Privacy

What ChatGPT, Claude and Gemini actually do with your conversations

Three assistants, three sets of defaults, and one thing they have in common: the conversation leaves your device.

Maruta G · 5 September 2026 · Leer en español

Every mainstream AI assistant runs on someone else's computer. You type a question, it travels to a data centre, and what happens to it next is governed by a policy document you almost certainly have not read.

This article is a summary of what those documents currently say. Every number below comes from the provider's own published policy, linked at the end. Where a provider is vague, we say so rather than filling the gap.

The short version

 ChatGPT (free/Plus)Claude (free/Pro/Max)Gemini Apps
Trains on your chats by defaultYes, unless you turn it off in Data ControlsOnly if you enable the model improvement settingYes, while Keep Activity is on
When you delete a chatGone from back-end systems within 30 daysGone from back-end storage within 30 daysDeleted — except chats a human reviewer has seen
Kept even after you deleteData already used in a completed training run; anything under legal holdUp to 5 years de-identified if training was on; 2 years if flagged; 7 years for safety scoresHuman-reviewed chats: up to 3 years
Humans may read itYes, for abuse review and safetyYes, if flagged by trust and safety systemsYes — a subset of chats, by Google staff and trained service providers
Default retention if you do nothingUntil you deleteUntil you delete18 months, then auto-deleted

Google says the quiet part out loud

The Gemini Apps Privacy Notice is the most explicit of the three, and worth quoting directly. On what happens when you press delete:

Chats reviewed by human reviewers (and related data like your language, device type, location info, or feedback) are not deleted when you delete your activity. Instead, they are retained for up to three years.

Read that carefully. Deleting your activity does not delete the copy a human already looked at. That copy has its own three-year clock, and you have no control over it.

Google is equally direct about what you should therefore avoid typing:

If that setting is on, don't enter data that's confidential or that you wouldn't want a reviewer to see or Google to use to improve its services.

And turning the setting off is not a full exit either. The same notice says that even with Keep Activity off, or in a temporary chat, Google still uses your chats to respond to you and to protect Google, its users and the public, “including with help from human reviewers”.

Anthropic publishes the longest clocks

Anthropic's retention page, updated on 1 July 2026, is unusually specific, which is to its credit. Deleting a conversation removes it from your history immediately and from back-end storage within 30 days. But three other clocks run alongside that one:

Anthropic also states plainly what no provider can undo: if a training run already used your data, turning the setting off afterwards does not remove it from models that have already been trained.

OpenAI: the default runs the other way for consumers

On consumer ChatGPT plans, your conversations may be used to improve OpenAI's models unless you opt out in Data Controls. On Team, Enterprise and API accounts, the default is reversed: business data is not used for training. The difference matters, because the person most likely to paste something sensitive into a chat is a professional using the consumer app on their own phone.

Deleted conversations are removed from OpenAI's systems within 30 days, with an exception for de-identified data and legal obligations. That exception is not theoretical: in the copyright litigation brought by The New York Times, a court ordered OpenAI for five months to preserve output logs that would otherwise have been deleted, and a sample of twenty million of them was later handed to the plaintiffs' lawyers. The order itself was lifted in October 2025. We go through the whole timeline in what “delete” actually means.

What none of this means

It does not mean these companies are acting in bad faith. Retention windows exist for real reasons: abuse investigation, incident response, legal obligations. Human review genuinely does make models safer.

What it means is narrower and harder to argue with: once a conversation leaves your device, its lifetime is governed by someone else's policy, someone else's security, and potentially someone else's court order. You can change a setting. You cannot change the architecture.

The only category where the question does not arise

There is one arrangement in which none of the rows in that table apply, because there is nothing to retain: a model that runs on your own hardware and never opens a network connection.

That is what Pinku does. The model file is downloaded once and every token after that is generated by your iPhone or your Mac. There is no account, no server, no retention window, no human reviewer, and no setting to get wrong — the conversation is a file on your device, and deleting it is a file deletion.

The honest trade-off is capability: a 1–4 GB model on a phone is not GPT-5, and pretending otherwise would be the same kind of marketing this article is arguing against. We wrote up exactly what you gain and lose in a companion piece on what actually runs on an iPhone in 2026 (coming shortly).

Sources

Figures checked on 5 September 2026. Policies change; if you find one of these out of date, tell us and we will correct the page.