Dragging a document into an AI assistant can start several processes: a transfer to a server, text extraction, storage, retrieval and a model request. The chat window usually shows very little of this. To understand where your file goes, you need the rules for the particular product and account.
A promise that data is not used for training answers one question. It does not tell you whether the file is stored, who can access the conversation or when deletion finishes.
Follow the file through the service
An application may extract text from a PDF, use optical character recognition on a scan or break a large document into searchable passages. The model might receive selected passages rather than the original file.
This affects both privacy and accuracy. The service may keep the original upload and a processed representation. Meanwhile, a correct answer depends on the relevant content reaching the model. A chart, footnote or scanned table can be missed or interpreted incorrectly.
Ask the assistant for the passage supporting a material claim, then compare it with the document. That is especially useful when a file includes several versions of the same figure. Uploading the right document is not the same as obtaining a faithful reading.
Retention is not one setting
A service can apply different retention rules to chat history, uploaded files, API requests, security logs and feedback. Consumer and business accounts may also have different terms.
For example, Anthropic’s commercial data-retention page distinguishes API inputs and outputs from saved conversations and services such as its Files API. It also lists exceptions for policy enforcement, legal requirements and other arrangements. The lesson is to read the rule for the feature you use, rather than carry a headline from one product into another.
Deleting a conversation may remove it from the interface before all backend deletion processes finish. A saved file may have its own lifecycle. If a provider describes a deletion window, record both what it covers and what exceptions it names.
Training and access are different questions
A service can avoid using your content to improve models while retaining it to deliver the product. Conversely, a preference about model improvement may not affect every feedback submission or third-party integration.
Access deserves a separate check. A work account may be administered by an organization. Shared conversations can expose content to other people. Connected tools may send selected text to a search engine, database or external application.
Before uploading sensitive material, reduce the file to what the task needs. Removing irrelevant names or account details can be more dependable than relying on the model to ignore them. Check hidden sheets, comments and document properties as well as the visible page.
Local document chat changes the route
A genuinely local workflow can keep processing on the device. LM Studio documents local document processing for its offline chat features. That is a product-specific capability, not a property of every application marketed as local AI.
External tools can change the route again. A local model that sends a passage to a remote search service no longer keeps the entire task on the device. Cloud-synced folders and automatic backups can create additional copies independently of the AI application.
Our local AI guide describes a practical offline test. Use a harmless sample file first and verify the workflow with the network disconnected.
A short check before the upload
Identify the product, account type and feature. Then locate its current statements about storage, model improvement, deletion and connected services. If an important answer is missing, treat it as unknown.
For a business document, also check whether you are allowed to share it through that service. An employee’s personal preference is not necessarily the organization’s permission to transfer customer or contractual information.
After the task, keep the useful output in your own records and remove uploads you no longer need where the product allows it. Check the actual deletion controls instead of assuming that closing the browser clears the conversation.

