AI WITH MEL & MO ← BACK TO AI LIBRARY
LEARN AI / AI LIBRARY / AI WATCH OUTS

Where your data goes

Who can read what you type, how long it's kept, and what the training setting covers.

JUL 2026·3:28·WITH MEL
TRANSCRIPT

The full script, word for word — 565 words, about 3 minutes to read. Current as at July 2026. AI tools change quickly; if something looks different when you try it, check the product's own help pages.

Paying for your AI subscription doesn't buy you privacy. And switching training off — which you should — does less than the name suggests. What it changes is how long your conversations are kept, not whether they're kept.

The line isn't free versus paid — it's consumer versus contracted. Consumer accounts — the free tiers and the personal subscriptions on top of them — train on your conversations by default. Contracted accounts are the ones an organisation signs: business, enterprise, education, the developer interface. Those are excluded, because there's an agreement behind them. A twenty-dollar personal plan is a consumer account. And training doesn't mean somebody reads your chat — it means your words become part of what the next version learns from.

Turning training off doesn't mean nothing is kept — it changes how long. On Claude, opting out puts you on a thirty-day window; leave training on and that becomes five years. On ChatGPT, a deleted conversation is gone from their systems within thirty days. Google works differently again — switch activity off and conversations still sit for seventy-two hours, and the default setting keeps them eighteen months. So everything you type is held somewhere for a period. What you're choosing is the length.

Two things sit above all of that. First, safety flags. If an automated system flags a conversation as breaching the usage policy, retention changes — on Claude, up to two years for the conversation itself and seven years for the classification scores, whether or not you've turned training off. Second, litigation. A court ordered OpenAI to preserve deleted conversations during the New York Times copyright case, then ordered twenty million of them handed to the other side's lawyers. Names were stripped out; researchers who looked still found addresses and phone numbers.

None of which makes the switch pointless — thirty days against five years is a real difference, and it costs two minutes. It's in settings, under data controls or activity — the wording differs by tool and moves often enough that naming a menu here would date this video. It stops future conversations, not past ones. And check it twice a year, because one major assistant flipped to training-by-default in a single terms update in twenty twenty-five.

One more, because it's coming at businesses from the regulators now. Australia is a good marker: from December twenty twenty-six, if a business uses a computer program — and that includes AI — to make, or substantially help make, a decision that significantly affects someone's rights or interests, it has to say so in its privacy policy. Screening job applicants. Assessing an application. Setting one customer's price and not another's. Similar duties are arriving elsewhere. The obligation is disclosure, not permission — but you can't disclose what you haven't mapped.

So the working rule. Decide once what never goes into a consumer account — client names, staff matters, anything you're contractually bound to protect, anything someone told you privately. Then it's a habit, not a judgement you're making at speed, every single time.

One thing to do this week. Open the settings on whichever assistant you use most, find the data or activity section, and see whether training is on or off. Thirty seconds, one setting. The retention figures won't be on that screen — those sit in the privacy policy. If the number matters to you, that's the second click.

← BACK TO AI LIBRARY