What happens to your data when you entrust it to AI?
We share prompts, documents, photos, and personal conversations daily with generative AI. But once sent, how does this data circulate, how long is it kept, and what is it used for?
We tell AI about our days, our problems, our projects. We entrust it with work documents, photos, and increasingly, access to our emails or calendars. Through these exchanges, and with accumulation, this information reveals more than we explicitly state. It can hint at a profession, habits, interests, relationships, a working style, or concerns we haven't named but an AI chatbot can deduce.
The more interactions reveal about us, the less their fate is a minor detail. The question isn't just about the prompt itself, but what the service does with everything we provide. What exactly is received? What is stored? What can be reused across conversations? And when is our data used to improve or train the models?
The moment you hit Send, your prompt leaves your device for the remote infrastructure running the service. Upon arrival, it can be combined with a broader context: part of the current conversation, elements remembered from previous exchanges, internal instructions guiding the response, or data retrieved from a file or connected service. If you attach a document, the service might extract relevant parts. If you grant access to email or a calendar, it can fetch pertinent details.
What we type isn't always the full extent of what's submitted to the model, nor does the model necessarily receive everything we've shared with the service.
Once this context is built, it's converted into a format the model can process – the famous tokens. From this sequence, the model begins generating its response. This is inference: considering everything provided, it calculates at each step the probability of each token being the next. The response is built gradually, not pulled from a database. This is why it's called generative AI.
The elements used can even change during generation. An assistant connected to the web, a search engine, or other tools might fetch additional information, integrate it into the existing context, and then continue its response. The initial prompt can thus lead to multiple invisible technical exchanges behind a result that appears instantaneous on screen.
After generation, the result is sent back to the application and displayed.
If you've followed, you understand that a simple prompt can involve various data types and information, processed at different times for different reasons, with varying outcomes.
To respond, the service first uses data needed for the request: this is query processing. Once no longer necessary for the current exchange, deletion isn't automatic. Some or all of this information might remain with the provider for days or much longer, depending on the service, settings, and the reason for retention.
History is the most obvious manifestation. You close a chat, return the next day, and the discussion is still there. But deleting a conversation from the interface doesn't immediately erase all associated data. The provider might retain some for technical, security, abuse prevention, support, or legal reasons.
History shouldn't be confused with memory, which also stores usable data. It can record facts explicitly shared, or, depending on the service, deduce preferences, habits, or contextual elements from your exchanges for future use.
Then there's what the provider may extract from interactions to improve its systems. This data can be used to evaluate responses, identify errors, adjust components, and in some cases, join data used to train or refine models.
A piece of data doesn't necessarily have a single destination. Providing it for a response doesn't solely determine its future: multiple processes can follow or overlap, sometimes long after the exchange that introduced it into the system.
There's no standard retention period, and deleting a conversation from the interface doesn't always immediately remove associated data.
- ChatGPT: OpenAI deletes deleted conversations and temporary chats within 30 days, unless data is already de-identified or retention is required for legal/security reasons.
- Perplexity: Data may be retained as long as the account exists. After deletion, Perplexity states data is erased within 30 days, barring exceptions in its privacy policy.
- Copilot: Microsoft keeps the last 18 months of history, which can be manually deleted anytime.
- Gemini: Google deletes activity after 18 months by default, adjustable to 3 or 36 months, or without auto-deletion. When activity recording is off, exchanges remain for up to 72 hours; those selected for human review may be kept for three years after dissociation from the account.
- Claude: Anthropic deletes deleted conversations within 30 days but keeps flagged exchanges for up to two years, associated security scores for seven years, and data used to improve Claude for five years.
A conversation with a chatbot isn't a sealed one-on-one between you and the model. Most processing is automated, but internal teams or third-party contractors may access parts of exchanges to examine reports, investigate abuse or security incidents, provide support, comply with legal obligations, or evaluate services.
This doesn't mean employees spend their days reading our conversations. At OpenAI, Google, Microsoft, and Anthropic, access is regulated, limited to authorized personnel, and applied to targeted content samples based on the situation.
Our exchanges can also extend beyond the provider's perimeter when the assistant uses other services, whether you've connected them or they operate behind the scenes to process the request. A connected application might use parts of the conversation context or memory to perform an action, while a service like Perplexity might rely on models developed by OpenAI, Anthropic, or Google.
A single query can thus move from the chatbot you use to other companies' systems. These exchanges are usually governed by agreements between providers, but data processing and retention rules can vary.
At work, the rules change. The company providing your account may have more control over data, retention, or user-accessible functions. With Claude for Work, for instance, an organization's administrator can request an export including conversations and files linked to company accounts.
In return, these offerings generally provide greater protection for exchanges against the provider itself. OpenAI, Anthropic, Google, and Microsoft, for example, do not use data from their main business offerings to train their models by default.
Unfortunately, regaining control requires more than just clicking Delete. As you now know, deleting a chat doesn't always erase what its memory retained. Disabling memory doesn't delete already stored conversations. Refusing to let exchanges be used for training has no impact on history or memory. Even if you delve into menus for a thorough cleanup, providers' retention periods continue to apply.
Files can also follow their own lifecycle. Depending on the service and function used, deleting the conversation where a document was sent may not always remove the file itself. Stored in a library, project, or workspace, it may remain available until that space is deleted.
Disconnecting a third-party app doesn't necessarily erase information it has already provided to the chatbot. It might cut future access to messaging, calendars, or storage, while conversations that incorporated this data still need separate deletion.
More complex is data already used for training: depending on the provider, deleting the original conversation or revoking permission might prevent future training use, but it won't undo ongoing or completed training. Models already trained remain unaffected.
Reassuringly, the conversation doesn't persist as an identifiable exchange within the model that you could go and delete. Training modifies the model's parameters, though it doesn't preclude it from memorizing certain elements from the training data. The training copy may also continue to exist within the provider's systems for their designated period, even after permission is withdrawn.
The safest way to maintain control is to act before sending a prompt, file, or any material to the chatbot: check service settings, prefer temporary conversations when available, and only transmit the information it truly needs. And perhaps, most importantly, avoid confiding in it.
Fresh materials — Tech News

