Privacy

I sent OpenAI and Anthropic a GDPR erasure request.
Neither told me what they kept.

Five layers sit between the delete button and a conversation actually being gone. Only the first one is under your control.

Maruta G · 5 September 2026 · Leer en español

Every AI assistant has a delete button. Pressing it makes a row disappear from a list, immediately and satisfyingly. Whether it makes anything else happen is a different question, with a different answer for each layer of the system the conversation passed through.

None of what follows is a scandal. It is mostly the ordinary consequence of running software at scale, and some of it is legally required. But the gap between what the button looks like it does and what it does is wide enough to be worth writing down.

Layer 1 — your view, and then the storage

The row vanishing is instant and local. Behind it, both OpenAI and Anthropic publish the same window: a deleted conversation is removed from back-end systems within 30 days. Anthropic's wording is “deleted from our back-end storage systems within 30 days”; OpenAI's is that deleted chats are permanently removed within 30 days, unless de-identification or legal exceptions apply.

Thirty days is a reasonable number. Backups have to roll over, and a system that deleted from every replica synchronously would be a system that could not be restored after an incident. But it does mean that “deleted” means “scheduled for deletion” for a month.

Layer 2 — the weights, which cannot be edited

If your conversation was used in a training run that has already finished, deleting the conversation does not remove its influence from the resulting model. There is no known technique for reaching into a trained network and extracting one conversation.

Anthropic states this plainly rather than hiding it: turning the setting off means your data will not be used for future training, but “your data will still be included in model training runs that are already in progress, or in models that have been trained.”

This is the layer people underestimate. Deletion is a storage operation. Training is not storage.

Layer 3 — the copy a person read

All three major providers use human reviewers on some fraction of conversations. Google's Gemini Apps Privacy Notice is the only one that spells out what that means for deletion, and the sentence deserves to be read twice:

Chats reviewed by human reviewers (and related data like your language, device type, location info, or feedback) are not deleted when you delete your activity. Instead, they are retained for up to three years.

Your delete does not reach that copy. It has its own three-year clock, running independently of anything in your account settings, and there is no control surface for it.

Layer 4 — the safety flag

If an automated system decides a conversation might violate a usage policy, different rules apply. Anthropic publishes the numbers: inputs and outputs kept for up to two years, and the trust-and-safety classification scores for up to seven years.

Note the asymmetry. The classification score — a machine's judgement about you — outlives the conversation that produced it by five years.

Which conversations get flagged is not published. What is published is the policy the flag keys off, and it names four domains as “High-Risk Use Cases”:

Legal: Use cases related to legal interpretation, legal guidance, or decisions with legal implications. Healthcare: Use cases related to healthcare decisions, medical diagnosis, patient care, therapy, mental health, or other medical guidance. Insurance: […] Finance: Use cases related to financial decisions, including investment advice, loan approvals […]

Be careful with what that does and does not say. Those requirements are addressed to developers building products on Claude: they must put a qualified professional in the loop and disclose that AI was involved. They are not a statement that asking about your own health flags your chat, and we are not claiming that they are.

The precise position is this. The seven-year clock starts when an automated system decides a conversation may violate the Usage Policy. The Usage Policy is the document that names those four domains. Whether conversations in them are more likely to be flagged is not disclosed, and there is no mechanism for you to find out whether any particular conversation of yours was.

So the categories where you would most want to know — your health, your money, your legal exposure — are exactly the categories where you cannot. That is not an accusation. It is the honest shape of the information available to you, and it is the reason some conversations are worth keeping off a network entirely.

Layer 5 — the court

The clearest demonstration that the delete button is not the last word came out of the copyright litigation brought against OpenAI by The New York Times and others. The timeline is worth stating precisely, because it is widely misreported in both directions.

So the sweeping preservation order is over. Anyone still saying “OpenAI has to keep your deleted chats forever” is a year out of date.

But the part that actually matters is not over. For roughly five months, chats that users had deleted were retained because a court said so. A sample of twenty million of them, de-identified, has since been handed to the opposing side's lawyers in a copyright case. Nobody in that sample was asked, and nobody in it can tell whether they are in it.

OpenAI fought the order and says the preserved data sits behind a small audited legal and security team. There is no reason to doubt that. The point is structural, not moral: a retention policy is a promise a company makes, and a court can suspend it for everyone at once.

I sent both companies a GDPR erasure request

From my own personal accounts — the consumer tier this article is about, not a business plan with different defaults — I sent OpenAI and Anthropic a formal request under the GDPR, and kept what came back.

