siift's Privacy-First stance
SS

Author

Samim Safaei

Founder @ siift.ai | Fixing the early stage Founder Journey with AI

Connect on LinkedIn

siift's Privacy-First stance

Entrepreneurs are leaking their IP to AI. Discover the AI two-tier privacy system; how Big AI is predatory by design, and how siift is pioneering Non-Disclosing AI (NDAI) to protect your business.

Why siift is making the commitment to be the world's first Non-Disclosing AI.

AI is threatening to society, but not how you think.

Forget the doomsday ASI scenarios, the robot uprising, the mass job replacement headlines. Those fears, while not entirely baseless, are a convenient distraction from something much closer and more corrosive already happening. The real threat is quiet, structural, intellectual property extraction for domain experts, entrepreneurs, founders and small business owners who are training AI to eat their lunch, and rip up what's left of the social contract and gainful economic opportunities.

If you’ve been following siift at all, you know I don’t do fear-mongering. I’m an engineer by training and a 5x founder who has spent over a decade learning things the hard way. I’m not writing this to scare you. I’m writing this because the writing is on the wall as I and many others are starting to notice.

Below is the state of current state of user privacy in the AI industry, especially for those using AI to build a business, and siift's alternative to big AI exploitation or expensive DIY local systems.

Understanding the AI Game

AI was always the endgame of the modern internet. Whether done voluntarily and consciously or otherwise, putting virtually all collective human knowledge online was arguably the biggest heist in history. The language models trained on that data are impressive, sure ~ but they’re actually not the main event. The real value isn’t the old internet data baked into the model. It’s the new things you create with it: your strategies, your timely insights, your new strategies, your practical solutions to real problems.

What makes AI different from every technology wave before it: crypto, SaaS, mobile, even the internet itself is that AI can close “the value loop.” It can generate ideas, help you execute on them, reassess the results, and keep building. No prior technology could do that. This perpetual value potential is what makes AI economically unprecedented, and it’s exactly why these AI companies are serving you for basically free. They’re not being generous. They’re extracting even more information from you.

And whose value is most vulnerable to this extraction? Entrepreneurs. Your IP, Intellectual Property, is high-value ~ it’s profitable, innovative, often the seed of something disruptive ~ and it’s low-defensibility, because you don’t have the legal teams, compliance infrastructure, or negotiating leverage to protect it. You’re doing your most sensitive work on the cheapest tiers of tools built by companies that can’t actually afford to run them.

Speaking of which: is it a coincidence that every major provider has quietly shifted to saying “you own your outputs”? OpenAI, Google, Anthropic ~ they all have this language in their terms now, and it keeps changing and sounding increasingly vague. But ownership does not equal privacy or control. Intellectual Property is conveniently omitted from these reassurances. You “own” the output the same way you “own” a photo you post to a social platform ~ technically yours, but effectively theirs to reuse in ways you’ll never fully understand.

So the real question isn’t who owns the output. It’s what happens to your inputs and context, and whether your outputs can essentially be recreated by others. In other words: when you use an AI system, who owns the IP discussed?

The Two-Tier System

There are two completely different privacy regimes in AI right now, and which one you get depends entirely on how much you pay.

On the enterprise and API tier, you get the good stuff: your data isn’t used for training (supposedly at least), you get contractual guarantees, compliance certifications, zero-data-retention options, and IP indemnity. On the consumer tier — the Free, Plus, and Pro plans that most founders actually use — your conversations are used to improve models by default, opt-outs are buried in settings most people never find, human reviewers can access your chats, and data retention policies are deliberately vague.

The same prompt, to the same model, gets treated completely differently depending on your plan. Privacy is a luxury good. Or even worse, data is being extracted on mass from consumers to enterprises with every model update.

And the reason isn’t because big companies are necessarily evil, even the current darling of the AI world Anthropic, who built its brand on being “privacy-first” reversed course. Anthropic launched Claude with an explicit promise not to use consumer data for training. Then in August 2025, they flipped ~ consumer users on Free, Pro, and Max plans now have training enabled by default unless they opt out. Opting in extends data retention from 30 days to 5 years. The consent flow was widely criticized as a dark pattern: a large “Accept” button with a pre-toggled “On” switch for training in smaller print below. Users had until September 28 to decide or lose access. Many accepted without understanding the implications.

