# What Counts as Private AI?
Source: https://humanspark.ai/frameworks/what-counts-as-private-ai/

*"Cloud AI" is three different things. Match each kind of data to the lowest tier that protects it.*

**When to use:** Before anything sensitive goes near a chatbot.

1 Consumer cloud

the public square

The everyday ChatGPT, Claude or Gemini. Inputs may be logged or used for training. **Public data only.**

2 Enterprise cloud

the rented office

A business tier or API under a DPA with no-training, zero-retention terms. **Confidential data**, if that contract is genuinely in place.

3 Local

the vault

Open models on your own hardware, no third party. **Your most sensitive data**, and the simplest route when it must stay local.

> **The Data Privacy Matrix:** Public material is fine in any tier. Sensitive data never goes into a consumer tool.

> **The Tier 1 → 2 jump:** Moving from a consumer tool to a contracted one changes your data-control position substantially. The contract is only the start: personal data still needs the right GDPR and transfer safeguards.

## Related frameworks

- [Where Does It Run?](https://humanspark.ai/frameworks/where-does-it-run/) - The full venue decision behind the tiers
