
A padlock and a phone. Image: Book Catalog / Wikimedia Commons, CC BY 2.0, cropped
Millions of people now tell AI chatbots things they wouldn’t tell their friends: health worries, money problems, relationship trouble, work secrets. But where does all of that go? Who can read it? How long is it kept? And is it being used to train the next model, or to sell you something? We went through the privacy policies, help pages and official statements of the six biggest AI companies to find out. The short answer: unless you change your settings, most of them are using your conversations, and the details vary a lot more than you might expect.
This guide covers personal (consumer) accounts, as of September 2026. Business, enterprise and developer (API) accounts almost always get much stronger protections, which we cover at the end. Policies change often, so check your own settings.
At a glance: how the six compare
Swipe the table sideways to see every column →
| Company | Trains on your chats by default? | Can you opt out? | Can humans read your chats? | How long chats are kept | Chats used for ads? | Private mode |
|---|---|---|---|---|---|---|
| OpenAI (ChatGPT) | Yes | Yes | Yes, for safety, support and legal reasons | Until you delete them; then up to 30 days | Yes on Free and Go plans | Temporary Chat (30 days, no training) |
| Anthropic (Claude) | Yes, since 2025, unless you opted out | Yes | Limited: flagged chats and feedback | Up to 5 years if training is on; 30 days if off | No | Incognito (never used for training) |
| Google (Gemini) | Yes | Yes | Yes, human reviewers | 18 months by default; reviewed chats up to 3 years | No, says Google | Temporary chat (72 hours) |
| Meta (Meta AI) | Yes | No in the US; EU and UK can object | Not clearly stated | Not clearly stated | Yes, with no opt-out (outside EU, UK, South Korea) | None |
| Meta (Muse agent) | Yes, after removing personal info | Yes | Not clearly stated | Until you tell it to forget | No | User-held encryption promised |
| Microsoft (Copilot) | Yes | Yes | Some, for improvement and safety | 18 months | Yes, if personalization is on | Not signed in (excluded from training) |
| Apple (Apple Intelligence) | No | Not needed | No, says Apple | Not stored in its cloud | No | Private by design |
Green = better for your privacy, red = worse, amber = partly or unclear. Based on each company’s published policies as of September 24, 2026.
The quick verdict: Apple is the clear outlier, keeping most processing on your device or in cloud servers it says even it can’t access. Anthropic and Google don’t use your chats for ads, but keep them for a long time if you let them train on your data. OpenAI, Microsoft and especially Meta now use what you tell their chatbots to shape the ads you see.
OpenAI (ChatGPT)
Does it train on your chats?
Yes, by default. If you use ChatGPT’s Free, Go, Plus or Pro plans, your conversations can be used to train OpenAI’s models unless you switch it off. You can do that in Settings → Data Controls → “Improve the model for everyone,” according to OpenAI’s help center. You can keep your chat history while opting out.
Two things to know. First, opting out only applies to future chats; anything already used for training stays in the models. Second, opting out doesn’t mean nobody at OpenAI can ever see your chats. OpenAI says authorized staff and trusted service providers may still access conversations to investigate abuse or security incidents, provide support, or deal with legal matters.
How long does it keep them?
Your chats stay in your history until you delete them. Deleted chats and Temporary Chats, which don’t appear in your history and are never used for training, are removed from OpenAI’s systems within 30 days.
That promise was tested in 2025. As part of its copyright lawsuit, The New York Times got a court order in May 2025 forcing OpenAI to keep chat logs it would normally have deleted, including deleted chats. OpenAI fought the order, and it was lifted from September 26, 2025, Engadget reported, but logs already preserved remain held, along with data from accounts the Times flagged. It’s a reminder that “deleted” can be overruled by a judge.
Ads are now in ChatGPT
This is the biggest change of 2026. OpenAI began showing ads to logged-in adults on the Free and Go plans in the US in February, and has since expanded to Europe and parts of Asia. Ads are matched using the topic of your current conversation and, if you have personalization turned on, your past chats, memories and previous ad interactions.
