AI privacy checklist: 10 checks to test an AI tool in an hour

Workspace with laptop, phone, and privacy checklist, stylized AI motifs

When you consider adopting an AI app—chatbot, editor, image tool, or assistant—you don’t need to be a security engineer to check whether it respects your privacy. This guide gives a focused, non-technical AI privacy checklist you can run in about an hour. Each check includes what to do, an example of a safe vs. risky result, and quick next steps if something looks wrong.

The 10 quick tests (one-hour AI privacy checklist)

Work through these in order. A single person can complete most of them in 5–10 minutes each.

Test 1 — What does the app ask for during signup?

Action: Start a trial or create an account. Note required fields and permissions (email, phone, calendar, contacts, storage, microphone, camera).

Safe result: Only necessary information is requested (email, optional profile). Permissions are optional and explained.

Risky result: The app requests account-wide access to other services, full contact lists, or broad storage/camera permissions without clear justification.

Test 2 — Scan the privacy policy for five keywords

Action: Use the site’s privacy policy. Search for: “retention,” “share,” “training,” “delete,” and “encryption.” If a searchable policy isn’t available, note that lack of transparency.

Safe result: Clear statements that user data can be deleted, describes retention period, says uploads won’t be used to train models without opt-in, and describes encryption in transit.

Risky result: Vague language like “we may use data” without limits, no deletion path, or no mention of training or retention.

Test 3 — Try a dummy personal data upload

Action: Create a harmless dummy file that looks like personal data (e.g., “John Test, SSN 000-00-0000, DOB 01/01/1990”). Upload it to the tool or paste it into the chat, then request confirmation of how it was used (“Did you store or use this for training?”).

Safe result: The tool either refuses to accept personal data, returns a clear statement that the content won’t be used to train models or shows a transient-only response and offers deletion.

Risky result: No clear answer, or the tool reuses the content in subsequent prompts or stored files without offering an option to delete.

Test 4 — Check data deletion and export paths

Action: Look for account settings to download or delete data. If not visible, ask support with a simple message: “How can I export my data? How do I permanently delete my account and content?”

Safe result: A clear export tool and a one-click or documented deletion procedure, ideally with a confirmation email and timeline.

Risky result: No clear method, or support says deletion is manual or may take an unspecified, long time.

Test 5 — Inspect integrations and connected apps

Action: If the tool asks to connect to Google, Slack, or a password manager, inspect the OAuth scopes shown during sign-in and list the integrations in settings.

Safe result: Scopes are narrow (e.g., read-only email metadata, file access limited to a specific folder) and integrations are optional.

Risky result: Wide scopes like full mailbox access, full drive access, or permanent “manage your data” permissions for third parties.

Test 6 — App permissions on mobile and browser

Action: On mobile, review app permissions (camera, mic, contacts). In a browser, check if the site requests camera/microphone or filesystem access, and whether those are used right away.

Safe result: Permissions are requested at the moment they’re needed, with an explanation for why.

Risky result: Persistent background permissions, or the app requests camera/microphone access at install with no explanation.

Test 7 — Probe with simple support questions

Action: Send support or the chatbot three direct questions: “Do you retain user content? For how long? Do you use content to improve models?” Note if responses are fast, detailed, and consistent.

Safe result: Clear, consistent answers with links to policy sections and an option to opt out of training.

Risky result: Generic or evasive replies, long delays, or redirects that don’t answer retention or training questions.

Test 8 — Find signaled compliance and external attestations

Action: Look for certifications or compliance notes (e.g., GDPR statements, SOC reports, enterprise data handling). Check an app store privacy label if available.

Safe result: Documentation of relevant compliance measures, or a clear explanation for small teams without formal certification.

Risky result: No mention at all and vague claims like “we comply with laws” without specifics.

Test 9 — Try a follow-up prompt to test data reuse

Action: After uploading or submitting text, start a new session and ask the AI to summarize your earlier upload or to find it in “my uploads.” Watch whether the tool can retrieve it without an obvious file link.

Safe result: The new session can’t access prior content unless you explicitly attach a file or reference and grant access.

