TL;DR: Your phone's built-in AI assistant — Gemini (Android), Apple Intelligence/Siri (iOS), Galaxy AI (Samsung) — is fundamentally different from a chatbot: it is embedded in the OS and can read your screen, notifications and messages, and respond to your voice in the background. Some processing happens on-device, some goes to the cloud: Apple routes complex requests through Private Cloud Compute, Google uses Gemini's cloud. A VPN encrypts your phone's network traffic and hides your IP from Wi-Fi networks and your ISP, but it does not prevent the assistant from reading your screen and cannot cancel data collection in your account. Real privacy requires two layers: correct assistant settings and a reliable VPN for network traffic.
Built-in AI assistant vs chatbot: Gemini, Apple Intelligence/Siri, Galaxy AI
A chatbot like ChatGPT or Claude is something you open intentionally — in a browser or a separate app — get your answer, and close the tab. A built-in AI assistant works differently: it is integrated directly into the operating system and runs persistently in the background. It listens for a hotword, can see the current screen, and may act across apps without an explicit user request. In terms of OS access rights, it is closer to the OS itself than to any third-party app.
For privacy when using AI chatbots specifically, see: smart speaker privacy and always-on listening. This article is about the system assistant embedded in your phone — an agent inside your OS.
The major players in 2026:
- Google Gemini / Gemini Intelligence (Android 17): the default assistant on Pixel devices and most Android phones. The new agentic layer, Gemini Intelligence, introduced in Android 17, can act across apps — reading the screen, completing tasks in Gmail, Chrome and other applications without step-by-step prompting.
- Apple Intelligence / New Siri (iOS 26.4 to iOS 27): iOS 26.4 (spring 2026) brought on-screen awareness — Siri can now read the contents of the active screen and respond in the context of the open app. iOS 27 (September 2026) adds full conversational AI and multi-app automation. A notable architectural detail revealed at WWDC 2026: the new Siri uses Google Gemini models, but requests are processed through Apple Private Cloud Compute (PCC), not directly through Google's infrastructure.
- Samsung Galaxy AI / Bixby: a dual-assistant system on Samsung Galaxy devices. Galaxy AI bundles features powered by Google and Samsung models (photo editing, summarization, Circle to Search); Bixby is the voice assistant and automation platform. They run in parallel with partially overlapping settings — which creates the privacy confusion described below.
A key difference from a smart speaker: the phone assistant has constant access to a live screen, messaging history, email, a calendar and banking apps. This substantially widens the potential data surface.
What data does your phone's AI assistant actually see
The data accessible to a built-in system assistant is broader than most third-party apps get — precisely because it operates at OS level and, in some cases, acts without explicit per-action consent.
- Screen contents (on-screen awareness): when this mode is active, the assistant sees everything currently displayed — texts, images, open documents, web pages. On iOS 26.4+, this is enabled by default when Apple Intelligence is on. On Android 17, Gemini Intelligence accesses screen content via the Accessibility API.
- Notifications and messages: the assistant can read incoming notifications from messengers, email and other apps if you granted Notification Access — giving it access to message fragments directly from the notification shade.
- Voice and microphone: the assistant continuously listens for the hotword (Hey Google, Hey Siri). Even in passive mode it requires persistent microphone access. On false triggers, it records surrounding audio fragments.
- Location and context: current location, time of day, nearby places — used for contextual suggestions and automatic feature activation.
- Activity history and queries: all assistant requests, features used, apps opened and results may be saved to your Google/Apple/Samsung account for personalization and model improvement.
- Direct app access: email, calendar, messages, contacts, notes — the assistant can read, search and create entries with the appropriate permissions.
On-device vs cloud: where your data leaves the phone
Developers emphasize on-device processing — and it does reduce certain risks. But processed on-device is not the same as nothing goes to the cloud.