The irony is almost poetic since at the same time, Anthropic’s API actually became more private ~ reducing log retention from 30 to 7 days, with zero-data-retention available for enterprise customers. So the company simultaneously tightened privacy for its highest-paying customers (enterprise) and loosened it for everyone else (consumers). Same two-tier system, made more extreme on both ends. Crowdsourcing IP to the highest bidder doesn’t seem that far-fetched anymore, does it?

Independent legal analysis flagged the opt-in UI as a potential GDPR violation. No regulatory action as of early 2026, but GDPR compliance remains contested. Meanwhile, employees on Pro accounts unknowingly bound their organizations to training consent, and small businesses using Pro plans face the same exposure as Free users.

And I’m not picking on Anthropic. They arguably have the best models and stance compared to other Big AI. If anything, they held out longer than anyone else. But that’s precisely what makes this notable: if the “privacy-first” company couldn’t sustain its promise, what does that tell you about everyone else’s? Is the problem the people, or the business model? 

The Fine Print Always Changes

Even the privacy promises that do exist can be overridden by forces entirely outside the provider’s control.

In the NYT v. OpenAI case, a federal court forced OpenAI to retain all ChatGPT user data indefinitely ~ including explicitly deleted conversations. Enterprise and zero-data-retention customers were carved out. Everyone else was exposed. Then in January 2026, a federal judge compelled OpenAI to produce 20 million anonymized ChatGPT logs to copyright plaintiffs. OpenAI’s attempt to cherry-pick only relevant logs was rejected.

Read that again. Twenty million conversation logs, ordered into the hands of third parties. And this was just one lawsuit.

It gets worse. In early 2026, OpenAI started testing ads in ChatGPT on Free and lower tiers, with personalization drawing on past chats and stored memories by default. The boundary between “not training on your data” and “monetizing your data” is now officially blurred. Google went further in late 2025, enabling Gemini access to Gmail, Chat, and Meet by default for US users and rebranding it “Personal Intelligence.” In the US it was opt-out; in Europe, opt-in. A lawsuit alleges this was done without proper consent.

And even the enterprise “no training” promises don’t address what happens to metadata, or the fact that your data passes through processing infrastructure designed for safety review, abuse detection, and usage analytics ~ not just inference.

The takeaway is uncomfortable but essential: your AI privacy isn’t governed by what the provider promises. It’s governed by what courts order, what regulators allow, and what business model pressures demand. The question isn’t whether your current provider’s policy will change. It’s when.

The Leak You Don’t See

It’s not just the providers. It’s what users are already doing at scale, mostly without realizing it.

Seventy-seven percent of employees have pasted company data into AI tools, using personal accounts to do it. Sensitive data now makes up roughly 35% of ChatGPT inputs, up from 11% in 2023. Shadow AI breach costs average $670,000 higher than controlled environments. Thirteen percent of organizations reported AI-specific breaches for the first time in 2025.

Over 225,000 OpenAI credentials have been found on dark web markets ~ not from OpenAI breaches, but from compromised user devices, giving attackers full access to chat histories that might contain months of sensitive business conversations. And 99% of enterprise environments had sensitive data exposed to AI tools due to insufficient access controls. AI privacy and security incidents surged 56.4% year-over-year.

Here’s the asymmetry that keeps me up at night: a Fortune 500 company that leaks source code has legal teams, incident response processes, and cyber insurance. A solopreneur who pasted their business plan, customer list, and financial model into a free chatbot has nothing. The people creating the most value per conversation have the least protection.

Regulation Is Coming ~ But Not for Entrepreneurs

The EU AI Act hits full enforcement in August 2026, the first comprehensive AI regulation globally, with penalties up to 7% of global revenue. Italy has already fined OpenAI €15 million for GDPR violations. In the US, state-level enforcement is accelerating ~ the CPPA issued a $1.35 million fine for operational compliance failures, not breaches.

Sounds promising, right? Except these regulations are designed around enterprise compliance infrastructure: legal teams, Data Protection Officers, documented processes. Over 60% of European SMEs haven’t even started compliance. An IAPP study found that the gap between expected and actual confidentiality in AI chatbots reveals “structural opacity” the problem isn’t outright abuse, it’s that it’s deliberately hard to understand what’s happening with your data.

