How to Use AI Assistants Safely: A Practical Privacy Guide

28.07.2026 7
How to Use AI Assistants Safely: A Practical Privacy Guide

Most privacy advice about AI assistants stops at "be careful what you type", which is true and almost useless. This guide is the practical version: what each major assistant actually keeps, for how long, which settings genuinely change that, and which habits protect you regardless of vendor. Every retention figure below comes from the providers' own documentation, not from a summary of it.

1. Treat "share" as publishing, not sending

This is the single most expensive misunderstanding, and it has now happened three times in public. Nearly 100,000 shared ChatGPT conversations turned up in Google. More than 130,000 chats from Claude, Grok, ChatGPT and others were found readable on Archive.org. In July 2026 hundreds of shared Claude conversations appeared in search results containing wallet seed phrases and payroll files.

In every case nothing was hacked. Users pressed a share button expecting it to work like sending a file, and it worked like putting up a web page.

Important: A share link is a public URL. It does not require a password, it does not expire by default, and once a search engine or an archiver has seen it, revoking the link does not retrieve the copy. If you need to show a conversation to one person, a screenshot of the relevant part is safer than a link to all of it.

2. Deleting a chat is not the same as the data being gone

This is where the published policies are more revealing than the marketing. The numbers differ per vendor and are worth knowing before you decide what to type.

  • Claude: a deleted chat disappears from your history immediately and is removed from back-end storage within 30 days. If you enabled training, conversations may be kept de-identified for up to five years in training pipelines. Chats flagged by automated safety systems are kept up to two years, and the classification scores derived from them up to seven.
  • Gemini: activity auto-deletes after 18 months by default, adjustable to 3 or 36 months, or never. Turning activity off still keeps future chats for 72 hours. The important part: conversations that were reviewed by human reviewers are not deleted when you delete your activity, and are retained for up to three years.
  • ChatGPT: memory is stored separately from chat history, so deleting a conversation does not remove what the assistant saved from it. Deleted saved memories may be logged for up to 30 days.

The practical consequence: if a secret entered a conversation, deleting the chat is not remediation. Rotating the secret is.

3. Turn off training on your data, and know what it does not cover

Every consumer assistant now has this switch, and it is worth finding once.

  1. ChatGPT: Settings, Data Controls, turn off "Improve the model for everyone". It applies account-wide across devices, and your history still works normally.
  2. Claude: the training setting is in Privacy settings; it only ever applied to chats created or resumed after you switched it on, and Incognito chats are excluded from training regardless.
  3. Gemini: Keep Activity off. Note Google's own wording, that a subset of chats is reviewed by humans, and reviewed chats survive your deletions for up to three years.

Turning training off stops your text from shaping future models. It does not make the conversation invisible to the provider, does not shorten safety retention, and does not apply retroactively to what was already used.

4. Decide what never goes in the box

Google states it plainly in its own help pages: do not enter confidential information that you would not want a reviewer to see. That is a reasonable rule for every assistant, not just theirs. In practice, a short list covers most of the damage seen in the leaks so far.

  • Anything that is a credential: passwords, API keys, recovery phrases, one-time codes. These have appeared in every public leak, and they are the only category where exposure is immediately exploitable.
  • Identity documents: passport and national ID numbers, tax numbers, full dates of birth in combination with a name.
  • Other people's data: client lists, payroll files, medical details of relatives, children's names and schools. You cannot consent on their behalf, and this is what turned the ChatGPT and Claude leaks from embarrassing into serious.
  • Anything under an NDA or regulatory duty: unreleased financials, patient records, case files. In many jurisdictions pasting these into a consumer tool is itself the breach, before anything leaks.

If you genuinely need to work on such material, redact it first. Replace real names and numbers with placeholders, do the work, then map the answer back yourself.

5. Keep work and personal accounts apart

Business and enterprise tiers of the major assistants are covered by different terms than consumer accounts, typically excluding your content from model training by contract rather than by a toggle you might forget. That difference is worth using. Beyond the legal side, mixing accounts is how a client's document ends up in a personal chat history that later gets shared for an unrelated reason.

6. Be deliberate with agents and connected tools

The newer risk is not what you type but what you connect. Assistants can now browse, run code, read your files and act through integrations. Each connector is a standing permission, and it usually outlives the task you granted it for. Review what is connected the same way you would review OAuth apps on a Google account, and disconnect anything you cannot name a current use for. Where an agent needs credentials, give it scoped, revocable ones, never your primary keys.

A five-minute checklist

  1. Open your shared links list in each assistant and revoke everything you do not actively need public.
  2. Turn off model training in each account, and set activity auto-delete to the shortest period you can tolerate.
  3. Rotate any credential that has ever appeared in a chat, whether or not it was shared.
  4. Review connected apps and integrations, and remove the ones you no longer use.
  5. Decide your own red line for what never goes in, and stick to it even when it is inconvenient.

Where a VPN fits, and where it does not

Honesty is more useful here than an upsell. A VPN does nothing about any of the exposures above: nothing was intercepted in transit, and the data left through the account holder's own actions. What a VPN does address is a narrower and separate question, namely who can see that you are using a given service at all. That matters if you are on a monitored network, or in a country where a specific assistant is blocked or where using one is politically sensitive. It is a real use case, and it is not the same thing as protecting the contents of your conversation. For the contents, the only controls that work are the ones in this article. The same distinction came up when shared Claude chats appeared in Google and when ChatGPT was found passing query summaries to Meta.

Conclusion

Conclusion: The failures so far have not been exotic attacks. They have been ordinary buttons doing exactly what they said, used by people who assumed something gentler. Two habits remove most of the risk: treat every share link as a published web page, and treat every secret that touches a chat as one you now have to rotate. Everything else in this guide is refinement around those two.
Tags: claude anthropic chatgpt openai gemini google grok archive.org meta ai privacy privacy data retention cybersecurity digital rights security vpn

Read also