From Friday Deep-Dive · Friday, September 18, 2026 · 10 min read
Your AI chat box is not a private notepad
ChatGPT, Claude, Gemini, Copilot, and Grok all have settings that decide whether your conversations train the model, what the tool remembers about you, and how long your chats stick around after you delete them. On most personal accounts, training is switched on until somebody turns it off. The fix takes about five minutes. In the full post: the exact menu path to turn off training on all five platforms, how to see what memory has stored about you, where the private chat button lives on each tool, why delete does not mean gone, the seven things a publication should never paste into any chatbot, what that February court ruling about AI and legal privilege actually said, and a five-step setup you can hand to your whole staff.
Credit where it is due: this week's idea started with a thread by @jackcoder0 on X, walking through the AI privacy settings most people never touch. It was good enough that I wanted every publication to see it. Before passing it along, I checked every menu path and claim against the companies' own help pages. A few menus had moved, and a couple of claims were stronger than the facts. What follows is the checked version, rewritten for people who run publications.
Here is the uncomfortable part. Your reporters, your ad reps, and your front office are probably pasting things into ChatGPT and Claude every day. Meeting notes. A client's ad copy. A draft of a story that has not run yet. Maybe a subscriber list.
The chat box feels like a notepad. It is not a notepad. It is closer to a form that sends everything you type to a company's servers, where it gets stored, sometimes read by people doing safety review, and on most personal accounts, used to train the next version of the product.
None of that is a scandal. It is all in the terms we clicked through. But almost nobody has opened the settings that control it. Fixing that takes about five minutes, and it is free.
Why this is different from Google
When you search Google, you get links back. When you talk to ChatGPT, you are handing it material. On most personal accounts, that material can be used to improve future models.
Your name does not get attached to it. But the substance of what you typed goes into the pile.
So the question is not "is AI dangerous." The question is "have I told it what it is allowed to keep."
1. Turn off training
This is the single most important setting, and every major platform has one. It stops your future conversations from being used to train the model. It does not reach back and pull out anything already used.
- ChatGPT: click your profile picture, then Settings > Data Controls, and turn off Improve the model for everyone.
- Claude: click your name in the bottom left corner, then Settings > Privacy, and turn off Help improve Claude. Worth knowing: Anthropic changed its policy in 2025 so that on Free, Pro, and Max accounts this is on unless you switch it off. Leave it on and your chats can be kept for up to five years. Turn it off and the standard is 30 days.
- Gemini: go to myactivity.google.com/product/gemini and turn off Keep Activity. Google renamed this from "Gemini Apps Activity" in 2025, so older guides use the old name.
- Copilot: click your profile icon, open your profile, then Privacy, and turn off both Model training on text and Model training on voice.
- Grok: there are two separate switches. On X, go to Settings and privacy > Privacy and safety > Grok and turn off the training option. This is easiest on the desktop website. Then on grok.com, go to Settings > Data Controls and turn off Improve the Model. Turning off one does not turn off the other.
One reassurance: if your publication pays for a business plan, like ChatGPT Business or Enterprise, Claude for Work, or Copilot through a Microsoft work account, those generally do not train on your data. The free and personal plans are the ones to check.
2. Look at what it remembers about you
ChatGPT, Claude, and Gemini can all remember details about you from one conversation to the next. That is what makes them useful. It also means there is a running profile of you on somebody else's server, built from things you said and have probably forgotten.
Go look. It takes a minute, and most people are surprised.
- ChatGPT: Settings > Personalization > Memory. You can delete individual items, and you can switch off saved memories and chat history reference separately.
- Claude: Settings > Capabilities, then View and edit memory. One catch: turning off the memory switch stops new memories, but it does not erase what is already stored. To wipe it, use reset.
At a publication, delete these on sight: source names, the names of people in a story you have not published, anything from a personnel issue, and anything an advertiser told you about their business in confidence.
3. Use private mode for anything sensitive
Every major platform now has a chat mode that stays out of your history, does not create memories, and is not used for training.
- ChatGPT: start a new chat and click Temporary in the top right.
- Claude: click the ghost icon in the top right of a new chat. It is not available inside Projects.
- Gemini: look for Temporary chat at the top of Gemini. On the web it sits in the top right corner.
- Grok: click the ghost icon to start a Private Chat.
The answers are exactly as good. The only difference is what gets kept.
Here is the part most guides get wrong, and it matters: private mode does not mean nothing is kept. ChatGPT, Claude, and Grok still hold these chats for up to 30 days for safety review. Gemini keeps them up to 72 hours. Private mode keeps a conversation out of your history and out of training. It does not make it vanish the second you close the tab.
4. "Delete" does not mean gone
Deleting a conversation removes it from your list. It does not instantly remove it from the company's servers.
- ChatGPT: deleted chats are removed from OpenAI's systems within 30 days.
- Claude: a deleted conversation will not be used for future training.
- Gemini: with Keep Activity on, chats auto-delete after 18 months by default, and you can change that to 3 or 36 months. There is also a catch in Google's own help pages: if a chat was picked for review by a person, that copy can be kept for up to three years, even after you delete your activity.