Apple / Siri: basic tasks (voice recognition, simple commands) are handled on-device using the Neural Engine. Complex requests — summarizing documents, multi-step agentic tasks, queries routed through Gemini — go to Apple Private Cloud Compute (PCC). Apple states PCC is isolated: employees cannot access data processed there, sessions are deleted automatically, and the architecture is publicly verifiable. The 2026 key fact: Siri uses Gemini models through PCC — Apple says Google does not receive personal user data or IP addresses. MacRumors and Business Standard confirmed this architecture from WWDC 2026.
Google Gemini: basic voice commands and Pixel on-device AI features run locally. Complex agentic tasks, web search and long document analysis go to Google's cloud. Android 17's agentic layer expands on-device execution — but the principle remains: the more complex the task, the more likely the cloud is involved.
Samsung Galaxy AI: there is a dedicated toggle for Process data only on device that restricts certain Galaxy AI features to local execution. Important caveat: this covers only Galaxy AI features, not Gemini and not Bixby, which follow their own data policies independently.
The main privacy risks of AI assistants in 2026
Ambient activation and false triggers. Hotwords trigger on similar-sounding phrases — a documented fact for every major assistant. Since Android 17 and Gemini Intelligence launched, users on Reddit and tech forums have reported incidents where the assistant appeared to respond to background conversations even with the hotword seemingly off. To be clear: these are user reports, not confirmed evidence of systematic covert monitoring. Google denies intentional listening without a command. The risk of false triggers is real and documented, and warrants a review of your settings.
Agentic AI expands the attack surface. On-screen awareness and cross-app actions are useful features that simultaneously expand the potential data exposure surface. If a system assistant is compromised — through an update vulnerability, or a prompt injection attack (malicious text on a web page that instructs the assistant to take action) — it could theoretically relay on-screen data externally. Security researchers demonstrated successful prompt injection attacks against large LLM systems in 2025 and 2026.
Multi-assistant confusion (Counterpoint Research, 2026). One of the key findings of the Counterpoint Research AI Privacy and Security Scorecard 2026: most Samsung Galaxy users cannot tell, at any given moment, whether Galaxy AI, Gemini, or Bixby is active. Privacy settings for one do not apply to the others. Disabling Bixby does not disable Gemini. This creates an illusion of control.
Regulatory gap and EU pressure. According to CNN Business, Apple and Google are in an ongoing dispute with the EU in 2026 over requirements to open OS APIs to third-party AI assistants. If met, users face a new choice: a platform assistant with a known privacy policy, or a third-party one with an opaque data processing chain.
Where the assistant processes your data — at a glance
| Assistant action | Processed where | Does VPN help? |
|---|---|---|
| Simple voice command (set a timer) | On-device | No — no network traffic leaves the phone |
| Complex Siri request / agentic task | Apple Private Cloud Compute (PCC) | Partially — hides IP and network, not the request content |
| Screen reading and cross-app actions | On-device + sometimes cloud (for final response) | No — OS-level access, not network traffic |
| Web search triggered by the assistant | Google/Bing cloud | Yes — hides your IP from the search provider and ISP |
| Assistant activity history sync | Account cloud (Google/Apple/Samsung) | No — account data, not traffic |
Does a VPN protect you from AI assistant tracking? (honest answer)
A VPN is a tool for protecting your phone's network traffic, and it does this well. When connected through LiMP VPN, your traffic is encrypted and your IP address is hidden from the Wi-Fi access point, ISP and external services. For a full breakdown and plans: LiMP VPN plans from £1.20/month.
A built-in system assistant does not work like a browser or a third-party app. When Gemini reads your screen, it is not pulling data over the internet at that moment — it is a local OS operation through the Accessibility API. A VPN does not sit between the assistant and your phone's screen. The same applies to notification access and account-synced history — these operate at system and account level, not as network traffic a VPN can intercept.
A VPN helps:
- Hide your IP when the assistant performs a web search on your behalf — your ISP cannot see what is being searched.
- Protect the connection between your phone and the assistant's cloud servers on public Wi-Fi (cafes, airports, hotels).