Not a support ticket. A request under Article 15, the right of access, and Article 17, the right to erasure, asking specifically for the things this article has been describing:

Any conversations flagged by your trust and safety classifiers, along with the specific reasons for flagging. Any data derived from my conversations (classification scores, metadata, logs). Any de-identified data that originated from my account, including any data used for model training. Information about how long each category of my data will be retained and the legal basis for such retention. […] Please confirm in writing what data has been deleted and, if any data is retained, provide the specific legal basis for each category of retained data as required under Article 17(3).

That last sentence is the test. It is not a favour to ask: under Article 12(3) a controller has one month to respond.

The timeline

What OpenAI sent back

We acknowledge receipt of your request to delete any data associated with you processed by OpenAI, but keep your OpenAI account. For security and privacy reasons, the quickest way to delete data that is not necessary to maintain your account or our services, while keeping your ChatGPT account active, is to use our self-service tools outlined below.

What followed were links: the Delete all chats button, the memory FAQ, the privacy portal. Read the clause emphasised above. The self-service tools cover data that is not necessary to maintain the account or the service. That implies a second category — data that is necessary — and the reply does not say what is in it, how long it is kept, or on what legal basis. Those were the questions.

What Anthropic sent back

When you delete a conversation it will be removed from your chat history immediately, and deleted from our back-end storage systems within 30 days in accordance with our retention periods. […] When you choose to delete your account, your personal data connected to your account will also be deleted in accordance with our retention periods.

“In accordance with our retention periods” is not an answer to the question; it is a pointer back to it. Those periods are the ones earlier in this article: 30 days for ordinary storage, up to two years for a flagged conversation, up to five years for de-identified training data, up to seven years for a classification score. Deleting your account does not reset those clocks — it hands you to them.

The same reply added something most people have never considered:

if you are accessing Claude through a third party service (e.g. Quora's Poe or Cursor), you will need to request account deletion through that third party service provider.

Deleting your account at the model provider does not delete the copies held by whatever else you piped it through, and you are expected to know the list.

What neither of them did

Neither reply confirmed in writing what had been deleted. Neither gave a legal basis for anything retained, which Article 17(3) requires when a controller keeps data despite an erasure request. Neither engaged with the access request at all: no list of flagged conversations, no classification scores, no retention schedule by category. Both answered a legal request with a link to a settings page.

I am not claiming a proven breach. I did not escalate to a data protection authority, so nothing here has been adjudicated, and both companies' published policies do contain much of what I asked for. Both replied politely; one replied very fast. But the request was specific and the answers were generic, and that gap is the point: I asked two of the most sophisticated privacy teams in the industry, in the most formal terms available to a European citizen, whether my data was gone. Neither said yes.

Not because they were hiding something. Because “yes” is not a thing either of them is in a position to say.

The replies are quoted verbatim except that the support agents' names have been removed; they answered their tickets correctly and should not be identifiable from this page. They are personal correspondence, reproduced as received. Both companies' current published policies are linked at the end and say the same things.

What deletion means somewhere else

For contrast, consider what “delete” means for a file on your own machine. The operating system unlinks it. There is no thirty-day window, no reviewer's copy, no training pipeline, and no third party who could be ordered to produce it, because no third party ever had it.

That is not a claim about anyone's trustworthiness. It is a claim about how many parties are involved. Five of the layers above exist because the conversation travelled somewhere. A conversation that never leaves the device has one layer.

Where this leaves you

We are not writing this from a position of purity. We use cloud assistants every day, by choice, and we build products on top of them. Claude and ChatGPT are better than anything that fits on a phone, and convenience wins more often than we would like to admit.

So this is not an argument for quitting them. It is an argument for knowing which rules you are playing by, and then choosing deliberately for the conversations where it matters — the ones you would mind someone reading, which for most people is a small fraction of the total.

For that fraction, the only arrangement in which none of the five layers exists is a model that runs on hardware you own. It is the problem we work on: Pinku runs language models on an iPhone or a Mac with no account and no network connection, and Keeper keeps photos and files encrypted on the device. The rest of the time we are in the same boat as you, typing into someone else's computer because it is easier.

Every figure in this article is quoted from a provider's own published policy or a court filing, all linked below. Check them rather than taking our word for it — and if one is out of date, tell us and we will correct the page.

Sources

Checked on 5 September 2026.