What Does AI Actually Know About You? The 10-Minute Privacy Audit

What Does AI Actually Know About You? The 10-Minute Privacy Audit

πŸ•΅ What AI actually knows about you

Most people picture a chatbot like a search box. You ask, it answers, it forgets. That stopped being true a while ago and nobody sent a memo.

There are three separate things your AI is holding right now, and they’re worth telling apart:

  • 1. What you typed. Every prompt. The contract you pasted for a second opinion. The doctor’s letter you asked it to explain. The email draft about your coworker.
  • 2. What it wrote down about you. This is the one that surprises people. It isn’t storing your chats β€” it’s storing conclusions. A running profile. Your job, your kids’ names, how you like to be talked to, what you’re worried about.
  • 3. What it kept after you closed the tab. Chat history, model training, and β€” increasingly β€” what you do outside the chat window.

That third one moved fast this year. In July, Google began using uploaded photos and Search materials to train its AI by default, opt-out available. In August, OpenAI shipped a feature that keeps a record of the apps and websites you visit. Meta claims the right to use your AI conversations to target ads across its apps.

So I opened mine up. Here’s my Claude memory settings β€” read what it has stored, then look at the third toggle and the red line underneath it:

Can you believe it even knows my dog’s name? Nobody sat me down and asked for that. It came up in passing and it wrote it down, the way a very attentive stranger would.

And then read the red line again: “Deletion didn’t finish. Some memories of sensitive topics may still be saved.”

I had turned sensitive topics off. It told me β€” honestly, and to its credit β€” that turning it off didn’t fully work. That’s a company being straight with me, and it’s still a sentence that should make you sit up. Most tools don’t tell you that at all.

Then I went and looked at Grok, which keeps something it calls a User Memory. Not my chats. A dossier:

It had my name, the username out of a config file on my machine, what laptop I use, which operating system, which virtual machines I’d tried and why I abandoned the first one β€” and the fact that a software license of mine expired in March. There were pages and pages of user memory. It knew more about me than I did, it felt like!

I never told it most of that in so many words. It assembled it, the way you’d assemble a picture of a stranger from a year of their small talk.

Want to see yours? Ask:

Based on everything you remember about me, write a profile of who I am, what I do, what I care about, and what I'm worried about. Be specific. Don't be flattering.

Fifteen seconds. You will not forget the answer.

Then I ran it in ChatGPT and I can’t show you the output. Here’s why…

⚠ The memory you can see is not the memory that matters

My ChatGPT memory page was nearly empty. A few lines. Nothing I’d mind a stranger reading.

Then I ran the prompt. It came back with pages about me. Family, work, money, the things I’ve been chewing on for months.

I can’t show you much of that response and it’s PAGES long.

Here’s what’s going on, because it took me a minute to work out. ChatGPT has two memory systems, and only one of them has a list you can read:

  • Saved memories β€” the visible list. Discrete facts it decided to write down. You can read them, edit them, delete them one by one.
  • Reference chat history β€” a toggle, and nothing else. No list. No page to review. It pulls from everything you’ve ever typed into it, and you have no way to see what it’s drawing on until you ask.

An empty memory page tells you nothing about the second one. Mine was blank and it still knew everything.

So when you do the audit below, don’t stop at the list. Find Reference chat history and decide, deliberately, whether you want it on.

And do it in this order: run the prompt first, then look at the settings. The other way round, you’ll see a short list, decide you’re fine, and close the tab.

πŸ”’ The 10-minute audit

Before the click-by-click, two numbers that explain why this matters more than it used to.

39.7% of all AI interactions involve sensitive data, and the average person feeds sensitive data into an AI tool once every three days. That’s from a Cyberhaven report published in February. Most of it goes through personal accounts, not company ones β€” 32.3% for ChatGPT, 58.2% for Claude, 60.9% for Perplexity.

And in February, one AI chat app leaked 300 million messages belonging to 25 million users. Not a sophisticated hack β€” a misconfigured database left readable by anyone with the URL. The researcher who found it then scanned 200 other iOS apps and found 103 of them had the same hole.

Nobody’s chats were safe because nobody’s chats were secret. They were just unlooked-at.

Here’s the fix. Ten minutes, once. Run the profile prompt first, in each one, before you touch a setting.

ChatGPT β€” Settings β†’ Personalization β†’ Memory. Two things live here and you want both. Manage memories opens the visible list β€” read it, delete anything you wouldn’t hand a stranger. Reference chat history is the toggle with no list behind it; that’s the one that knew everything about me. Turning off Reference saved memories switches chat history off too. Then Settings β†’ Data Controls and turn off improving the model for everyone. (Not seeing any of this? You’re probably in Codex or the sidebar app β€” go to chatgpt.com in a browser and click your name, bottom left.)

Claude β€” Settings β†’ Memory. Three toggles: search past chats, generate memory from chats, include sensitive topics. Under them, your actual stored profile. Read it.

Gemini β€” myactivity.google.com β†’ Gemini Apps Activity. Set auto-delete. While you’re there, check what July’s default training change picked up.

Then adopt one rule, which is worth more than all the toggles combined:

If you wouldn’t put it in an email to a stranger, don’t paste it into a chatbot on a personal account.

Client contracts, medical letters, anything with a social security number, anything under NDA. Use your company’s approved account for company data. That one habit closes more risk than every setting on this page.

🎁 Free download: The AI Privacy Audit

Every menu path above on one page for ChatGPT, Claude, Gemini and Copilot, plus the “what do you know about me” prompt and a short what-never-to-paste list you can send to your team.

β†’ Get the free checklist

Related guides

Frequently asked questions

How do I see what ChatGPT remembers about me?

Go to Settings β†’ Personalization β†’ Memory. Manage memories opens the saved list, which you can read, edit and delete. Reference chat history is a separate toggle with no list behind it, so the quickest way to see what it draws on is to ask ChatGPT to write a profile of you first.

Does an empty ChatGPT memory page mean it doesn't know anything about me?

No. ChatGPT has two memory systems. Saved memories is the list you can see. Reference chat history pulls from your past chats and has no page to review. Run the profile prompt first, then check the settings.

Where are Claude's and Gemini's memory settings?

In Claude, open Settings β†’ Memory: three toggles (search past chats, generate memory from chats, include sensitive topics) with your stored profile underneath. For Gemini, go to myactivity.google.com β†’ Gemini Apps Activity and set auto-delete.

What should I never paste into a chatbot?

If you wouldn't put it in an email to a stranger, don't paste it into a chatbot on a personal account. That means client contracts, medical letters, anything with a Social Security number and anything under NDA. Use your company's approved account for company data.

Scroll to Top