PTN—30
Data boundaries
Make consent, retention, and incognito first-class interface — itemized, per-use controls instead of a buried all-or-nothing toggle.
Every AI conversation is also a data event, and most products handle that fact in a settings page nobody visits, written by lawyers for lawyers. The person pasting a salary negotiation into a chat is making a retention decision whether or not the interface admits it. Data boundaries move that decision into the open: what this conversation feeds — training, memory, analytics — for how long, and a control at the moment of use, not three menus away.
Itemization is what separates consent from surrender. “Help improve our products” bundles model training, memory, analytics, and human review into one checkbox, so the person who wants memory but not training gets neither choice — they get a bundle sized to maximize acceptance. Honest boundaries list the uses separately and let each be declined on its own. The bundled toggle is not a simplification; it is a negotiating position dressed as one.
Off-the-record mode is the pattern’s sharpest tool, and precision is what makes it trustworthy. “Temporary chat” must state its actual terms: not in history, not used for training, deleted after thirty days — whatever the truth is, in those words. A vague incognito invites people to infer absolute erasure, and the gap between inferred and actual coverage is where the betrayal story lives. The mode’s honesty matters more than its strength; people can work with “retained briefly for abuse screening” but not with a promise they later learn was rounded up.
The current boundary state has to stay visible during the conversation, because the moment of disclosure is the moment that matters. A person deciding whether to paste the medical record needs the answer in their peripheral vision — this chat is off the record, or it is not — rather than from memory of a toggle set weeks ago. Boundary state that must be recalled instead of seen will be recalled wrong, always in the direction of oversharing.
Anatomy
Conversation · privacy
Saved · memory onCovers this conversation only: no history, no memory, no training. Deleted when you close it.
Use this chat to improve the assistant
Remember shop preferences for future chats
Count feature use — content is never read
Each use is its own decision — declining one never disables the others.
An off-the-record control with itemized data uses, per-item opt-outs, and the active boundary state visible in the conversation.
- 1Precise off-the-record. The mode states exactly what it covers and for how long — actual terms, not an inference-inviting name.
- 2Itemized uses. Training, memory, and analytics are listed separately — a bundle sized for acceptance is not consent.
- 3Per-item opt-out. Each use can be declined on its own, so keeping memory does not require donating training data.
- 4Visible boundary state. The active boundary stays in view during the conversation — recalled state is misremembered state.
When to use
- Conversations carry sensitive material — health, finances, personnel, unreleased work.
- Inputs feed training, memory, or analytics and the person would care which.
- Enterprise or regulated contexts where retention terms are contractual, not preferences.
- The product has memory, making “what does this system keep?” a live question in every session.
Design considerations
- 01State off-the-record terms in operational language — “not saved to history, not used for training, deleted within 30 days” — and match them exactly in the backend.
- 02Itemize data uses and make each independently declinable; never gate a useful feature on an unrelated consent.
- 03Keep the boundary state visible in the conversation surface itself, at the moment of disclosure.
- 04Put the incognito control where conversations start, one gesture away — a privacy mode behind three menus protects nobody at the moment it matters.
- 05Disclose the exceptions honestly: if safety review or legal hold can retain excluded data, say so up front rather than in the incident postmortem.
- 06Carry boundaries through the pipeline — an opt-out the analytics warehouse ignores is a lie with a UI.
Pitfalls
- ✕The bundled toggle: one “improve our products” switch covering training, review, and analytics, forcing all-or-nothing on people who wanted to say yes to half.
- ✕Incognito that rounds up — a temporary mode people reasonably read as total erasure while data persists in logs, caches, or review queues.
- ✕Buried boundaries: honest controls, three menus deep, discovered only after the sensitive conversation already happened.
- ✕Interface-only opt-outs, where the toggle flips a flag the data pipeline was never taught to respect.
- ✕Punishing the private: degrading core functionality in off-the-record mode beyond what the data genuinely requires, taxing exactly the caution you claimed to support.
In the wild
- ChatGPT
- Temporary Chat states its terms in the interface — not in history, not used to train models, retained up to 30 days for safety — and the mode is visibly active during the conversation.
- Gemini
- Apps Activity controls expose retention as an explicit setting with stated timeframes, separating conversation history from the product’s other data uses.
- Zoom AI Companion
- Shows every participant an indicator when AI features are active in a meeting, and gives hosts per-meeting control — the boundary is visible to the people whose data it covers.