Only 47% of people globally trust AI companies to protect their data. Gartner predicts 40% of data breaches will be attributed to shadow AI by 2027. Nobody is coming to save founders or small business owners on this, regulation for entrepreneurs is an oxymoron and highly unlikely due to the freedom we need to operate in, its a political minefield to try to create restrictions on innovation. Not regulators, not providers, not the market. If you’re building something valuable with AI, the responsibility to protect it is entirely yours, and most of the tools you’re using are working against you by default.

Why AI Business Models Are Predatory by Design

This isn’t a conspiracy theory, and I’m not accusing anyone of being evil or acting illegally. It’s simpler and more structural than that.

Current AI economics are broken. These companies have unrealistic valuations stacked on top of massive hardware costs with negligible, if any, profit margins. We are in a massive AI bubble where even the market makers, despite record-breaking revenue growth, are not profitable or sustainable because of the scale of premature technology investment required to compete. The unhinged capital investments for data centers and hardware development needed to remove the current bottlenecks to AI progress are the canary in the coal mine, creating a predictable set of survival strategies. 

First, over-promise and under-deliver; they can’t afford to actually ship what they claim, so the marketing always runs ahead of the product. Second, data monetization; selling your data to the highest bidders, either directly or indirectly through model training. Third, equity and margin grabs; demanding ownership stakes or revenue cuts that strangle the businesses they claim to serve. And fourth, the oldest trick in the book; subsidize prices artificially low to create dependency, then change the terms once you’re locked in.

The root cause is uneconomical inference costs, simply meaning it costs too much to produce a useful output from AI, which is forcing every provider into some form of additional extraction to survive long-term. The accelerationist “grow at all costs” playbook makes this inevitable, not a choice or something they can reliably promise not to do. When a company is burning billions to serve you a “free” chatbot, the product is you. We’ve seen this movie before with social media. And maybe even more relevantly with Amazon basics copying top performing products in its marketplace. And maybe most relevantly, Apple's well-documented and questionable tactics in its the app store are given as clear warnings as the risk for "AI wrappers" over a year ago. The trend is that what’s being extracted is growing, it isn’t just your attention, your social graph or even publicly disclosed features ~ it’s going for private thoughts, strategy and your competitive edge. Atleast indirectly. If that sounds paranoid, just look at the growing number of reports that claim this very thing. And not just small independents, but even Samsung.

The Real Danger Nobody Is Talking About

So let me reframe what the “AI threat” actually looks like for the people who are building the future economy.

It’s not super-intelligence or robots. It’s systematic privacy infringement creating an antitrust nightmare, driven by broken economics. Curiously, most entrepreneurs today aren’t worried about privacy or IP exposure when talking to an AI that is more capable and connected than all the people they are very wary of sharing their business ideas with. They’re more concerned with output and speed than strategy or long-term outcomes. “Execution is the new moat”, “its about who can move the fastest” or [insert your favorite tech bro mantra here].

But as autonomous agents push the boundary of what AI can do, execution is arguably solved, and the next frontier is strategy. It’s about the specific path and steps used to execute effectively towards a specific goal. This is not a potential what if, this is being used at scale by the biggest tech companies like Meta already to automate out its own workforce.

There’s a key distinction for entrepreneurs is simple ~ consumer data liability versus business data liability carry wildly different stakes. For consumers, having their data mined is a common, tolerable compromise, re: social media. For enterprises, there are expensive solutions to secure their IP (private cloud, on prem, etc). But what about everyone in the middle? The entrepreneurs and small businesses who have more valuable and vulnerable data than consumers but lack the resources to afford enterprise security?

If an AI provider can access your business IP, two things happen.
1. First is direct hijacking of your strategy, insights, or execution plans. They get copied by the vendor themselves, or sold to the highest bidder. 

2. The second is more insidious: indirect diffusion. Your new ideas get trained into models, which then serve them as default answers to anyone asking similar questions. Your original thinking becomes everyone’s thinking just a few months later, and you never see a cent of the value.

