Unfiled invention material has one property that makes AI tools risky: mistakes are irreversible. Once a cross-section sketch or a claim-adjacent system diagram enters a training pipeline or gets reviewed by a stranger, no delete button undoes it. And the terms of most tools give you a single unhelpful sentence — "we may use your submissions to improve our services" — which promises nothing and permits almost anything.
The fix is not paranoia; it is a fixed checklist run before anything unfiled goes into any tool. This guide gives you the eight checks in one table, then walks through each one with concrete examples of what a passing answer looks like, using the PatentFig AI trust page as the reference wording. Hold any vendor's language next to it and the gaps show up fast.

Vetting an AI tool for pre-filing material is a terms-reading exercise, not a features comparison.
Quick answer: the 8-check table
| # | Check | Where to look | What a passing answer looks like |
|---|---|---|---|
| 1 | Training clause | Terms of service and privacy policy; search "train," "improve" | Three doors closed: no training on own models, no training by third-party AI providers, no human review for training or benchmarking |
| 2 | Retention and deletion | Privacy policy, data retention section | Specific numbers: deletion deadline, backup rotation period, legal carve-outs named |
| 3 | Encryption | Security or trust page | Encryption at rest stated explicitly, not just TLS in transit |
| 4 | Internal access | Security or trust page | Least-privilege access, MFA on admin accounts, access logs |
| 5 | Subprocessors | Subprocessor list or DPA annex | Inference provider, cloud storage, and payment processor named |
| 6 | Content ownership | Terms, "user content" section | You own uploads and outputs; vendor license is narrow, service-delivery only |
| 7 | Paperwork | Sales or legal channel | DPA, SCCs for cross-border transfers, mutual NDA, no-training commitment in contract |
| 8 | Default settings | Product settings page | Training toggles off by default, or all switchable off by you |
A tool that clears all eight has earned the right to be judged on quality. Now each check in detail.
Check 1: the training clause decides everything else
Open the terms and search for "train," "improve," and "your content." What you want is a flat, unhedged no. What you usually get is "we may use your submissions to improve our services" — a sentence that could mean your exploded view feeds a model, or not, at the vendor's discretion.
A real answer closes three doors. The reference wording on the PatentFig trust page: customer prompts, uploads, outputs, and project metadata are not used to train its own models; third-party AI providers are not permitted to train on customer content submitted through the service; and customer content is not reviewed for training or benchmarking purposes. Own models, upstream providers, human review — three doors. A commitment that only closes one leaves the other two open.
If the terms say nothing about training either way, assume the worst. Silence is a policy too.
Check 2: retention only counts in numbers
Every tool has a delete button; few say what it does. Removing a file from your list, from production storage, and from backups are three separate events on three timelines.
So read the retention section for numbers, not adjectives. As an example of a considered answer, the same trust page commits to deleting closed-account content within 30 days and purging backups on a 90-day rotation, with carve-outs for billing and audit records required by law. Other vendors' numbers do not have to match — but a vendor that has thought retention through will state days and exceptions. "You can delete your data at any time" is not an answer; treat it as no answer at all.
Checks 3–5: encryption, employees, and the supply chain
Encryption. TLS in transit is table stakes and tells you nothing. Look for encryption at rest, stated explicitly.
Internal access. Least-privilege access, MFA on admin accounts, access logs. Three questions that are really one: if a curious employee wanted to look at your unfiled invention, what stops them?
Subprocessors. One minute on the supply chain: who runs the inference, where files live, who touches payments. A vendor willing to name its subprocessors usually has less to hide. A vendor that names none leaves you guessing how many companies your drawings pass through.

Between upload and output, one drawing can cross inference, storage, and payment infrastructure — every hop belongs on the checklist.
Checks 6–7: ownership, and the paperwork test
Ownership hides in a paragraph most people skip. Two things to find: who owns uploads and outputs, and how wide a license the vendor takes. Some consumer tools claim a perpetual, worldwide, sublicensable license to user content. Harmless for meme captions; a problem for a claim-adjacent diagram. A passing license is narrow — just wide enough to deliver the service.
Paperwork matters most for firms and in-house teams: can the vendor sign a DPA, standard contractual clauses where transfers cross borders, and a mutual NDA — and can the no-training commitment be restated in a signed contract instead of a web page that can change? Solo inventors can skip the signing but not the question. A vendor built to survive a law firm's procurement review is rarely careless with anyone's files.
Does uploading count as public disclosure?
Handle this question carefully, and not with blog posts. In general, transmitting material to a private, access-controlled service under confidentiality terms is a different act from posting it on a forum, and is not usually treated as making it available to the public. But "usually" is doing heavy lifting in that sentence. The analysis depends on the specific tool's terms, whether content can be reviewed by humans or absorbed into training data, and how your jurisdiction defines availability. For US filings, the framework lives in MPEP 2152; international routes add the PCT system layer on top.
The practical move: bring the tool's actual terms to a patent attorney or agent. Ten minutes, and it's the cheap kind of ten minutes. The vaguer the terms, the more that conversation is worth.
Check 8: free tiers and consumer defaults
The economics are simple. If you're not paying, your data is part of the price, and the defaults follow: history retained, training enabled, the opt-out three menus deep. The enterprise tier of the same company often runs under a completely different data policy than the free tier. Same logo, different contract.
Unfiled material gets exactly three acceptable routes:
- a professional tool with an explicit written no-training commitment;
- a tool where you have switched every data-use toggle off yourself;
- sanitized input — key structures stripped out, generic placeholders in their place.
Pick one; there is no fourth. Only after a tool clears all eight checks does workflow matter — sketches into line-art masters, then a Figure Checker pass for margins and reference numerals before anything goes near a filing. The vendor-review angle is covered in more depth in this breakdown of pre-filing material handling.
FAQ
Are free-tier and paid-tier terms the same?
Often not. The consumer product and the enterprise product of the same company can run under entirely separate data terms. An enterprise no-training commitment says nothing about the free tier. Verify the terms of the exact tier you use.
What documents should a firm request in procurement?
Four: a data processing agreement (DPA), standard contractual clauses (SCCs) where transfers cross borders, a mutual NDA, and the no-training commitment restated as contract language. Add the subprocessor list, and expect the security review to ask for a trust page or security whitepaper.
The terms never mention training. Now what?
Treat silence as "yes, we train." It is a policy — just one that favors the vendor. Either switch tools or take the sanitization route.
Is sanitizing the material before upload a workable fallback?
Yes, and it is the only fallback when the terms fail: strip core structures, dimensions, and fit relationships, keep only generic geometry. But sanitization limits the damage of a leak; it does not fix bad terms. If the sanitized version still carries sensitive detail, the first seven checks still apply.
The comparison template is here: PatentFig trust and security. Hold your other tools' answers up against it and see what's missing.
Not legal advice. Novelty and disclosure questions belong with your patent counsel.
Top comments (0)