People tell AI assistants remarkable things: health worries, relationship problems, financial details, confidential work documents. The conversational style makes it feel private. But your messages are processed on company servers, and depending on your settings they may be stored, reviewed or used to improve future models.
This does not mean you should avoid AI. It means you should use it deliberately.
Updated September 2026: we added the exact settings and retention periods for ChatGPT, Claude and Gemini, with links to each company’s documentation, and sources on fake AI apps.
Know what happens to your chats
Policies differ between providers and between free, paid and business plans, and they change over time. Here is how the three biggest assistants handle consumer accounts as of September 2026:
| ChatGPT | Claude | Gemini | |
|---|---|---|---|
| Used for training by default? | Yes, unless you turn it off | Only if you choose to allow it | Yes, while Keep Activity is on |
| Setting | Improve the model for everyone | Model training choice in Privacy Settings | Keep Activity |
| How long chats are kept | Temporary chats up to 30 days | 30 days if you opt out of training, up to 5 years if you opt in | 18 months by default; 72 hours with Keep Activity off |
Google says plainly that “a subset of chats are reviewed by human reviewers” when Keep Activity is on (Gemini Apps Privacy Hub). Anthropic’s retention periods come from its August 2025 consumer terms update. Questions worth answering for any service:
- Are my conversations used to train models by default, and can I opt out?
- How long are chats kept, including deleted ones?
- Can staff or contractors review conversations, for example for safety?
- What happens to files I upload?
Settings to change today
- Model training. In ChatGPT, turn off Improve the model for everyone under Settings, then Data controls. In Claude, check your choice in Privacy Settings. In Gemini, turn off Keep Activity or shorten its auto-delete period.
- Chat history and memory. Some assistants remember details across conversations. Review what is stored and delete anything you do not want kept.
- Temporary chats. ChatGPT’s temporary chats are not used to train models and do not create memories, though OpenAI may keep a copy for up to 30 days for safety. Other assistants offer similar modes.
- Connected apps. If you have linked email, calendars or cloud storage, review those permissions and remove any you no longer use.
What never to share
- Passwords, security codes and recovery keys
- Full card numbers, bank details and government ID numbers
- Other people’s personal information without their consent
- Confidential employer information your company has not approved for AI tools
- Anything you would be distressed to see leaked
Redact before you paste You can get almost all the benefit of AI help with names, account numbers and identifying details removed. Replace them with placeholders like [Client A] or [Account 1].
At work, follow the policy
Consumer AI accounts are not the same as company-approved tools. Business plans usually include contractual commitments not to train on your data, plus admin controls; OpenAI, for example, does not train on ChatGPT Business or Enterprise content by default. If your employer provides an approved assistant, use it for work material. If there is no policy yet, ask before pasting anything confidential. Our guides to summarizing documents with AI and writing an AI policy cover safe handling of files.
Health, legal and money questions
AI can help you understand a diagnosis, prepare questions for a doctor or decode a contract. Keep questions general where you can, avoid including identifying details, and remember that chatbots are not covered by the confidentiality rules that apply to doctors and lawyers. See our guides to AI in healthcare and AI for personal finance.
Watch out for fake AI apps
Criminals disguise malware as AI tools. In 2023 Meta reported finding more than 1,000 web addresses spreading ChatGPT-themed malware, much of it as browser extensions, and security firm ESET blocked over 650,000 attempts to reach malicious ChatGPT-themed domains in the second half of 2023. Download assistants from the official developer or app store, check the publisher name and be wary of extensions that ask to read all your browsing data.
A simple rule of thumb
Treat an AI chat like an email to a company: useful, usually safe, but not a diary. Adjust your settings once, redact sensitive details as a habit and use approved tools for work, and you can get the benefits of AI without handing over more than you need to.
Sources
- Data controls FAQ, OpenAI Help Center
- Temporary chat FAQ, OpenAI Help Center
- Updates to Consumer Terms and Privacy Policy, Anthropic, August 2025
- Gemini Apps Privacy Hub, Google
- Meta finds more than 1,000 domains sharing ChatGPT-themed malware, Axios, May 2023
- Beware of fake AI tools masking a very real malware threat, ESET WeLiveSecurity, July 2024



