Your phone advertises on-device AI. Then a writing feature asks for permission to use an online service. Those two statements can coexist: a product can take different processing routes for different requests.
Follow the feature, not the slogan
Find the privacy documentation for the exact feature you want to use. Check whether processing happens on the device, on the provider’s servers or through another provider, and what determines that route. Apple Intelligence, for example, documents both device processing and Private Cloud Compute.
Avoid extending a privacy promise for one feature to every AI application on the same device. A downloaded app can have its own account, network behaviour and policy.
Ask what leaves the device
Look for information about the request text, attachments, account identifiers, retention and optional feedback. “Not used for training” answers one question; it does not answer every question about processing or storage.
For work or somebody else’s personal information, check that you are allowed to use the service before sending it. A short, invented sample is often enough to evaluate whether the feature is useful.
Make a task-sized decision
Decide what information this particular request really needs. Remove irrelevant details before submission. If you require offline operation, verify that the specific task works without connectivity and consult its documentation; one successful offline action does not prove that the entire product is always local.