Consumer service terms: a hellhole
You are the product. You will eat the slop and be happy about it
When I decided to start blogging again on this very site, dcalves.com, I wanted to register an internet domain and use it to receive emails as well (contato@dcalves.com). At the time, I opted for Google Workspace and noticed it offered far more features and data privacy safeguards compared to the standard consumer plan I was subscribed to back then, Google One.
I was intrigued because it seemed like Google was taking my data much more seriously. I found it odd and asked myself why the Google One consumer plan didn't show this same willingness when it came to handling my data privacy.
The illusion of user data privacy and safety from data farming
That was when I discovered something in April that completely changed the way I interact with SaaS (Software as a Service). Consumer plans are deliberately structured so that the user and their data are the product: the product that will train and improve the service for the only occasions where these services are actually offered as real products: enterprise subscriptions or government contracts.
So, using an artificial intelligence to organize my financial life, my credit card bills, invoices, taxes, interest rates, my debts, and to make long-term plans: all this information was feeding this corrupted structure masquerading as a service. In reality, I was PAYING to be the product, handing over my data to improve the very company I was paying a subscription to.
That sparked a relentless wave of cancelling subscriptions - AI, email services - and I found myself in a rather delicate and dreadful situation.
If it isn't safe from an information security standpoint to have a standard consumer plan, I will seek out SaaS under the terms and conditions applicable to enterprises and governments.
And so I took charge. Today, I am extremely careful about the information I put out on the Internet and the conditions under which I use Software as a Service.
Let me give you an example of my current setup, where I managed to find my footing to get at least some peace of mind (I do have obsessive-compulsive disorder, after all).
My OS: I ditched Windows as soon as Windows 11 was announced. It was one of the best decisions I've ever made. Not only did it make me more technically fluent, but I am now the one who dictates the sovereignty of it all: updates, internet interaction surfaces, network connections (Wi-Fi, Bluetooth), app-to-app communication, ports, APIs. I am in control: I am no longer the product.
Email, calendar, and contact services: I switched entirely to Proton. It’s a privately held company. It’s not publicly traded and doesn't answer to the shady interests of shareholders like Vanguard and BlackRock. I reviewed their terms and conditions, and the service is scaled and sold precisely with data sovereignty and personal information in mind. The service is to provide email, calendar, and cloud storage where user data is NOT used to feed the machine and improve the product, nor is it directly sold to third parties.
Artificial intelligence services: with the cancellation of my Google One, my access to Gemini via the consumer platform stopped as well. So, I looked among AI providers for those with terms and conditions most similar to those offered to enterprises and governments. And what did I find?
There is no escape for artificial intelligence on consumer plans.
Even on the most expensive ones, at $100 a month, the data is classified as consumer user data, not enterprise or government data. In the case of artificial intelligence, this greed is even more dreadful and dangerous. Sensitive information - financial and medical data, data I handle with my clients as a solopreneur containing sensitive info and trade secrets: is deliberately used to improve their models. Private and sensitive data feeds the model, and the moment that model is released after training, there is a statistical chance greater than zero that it will expose all the data harvested from me.
So, if there is no escape in consumer plans, is it worth getting an enterprise plan? No.
None of the providers offer enterprise plans for just one person. I have to pay for at least two seats, but in most cases, they require a minimum of five users for an enterprise plan.
The way out, then, is to use AI services through their APIs. Data processed via APIs is governed by the terms and conditions offered to enterprises and governments - the safest ones, featuring DPA (Data Processing Agreements) and ZDR (Zero Data Retention). They are a safer option for processing personal and sensitive data, or simply for exercising the sovereignty of individual privacy by not having your information feed artificial intelligence models.
What comes next?
The problem is much bigger than just the services I mentioned. The issue extends to mobile devices, cell phones, smartphones, Android, smartwatches, and even Smart TVs.
I have taken up the FOSS fight. Historically, the villainy has always been very clear. But nowadays, this villainy is much more dreadful and much more damaging, but above all, much less transparent.
Also, run local AI models.
Exercise digital sovereignty. Inform yourself, study. Join Free and Open Source Software.