What happens to your AI chats after you hit send
One chatbot keeps your words five years, one feeds them to ads, and for months “delete” did nothing. The settings that change it.
In May 2025, a federal judge ordered OpenAI to stop deleting ChatGPT conversations. All of them: every user’s chats, including the ones people had deliberately deleted, had to be preserved as potential evidence in The New York Times’ copyright lawsuit. For about four and a half months, the delete button in the world’s most popular chatbot removed conversations from your screen and nothing else. Most of its hundreds of millions of users never knew.
That episode is the clearest lesson available about AI chat privacy: what happens to your words after you hit send is a policy decision, and policies can change without your screen looking any different. This post follows the text you type into the four biggest consumer chatbots. What gets kept and for how long, what trains future models, what now feeds ad targeting, and which parts you can change in about five minutes of settings. The answers differ far more than the chat windows do.
For four and a half months, delete deleted nothing
The preservation order deserves the opening slot because of how it ended, not just how it started. On October 9, 2025, Judge Ona T. Wang terminated it, backdated to September 26. OpenAI no longer had to preserve every outgoing chat. But the termination came with two exceptions that are still true today: everything saved during the freeze remains accessible to the case, and OpenAI must keep holding data for any account the Times flags as relevant, a list the court allowed to grow.
The uncomfortable middle of the story is June 2025, when coverage of the order spread and users discovered their delete buttons had been ceremonial for weeks. Nothing in the product had changed. No banner appeared in the chat window. The conversations people thought they had erased, and the temporary chats they believed were evaporating, were being set aside in a legal hold, viewable by a small audited legal team rather than truly gone. OpenAI fought the order loudly and publicly, calling it an overreach that swept up hundreds of millions of uninvolved users, and on the substance that objection was reasonable.
But that’s exactly the lesson. Your conversations sit in a database under someone else’s control, governed by their policy, their courts, and their litigation calendar. The point is not that OpenAI wanted this; it’s that wanting otherwise didn’t matter. A company can only promise you what a subpoena doesn’t override, and a privacy policy is a description of intentions, not a law of nature. Everything else in this post should be read with that asterisk attached.
Three questions decide how private a chatbot is
Privacy policies run thousands of words, but for a chat service they compress to three questions. How long is my conversation kept? Is it used to train future models? And who besides the model can see it: human reviewers, ad systems, lawyers? Every provider answers all three; they just answer them differently, and none of them put the answers in the chat window where you’d see them.
The three questions are not equally reversible, which is why the order matters. Retention expires: a chat kept 30 days is gone in 30 days. Human review is bounded: a stranger reads your conversation once. Training is forever: once your words have nudged a model’s weights, no deletion request reaches into the finished model and pulls them back out. Every provider’s policy says some version of this, quietly. It’s the reason the training question deserves more of your attention than the other two combined.
Two things jump out of that table. First, training on your conversations is the default almost everywhere; the differences are in how easy the exit is. Second, the retention numbers span two orders of magnitude, from 30 days to five years, for the same basic act of typing a question into a box. The next three sections take the rows one at a time.
ChatGPT trains on your chats unless you flip one switch
For ChatGPT’s free and Plus tiers, the “Improve the model for everyone” setting ships turned on: your conversations are eligible to train future models until you find Settings, then Data Controls, and turn it off. Turning it off only protects future chats. Anything already absorbed into training stays absorbed; there is no reaching back into a model’s weights to remove your contribution.
Deletion has a defined shape too: a deleted conversation leaves OpenAI’s systems within about 30 days, unless a legal hold (see above) says otherwise. For one-off sensitive questions there’s a cleaner tool: Temporary Chat, which never enters your history, is never used for training, and is kept at most 30 days as a safety copy. It’s the closest thing a major chatbot offers to an incognito mode, and almost nobody uses it.
Why is the default on? Because the arrangement is genuinely useful to OpenAI: real conversations are the raw material that makes the next model better at real conversations. There’s nothing hidden about it; the setting is documented, named in plain English, and honored when you flip it. But defaults do the deciding for most people. The practical takeaway isn’t outrage, it’s five seconds of awareness: know which side of that switch you’re on, because right now you are on one of them.
