Are AI chats private? Here's who can read them
Nobody is reading your chats. Until somebody is.
This week, people found other people’s Claude conversations in Google.
Coding problems. Work notes. Erotica. In some cases personal and company information that nobody meant to publish.
The reaction was outrage. I follow the outrage. What I don’t follow is the surprise.
Because nobody ever promised you a confidential conversation with a chatbot. Not the companies building them, not their privacy policies, not the settings pages people point at as reassurance. The protection everyone assumes is there was never offered in the first place.
It’s all in the terms. Almost nobody reads the terms.
So here is the honest answer to the question I get asked a lot in my AI Fluency and Claude Super User sessions: how private are my conversations with a chatbot?
What actually happened with the Claude chats?
Shared Claude conversations and artifacts became findable through Google. It was spotted on Reddit first, then picked up by WIRED.
There was no breach. Nobody was hacked. These were pages created through Claude’s share button, which generates a public URL. Anthropic tells crawlers not to index those pages using robots.txt, but Google and Bing have both said for years that robots.txt alone doesn’t prevent indexing. It asks a crawler not to visit. It doesn’t stop a URL surfacing in results if the search engine finds it another way. The tag that actually prevents indexing is noindex, and it wasn’t there.
So the door wasn’t forced. It was never locked.
It has also happened before. Forbes reported hundreds of Claude conversations appearing in search results last year. ChatGPT and Grok have both been through the same thing.
But I turned off model training. Doesn’t that make my chats private?
No. It makes them untrained on. Those are different things.
Both Anthropic and OpenAI let you switch off model training (Gemini does too but theirs is impractical), and you should. But read what the setting promises. It governs whether your conversations are used to build the next version of the model. It says nothing about whether they’re stored, who can retrieve them, or what happens when a court asks for them.
On Claude, that setting is tied directly to how long your data is kept. Anthropic’s privacy centre states that if you allow your chats to be used to improve Claude, they may be retained in de-identified form for up to five years in the training pipelines. If you don’t, they sit in back-end storage for up to 30 days.
Thirty days is not zero. It’s just shorter.
Anthropic might keep your data for longer
Three exceptions sit underneath the 30 days, and they’re all in Anthropic’s published policy.
If a conversation gets flagged by the automated trust and safety systems as breaching the usage policy, the inputs and outputs are held for up to two years. The classification scores attached to it are held for seven. Your training setting is irrelevant to this. It applies whether the toggle is on or off.
If you press thumbs up 👍 or thumbs down 👎, the conversation is stored for five years and may be used for research and model training. A single click on a feedback button overrides the setting you carefully switched off.
And then the catch-all: Anthropic may retain chats where required by law, to resolve disputes, or to enforce its usage policy.
That third one isn’t a loophole. Every company holding data has a version of it, and it’s the sensible position. But it’s the sentence that turns the other two into something bigger, and it leads straight to the part most people have never considered.
If you're finding this useful, tap the ❤️ so I know it's landing
Is Gemini any better for privacy?
Nope. Google is the most honest of the three, and it makes for uncomfortable reading.
Buried in the Gemini Apps Privacy Hub is a line telling you that human reviewers, including trained reviewers working for its service providers, read some of what you type.
There it is. Written down, published, sitting on a support page anyone can read. The company is telling you plainly not to treat this as a private conversation.
It gets better. Conversations selected for human review are kept for up to three years. They aren’t connected to your Google account, which means deleting your Gemini activity doesn’t delete them. You can empty your history and the reviewed copy carries on existing somewhere else entirely.
Default retention on your own activity is 18 months, adjustable to three or 36. The controls exist. They’re just not where you’d look and they don’t do what you’d assume.
So when I say nobody promised you confidentiality, this is what I mean. One of the three biggest AI companies in the world put the warning in writing.
Can a court get hold of your chats?
Yes. It has already happened, on a significant scale.
On 13 May 2025, Magistrate Judge Ona Wang of the Southern District of New York issued a preservation order in the New York Times copyright case against OpenAI. It required OpenAI to retain all output log data from ChatGPT and its API.
