AI on your data: personalisation without surveillance

We want an AI that knows us — but knowing shouldn't require watching. There's a technical difference, not a philosophical one, between a model trained on everyone's data and a model that learns only from you. This is that difference, told through the sources.

Editorial illustration of a personal AI model learning inside your device, protected by a privacy perimeter

The promise of modern artificial intelligence is seductive: an assistant that understands you. That knows how you write, what you search for, what you need before you ask for it. But there's an uncomfortable question hidden beneath that promise. For a machine to know you this well, who had to look at your data — and what stays stored there, forever, after they've looked?

The usual answer over the last decade has been to build global models: a single artificial brain, trained on mountains of data collected from millions of people, hosted in a data centre somewhere. It's powerful. But it isn't neutral from a privacy standpoint — and the reason is technical, not ideological.

The model that remembers too much

Contrary to what intuition suggests, a language model doesn't "summarise" its training data and discard the original. Part of it stays memorised — and, with the right prompt, the model returns it verbatim. In a landmark investigation into this phenomenon, a team led by Nicholas Carlini measured it and concluded that "[m]emorization significantly grows as we increase (1) the capacity of a model, (2) the number of times an example has been duplicated, and (3) the number of tokens of context used to prompt the model" [1]. In other words: the bigger and more heavily trained the model, the more verbatim data it can reproduce. An address, a number, a sentence that only ever existed in one place — they can come back out.

European regulators have grasped the implication. In the opinion it issued in December 2024, the European Data Protection Board (EDPB) was clear: an AI model trained on personal data cannot, in every case, be considered anonymous [2]. Anonymisation has to be assessed case by case, and only holds up when it is "very unlikely to directly or indirectly identify individuals whose data was used to create the model" and equally unlikely "to extract such personal data from the model through queries" [2]. That's a high bar. And many global models don't clear it.

The false dilemma: personalise OR protect

This is where a lazy dilemma usually gets born: either you have a useful AI that learns with you, or you have privacy — pick one. That's false. Engineering solved the essence of this problem years ago, and it's called federated learning.

The idea is an elegant inversion. Instead of bringing your data to the model, you bring the model to your data. Google researchers Brendan McMahan and Daniel Ramage described it like this: "your device downloads the current model, improves it by learning from data on your phone, and then summarizes the changes as a small focused update" — and only that update, encrypted, leaves the device; "all the training data remains on your device" [3]. The model learns your pattern without your pattern ever leaving home.

This changes the nature of personalisation. It stops being a single model that knows a little about everyone — and becomes, at the limit, a model of your own, tuned to your behaviour, that doesn't need to compare you with strangers to understand you. Personalising and centralising stop being the same thing.

A personal model learns inside the user's device, with data remaining within a privacy perimeter

Why this matters (especially) for your money

No data is as revealing as financial data. Your statement tells where you are, what you spend on, who you live with, whether you're ill, whether you're struggling. That's why distrust sharpens when AI gets close to your wallet — and the numbers confirm it. A 2024 Cisco survey found that 30% of generative AI users have already entered personal or confidential information into these tools, while 84% fear that the data they share will end up public [4]. We want the convenience; we fear the price.

On the specific terrain of money, the line is even sharper. A TD Bank survey found that although 78% of Americans already use AI tools daily, only 18% would trust AI to make financial recommendations on its own [5]. People aren't rejecting the technology — they're rejecting the opacity. Kiran Vuppu, TD's U.S. Chief Information Officer, put it like this: "Consumers are clearly signaling that transparency, security and human accountability are not optional features; they're foundational requirements" [5].

And trust isn't a decorative extra — it's what unlocks adoption. Harvey Jang, Cisco's Vice President and Chief Privacy Officer, noted that "nearly 60% of consumers aware of privacy laws are comfortable using AI," and that "broadening awareness and educating consumers about their privacy rights will empower them to make informed decisions" [4]. Boiled down: people who understand how their data is protected use the technology with less fear.

How AtivaMoney sees this

AtivaMoney was built on the right side of this dilemma. Ours is a privacy-first, self-hosted philosophy for managing your money in Portugal: your financial data is yours, not our product. We don't make money by selling it, or by feeding it to a global model to train another company's brain. We make money from your subscription. That's a difference in business model — and, in the end, the business model is what decides what happens to your data.

In practice, that translates into concrete choices:

  • Individualised categorisation: the way your transactions get organised learns from your history and your corrections — not from a template profile built out of millions of strangers. The pattern that matters is yours.
  • Minimisation, not accumulation: we collect what's needed for the app to work, not everything it would be possible to collect "just in case". Less data stored means less surface area for risk.
  • Control and portability: you export what's yours (CSV/PDF) whenever you want. And on the roadmap is the option to run AtivaMoney on your own cloud — with no middlemen. That's a commitment for the future, not a promise already kept, and we say so honestly.
  • No conflict of interest: an app that profits from your data has a quiet incentive to collect more. An app that profits from your subscription has the opposite incentive: protect you so you stay.

We don't promise you an oracle that decides for you. We promise you a tool that learns with you and works for you — which is, after all, what a personal AI should be.

5 questions to ask any AI that touches your money

  1. Where is my data processed? On my device, or sent to a third party's central model? If it leaves, where does it go, and how long does it stay there?
  2. Is my data used to train shared models? If the answer isn't a clear "no", assume it is — and check whether you can opt out.
  3. What's the business model? Am I paying with money, or paying with data? One of the two is always happening.
  4. Can I export and delete everything? Portability (GDPR, Article 20) and genuine deletion are the acid test of whether someone respects that the data is yours.
  5. Does personalisation really need the cloud? If a model can learn on the device, requiring centralisation is a choice — not an inevitability.

The good news on this topic is that the technology for private AI already exists. What's often missing is the will to use it — and the demand, on your part, that it gets used. Don't trade control for convenience without asking the price. Ask first. Decide after.

Start free — no card

References

  1. Carlini, N., Ippolito, D., Jagielski, M., Lee, K., Tramèr, F. & Zhang, C. — Quantifying Memorization Across Neural Language Models, arXiv:2202.07646, 2022
  2. Comité Europeu para a Proteção de Dados (EDPB) — Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models, 17 de dezembro de 2024
  3. McMahan, B. & Ramage, D. (Google Research) — Federated Learning: Collaborative Machine Learning without Centralized Training Data, 2017
  4. Cisco — 2024 Consumer Privacy Survey (declarações de Harvey Jang, VP & Chief Privacy Officer), outubro de 2024
  5. TD Bank — Nearly 80% of Americans use AI Tools but Most Still Want Humans Making Financial Decisions (declarações de Kiran Vuppu, U.S. CIO), 2025

This article was translated from the Portuguese original.

Start for free — no card required →