Generative AI introduces privacy questions that traditional product policies often gloss over.
What happens to the user's prompt?
Is it stored?
Is it sent to a third-party model provider?
Is the output saved?
Is the data used for training?
Can a human see it?
Does the same data flow into analytics and support systems?
A privacy policy does not need to expose proprietary model architecture. It does need to give users an accurate picture of material processing.
Start with the AI data lifecycle
Map:
User input
↓
Application
↓
Prompt construction
↓
AI provider
↓
Model response
↓
Storage / logging
↓
Human or automated action
Every arrow can be a privacy decision.
What to explain
What is collected
Examples:
- Prompts
- Uploaded files
- Conversation history
- Account information
- Usage metadata
Why
Separate purposes.
For example:
We process your prompts to generate requested outputs.
is different from:
We use prompts to improve a general-purpose model.
If the second activity exists, describe it accurately and assess the relevant legal basis.
Who receives it
If an external model provider processes the data, do not write as if the model runs entirely inside your application unless it actually does.
Retention
Explain how long prompts, outputs, logs, or uploads remain, where the policy can reasonably do so.
Human access
If staff review prompts or outputs for abuse detection, support, or quality assurance, say so where required.
AI features create new “secondary use” risk
A feature may begin as:
Generate a summary.
Then the company decides:
Let's use these conversations to train the classifier.
That is a new use that should go through the same privacy review as any other new processing activity.
Do not make “AI improvement” a catch-all purpose for anything your product might do later.
Build the policy from the data flow
A good process is:
AI architecture
→ data inventory
→ purpose analysis
→ vendor review
→ user communication
→ policy
Not:
Policy template
→ make AI section sound modern
Test the policy against the product
Ask:
- Does the policy mention external model providers where relevant?
- Does it describe prompt/file processing accurately?
- Does it distinguish product functionality from model improvement?
- Does it match retention settings?
- Does it explain rights and complaint mechanisms?
Where Privra fits
Privra can identify AI-related processing in your environment and connect it to vendors, data categories, purposes, retention, and user-facing documentation.
The objective is simple:
Users should be able to understand what happens when they put their data into an AI feature.