> ## Content Index
> Fetch the complete content index at: https://techessentials.in/llms.txt
> Use this file to discover other available public pages before exploring further.

# Who Reads What You Type Into AI?
- URL: https://techessentials.in/who-reads-what-you-type-into-ai/
- Published: 2026-08-25T07:20:21.000Z
- Updated: 2026-08-25T07:20:21.000Z
- Author: Sanidhay Kumar
- Tags: AI

*What OpenAI, Google, Meta, and Anthropic say on their own pages about who reads your chats, what happens to them, and whether delete means delete.*

Every workshop, the same moment. ChatGPT has just drafted a payment reminder in ten seconds. Then a hand goes up at the back.

"Sir, before I put my customer data in this thing. Who can see it?"

It is the best question in the room. So today, no advice, only facts from the companies' own pages and from documented cases. Six questions. You decide at the end.

## Who can see what I type?

The company running the chatbot can. All four big ones say so on their own pages, each with its own conditions.

OpenAI says ChatGPT conversations are monitored by automated systems, and its team [may review flagged content](https://openai.com/transparency-and-content-moderation/?ref=techessentials.in). Google says a subset of Gemini chats [are read by human reviewers](https://support.google.com/gemini/answer/13594961?ref=techessentials.in), including outside contractors, after the chat is disconnected from your account. Meta says your normal WhatsApp messages stay end-to-end encrypted, and that [Meta can read the messages you send to Meta AI](https://faq.whatsapp.com/623460230302218?ref=techessentials.in). Anthropic says its employees [cannot access your Claude conversations by default](https://privacy.claude.com/en/articles/10458704-how-does-anthropic-protect-the-personal-data-of-claude-users?ref=techessentials.in), with two exceptions: chats you submit as feedback, and chats flagged for a rules review, which a small Trust and Safety team can read.

## What do they do with it?

The free and personal versions of all four can use your chats to make the AI better.

OpenAI says ChatGPT ["improves by further training on the conversations people have with it, unless you opt out"](https://help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance?ref=techessentials.in). Google's setting is called ["Keep Activity"](https://support.google.com/gemini/answer/13594961?ref=techessentials.in) and it is on by default. Chats a human reviewer has seen, the subset above, are kept up to three years, even if you delete your history. Meta's AI terms say it uses your interactions ["to personalize your experiences and ads, and improve AI at Meta"](https://www.facebook.com/legal/ai-terms/). Anthropic [asks at signup](https://www.anthropic.com/news/updates-to-our-consumer-terms?ref=techessentials.in) whether your Claude chats may train its models, and reviewers found the toggle pre-set to yes. With it on, an anonymized copy [can be kept up to five years](https://privacy.claude.com/en/articles/10023548-how-long-do-you-store-my-data?ref=techessentials.in). With it off, thirty days.

Meta uses it for one more thing. Since [December 16, 2025](https://about.fb.com/news/2025/10/improving-your-recommendations-apps-ai-meta/?ref=techessentials.in), what you say to Meta AI helps decide which posts, Reels, and ads you see across Facebook, Instagram, and WhatsApp. Europe, the UK, and South Korea are excluded. India is included. Europeans also get a form, under their privacy law, to object to Meta using their AI chats at all. India has no such form.

The paid business versions run on the opposite default. OpenAI: ["By default, we do not use your business data for training our models"](https://openai.com/enterprise-privacy/?ref=techessentials.in) on ChatGPT Business, Enterprise, and the API. Google says the same for [Gemini through a paid Workspace account](https://knowledge.workspace.google.com/admin/gemini/generative-ai-in-google-workspace-privacy-hub?ref=techessentials.in), and Anthropic says the same for [Claude for Work and its API](https://privacy.claude.com/en/articles/7996868-is-my-data-used-for-model-training?ref=techessentials.in). Same chat window. Different contract.

## Can a stranger read my chats?

No. No feature in any of these products lets a stranger look up your conversations, and there is no documented case of the model repeating one user's private chat to another user.

Software broke, and share features published more than people expected.

