Your AI Tool Kept Your Emails After You Disconnected It
OpenAI, Anthropic, and a personal AI assistant called Instinct just gave three different answers to what happens to your data after a conversation ends. Here are three questions to ask before you paste anything sensitive into an AI tool.
By Patin Team · Examples are illustrative composites
Before you connect an AI tool to anything sensitive, "disconnect" and "delete" are two different promises, and most people only check the first one. This week gave professionals a live example of why that gap matters, and two vendors just published very different answers to what happens to your data once a conversation ends.
What happened
On August 23, researcher Claire Vo found that the personal AI assistant Instinct kept full copies of users' emails even after they disconnected their Google accounts. Revoking access stopped Instinct from reading new mail. It did nothing to the mail it had already synced. Instinct shipped a deletion tool overnight, but the finding stood: turning off a connection is not the same as erasing what the connection already copied.
The same week, the two largest AI vendors drew that line differently on purpose. OpenAI announced Zero Data Retention for its frontier API models on August 20 — prompts and responses are deleted the moment a request completes, and the company says no human at OpenAI can see them. Anthropic went the other way on August 21: its enterprise policy keeps a 30-day monitoring window, but the data itself now lives in each customer's own cloud infrastructure rather than on Anthropic's servers, a change built with input from more than 100 regulated-industry customers.
Neither approach is wrong. They're answering different questions. OpenAI's promise is about duration — how long anything is kept. Anthropic's is about location — whose infrastructure it sits on while it's kept. A professional evaluating either vendor needs to know which question they're actually asking, because "your data is deleted" and "your data never leaves your building" are not the same guarantee, and a vendor can offer one without the other.
What to do differently
Before you paste anything sensitive into an AI tool — client names, financial figures, unreleased plans — get three specific answers from the vendor, not a general privacy-policy skim:
- What do you keep, and for how long? A 30-day retention window and zero retention are both legitimate answers. "We don't really specify" is not.
- Where does it sit? Your infrastructure, the vendor's servers, or a third party's. This is a separate question from how long it's kept — a vendor can answer one well and dodge the other.
- What happens to data already synced if I revoke access? This is the one Instinct failed. A disconnect button that only stops future access, without touching what's already copied, is a gap worth finding before you use the tool for anything you'd regret being retained.
Worked example: the ops manager evaluating a new tool
Priya runs operations at a 60-person logistics company and is deciding whether to connect a new AI scheduling assistant to the team's shared calendar and email. The vendor's marketing page says "enterprise-grade security" and nothing more specific. Instead of taking that at face value, she asks support directly: how long is calendar data retained, where does it live, and if she disconnects the tool in six months, does it delete what it already read or just stop reading new events? The vendor's answer to the third question — a vague "we'll look into removing that" — is what she uses to decide, not the marketing copy.
Second example: the freelancer with client contracts
Marcus is a freelance copywriter who wants to use an AI tool to draft client emails and needs to know whether pasting a client's unreleased product brief into that tool creates a problem he can't undo. He isn't evaluating a vendor for a whole company — he's making a one-person decision about a single paste. The same three questions apply at a smaller scale: does this specific plan retain the brief, where does that copy sit, and if he stops using the tool next month, is the brief gone or just inaccessible to him.
The takeaway
"I disconnected it" is a claim about access, not a claim about deletion, and this week made the difference between them concrete enough to check before you connect anything else.
Put this into practice
Reading is a start — but skill comes from doing. Try these drills now.
Reading about it only gets you so far
Patin turns this into five-minute drills that score what you write and tell you why. It's in closed beta — join the waitlist and we'll email you when your cohort opens.
Just want the writing? .
Keep reading on this
Your ChatGPT Privacy Toggle May Have Reset. You Won't Get a Warning.
Users are reporting that ChatGPT's opt-out from training reverts to 'on' after app updates, with no notice. Here's what to check today, and why the toggle was never the whole story.
4 min readWhat Actually Happens to Your Data Inside an AI Tool
Three separate incidents this year — a disconnected assistant that kept synced email, a SaaS vendor training AI on tickets by default, a PII filter that misses deal terms — reduce to the same four questions. Here's the one-time audit that answers all of them.
4 min readThere's Now a Free Tool That Strips PII Before Your AI Sees It. Here's When to Use It.
OpenAI released a free, on-device model that catches personally identifiable information before text reaches any server. 96% accuracy across 8 categories — and the 4% it misses is where your judgment still matters.
4 min read