Are AI coding assistants private?
What to check
Read each tool's privacy policy and data settings. Some plans let you opt out of training, while others keep code snippets longer for abuse monitoring or support. Business and enterprise plans often include clearer data terms and admin controls.
Also check whether the tool sends your whole project or only the open files. Limiting what the assistant can see reduces exposure. Some tools let you exclude folders or files with a settings file.
- Check training opt-out settings
- Confirm data retention periods
- Review business plan terms
- Exclude sensitive folders where possible
Protecting sensitive code
Keep secrets such as API keys out of your code and out of prompts. Use environment variables and a secrets manager instead. A key pasted into a chat can end up stored in logs you cannot delete.
For highly sensitive projects, ask your organization about approved tools or self-hosted options. A written policy makes these choices easier for the whole team.
- Keep API keys out of prompts
- Use environment variables or a secrets manager
- Ask about approved tools at work
- Consider self-hosted options for sensitive code
Common mistakes
- Pasting API keys or customer data into a chat box.
- Assuming a free plan has the same protections as a business plan.
- Never reading the privacy settings after installing.
