The short answer
- **What you type into an AI tool leaves your device.** It is stored by the provider, may be reviewed for safety, and may be used for training unless you opt out.
- **Canadian privacy law applies to AI.** Organisations need a valid reason and, usually, your consent to collect and use your personal information — including to train or run AI.
- **You have rights.** You can ask what an organisation holds about you, correct it, withdraw consent and complain to a privacy commissioner.
- **Small habits protect you most.** Share less, change a few settings, and think twice about photos and voice.
Where your data goes when you use AI
- **Your device** sends your prompt, files, photos or voice to the provider's servers — often in the United States — unless the model runs locally.
- **The provider stores it** with your account, for a period set by its [retention policy](/glossary/data-retention), even after you delete a chat.
- **Automated systems and sometimes people review it** to detect abuse and improve safety.
- **It may train future models**, depending on your settings and plan. Data used in training can't practically be removed later.
- **Connected apps and plug-ins** may receive it too, under their own policies.
- **AI features in other apps** — email, photo, office suites — often send content to an AI provider behind the scenes; their privacy policies should name who.
The laws that protect you
Canada has several privacy laws, depending on who holds your information and where. None is specific to AI, but all of them apply to it.
| Law | Covers | Regulator |
|---|---|---|
| [PIPEDA](/glossary/pipeda) | Private-sector businesses' commercial activities, except where a similar provincial law applies; federally regulated businesses everywhere | Office of the Privacy Commissioner of Canada |
| Québec's private-sector act, modernised by [Law 25](/glossary/law-25) | Businesses in Québec | Commission d'accès à l'information |
| Alberta and British Columbia PIPA | Private-sector organisations in those provinces | Provincial information and privacy commissioners |
| Privacy Act | Federal government departments and agencies | Office of the Privacy Commissioner of Canada |
| Provincial public-sector and health privacy laws | Provincial governments, municipalities, schools, hospitals | Provincial commissioners and ombudspersons |
Québec's Law 25 goes furthest: organisations must name a person in charge of protecting personal information, assess privacy risks before new projects and before sending data outside Québec, report serious incidents, keep tracking technologies off by default, and tell you when a decision about you is made solely by automated means.
Your rights, and how to use them
- **Access.** Ask an organisation what personal information it holds about you and how it's used. Under PIPEDA it generally must answer within 30 days.
- **Correction.** Ask for inaccurate information to be fixed.
- **Withdraw consent.** You can withdraw consent for many uses, subject to legal or contractual limits — including, with many AI providers, use of your chats for training.
- **Automated decisions (Québec).** Be told when a decision was automated, learn the main factors, and have it reviewed by a person.
- **Portability and de-indexing (Québec).** Get your data in a usable format, and ask that information about you stop being disseminated or indexed in some circumstances.
- **Complain.** If an organisation doesn't respond or you think your rights were breached, complain to the relevant commissioner. It's free.
A request you can copy
"Under applicable privacy law, I request access to the personal information you hold about me, the purposes for which it is used, whether it has been used to train or operate AI systems, and the third parties to whom it has been disclosed. Please reply within 30 days."
Ten steps you can take today
- Turn off training on your chats in each AI assistant you use (see [where to find it](/guides/use-ai-assistants-safely#settings)).
- Use temporary or incognito chats for health, money, legal or family questions.
- Review and prune what the assistant's [memory](/glossary/ai-memory) has stored about you.
- Replace names and numbers with placeholders before pasting documents.
- Crop or blur faces, licence plates, addresses and ID cards before uploading photos.
- Remove connected apps and plug-ins you no longer use.
- Be cautious with voice features: a few seconds of audio can be enough to [clone a voice](/glossary/voice-cloning).
- Check the privacy settings of AI features built into your phone, email and photo apps.
- Set your social-media profiles to limit public posts and photos being scraped.
- Talk with your kids about what not to share with chatbots and apps.
AI in public spaces and at work
[Facial recognition](/glossary/facial-recognition) and other biometric tools raise the highest privacy stakes, because you can't change your face. In 2021 Canada's privacy commissioners found that Clearview AI's mass collection of online photos was illegal in Canada, and the federal commissioner found the RCMP broke the law by using it. Employers, too, must keep employee monitoring reasonable and transparent; in Ontario, employers with 25 or more staff need a written electronic monitoring policy. See [AI and jobs in Canada](/guides/ai-and-jobs-in-canada#rights).
For organisations: a privacy checklist for AI projects
- **Know your data.** List what personal information the AI will see, from whom, and why it's needed.
- **Assess the risk first.** Do a privacy impact assessment — required in Québec for new technology projects involving personal information and before transferring it outside the province.
- **Read the vendor's terms.** Confirm in writing that your data won't train their models, where it's stored, how long it's kept and who can access it.
- **Get meaningful consent** where needed, and update your privacy policy to name AI uses and providers.
- **Minimise and de-identify.** Send the AI only what it needs; strip identifiers when you can.
- **Keep humans accountable** for decisions about people, and be ready to explain them.
- **Plan for incidents.** Know how you'd detect, record and report a breach involving an AI tool.
- **Name an owner.** Someone must be responsible for privacy — in Québec this is a legal requirement.
Small businesses can start with our [practical guide to AI for small business](/guides/ai-for-small-business).
How AI Broadsheet handles your privacy
We practise what we report. You can read everything without an account; our analytics are cookieless; ads are non-personalised unless you agree; Young Lab collects nothing about children. Details are on our [privacy page](/privacy).
Frequently asked questions
Does ChatGPT or Claude use my conversations for training?
On consumer plans, your chats may be used to improve models unless you turn that off in settings; each company sets its own defaults and they change over time. Business and education plans generally exclude your data from training by default.
Is it legal for AI companies to train on my public posts?
It's contested. Canadian privacy regulators have said that publicly accessible personal information is not free for any use, and scraping can breach privacy law. Courts and regulators in several countries are examining the question. You can limit exposure through your platform settings.
What is Law 25 and does it apply to me?
Law 25 modernised Québec's privacy law. It protects people whose information is held by businesses operating in Québec, and it applies to any organisation that collects personal information in the course of business there, wherever it is based.
How do I complain about an AI company's use of my data?
First write to the company's privacy officer. If you're not satisfied, file a free complaint with the Office of the Privacy Commissioner of Canada, or with the Commission d'accès à l'information if you're in Québec, or your provincial commissioner in Alberta or British Columbia.
Words to know
personal informationpipedalaw 25data retentionai memoryfacial recognitionautomated decision makingtraining data