Overview
How might we design data ownership & control so people can trust and act on AI output?
When to use
- Essential for all AI applications where user trust depends on transparency and control over personal data, ensuring compliance with privacy regulations and building user confidence.
When to skip
- Ephemeral tools that store nothing durable and only need a clear “we don’t keep this” line.
- Enterprise admin-only consoles where end users correctly have no deletion rights.
- When legal cannot honor a control you show, never advertise deletion you cannot complete.
Rules
Settings that claim “don’t train on my data” with no confirmation of scope or lag.
Delete chat that still leaves embeddings or admin logs undisclosed.
Dark-pattern retention defaults that require digging to turn off memory or sharing.
Export that omits the formats users need to leave the product.
Evidence
| Product | Implementation |
|---|---|
| ChatGPT | Data Controls for training opt-out, history, and memory management. |
| Claude | Privacy and training settings with project/workspace data boundaries. |
| Google Account | Activity and AI feature controls tied to account-wide data settings. |
| Apple Privacy Dashboard-style patterns | Permission and data-use summaries users can audit over time. |

