Skip to content
beginnerprivacydata-protectiongetting-startedai-curious

Is It Safe? What Happens to What You Type Into AI

Where your chats go, who can see them, whether they train the model, and what has actually gone wrong so far. Then how I decide what to share, and how to make that decision yourself.

Fabian Mösli Fabian Mösli
· 12 min read · 2026-10-01

Key Takeaways

  • • Your chats are stored on the vendor's servers, may be read by reviewers, can be requested in court, and on personal accounts may train future models unless you switch that off. What matters is whether it's a personal account or a work account.
  • • Most real incidents so far came from share buttons, breaches and people pasting company data into personal accounts. A model repeating your chat word for word to a stranger is very unlikely, and with training switched off it doesn't apply.
  • • Chatting with AI is roughly as risky as any other cloud service you trust with personal data, except that you probably tell it more. Connecting it to your email or files is a newer kind of risk. Check your settings, then decide how much you're comfortable sharing.
In this guide

When AI makes people uneasy, the worry is often about data. Where does what I type go? Who reads it? Will it show up somewhere it shouldn’t?

Those are fair questions, and many people who use these tools daily don’t know the answers. DuckDuckGo (the privacy-focused search engine) surveyed US adults in June 2026: a third of chatbot users had told a chatbot something they hadn’t told friends, family or their doctor. About half didn’t know their chats could be used to train the model by default. Only a quarter knew their chats could be requested in a court case.

This guide has two parts. First, what’s established: what happens to your text, what has actually gone wrong, and how the law differs depending on where you live. Second, what I think and what I do. That part is my personal calculation, and you may land somewhere else. That’s fine, as long as you land there on purpose.

One thing this guide doesn’t cover is the bigger fear about jobs and where all this is going. I wrote about that in Why I’m Optimistic About AI.

Part 1: What’s established

What happens to what you type

When you send a message to ChatGPT, Claude, Gemini or Copilot, it goes to the company’s servers, gets processed there, and is stored there. Your chat history sits in their data centre, not on your laptop. From there, four things can happen to it.

It can be used to train future models. On personal accounts this is usually on by default or offered as a choice you click through at signup. You can switch it off in the settings. On work accounts the company buys, training is off by default and usually written into the contract.

People can read it. Providers can have people review conversations, mostly for safety and quality. Google, for example, says chats picked for human review are kept for up to three years, even if you delete them.

It stays for a while after you delete it. Deleting a chat removes it from your list straight away. The copy on the server usually goes within about 30 days, and some providers keep flagged or reviewed chats much longer.

It can be requested by a court. A conversation with a chatbot has none of the confidentiality you get with a doctor or a lawyer. OpenAI’s CEO said so himself in 2025 and called it “very screwed up”. When the New York Times sued OpenAI, a US judge ordered OpenAI to keep chat logs, including ones users had deleted, for several months.

Here’s how the four big assistants handle it on personal accounts, as of October 2026. These settings change, so check the current version in your own account.

Training on your chatsHow to switch it offHow long chats are kept
ChatGPTOn unless you switch it offSettings → Data Controls → “Improve the model for everyone”Deleted chats are removed within about 30 days. Temporary Chat isn’t used for training.
ClaudeYour choice (“Model improvement”)Settings → PrivacyUp to 5 years if you allow training, de-identified. Deleted chats removed from back-end storage within 30 days. Chats flagged by safety systems are kept up to 2 years and may be used to improve safety detection, whatever your setting.
GeminiOn while “Keep Activity” is onGemini Apps Activity → turn off “Keep Activity”With it off, chats are still kept for 72 hours. Chats picked for human review are kept up to 3 years.
Copilot (consumer)On unless you opt outCopilot privacy settingsConversation history stored for 18 months by default.

Microsoft 365 Copilot at work is a different product from the consumer Copilot. Microsoft says conversations there aren’t used to train its models.

Personal account or work account

Paying doesn’t make it private on its own. Claude’s paid personal plans fall under the same training choice as the free one. What matters is whether it’s a personal account or a work account your company signed a contract for.

A work account comes with an agreement about what the provider may do with your data. A personal account comes with terms you clicked through. That’s why many companies block the personal versions of these tools and hand out Copilot or an internal chatbot instead, and why I wrote a whole guide on what to do when your company blocked ChatGPT. The short version: never put work data into a personal account, however much better the personal tool is.

