Google, Meta, Microsoft and other RTB firms send RTB data about people in the U.S. to Russia and China and anyone else who signs up...many people don't see the difference. In fact for many people, the CCP having your data is far less of a risk vector than the thousands of others who get your data every single time you hit a webpage, visit the local store etc...
When Google, Meta, Microsoft etc... are selling your data thousands of times a day, and companies aggregate that to sell even sensitive information completely based on even national security sensitive categories.
https://www.iccl.ie/wp-content/uploads/2023/11/Americas-hidd...
https://www.eff.org/deeplinks/2025/01/online-behavioral-ads-...
* it's not a "random third party". You know to whom the data is being sent, and at least according to service agreements, most services don't use your data for training. If you don't trust Claude, you could trust AWS hosted version, or GPT/Deepseek hosted on Azure. Well, if you think Amazon/Microsoft is not trustworthy and they may misuse your data in these cloud services (not some random consumer facing service where you are the product), you might as well give up your digital life.
This is a claim that really irks me (when companies make it). It’s a non-denial denial. “We don’t train on user data” is NOT the same as:
- We don’t retain user data
- We don’t share user data with business partners
- We don’t mine user data for business ideas or ways to compete with our users’ products
- Etc.
Running local models don’t protect you from prompt injection attacks or hallucinations.
There are some startups building capabilities apis to limit that but most websites/apps either don’t have the resources or aren’t willing to expose those capabilities.
And as some others have mentioned, users have a track record of giving up privacy for convenience. I’m not convinced educating non-technical users about the risks involved will ward them off.
Care to elaborate with example(s) of a startups doing this?