When you type into an AI assistant, your words go to the provider’s servers, get saved to your account, and may be used to train future models unless you switch that off. Some chats are read by human reviewers. Deleting a chat hides it at once, but copies usually last up to 30 days, and some reviewed chats last years.
The fixes are simple: change one setting per tool, use temporary chats for sensitive one-offs, and keep some things out of chats entirely. This guide covers AI privacy in plain terms, with the settings in ChatGPT, Claude and Gemini as of September 2026, and a one-page policy for a small team.
- Consumer AI chats are stored on the provider’s servers and, depending on one setting, may be used to train future models.
- ChatGPT, Claude and Gemini each have a switch to stop training on your chats, plus a temporary or incognito mode.
- Deleted chats linger for up to about 30 days, and Gemini keeps chats that humans reviewed for up to three years.
- Business plans from OpenAI, Anthropic and Google do not train on your data by default.
- Never paste passwords, keys, other people’s personal data or anything under NDA into a consumer chat.
Where your prompts actually go
Every message travels to the provider, is processed by the model and, in a normal chat, is saved to your history. From there, four things can happen to it.
Training. Used to improve future models, if the setting allows it.
Human review. Read by staff or contractors, for quality or because a safety system flagged it.
Retention. Kept for a set period, and sometimes longer for legal or safety reasons.
Personalization. Used for memory features and, with some assistants, for ads.
Memory and training are separate switches, as OpenAI’s help pages point out. Turning one off leaves the other exactly as it was.
How to turn off AI training in ChatGPT, Claude and Gemini
Here is how ChatGPT, Claude and Gemini handle your chats on personal plans, according to their own help pages in September 2026.
| ChatGPT | Claude | Gemini | |
|---|---|---|---|
| Chats used for training when | “Improve the model for everyone” is on | “Help improve our AI models” is on | Keep Activity is on |
| Private mode | Temporary chat: not used for training, kept up to 30 days | Incognito chat: not used for training | Temporary chat: not used for training, kept 72 hours |
| After you delete a chat | Removed from systems within 30 days | Removed from back-end storage within 30 days | Removed from your activity; chats already reviewed by people are kept up to 3 years |
| Business plans | Not used for training by default | Not used for training by default | Workspace: not used for training without permission |
Each provider keeps exceptions for safety and legal obligations. Anthropic, for example, keeps chats flagged for violating its usage policy for up to two years. If you allow training, it may keep de-identified data for up to five years.
ChatGPT
Open Settings, select Data controls, and turn off “Improve the model for everyone”. On a personal plan, the same switch covers Codex tasks. Your existing chats stay in your history.
Claude
Open Settings, select Privacy, and turn off “Help improve our AI models”. New chats and coding sessions are then excluded from future training, and Anthropic says it also stops using your earlier chats in future training runs.
Gemini
Open Gemini Apps Activity and turn off Keep Activity. Future chats are still kept for 72 hours so Gemini can reply and protect the service, but they are not used for training unless you send feedback. If you keep it on, you can shorten auto-delete from the default 18 months to 3.
Other assistants use chats in other ways. Since December 16, 2025, Meta uses your conversations with Meta AI to personalize content and ads in most regions. Meta says sensitive topics such as health or religion are not used for ads.
Microsoft’s Copilot app shows ads to people without a Microsoft 365 subscription. Those ads can draw on your chat history and saved memories unless you turn off “Allow ads personalization” under Settings, then Personalization. With ad-supported assistants, check the ad settings as well as the training ones.
What never to paste into an AI chat
Google’s own privacy hub asks you not to enter anything you would not want a human reviewer to see. That is a good rule for every assistant. In practice, keep these out of consumer chats:
Secrets. Passwords, API keys, tokens, private keys and recovery codes. Our guide to keeping API keys safe covers what to do instead.
Other people’s personal data. Customer lists, patient or HR records, anything you would need their consent to share.
Identity and money. Government ID numbers, bank details and card numbers.
Confidential business material. Unreleased financials, deal terms, legal advice, or code and documents under NDA.
Anything a contract forbids. Many client agreements bar sharing their data with third parties, and an AI provider is a third party.
Remember that files and screenshots count. A pasted spreadsheet or a screenshot of your inbox carries everything in it. Oversharing here has a knock-on risk too: scammers increasingly use leaked personal details to make voice clones and phishing messages more convincing, covered in our guide to AI scams.
