Fundamentals6 min read

“I have nothing to hide” — the wrong lens for AI privacy

“I have nothing to hide” confuses privacy with secrecy. Privacy isn't concealing wrongdoing — it's keeping control of information that's yours (and other people's).

By Alexis de ONYRI

“I have nothing to hide” is the wrong lens for AI privacy, because it confuses privacy with secrecy. Privacy isn't the art of concealing wrongdoing; it's control over information that belongs to you — and, most often when you use AI at work, to others: your clients, your patients, your colleagues. That control isn't justified by guilt; it's a default stance.

Privacy isn't the same as secrecy

Legal scholar Daniel Solove dismantled the “nothing to hide” argument: reducing privacy to concealment means accepting that only wrongdoing justifies protecting yourself. Yet you close the bathroom door with nothing to hide; you seal an envelope without a plot. Privacy is the right to a closed door — not proof that you've done nothing wrong.

Diagram: a window with one half wide open (everything exposed) and the other veiled by a curtain — you choose what's seen, without having to justify it.
Drawing a curtain isn't hiding wrongdoing: it's deciding what's seen.

It's almost never only your data

At work, what you paste into AI is rarely your secret: it's a client's name, a patient's file, a colleague's salary, a partner's contract. “I have nothing to hide” doesn't hold — because it's not yours to decide to hand over someone else's data. You're its custodian, not its owner.

  • A client's name isn't your information to give away.
  • Health data concerns the person involved, not you alone.
  • A trade secret belongs to the company that entrusted it to you.
  • Even “harmless” data, cross-referenced with other bits, can re-identify someone.

Reclaim the default reflex

We used to have a simple, unspoken reflex: don't hand what's private to just anyone. AI broke it, because it's useful and pasting is fast. Reclaiming it doesn't mean giving up AI — it means deciding, by default, that sensitive data doesn't leave in the clear.

That's what ONYRI Sanitize does: it detects sensitive data and replaces it with tokens before sending, then restores the answer in your browser. You keep AI's power and control over what was entrusted to you — the goal, really, is to rediscover something essential we'd quietly forgotten: our privacy.

Frequently asked questions

Isn't privacy just for people with something to hide?
No. That's a classic confusion between privacy and secrecy. We protect private information without having done anything wrong — like closing a door or sealing an envelope. Privacy is control over what concerns you, not a confession.
If I trust the AI provider, why anonymize?
Because it's not only about trust. It's also control (data that has left is out of your hands), protecting other people's data (clients, patients), and the risk of a leak at any third party. Anonymizing keeps the choice on your side.
Isn't this a bit paranoid?
No, it's responsibility. When you handle a client's or a patient's data, you're its custodian. Anonymizing before AI isn't hiding — it's honoring the commitment not to expose what was entrusted to you.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Anonymize my prompt

Read next