That covered:
Conversations users had deleted.
Conversations from people who had switched off training and data sharing.
And temporary chats, the mode marketed on the promise that it disappears.
It applied to Free, Plus, Pro, Team and API users without a zero data retention agreement. Enterprise and Education accounts were excluded, which tells you where the protection actually sits.
The obligation ended in the autumn of 2025 and OpenAI returned to its normal deletion schedule. But everything captured during that window is still held. And in November 2025 the court ordered 20 million de-identified conversation logs to be handed over in discovery.
Twenty million conversations. People deleted those chats. The deletion did not survive contact with a judge.
None of this required anyone to behave badly. OpenAI fought the order. The judge was doing her job. The system worked exactly as designed, and the result is that a lot of people’s private conversations are now sitting in a legal hold they will never be told about.
Are incognito and temporary chats more private?
Somewhat. Not in the way the names suggest.
Claude’s incognito chats do something real. The conversation stays out of your history, it doesn’t feed memory, and it isn’t used for training even if your model improvement toggle is switched on. Anthropic confirms that last point directly. ChatGPT’s temporary chats behave much the same way.
If your worry is that a one-off sensitive query will end up in the next model, these modes solve it.
Now the part that doesn’t get mentioned.
Neither mode deletes anything in real time. Claude’s incognito chats are held for around 30 days before automatic deletion, unless they’re flagged as a usage policy breach, in which case the two-year window applies. ChatGPT’s temporary chats sit on OpenAI’s servers for up to 30 days under abuse monitoring, and remain producible under legal process during that time. Which, as we’ve just established, is not hypothetical.
Then there’s this, from Anthropic’s own help centre. Incognito chats aren’t visible in users’ chat histories, but they remain available to account owners through data export features, subject to your organisation’s retention policy.
Read that twice if you have ever opened an incognito chat on a work account to draft your CV. Incognito hides the conversation from you. It does not hide it from your employer.
Can your employer read your AI chats?
On a work account, yes.
Claude Team and Enterprise plans give the Primary Owner (so, whoever pays for the account) the ability to run an organisation data export. It contains members’ conversations, uploaded files and usage patterns. It isn’t a live feed and somebody has to choose to run it, but the capability is there, it’s documented, and as established, it takes incognito chats with it.
Enterprise adds audit logs, a compliance API for real-time monitoring, and configurable retention. That 30-day default is a default. Your organisation can set it to years.
ChatGPT Enterprise and Business work on the same principles. This isn’t a Claude problem, it’s what enterprise software is.
And it isn’t a scandal either. If you run a regulated business, or one that might one day face a legal claim, you need a record of what your people did with company tools. Anthropic and OpenAI are not doing anything wrong by providing that. They’d be criticised if they didn’t.
The problem is the mismatch. Almost nobody typing into a work account knows any of this is true. They’re using an interface that looks like a private conversation, on an account that is explicitly not private, and nobody has told them.
If you’re on a company seat, the rule is simple. Job hunting, health questions, money worries, grievances about your manager and anything you’d rather HR never read do not belong there. Use a personal account for personal things. A personal Pro account has no organisation above it and no export path, even if your employer pays for it.
Can an AI company get hacked?
Every route so far has been legitimate. A search engine doing its job, a policy being applied, a judge issuing an order, an admin running an export. Then there’s the illegitimate route, and AI companies are not immune.
In January 2025, researchers at Wiz found a DeepSeek database sitting on the open internet with no authentication at all. Over a million log lines, including plaintext chat histories and API secrets. Anyone who found the open ports had full administrative control.
In March 2023, OpenAI took ChatGPT offline after a bug let some users see other people’s details, including chat metadata and partial payment information. In November 2025 it disclosed a breach at Mixpanel, a third-party analytics provider, exposing names, email addresses and location data for API customers. No conversations that time, but it makes the point about supply chains: your data isn’t only where you think it is.
In February 2026 a consumer app called Chat & Ask AI, with more than 50 million downloads, exposed hundreds of millions of private conversations. Full chat histories, tied to real users, including some of the most desperate questions a person can ask.
