AI Safety: What You Can Trust AI with and What You Can't. The 5 Levels of Your Data and Where the Line Runs
What can you trust artificial intelligence with, and what can you not, once it no longer merely stores your data but understands you and can influence your decisions?
The host shows that turning off training does not settle the main question: ChatGPT chats keep being stored, take thirty days to delete, and neither ChatGPT, Gemini nor Anthropic lets you delete them by topic. A separate system decides whether a request goes to moderators — in the Canadian murder case OpenAI employees refused to hand the requests to law enforcement — and Google keeps reviewed chats for up to three years. The main risk for Alexander Volchek is not advertising but a person's portrait: a system that understands how you think and what you fear gets a map of how to talk to you. The five levels of data, from green to black, provide the frame, and his own conclusion is unexpected: personal thoughts are worth more than blood tests or the access to accounts that GPT Finance asks for.
What to watch for
Key takeaways
Mail was stored in the cloud before, banks saw transactions, phones kept messages, but artificial intelligence adds a new layer — it can understand all of it. A system that can be taught to understand a person can be taught to influence one: not with sneaker ads but with advice, an argument and a phrasing that changes a decision. So this is not about paranoia but about grown-up work with AI — what to trust it with, what not to, and where the lines run.
There are countries where every phone call is recorded — in Russia it is the Yarovaya law — and the recordings sit for several years and cannot be deleted. Analysis used to require one person to listen to the calls or search a transcript for mentions of people and actions. Today a conclusion on whether a person reasoned about certain topics takes under a second, and the point is no longer speed but that the system can use who you are.
ChatGPT trains on the user's data by default, but even with training off all chats continue to be stored, and a deleted chat is deleted over thirty days, not at once. A person usually decides to delete data when a threat appears — which means the threat already exists, and the data stays available for another thirty days, perhaps longer. Neither ChatGPT, Gemini nor Anthropic lets you delete chats on a given topic; the host himself does not delete his chats and knowingly trades confidentiality for the quality of the system's work.
Every request now goes into a model that reasons, and inside it there is a safety block: protection against distillation — China runs tens of thousands of bots to train its own models on the answers of American ones — national laws and the companies' internal rules. OpenAI, Anthropic, xAI and Gemini differ in the style and quality of their answers, and the answer depends on the country, the IP address, where the account is registered, previous chats, the language and the prompt. The American companies agreed not to explain how to make bombs and chemical weapons, but otherwise the chat has to choose what to answer people in countries with different laws.
First a request is checked by automated moderators, then by a human. In the Canadian murder case the killer's ChatGPT requests went for review to OpenAI employees, who refused to hand them to law enforcement. Shared ChatGPT chats ended up on the internet in full, and Google states outright that reviewed chats may be kept for up to three years, although ordinary ones are deleted after eighteen months. A conversation with an attorney or a doctor in America cannot be brought into the open; a conversation with ChatGPT or Gemini can.
Sneaker ads are the weak level; real influence begins where the system knows what you fear, what matters to you and where your money is. Even after the chats are deleted, the system has already learned who you are: it sees weaknesses, dreams, conflicts, who influences you and where your position is weak. Influence used to cost a lot — it took a psychologist, a salesman, a political strategist — now it can be scaled, and by giving data you hand over a map of how to talk to you.
OpenAI and Google with Gemini act within US law: the AGI they are working toward must not be used against US citizens, but may be used to defend the country — and therefore against the citizens of other countries in case of war. In China every system passes through a state control system built over decades: five years ago a politically negative message in WeChat already triggered a notice of a legal violation, and cameras catch even litter dropped in the wrong place. Systems built in Iran, Russia or China are fully under control, and chats can train on their data endlessly.
There are two leaders in models — the US and China — but the US has a phenomenal lead. ChatGPT alone has a billion weekly users, all of China together has six hundred million, Gemini has more than eight hundred million monthly, and Google has a billion in search. The US has tens of times more money and infrastructure: Anthropic, xAI and OpenAI are preparing public listings, xAI through Elon Musk's SpaceX, and Goldman Sachs expects the AI infrastructure market to grow to more than seven trillion dollars within five years.
The systems are getting better at detecting attempts to bypass sanctions and access restrictions — not because of the sanctions, but because OpenAI and Anthropic have no interest in their systems being used on foreign markets and work in the interests of certain people, clans and a state. Europe has strict regulation and user rights, but no magical disappearance of data; Pavel Durov, Apple and Elon Musk say Europe demands data in order to manage people — and the host agrees. Data lives in a legal world, not in a vacuum, and you need to understand the rules of your own country.
