
Where Your AI Conversations Live, and Who Can Read Them
Think about what you typed into an AI assistant last week. A client name. A contract clause. Numbers from a spreadsheet you are not supposed to email. Something about your health, because it was faster than searching.
When memory is off, that lives in one conversation you will probably never open again. When memory is on, it becomes part of a profile the assistant carries into every future chat. Most people switched that on without reading anything, because the setting arrived switched on already.
This is not an argument for turning it off. It is worth knowing what the companies themselves say happens to that text, because the published policies are more specific than the rumours, and in places more surprising.
Three different things get stored
People talk about AI privacy as one question. It is at least three, and they have different rules.
Your conversation history. The threads in the sidebar, stored on the company's servers, tied to your account.
Your memory. The profile built from those conversations. It usually lives separately from the chats it came from, which matters a lot in a minute.
Copies made for review. When a conversation gets flagged, reported, or sampled for quality, a copy can be made, and that copy follows a different rule than the original.
What the policies actually say
On deletion, OpenAI is specific. A deleted chat disappears from your account immediately and is scheduled for permanent deletion from its systems within thirty days. The exceptions are stated: content already de-identified and disconnected from your account, and content it has to keep longer for security or legal reasons. Temporary chats are deleted within thirty days even if you never touch them.
On who can read your text, OpenAI lists four situations: investigating abuse or a security incident, supporting you when you contact them, handling legal matters, and improving model performance unless you have opted out. It says access is limited to authorised personnel on a need to know basis, logged, and subject to training requirements.
Google is blunter in a different way. Conversations that have been seen by human reviewers are not deleted when you delete your activity. They are kept for up to three years, disconnected from your Google account. Its own guidance says plainly not to enter confidential information, or anything you would not want a reviewer to see.
Most assistants also offer a mode that stays out of all of this. Temporary chats in ChatGPT, incognito in Claude, private chat in Grok, where the conversation does not enter memory or history and is removed within thirty days.
Read those together and the picture is reasonable but narrower than people assume. Normal chats are deleted on a clear timetable. Reviewed chats are a separate track, and on at least one major platform that track runs for years.
The part almost everyone gets wrong
Deleting a conversation does not necessarily remove what the assistant learned from it.
The memory is a separate store. If a chat produced an entry about your job, your client or your preferences, deleting the chat does not automatically delete that entry. You have to open the memory settings and remove it there, as its own action.
This is the single most useful thing to know about AI memory and privacy, and it follows directly from how memory works: it keeps a summary of you rather than your words, held apart from the conversations that produced it. That mechanism, and what it costs you, is the subject of what AI actually remembers.
The second thing people get wrong is subtler. Searching your history and knowing what an assistant holds about you are not the same operation. You can scroll the sidebar all afternoon and never see the profile, which is why finding is not remembering matters here too.
What to do this week
Read your memory, once, properly. Every major assistant has a settings page listing what it has stored about you. Ten minutes there is more informative than any article, including this one. People routinely find entries they do not remember creating and details that are simply wrong.
Delete the entries you would not want read aloud. Not the chats, the entries. Do both if you like, but the entries are the part that persists.
Use the private mode for the sensitive things. Health, finances, anything about another person who did not agree to be in your chat. Temporary or incognito mode exists for exactly this and costs you nothing except memory of that conversation.
Decide once what never goes in at all. Credentials, government numbers, other people's private details. There is no setting that makes those safe, and a rule you decide in advance is more reliable than judgement at eleven at night.
What to ask of anything that holds your memory
If you use a separate tool to keep memory across assistants, you are adding another place your text lives. That is a reasonable trade, and the questions to ask are simple.
Where is the text kept, on your machine or on their servers, and is it readable by them. Some tools keep everything local by design, which is the strongest answer available and worth preferring for sensitive work.
Can you see every item and delete any of it, one by one. If you cannot inspect it, you cannot correct it, and you will end up not trusting it.
Can you export everything and leave. A memory you cannot take with you is a memory someone else controls. The manual version of that is covered in moving context by hand.
What happens when you delete. Removed everywhere, or hidden from your view. Ask it plainly, and prefer the tool that answers plainly.
Which of these matters most depends on the form the tool takes, since an extension, a hub and a developer API each sit in a different place relative to your data. Which form solves which problem covers that difference.
The uncomfortable summary is that all of this already applies to you. Memory arrived switched on, the conversations are already stored, and a profile has already been built. The only real choice left is whether you look at it.