Tools

What to Check Before Trusting a New AI Tool With Client Data

A new AI tool looks great in a 90-second demo. The demo doesn't show you the data policy, the failure modes, the price after the trial, or how hard it is to leave. This is a due-diligence checklist for a freelancer or small business deciding whether to trust a tool with real work and real client data — a 10-point check, red and green flags, a scoring worksheet, and a worked example on a made-up tool.

The 10 things to check

# Check Where to look / what "good" looks like
1Company identityA real company name, address, and team are findable. An "About" with no names and no legal entity is a caution.
2Data handlingPrivacy policy states what's collected, where it's stored, and which sub-processors/model providers see it.
3Training on your inputsDo they train models on what you upload? Is there an opt-out, and is it on by default?
4Content ownership & licenceTerms should say you own your inputs and outputs, and grant the vendor only the licence needed to run the service.
5Retention & deletionCan you delete data and your account? Does deletion actually remove it, and within a stated window?
6Integrations & permissionsWhen it connects to email/drive/calendar, does it ask for read-only where possible, or full access to everything?
7Security postureLook for specifics (encryption in transit/at rest, SSO, an audited compliance report you can request) — not just the word "secure".
8Pricing & trial termsPrice after the trial, whether a card is required up front, auto-renew terms, and how cancellation works.
9Export & lock-inCan you get your data and work out in a standard format if you leave? Or is it trapped in their UI?
10Model/provider dependencyWhich underlying model powers it? If that provider changes pricing or access, does the tool break?

Then test the behaviour, not just the paperwork

Red flags

Green flags

Scoring worksheet

Tool: __________________________   Date checked: __________
Score each 0 (fail) / 1 (partial) / 2 (good):

[ ] 1. Company identity clear
[ ] 2. Data handling documented
[ ] 3. Training opt-out (off by default = 2)
[ ] 4. You own inputs/outputs
[ ] 5. Retention & deletion stated
[ ] 6. Least-privilege integrations
[ ] 7. Concrete security details
[ ] 8. Pricing & trial terms clear, no card trap
[ ] 9. Export exists, low lock-in
[ ] 10. Model dependency understood

Behaviour:
[ ] Tested on low-stakes work
[ ] Failure mode is visible, not silent
[ ] Solves a real bottleneck I have

Total: ___ / 26
Data sensitivity of intended use (low / medium / high): ______

When to skip the tool

Worked example — a hypothetical tool

Hypothetical, invented for illustration. "InboxZero AI" promises to draft all your client email replies. On the checklist: company is a named entity with docs (2). Privacy policy names storage region but not the model provider (1). Training on inputs is on by default, opt-out is in an account sub-menu (0). Terms confirm you own outputs (2). Deletion is documented, 30-day window (2). It requests full Gmail access, no read-only option (0). Security page lists encryption and offers a compliance report on request (2). Free trial needs a card, auto-renews monthly, cancellation is self-serve (1). Export is copy-paste only (0). Built on a single third-party model with no stated fallback (1). Behaviour: tested on a personal draft, it invented a meeting time that was never discussed and stated it plainly — a silent-ish failure (0).

Total ≈ 11/26, and it would touch a client's entire inbox. Verdict: don't connect it to real accounts. It might be usable as a standalone draft assistant you paste into — never wired into live email — and only after turning off input training.

After it passes

Approval isn't permanent. Models update and behaviour drifts, often with no announcement. Keep a one-line log per tool (name, date checked, score, notes) and re-run the check if output quality shifts or the pricing/terms change. This pairs with our rundown of common AI automation mistakes that cost freelancers clients.

Written by the Stack Your Side team

We research and write every guide based on publicly available product information, documented tool behavior, and general freelance industry practice. Where we haven't personally tested a tool hands-on, we say so directly rather than implying otherwise. See our editorial policy for how we approach accuracy and updates.