Soulform

Essay

Who can read what you tell your AI?

Nobody is reading your chats out of curiosity, but the ones most likely to be reviewed are the ones you'd least want reviewed.

By Filipe Aleixo, 26 July 2026, 6 min read

Updated 27 July 2026

  • privacy

Writing to an AI feels like writing to something that won't judge you. Can you ever be sure no one else is reading?

It tends to arrive a few days late, never while you're typing. You're brushing your teeth and you remember how much you told it about your relationship, and wonder who else could read that.

Can the people behind the AI read my chats? Are deleted chats really deleted? Does it learn from what I say? And underneath those, can it be used against me?

These questions all come from the same place: the knowing only goes one way. People say things to an AI they wouldn't have told another person, and the reason is usually the same: the AI won't judge them for it. But somewhere on a server there is a version of you nobody else has met, and in exchange you know almost nothing: not who can read what you wrote, not how long it stays, not what delete actually removes.

I'm not going to tell you to stop confiding in AI. You don't have to. But you can find out what your AI provider commits to, and where they go quiet.

What the AI providers keep

Training means your words can be folded into a future version of the AI model itself. This is the biggest fork in the road, because it's the one place nothing can be walked back. You can delete the chat; the learning stays, and none of the three main AI providers offers to remove it from a model already trained.

ChatGPT and Claude both train on what you write unless you go and stop them. Consumer ChatGPT uses your conversations to improve its models unless you opt out, either in the data controls or through OpenAI's privacy portal. Claude did not train on consumer chats at all until August 2025; now it does unless you opt out in your account settings.

Gemini's version is a bundle. Keep Activity decides as one choice whether your chats are saved to your Activity and whether they train Google's models, and switching it off also makes Workspace unavailable inside Gemini.

How far back the switch reaches is where the three providers differ. Turn Anthropic's off and it stops using previous as well as new chats for future training, and deleting a chat takes it out too. The other two only scope forward: OpenAI's covers new conversations, Google's covers future chats, and neither says what happens to the ones already stored. What no switch can ever reach is a model training run already under way.

All three keep a way back into training, and none of the three toggles mentions it: rating a response. OpenAI says that even after you opt out, if you give a thumbs up or thumbs down then the entire conversation attached to that rating can be used for training. Anthropic says it may store the whole related conversation as part of your feedback, and train its models on it. Google reaches furthest: with Keep Activity off, submitting feedback lets it use the last twenty-four hours of your chats, not just the one you rated.

Anthropic is the only one of the three that publishes a safety carve-out: conversations flagged for safety review are used for model improvement regardless of your setting. Flagged material also gets its own clock: the conversation for two years, and the trust and safety scores about you for seven.

The business versions are where the strong promises live. OpenAI says plainly that it does not train on business or API customer data by default, and Anthropic says the same for its commercial products. Both tiers have a switch. What differs is which way it points before you touch it: business defaults to no and you opt in to share, while consumer, the tier people actually confide in at night, defaults to yes and you opt out.

Training is not the only thing the providers keep. Deleting a conversation deletes the transcript you can see, but these AI tools derive things from your words: memory entries, profile summaries, copies pulled for review, backups still inside their cycle.

OpenAI says this about its own memory: to fully delete something ChatGPT may know about you, you have to delete every source where it appears, including past chats, archived chats, files, the memory summary, and any connected apps. Memory lives separately from your chats, so deleting a conversation does not remove what was learned from it. Turn memory off and on again and it can rebuild itself from the history you kept.

And that first toggle decides more than training. OpenAI's deletion does not apply to content that has already been de-identified, which is what happens when you allow training, so allowing it quietly decides what the delete button can still reach. Anthropic de-identifies flagged content for safety training, and says it may re-identify that content to enforce its terms. Anything already trained into an AI model is, for practical purposes, beyond deletion everywhere.

Who may read it

Even with training switched off, your conversations sit on servers. All three providers publish an answer to who may read them, and in each case I found it in a help article rather than the privacy policy. OpenAI's names a limited number of authorized personnel, plus trusted service providers, for abuse investigations, support you asked for, legal matters, and model improvement. Anthropic's is narrower: access limited to a small number of personnel involved in model training, with your data de-linked from your email before review. Google's is a subset of chats read by human reviewers, including trained service providers, to improve Google services.

The plain summary: none of the three promises that no human will ever see a given conversation. One route in is a sample, pulled to improve the service. The other is a safety flag, and that one selects for the conversations you would least want anyone reading.

How long it stays

After you delete, ChatGPT schedules the conversation for permanent deletion within about thirty days, unless it is legally required to keep it or you allowed training, and Claude clears it from back-end storage within thirty days.

A different clock runs on what you leave alone. Gemini auto-deletes activity after eighteen months by default, a period you can change to three months, thirty-six, or off entirely. And if you allowed training, Claude keeps your data de-identified in its training pipelines for up to five years.

The legal requirement to keep data has already been used once with OpenAI: in 2025 a US court ordered it to preserve chats that users had already deleted; the full story lives in the deletion essay.

What to do tonight

Short of running an AI model on your own hardware, all of it runs on trust. If you use ChatGPT, Claude or Gemini, assume a person at the company reads this one conversation. You cannot check how often anyone actually reads, so weigh the consequence against what the writing gives you.

Tonight, in the AI you actually use: open the privacy or data settings, find the training toggle, and decide it deliberately instead of by default. Two minutes, and on Claude the change reaches back over what you already wrote.

If there's a temporary or incognito mode, read what it actually promises. None of the three feeds training, and all three still hold the chat: ChatGPT for up to thirty days for safety, Claude for thirty days, Gemini for seventy-two hours. Google is the one that says its reviewers still reach those chats, to protect the service though not to improve its AI.

If the tool keeps a memory or profile about you, open it and read what's in it, knowing that OpenAI says the summary will not show you everything it remembers. Read it for what the tool concluded about you.

Then delete what you'd want deleted, knowing now what deletion does and doesn't cover. Imperfect deletion is still worth doing. If you live in the EU or the UK you can request a copy of your data and its erasure, though no request reaches what is already inside a trained model. Which is the question underneath all of it: do you actually own what you wrote?

Going forward, sort what you confide into two piles by consequence. The tangle itself, the feelings, the reflection about who you're becoming: that material is about you, and you get to decide your own risk. Other people's secrets, real names attached to accusations, details that make a third party findable: keep those out of any logged-in tool, or strip the details that make them so. You can process your relationship without naming names.

You might have already given these AI tools the most unguarded version of you. Mostly, that ship has sailed. What you can do is end the asymmetry from here: the next time you confide something, you'll know the terms first.

Facts on this page are as of 26 July 2026, checked from the EU.
If something here is wrong, tell us and we will publish a correction, dated.

If you're in crisis right now, this page can wait.
Crisis resources are staffed by humans.