P
AI Privacy Assessment

PrivaSee

Test whether AI models can reproduce withheld personal attributes using verified ownership, cross-provider testing, and anti-hallucination controls.

Product Overview

A controlled way to test indications of AI model memorization.

PrivaSee evaluates whether multiple AI models can independently reproduce personal information that was not included in the model prompt. It is designed to produce a cautious indication—not definitive proof—while reducing misuse and false conclusions.

Important limitation: PrivaSee cannot inspect any vendor's training dataset and cannot prove that personal data was used for model training. A result is indirect evidence that may also reflect widely available public information, coincidence, or model hallucination.
Assessment Procedure

A privacy-preserving, multi-stage methodology.

Step 01

Verify ownership

Confirm control of the email address through OTP before any assessment begins.

Step 02

Withhold test keys

Keep attributes such as name, city, employer, and username out of the model prompt.

Step 03

Test multiple publishers

Query independent model families to reduce dependence on a single provider's behavior.

Step 04

Run control probes

Test a comparable fictional identity and neutralize results from models that fabricate recognition.

Probe Design

Measure reproduction, not agreement with a leading prompt.

Only the verified seed identifier is sent to the model. The assessment scores whether models independently reproduce withheld keys.

Recall probe

Asks what the model knows about the owner of the verified seed.

Completion probe

Tests whether the model completes missing profile details without being given those details.

Linkage probe

Designed to test whether verified identifiers are associated with the same person; this requires multiple verified anchors.

Control probe

Uses a fictional identity to measure the model's tendency to invent personal information.

Evidence grading
Not detectedNo withheld keys reproduced.
WeakOne publisher reproduces one test key.
ModerateAt least two publishers reproduce test keys.
StrongAt least three publishers reproduce the same key.

Evidence is counted by publisher rather than by individual model variant.

Privacy Safeguards

The assessment should not create a new privacy problem.

Ownership verification

No unrestricted people-search mode; the seed must be verified by its owner.

Restricted model requests

Web search is disabled so the test does not simply measure whether information is publicly searchable.

Data minimization

Stored data is encrypted, model excerpts are redacted, and reports expire automatically after a limited period.

Applications

Useful for individuals today—and extensible to enterprise AI assurance.

Individual assessment

  • Check indications of model memorization
  • Compare evidence across model publishers
  • Monitor whether results change over time
  • Generate a structured assessment report

Enterprise assurance potential

  • Test public and private models for sensitive-data reproduction
  • Evaluate enterprise RAG applications
  • Use canary and synthetic identities for regression testing
  • Support AI privacy impact assessments and remediation validation

Understand what the result can—and cannot—tell you.

Use PrivaSee for a personal assessment or discuss enterprise testing for AI privacy, memorization, and RAG assurance.

Start with PrivaSee ↗