And a browser extension marketed as a privacy tool was found intercepting conversations across ChatGPT, Claude, Gemini, Copilot, Perplexity, DeepSeek and Grok, then sending them to a data broker. The AI company wasn’t breached at all. Everything you typed was collected on its way past.
None of this makes AI companies uniquely careless. It makes them normal. Which is the point: you are handing your most candid thoughts to organisations that will, eventually, have a bad security day like everyone else.
So why does it feel private?
Because there’s nobody there.
That’s the entire mechanism. Every other channel you use has a visible recipient. You compose an email to a person. You post in a channel where colleagues are watching. You choose your words in a meeting because faces are looking back at you. The audience is built into the interface, and it shapes what you’re willing to say.
A chatbot removes the audience. No reply-all risk, no tone to manage, no reputational cost, no eyebrow raised across the table. Just a text box that responds helpfully and never judges you.
So people type things they would put nowhere else. The medical worry before they’ve told their partner. The salary they’re being paid and what they think about it. The client’s name and the client’s numbers. The thing about their business partner they haven’t yet said out loud. Whole strategies. Whole grievances. Whole drafts of resignation letters.
Nobody sends an email believing it evaporates. People believe exactly that about a chatbot, and the design encourages it.
That belief is why these tools work as well as they do. You get better answers from Claude or ChatGPT precisely because you tell it things you wouldn’t tell a colleague, and if everyone typed defensively the tools would be far less useful.
So the risk isn’t that chatbot logs are less secure than your inbox. Mostly they aren’t. It’s that the contents are considerably more revealing, and the people producing them believe the opposite.
So what should you actually do?
I’m not going to make the abstinence argument, because we all know that doesn’t work. But there are some things you can do:
Switch off model training. Claude: Settings, Privacy, model improvement toggle. ChatGPT: Settings, Data Controls. This shortens retention and keeps your work out of the next model.
Stop pressing thumbs up and thumbs down. One click stores that conversation for five years and overrides the setting you just switched off. If you want to give feedback, do it on something you wouldn’t mind reading back.
Treat share links as publishing. Anything you share by link is a page on the open internet. Go and delete the old ones you no longer need.
Use incognito or temporary chats for sensitive queries, knowing what they do. Good for keeping things out of your history and out of training. Useless for hiding anything from your employer.
Separate work and personal accounts. The company seat is for company work. Everything else goes on a personal account with no organisation above it.
Assume a second reader exists. Not somebody watching in real time. A court, an admin, a researcher, an attacker, at some point you can’t predict.
None of this takes more than ten minutes.
Reader, know thy chatbot privacy…
There is no doctor patient confidentiality between you and a chatbot. There is no attorney client privilege. There is no off the record.
Those protections exist because societies decided, over centuries, that certain conversations were valuable enough to shield by law. No equivalent decision has been made about the conversations we are now having with machines, and the volume of sensitive material flowing into them is growing far faster than anyone is thinking about protecting it.
That will get litigated over the next few years. Some of it should. Until then, the working assumption has to be that your chats are one court order, one data export or one flagged conversation away from being read.
Which is really an argument about fluency, not privacy.
Every fact in this post came from published policies and public court records. None of it is hidden. It’s sitting in help centre articles that take twenty minutes to read, written in plain English by companies that are not trying to deceive anyone. The reason almost nobody knows it is that almost nobody looks, and the settings have names that suggest they do more than they do.
Working out what a tool actually does with what you give it is a skill. It’s the same skill as knowing when a model is confidently wrong, or what happens to the document you just uploaded. It’s learnable, it takes less time than people fear, and it is the difference between using these tools well and using them hopefully. I made a related argument that anything you say to an AI notetaker can and will be used against you.
If you want to work through this properly with your team, AI Fluency for Leaders is my three hour, CPD-certified, five star rated course that and covers exactly this ground.
Nobody is reading your chats.
Until somebody is.
Reader, if you know anyone who would find this useful, I’d be grateful for a share!






