What makes an AI tool trustworthy?
Julian from modelflow · Published 26 September 2026
AI tools promise speed, but few say where your data goes, who can read it and how long it stays. What actually earns trust, what has already gone wrong, and the questions worth asking before you upload anything.
The tool is rarely the AI
Most AI products on the market do not run a model of their own. They are an interface, a set of prompts and an integration, sitting on top of one of a handful of large model providers. That is a perfectly legitimate way to build software, but it changes who you are really trusting.
Upload a document and it usually does not stay with the tool. It travels on to the provider’s servers, often in the United States, where the provider’s terms and its contract with the tool decide what happens next. You have signed neither, and you have probably read neither. On top of that, US providers can be compelled under US law to hand over data even when it is stored in Europe.
The privacy promise on a tool’s website is only as strong as the weakest link behind it. The only promise that cannot be broken is the one nobody has to make, because the data was never collected and never passed on.
Where your data ends up
Data rarely escapes through a spectacular hack. More often it simply turns up somewhere nobody thought about when the feature was built:
- In a stranger’s account. In March 2023, a bug in ChatGPT showed some users the titles of other people’s conversations, and a small share of subscribers saw parts of other people’s payment details (Engadget).
- In an open database. In January 2025, security researchers found a DeepSeek database open to anyone on the internet, holding more than a million log lines including chat histories (Wiz).
- In search results. In mid-2025, thousands of ChatGPT conversations that people had shared by link could be found on Google, some with names and personal details, until OpenAI pulled the option (TechRadar).
- In training data. Since autumn 2025, Anthropic trains its models on chats from its consumer plans unless users switch it off, and keeps those chats for up to five years (Anthropic).
- With the provider, for good. In 2023, Samsung engineers pasted internal source code into ChatGPT to hunt for bugs. There was no getting it back, and Samsung banned generative AI on company devices (Bloomberg).
None of this took bad intent. A bug, a misconfigured server, a handy share button, a changed default. With confidential documents, that is all it takes.
What “deleted” really means
Nearly every provider promises to delete your data eventually. The fine print matters more than the promise.
Deleting a chat often just removes it from your screen. Copies can survive in logs, backups and monitoring systems for weeks or months. And any deletion policy can be overruled by a judge: in 2025, a US court ordered OpenAI to keep ChatGPT conversations its users had deleted, for months, as evidence in a copyright case (OpenAI).
The only data that cannot leak, be subpoenaed or be kept longer than promised is data that was never stored in the first place.
Can you trust the answer?
Privacy is only half of trust. The other half is whether the output is right, and the honest answer is: not always. A language model gives the most likely answer, not a verified one, and it sounds just as sure either way. What that means for the figures in a financial model is covered in Why faster is not always better.
A trustworthy tool does not claim its AI is always right. It does not ask you to trust it at all.
Seven questions for any AI vendor
Ask these before you upload anything confidential. A vendor that cannot answer them clearly has answered them anyway.
- Which model runs behind your tool, and who operates the servers it runs on?
- Where is my data processed and stored, and which country’s law applies there?
- Is my data used for training, and is that off by default or only if I opt out?
- How long do you keep my data, including logs and backups, and what happens when I delete it?
- Who can access it: your staff, your subcontractors, the model provider?
- Is there a data processing agreement that names every sub-processor?
- When the AI gives me a result, how do I check it against the source?
How we handle it
In short: with modelflow, none of this is your problem.
- No provider behind us. We run European open-weight models on GPUs we operate ourselves in the EU. Your documents never reach OpenAI, Google, Anthropic or any other AI provider.
- Nothing to leak. Documents sit in memory while you review them and are gone afterwards. They never touch a disk, a log or a database.
- No training, no sharing. No model learns from your documents, and nobody else gets them.
- Proof without content. For ten years, the journal records who approved which value from which page. It knows the document by its fingerprint and never stores its content or the figures.
- Every value checked. Nothing enters your model until a person has seen it where it was found.
Our data processing agreement is part of the terms of use.