How to Vet a New App or AI Tool Before Using It
This is a different question than spotting a fake or scam app — a brand-new app or AI tool can be completely legitimate, built by a real team, with no intent to steal anything, and still be a bad place to put your data. Legitimacy and good data handling aren’t the same thing. Here’s what to actually check before you connect an account, upload a file, or paste something sensitive into a new tool.
Read the Data-Sharing Section, Not the Whole Privacy Policy
Nobody reads a full privacy policy, and you don’t need to — you need one section: what data gets shared with third parties, and under what conditions. Search the document for “third party,” “share,” or “sell.” A policy that’s vague here (“we may share information with partners to improve our services”) is worth more caution than one that names specific categories of data and specific reasons.
- If the policy doesn’t mention data retention at all — how long they keep your data after you stop using the app — that’s a gap, not a neutral omission
- A policy last updated years ago on an app that’s actively adding features is a sign the legal side hasn’t kept pace with what the product actually does now
Check Permissions Against What the Tool Actually Needs
The same permission-matching logic from spotting scam apps applies here, just for a different reason — not fraud detection, but data minimization. A note-taking app asking for contacts access, or a photo editor asking for microphone access, has no functional reason for that request even when the company itself is completely real. Decline optional permissions by default and grant them individually later if a specific feature actually needs one, instead of accepting everything during onboarding just to get past the setup screen.
AI Tools Specifically: Check the Training Default
This is the one most people skip. Many AI tools use your inputs — your prompts, uploaded documents, code — to train future models unless you explicitly opt out, and the opt-out setting is often buried a few menus deep rather than surfaced during signup.
- Search the tool’s settings for “data usage,” “model training,” or “improve our models” specifically, and toggle it off if you don’t want your inputs used that way
- Business or team tiers on the same tool often have different default data handling than the free or individual consumer tier — if you’re using a tool for client work, check whether the plan you’re actually on matches the data-handling terms you assumed applied
- Treat anything you wouldn’t want to see resurface in someone else’s output as off-limits for a free-tier AI tool by default, until you’ve confirmed otherwise in writing, not just assumed it from the marketing page
How Long the Company Has Existed Changes the Risk
A five-person startup two months old and a company operating for several years carry a different risk profile for the exact same privacy policy text, even when the wording is identical. A newer, smaller team is more likely to pivot, get acquired, or shut down — any of which can change what happens to data already collected, sometimes with only a brief email notice buried in a policy update. That doesn’t mean avoiding every new tool, but it does mean treating what you hand a brand-new app differently than what you’d hand an established one, at least until it’s proven stable.
Test With Throwaway Data First
Before connecting a real account, a real document, or a real client file, run the tool once with something low-stakes — a test document, a secondary email, a sample project instead of a live one. This does two things: it shows you how the tool actually behaves with your data before you’ve committed anything sensitive, and it gives you a clean way to check later whether test data you can identify shows up anywhere it shouldn’t.
Confirm There’s a Real Way to Delete Your Data
Search specifically for a data deletion or account deletion option before you need it, not after. A tool that makes account deletion easy to find and genuinely removes your data is a different company culturally than one that requires an email request, offers no confirmation, or hides the option behind multiple support tickets — the friction in the deletion process is often a more honest signal about a company’s priorities than anything in their marketing copy.
A Common Mistake: Granting Everything to Get Past Onboarding
Most people accept every permission request and toggle during initial setup just to reach the app faster, meaning to revisit it later — and then never do. If you can’t commit to reviewing settings afterward, the safer default is declining optional permissions during onboarding itself, since “later” rarely actually happens once the tool is already working for you.
Weigh It Against What the Tool Is Actually Worth to You
Not every tool needs this level of scrutiny — a free game with no account system carries a different risk than an AI tool you’re feeding client documents or a finance app connected to your bank. Match the depth of vetting to what’s actually at stake; if you’re deciding whether a specific AI subscription is worth paying for in the first place, our AI apps worth paying for guide covers that separate question once you’ve confirmed the data-handling side checks out.
A password manager sits at the far end of this scrutiny scale, since it’s holding the single most sensitive category of data by design — our best password managers guide covers which ones are actually worth trusting with that, and when the free option already built into your browser stays genuinely enough.