OpenAI’s advertising principles say ads don’t influence ChatGPT’s answers, that it keeps “conversations with ChatGPT private from advertisers,” and that it never sells your data to advertisers. The matching happens inside OpenAI. You can turn off ad personalization, clear the data used for ads, accept fewer daily messages to avoid ads, or pay for an ad-free plan like Plus or Pro.
Incidents
- Shared chats on Google (2025): a “make this chat discoverable” option on shared links led to thousands of ChatGPT conversations, some containing mental health details and confidential work, showing up in search results. OpenAI scrapped the feature.
- Mixpanel breach (November 2025): an analytics vendor was hacked, exposing names, emails and rough locations of some API users. OpenAI says no chats, passwords or payment details were involved.
Using ChatGPT through Siri
If you use ChatGPT through Apple’s Siri without signing in, you get stronger protection. Apple hides your IP address, and under Apple’s terms OpenAI must not store your requests or use them for training. Sign in to your ChatGPT account, though, and OpenAI’s normal rules apply. (OpenAI recently told a court that hardly anyone uses the Siri integration anyway.)
Anthropic (Claude)
Does it train on your chats?
It does now, unless you say no. For years, Anthropic stood out for not training on consumer conversations. That changed on August 28, 2025, when it asked Free, Pro and Max users, including people using Claude Code on those plans, to choose whether their chats could be used to improve Claude. Anthropic says it didn’t apply a default, but critics pointed out that the setting in the pop-up was switched on unless you turned it off. You can change it any time in Settings → Privacy.
Anthropic says it uses “a combination of tools and automated processes to filter or obfuscate sensitive data” and that it does “not sell users’ data to third parties.”
How long does it keep them?
This is where Claude’s policy gets long. According to Anthropic’s privacy center:
- If you allow training, your data may be kept “in a de-identified format for up to 5 years.”
- If you don’t, the previous 30-day retention applies.
- Deleted chats disappear from your history immediately and from Anthropic’s back-end systems within 30 days.
- Chats flagged by its automated safety systems are kept for up to 2 years, and their safety classification scores for up to 7 years.
- Feedback you send, such as a thumbs up or down, is kept for 5 years.
Incognito chats are never used for training, even if you’ve allowed it for normal chats.
Ads
Claude has no ads.
Incidents
In July 2026, around 600 Claude conversations and “Artifacts” that people had shared with public links turned up in Google and Bing search results, some including medical details and personal contact information, Malwarebytes reported. It wasn’t a hack, and only shared chats were affected, but it was the second such incident for Claude in two years, and Anthropic said the feature was working as designed.
Google (Gemini)
What it collects
Google’s Gemini privacy hub is refreshingly blunt about how much it collects: everything you type, say or share with Gemini, including files, photos, videos and your screen, plus information from your apps and devices, which can include call and message logs, contacts, installed apps and on-screen content.
Does it train on your chats, and can people read them?
Yes, and yes. A setting called Keep Activity (formerly Gemini Apps Activity) is on by default. While it’s on, your conversations can be used to improve Google’s AI models and can be read by human reviewers, who check whether Gemini’s answers are accurate and safe. Google explicitly warns people not to share anything confidential that they wouldn’t want a reviewer to see.
How long does it keep them?
- With Keep Activity on, chats are kept for 18 months by default. You can change this to 3 months, 36 months or forever.
- Chats seen by human reviewers are disconnected from your account but kept for up to 3 years, and they’re not deleted when you delete your activity.
- Even with Keep Activity off, chats are kept with your account for 72 hours so Gemini can respond and to guard against system failures.
- Temporary chats last 72 hours and aren’t used for training.
Gmail, Photos and ads
Gemini can now connect to your Gmail, Photos, Drive and Calendar through a feature called Personal Intelligence, which is off by default. Google says Gemini “doesn’t train directly on your Gmail inbox or Google Photos library,” only on things like your prompts and its responses, after filtering out personal data. And on ads, Google is clear: “Your Gemini Apps chats are not being used to show you ads.”
Meta (Meta AI and Muse)
Meta runs two very different AI products with very different rules.
