by PrivScan (LX AI)

Blog · Home

Privacy policy gaps AI products usually find first

A privacy-policy gap is any place where your published notice does not match what the product actually does with personal data. AI features create gaps quickly, because they add collection points that a template written before the feature existed never mentions.

Key takeaways

Where AI products leak disclosure gaps

  1. Prompt and upload handling. Is the text a user types sent to a model provider? Retained? Used for training? The notice has to say.
  2. Inference logging. Logs kept for debugging or abuse monitoring are still personal data.
  3. New categories, old notice. Images, audio and files are newer categories than most templates list.
  4. Automated decision-making. Where output materially affects a person, the logic and the consequences need describing.
  5. Transfers. Model inference often happens in another jurisdiction; that is a transfer to disclose.
  6. Retention for AI data. Prompts and outputs rarely share the retention period of your account data.

How to close them

Walk the product the way a user would and write down every place personal data enters it. Compare that list against the notice line by line. Where the notice is silent, add the category, the purpose and the retention. Where the notice is vague, name the category instead.

How PrivScan helps

PrivScan scans the site or app for the consumer-privacy gaps above — cookies, consent, trackers and data collection — and returns them as a prioritised checklist, so the gap between what the product does and what the notice says becomes a work queue rather than a guess.

Frequently asked questions

Is a prompt personal data?

It can be. If the prompt can be linked to an identified or identifiable person, it falls in scope and needs to be covered by the notice.

Do we need to name our model provider?

Recipients of personal data are normally disclosed. Naming the provider, or at least the category and location, is the safer disclosure.

Do we have to describe training use?

If user content is used to train or improve a model, say so plainly. Silence on that point is one of the most-read lines of any AI privacy notice.

How often should the policy be revisited?

On every material change to what you collect or which providers you use — for AI products, that is usually more often than once a year.

Can PrivScan write the policy for us?

No. It reports the gaps it can detect from the site and your description. Drafting the disclosure still needs a human.

Is the output a compliance certificate?

No. It is a decision-support checklist, and a reviewer still has to confirm the facts.

References

Try the product: PrivScan

2026-09-20 · primary sources only · no fabricated traffic metrics · decision-support only