AI and your privacy: what you already gave away

AI & Life — The Hurtful Truth · September 2026

Run the mental audit now: the conversation where you described your symptoms, the one where you pasted a work email to "clean it up," the argument you typed out at 2 a.m. because the chatbot was awake. If you assumed those were private, 2026 has an uncomfortable correction for you — and it's been arriving one settings page at a time.

The assumption that broke. Researchers reported that people treat AI conversations as private — and chatbots learn from conversations users believed were private. Stanford's HAI put the practical version of the warning in its title: be careful what you tell your AI chatbot. A psychiatric journal went further and called chatbot privacy an oxymoron, arguing you should assume your data is always at risk. That's not a fringe framing anymore; it's the sober read of how the default actually works.

The mechanism is simple, which is why it works. Unless you change a setting, your chats are candidate training data. That default was newsworthy enough that WIRED walked through how to opt out when Anthropic moved to use Claude chats for training, and guides now cover every major vendor — how to stop chatbots from training on your data, where the hidden menus live, and what the trade-offs are. Which is the uncomfortable part: the control exists almost everywhere. It's just buried, vendor-specific, and nowhere near the conversation where you needed it.

And the fine print differs by vendor in ways that matter. One analysis found a five-year gap in how long ChatGPT, Gemini, and Claude keep or use your data — five years of difference between what the same honest conversation costs you on each service. Add the scattered defaults elsewhere — a hidden setting turned on by default feeding X's AI, Google quietly training on your data until you find the toggle — and "just check the privacy settings" turns out to be a part-time job. Singapore's regulator now requires AI-training notifications when personal data is used, which tells you governments noticed the gap too.

What you shouldn't type, ever. Guides converge on the same list: passwords, financial details, medical details, identity documents, anything about someone else. Not because a chatbot is malicious — because it's a third-party service with retention, training pipelines, and terms that can change. The rule that survives every privacy guide is the oldest one: don't put in the machine what you wouldn't put on a public bus.

The hopeful signal — private by default as a selling point. This month brought a genuinely interesting turn: Mistral and Mozilla announced a partnership for private AI browsing — private-by-default moving from compliance cost to competitive advantage. If that becomes a real differentiator, your privacy setting stops being homework and becomes a feature. Watch whether the industry lets it.

What to actually do: go turn off training on every chatbot you use, today — the step-by-step opt-out guides exist precisely because the setting won't come to you. Don't type identifying details into general chatbots; if you must, use temporary or incognito-style chat modes and delete the history afterward. Read the training toggle before the first conversation, not after the one you regret. And treat "private chat" as a product feature you verify per vendor, per account, per update — because that's what it currently is.

The daily tracker of what AI actually does to your data — with the receipts — is updatesbyai.com. And if you want the same uncomfortable audit applied to your health instead of your chats, our health edition runs the identical honesty policy on a different kind of record — the kind with your name on it.


Part of the ecosystem: updatesbyai.com · a0flow.com · hurtfultruth.com