Meta AI: your chats shape your ads
Since December 16, 2025, Meta has used people’s conversations with Meta AI, in its standalone app and inside Facebook, Instagram, WhatsApp and Messenger, to personalize the content and ads they see, Meta announced. There’s no setting to opt out; the only way to avoid it is not to use Meta AI. Meta says it won’t use chats about sensitive topics, such as health, for ad targeting, and the change doesn’t apply in the EU, UK or South Korea.
Your Meta AI conversations, along with public posts, are also used to train Meta’s AI models. People in the EU and UK can object under data protection law; in the US, there’s no equivalent option.
Meta AI also had a notorious privacy stumble in 2025, when people using its app accidentally published private conversations, about medical problems, legal troubles and relationships, to a public “Discover” feed after tapping Share. Meta added a warning screen after a campaign by the Mozilla Foundation.
Muse: a much more private design
Muse, the personal AI agent Meta launched on September 8 (and the one inside the new Muse Charm gadget), works differently:
- Meta says Muse “doesn’t share a person’s conversations or the data in their VM with Meta’s ad systems.”
- Each person’s Muse runs on its own isolated cloud computer, and a separate “Sentinel” agent must approve anything it sends to the internet.
- Muse can’t see your passwords or payment methods, which go into secure storage.
- You can opt out of your Muse interactions being used for training. If you don’t, Meta says it removes critical personally identifying information first.
- Later this year, Meta promises a “Confidential VM” where your data and conversations are encrypted “with a key only they hold, so not even Meta can access it.”
If Meta delivers that last point, Muse would go from one of the least private AI products to one of the most private. For now, it’s a promise.
Microsoft (Copilot)
Does it train on your chats?
Yes, unless you opt out. According to Microsoft’s Copilot privacy FAQ, conversations from consumer Copilot are used to train its AI models, but some people are automatically excluded: anyone not signed in, users under 18, people using work or school accounts, and everyone in Brazil, China (excluding Hong Kong), Israel, Nigeria, South Korea and Vietnam.
Microsoft says it doesn’t train on your Microsoft account profile, your email contents, or identifying information in images and files you upload, and that it removes names, phone numbers, addresses and other identifiers before training.
In August 2026, Microsoft merged its consumer and work Copilot apps into one. Under the new app’s privacy terms, Microsoft may use your voice and text conversations, images and files you upload, and de-identified Bing and MSN data to improve Copilot, unless you opt out in your privacy settings.
How long does it keep them, and who sees them?
Conversations are kept for 18 months, and you can delete them at any time. Some conversations are reviewed by automated systems and humans for product improvement and safety, and Microsoft says there’s no way to opt out of review when a violation is suspected.
Ads
If you turn on personalization, Microsoft uses your Copilot conversation history to “further personalize the ads you already receive.” Its privacy statement says Copilot uses prompts to provide and improve services, “including relevant advertising.”
Legal scrutiny
In August 2026, US law firm Migliaccio & Rathod said it was investigating whether Copilot users clearly understood and agreed to their conversations being used for AI training. It’s an investigation, not a lawsuit, but it shows how opt-out training is becoming a legal flashpoint.
Apple (Apple Intelligence and Siri)
The privacy outlier
Apple takes a fundamentally different approach. Apple Intelligence runs on your device where it can, and sends harder requests to Private Cloud Compute, Apple’s own AI servers. Apple says that when Private Cloud Compute handles your request, “personal data is not stored nor made accessible to Apple or anyone else,” and that outside security experts can inspect the software to check that claim, according to its June announcement. Apple has also said it doesn’t use its users’ private personal data or interactions to train its AI models, and it doesn’t use your AI requests for advertising.
What about Google’s Gemini inside Siri?
This year’s new Siri is built on Apple Foundation Models “custom-built in collaboration with Google and its Gemini models.” That has raised understandable questions about whether Google can see your Siri requests. According to Apple, the requests still run through Private Cloud Compute under its privacy protections, and reports on the deal say Google isn’t allowed to use Siri interactions to train its own models. That second point comes from reporting on the deal, not from Apple directly.