- March 2023: a bug showed some ChatGPT users the [titles of other people's chats](https://openai.com/index/march-20-chatgpt-outage/?ref=techessentials.in). Titles, not contents. Fixed the same day.
- January 2025: a researcher found Meta AI numbered every prompt and never checked who was asking. Changing the number [returned someone else's conversation](https://techcrunch.com/2025/07/15/meta-fixes-bug-that-could-leak-users-ai-prompts-and-generated-content/?ref=techessentials.in). Meta fixed it, paid him $10,000, and says it found no evidence anyone exploited it.
- 2025, twice: over 4,500 ChatGPT conversations [appeared in Google search](https://techcrunch.com/2025/07/31/openai-removes-chatgpt-feature-after-private-conversations-leak-to-google-search/?ref=techessentials.in) because users shared them with a link and ticked a box marked "make this chat discoverable." OpenAI judged the box too easy to tick and removed it. Meta AI app users pressed Share and [published private questions to a public feed](https://techcrunch.com/2025/06/12/the-meta-ai-app-is-a-privacy-disaster/?ref=techessentials.in) without realising it; Meta added a warning to the button.
- July 2026: shared Claude conversations [appeared in Google search](https://techcrunch.com/2026/07/27/psa-your-claude-shared-chats-and-artifacts-may-have-ended-up-on-google/?ref=techessentials.in). These were chats users had turned into share links and posted somewhere public; Anthropic had them out of search results the same day.

One more, on the training question. In 2023, researchers showed that a model can memorise fragments of its training data and [repeat them back verbatim](https://not-just-memorization.github.io/extracting-training-data-from-chatgpt.html?ref=techessentials.in), including a real email address and phone number. That data came from the public internet, not from anyone's chats, and the trick could not target a specific person.

## Does delete actually delete?

For four months in 2025, deleting a ChatGPT chat removed it from your screen and erased nothing on OpenAI's servers.

OpenAI's policy says a deleted chat is removed from its systems within 30 days, [unless the law requires otherwise](https://openai.com/policies/row-privacy-policy/?ref=techessentials.in). The New York Times is suing OpenAI over its journalism being used for training, and in May 2025 a judge ordered OpenAI to [preserve all user conversations, including the ones users deleted](https://openai.com/index/response-to-nyt-data-demands/?ref=techessentials.in). OpenAI called the order an overreach and fought it. The obligation ended on September 26, 2025, and normal deletion resumed. The chats from those months are still stored under legal hold, accessible, in OpenAI's words, only to "a small, audited OpenAI legal and security team."

In November 2025, the court ordered OpenAI to hand [20 million real consumer conversations](https://openai.com/index/fighting-nyt-user-privacy-invasion/?ref=techessentials.in) to the Times' lawyers, a random sample from December 2022 to November 2024\. A judge [affirmed the order in January 2026](https://news.bloomberglaw.com/ip-law/openai-must-turn-over-20-million-chatgpt-logs-judge-affirms?ref=techessentials.in), and OpenAI produced the sample. No user was told whether their chats are in the sample, and there is no way to find out. But the chats were stripped of names and personal details first. Only outside lawyers and their technical consultants can see them, and a court order forbids making any of it public. Business and API accounts were not included.

Nobody's chats were published. But your data sits under the company's promises, and the company's promises sit under a court.

## So is it safe?

Samsung's engineers pasted internal source code into ChatGPT in 2023\. No theft was reported, and Samsung still [banned the tools on company devices](https://www.bloomberg.com/news/articles/2023-05-02/samsung-bans-chatgpt-and-other-generative-ai-use-by-staff-after-leak?ref=techessentials.in). Its internal memo gave the reason: data on external servers is "difficult to retrieve and delete."

Google's Gemini page tells its users: ["Please don't enter confidential information that you wouldn't want a reviewer to see."](https://support.google.com/gemini/answer/13594961?ref=techessentials.in)

Meta's AI terms tell its users: ["Do not share information that you don't want the AIs to use and retain."](https://www.facebook.com/legal/ai-terms/)

Anthropic's help pages [advise against entering](https://support.claude.com/en/articles/8325621-i-would-like-to-input-sensitive-data-into-my-chats-with-claude-who-can-view-my-conversations?ref=techessentials.in) financial information, health records, passwords, or confidential business documents into Claude. Read why. It's because of the nuances.

