under a commercial agreement, or a model running locally.
- Amber work goes to an opted-out consumer account, redacted, inside a temporary chat.
- Green work goes anywhere, including free tools you are trialling this week.
- One tool per job. Fewer accounts means fewer settings pages to audit later.

## Step 4 - The redaction habit that costs nothing

Keep a five-line find-and-replace list in a note:

- Client names become Client A, Client B
- Revenue figures become indexed units
- Real email addresses become name@example.com
- API keys become KEY_PLACEHOLDER
- Street addresses and phone numbers get deleted entirely

Paste the redacted version. Nine times out of ten the answer is identical, because the model needs the shape of your problem, not the identity of your customer.

## Step 5 - Four traps people miss

- The meeting recorder. Transcription tools capture the most sensitive conversation you have all week and frequently sit on consumer terms nobody read.
- The browser sidebar extension. It can read the page you are looking at, including an open customer record in your CRM.
- The shared laptop login. One teammate signed into a personal account undoes every setting you changed.
- File uploads and screenshots. Uploading a PDF is exactly the same exposure as pasting its text, but it feels smaller, so people get careless with invoices and contracts.

## Step 6 - The quarterly re-check

Book a 30 minute block every 90 days:

- Re-open each settings page. Providers rename, move, or reset toggles during redesigns.
- Re-read the terms-change email you archived without opening.
- Delete accounts for tools you stopped using. A dormant account holding your data is pure downside.
- Refresh the screenshots in your evidence folder.

## If you think something already leaked

- Rotate credentials first. Any key that touched a chat window is burned.
- Delete the conversation, then request account-level deletion if the provider offers it.
- Log the date, the tool, and what was exposed. If a client contract requires notification, notify early and plainly.
- Do not assume deletion equals removal from a trained model. Assume it is out there and manage the consequence instead.

## How to use

Block 60 minutes this week. Spend the first 20 on Step 1, the next 15 writing your green, amber and red lists into one note, and the last 25 building the redaction list and doing a practice run on a real task. Then create a recurring calendar event, every 90 days, titled AI privacy re-check, and paste this document into the event notes.

Carry two rules forward. First, the plan type decides the policy, so never assume a personal upgrade protects you. Second, the billboard test: if seeing that text on a billboard outside your best client's office would hurt, it does not belong in a consumer AI tool.

Verify every setting yourself before relying on it. These policies changed repeatedly over the last twelve months, and they will change again.