logoalt Hacker News

carschnotoday at 10:31 AM2 repliesview on HN

> On top of that, I exported my location timeline from Google Maps, my Uber trips, my bank transactions, and Shazam history. I would ask Claude Code to start with the photos and then gradually give it access to the different data exports.

Is anyone else feeling uncomfortable with that? It is a great project and I don't want to bash it with general concerns, but sharing all my financial and location details with any service seems like opening the floodgates to my house.

My concern is not even strictly related to AI, but about sharing all my most private data with any service. There is always a significant chance all of it is leaked sooner or later.


Replies

svattoday at 3:58 PM

> There is always a significant chance all of it is leaked sooner or later.

As an adversarial/worst-case model, it can be useful to think of every service as potentially storing forever all the data that you ever give it access to. As a practical matter, services have terms of service that they follow. If your Claude Code terms say that your data will not be used for training, you can be reasonably confident that they will not be, and storing the raw inputs forever (as suggested by “significant chance all of it is leaked sooner or later”) would be even more unlikely. (For example, Google has entire teams dedicated to compliance with users' “wipeout” settings. You can take a look at https://myactivity.google.com and https://myadcenter.google.com to see some of what Google knows and thinks about you, and if you've chosen "Auto-Delete after 3 months" or whatever, you can be very sure it will be gone after that time. Every single team that stores user data is required to comply with this.)

I do think the services make it harder than it should be, to find out what the terms are — for a given usage of their services whether and for how long the details will be stored by them. Just saying that you can find this out and generally rely on it at least at the time (at a reasonable threat model, e.g. not treating the service as a malicious adversary having a giant law-breaking conspiracy that has never been exposed).

subpixeltoday at 12:08 PM

Not uncomfortable just deeply uninterested. I’m into preserving family stories - I’m not into the navel-gazing that is all manner of ‘quantified self’ endeavors