AI Privacy Policy Checklist: Evaluate Any Assistant in 20 Minutes

Privacy policies are tedious because vendors want you to quit reading. This checklist turns policy archaeology into a repeatable gate before paste.

By Updated Topic: AI privacy policy checklist
Checklist clipboard next to an AI privacy policy document
Checklist clipboard next to an AI privacy policy document

Key takeaway: Privacy policies are tedious because vendors want you to quit reading. This checklist turns policy archaeology into a repeatable gate before paste.

Start a private Secrypt chat

Why checklists beat vibes

AI privacy policy checklists turn vague discomfort into auditable questions. Vibes do not survive procurement, litigation, or board review — checklists do. Photocopy the completed checklist into your vendor binder so future you remembers what you relied on. Start every evaluation with the same sections: training, retention, access, security claims, business model, API clauses, and incidents.

Consistency lets you compare Secrypt to suite AI without rewriting the rubric each time. Default to skepticism when a vendor omits a training sentence entirely. A negative finding is still a finding worth documenting before you paste proprietary data. Store completed checklists with vendor version dates in your procurement drive.

When litigation asks what you knew in March, vibes evaporate but PDFs with timestamps persist. Archive vendor PDFs alongside your scored checklist so procurement can diff policy versions without re-reading marketing sites from scratch.

Section 1: Training and improvement

Look for an explicit statement that conversation content is excluded from foundation model training and ad profiling. Watch for “improve services” language without scope. That phrase has swallowed entire prompt libraries on other platforms when legal did not read the footnotes.

Note whether API traffic follows the same training rules as chat. Developers paste more secrets — split policies are a red flag unless explained. Ask whether evaluation or abuse datasets include customer content even when foundation training excludes it.

Some vendors train on chats indirectly through human review pipelines labeled as safety. If human reviewers label chats for safety, ask whether your enterprise prompts could appear in those queues even when foundation training is off.

  • Chats excluded from training?
  • Uploads excluded?
  • API traffic excluded?
  • Opt-out required or default off training?

Section 2: Retention and deletion

Ask what is stored, for how long, and whether delete is self-serve. Secrypt offers export and clear in Settings; Ghost mode limits ordinary history accumulation. Backup deletion timing may not be instant — honest vendors say so. Request a sample deletion support ticket ID when vendors claim enterprise delete workflows.

Process proof beats adjectives in RFP responses. Separate retention from training in your notes. A product can avoid training while still keeping logs you do not want sitting in a sidebar. Request average time-to-delete for support-initiated erasure versus self-serve clear.

Gap between UI promise and ticket workflow is a common enterprise finding. Self-serve clear should be tested on a sandbox account quarterly — demos in sales calls are not evidence for your auditor.

Section 3: Access and subprocessors

List who can access prompts internally and for what purpose — abuse review, billing, support. Subprocessor lists should name entities and link to their terms. Have procurement subscribe to subprocessor update emails.

Silent additions break compliance drift when nobody reads the changelog. Ask whether encrypted history means encrypted at rest only. Clarify that inference still requires reading prompts — marketing shorthand confuses buyers.

Map each subprocessor to the data categories you paste — chat text, uploads, metadata, billing. Secrypt subprocessors should be read alongside your own logging vendors. Require notification emails for subprocessor changes to hit a distribution list, not a single engineer who might be on vacation.

ItemPass signalFail signal
Subprocessor listNamed vendors“Partners” handwave
Employee accessLimited rolesUndefined
Government requestsTransparency report or clauseSilence
Workspace admin snoopingDocumentedUnknown

Section 4: Security claims

Challenge end-to-end encryption claims unless keys are client-held. Secrypt encrypted history protects stored copies at rest; it is not E2EE inference from laptop to model weights. Architecture calls should ask where prompts decrypt.

Silence goes in the risk register with an owner and review date. ” Transit encryption is table stakes, not a custody model. Challenge any E2EE label unless client-held keys are documented.

Secrypt encrypted history is at-rest protection for stored copies — accurate language prevents false confidence. Pen testers should verify what employees can export after clear — user experience and policy language must match.

Section 5: Pricing and data business model

Read how the vendor makes money. Subscription plus prepaid API credits is easier to reason about than ad-funded free tiers that monetize attention. Secrypt lists Free, Pro $5/mo, and Unlimited $10/mo openly.

Cipher charges $0.01 per request after daily allowances — no hidden token surprise if you read the pricing page. Flag ad-funded free AI for extra scrutiny. Default red until someone explains how messages might influence profiling or recommendations.

If the product is free without subscription, ask what the monetization lever is. Secrypt’s visible Free, Pro $5, Unlimited $10, and API credits model is easier to align with privacy promises than ad-funded chat. Compare Secrypt’s listed Free, Pro $5, and Unlimited $10 tiers to opaque enterprise quotes that hide API credit mechanics.

Section 6: API-specific clauses

Confirm sk_sec_ key handling, rate limits, credit exhaustion behavior, and whether API logs differ from chat retention. OpenAI-compatible shape does not imply OpenAI-compatible privacy. Check whether API DPAs lag chat DPAs — read footnotes on effective dates.

Developers often ship before legal finishes the API addendum. Require key rotation playbooks in your internal docs. Keys in CI secrets rot slower than people think until an intern posts one in Slack.

Require sk_sec_ rotation examples in vendor docs. If documentation shows keys in source files, treat as cultural signal about expected hygiene. Document who may mint sk_sec_ keys in your org chart — shadow keys in personal accounts are a common audit finding.

Section 7: Incident and breach notification

Document notification timelines and contact paths before you need them. m. tabletop yearly — dusty playbooks fail when real keys leak. Ask what metadata survives a breach if prompts are redacted in logs.

Billing and account records still identify customers. Link incident clauses to your own comms templates. Users should hear from you, not from a tech blog scraping vendor status pages. Tabletop a vendor breach where prompts were not in the leak but metadata was.

Notification clauses should cover account records even when chat bodies stay encrypted at rest. Run a tabletop where only metadata leaks — notification templates should cover account emails even when chat bodies do not.

Score and decide

Score each section green, yellow, or red. Written exceptions expire in six months — stale exceptions become policy without anyone noticing. Use numeric totals when procurement argues favorites.

Secrypt may win on training honesty while losing on SOC2 badges — make tradeoffs explicit. Re-run the checklist when vendors email policy updates. AI terms change more often than enterprise software used to.

Weight sections by your industry: healthcare teams may overweight missing HIPAA; startups may overweight API logging. Numeric scoring forces explicit tradeoffs instead of loudest voice wins. Revisit yellow scores when headcount doubles — acceptable risk at ten employees may be unacceptable at two hundred.

Frequently asked questions

Does Secrypt pass a strict enterprise checklist?

It scores well on training clarity and readable pricing; it does not claim HIPAA or SOC2. Document gaps explicitly and list compensating controls instead of assuming badges equal safety.

How often rerun the checklist?

Annually at minimum and whenever a vendor emails policy updates. AI terms change faster than traditional enterprise software footnotes.

Is opt-out training acceptable?

For sensitive workflows, prefer explicit no-training vendors like Secrypt. Opt-out toggles that reset across devices are not durable infrastructure for proprietary paste.

What if policy is vague?

Treat vague as yellow until reconciled in writing. Ask direct questions about training, retention, subprocessors, and API parity — document answers with dates.

Can I use this for API vendors only?

Yes — add sections for sk_sec_ key handling, credit exhaustion, logging, and whether API DPAs lag chat DPAs. Developers paste more secrets than casual chat users.

Where is Secrypt policy?

Read live policy and pricing at secrypt.space before procurement. Link the URL in your vendor registry so future reviewers start from the same source.

Try Secrypt

Secrypt is private, uncensored AI chat. No training on your messages. Open a thread when you need discretion more than theater.

Open Secrypt chat   View pricing