232 APPS TRACKED · 227 CLAUSES ON FILE · 38 WITH NO CLAUSE TO QUOTE

Which privacy tools train AI on your data?

Of the 13 privacy tools on file, 8 are graded, and none of them trains on your data by default. The other 5 have a policy that doesn't say either way. The best graded is 1Password (A) and the worst is Proton (B).

13 APPS TRACKED IN THIS CATEGORY · WORST FIRST

Can a password manager, a VPN or a private browser train on what it was built not to see?

Privacy tools are sold on absence: a vault the company can’t open, a VPN that keeps no logs, a browser that doesn’t follow you. The question here is narrower: does anything the tool does hold train a model, and how hard is it to stop. The documents divide by the kind of promise they make. An inability the company describes, an undertaking given in words it could rewrite, or nothing that reaches the question.

The ones that cannot open the vault

Bitwarden’s policy defines Vault Data, says it is “encrypted using secure cryptographic keys under your control”, then states the incapacity in five words: “Bitwarden cannot access Vault Data.” Asked whether the grade was too generous, Bitwarden answered: “Correct, Bitwarden cannot access Vault data.” The reply is printed on the verdict. The A is about the vault, not the account: names, emails and payment details are collected and analysed.

The same inability, in a section about exporting your own data, where the company explains why it can’t hand you a decrypted copy. “we are unable to decrypt your Secure Data” is the whole case for the A. Outside the vault is another matter, and the same policy says “We may use your communications with us for training and quality assurance”. That reads as support-quality work, and no sentence mentions machine learning or AI, but on this site the word deserves quoting. A second sentence, under legitimate interests, goes further: 1Password processes “Contact Information, Service Data, and Diagnostic Data, to develop and train new technology”. Not the vault. But the verb is train.

The ones that undertake not to

Brave says of its Leo AI conversations: “We do not use your conversations for model training.” The sentence isn’t hedged, and the setting that clears your history is named to the URL. B and not A because it’s a promise Brave could withdraw by editing the page. Prompts still pass through its servers, and large ones are cached for minutes.

Firefox’s built-in AI runs on “small language models downloaded to your device”, and what those models see, page content, PDFs, images and tab URLs, stays there and isn’t “used for training purposes without your explicit consent”. The third-party chatbots are separately opt-in, with consent as the legal basis. Nothing starts unless you start it. Enable a chatbot and that provider’s terms govern.

DuckDuckGo builds no models and keeps no chats, so the question passes to the providers behind Duck.ai. DuckDuckGo publishes what they may not do: it has “agreements in place with all model providers”, including “not using Prompts and Outputs to develop or improve their models”. Contractual, not a stated inability. That’s the line between B and A here.

Dashlane’s answer isn’t in its privacy policy, whose own sentence on the subject is for Connecticut residents only. It’s in its security documentation: “user data must never be used to train or fine-tune AI models”, a constraint it puts beside its zero-knowledge architecture. Zero-knowledge is asserted there as a constraint on features, not shown as an inability to read your vault: an undertaking, not an architecture.

Opera’s privacy statement never uses “train”. Its AI FAQ in the help centre does, and answers no each time it asks. “Opera AI does not use information that you provide in the AI chat, nor the content of websites that you are browsing, to train AI models.” An undertaking is what a B is here. This one sits on a help page, not in the privacy statement.

Proton’s statement is explicit and scoped to one feature: “Proton Scribe does not use content data or any of your data to train its models.” For a company whose core products are end-to-end encrypted, the question largely doesn’t arise elsewhere, but the capture doesn’t speak to any other Proton AI feature, and the grade is the writing assistant’s.

The ones whose documents never reach the question

Nightfall’s only training sentence is a carve-out: data reached through “Google Workspace APIs accessed through our services” is not used for “developing, improving, or training” its models. That’s a condition of Google’s API terms, not a commitment Nightfall chose. Nightfall is a data-loss-prevention product and sees a great deal beyond Workspace; about that, the document is silent.

Nord’s policy mentions machine learning once, for a bank-monitoring feature that retrieves your transaction history and runs “an automated analysis, which may include machine learning, to derive statistical patterns that represent typical account activity”. That’s a model applied to your data to serve you, not a statement that your data trains one. No form of “train” appears.

Mullvad splits the question between a GDPR policy for the little it processes and a no-logging policy for what it refuses to keep, and neither mentions training, machine learning or artificial intelligence. The nearest thing is a denial about something adjacent, “No automated decision making (including profiling) takes place”, which is the automated-decision right, not model training. The silence sits on a stated position: it holds almost nothing to train with.

Every quotation above is the company’s own words, read from a dated, archived copy linked on each verdict or, where the entry says so, from its reply. Every grade here is the one on the company’s own entry. UNCLEAR is a finding about the document, never an accusation about the company. A policy that comes to answer the question is re-read against it. How grades are set · Right of reply