Unibase
    • Memory
    • BitAgent
    • UB Bridge
    • Membase
    • AIP
    • Unibase Pay
    • Unibase DA
    • Explorer
    • Docs
    • Blog
    • GitHub
    • Twitter
    • Telegram
    • Discord
Unibase

© 2026 Unibase

Products
MemoryBitAgentUB Bridge
Infrastructure
MembaseAIPUnibase PayUnibase DA
Developers
ExplorerDocsBlog
Community
GitHubTwitterTelegramDiscord
HomeBlog
Where Your AI Conversations Live, and Who Can Read Them

Where Your AI Conversations Live, and Who Can Read Them

AI Memory
Unibase DailyUnibase Team·22/09/2026
View the original post on Medium

Think about what you typed into an AI assistant last week. A client name. A contract clause. Numbers from a spreadsheet you are not supposed to email. Something about your health, because it was faster than searching.

When memory is off, that lives in one conversation you will probably never open again. When memory is on, it becomes part of a profile the assistant carries into every future chat. Most people switched that on without reading anything, because the setting arrived switched on already.

This is not an argument for turning it off. It is worth knowing what the companies themselves say happens to that text, because the published policies are more specific than the rumours, and in places more surprising.

Three different things get stored

People talk about AI privacy as one question. It is at least three, and they have different rules.

Your conversation history. The threads in the sidebar, stored on the company's servers, tied to your account.

Your memory. The profile built from those conversations. It usually lives separately from the chats it came from, which matters a lot in a minute.

Copies made for review. When a conversation gets flagged, reported, or sampled for quality, a copy can be made, and that copy follows a different rule than the original.

What the policies actually say

On deletion, OpenAI is specific. A deleted chat disappears from your account immediately and is scheduled for permanent deletion from its systems within thirty days. The exceptions are stated: content already de-identified and disconnected from your account, and content it has to keep longer for security or legal reasons. Temporary chats are deleted within thirty days even if you never touch them.

On who can read your text, OpenAI lists four situations: investigating abuse or a security incident, supporting you when you contact them, handling legal matters, and improving model performance unless you have opted out. It says access is limited to authorised personnel on a need to know basis, logged, and subject to training requirements.

Google is blunter in a different way. Conversations that have been seen by human reviewers are not deleted when you delete your activity. They are kept for up to three years, disconnected from your Google account. Its own guidance says plainly not to enter confidential information, or anything you would not want a reviewer to see.

Most assistants also offer a mode that stays out of all of this. Temporary chats in ChatGPT, incognito in Claude, private chat in Grok, where the conversation does not enter memory or history and is removed within thirty days.

Read those together and the picture is reasonable but narrower than people assume. