Private AI for Journalists: Protecting Sources and Story Material
Reporters use AI to structure interviews, draft FOIA language, and stress-test narratives. Private AI keeps those experiments out of training pools and careless retention.
Key takeaway: Reporters use AI to structure interviews, draft FOIA language, and stress-test narratives. Private AI keeps those experiments out of training pools and careless retention.
Why newsrooms care about AI privacy
A scoop dies when source details leak into a training set or sit in a chat history someone subpoenas. Newsrooms adopted email policies decades ago; AI prompts need the same discipline now. Freelancers without IT departments feel the gap most acutely — one paste into a consumer bot can expose a whistleblower’s employer before publication.
Private AI for journalists means choosing tools like Secrypt that state conversations are not used to train models and do not fuel ad profiling from message content. Source retaliation is real; training pools are abstract until a competitor’s story sounds like your notebook. Document which tools reporters used while reporting — source lawyers increasingly ask before publication.
Editorial lawyers care about chain of custody for notes, not just final copy. When AI sits in the middle of that chain, the vendor’s training and retention posture becomes part of your defense if accuracy or confidentiality is challenged later.
Separate identity from content
Never type a source’s legal name into any hosted model when a codename suffices. Separate who someone is from what they alleged — structure beats biography in prompts. Use burner devices and accounts for the most sensitive threads if your security editor demands it.
Secrypt accounts enable encrypted history; anonymity still depends on your broader OPSEC. Remember HTTPS inference is not steganography. Hostile networks and compromised laptops defeat vendor promises regardless of marketing.
Practice describing allegations with role labels — “official A,” “witness B” — until publication names clear legal review. The habit reduces accidental identity leaks when you paste interview fragments during a late-night rewrite.
Storyroom workflow
Morning meeting: outline the FOIA request in Secrypt using agency names only. Midday: stress-test the narrative arc with hypotheticals. Evening: clear history after publish so tomorrow’s unrelated beat does not share a sidebar with yesterday’s sealed material.
Keep raw audio transcripts offline until redacted. Editors should assign which desks may use hosted AI versus air-gapped local tools for national security beats. Data desk scripts calling Cipher should use redacted abstract batches, not full leak archives.
Photo desks need AI policy too — captions and metadata carry identity even when body text is clean. A polished image description can dox a source when EXIF or location tags ride along with the upload path.
- Use codenames for sources in prompts
- Keep raw audio transcripts offline until redacted
- Clear Secrypt history after publish
- Do not upload sealed court PDFs
- Verify facts outside the model
Training policy matters for scoops
Mainstream assistants with opt-out training still processed your text for that session. For pre-publication material, prefer explicit no-training vendors. Secrypt’s stance — conversations not used to train models — removes a long-tail risk that your embargoed lede becomes someone else’s fine-tuning data.
Training policy does not replace source protection tradecraft. It narrows one leak channel among many. Explain training policy in morning standup when interns arrive — they default to consumer tools unless coached.
Compare Secrypt’s training stance to consumer defaults in one internal slide for editors. Facts beat slogans when the standards desk writes the official AI memo.
Tool comparison for desks
Investigative desks need fewer refusals on lawful crime and corruption context; Secrypt’s uncensored posture helps brainstorm without moralizing soft blocks — illegal assistance remains off limits. Cost matters for freelancers: Free tier for pilots, Pro at $5/month, Unlimited at $10/month, with short trials on paid plans.
Compare refusal tone on three real prompts from your beat before standardizing — usefulness beats slogan matching. National security desks may still require air-gapped tools; Secrypt is not a clearance solution for classified material.
