Treat an AI provider exactly like any third-party data processor: whatever you paste leaves your boundary and is subject to their handling, retention, and training policies. The core question is where does this data go, who can see it, and is it used to train a model?
