CHECKLIST

The AI assistant settings checklist

What this covers: How to review and tighten the permissions, memory settings, and data controls on every AI tool you already use. No new software, no new subscriptions. The whole audit takes about twenty minutes.

Part one of a three-part series on using AI without paying a price you never agreed to. Published 1 September 2026.


Quick summary

Most AI privacy risk is not in a tool you have not tried. It is in the permissions you granted months ago and never revisited. This checklist covers five areas: what to check before connecting anything new, permissions on tools you already use, memory and training settings, account hygiene, and the one habit that replaces everything else. Work through it once, then set a ninety-day reminder to repeat it.


Before you connect a new AI tool: what to look for in the terms of service

Almost everyone reads the privacy policy. Almost nobody reads the terms of service. The privacy policy is written by marketing to reassure you. The terms of service is written by lawyers to protect the company. The second document is the honest one.

You do not need to read it end to end. Search it for these four words:

Perpetual. How long the company keeps the right to use your material. If the licence does not end when your account does, that is the whole story.

Irrevocable. Whether you can withdraw the permission later. If you cannot, deleting your account does not undo anything.

Sublicensable. Whether they can pass your material to third parties you have never heard of and cannot audit.

Training. Whether your material feeds their models. This is sometimes acceptable, but you should know whether you agreed to it.

If a tool claims a perpetual, irrevocable licence to your material, you are not a customer of that product. You are a supplier to it. That may still be a trade worth making. Make it knowingly.

Checklist: Before connecting a new AI tool

  • Search the terms of service for: perpetual, irrevocable, sublicensable, training.
  • Check whether the tool can take actions on your behalf, or only read.
  • If it can act, confirm whether it asks for your approval every time, or acts automatically.
  • Verify whether you can delete your data from their systems, not only disconnect the account. These are different things, and several products have shipped the second while implying the first.
  • Look for a published security contact. Companies that take this seriously make it easy to report a problem.

How to set permissions on AI tools you already use

The principle is simple: match the permission to the task.

There is a significant difference between a tool that needs context and a tool that needs control. Reading is not acting. A scoped, one-time permission is not the same as standing, always-on access. Most of the value people get from AI sits in the first category. Almost all of the risk sits in the second.

Checklist: Permissions to review now

  • Email. Set to read-only wherever the option exists. Never grant write access without a specific reason you could explain to someone else.
  • Calendar. Read-only. An AI assistant does not need to send invitations on your behalf in order to be useful for planning.
  • Location. Off by default. Turn it on only when a specific task requires it, then turn it off again.
  • Screen, microphone, and keyboard. Off by default. These are the highest-risk permissions and the least often necessary. Screen capture sees everything on your display, including things you never typed into the tool.
  • Payment details. Never stored with an agent that can transact autonomously. If a tool can both hold your card and decide to spend it, you have removed the only checkpoint in the system.
  • Files and cloud storage. Grant folder-level access rather than whole-drive access wherever the product allows it.

How to manage AI memory and training settings

Most AI tools now store information about you between sessions. Most users have never opened those settings.

Checklist: Memory and training

  • Find the memory settings in every AI tool you use weekly.
  • Read what is already stored. For most people, this is the moment the scope becomes clear.
  • Delete anything you did not intend to share.
  • Turn off training on your data where that option exists.
  • Check whether sensitive categories (health, beliefs, finances, family) are stored by default or by choice. Products differ significantly here, and that difference reflects how a company thinks about its users.

One example of what good looks like: Anthropic's August 2026 memory update pauses before storing sensitive categories, defaults that setting to off, applies nothing retroactively, and shows every stored item as something you can edit or delete. Disclosure: I am a Claude Community Ambassador, so weigh my enthusiasm accordingly. The point is not the product. The point is the behaviour. A tool that stops and asks, and defaults to no, is doing something structurally different from one that stores by default and buries the control. Reward the first kind wherever you find it, because companies build more of whatever gets rewarded.


Account hygiene checklist for AI users

  • Open your Google and Microsoft account permissions pages and revoke third-party access you no longer use. Most people find something they forgot about years ago.
  • Use a separate email address for testing new AI tools. This costs nothing and limits the exposure if something goes wrong.
  • Enable two-factor authentication on every account an AI agent could reach.
  • Audit which accounts share a password with an account an agent can read.

The single most important AI privacy habit

If you do nothing else on this list, do this.

Before adopting any new AI tool, wait one week and search for what other people found.

In August 2026, a widely praised personal AI assistant was found to be retaining emails in plain text after users disconnected it, following instructions embedded by third parties, and sending messages on behalf of users without asking. Every one of those problems was discovered by early adopters within about seven days of release.

Waiting a week costs almost nothing. It is not excessive caution. It is second-mover advantage, and it is the same strategy that produced Google Search, Gmail, Chrome, and Waymo. The first mover pays for the market's education. You are entitled to collect on it.

  • Set a ninety-day reminder in your calendar to run this audit again.

This checklist accompanies part one of a three-part series on using AI without paying a price you never agreed to. Part two covers what you are giving away when you post about your children. Part three covers what the AI race is costing your capacity to think.

Build with AI teaches non-technical professionals to use AI without handing over more than they meant to. Five live sessions a week, built on the thing that survives the tools: judgment. Applications are open.

Frequently asked questions

How do I check what permissions I have given an AI tool?

Start with your device's app settings (iOS: Settings > Privacy and Security; Android: Settings > Apps > Permissions). For web-based tools, check the tool's own account settings page, then also review Google's connected apps page at myaccount.google.com/permissions and Microsoft's equivalent under account.microsoft.com/privacy.

What is the difference between deleting an account and deleting my data?

Deleting your account removes your login access. Deleting your data removes what the company holds about you. These are separate actions, and some tools require an explicit data deletion request separate from closing the account. Look for a "Delete my data" or "Right to erasure" option in the tool's privacy settings.

Can AI companies train their models on my data without telling me?

Yes, unless you opt out or their terms prohibit it. The setting is often found under "Privacy" or "Data controls." For ChatGPT: Settings > Data controls > Improve the model for everyone. For Claude: Settings > Privacy > Use my conversations to improve Claude. Check this whenever you start using a new tool.

How often should I run an AI permissions audit?

Every ninety days. Permissions accumulate quietly and no product will remind you to remove one. Set a recurring calendar reminder at the end of this audit.

What is the four-word terms of service search method?

Before connecting any new AI tool, use Ctrl+F (or Cmd+F) to search its terms of service for four words: perpetual, irrevocable, sublicensable, and training. Each word reveals a different category of risk in how the company can use your content.

What should I do if I find a term I do not like in the ToS?

You have three options: decline the tool, use it only with content you would be comfortable making public, or contact the company's privacy team to ask whether a different data tier is available. Most people skip straight to option two without realising it is a choice.
Build With AI Club

Ready to build with AI?

Join as a Pro Fellow -- live sessions 4 times a week, five structured paths, and a full playbook library.

Apply to Build with AI