Will it repeat my secrets to someone else?

A common fear goes like this: you tell the AI something, it learns it, and then it tells someone else. Company documents coming back word for word to a stranger.

It’s very unlikely, but it isn’t impossible. Researchers have managed to pull word-for-word text out of ChatGPT that it had seen during training, the longest over 4,000 characters, using a trick that has since been fixed. But what models memorize is mostly text they saw many times: licence texts, famous quotes, boilerplate that appears on thousands of websites. Something you typed once is the opposite of that, and providers filter and de-duplicate their training data. Two privacy researchers who went through more than 1,300 papers in their field concluded that it focuses too much on this risk, and too little on how data gets collected, leaked while you use a tool, and exposed by AI agents.

Two practical consequences. If you’ve switched training off, your chats aren’t used to train the models, so this risk doesn’t apply. If you leave it on, don’t paste anything you couldn’t live with resurfacing.

What has actually gone wrong so far

Looking at the real incidents is more useful than imagining what could happen. Most of them weren’t about the model at all.

People pasted company data into personal accounts. In 2023, engineers at Samsung put confidential source code and a transcribed internal meeting into ChatGPT. Samsung banned the tools on company devices afterwards. It still happens: a Deloitte survey in the UK this year found about a third of employees use AI through personal accounts.

Share buttons published chats. In 2025, thousands of shared ChatGPT conversations showed up in Google search, some with names and mental health details. Only chats that people had shared and marked as discoverable were affected, but many hadn’t understood what that checkbox meant. OpenAI removed the option. Meta’s AI app had the same problem with a public feed that people mistook for saving a chat privately.

Providers got breached, like any other online service. In 2023 a software bug let some ChatGPT users see the titles of other people’s chats, and may have exposed partial payment details for about 1% of paying subscribers. In 2025, security researchers found a database belonging to the Chinese provider DeepSeek open on the internet, with chat histories in it.

Courts asked for chats. That’s the New York Times case above.

Every one of these came from a person pasting or sharing the wrong thing, a breach, or a court order. The first is the part you mostly control.

The profile question

Two things make AI different from other online services. The first is what you tell it. A search engine sees your question. A chatbot gets, as the privacy company Proton put it after surveying chatbot users this year, “the hesitation, the follow-up questions, and the personal context”. People tell it about their health, their money and their relationships, often more openly than they’d tell a person, because it doesn’t judge. Over months, that adds up to a detailed picture of how you think and feel.

That isn’t a new kind of threat, though. Companies built detailed profiles of us long before chatbots. A 2012 New York Times report described how Target could tell from about 25 products in a shopping basket that a customer was probably pregnant, and roughly when the baby was due. A 2015 study using nothing but Facebook likes judged people’s personality more accurately than their friends and family did, and with a few hundred likes it caught up with their spouses. The difference is that those profiles were pieced together from behaviour, while with a chatbot you write it down yourself, in your own words.

Connecting AI to your email and files is a newer risk

Everything so far is about chatting. The second difference shows up once you give an AI access to your email, calendar or files so it can act for you.

The risk is that the AI reads something with hidden instructions in it and follows them. In 2025, researchers showed that a single email, which the recipient didn’t even have to open, could make Microsoft 365 Copilot collect internal files and send them to an outside server. Microsoft fixed it before anyone is known to have used it. But it’s a type of attack older services don’t really have. If you want to understand what these connected assistants actually do, Is It Really an AI Agent? is a good start.

The law depends a lot on where you live

I’m not a lawyer. I did some research, and this is how I understand it:

SwitzerlandEUUnited States
General privacy lawFederal Act on Data Protection, which the data protection commissioner says applies to AI directlyGDPRNo general federal privacy law. State laws instead, with California’s the most important
Health data you type in yourselfSpecially protected personal dataSpecially protected personal dataHIPAA doesn’t apply: it covers doctors, hospitals and insurers, not a chatbot you chose to use
Enforcement so farGuidance from the data protection commissionerItaly fined OpenAI €15 million in 2024 over how it used people’s data for training (OpenAI is appealing)The FTC can act against companies that break their own privacy promises

The differences are big. In the US, health information you paste into a chatbot has far less protection than the same information at your doctor’s office. In Europe, a regulator has already fined a chatbot provider. But in none of these places does the law make a personal chatbot account confidential. Your settings and your own choices matter more than where you live. Get legal advice when it matters. If you handle other people’s data at work, your company’s data protection officer is the person to ask.

