Is It Safe to Put Your Information Into AI Tools?
It depends on three things: which tool, which account you are signed into, and what you paste. A free consumer chatbot and the same company's business product frequently have opposite defaults on whether your conversation is used to train the model. Nothing you type is as private as a note to yourself. Most of the real risk is avoidable once you know where to look.
What happens when you press send
Your text leaves your device for the company's servers, because the model runs there rather than on your laptop. What happens next is set by product policy, not by anything visible in the chat window, and that policy belongs to whoever built the chatbot in front of you rather than to the model it calls.
Four things are commonly true at once. The conversation is stored, so you can return to it. It may be used to improve future versions of the model. It may be read by a person: Google's Gemini Apps Privacy Hub states that human reviewers assess conversations, and that reviewed chats are kept up to three years, separated from your account. And it may persist after you delete it.
Training use is narrower than it sounds. Almost everything a model knows was gathered before you opened the app, which is the subject of where training data actually comes from. Your conversation, if it is used at all, is one small addition to that. It is still your text.
The US National Institute of Standards and Technology treats this as a named risk. Its Generative AI Profile, published in July 2024, lists Data Privacy among twelve risks specific to generative systems and notes that models "may leak, generate, or correctly infer sensitive information about individuals."
Consumer and business accounts often have opposite defaults
The same company often ships one set of defaults to individuals and the reverse set to paying organizations.
OpenAI's help documentation, current as of September 2026, describes the split. For individual accounts it says "we may use your content to train our models," with an opt-out in settings. For business products it says "By default, we do not train on any inputs or outputs from our products for business users," covering Business, Enterprise and the API.
The trade in a work account is worth naming: stronger contractual protection against training, less privacy from your employer. OpenAI's help page on deleting chats notes that "Authorized compliance tools may still access eligible workspace data under your organization's retention policy." A work account is not a private account.
Defaults also move. Anthropic announced on 28 August 2025 that Claude Free, Pro and Max users would be asked to choose whether their conversations could be used for training, with five-year retention for those who allow it and 30 days for those who decline, and that the change did not apply to its commercial products. One company, one date, and it makes the general point: whatever you confirm today has a shelf life.
What a review of the major privacy policies found
In September 2025, Stanford researchers led by Jennifer King published an analysis of the privacy policies of six frontier AI developers, as those policies stood in May 2025: Amazon, Anthropic, Google, Meta, Microsoft and OpenAI. Reading 28 documents across the six companies, they found that all six "appear to employ their users' chat data to train and improve their models by default," that some retained it indefinitely, and that the policies often omitted basic information about what was collected and for how long. Companies running many products also merge chatbot interactions with data from elsewhere in their services, and most did not filter children's conversations out of training sets.
Two caveats matter: this is a reading of published policies at a fixed date, not an audit of internal systems, and several of those policies have changed since. The paper accounts for one of those changes itself, noting that Anthropic moved consumer accounts from opt-in to opt-out in August 2025, which is a move toward training on chat data rather than away from it. King's advice in Stanford's October 2025 write-up was narrow and reasonable. Think twice before sharing sensitive personal or health details, and opt out of training wherever the option exists.
Deleting a chat is a policy, not a physical law
Delete usually means scheduled for deletion. OpenAI says a deleted conversation leaves your account view immediately and is scheduled for permanent deletion within 30 days, "unless it was already de-identified and disassociated from your account or OpenAI must retain it longer for security or legal obligations."
That final clause did real work. In the copyright case brought by The New York Times, a court ordered OpenAI to preserve consumer ChatGPT output data it would otherwise have deleted. OpenAI said on 5 June 2025 that the order covered Free, Plus, Pro and Team, now called Business, along with API customers without a zero data retention agreement, but not Enterprise or Edu. That preservation obligation ended on 26 September 2025 and OpenAI returned to deleting content within 30 days.
The data already preserved did not go away. In November 2025 the court ordered OpenAI to hand 20 million of those conversations to the plaintiffs, and a district judge upheld that order on 5 January 2026. OpenAI says the sample was drawn from December 2022 to November 2024, that it does not cover Enterprise, Edu, Business or API customers, and that the conversations are de-identified before release. As of September 2026 the dispute over that production is still running.
The lesson is not about one company. A deletion promise describes ordinary operations, and litigation can suspend it and then reach back into what was kept. Treat "I deleted it" as better than nothing, not as proof the text is gone.
Anything a memory feature saved from a conversation is a separate record with its own delete button, covered in what the product stores about you.
What not to paste
The UK National Cyber Security Centre set out two rules in March 2023 that still hold: do not include sensitive information in queries to public chatbots, and do not submit anything that would cause a problem if it were made public.
Canada's Get Cyber Safe programme, in guidance dated 6 December 2024, names social insurance numbers, financial information and account credentials specifically, and adds that "once you provide your data, you lose control over where it goes and who can see it."