Risky result: The tool references prior content from past sessions without explicit linking, showing persistent storage tied to your account.

Test 10 — Confirm billing and account recovery practices

Action: Review billing settings, who receives invoices, and how account access recovery works (SSO, password reset). Note if backups or logs may be accessible by third parties.

Safe result: Clear billing owner, SSO options for teams, and multi-factor authentication recommended or required.

Risky result: Billing tied to personal emails for team accounts, weak recovery options, or no MFA support.

What to ask vendors (short, precise questions)

  • “Do you use customer content to train models by default? If yes, how can my account opt out?”
  • “How long do you retain uploaded content and logs? Please describe retention timelines.”
  • “What encryption do you use in transit and at rest?”
  • “How can we export and permanently delete our data?”
  • “Which third parties can access our data and under what terms?”
  • “Do you publish data access logs or provide audit exports for enterprise accounts?”

Tip: Ask for answers in writing. A written response can be pasted into your vendor questionnaire or legal review.

Quick browser & mobile checks non-technical users can run

  • App store privacy labels: On iOS/Android app pages, review the privacy label summary for data types collected.
  • Browser permissions: Click the padlock icon next to the URL to inspect camera/microphone and location permissions.
  • OAuth screens: When signing in with Google/Microsoft, read the permission list carefully. Deny broad permissions and look for “limit access” options.
  • Use a new account: If unsure, create a free test account using a dedicated email and minimal permissions to isolate test results.

Sample prompts to probe the AI and support

Copy these when talking to chatbots, sales, or support:

  • “Please describe, in one sentence, whether you use my content to train models. If yes, how can I opt out?”
  • “Where can I download everything my account has uploaded? Provide the steps.”
  • “What data does your service store for 90 days vs. permanently?”
  • “List third-party subprocessors with access to customer content.”

Sample results and what to do next

If results look safe: Save vendor answers, capture screenshots of settings, and add the tool to your internal inventory with notes about retention and opt-outs.

If you find risks: Ask the vendor for written remediation timelines. For critical risks (full mailbox access, no deletion path, or unclear training policies), avoid connecting sensitive accounts until resolved or use an alternative that supports local processing or enterprise controls.

One-page takeaway checklist for teams (printable)

  • Account permissions: minimal and justified
  • Privacy policy: retention, training, delete/export paths
  • Dummy upload test: tool refuses or offers deletion
  • Integrations: OAuth scopes narrow and optional
  • Mobile/browser permissions used only when needed
  • Support answers: written, consistent, link to policy
  • Compliance signals: documented or explained
  • MFA and clear billing ownership

Limitations of this checklist

This checklist is a practical screening tool for non-technical decision makers. It reduces risk but doesn’t replace an engineer-led security audit or legal review when handling regulated data. Vendors can change policies and interfaces; answers you receive may be inconsistent. Some risks—hidden data sharing or subtle training uses—may only be found in formal audits, contract clauses, or independent third-party attestations.

Conclusion

An AI privacy checklist doesn’t need specialized tools or deep technical expertise. In about an hour you can learn how an AI tool handles signups, permissions, uploads, retention, and integrations. Use the tests, save written vendor responses, and prioritize tools that offer explicit deletion, narrow OAuth scopes, and an opt-out for model training. For sensitive or regulated data, treat this checklist as the first step and plan a technical review before full rollout.

FAQ

How long will this checklist take to run?

About 45–75 minutes. Most checks take 5–10 minutes. If a vendor requires a formal response, follow-up may take longer.

Can a vendor’s written answer be trusted?

A written answer is better than none, but it isn’t proof. Prefer vendors who document policies publicly, offer export/delete tools, and can provide compliance reports or contractual guarantees.

What if the tool offers a local or on-device option?

Local/on-device processing reduces many risks because data stays on the device. Still verify whether uploads, backups, or optional cloud features are disabled and check how updates are handled.

Should small businesses require an audit for every AI vendor?

Not always. Use this checklist first. For tools handling regulated data or core business secrets, require an independent audit, SOC reports, or contractual data protection clauses before full adoption.