A freelance architect, translator, designer or consultant usually keeps two kinds of notes: what to do, and for whom. Typed into a cloud to-do app or a consumer AI assistant, a line such as “send the revised plans to the Benali family, they are worried about the bank loan” discloses a client’s name, a project and a financial circumstance to a third party. This note sets out, as background and from primary texts, the professional-secrecy rule in French criminal law, the GDPR principles of data minimisation and data protection by default, the obligations attached to using a processor, and what three AI providers state about training on and retaining user content. It ends with what an on-device planner, AISir by HisnLabs, changes and what it leaves to the freelancer. Nothing here is legal advice, and no claim is made that any tool makes a given use lawful.
Background
Professional secrecy
French criminal law punishes the disclosure of secrets by those who hold them by profession: “La révélation d’une information à caractère secret par une personne qui en est dépositaire soit par état ou par profession, soit en raison d’une fonction ou d’une mission temporaire, est punie d’un an d’emprisonnement et de 15 000 euros d’amende” (the disclosure of secret information by a person who holds it by status or profession, or by reason of a temporary function or mission, is punishable by one year’s imprisonment and a fine of 15,000 euros) [1]. Whether a given freelancer is such a holder depends on the profession and its rules; many freelancers are bound instead, or as well, by confidentiality clauses in their contracts. In either case, the question is the same: who, other than the professional, can read what the client confided.
Data minimisation and data protection by default
Where a freelancer processes clients’ personal data in the EU, the GDPR applies. Article 5(1)(c) requires personal data to be “adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’)”. Article 25(2) turns this into a default: the controller “shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility” [2]. The UK regulator, which applies the same principle under the UK GDPR, summarises it: “identify the minimum amount of personal data you need to fulfil your purpose. You should hold that much information, but no more”, and “periodically review your processing … and delete anything you no longer need” [3].
Processors
A cloud service that stores or processes client data on a freelancer’s behalf is, in GDPR terms, normally a processor. Article 28(1) requires the controller to “use only processors providing sufficient guarantees to implement appropriate technical and organisational measures”, and Article 28(3) requires a contract under which the processor, among other things, “processes the personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country”. Article 32 lists security measures such as “the pseudonymisation and encryption of personal data” and “the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services” [2]. Whether a provider acts as a processor or as a controller in its own right, for example when it reuses content to train its models, is a legal assessment this note does not make.
Findings
What the French regulator advises for generative AI
The CNIL’s question-and-answer page of 18 July 2024 advises end users to submit only information they are authorised to share, and gives an example: “ne jamais partager d’informations confidentielles telles que des données personnelles, des données de l’entreprise ou de l’administration (en particulier lorsqu’elles sont couvertes par un secret comme le secret des affaires ou des obligations de déontologie) lors de l’utilisation d’un service grand public” (never share confidential information such as personal data or company data, in particular when covered by a secret or by professional ethics obligations, when using a consumer service). Where data may be reused by the provider, the organisation “devra mener une analyse au cas par cas pour déterminer s’il doit ou non interdire la fourniture de toute donnée personnelle”, and the CNIL notes that such prohibitions “ne seront pas nécessaires dans le cas d’un déploiement sur site (on premise) où aucune réutilisation des données par le fournisseur n’est possible” [4].
What three providers state about training and retention
OpenAI’s page on ChatGPT memory states: “We may use content that you provide to ChatGPT, including memories, to improve our models for everyone. If you’d like, you can turn this off through your Data Controls”, and adds: “we won’t train on content from ChatGPT Team and Enterprise customers” [5]. Anthropic announced on 28 August 2025: “We will train new models using data from Free, Pro, and Max accounts when this setting is on”, and “We are also extending data retention to five years, if you allow us to use your data for model training”; the updates “do not apply to services under our Commercial Terms” [6]. Google’s Gemini Apps Privacy Hub states that “A subset of chats are reviewed by human reviewers (including Google’s trained service providers)” and that reviewed chats “are retained for up to three years”, even after the user deletes the activity [7].
