← All guides

Knowledge & actions · Explore this field ↗ · Governance · 2 min read

Privacy by conversation

Transcripts feel informal; they are still records containing identity, intent, and often sensitive detail.

01

Chat invites oversharing

People explain problems in narrative form and include names, account details, health information, or third-party data that a form would never request. The interface should warn before likely sensitive collection, provide redaction guidance, and avoid asking users to paste secrets. Detecting sensitive text can support minimization, but it does not replace purpose limitation.

02

Separate operational uses

Service delivery, quality review, fraud investigation, legal retention, and model improvement are different purposes. Record them separately. A user’s consent to keep a support case is not automatically consent to train a model. Where logs are necessary, restrict access, encrypt storage, define retention, and preserve deletion links across indexes and derived summaries.

03

Human handoff changes access

Tell the user when a teammate will see the transcript and what else will be attached. Send the minimum account context needed to continue. Internal notes should not flow back into a model response unless explicitly allowed. Shared workstations and kiosks need immediate transcript clearing and conservative authentication.

04

Operator note

Map every transcript field from capture to deletion. Include model provider, observability vendor, help desk, data warehouse, and backups. Test export and deletion across derived embeddings and summaries. If deletion cannot propagate, do not promise that it does.

05

Minimize at the moment of collection

Privacy notices are most useful when the user is about to cross a boundary. Before asking for an order number, say what it will retrieve. Before transferring to a person, say that the transcript and account context will be shared. Before accepting an attachment, describe prohibited secrets and retention. Provide a secure field for credentials or payment details instead of inviting them into chat. These local explanations complement the full privacy notice and reduce accidental oversharing more effectively than a link shown only at the start.

Primary reading

Sources and limits

These links support the architecture, policy, or product behavior discussed above. Vendor documentation describes vendor features; it is not independent proof of performance. Current details should be rechecked before a production decision.

  1. NIST — Privacy Framework
  2. Amazon Lex — Conversation logs

Find your next good decision.

Start typing to explore the guides.

76 sourced guides · Escape to close