Where your child's AI conversations actually go
"We take your privacy seriously" tells you nothing. Here is what actually happens to the text, and the four questions that produce real answers.
When a child types a question into an AI tool, that text goes somewhere and is handled by more parties than most parents expect. None of this is sinister; it is how the products are built. But it is worth knowing accurately, because the vague reassurance in most privacy pages is not an answer.
This describes the general shape. The specifics vary by product, which is exactly why the questions at the end matter.
The journey of a single question
- The text leaves the device, encrypted, and reaches the product's servers.
- The product may check it against a content filter — often by sending it to another company's model to be judged.
- It is sent to whichever company actually runs the model. This is frequently not the company whose name is on the app.
- There may be a gateway or reseller in between, which is a further party receiving the text.
- The answer comes back, possibly gets checked again, and is shown to the child.
- Some or all of it is stored: the conversation history, and often a log for abuse prevention.
So a single question can be handled by three or four organisations. A parent asking "who sees this" and being told "only us" has been given an answer that is unlikely to be complete.
The training question, asked properly
This is where careful wording does a lot of work, and it is worth learning to hear it.
"We do not train our models on your data" can be entirely true while your child's conversations are still used for training — by the company that actually runs the model, under their terms, because the product is simply a customer of theirs.
So the question to ask is not whether the vendor trains on it. It is whether anyone in the chain does, including the model providers and any gateway. A vendor who has arranged for that not to happen will say so specifically and can point to the setting or the agreement. A vendor who has not will answer the narrower question.
How long it is kept
Usually longer than parents assume, and for reasons that are often legitimate — abuse investigation, debugging, the child's own history. The reasonable expectations are a stated period rather than "as long as necessary", and a way to delete a conversation that actually deletes it rather than hiding it from the interface.
Worth asking specifically whether deleting a conversation removes it from the providers downstream, because frequently it does not.
What a school or parent can see
A separate question from what the company can see, and there is a real tension in it.
Full visibility of everything a teenager writes will end their honesty and is rarely the right parenting decision. No visibility at all leaves an adult unable to notice a pattern that matters. The workable middle is a record of decisions — what was blocked, roughly what category, how often — which is enough to prompt a conversation and not a transcript of a child's private questions.
Whichever a product does, you should be able to find out in a sentence, and your child should be told. Monitoring a child has not been told about tends to be discovered, and what it costs is not the monitoring.
The four questions
- Which companies receive what my child types — including any gateway or reseller, by name?
- Is that content used to train any model, by you or by them? Not just by you.
- How long is it kept, and does deleting a conversation delete it everywhere?
- What can I see, what can the school see, and does my child know?
A product built with children in mind can answer all four in a few sentences. Difficulty answering is itself informative, and worth more than any privacy page.
What to tell your child
One idea, and it holds regardless of the product: it is not private, and it is not a friend. Anything that genuinely matters should go to a person who can actually notice and act.
This is worth saying even about a well-designed product, because the habit protects them in every other tool they will ever use.
Common questions
Who can see what my child types into an AI chatbot?
Typically several organisations: the product, whichever company runs the model, any gateway or reseller in between, and sometimes a separate provider doing content filtering. A vendor answering 'only us' has probably not described the full chain.
Is my child's AI conversation used for training?
Ask whether anyone in the chain uses it, not just the vendor. 'We do not train on your data' can be true while the company actually running the model does, under their own terms.
Can I delete my child's AI conversations?
Usually from the interface, but ask specifically whether that removes it from the providers downstream. Frequently it does not.
Published by Navōn. How these guides are written and checked.
Read next
- Safe AI for kids: what a parent should actually check
Age ratings and marketing language tell you very little. Six checks a parent can make in ten minutes before letting a child use an AI tool.
- 12 questions to ask before you buy an AI tool for your school
A procurement checklist with the answers that should worry you. Print it, take it to the demo, and ask every question in order.
- Talking to your child about AI
What to say at different ages, the questions children actually ask, and why the goal is being the person they tell rather than the person who checks.