Three TNT Transmitters to Cease Operations November 24th; Affected Households Won't Bear Costs
The shutdown of three TNT transmitters, scheduled for November 24, 2026, follows ARCOM's approval earlier this summer. The audiovisual and digital regulator has now outlined the specifics. For the affected viewers, television reception should continue uninterrupted as channels commit to ensuri

Chuwi UBox: Ryzen 5, 16GB RAM, Windows 11 Pro for Under €290?
The Chuwi UBox packs a Ryzen 5 6600H processor, 16GB of memory, and a 512GB SSD into a 650-gram enclosure. With a promotional code on AliExpress, its price drops into the entry-level mini PC range, offering significantly more power than comparable Intel-based models. Chuwi, known for its affordab

Alleged ShinyHunters Member Arrested in Jordan Aids FBI
Saif al-Din Khader, apprehended by Jordanian authorities on September 29th, is now helping the FBI pursue other members of ShinyHunters. This extortion group recently claimed responsibility for stealing data from all FBI employees, including medical and psychiatric records. Three individu

LDLC Confirms Data Breach: Customer Personal Information Accessed
French online retailer LDLC has reported a cybersecurity incident. Unauthorized access to one of its systems allowed cybercriminals to view customer personal data. This includes names, addresses, phone numbers, and account details. LDLC assures that banking information and passwords were not c

Google: Space Data Centers Need 1,800 Starship Launches
Google is developing orbital data centers. To make this project viable, the tech giant is awaiting significant progress from SpaceX and its Starship rocket. On October 1st, Google sent its first space-bound data center into orbit aboard a SpaceX Falcon 9 rocket. This mission wi

Ryzen 5 9600X Hits €142.36 on AliExpress for AM5 Builds
Our review highlighted the Ryzen 5 9600X not just for its raw performance, but for its remarkable efficiency and cool operation under load. Now, with a price cut to less than half its launch cost during AliExpress's Local Day, it presents a much more compelling option for an AM5 platfo