Writing

Is it safe to tell an AI chatbot about your relationship?

Written

A great many people are now telling AI chatbots things they have not told their friends. It is available at 2am, it does not get tired of the subject, and it does not have to see your partner at dinner next week.

Then, usually a little way in, a thought arrives: where is this going?

Search that thought and almost every answer is a tutorial for switching off a training toggle. That is not wrong, and it is a much weaker answer than it looks. This is an attempt at a better one.

The question is actually three questions

People collapse these into one. They have different answers with different consequences.

Will a person read it? Support staff, safety reviewers, contractors doing quality work. Most services reserve some version of this right, usually narrowly.

Will it train the model? Whether your words become part of what the system learns from — and whether anything of yours could ever surface in someone else's output.

Can it come back out? Not through malice: through a breach, a subpoena, a legal hold, an account someone else is signed into, or a device someone else can open.

The third is the one people consider last and the one that has actually hurt people. It is also the one a training toggle does nothing about.

This is not a fringe worry, and the reporting on it is good. Three worth finding for yourself — we are deliberately not linking out, because this site makes no requests to anywhere else, but the titles are enough to search:

  • Stanford HAI, Be Careful What You Tell Your AI Chatbot (October 2025), on how conversations get pulled into training.
  • The Washington Post, end of August 2026, on who can read your chats.
  • Fast Company, Stop Letting ChatGPT and Other AI Chatbots Train on Your Data — a guide that exists precisely because the default usually runs the other way.

Read them rather than our paraphrase of them.

Why "you can turn it off" is the weakest possible answer

A setting is a promise about the current version of a product, made by the current owners, under the current business model.

Settings get renamed. Defaults get revisited after a bad quarter. Products are acquired. "Off" sometimes means off for training but on for storage, and that distinction lives in a policy document written to be legally accurate rather than understood.

None of that requires anyone to lie to you. It only requires normal corporate time to pass.

So it is worth sorting any promise into one of three tiers before relying on it:

A setting. You changed a value. It holds until something changes it — a redesign, a migration, a new default applied to everyone. The weakest tier, and where most reassurance lives.

A policy. The company has committed in writing. Stronger, because breaking it has consequences. Still a promise about future behaviour, and still revisable with notice.

A structure. The thing cannot happen because of how the system is built — the material is not held in a form that permits it, or it is not in the company's possession at all. This is the only tier that does not depend on anyone continuing to mean it.

Nearly all consumer AI privacy reassurance is tier one, delivered in the tone of tier three.

What to check, for any product, in about ten minutes

Not exhaustive. These are the questions where the answer tends to be revealing.

Is the protection on by default, or did you have to go and find it? Defaults are the real policy. Everything else is a feature for the small number of people who go looking.

Does the policy separate training from retention? "We do not train on your data" and "we do not keep your data" are entirely different sentences. Plenty of products say the first while doing the second, quite legitimately.

What happens when you delete? Ask specifically: does delete reach backups, and by when? A stated window — even a long one — is a far better sign than a page that uses the word "delete" without ever saying what it reaches.

Can you get it out? Export is a good proxy for whether a company thinks of your material as yours. It is also what lets you leave without losing everything.

If they were compelled to hand something over, what is there to hand over? This is the tier three question, and very little is designed to answer it well.

The person who never agreed to any of this

Here is the part that is almost never mentioned, and it is the one worth sitting with.

When you describe your relationship to a chatbot, you are not only submitting your own information. You are submitting a characterisation of someone else — their behaviour, their words, their worst evening of the month — written by the person currently most upset with them.

They did not consent to that. They do not know it happened. There is no setting they could change, because it is not their account.

This is not an argument for silence. Being able to work out what you think, in private, before speaking is one of the most useful things a person can do, and the alternative — carrying it alone until it comes out sideways — is worse. But the privacy question here has two people in it, and only one of them is answering it.

If you want a smaller principle to hold: write about what happened and what it did to you; be careful about building a case file on a person who is not in the room. It is better for them, and it is better for you, because a case file has to be maintained and it slowly becomes the relationship.

Where we come into this

We are building Atween, so we have an obvious interest here and should be exact.

Atween is a private place to work out something you need to say to one person, and to send a version you have approved. Your own words are never shown to them.

What we have committed to publicly is on this site — in the agreements and in plain language on what you should know — including that training on your material is a separate thing you would have to agree to, not a default you have to go and switch off.

On the tier three question, a straight answer. The other person seeing your words is not a setting. There is no screen where it can be turned on — not by them, not by us, not by anyone paying for it — and there was never going to be one, because the product is arranged around that being impossible. It does not cover everything on this page; nothing we can say answers the subpoena question as well as it deserves. But it is the one promise here that does not depend on us continuing to mean it.

The rest are commitments, published where you can hold us to them, and they are not a reason to take our word for anything. The five questions above are the ones we would want a stranger to ask us.

It is not released yet. When it is, it will be here.

If you want the other half of this — not what happens to the words, but what happens to you when the only thing listening has only ever heard your side — that is the next piece.

Everything in Writing