BlogPrivacy

Privacy-First AI: Why Your Assistant's Data Handling Matters More Than Its Capabilities

An AI that knows everything about you is only as trustworthy as its data handling. A deep dive into how Winston the Pug stores memories, handles OAuth, and stays GDPR-compliant.

W
Winston the Pug
March 20265 min read

Here’s a question most people never think to ask their AI assistant provider: “Have you ever used a customer’s conversations to train your AI models?”

The honest answer, for most commercial AI assistants, is yes, or at least it was until recently. OpenAI, Anthropic, Google, and most other AI companies have historically used customer interactions as training data. It’s how models improve.

But what if you don’t want that? What if the whole point of having a personal AI is that it knows intimate details about your family, your health, your work, and you explicitly do not want any of that anywhere near a training set?

“The most capable AI in the world is still a liability if it doesn’t treat your data with the same respect you do.”


Why is data handling the real trust problem with AI assistants? #

Because most assistants were built for capability first and treat privacy as an afterthought, so the knowledge they hold about you may also improve the product.

Every AI assistant you use learns from the people who use it. OpenAI trains GPT on conversations. Anthropic uses Claude interactions for improvement. Most AI companies make this explicit in their terms, usually in paragraph eight of a document no-one reads.

The problem isn’t that these companies are malicious. The problem is that training data use and privacy protection are structurally opposed. When your AI assistant knows everything about you, and that knowledge might be used to improve the product, there’s an inherent tension that no amount of policy wording fully resolves.

This is the core problem with most AI assistants: they weren’t built for privacy-first use cases. They were built for capability, and privacy was added as an afterthought.


What data does Winston the Pug store, and where? #

Three categories: conversation history, structured memories, and OAuth tokens, each stored in an encrypted, per-user store and never used to train AI models.

There are three categories of data Winston the Pug touches:

1. Conversation history. Your chat with Winston the Pug is stored in our system. It’s used to power your AI’s memory, so it can reference past conversations, and to provide the service you’ve paid for. It is never used to train AI models. This is contractually guaranteed, not just policy.

2. Memories. These are the structured facts Winston the Pug extracts and stores about you. Your timezone. Your partner’s name. Your child’s school schedule. The plumber you hired last October. Stored in an encrypted memory store, isolated per user, powered by GraphANN™, the ICO-registered vector store.

3. OAuth tokens. When you connect Gmail, Calendar, or Drive, you authorise Winston the Pug via OAuth. We receive an access token and a refresh token. Both are encrypted at rest. We only request the minimum permissions needed to do what you asked.


Memory, built for privacy #

Most AI companies use third-party memory databases run by other vendors. These are good products, but they weren’t designed for user isolation as a primary constraint.

Winston the Pug runs its own memory store, designed from the ground up for user isolation as the default. Winston’s memory is powered by GraphANN™, the ICO-registered vector store. Each account’s memory is encrypted separately. There is no cross-contamination, no shared infrastructure risk, no “tenant isolation” feature you have to pay extra for.

“Privacy isn’t a feature we added. It’s the architecture.”


How does Winston the Pug comply with GDPR? #

Winston the Pug is built to meet GDPR obligations: your conversations are never used to train AI models, OAuth tokens are encrypted at rest, and your memory store is isolated per user.

We also maintain a designated Data Protection Officer, publish transparency reports, and keep a detailed data processing register as required under GDPR. Every right the regulation grants you is wired into the dashboard, not buried in a support queue.


Your rights, fully supported #

Under GDPR, you have the right to:

  • Access your data
  • Correct it
  • Delete it
  • Restrict processing
  • Port it to another service

All of these are implemented in Winston the Pug’s dashboard, with no email to support required, no waiting period. Your data, your control, immediately.

“We make it easy to leave because we believe the best relationships with AI assistants are built on genuine trust, not data lock-in.”


What does deleting your account actually delete? #

Everything: your memory store is wiped within seconds, OAuth tokens are revoked immediately, and conversation logs are purged within 30 days, with no recoverable soft-delete.

Most services claim to delete your data when you ask. The reality is more complicated: backups, logs, cached copies, replica databases. At Winston the Pug, deletion is immediate and thorough.

When you delete your account:

  1. Your memory store is wiped within seconds
  2. All OAuth tokens are revoked immediately
  3. Conversation logs are purged within 30 days

There is no “soft delete” that keeps your data recoverable. GDPR’s right to erasure requires deletion without undue delay; we exceed that requirement.

You can export everything first: a complete download of your memories, conversation history, and profile data in standard JSON format. Then, when you’re certain, delete.

Related reading: see how an assistant with memory keeps recall private to you, how a proactive assistant stays respectful, and what to look for when choosing an AI personal assistant.


Privacy isn’t a feature. It’s the architecture. Try Winston the Pug. Your data stays yours.

Get started

Ready to try Winston the Pug?

Available on WhatsApp and Telegram, with Signal, Discord and Slack on the way. No new app needed.

View Pricing