Green — general questions like a plant disease or a choice of grain; yellow — personal thoughts, plans and drafts, which the host calls the foundation of real AGI; orange — work, contracts, code and client data. Red — finances, medicine, taxes, passports and legal disputes; black — passwords, private keys and other people's personal data without permission, which should be given to an ordinary chat only with great care. The host finds it strange that the world ranks work data above a person's thoughts.
The host has thousands of hours of his own thoughts recorded over ten-plus years, and they seem more important to him than blood counts, cholesterol or an ultrasound, although the world treats medical data as more sensitive. He calmly uploads his tax returns to ChatGPT — there is no Social Security number in them — but does not urge others to do the same. The new GPT Finance module, in his view, was built for access to the user's finances, and that is far less important information than thoughts: it is through those that a person can be influenced on a really large scale.
What this episode is about
A solo ToTheMoon episode with Alexander Volchek on AI safety and privacy. The most personal things people now write not in a diary but in ChatGPT — work, money, health, relationships, documents, fears and plans. The host says up front that artificial intelligence is not dangerous and that one should work with it more, but a chat is not a text box: it is a system to which a person hands the context of their life, and which is able to understand it.
The first part is about how data is stored. ChatGPT trains on the user's data by default, but the problem is not training: even with training off the chats are kept, a deleted chat takes thirty days to delete, and neither ChatGPT, Gemini nor Anthropic lets you delete thousands of chats on one topic. The host himself does not delete his chats — he knowingly trades confidentiality for the quality of the system's work. Chats can be exported, but they can only be analyzed with your own program through the API, in Codex or with Claude.
Next comes what happens to a request inside the thinking model. There is a safety block: protection against distillation — China, according to the host, runs tens of thousands of bots to train its own models on the answers of American ones — national laws, the companies' internal rules, and the different styles of answers at OpenAI, Anthropic, xAI and Gemini depending on the country, the IP address, the language and previous chats. A separate system decides whether a request goes to moderators: in the Canadian murder case the killer's requests went for review to OpenAI employees, who refused to hand them to law enforcement.
Google states outright that some chats are read by reviewers and that reviewed data is kept for up to three years — even though ordinary chats are deleted after eighteen months or sooner by the user's settings. The host recalls Pavel Durov's complaint about France, where data on blockchain purchases leaked from officials to criminals, the stories of leaked VKontakte messages, and reminds us that a conversation with a lawyer or a doctor in America is protected, while a conversation with ChatGPT or Gemini is not.
The central thesis is about influence. Sneaker ads are the weak level; real influence begins where the system understands how you think, what you fear and where your money is. Influence used to be expensive — it took a psychologist, a salesman, a political strategist; now it can be scaled, and by giving data a person hands over a map of how to talk to them. Systems will train more and more on each person's data, voice included: the host's own system already learns from the voices of ToTheMoon participants, and forbidding that is hard when a voice is already out on Instagram and YouTube.
Much of the time goes to countries. OpenAI and Google are tied to the US government, and by their documents AGI must not be used against US citizens, but may be used to defend the country. In China every system passes through state control, and five years ago WeChat was already sending notices for political messages. There are two leaders, the US and China, but ChatGPT has a billion weekly users against six hundred million in all of China, and the US has tens of times more money; Anthropic, xAI and OpenAI are heading for the stock market, and Goldman Sachs values the AI infrastructure market at more than seven trillion dollars within five years. Europe with its strict regulation, Russia and China are different legal worlds, and data lives in them, not in a vacuum.
The finale is the five levels of data: green (general questions), yellow (personal thoughts and drafts), orange (work, contracts, code, client data), red (finances, medicine, taxes, passports) and black (passwords, private keys, other people's personal data). The host argues with this hierarchy: thousands of hours of his recorded thoughts matter more than blood counts, while the new GPT Finance module asks for access to finances, which count for less in influence than thoughts. He himself calmly uploads his tax returns to ChatGPT — without a Social Security number — and closes with a question: is it a plus or a minus that AI understands you better and better?
The episode is useful because it moves the privacy conversation from the level of "turn off training" to the level that actually matters: not where the data sits, but who can read it and on what grounds, and what a system that has understood a person can do with that understanding. The five levels of data are a handy frame, but the host's main point runs against it: the most valuable and most vulnerable thing is not passwords or accounts but thoughts — and those are precisely what people hand to AI most willingly.
Episode transcript
The episode is in Russian; below is an English reading guide to the transcript (the full EN transcript is a machine translation). Voice matching applied to 63 segments: 0 identified, 0 mixed, 63 probable, and 0 unresolved.
Read transcript on a separate page
Loading…