Systems
Security
Data
Python

PLEXData Engineering for people and agents that act on systems

Permissions, Limits, Evidence & eXecution.

No. 012 Latest feature

Wednesday, 30 September 2026

plexdata.online

002

Published
Updated 29 Sep 2026
Author
Dorian Sotpyrc
Reading
9 minutes · 7 sections
Fields
  • Privacy
  • AI systems
  • Data retention
  • Security

Evidence · Privacy

Your AI Chat History Isn't Private — Here's What's Actually Logged

The chat window is only the visible record. Depending on the product and settings, the same message can also create usage logs, safety records, device metadata and retention obligations you never see.

References
Fig. 1 · Live model The visible conversation is one record. The surrounding system can create others.
In this article · 7 sections
  1. 01The chat is not the log
  2. 02Training is a separate question
  3. 03Temporary is not zero retention
  4. 04Providers do this differently
  5. 05Delete does not mean instant erasure
  6. 06Work accounts change the boundary
  7. 07What to do before you paste

An AI chat feels private because it looks like a conversation between you and a machine. There is no public audience, no comment thread and usually no obvious sign that anything exists beyond the transcript.

That interface is easy to mistake for the system.

It is not. The transcript is only the part you can see. The service around it may also process account identifiers, timestamps, device information, usage events, safety classifications, files, location signals and other operational data. Exactly what is retained — and for how long — depends on the provider, product, account type and settings.1

§ 01The chat is not the log

Start with the simplest distinction: conversation history is not the same thing as service logging.

OpenAI's current privacy policy, for example, separates user content from log data, usage data, device information and location information. Its examples of log data include IP address, browser type, settings and request time. Usage data can include features used, actions taken, access time, country, user agent and device type.1

Table 1 — One chat can create more than one record
LayerTypical examplesVisible to you?
ConversationPrompt, response, uploaded contentUsually
Account / usageTime, model, feature use, account or workspace contextSometimes
Device / networkIP address, browser, device type, general locationNot in chat history
Safety / integrityAbuse signals, policy flags, feedback or review recordsUsually not

That does not mean a human is reading every conversation. It means the product has more data surfaces than the transcript. Privacy decisions should start from those surfaces, not from how empty the sidebar looks.

§ 02Training is a separate question

One of the most common mistakes is to treat “not used for training” as if it meant “not stored”.

OpenAI states this directly: if you turn off Improve the model for everyone, new conversations are not used to train models, but regular chats can still appear in history. Saved chats remain until you delete them or a workspace retention rule removes them.2

The same distinction appears elsewhere. Anthropic gives consumer users a model-improvement choice, while its retention rules separately describe deletion, standard retention and longer periods for certain safety cases.56

§ 03Temporary is not zero retention

Temporary modes are useful. They are also easy to overread.

ChatGPT Temporary Chat stays out of normal history, does not create or update memories and is not used for model improvement while it remains temporary. OpenAI says a copy may still be retained for up to 30 days for safety purposes.3

Google documents a different window. Gemini temporary chats — and chats created while Keep Activity is off — are retained with the account for 72 hours so the service can respond, handle feedback and protect Google, users and the public. They do not appear in Gemini Apps Activity and temporary chats are not used to train Google's AI models.4

The practical lesson is not that temporary modes are bad. It is that temporary means a different retention path. It does not automatically mean zero records.

§ 04Providers do this differently

There is no universal “AI chat privacy setting”. The names, defaults and retention periods vary.

Table 2 — Selected consumer chat controls, checked 29 Sep 2026
ProductHistory / activityLower-retention mode or controlDocumented note
ChatGPTSaved chats remain until deletion or workspace policy removal.Temporary ChatTemporary copy may be kept up to 30 days for safety.3
Gemini AppsKeep Activity defaults to 18-month auto-delete for eligible personal accounts.Temporary Chat or Keep Activity offFuture chats are retained for 72 hours in those modes.4
Claude consumerUsers can delete conversations from history.Model-improvement setting affects use and retention rulesDeleted conversations are removed from history immediately and normally from the backend within 30 days; safety exceptions can be longer.5
Microsoft CopilotMicrosoft documents 18 months of conversation history for signed-in users.Privacy controls can change model-training use and history managementIndividual chats or full history can be deleted.7

This table is deliberately narrow. It does not try to flatten every product tier into one number. Business, enterprise, education, API and managed-workspace products often have different contracts and retention rules.

§ 05Delete does not mean instant erasure

Deleting a chat is still worth doing. But the button usually changes the user-facing state before every backend copy is gone.

01DELETEremoved from your account view
→
02DELETION QUEUEprovider removes backend copies
→
03EXCEPTIONSlegal, security or de-identified data may follow different rules
Fig. 2Example pattern, not a universal timer. OpenAI says deleted saved chats are scheduled for permanent deletion within 30 days, subject to stated legal, security and de-identification exceptions.

OpenAI's current retention guidance says a deleted saved chat disappears from the account view immediately and is scheduled for permanent deletion from its systems within 30 days, unless the chat was already de-identified and disassociated from the account or longer retention is required for security or legal reasons.8

Anthropic's consumer guidance similarly says deleted conversations are removed immediately from history and automatically deleted from the backend within 30 days under its standard rule, while documenting longer retention for some usage-policy violations and trust-and-safety classification scores.5

§ 06Work accounts change the boundary

Your employer's AI workspace is not the same privacy boundary as a personal chat account.

OpenAI's managed-account guidance says organisation-controlled accounts may expose submitted content, conversation history, shared workspace content, usage/activity metadata and certain security or privacy settings according to workspace configuration, permissions and applicable law.9

That is not automatically a problem. In a business setting, auditability can be a feature. The important point is to know which boundary you are using before you paste confidential material into it.

Connected apps add another boundary. If a chat sends data to a third party, that third party's privacy and retention rules can apply too. The original AI provider's temporary-mode promise does not automatically follow the data downstream.

§ 07What to do before you paste something sensitive

You do not need to memorise every privacy policy. You need a short decision routine.

Checklist

Six checks before you paste

§ 08References

  1. 1OpenAI — Privacy Policy, personal data collected from use of servicesopenai.com
  2. 2OpenAI Help — Data controls in ChatGPThelp.openai.com
  3. 3OpenAI Help — Temporary chat in ChatGPThelp.openai.com
  4. 4Google — Gemini Apps Privacy Hubsupport.google.com
  5. 5Anthropic Privacy Center — How long do you store my data?privacy.anthropic.com
  6. 6Anthropic — Consumer Terms and Privacy Policy updateanthropic.com
  7. 7Microsoft Support — Copilot privacy controls / conversation historysupport.microsoft.com
  8. 8OpenAI Help — Chat and file retention in ChatGPThelp.openai.com
  9. 9OpenAI Help — Data access for your managed ChatGPT accounthelp.openai.com

Policies change. This article records the provider documentation available on 29 September 2026. Check the linked source before relying on a retention period for regulated or high-risk work.