Where Your Words Go
Tessa is halfway through pasting the next batch of guest reviews when a colleague leans over and asks the question this chapter exists to answer: "Wait — where does all that actually go?" She does not have an answer. She has been putting Waymark's material into that box for five chapters, and she has never once thought about the trip it takes.
It is a fair question with an honest answer, and the answer is neither a scandal nor nothing. The text leaves the building. It travels over the internet to the provider's computers — the arrangement from Chapter 1, where the model runs on someone else's machines — it is processed there to produce the reply, and then, in most cases, it stays somewhere for a while. That is the fact worth having before the next paste, and this page is that fact in full.
What Happens to a Paste?
Follow one paragraph of text through. Tessa presses Enter; her words travel across the internet to the provider's servers; the model reads them and assembles an answer; the answer travels back and appears on her screen. That much she could have guessed. The part she has not thought about is what is left behind at the far end.
Usually two kinds of copy. The obvious one is the chat history — the conversation sitting in the sidebar, which exists because a copy of everything she typed is stored on the provider's side and handed back to her when she reopens it. The less obvious one is logs: the ordinary records a service keeps of what it processed, kept for debugging, for detecting abuse, and for billing. A log is just a running record of what a system did, and every online service keeps them. She cannot see those, and neither can most of the provider's own staff.
None of that is sinister — it is how online services work, and her email provider does the same. What matters is the sentence that "it's just a chat box" quietly hides: pasting text into that box is sending company material to another company. Once that sentence is in her head, the rest of the chapter is common sense.
The Three Questions That Matter
Nobody needs to read a full legal policy to know where they stand. Three questions cover almost all of it, and providers answer all three in writing.
First: is my text kept, and for how long? Some services hold conversations until you delete them; some hold them for a fixed number of days and then discard them; some keep a shorter, stripped-down record for abuse checks after the conversation itself is gone.
Second: is my text used to train future models? Training is the process that builds a model in the first place, out of enormous amounts of text — the subject of a different book on this shelf. If your conversations are added to that pile, they can influence what later versions of the model produce. Some providers do this by default, some never do it, and many let you turn it off.
Third: who at the provider can see it? Machines process every conversation; people sometimes read samples of them — for quality checks, for investigating a reported problem, for catching abuse. "A person may read a sample of this" is a different feeling from "a machine handled it", and it is worth knowing which one applies.
The important part is not any particular answer. It is that the answers genuinely differ — by provider, by plan, and sometimes by a setting Tessa can flip herself. So "the AI keeps everything forever" and "nothing is stored" are both guesses, and both are wrong about somebody.
Settings and Plans Change the Answer
Many products carry a switch worded roughly "don't use my conversations to improve the model". Flipping it answers the second question, and what it does to the first varies by product: some carry on storing your history exactly as before, while with others the same switch also shortens how long conversations are kept — from months down to a few days. What it never means is that nothing is kept. Turning off training is not turning off retention, and reading the switch as "now nothing is stored" is the most common mistake people make with it.
Plans matter at least as much. Business and company accounts typically come with stronger commitments than free personal ones — retention the company itself controls, no training on customer text, and promises written into a contract rather than a policy page that can change. The same product can therefore handle two conversations under two different sets of rules, depending on which account they were typed into. Knowing which account Tessa is signed in to is knowing which promises apply to her pastes, and it is not a detail she can assume from the logo on the page.
Both live in dull, findable places: a privacy or data-controls page in the product's settings, and a policy page on the provider's site. Ten minutes, once per tool.
Calibration, Not Alarm
Think of the difference between talking in a hotel lobby and talking in your own kitchen. Nobody in the lobby is spying on you. But you are audibly in someone else's building, staff walk past, and there may be a camera in the corner — so you talk about the weather there and save the family finances for home. Not fear; calibration. That is the right posture for the chat box.
For the public brochure copy Tessa was polishing in Chapter 2, none of this matters at all. That text is going on Waymark's website next week; a copy of it sitting in a provider's logs changes nothing. For a guest's booking details, every one of the three questions matters, and matters immediately.
Which means the useful skill is not "use less AI". It is telling those two cases apart, reliably, at speed, on a Thursday afternoon. The next page draws that line item by item. This page's job was smaller and comes first: when someone asks Tessa where her words go, she now has a real answer instead of a shrug.
- "The chat is private, like my notes app." A notes app on your own machine keeps its text on your machine. A chat box transmits it to another company, which processes it and typically retains it under their policy, on their timetable, not yours.
- "Everything I paste is training the AI." It depends on the provider, the plan, and a setting that is often yours to change. It is a thing to check rather than assume — and assuming the safe-sounding direction is just as wrong as assuming the scary one.
- "Deleting the chat deletes everything." Deleting removes your view of the conversation. What remains on the provider's side, and for how long, follows their retention policy — which is exactly why the first of the three questions is worth asking before the paste, not after.
- "The provider promises privacy, so I am covered." Promises live in a policy and in the plan you are actually on, not in a slogan on the home page. The same product routinely offers weaker terms on a free personal account than on the company one.
- Every paste is a small data-handling decision. Making it knowingly, rather than by habit, is the whole difference between casual use and professional use of these tools.
- The three questions are portable. They work on any AI product Waymark ever considers, including ones that do not exist yet — which is more than can be said for advice about any particular tool.
Knowledge Check
Tessa pastes a paragraph of guest reviews into the chat box. What does this page say happens to that text?
- The browser runs the model locally, so the reviews never leave Tessa's own machine
- It travels to the provider, is processed there, and usually stays behind in some form
- It is deleted by the provider the instant the answer has been sent back to her screen
- It is added to the pile of text used to train the next model, in every product
Which set of questions does this page recommend asking about any AI product before trusting it with work material?
- How large the model is, how fast it answers, and how much the paid plan costs each month
- What its knowledge cutoff is, how big its window is, and whether it can search the web
- Whether the text is kept and for how long, whether it trains future models, and who can read it
- Which security certifications the provider holds, and which country its head office is in
Tessa turns on the setting labelled "don't use my conversations to improve the model". What has changed?
- Her text should stop feeding future training, though something is still being kept
- Nothing is stored on the provider's side any more, so retention is no longer a question
- Her free account now carries the same contractual promises that a business plan does
- The conversation is processed on her computer instead of being sent across the internet
A colleague deletes a chat that contained sensitive material and says the problem is handled. Is it?
- Yes — deleting a conversation removes every copy of it from the provider's systems
- No — the delete button changes nothing at all, since providers ignore deletion requests
- Yes — provided the training setting is switched off immediately after the deletion
- Not really — it removes her view, while provider-side retention follows their own policy
You got correct