The Office of the Privacy Commissioner of Canada, in guidance updated 6 May 2025, covers the part people forget. It advises limiting identifiable detail, altering names where you can, and never sharing pictures or personal information of minors. Much of what ends up in a chatbot belongs to someone else: a colleague's performance issue, a friend's diagnosis, a client's contract. You are disclosing it on their behalf.
Google says the same thing from the vendor side: "Please don't enter confidential information that you wouldn't want a reviewer to see or Google to use to improve our services."
A workable test is whether you would be comfortable with the text appearing in a support ticket at that company. If not, rewrite it first. Replacing names with roles, cutting account numbers and describing a situation rather than pasting the document usually costs nothing in answer quality.
How to check the tool in front of you
Three checks cover most cases and outlast any menu redesign. They take two minutes per tool, once, and they sit alongside the ordinary habits of using AI well.
Find the training setting. It nearly always lives under an account menu, in a section called Privacy, Data controls or Activity, and the wording refers to improving the model or saving activity. Turning it off usually stops future conversations being used for training. It does not delete existing history, a separate control.
Find the retention setting. Some products let you choose how long activity is kept, and some offer a mode that skips history entirely. In ChatGPT that is Temporary Chat, which OpenAI says is not used for training and is deleted after 30 days. Google keeps chats 72 hours when activity is off.
Search the terms for two words rather than reading the document: "train" and "retention". Nearly every sentence that affects you sits next to one of them. If the tool is a small product built on a larger model, check what it says about the underlying provider, because a thin wrapper inherits that provider's handling of your text.
Tools that act on your behalf need more care than tools that only answer. An assistant with access to your inbox can be manipulated by instructions hidden in what it reads, a problem called prompt injection, so the question becomes what the tool can reach as well as what you type. Our guide to AI agents covers the difference.
If you have already pasted something sensitive
The right response depends on what it was.
A password, API key or access token: change it. That is the one case with a clean fix, and speed matters more than tidiness.
A financial or government identifier: deletion helps but does not undo the disclosure. Watch the account, and use any fraud monitoring you have.
Confidential work material: tell whoever owns that risk at your organization. Unwelcome, and almost always better than the alternative, because your employer may have an agreement with the provider that changes the options.
In every case, delete the conversation and check whether the training setting was on at the time. If it was, turn it off and look for the provider's data deletion request form, which many jurisdictions require. Opting out later may not remove content already used.
Sharing a chat is a publishing decision
The one habit worth forming applies before anything goes wrong. In late July 2025 OpenAI removed a feature that let a shared chat link be discoverable by search engines, after Fast Company found thousands of such conversations indexed by Google. The option was opt-in, and people checked it without understanding the consequence. OpenAI's chief information security officer said it "introduced too many opportunities for folks to accidentally share things they didn't intend to."
That particular feature is gone. The decision it exposed is not. A share link is a copy of the conversation living outside your account, readable by anyone who has it, and it carries the whole thread rather than the one answer you meant to show someone. Read back what you are about to publish.
That is the short version of the whole article. Know which account you are signed into, know what the training setting is doing, and decide what goes in before you type it rather than after. Those three habits are available on every tool, they survive every redesign, and they cover most of the risk you can actually control.
Related AI terms
- Data privacy: protecting personal information exposed to AI systems.
- PII: information that can identify a specific person.
- AI training opt-out: a setting meant to keep your data out of training.
- Temporary chat: a mode that limits how a conversation is saved.
- Zero data retention: an arrangement where a service keeps nothing afterwards.
- Training data consent: agreement covering use of data to train AI.
Frequently Asked Questions
Does incognito mode or a VPN make an AI chat private?
No, and the reason is worth understanding. A private browsing window hides the session from other people using your computer, and a VPN hides which network your traffic came from. Neither changes anything at the other end. Your text still arrives at the company's servers, still lands in an account, and is still handled under whatever that product's retention and training policy says. The controls that matter are inside the AI tool, not in your browser or your connection.
Is it safe to enter personal information into ChatGPT?
Use one rule and most decisions answer themselves: do not type anything you would mind seeing in a support ticket at that company. Some categories fail that test every time. Passwords and access keys, financial and government identifiers, health details, and identifying information about someone else, particularly a child, should not go in at all. Canada's Get Cyber Safe guidance names credentials, financial information and social insurance numbers specifically. Before you paste anything borderline, open the account settings and check what the training control is set to, then rewrite the text with roles instead of names. That edit usually costs nothing in the quality of the answer.
Can the AI repeat my information back to someone else?
Possible in principle, unlikely for any one message. Research presented at the 2021 USENIX Security Symposium showed that verbatim text, including names and contact details, could be extracted from a language model's training data, and that larger models memorised more. That took a deliberate attack on an older model. The realistic routes are simpler: a breach of the stored conversation, a reviewer reading it, an administrator retrieving it from a work account, or you sharing a link yourself.
Does turning off training delete my chat history?
No. They are separate controls in most products. OpenAI states that with the training setting off, conversations still appear in your history but are not used to improve the model. If you want the content gone you have to delete it, and deletion is usually scheduled rather than instant. Some products offer a mode that skips history altogether, which is cleanest for a question you would rather not have stored.