Agents see more than your messages
An AI agent reads files, screens and connected apps to do its job. With a cloud model, what it reads goes to the provider just like a message you typed. Give an agent a project folder rather than your whole disk, and connect only the apps a task needs.
A meeting note-taker raises the audio version of the same question. Our guide to AI meeting notes covers the consent rules and what happens to the recording.
Policies differ on connected data. Anthropic, for example, says raw content from connectors such as Google Drive or MCP servers is not used for training unless it is copied into the conversation itself. For the wider risks of giving an agent your machine, see whether it is safe to let AI control your computer.
Local or cloud: which is more private?
A model that runs entirely on your own computer, through a tool such as Ollama or LM Studio, keeps your prompts on your machine. That makes it the most private option for sensitive text, at a cost.
- Prompts and files never leave your computer
- Works offline, with no account and no retention policy to read
- Good enough for many tasks: summaries, drafts, classifying documents
- Smaller models than the best cloud assistants, so weaker on hard tasks
- Needs a machine with plenty of memory, especially for larger models
- The app around the model can still have cloud features, so check its settings
A practical split: use a local model for anything confidential, and a cloud assistant on a business plan for everything else. Our guide to running AI models locally covers the setup.
An AI privacy policy for a small team
A team does not need a legal document. It needs a page everyone has read. Adapt this one:
# How we use AI tools
1. Company work happens in company accounts on business plans,
which do not train on our data by default.
2. Never paste passwords, keys, customer personal data or NDA material
into any AI tool.
3. Personal AI accounts: training switched off, and no company data.
4. Use temporary or incognito chats for one-off sensitive questions.
5. No thumbs up or down on chats that contain company information.
6. Agents get a project folder and test keys, never production credentials.
7. New connectors (email, drive, calendar) need approval from [owner].
8. If something sensitive gets pasted, tell [owner] the same day.Review it twice a year. Provider settings and defaults change often, so recheck the help pages linked below when you do.
FAQ
Does ChatGPT train on my conversations?
On personal plans, OpenAI may use your chats to train its models unless you turn off “Improve the model for everyone” in Settings, then Data controls. By default, it does not train on ChatGPT Business, Enterprise, Edu or API data.
Are temporary and incognito chats private?
More private, not invisible. They stay out of your history and are not used for training, but providers keep a short-term copy for safety: up to 30 days for ChatGPT and 72 hours for Gemini.
Can a human read my AI chats?
Sometimes. Google says human reviewers read some Gemini chats, and keeps reviewed chats for up to three years, disconnected from your account. Providers also review chats that their safety systems flag.
If I delete a chat, is it gone?
From your view, immediately. From the provider’s systems, usually within 30 days, with exceptions for legal obligations, flagged content and data already de-identified or reviewed.
Is a paid personal plan more private than a free one?
Not by itself. ChatGPT Plus and Pro, and Claude Pro and Max, follow the same consumer rules as the free plans. What changes the defaults is a business plan with its own data terms.
- Your chats are stored by the provider, and training depends on one setting you control.
- Turn off training in each tool you use, and skip the feedback buttons on sensitive chats.
- Deleted does not mean gone at once: expect up to 30 days, longer for reviewed or flagged chats.
- Keep secrets, other people’s data and NDA material out of consumer chats entirely.
- Use business plans for company work and local models for the most sensitive text.
Read next: how prompt injection can turn an agent against you, and a practical guide to AI for small business.
- Data controls in ChatGPT, OpenAI Help Center, September 2026
- How your data is used to improve model performance, OpenAI Help Center, September 2026
- Chat and file retention in ChatGPT, OpenAI Help Center, September 2026
- Is my data used for model training? (consumer), Anthropic Privacy Center, March 2026
- How do I change my model improvement privacy settings?, Anthropic Privacy Center, August 2026
- How long do you store my data?, Anthropic Privacy Center, July 2026
- Is my data used for model training? (commercial), Anthropic Privacy Center, August 2026
- Gemini Apps Privacy Hub, Google, August 2026
- Generative AI in Google Workspace Privacy Hub, Google, August 2026
- Microsoft Copilot for individuals: your privacy controls and choices, Microsoft Support, August 2026
- Improving your recommendations on our apps with AI at Meta, Meta, October 2025