Regulators have acted on the legal basis for training. The Italian data protection authority announced on 20 December 2024 that it had fined OpenAI “quindici milioni di euro” (fifteen million euros), finding among other things that the company “ha trattato i dati personali degli utenti per addestrare ChatGPT senza aver prima individuato un’adeguata base giuridica” (processed users’ personal data to train ChatGPT without first identifying an adequate legal basis) [8].
| Kind of tool | Who holds the notes | Training on content | What to check |
|---|---|---|---|
| Cloud to-do or notes app | The provider’s servers | Depends on the provider’s terms | Processor terms, location of servers, deletion |
| Consumer AI assistant (individual plans) | The provider; some chats reviewed by people | OpenAI and Anthropic: may train unless the user turns it off | Training setting, retention period, human review |
| Business AI plans | The provider, under commercial terms | OpenAI Team and Enterprise, Anthropic commercial terms: not trained on, as stated | The contract (Article 28), transfers, sub-processors |
| On-device planner (AISir) | The freelancer’s Mac | None: the model runs on the Mac | The Mac’s own security, backups, what the user exports |
Implications for freelancers
Three practical consequences follow. First, minimisation applies to the planner as much as to the client file: a to-do line rarely needs a client’s full name, family circumstances or bank details to be useful. Second, the plan matters as much as the provider: the same provider can train on an individual account’s content and not on a business account’s, so a freelancer on a personal plan may be outside the protections a company’s IT department negotiated. Third, deletion is not uniform: a reviewed chat can outlive the user’s deletion of the activity [7], so “I deleted it” is a statement about the user’s view of the data, not necessarily about the provider’s copy.
Recommendations
- List the tools in which you write client names or project details, and for each one note who holds the data, where, and under which terms.
- Write tasks with the least identifying detail that still works: a project code or first name instead of a full name and circumstances.
- On consumer AI plans, check the training setting and the retention period, and do not paste material covered by a confidentiality clause.
- Where a provider processes client data for you, keep its data processing terms and its list of sub-processors with your records.
- Prefer tools that keep notes on your own device for confidential work, and protect that device: disk encryption, a strong account password, encrypted backups.
- Review and delete old notes on a schedule, as the minimisation principle expects.
Relevance to AISir
AISir 1.0.1 is a Mac planner for freelancers: a quick bar (⌥Space) that turns a note into a task, a day timeline, labels suggested by the AI, reminders, voice notes and a voice you can talk to. Its Help states that “tasks, notes, transcripts, memory and the AI all stay on this Mac. No cloud AI, no account, no telemetry”, and that tasks, call notes and transcripts “are saved in a database in Application Support/AISir on this Mac”. The model, Gemma 4 E2B, runs on the Mac and is downloaded once from Hugging Face. Web lookups are off by default; when turned on, AISir “may send a short, neutral search term” to Wikipedia and Wikidata, or to Brave Search with the user’s own key, directly from the Mac, and “never sends client names, labels, notes, tasks, transcripts, memories, email addresses or phone numbers”. The licence check contacts HisnLabs’ server only when the user clicks Activate, Check now or Deactivate, and sends the licence key, a signature and an anonymous number for the Mac, “nothing about your tasks”. Details are on the AISir page.
AISir does not make any processing lawful, and HisnLabs makes no compliance claim for it. It does not encrypt notes beyond what macOS provides, it does not decide what a freelancer may write about a client, and it cannot protect data the freelancer exports, emails or backs up elsewhere. Its small model makes mistakes and answers take about four seconds; Arabic support is weaker than French and English in places; it runs only on Apple silicon with macOS 15.
Limitations
This note is a description of texts, not legal advice, and it does not assess whether any particular freelancer is bound by professional secrecy or acts as a GDPR controller. EUR-Lex was temporarily unavailable on the day of writing, so the GDPR wording was read from an archived copy of the same page; the European Data Protection Board’s guidelines on controllers and processors could not be reached and are not cited. The ICO text concerns the UK GDPR. Provider statements are quoted as published and may change; the OpenAI page was read through an archived copy. The statement that AISir encrypts nothing beyond macOS reflects the absence of any such feature in its Help. HisnLabs makes AISir and FireAI, which readers should weigh.
How FireAI and HisnLabs fit in
Knowing which of your tools send client work to a server starts with seeing their connections. FireAI shows, per app, where each connection from your Mac goes and asks before a newly installed app connects to the internet.
FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac.
You can read the technical decisions behind it, or try FireAI for 17 days, at FireAI, by HisnLabs.
