Privacy & trust
How do you evaluate whether an AI coaching tool is privacy-safe?
Ask who the tool works for. A privacy-safe AI coaching tool cannot read direct messages between people, keeps what each person types private to them, shows leadership only aggregate themes that can't be traced to anyone, masks personal information before it reaches a language model, and has zero-retention terms with its model providers. Then check SOC 2 Type II, hosting, deletion, and what employees are told in plain language.
Somebody always asks it in #general within a day of rollout: "Wait, can this thing read my DMs?"
How that question gets answered tells you most of what you need to know. If the answer is a clear "no, it can't," people shrug and get on with it. If the answer is "well, it depends on the settings," the tool is already in trouble. People start writing differently. The honest messages go somewhere else. And a tool meant to help with the conversations at work ends up making them harder.
This is a checklist for evaluating AI coaching and conversation tools before you get to that moment. It works for a security review, an HR review, or just your own gut check.
Start with one question: who does this tool work for?
Every other question is a version of this one. A tool that works for the person using it treats privacy as part of the design: it can't read DMs, it doesn't report on individuals, and what you type stays yours. A tool that works for someone watching treats privacy as a setting that an admin can change.
You can usually tell which one you're looking at by how the vendor answers the questions below. Clear, short answers are a good sign. Long answers full of "configurable" are worth a second look.
The checklist
1. What data can it read?
Get a specific list. Public channels? Only channels someone has invited it to? Private channels? Direct messages between people? Calendar? Meeting recordings? Email?
The line that matters most is DMs. Direct messages are where people vent after a rough standup, ask the question they're embarrassed to ask in public, and work out what they think before they say it. A tool that can read them, even "for context," will change behavior once people find out. Ask whether DM access is impossible by design or just turned off by default. Those are very different answers.
2. Who sees what?
Walk through it person by person. When an employee types something to the tool, who else can see it? Their manager? HR? An admin? The vendor's support team?
For a tool meant to help someone prepare for a hard conversation, the answer should be nobody. The draft of the message you're nervous about sending, the question about whether you're overreacting, the admission that you've been avoiding someone for three weeks: if any of that can reach your manager, you won't type it.
3. Aggregate vs individual views
Most tools offer leadership some kind of view. Ask exactly what it shows.
Aggregate themes ("the team finds the roadmap unclear") can be useful and safe. Individual views (what one person said, how one person is "trending") turn the tool into a reporting system, whatever the marketing calls it. Also ask how small a group can be before an aggregate effectively points at one person. A "team insight" drawn from a team of three isn't anonymous.
4. Model provider and retention
Almost every AI tool sends text to a large language model run by someone else. Ask which providers the vendor uses, and whether they have zero-retention terms with each one, meaning the provider doesn't store the content after responding and doesn't train on it.
"We don't train on your data" is a narrower promise than zero retention. Ask for both, in writing.
5. Personal information handling
Ask what happens to names, email addresses, and other personal details before text reaches the model. Some tools mask personal information first, so the model works with placeholders. Others send everything as-is. You want to know which.
6. Hosting
Where is the data stored and processed? Which country, which cloud provider? If you have data residency requirements, ask early, before anyone gets attached to the product.
7. SOC 2
Ask whether the vendor has a SOC 2 report, and which type. Type I says controls existed on one day. Type II says an auditor checked they actually worked over a period of months. Ask to see the report. Then remember that SOC 2 covers security controls, not product design. A tool can pass SOC 2 and still show managers every message their team sends to it.
8. Deletion
What happens when someone leaves the company? When the contract ends? When an employee asks for their data to be deleted? How long until it's gone, including backups? "We'll handle that if it comes up" isn't a deletion policy.
9. Consent and transparency for employees
Can an employee find out, in plain language, what the tool reads and who sees what? Is there a page you can link in the rollout message? Do people choose to use it, or is it switched on around them?
A good test: write the two-sentence explanation you'd post in #general. If you can't write it without hedging, you don't understand the tool well enough yet, or the tool isn't as clear as it should be.
Questions to ask any vendor
Bring this table to the call. You're listening for short, specific answers.
| Question | Good answer | Red flag |
|---|---|---|
| Can the tool read direct messages between people? | No, by design | "Only if enabled," or "only for context" |
| Who can see what an employee types to the tool? | Only that employee | Managers, HR, or admins "with permission" |
| What does leadership see? | Aggregate themes, never traceable to a person | Per-person dashboards, ratings, or rankings |
| How small can a group be in an aggregate view? | A clear minimum, explained without prompting | No minimum, or "we haven't needed one" |
| Which model providers do you use, and what are the retention terms? | Named providers, zero-retention terms with each | "Industry standard," or no names |
| Is personal information masked before it reaches the model? | Yes, and here's how | "The model provider handles security" |
| Where is data hosted? | A specific country and cloud provider | "In the cloud" |
| Do you have SOC 2? Which type? | Type II, with the report available | "In progress," or Type I only with no date for Type II |
| How is data deleted when someone leaves or asks? | A defined process and timeline, including backups | "Contact support" |
| What do employees see about how the tool works? | A plain-language page you can link | Nothing written for employees |
Red flags
Some answers should end the evaluation, or at least send it back to the start:
- DM access of any kind. Including "optional," "admin-controlled," or "anonymized."
- Individual reporting to managers or HR, especially anything that rates employees or predicts who might leave. That's surveillance, whatever the slide says.
- Sentiment analysis on named people.
- Privacy that lives only in a policy. If an admin can flip a setting and see more, assume someone eventually will.
- No named model providers. If they can't tell you where the text goes, they may not know.
- Hedged answers to direct questions. "It depends on your configuration" is sometimes fine. On DMs and individual visibility, it isn't.
- A rollout plan that skips employees. If the vendor suggests not telling people what the tool can see, walk away.
How Ren answers these
For reference, here's how Ren, an AI app for the conversations between people at work in Slack and Microsoft Teams, answers the core questions. Ren cannot read direct messages between people. Your conversations with Ren are private and never shared with your manager or HR. The team-wide view is aggregate and never traceable to a person. Ren is SOC 2 Type II, hosted in the US, masks personal information before it reaches a language model, and has zero-retention terms with its model providers. The full detail is on the trust page.
Use the same table with any vendor you're comparing, Ren included, and hold everyone to the same answers.
Related: Privacy-first manager coaching, explained · AI coaching platforms compared · How AI in Slack can help you run better 1:1s · Trust and security at Ren
If this is the standard you want on your team
Send it to them. In your own voice.
One click opens a draft in your email or copies the share text, edit it, send it from your own address. We never email anyone on your behalf.
More guides
- Privacy & trustLegal-defensible 1:1 documentation, without surveilling your teamHow to build a record of manager decisions that holds up in an employment claim, without recording conversations, without monitoring employees, and without losing the trust that makes accountability possible in the first place.
- Privacy & trustPrivacy-first manager coaching, explainedManagement software is splitting into two camps: monitoring tools that managers ignore, and coaching tools managers trust. Here's the design that separates them, why it matters legally, and why it's the only kind that actually gets used.
- Guides for managersHow to use The Accountability Dial™ to draft hard feedbackA working playbook for the five stages of The Accountability Dial (Mention, Invitation, Conversation, Boundary, Limit), with example scripts you can adapt for the conversation you've been avoiding.