Developers on the data desk can point automation at https://secrypt.space/v1 with model cipher when scripts need private inference. Keep API keys in a newsroom vault, not a shared Slack pin.
| Need | Mainstream AI | Secrypt |
|---|---|---|
| Source-heavy drafts | Risky defaults | Private uncensored chat |
| Adult / crime context | Over-refusal | Less filtered within law |
| Cost for freelancers | Varies | Free → $5 → $10 |
| API for scripts | Separate terms | Cipher compatible |
Uncensored does not mean reckless
Uncensored on Secrypt means the model engages lawful sensitive topics — abuse investigations, extremism research, medical edge cases — without performative refusal theater. It does not mean publish unverified allegations or dox subjects. Editorial standards still gate what goes to print.
Train interns: less filtering requires more editorial judgment, not less. Standards editors remain the publish button — AI suggests, humans certify facts. Uncensored brainstorming is not uncensored publishing.
When a draft sounds too clean, that is a signal to verify harder, not to ship faster. Models smooth narratives; reporters break them against primary sources.
Collaboration without oversharing
Slack screenshots of AI threads are the new email forward leak. Share outlines, not raw prompts with source codenames, in newsroom channels. When contractors leave, revoke any Cipher sk_sec_ keys they held for data projects the same day access ends.
Ghost mode helps for sensitive one-off threads that should not linger in a shared account’s sidebar. Use export-to-doc for editor review instead of share links that preserve prompt history.
Freelancers need written AI policy from assigning editors — defaults differ by outlet. A stringer working for three publications should not guess which retention rules apply.
Encrypted history and Ghost mode
Signed-in Secrypt users get encrypted history — stored thread copies protected at rest. That is not end-to-end encrypted inference; the service still reads prompts to generate answers. Ghost mode limits ordinary history persistence for threads you mark ephemeral.
Use both when pre-publication sensitivity is high. Export before clear if counsel wants a record — deletion timing for backups may not be instant. Traveling reporters on shared bureau laptops should clear sensitive threads before flights.
Cross-border assignments: know where secrypt.space traffic routes and what your outlet’s policy says about international access. Policy literacy travels with the reporter, not just the laptop.
Field test before the big story
Run a dry story: public records only, full workflow from outline to clear. Note latency, refusal tone, and whether Ghost mode behaves as expected. Only then bring codename-protected material into the same tool if security editors approve.
Escalate to local models when sources face physical risk. Re-read Secrypt policy quarterly — hosted AI vendors update retention language often without a press release.
Field tests include operational contingencies: satellite fallback when hotel Wi‑Fi blocks HTTPS, backup power for long edits, and a printed checklist when connectivity fails mid-deadline.
Frequently asked questions
Should journalists use Secrypt for every prompt?
Use it for sensitive pre-publication work when policy allows. Public background research may not need the same bar. Re-read the live secrypt.space privacy policy for chat, uploads, and Cipher API scope before relying on this for regulated or client-confidential work.
Is Secrypt anonymous without an account?
Accounts enable history and billing features. True anonymity depends on broader operational security, not marketing slogans. Re-read the live secrypt.space privacy policy for chat, uploads, and Cipher API scope before relying on this for regulated or client-confidential work.
Can AI verify sources?
No. Models confabulate. Verification remains reporting work. Re-read the live secrypt.space privacy policy for chat, uploads, and Cipher API scope before relying on this for regulated or client-confidential work.
Does Secrypt train on my notebooks?
Secrypt states conversations are not used to train models. Still minimize sensitive identifiers in prompts. Re-read the live secrypt.space privacy policy for chat, uploads, and Cipher API scope before relying on this for regulated or client-confidential work.
What about government subpoenas?
Read Secrypt policy and consult newsroom counsel. No consumer chat is subpoena-proof by default. Re-read the live secrypt.space privacy policy for chat, uploads, and Cipher API scope before relying on this for regulated or client-confidential work.
Can I use Cipher API in data scripts?
Yes with sk_sec_ keys; protect keys and respect API quotas and billing. Re-read the live secrypt.space privacy policy for chat, uploads, and Cipher API scope before relying on this for regulated or client-confidential work.
Related guides
Try Secrypt
Secrypt is private, uncensored AI chat. No training on your messages. Open a thread when you need discretion more than theater.