Is a work AI account more private than my personal one?
More protected in one direction, less in the other. Business and enterprise accounts usually come with a contract saying the provider will not train on your content, and often with retention controls the organization sets. They also mean your employer administers the data, and OpenAI notes that authorised compliance tools may access eligible workspace content under an organization's retention policy. Use the work account for work, and not as a private space.
Is a model that runs on my own computer safer?
For the part of the problem covered here, yes, because the text never leaves the machine. If the model runs locally, there is no server copy, no retention period, no reviewer and no legal hold to worry about, since none of those things have anything to hold. The trade is that local models are generally smaller and less capable than the hosted ones, and you take on the security of your own device. It is a reasonable answer for a narrow set of genuinely sensitive work, not a general substitute.
Can people see my conversations with AI?
Some people, in defined circumstances. Google's Gemini Apps Privacy Hub states that human reviewers assess conversations, and that reviewed chats are kept for up to three years, separated from your account. Other users of the same product cannot reach your chats, with two exceptions you create yourself: a share link, which is a readable copy of the whole thread for anyone holding it, and a work or school account, where OpenAI notes that authorised compliance tools may access eligible workspace data under your organization's retention policy. Courts are the third route. In the New York Times litigation a court ordered OpenAI to preserve consumer conversations it would otherwise have deleted, and later to hand a sample of them to the other side.
Sources
- Get Cyber Safe, Government of Canada, "Why you should never give your personal information to AI," 6 December 2024. https://www.getcybersafe.gc.ca/en/blogs/why-you-should-never-give-your-personal-information-ai
- Office of the Privacy Commissioner of Canada, "Your privacy and AI chatbots," updated 6 May 2025. https://www.priv.gc.ca/en/privacy-topics/technology/artificial-intelligence/ai-chatbots_ind/
- UK National Cyber Security Centre, "ChatGPT and large language models: what's the risk?," 14 March 2023. https://www.ncsc.gov.uk/blog-post/chatgpt-and-large-language-models-whats-the-risk
- National Institute of Standards and Technology, "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile," NIST AI 600-1, July 2024. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf
- Jennifer King, Kevin Klyman, Emily Capstick, Tiffany Saade and Victoria Hsieh, "User Privacy and Large Language Models: An Analysis of Frontier Developers' Privacy Policies," 5 September 2025. https://arxiv.org/abs/2509.05382
- Nikki Goth Itoi, "Be Careful What You Tell Your AI Chatbot," Stanford Institute for Human-Centered AI, 15 October 2025. https://hai.stanford.edu/news/be-careful-what-you-tell-your-ai-chatbot
- Stanford Report, "Study exposes privacy risks of AI chatbot conversations," 15 October 2025. https://news.stanford.edu/stories/2025/10/ai-chatbot-privacy-concerns-risks-research
- Nicholas Carlini et al., "Extracting Training Data from Large Language Models," 30th USENIX Security Symposium, August 2021. https://www.usenix.org/conference/usenixsecurity21/presentation/carlini-extracting
- OpenAI, "How your data is used to improve model performance," OpenAI Help Center. https://help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance
- OpenAI, "Data Controls FAQ," OpenAI Help Center. https://help.openai.com/en/articles/7730893-data-controls-faq
- OpenAI, "How to delete and archive chats in ChatGPT," OpenAI Help Center. https://help.openai.com/en/articles/8809935-how-to-delete-and-archive-chats-in-chatgpt
- OpenAI, "How we're responding to The New York Times' data demands in order to protect user privacy," 5 June 2025, updated 22 October 2025. https://openai.com/index/response-to-nyt-data-demands/
- Anthropic, "Updates to Consumer Terms and Privacy Policy," 28 August 2025. https://www.anthropic.com/news/updates-to-our-consumer-terms
- Google, "Gemini Apps Privacy Hub," Gemini Apps Help. https://support.google.com/gemini/answer/13594961
- Engadget, "OpenAI is removing ChatGPT conversations from Google," 1 August 2025. https://www.engadget.com/ai/openai-is-removing-chatgpt-conversations-from-google-194735704.html
- Chris Stokel-Walker, "Exclusive: Google is indexing ChatGPT conversations, potentially exposing sensitive user data," Fast Company, 30 July 2025. https://www.fastcompany.com/91376687/google-indexing-chatgpt-conversations
- OpenAI, "Fighting the New York Times' invasion of user privacy," 12 November 2025. https://openai.com/index/fighting-nyt-user-privacy-invasion/
- Jones Walker LLP, "OpenAI Loses Privacy Gambit: 20 Million ChatGPT Logs Likely Headed to Copyright Plaintiffs," National Law Review, January 2026. https://natlawreview.com/article/openai-loses-privacy-gambit-20-million-chatgpt-logs-likely-headed-copyright
- TechCrunch, "New York Times says OpenAI hid evidence in ChatGPT copyright trial," 9 July 2026. https://techcrunch.com/2026/07/09/new-york-times-says-openai-hid-evidence-in-chatgpt-copyright-trial/