Part 2: What I think, and what I do

My calculation

I share a lot with AI. It was a conscious decision, and I’ve written before about why it makes the answers so much better. For me, the upside is worth the risk.

Part of that is my situation. I have an online presence, so a lot about me is public anyway. And I use so many digital services that I have to assume some of them have already been hacked or will be at some point. My principle has always been the same, with or without AI: I only share what I’d be somewhat comfortable seeing exposed. The test I use is whether it would end my career if it became public. If not, I’m fine sharing it.

That calculation only covers my own information. Client data and my company’s confidential information aren’t mine to weigh up, so they stay out of any tool that isn’t approved for them.

My setup

At work, training is off and memory is on. Most of my work AI use runs through our company AI operating system, which stores what it learns according to rules we wrote. Changes are proposed first and only saved once they’ve been reviewed, under my supervision. I’ve also split my work files across several separate repositories on GitHub (project folders on a service that stores and tracks versions of files), so I can give the AI access to just the one it needs for a task instead of everything. The risk I accept there is that GitHub itself gets compromised.

Privately, training is off too, and I’ve opted out of every optional metric that’s collected to improve the product. Memory is on, but I mostly work with agent setups where I control what gets remembered.

The more interesting decisions are about what I connect:

  • My private email is not connected. It’s the second factor for a lot of my logins, so connecting it is just too risky. When my AI needs to see an email, I forward it to a separate address I set up just for the assistant.
  • My calendar is connected to my private AI setups.
  • My messages are partly connected. My assistant can read the WhatsApp chat I use to write notes to myself, plus a few groups I’ve put on an allow list. Before I add a group, I make sure the people in it agree and understand what that means. Nothing else.
  • Sensitive files stay on my local disk. When my AI works with one, its contents go to the model provider, so I accept the risk that the provider gets compromised.

None of this is risk-free, and I don’t pretend it is. It’s a set of calculated risks I chose because I understand them.

Is AI more dangerous than other digital services?

My view: probably not more and not less. Your chats sit on someone’s servers like your email, your photos and your documents already do. Providers can be breached like any other online service. Courts can ask for the data, as they can for any other cloud data. The two differences are the ones above: you probably tell a chatbot more than any other service, and connected assistants open up a newer kind of attack. I’m careful with both, and I still take some calculated risks.

What I’d tell someone who feels uneasy

Don’t take risks you don’t understand. But don’t take the lazy way out either. “I don’t know anything about this, so I won’t touch it” feels safe, and right now it’s the bigger risk. AI is changing business and society, and staying out is a much bigger risk than doing your homework and carefully taking on more.

The better path is to do your homework, make informed decisions, and then increase your risk appetite step by step as you understand more. You don’t need a course to start. AI can teach you almost anything, including how these systems work. For what a specific product does with your data, check the provider’s own help pages, because the chatbot itself may be out of date. There are excellent videos, there are classes, and there are people you can hire. Pick whatever suits you.

Thirty minutes this week

If you want to go from uneasy to informed, this is where I’d start.

  1. Find out which account you’re using. Personal or work? If it’s for work, ask whoever runs the tool what kind of data it’s approved for.
  2. Open the data settings and make a choice about training. Use the table above to find the switch. Whatever you decide, decide it yourself instead of leaving the default.
  3. Look at what it remembers about you. Most assistants now have a memory you can view. Read it, delete what you don’t want there, or switch it off.
  4. Check your shared links. If you’ve ever shared a chat, look at the list in your settings and delete what shouldn’t be out there.
  5. Before you paste something, run the test. Would you be somewhat comfortable seeing this exposed? For your own information, that’s your call. For information about other people, ask them first. For client data and anything confidential from work, the answer is no unless the tool is approved for it.
  6. Hold off on connecting email and files until you understand what the assistant will do with them.

None of this takes more than half an hour. After that you know what happens to what you type, and you can decide how much to share, which is the point. For the three everyday rules, including what you’re allowed to share, see Getting Started with AI.

Published: 2026-10-01

Last updated: 2026-10-01

Stay in the loop

Don't miss what's next

One email when I've learned something worth sharing, roughly once a month.