— Journal · 4 MIN READ · Privacy

Apple will train its AI on your data — if you say yes

With iOS 27, Apple's promise that your data is never used to train its models gained a clause: unless you choose to help. Opt-in is the decent version of this. It is also a reminder that a privacy promise written in a policy is only as strong as the next policy.

Apple will train its AI on your data — if you say yes

Apple had a sentence it liked to repeat about its AI: "Your private personal data and interactions are never used to train our foundation models." With iOS 27, which started rolling out on 14 September, the full stop moved. The sentence now continues: "unless you explicitly choose to help improve them."

When you turn on the new Siri, a prompt asks whether you want to help improve it. You can agree, or you can pick "Not now" — which, as heise points out, is the visually quieter of the two buttons. According to the pre-release privacy policy, those who say yes share their whole interaction with Siri and dictation, including the audio and the transcripts. It is not linked to the Apple Account, and audio is reviewed only by Apple employees. You can change your mind later in Settings, under Analytics & Improvements.

Opt-in is the decent version

Let's be fair first. This is opt-in, not opt-out. Nothing is collected until you say yes, and a lot of the industry would have done this the other way round and called it a feature. Models get better on real conversations; a company that wants a good assistant has a reason to ask. Asking is the honest way to get it.

The problem is not the decision. It is what the decision reveals about where privacy lived.

A promise in a policy is a promise until the next policy

"Never" was a statement of intent, written in a document the same company can edit. It held until the product needed something else, and then it gained a clause. That is not a scandal; it is how policy text works. But it means the guarantee was always a sentence, not a property of the system.

There is a difference between privacy as a promise — we will not look — and privacy as architecture — we cannot look, because the data never reaches us. The first can be renegotiated with a dialog box. The second would need a rebuild.

And dialog boxes are designed. Which button is bold, which one says "Not now" instead of "No", when the question appears — at setup, when you are trying to get something working — all of that is product design, and it moves consent rates. We have written before about cookie banners for the same reason: consent collected by an interface built to collect it is technically consent and practically a nudge.

What we do instead, where we can

We are a small studio, not Apple, and we do not train foundation models. But we make the same kind of decision on a smaller scale, and we try to make it in the architecture.

  • RVer AI, the content assistant inside our clinical VR system, runs inside the equipment itself. What a service learns stays in that service; nothing is pooled across clients and nothing trains anything central. There is no cloud and no account to consent to, because there is nothing to send.
  • Our website analytics collect no identifiers. There was no banner to click, because there was nothing to ask permission for.
  • And when a promise on our own site could not be kept on a bad day — a fixed reply time — we took it out, rather than let the text say something the system could not guarantee.

None of this is free. On-device models are smaller; aggregate analytics answer fewer questions; learning per service learns slower. Those are real costs, and we choose to pay them where the data is sensitive enough to justify it.

If you build products

Decide what you will never collect at the architecture level, before anyone writes the privacy policy. If a promise matters, make it true by construction, so the next product meeting cannot quietly add a clause. And for everything you do need to ask for, ask like Apple did — opt-in, reversible — but design the question as if the user were someone you respect, because they are.

Apple chose the decent path here. The lesson for everyone else is simpler: the only privacy promise that survives a roadmap is the one the system cannot break.

— The journal, by email

One email when something worth reading goes up.

No sequences, no sharing, unsubscribe in one click. See our privacy policy.

— Read next
— Next steps

Tell us what was only ever described.

info@amplifiedcreations.com