Claude and Gemini differ most on one number: how long
Anthropic did something unusual in August 2025: it asked. Every Claude Free, Pro, and Max user was shown an explicit choice: allow chats to train models, or don’t. The honest part is the price tag attached to each answer. Say yes and new conversations are kept up to five years. Say no and retention drops to 30 days. Deleted conversations aren’t used for training either way, and the choice can be reversed anytime in privacy settings, though only for chats going forward. Five years is a long time; 30 days is among the shortest defaults in the industry. Few products put a 60x gap behind a single toggle.
The catch is that the choice arrived as a popup, and popups get clicked through. Existing users faced a deadline: pick an answer or stop using the product. An answer given in a hurry, months ago, is still governing your retention today. If you use Claude and can’t remember which button you pressed, that is precisely the problem, and the privacy settings page will tell you in ten seconds.
Google’s Gemini buries its number deeper. Gemini Apps Activity keeps your chats for 18 months by default, adjustable to 3 or 36, and uses them to improve Google’s models. The fine print is where it gets interesting: conversations sampled for human review are kept up to three years, stored disconnected from your account, and deleting your activity does not delete them. Turn activity off entirely and chats still linger 72 hours. Google’s own page says the quiet part plainly: don’t enter anything confidential you wouldn’t want a reviewer to see. That warning applies, in practice, to every service in the table.
Meta crossed a line the others haven’t: chats now tune ads
Every provider above uses chats to make the model better. Only one uses them to make advertising better. Since December 16, 2025, what you say to Meta AI on Facebook and Instagram becomes a signal for the ads and content you see, the same way liking a post always has. Meta announced the change on October 7, 2025 through in-app notices and emails, the kind most people swipe away, then switched it on for everyone about two months later. Mention hiking to the assistant and the feed learns you hike. Meta excludes sensitive categories from targeting, including health, religion, politics, and sexual orientation, and WhatsApp chats stay out unless you link accounts. Regulated markets like the EU and UK were carved out of the rollout.
The detail that matters most: there is no opt-out for this specific use. You can tune ad preferences around the edges, but no switch keeps your AI conversations out of personalization while you keep using the assistant. The exit is the door. That is a genuinely different deal from the other three, and worth knowing before you treat the assistant in your group chats like a diary.
Businesses already bought the privacy you’re not getting
Here is the asymmetry hiding under all of this: the strict privacy defaults already exist, just not for you. Data sent to OpenAI’s API is not used for training, full stop, no toggle to find; requests are kept about 30 days for abuse monitoring, and approved organizations can get zero data retention, where content isn’t stored at all. Anthropic’s commercial and API traffic sits entirely outside the consumer training policy. Enterprise chatbot tiers make the same promise. When a customer pays per token and can walk away, no-training-by-default is simply what the contract says.
The split even held under legal pressure: through the preservation saga, OpenAI’s zero-retention API arrangements stayed outside the order’s reach, because you cannot be forced to preserve what you never stored. Not storing the data turns out to be the only privacy posture that survives every scenario: policy changes, acquisitions, breaches, and subpoenas alike. Businesses figured this out and negotiated for it. Consumers mostly haven’t, because the chat window never mentions it.
The consumer app and the API often serve the exact same model. The difference is the deal around it: one side pays with money, the other partly with words. That’s not an accusation, it’s the pricing structure, and it’s why we’ve argued before that bringing your own API key changes more than the bill. Route your usage through a key and your prompts ride on the business-tier rules automatically.
Five minutes of settings fixes most of it; local fixes the rest
None of this means stop using AI chatbots. It means spend five minutes matching each app’s settings to what you actually type into it. The full pass:
Then adopt one habit that beats every toggle: keep identity out of content. A chatbot can help with your lease, your budget, or your health question without knowing whose they are; strip names and account numbers before pasting, the same discipline we recommend for money questions. Settings govern what a company does with your words. Redaction governs what the words are worth.
And for the conversations you’d never want in anyone’s database, the clean answer is the one this whole story points at: run the model on your own machine. A local model answers with the network cable unplugged. There is no retention window because there is no server, nothing to subpoena from a provider, no training default to find, no policy update arriving by email. The open models you can run today are past the point where private has to mean worse. Every provider in this post answers the three questions differently. A model on your own hardware is the only setup where you never have to ask them.
Disclaimer: This is general information, not legal advice. Tool licenses, content-usage rights, and platform policies summarized here change frequently and reflect sources available as of August 2026. Verify the current terms of each tool and the rules of each platform or marketplace before publishing commercial work, and consult counsel where real money or rights are at stake.