Here is a reminder from our own industry of how quickly this can change. In The New York Times' copyright lawsuit against OpenAI, a federal judge ordered OpenAI in May 2025 to preserve ChatGPT conversations it would normally have deleted, including chats users had deleted themselves. That order stood until late September 2025. The 30-day promise held right up until a court said otherwise.
The only data that is never kept is data you never typed.
5. What a publication never pastes, whatever the settings
No setting fully protects something you have already sent. For a publication, this is the list:
- Confidential sources, or anything that could identify one. Your state's shield law was written to protect you and your notes. Whether it reaches a copy sitting on a tech company's server is not a question you want your publication to be the test case for.
- Unpublished investigations. Draft stories, document dumps, tips you are still running down.
- Passwords, logins, and account numbers. If someone already did, change that password today.
- Other people's private information. Subscriber lists, an advertiser's sales numbers, a job applicant's resume, an employee's review.
- Anything from a lawyer. Advice from your publication's attorney, a demand letter, a settlement draft.
- Business numbers you would not hand a competitor. Revenue, pricing plans, a conversation about selling the business.
- Medical details tied to a name. Yours or anyone else's.
The easy test: if you would not put it in an email to a stranger, do not put it in the chat box.
You can still get most of the help by stripping names out first. "Summarize this contract" works just as well with the client's name replaced by "Client A."
6. The platforms do not play by the same rules
Most of us pick an AI tool for how well it writes. The data rules are worth a look too. The short version, as of this week:
- ChatGPT: trains on personal accounts unless you turn it off. Deleted and temporary chats are cleared within 30 days.
- Claude: training is on for personal plans unless you turn it off. Up to five years of retention if you leave it on, 30 days if you turn it off.
- Gemini: tied to your Google account. 18 months of history by default, and chats a person reviewed can stay up to three years.
- Copilot: trains on personal accounts unless you turn it off. Work and school accounts are not used for training.
- Grok: can train on both your Grok chats and your activity on X. Two switches, in two places.
None of them is "the private one." Each has settings that fix most of it.
7. Be careful what you let AI agents touch
The newest tools do more than answer questions. They read your email, open your files, browse websites, and take actions for you. That is a different kind of risk. A chatbot can only hold what you gave it. An agent can act on everything you gave it permission to reach.
Three things to know:
- Hidden instructions are real. A web page, email, or document can contain text written to trick an AI agent into doing something you never asked for, like sending your data somewhere. The agent reads it and follows it. The industry calls this prompt injection, and nobody has solved it yet.
- Add-ons can be bad. The security firm ESET scanned about 800,000 AI "skills," the add-ons that teach agents new tasks, between March and May of this year. About 25,000 looked suspicious, and more than 3,000 were flat-out malicious.
- You probably clicked Allow without reading. That popup asking for your Gmail, your Drive, or your calendar is a real key to a real door.
What to do: give an agent only the access the specific job needs. Every so often, check what you have connected and remove anything you do not use. In ChatGPT, look under Plugins in the left sidebar. In Claude, look under Customize > Connectors. And do not point an agent at emails or links from people you do not know.
8. What the court actually ruled
You may have seen it said that a court ruled AI chats have no legal confidentiality. That overstates it, so here is what actually happened.
In February 2026, in United States v. Heppner, federal Judge Jed Rakoff in New York ruled that documents a criminal defendant created on his own with the consumer version of Claude were not protected by attorney-client privilege. His reasons: Claude is not a lawyer, the defendant's attorneys had not directed him to use it, and the service's own privacy terms meant he had no reason to expect it would stay confidential.
That is one judge, in one case, on those specific facts. It did not declare every AI conversation public.
The practical lesson still holds, and it is the one I would pass along to your staff: write in an AI chat as if a lawyer might read it someday. Between lawsuits, subpoenas, and preservation orders like the one in the Times case, a chat log is a record, not a private thought.
9. The five-minute setup
Do this once. It covers every conversation from here on.
1 Turn off training on every tool you use.
One switch per platform, two for Grok. The paths are in number 1 above. About a minute.
2 Open memory and clean it out.
Delete source names, story subjects, personnel details, and anything a client told you in confidence. About a minute.
3 Find the private mode button on each tool.
Temporary on ChatGPT, the ghost icon on Claude and Grok, Temporary chat on Gemini. You just need to know where it is. Thirty seconds.
4 Check what your AI tools are connected to.
Remove anything you do not actively use. About a minute.
5 Put the never-paste list on the wall.
Sources, unpublished stories, passwords, other people's private information, legal material, business numbers, and medical details. Then make sure everyone on staff who uses AI has seen it. About a minute, plus the conversation.
The bottom line
None of this is a reason to stop using AI. I use it every day, and I think you should too.
It is a reason to spend five minutes in the settings. The tools are just as helpful afterward. They simply keep less of what you told them, and your staff knows what never goes in the box.
Have a good weekend.
Source: https://x.com/jackcoder0
Try this and tell me what happened.
Did it work? Hit reply. Did it come back sounding like a stranger? Hit reply harder. That’s the interesting failure, and it’s almost always fixable.
Get the next one in your inbox
Tuesday brief + Friday deep-dive. Free. Unsubscribe anytime.
Subscribe — free, twice weekly← Back to Nine AI privacy settings you may have never opened