Privacy & trust

How do you evaluate whether an AI coaching tool is privacy-safe?

Ask who the tool works for. A privacy-safe AI coaching tool cannot read direct messages between people, keeps what each person types private to them, shows leadership only aggregate themes that can't be traced to anyone, masks personal information before it reaches a language model, and has zero-retention terms with its model providers. Then check SOC 2 Type II, hosting, deletion, and what employees are told in plain language.

October 1, 20266 min readPrivacyAI CoachingBuyer's Guide

Somebody always asks it in #general within a day of rollout: "Wait, can this thing read my DMs?"

How that question gets answered tells you most of what you need to know. If the answer is a clear "no, it can't," people shrug and get on with it. If the answer is "well, it depends on the settings," the tool is already in trouble. People start writing differently. The honest messages go somewhere else. And a tool meant to help with the conversations at work ends up making them harder.

This is a checklist for evaluating AI coaching and conversation tools before you get to that moment. It works for a security review, an HR review, or just your own gut check.

Start with one question: who does this tool work for?

Every other question is a version of this one. A tool that works for the person using it treats privacy as part of the design: it can't read DMs, it doesn't report on individuals, and what you type stays yours. A tool that works for someone watching treats privacy as a setting that an admin can change.

You can usually tell which one you're looking at by how the vendor answers the questions below. Clear, short answers are a good sign. Long answers full of "configurable" are worth a second look.

The checklist

1. What data can it read?

Get a specific list. Public channels? Only channels someone has invited it to? Private channels? Direct messages between people? Calendar? Meeting recordings? Email?

The line that matters most is DMs. Direct messages are where people vent after a rough standup, ask the question they're embarrassed to ask in public, and work out what they think before they say it. A tool that can read them, even "for context," will change behavior once people find out. Ask whether DM access is impossible by design or just turned off by default. Those are very different answers.

2. Who sees what?

Walk through it person by person. When an employee types something to the tool, who else can see it? Their manager? HR? An admin? The vendor's support team?

For a tool meant to help someone prepare for a hard conversation, the answer should be nobody. The draft of the message you're nervous about sending, the question about whether you're overreacting, the admission that you've been avoiding someone for three weeks: if any of that can reach your manager, you won't type it.

3. Aggregate vs individual views

Most tools offer leadership some kind of view. Ask exactly what it shows.

Aggregate themes ("the team finds the roadmap unclear") can be useful and safe. Individual views (what one person said, how one person is "trending") turn the tool into a reporting system, whatever the marketing calls it. Also ask how small a group can be before an aggregate effectively points at one person. A "team insight" drawn from a team of three isn't anonymous.

4. Model provider and retention

Almost every AI tool sends text to a large language model run by someone else. Ask which providers the vendor uses, and whether they have zero-retention terms with each one, meaning the provider doesn't store the content after responding and doesn't train on it.

"We don't train on your data" is a narrower promise than zero retention. Ask for both, in writing.

5. Personal information handling

Ask what happens to names, email addresses, and other personal details before text reaches the model. Some tools mask personal information first, so the model works with placeholders. Others send everything as-is. You want to know which.

6. Hosting

Where is the data stored and processed? Which country, which cloud provider? If you have data residency requirements, ask early, before anyone gets attached to the product.

7. SOC 2

Ask whether the vendor has a SOC 2 report, and which type. Type I says controls existed on one day. Type II says an auditor checked they actually worked over a period of months. Ask to see the report. Then remember that SOC 2 covers security controls, not product design. A tool can pass SOC 2 and still show managers every message their team sends to it.

8. Deletion

What happens when someone leaves the company? When the contract ends? When an employee asks for their data to be deleted? How long until it's gone, including backups? "We'll handle that if it comes up" isn't a deletion policy.

9. Consent and transparency for employees

Can an employee find out, in plain language, what the tool reads and who sees what? Is there a page you can link in the rollout message? Do people choose to use it, or is it switched on around them?

A good test: write the two-sentence explanation you'd post in #general. If you can't write it without hedging, you don't understand the tool well enough yet, or the tool isn't as clear as it should be.

Questions to ask any vendor

Bring this table to the call. You're listening for short, specific answers.

Question Good answer Red flag
Can the tool read direct messages between people? No, by design "Only if enabled," or "only for context"
Who can see what an employee types to the tool? Only that employee Managers, HR, or admins "with permission"
What does leadership see? Aggregate themes, never traceable to a person Per-person dashboards, ratings, or rankings
How small can a group be in an aggregate view? A clear minimum, explained without prompting No minimum, or "we haven't needed one"
Which model providers do you use, and what are the retention terms? Named providers, zero-retention terms with each "Industry standard," or no names
Is personal information masked before it reaches the model? Yes, and here's how "The model provider handles security"
Where is data hosted? A specific country and cloud provider "In the cloud"
Do you have SOC 2? Which type? Type II, with the report available "In progress," or Type I only with no date for Type II
How is data deleted when someone leaves or asks? A defined process and timeline, including backups "Contact support"
What do employees see about how the tool works? A plain-language page you can link Nothing written for employees

Red flags

Some answers should end the evaluation, or at least send it back to the start:

  • DM access of any kind. Including "optional," "admin-controlled," or "anonymized."
  • Individual reporting to managers or HR, especially anything that rates employees or predicts who might leave. That's surveillance, whatever the slide says.
  • Sentiment analysis on named people.
  • Privacy that lives only in a policy. If an admin can flip a setting and see more, assume someone eventually will.
  • No named model providers. If they can't tell you where the text goes, they may not know.
  • Hedged answers to direct questions. "It depends on your configuration" is sometimes fine. On DMs and individual visibility, it isn't.
  • A rollout plan that skips employees. If the vendor suggests not telling people what the tool can see, walk away.

How Ren answers these

For reference, here's how Ren, an AI app for the conversations between people at work in Slack and Microsoft Teams, answers the core questions. Ren cannot read direct messages between people. Your conversations with Ren are private and never shared with your manager or HR. The team-wide view is aggregate and never traceable to a person. Ren is SOC 2 Type II, hosted in the US, masks personal information before it reaches a language model, and has zero-retention terms with its model providers. The full detail is on the trust page.

Use the same table with any vendor you're comparing, Ren included, and hold everyone to the same answers.


Related: Privacy-first manager coaching, explained · AI coaching platforms compared · How AI in Slack can help you run better 1:1s · Trust and security at Ren

If this is the standard you want on your team

Send it to them. In your own voice.

One click opens a draft in your email or copies the share text, edit it, send it from your own address. We never email anyone on your behalf.

Share with your team

Send this in your voice.

We don’t send the email. You do, from your own account, so it lands the way it should.

Try Ren

Push too hard, or go too easy? Ren is the third way, challenge with care.

Ren surfaces the conversation that matters, before it becomesthe next regretted exit, the slow-burn morale problem, or the deal that didn’t close. Built on The Accountability Dial™. Lives inside Slack and Teams. Private by design.

More guides

Ren logo

Start free

No credit card, and about two minutes to set up.

or use your email

Your conversations with Ren are always private.