A new investigation into AI chatbot privacy policies confirms what security researchers have long warned: opting out of model training doesn’t erase your data. As Neowin detailed on July 26, conversations with ChatGPT, Microsoft Copilot, Gemini, and others can persist on company servers for weeks to years after you’ve moved on—and sometimes even after you’ve hit “delete.”
The Messy Reality Behind the “Do Not Train” Switch
When you toggle off model improvement in your chatbot’s settings, you’re stopping one specific thing: the platform can’t use your future chats to teach its next large language model. That’s it. The provider can still:
- Store your conversation history for your account, for continuity, search, or legal hold.
- Retain transcripts temporarily just to operate the service—from seconds to days.
- Review flagged chats manually for safety or quality, often through third-party contractors.
- Keep your feedback, which often pulls the entire conversation into a review pipeline.
- Honor legal obligations that require preserving data regardless of your settings.
“Training” is only one lane. Every platform manages the others independently, and most users never see the fine print. Google’s Gemini Apps Privacy Hub, for example, says chats with activity saving turned off are still retained for up to 72 hours so the service can respond and protect its systems. That’s not a bug—it’s by design.
Retention Timelines: A Cross-Platform Snapshot
Here’s what the policies actually say about how long your data sticks around.
| Platform | Training Opt-Out Available? | Retention After Opt-Out | Feedback Exception | Temporary/Incognito Mode Retention |
|---|---|---|---|---|
| ChatGPT | Yes (Settings > Data Controls) | Not used for training, but history remains unless deleted; feedback may override | Thumbs-up/down can trigger training use of full conversation | Temporary Chat: 30-day retention for safety |
| Gemini | Yes (Gemini Apps Activity) | 72 hours for service delivery; human-reviewed samples may be kept up to 3 years | Feedback may re-enable training use | No dedicated temp mode; turning off activity minimizes retention |
| Claude | Opt-in by default (Help improve our AI models) | Opt-out prevents future training, but feedback may still be stored up to 5 years | Feedback stores entire conversation for up to 5 years | Incognito chats: generally 30-day retention |
| Microsoft Copilot | Yes (profile > privacy controls) | 18-month default retention; files retained up to 18 months | Not explicitly documented as exception | No temporary mode; manual deletion possible |
| Grok (on X) | Yes (Data sharing and personalization) | Turning off prevents training/fine-tuning; private posts excluded | Feedback can still permit training use | Grok.com Private Chat: deleted within 30 days |
| Meta AI | Objection process in some regions | Varies by jurisdiction; public posts and AI interactions used by default | Not clearly defined | No temporary mode |
Why Windows Users Should Care More Than Others
Microsoft Copilot is now deeply integrated into Windows 11 and the Microsoft account ecosystem. The assistant can see your Edge browsing, linked Office documents, and uploaded files. According to Microsoft’s Copilot Privacy FAQ, any file you share in a chat is treated like conversation text for training and personalization purposes—and can be stored for up to 18 months before automatic deletion.
Power users often bounce between multiple AI tools on the same machine: ChatGPT for research, Gemini for quick summaries, Copilot for system tasks, and Grok’s standalone app for real-time news. Each service has its own policy. If you’re using a personal Microsoft account for work tasks, you’re likely sending sensitive data to a consumer service that lacks enterprise protections. Microsoft explicitly says it excludes organizational Entra ID accounts and users under 18 from consumer model training—but that shield vanishes the moment you sign in with a personal account.
Six Steps to Take Control
Privacy is a usage habit, not just a settings menu. Here’s how to dial back your exposure without abandoning the tools.
1. Classify Before You Type
If your prompt includes passwords, recovery codes, financial records, medical details, client data, source code, or anything covered by regulation, stop. Consumer chatbots aren’t designed for that. Use an enterprise-approved environment or a locally run model instead.
2. Turn Off Model Improvement Everywhere
Spend five minutes now:
- ChatGPT: Settings > Data Controls > Improve the model for everyone → Off
- Gemini: Manage Gemini Apps Activity → Keep Activity → Off
- Claude: Privacy settings → Help improve our AI models → Uncheck
- Copilot: Profile > Privacy controls → Training on conversation activity and voice → Off
- Grok on X: Settings > Privacy and safety > Grok & Third-party Collaborators → Off
- Grok.com/App: Settings > Data > Improve the Model → Off
Remember: these changes only affect future conversations. Old chats are already in the pipeline.
3. Use Temporary Modes for Sensitive One-Offs
When drafting a private letter, analyzing a confidential error log, or testing code with proprietary logic, switch to the service’s ephemeral mode:
- ChatGPT: Start a Temporary Chat
- Claude: Open an Incognito window
- Grok.com: Use Private Chat
These chats don’t appear in your history and aren’t used for training, though providers still retain them for a short safety window (typically 30 days).
4. Redact Ruthlessly Before You Upload
An image of a spreadsheet, a PDF of a contract, a screenshot of a form—these are all conversation data. Replace real names with roles, black out account numbers, crop out identifying metadata, and use placeholders instead of real figures. A well-redacted snippet still gets you the answer without the exposure.
5. Never Rate a Sensitive Chat
Thumbs-up and thumbs-down buttons look harmless, but they often pull the entire thread into a separate review or training system—even if you’ve opted out. OpenAI, Anthropic, Google, and X all document this exception. If you must report a bad answer, use a general feedback form that doesn’t attach the full transcript, or strip sensitive text first.
6. Delete Old Histories—But Don’t Fool Yourself
Periodically clearing your chat logs reduces surface area and prevents accidental resurfacing. On Copilot, you can delete individual conversations or your entire history. On Gemini, you can set auto-delete to 3, 18, or 36 months. However, deletion doesn’t guarantee immediate erasure from every backup, safety queue, or de-identified dataset. Data previously reviewed by humans may already be disconnected from your account and retained for years, as Google’s Gemini Apps Privacy Hub clearly states.
The Bottom Line: Your Data, Your Responsibility
AI chatbots are more personal than search engines—they soak up your drafts, your work problems, your health concerns, and your unfiltered questions. The platforms have given us meaningful levers to limit future model training, but those levers don’t create a cone of silence. The strongest privacy feature remains the one you activate before pressing Enter: asking yourself whether this prompt is information you can afford to share with a service that—by design—may hold onto it longer than you expect.