The weak spots
Apple’s protections apply to Apple Intelligence itself. If you hand a request to ChatGPT through Siri while signed in to your ChatGPT account, OpenAI’s rules apply instead. And Apple’s own record isn’t spotless: in 2025 it agreed to pay $95 million to settle a lawsuit claiming Siri recorded private conversations without people’s knowledge, CBS News reported. Apple denied any wrongdoing.
What they have in common
1. Training is on unless you turn it off
Five of the six companies use personal-account conversations to train their AI by default. Only Apple doesn’t. Opting out is usually a single switch, but hardly anyone changes their defaults.
2. Opting out doesn’t undo the past
Every company that offers an opt-out applies it to future chats only. Anything already used to train a model can’t be pulled back out.
3. “Delete” doesn’t always mean deleted
Google keeps chats seen by human reviewers for up to three years, even after you delete them. Anthropic keeps flagged chats for up to two years and their safety scores for seven. And a court order kept OpenAI from deleting chats for months. Deleting a chat removes it from your view; it doesn’t always remove it everywhere.
4. People may read what you write
Google openly uses human reviewers. OpenAI, Microsoft and Anthropic all allow staff access for safety, abuse or support reasons. If you wouldn’t want a stranger to read it, don’t type it.
5. Chatbots are becoming ad businesses
A year ago, none of these chatbots used your conversations for ads. Today, ChatGPT, Meta AI and Copilot all do in some form. Google, Anthropic and Apple say they don’t. Expect this to be the privacy battleground of the next few years.
6. The biggest leaks come from the Share button
Most real-world exposure hasn’t come from hackers but from sharing features: ChatGPT links in Google search in 2025, Meta AI’s public Discover feed in 2025, and shared Claude chats in search results in 2026. A shared link is public. Treat it that way.
7. Business accounts get far better treatment
ChatGPT Business and Enterprise, Claude’s Team and Enterprise plans, Google Workspace, and Microsoft 365 Copilot for work accounts are all excluded from training by default, with admin-controlled retention. OpenAI and Anthropic’s developer APIs don’t train on your data either. If your job involves confidential information, use your employer’s approved tools, not your personal account.
8. Where you live matters
People in the EU and UK have legal rights to object that Americans don’t, which is why Meta’s ad changes don’t apply there and why Microsoft excludes several countries from training entirely.
How to protect yourself: a checklist
- ChatGPT: Settings → Data Controls → turn off “Improve the model for everyone.” Use Temporary Chat for sensitive topics. Turn off ad personalization if you see ads.
- Claude: Settings → Privacy → turn off the option to help improve Claude. Use Incognito for anything sensitive.
- Gemini: go to myactivity.google.com/product/gemini and turn off Keep Activity, or shorten auto-delete to 3 months. Use Temporary chats.
- Meta AI: there’s no US opt-out for ads or training, so the safest option is not to share anything personal. In the EU or UK, use Meta’s objection form. If you use Muse, opt out of training in its settings.
- Copilot: in your privacy settings, turn off model training, and turn off personalization if you don’t want your chats shaping ads.
- Apple: nothing to change for Apple Intelligence. Use ChatGPT through Siri without signing in if you want Apple’s extra protections.
- Everywhere: don’t paste passwords, ID numbers, bank details or other people’s personal information into a chatbot, and think twice before hitting Share.
MadRobot’s take
The uncomfortable truth is that the most useful thing about AI chatbots, that you can talk to them like a person, is exactly what makes their privacy policies matter so much. People confide in them. And for most of these companies, those confidences are, by default, raw material: for training, for product improvement and, increasingly, for advertising.
None of this is hidden. It’s all in the policies we’ve linked above. But it relies on people finding settings they don’t know exist and understanding retention rules that run to several pages. Apple has shown that a different model is possible, and Meta’s promises for Muse suggest even the most data-hungry companies know privacy can be a selling point.
Until private-by-default becomes the industry norm, the burden is on you. Spend five minutes changing your settings using the checklist above. It’s the cheapest privacy upgrade you’ll ever make.
Sources: OpenAI, OpenAI (advertising), Anthropic, Anthropic Privacy Center, Google, Meta, Meta (Muse), Microsoft, Apple, Apple (ChatGPT extension)


