Reportman.AI Logo Reportman.AI

← All articles

Artificial intelligence: how much is your data privacy worth?

· Toni Martir, arquitecto de software

The first question everybody asks before putting AI to work is how much it costs per month. And some assistants cost nothing, so the question is treated as answered and everyone moves on.

But they do have a price. It is not paid in euros, and it is written in the one document nobody opens: in exchange for the service, the provider keeps everything you type.

An assistant's text box; the typed line runs out of the box, crosses the edge of your network and piles up on the other side as stacked copies.
What you type into the box does not stay in the box.

The price, written by whoever collects it

The Gemini Apps Privacy Notice hides nothing. It says saved activity is used to improve Google services, «including to train generative AI models». It says human reviewers read, annotate and process some conversations. And it says reviewed conversations are kept for up to three years, held apart from your account — which is exactly why deleting your activity does not delete them: «are not deleted when you delete your activity».

It sums the whole thing up in one sentence that ought to be enough: «Don't enter anything you wouldn't want a reviewer to see».

There is no trick: the deal is published and coherent. The problem is that it gets accepted without being read, and at work, with information that is not ours to give.

What you hand over is not a datum, it is a context

For an AI to help with your actual job, one piece of data is not enough: it needs context. You have to tell it what your tables are called, what you measure, how you invoice, what counts as a good customer. That is not a loose personal detail you can black out: it is a description of your business.

And it has an awkward property: it cannot be anonymised. Generalise it to protect it and the answer stops being useful. Which is why the Spanish data protection authority's advice to the public — don't share personal data, «describe a fictitious case», don't reveal an organisation's confidential data — helps you ask about a procedure, but not work with your real data.

The three currencies

What privacy is paid with

With your data Zero euros. They train on what you type, and they keep it
Free in money
With a contract The provider commits in writing not to train on your data
Published price
With a machine of your own The model stays inside your network and nothing leaves
No subscription

All three are real. Only the contract gets advertised.

The contract one has a list price, and it is set by the same company: the Google Cloud Service Specific Terms, section 18, state that «Google will not use Customer Data to train or fine-tune any AI/ML models without Customer's prior permission or instruction». Same provider, two opposite deals. The difference is not the model: it is the clause. What you are buying is not intelligence, it is a contract.

And that is the mistake you see most in an office: using the consumer interface — gemini.google.com or the phone app — for company work, assuming the Cloud terms apply. They do not, not even if you pay: the Gemini notice explicitly covers anyone with «a paid subscription to a Google AI plan», and the section 18 clause governs only what goes in through Vertex AI or the API. (With a work or school account a third set of terms applies, Workspace's.)

The machine-of-your-own one is the one almost nobody advertises, and that is no accident: it does not suit whoever makes a living renting out the model. A model installed on your own computer sends nothing anywhere: it asks for an up-front investment instead of a monthly fee, and is usually slower; in exchange it is the only one of the three that lets you use your real data knowing it never leaves the building.

So how much is it worth?

It is worth whatever you decide to pay, and you pick the currency from those three. The catch is that if you don't pick, you are already paying with your data.

So the useful question is not how much your data privacy is worth. It is: this thing I am about to type into the box — what am I paying for it with?


At Reportman AI we build on the machine of your own: the copilot can work with a model installed inside your network, through the Agent, with no subscription — you supply the machine — and if you prefer the contract there are plans with models already tested. What applies in each case is written in our own privacy notice, which I invite you to read with the same suspicion you just read Google's with: «When using the "Local AI" engine, natural language processing, database schemas, and the resulting data never leave the user's device». Both routes are tried out from the same download.

Sources

Toni Martir, arquitecto de software · · sources checked on