## What about all the other AI apps?

Everything above describes four companies whose policies are public, dated, and picked over by journalists, courts, and regulators. The app stores hold thousands of other AI apps, and most are built on these same four engines through an API, a paid pipe into the model.

The privacy promises in that pipe run to the app company, not to you. OpenAI's business terms make privacy notices and consents [the app developer's job](https://openai.com/policies/business-terms/?ref=techessentials.in). Anthropic's commercial terms say the customer who owns the data [is the app company](https://www.anthropic.com/legal/commercial-terms?ref=techessentials.in). So the model provider does not train on what you type through an app. What the app company itself keeps, and how well it keeps it, is written only in that app's own policy.

The documented record on those apps is thin and unflattering. The biggest case came in February 2026: Chat and Ask AI, a popular app built on ChatGPT, Claude, and Gemini, left [300 million user messages readable in an unlocked database](https://www.malwarebytes.com/blog/news/2026/02/ai-chat-app-leak-exposes-300-million-messages-tied-to-25-million-users?ref=techessentials.in), and the researcher who found it saw similar holes in 103 of the 200 iOS apps he scanned. In 2024, Mozilla reviewed 11 AI companion apps: [all 11 earned its privacy warning label](https://web.archive.org/web/2024/https://foundation.mozilla.org/en/privacynotincluded/articles/happy-valentines-day-romantic-ai-chatbots-dont-have-your-privacy-at-heart/), and all but one said in their own policies that they may share or sell personal data. In September 2025, the US Federal Trade Commission [ordered seven chatbot companies to report](https://www.ftc.gov/news-events/news/press-releases/2025/09/ftc-launches-inquiry-ai-chatbots-acting-companions?ref=techessentials.in) how they collect, handle, and share what users say in conversations.

The four companies above answer this post's questions in writing. For any other AI app, the answers sit in that app's own privacy policy. That is the question mark.

## Where the switches sit

The controls that exist today:

- **ChatGPT**: Settings, then Data Controls, has a toggle called "Improve the model for everyone." Off means [new chats are not used for training](https://help.openai.com/en/articles/7730893-data-controls-faq?ref=techessentials.in). A Temporary Chat is never used for training and never saved to history, though a safety copy [can exist for up to 30 days](https://help.openai.com/en/articles/8914046-temporary-chat-faq?ref=techessentials.in).
- **Claude**: the toggle is called "Help Improve our AI models," under Settings, then Privacy. Off means [new chats are not used for training](https://privacy.claude.com/en/articles/12109829-how-do-i-change-my-model-improvement-privacy-settings?ref=techessentials.in), though chats already used stay inside models already trained. An Incognito chat [is never used for training](https://privacy.claude.com/en/articles/10023580-is-my-data-used-for-model-training?ref=techessentials.in), whatever the toggle says.
- **Gemini**: the switch is called "Keep Activity," at gemini.google.com under Settings and help, then Activity. With it off, chats still sit on Google's servers [for 72 hours](https://support.google.com/gemini/answer/13594961?ref=techessentials.in), then go.
- **Meta AI**: there is no training opt-out in India. Typing `/reset-ai` inside a Meta AI chat on WhatsApp [deletes Meta AI's copy](https://faq.whatsapp.com/688464770796037?ref=techessentials.in) of that conversation. Deleting the chat from your phone alone does not.

## For the record

- Everything above was checked against the linked pages in August 2026\. These policies have changed more than once in the last year and will change again. The links go to the live pages, which outrank this post.
- In every incident documented above, the exposure never came from the model talking. It came from bugs, from share buttons, and from third-party apps storing chats badly.
- This post describes the free and personal versions unless it says otherwise. The business versions are a different contract, and that difference is the single most useful fact in it.