- Prevent your ISP from seeing which cloud services your phone connects to.
A VPN does not:
- Prevent screen reading or notification access by the system assistant.
- Limit the assistant's access to your Google/Apple/Samsung account data.
- Cancel the saving of query history to the account cloud.
The bottom line: a VPN and assistant privacy settings are two separate, complementary layers of protection. Neither replaces the other. Android users with Gemini: see also VPN for Android.
How to lock down your AI assistant's privacy: checklist
- Identify which assistant is active by default. Android: Settings > Apps > Default apps > Digital assistant. iOS: Settings > Apple Intelligence & Siri. Samsung: Settings > Advanced features > Bixby, plus the Galaxy AI section.
- Disable the hotword and background activation if you do not need always-on voice input. Remove Hey Google and Hey Siri to eliminate false triggers and background mic access.
- Restrict screen and notification access. Android: Settings > Apps > Gemini > Permissions > Accessibility. iOS: Settings > Apple Intelligence & Siri > disable Use on Screen and notification access.
- Revoke access to email, calendar and messages if you do not use assistant automation for those apps. Each is a separate toggle.
- Clear activity history and disable training on your data. Google: myactivity.google.com > Activity controls > turn off Web and App Activity. Apple: Settings > Apple Intelligence > Siri History > Delete. Samsung: Galaxy AI > Improve Galaxy AI > off.
- Enable on-device-only mode where available — Samsung Galaxy AI has a dedicated toggle; iOS 27+ lets you choose Device instead of Device and Private Cloud Compute.
- Only install apps from official stores (App Store, Google Play, Galaxy Store) to reduce the risk of trojaned versions exploiting system assistant permissions.
- Enable LiMP VPN on public Wi-Fi to encrypt your phone's network traffic, including what the assistant sends to the cloud for complex requests.
Frequently asked questions
Does Gemini/Siri listen to my conversations without a command?
Not by design: both assistants activate via hotword or an explicit command. Hotwords do trigger on similar-sounding phrases — a documented fact. Since 2026, some Android/Pixel users have reported Gemini responding to background speech without a clear trigger; Google denies this as systematic practice. Mitigation: set Voice Match to Only when unlocked. For Siri: Apple processes voice primarily on-device.
Does Apple Intelligence send my data to Google?
No, according to Apple. While Siri uses Google Gemini models, requests are routed through Apple Private Cloud Compute. Apple states Google receives only an anonymized request with no link to your identity, IP, or account; sessions are deleted automatically.
Does a VPN hide my AI assistant queries?
Partially. A VPN encrypts network traffic and hides your IP from the ISP and Wi-Fi operator, including traffic from the assistant to cloud servers. But a VPN has no influence over what the assistant does inside your phone: reading the screen, accessing email, storing history in your account.
How do I turn off the AI assistant on my phone completely?
Android (Gemini): Settings > Apps > Default apps > Digital assistant > None. Also disable the hotword in Google settings. iOS (Siri/Apple Intelligence): Settings > Siri & Search > disable Listen for Hey Siri; Settings > Apple Intelligence > disable.
Is on-device processing safer?
Yes, for simple tasks — data never leaves the phone and network interception risk is zero. But on-device is not absolute privacy: data may sync to your account later, and complex requests still go to the cloud (Apple PCC or Gemini servers).
Can the assistant read my screen and app contents?
Yes, if on-screen awareness is enabled — iOS 26.4+ for Siri, Android 17 for Gemini Intelligence. The assistant sees the active app's text for contextual responses. To restrict: revoke Accessibility access (Android) or disable Use on Screen (iOS) in the specific assistant's settings.
Should I give the assistant access to my email and messages?
It is a trade-off. With access: email search, draft replies, meeting reminders. Without: only tasks unrelated to messages (timers, music, web search). Recommendation: grant access only to apps whose assistant-powered features you actively use — revoke the rest.
