Every mainstream AI assistant runs on someone else's computer. You type a question, it travels to a data centre, and what happens to it next is governed by a policy document you almost certainly have not read.
This article is a summary of what those documents currently say. Every number below comes from the provider's own published policy, linked at the end. Where a provider is vague, we say so rather than filling the gap.
The short version
| ChatGPT (free/Plus) | Claude (free/Pro/Max) | Gemini Apps | |
|---|---|---|---|
| Trains on your chats by default | Yes, unless you turn it off in Data Controls | Only if you enable the model improvement setting | Yes, while Keep Activity is on |
| When you delete a chat | Gone from back-end systems within 30 days | Gone from back-end storage within 30 days | Deleted — except chats a human reviewer has seen |
| Kept even after you delete | Data already used in a completed training run; anything under legal hold | Up to 5 years de-identified if training was on; 2 years if flagged; 7 years for safety scores | Human-reviewed chats: up to 3 years |
| Humans may read it | Yes, for abuse review and safety | Yes, if flagged by trust and safety systems | Yes — a subset of chats, by Google staff and trained service providers |
| Default retention if you do nothing | Until you delete | Until you delete | 18 months, then auto-deleted |
Google says the quiet part out loud
The Gemini Apps Privacy Notice is the most explicit of the three, and worth quoting directly. On what happens when you press delete:
Chats reviewed by human reviewers (and related data like your language, device type, location info, or feedback) are not deleted when you delete your activity. Instead, they are retained for up to three years.
Read that carefully. Deleting your activity does not delete the copy a human already looked at. That copy has its own three-year clock, and you have no control over it.
Google is equally direct about what you should therefore avoid typing:
If that setting is on, don't enter data that's confidential or that you wouldn't want a reviewer to see or Google to use to improve its services.
And turning the setting off is not a full exit either. The same notice says that even with Keep Activity off, or in a temporary chat, Google still uses your chats to respond to you and to protect Google, its users and the public, “including with help from human reviewers”.
Anthropic publishes the longest clocks
Anthropic's retention page, updated on 1 July 2026, is unusually specific, which is to its credit. Deleting a conversation removes it from your history immediately and from back-end storage within 30 days. But three other clocks run alongside that one:
- If you allow your chats to be used to improve Claude, they may be kept in de-identified form for up to five years in model training pipelines.
- If an automated trust and safety system flags a conversation, inputs and outputs are kept for up to two years, and the classification scores for up to seven years.
- Feedback you submit — a thumbs up, a bug report — is kept for five years.
Anthropic also states plainly what no provider can undo: if a training run already used your data, turning the setting off afterwards does not remove it from models that have already been trained.
OpenAI: the default runs the other way for consumers
On consumer ChatGPT plans, your conversations may be used to improve OpenAI's models unless you opt out in Data Controls. On Team, Enterprise and API accounts, the default is reversed: business data is not used for training. The difference matters, because the person most likely to paste something sensitive into a chat is a professional using the consumer app on their own phone.
Deleted conversations are removed from OpenAI's systems within 30 days, with an exception for de-identified data and legal obligations. That exception is not theoretical: in the copyright litigation brought by The New York Times, a court ordered OpenAI for five months to preserve output logs that would otherwise have been deleted, and a sample of twenty million of them was later handed to the plaintiffs' lawyers. The order itself was lifted in October 2025. We go through the whole timeline in what “delete” actually means.
What none of this means
It does not mean these companies are acting in bad faith. Retention windows exist for real reasons: abuse investigation, incident response, legal obligations. Human review genuinely does make models safer.
What it means is narrower and harder to argue with: once a conversation leaves your device, its lifetime is governed by someone else's policy, someone else's security, and potentially someone else's court order. You can change a setting. You cannot change the architecture.
The only category where the question does not arise
There is one arrangement in which none of the rows in that table apply, because there is nothing to retain: a model that runs on your own hardware and never opens a network connection.
That is what Pinku does. The model file is downloaded once and every token after that is generated by your iPhone or your Mac. There is no account, no server, no retention window, no human reviewer, and no setting to get wrong — the conversation is a file on your device, and deleting it is a file deletion.
The honest trade-off is capability: a 1–4 GB model on a phone is not GPT-5, and pretending otherwise would be the same kind of marketing this article is arguing against. We wrote up exactly what you gain and lose in a companion piece on what actually runs on an iPhone in 2026 (coming shortly).