The 2-Question AI Privacy Audit (Non-Technical): Are You Leaking Data Without Knowing?

Check two things: (1) Where does your AI run — your computer, a home device, or a VPS? Each has different privacy gotchas. (2) Is anything exposed to the public internet? Turn off Wi-Fi on your phone and try to access your AI — if you can, something is exposed. The #1 risk isn't AI itself, it's accidental exposure: 135,000+ OpenClaw instances were found publicly accessible due to configuration mistakes.

A lot of people think they have a "private AI setup."

Then later they find out:

You don't need to be technical to reduce that risk. You just need to answer two questions.

Why "private" setups accidentally become public

Most privacy failures aren't malicious. They're accidental.

Someone follows a tutorial, copies a command, opens a setting, and moves on. Then weeks later the setup is still running — with assumptions that were never checked.

Here are real scenarios we've seen:

None of these are exotic attacks. They're configuration oversights — and they're preventable.

This is why we like simple audits.

Audit question #1: Where does it run?

Pick one:

This matters because each option has different "gotchas."

Local (your computer)

Small home device (Raspberry Pi, Mac Mini)

Cloud server (VPS)

Audit question #2: Is anything exposed to the public internet?

You don't need to know what a "port" is to answer this.

Just ask:

If the honest answer is "not sure", treat that as a yellow flag.

How to check (non-technical version)

  1. Turn off Wi-Fi on your phone — use only mobile data
  2. Try to access your AI — can you reach it?
  3. If yes — something is exposed. That's not automatically bad, but you need to confirm it's protected (authentication, HTTPS, firewall rules).
  4. If no — good. It's only on your local network.

What "exposed" actually means

When something is reachable from the public internet, anyone with the right address can try to connect to it. That includes:

If your AI assistant can read files, send messages, or access accounts, you want that door shut and locked.

The #1 risk most people miss

The biggest risk is not "AI."

It's exposure.

When something is reachable from the public internet and it's not locked down properly, it becomes an open door. The AI part is almost irrelevant — it's the same risk as leaving any service exposed without authentication.

If you're using an AI assistant that can read files, send messages, or access accounts, you want that door shut.

The safest next step

If you want the safest move without becoming technical:

  1. Decide whether you want it local (recommended for most) or VPS (always-on)
  2. Make sure it's configured so you're not accidentally exposing anything
  3. Add basic monitoring so it stays reliable
  4. Review the Secure Setup Guide for a full security checklist

That is also why SouthSea defaults to draft-first workflows: the AI prepares the work, a person approves it, and sensitive steps stay controlled. Security hardening is part of every build.

Related reading

Book a 15-minute fit check

If you want a privacy sanity check and a plan for one recurring task, book a 15-minute fit check. Fixed-fee workflows start at AUD $3,500.

Book here: Schedule a fit check