This creates two founder failure modes which are potentially massive anti-trust breaches, that will be damning for society at large. Disillusionment ~ founders lose the incentive to innovate because value gets snatched before they can realize it for themselves. And predatory acqui-hiring where the few who succeed get absorbed early by larger interests, not because they want to sell, but because they can’t compete against their own leaked IP. anti-trust 

I know the “execution is the only moat” crowd will push back here. And yes, execution, distribution, and speed matter enormously. But the economic advantage becomes lopsided toward corporations here, if they’re have access to your execution techniques as well and can just automate them. These issues were exactly what modern IP law was created to prevent. Patents and other intellectual property protections were designed to give innovators the space they needed to actually realize the value of their creations, without fear of exploitation. To prevent anti-competitive practices that create monopolies and hinder social mobility. But how does AI change that game? IP law is now in unprecedented territory due to generative AI, where in some cases AI-generated works can’t claim originality and IP ownership, and the borders are blurring fast.

The end state is left unchecked: small business erodes, inequality accelerates, entrepreneurial activity collapses, and the innovation engine that keeps society moving forward starts seizing up. That’s not a science fiction scenario. It’s a trend line.

siift’s Alternative: The World’s First Non-Disclosing AI

OK so by now you’re probably wondering whether I’m just here to depress you. Well, I’m not. I’m explaining the moral gravity of the situation and why we are choosing to take a stand, unlike the “business as usual” approach that almost all other AI companies take. 

Our stance is simple, we’re leading by example with the movement towards NDAI: Non-Disclosing AI. Let me explain; our AI is a fully confidential line of communication, where anything sensitive you discuss does not get shared in any shape or form with outside parties, unless you explicitly agree to it on a case-by-case basis. This means no sharing of your sensitive data without your permission, directly or indirectly. This is a fundamental difference over other AI companies, and is core to our mission of empowering entrepreneurs and small businesses, not just maximizing profit extraction.

What siift explicitly does not do: we don’t farm your data, whether through directly selling it to the highest bidder, or indirectly leaking your secrets through collective model training. In other words, we don’t offer artificially low prices by then monetizing your sensitive information without your approval. The business model is straightforward usage fees for value delivered, which scales linearly up and down with how much you use it. More value, more cost. 

Now if you ever want to share data, say there’s a partnership opportunity that’s mutually worthwhile, we can broker that for a reasonable fee. But it’s only when you decide the opportunity is valuable enough, with transparent terms and for a fair fee. 

So how is this economically viable when every other provider has determined it isn’t? 

The answer is our technology. Siift charges sustainable usage-based fees because our patent-pending system makes our AI operationally efficient enough to maintain a profitable margin on token based pricing alone. No data exploitation subsidies. No investor loans bankrolling artificially low prices that will inevitably require exploitation later. The efficiency of our product is what makes the privacy-first model work in practice, not just in principle.

I won’t pretend this makes us cheap. We’re not trying to be. We’re trying to be transparent. And in a market where “free” means “we’re billing you in ways you can’t see,” honest pricing is a core feature.

Siift is taking a deliberate position on this, at a significant business cost. We believe AI in business should specifically protect IP, margins, and independence. This is a structural commitment baked into how the company is built, funded, and operated.

The Only Decision That Matters

We’re not saying that every AI provider is out to steal your ideas. Most of the people building AI tools genuinely want to help. But if they rely on Big AI model providers and don’t take extra measures to protect the IP you share, the economics of the current AI industry will push even the well-intentioned ones toward business models that are fundamentally misaligned with the interests of small business owners. You can see it in the policy reversals, the court orders, the dark patterns, the data leak statistics. This is a systematic failure that’s being downplayed. 

So here’s my ask, and it’s the same one I make at the end of everything I write: don’t take my word for it. Go read the terms of service for whatever AI tool you’re currently pouring your business strategy into. Compare it to ours. Check their data retention policy and what tier you’re on and what that tier actually guarantees. Don’t be fooled by SOC II or some compliance certification that already has loopholes for data farming baked in. Look for explicit commitments to not leak your IP, like this article. And if you can't find them, ask yourself whether you’d hand that same information to a stranger at a conference and just trust that they’d keep it confidential?

If the answer makes you uncomfortable, that discomfort is only going to grow over time.

Stop using consumer-grade AI to build out your most valuable ideas. They will monetize your IP the moment it becomes worth enough to justify it. 

Use a tool that was built from day one to be on your side, just siift instead.

siift's Privacy-First stance