Where Does Your Chat Go?
Taking Care of Your Data in AI Tools
Every prompt you type is shared with a commercial entity that may retain it, review it, and learn from it. This hour covers how we got here, what actually happens to your words, and the settings that put you back in charge.
Platform settings in this deck were checked in late 2025; privacy menus move often, so always verify against the current interface.
Legal complexity on one side, everyday users on the other
A friendly chat box
It feels like a private conversation; people ask AI about health worries, money troubles, relationship problems and work conflicts without a second thought.
A commercial data pipeline
Behind the box sit privacy policies written in dense legal language, covering retention, human review, model training and disclosure; terms most users have never read and couldn't parse if they did.
"Surveillance capitalism": your experience as raw material
Harvard economist Shoshana Zuboff coined the term for a business model built on collecting, analysing and commercialising consumer data, often without meaningful consent: human experience is translated into behavioural data, which becomes prediction products traded for profit.
In 2013, a Cambridge University researcher built a Facebook personality quiz called "This Is Your Digital Life". About 300,000 people took it for a small payment. The app harvested data not just from them, but from all their Facebook friends: up to 87 million profiles; likes, locations, friendships, personal details.
The data flowed to Cambridge Analytica, a political consulting firm, which used it to build "psychographic profiles" for micro-targeted political advertising in the 2016 US presidential election. The harvesting ran quietly from 2013 to 2016; the public learned of it only in March 2018, when whistleblower Christopher Wylie went to The Guardian and The New York Times.
The bill for "a breach of trust"
The intimacy problem: you tell AI things you'd never post
Curated for an audience
Posts are performances; filtered, flattering, meant to be seen. Even so, the harvested profiles were rich enough to swing advertising and politics.
Unfiltered by design
Chats with AI are candid: health concerns, relationship problems, financial difficulties, work conflicts, half-formed thoughts. That's a far more sensitive dataset than any social feed; held by commercial entities, often overseas.
Context, memory, training: three very different fates for your words
The conversation's scratchpad
Temporary working memory during a chat, cleared between sessions. The most benign fate; your words are used to answer you, then let go.
The account's notebook
Some tools keep persistent memory within your account so future chats know you. Convenient; and a growing dossier that deserves an occasional audit.
Absorbed into the model
Conversations selected for training become part of future models; persistent and potentially permanent. This is the fate the settings in this session control.
What "we may use your conversations for training" actually means
The four-step privacy audit for any AI tool
Defaults lean toward data collection; here's where to look
OpenAI
Settings → Data Controls → "Improve the model for everyone". "Temporary Chat" mode keeps a conversation out of history and training. Enterprise and Team accounts are excluded from training automatically.
Anthropic
Settings → Privacy → "Help improve Claude". Since September 2025 the default is opted in (previously opt-out), and retention runs up to five years regardless of the training toggle. Work, Enterprise and API use is excluded by default.
Gemini Apps Activity in your Google Account. Retention defaults to 18 months (adjustable to 3 or 36, or off); human reviewers may read conversations, and human-reviewed chats are kept up to three years even if you delete your activity.
Settings and defaults as checked in late 2025; menus and policies change frequently. Verify against the current interface before relying on this slide.
Copilot, Perplexity and Grok: check which version you're on
Microsoft
The consumer version strips personal identifiers from training data; Microsoft 365 Copilot keeps data inside your organisation's tenant and out of public model training. Consumer and enterprise settings differ substantially; know which one you're using.
Perplexity AI
An AI Data Retention toggle sits in settings, and an anonymous mode covers non-logged-in use. The platform updates frequently; re-check its policies periodically.
xAI
Settings live within the X platform, and Grok's data handling is tied to X's policies; review both Grok and X privacy settings, since data flows between them.
The newspaper test, and six friends
Some things never go in the box
Keys to accounts and identity
Passwords and security credentials · credit card and bank account numbers · government identifiers: Medicare numbers, Tax File Numbers, passports.
Data you hold in trust
Confidential business information without authorisation · personal health information about others · anything classified above OFFICIAL under government frameworks · any data you're legally or contractually obliged to protect.
Four privacy principles worth knowing by name
Open and transparent management
AI providers handling Australians' data must clearly explain how they manage personal information.
Use and disclosure
Data shouldn't be used for purposes beyond what you'd reasonably expect when you provided it.
Cross-border disclosure
Sending your data overseas requires equivalent protections; directly relevant when your chats live on US servers.
Security
Reasonable steps must be taken to protect your information from misuse, interference and loss.
Care for your data like it's leaving home; because it is
Where this deck's claims come from
Prepared August 2026 for the NT World Ink AI Special Topic Workshops. Privacy policies change frequently; always verify settings against the current interface before making decisions about sensitive data.