← Back to blog

Risk with Private IP and Public AI Models

Understand the complex and opaque landscape of risk generative AI models. Your IP may be exposed to public view, or used for training.

Risk with Private IP and Public AI Models

The Risk


Working in creative production with unreleased product runs huge risks with private / client IP, particularly when running through off-site models. There are many ways to expose or leak information that I have seen and heard of others doing, and I have taken a pro-active approach to guiding how and which to use for what context.

I have compiled a rubrik farther down for how to identify where that risk lies, and what you should know, and where to read further on that information.

Each model has their own rules, and how much you should trust it, but broadly speaking here are the key things to consider.

The Do’s

  • Use Local models when possible, all your IP stays on your own network
  • Use ComfyUI Partner-Nodes over other consumer/subscription platform
    • ComfyUI Partner-Nodes add a privacy layer, they delete inputs/outputs after 24 hours and does not transmit your identity/account

The Dont’s

  • Don’t use consumer platforms, if they can be avoided
    • Sharing and training are typically on by default, under higher tiers you can enable privacy on some
    • consumer/subscription platforms cost more, and require bulk purchases or subscriptions

The Gotchas

  • “No training” ≠ “no retention” ≠ “not visible.”
    • Most reputable commercial APIs (OpenAI, Google paid, xAI, Alibaba, Kling API, LTX-2 API) contractually promise no training on customer data by default
  • Foreign vendors typically have less documented ( or not at all ) rentention windows for user data.

Vectors for exposure

There are a few key surface areas where you can encounter some risk.

  1. Visibility: Generated results can sometimes be publicly visible, or shared outside your team / org without being obvious
  2. Training: Services may use your inputs to train their future models, which you may not even have the rights to grant
  3. Retention: Your data may be retained and live on a cloud server, and could be bought, sold or misplaced as the landscape evolves

The Risk Charts

Given the fast paced nature of this landscape, this list is not be evergreen, but should be a usefull reference, as well as show you what to look out for.

Image Models (ComfyUI Partner Nodes)


ModelPublicTrainingRetentionSource
NanoBanana (all)

No

No

Yes - up to 55 days for abuse monitoringGemini API
DALL·E / GPT-Image (OpenAI)

No

No

Yes - 30 days for abuse monitoringOpenAI
Kling (Kuaishou)

No

No

Yes - vague “as long as necessary”

KlingAI
Seedream (all)

No

No

Not Published

BytePlus ModelArk

Image Models (Consumer Platforms)


ModelPublicTrainingRetentionSource
Midjourney Basic / Standard

Yes

Yes

Yes - forever

TOS Privacy Policy
Midjourney Pro / Mega (Stealth)

Partial¹

Yes

Yes - forever

TOS Privacy Policy
Runway (standard)

No

yes

Yes - unspecified

Data Security Privacy Policy
Runway (Enterprise)

No

No

Per contract/DPAData Security Privacy Policy
ChatGPT Free / Plus

No²

Yes

Yes - until user deletedOpenAI
ChatGPT Team / Business / Enterprise

No

No

Configurable

OpenAI

1. 'Stealth' hides from website gallery on a "best efforts" basis only, ( what does that even mean? ) does NOT apply to shared Discord channels, pre-Stealth images stay public

2. Share-links are public web pages, deleting a chat does NOT delete its share link, Aug 2025 discoverable-share-link Google-indexing incident exposed user data

Video Models (ComfyUI Partner Nodes)


ModelPublicTrainingRetentionSource
Seedance 1/2 (ByteDance)

No

No

Not Published

Specific Terms
Grok (xAI)

No

No

Yes - 30 day auditxAI Security
LTX-2 ( Light)

No

No

Unclear¹

LTX Legal
Kling video (Kuaishou)

No

No

Yes - vague “as long as necessary”

KlingAI
Wan (Alibaba)

No

No

Not Published

Training Sources Privacy Notice
Veo (Google)

No

No

Yes - up to 55 days for abuse monitoringGemini API

1. Unsure — license grants hosting/storage rights, no stated window, and even may retain rights to share with third parties.

Video Models (Consumer Platforms)


ModelPublicTrainingRetentionSource
Higgsfield (standard)

No

yes

Yes - 30 day auditPrivacy Policy
Higgsfield (enterprise)

No

No

per enterprise agreementPrivacy Policy
Runway (standard)

No

yes

Yes - unspecified

Runway Security
Runway (enterprise)

No

No

per enterprise agreementRunway Faq

The Takeaways


TLDR:

As you can see, the consumer portals are well worth avoiding, and even paid tiers still can expose you to training or other exposure.

This is what I reccomend, to be the most safe while using online models, use the following, and use them through ComfyUI if you can.

For images:

NanoBanana and GPT image ( without share links ) is safest for images

For Video:

Seedance, Kling, LTX2 and Veo all have decent terms through Comfy UI, and if you use Higgsfield or Runway, use the enterprise versions, which would likely be out of your control anyways.

🔒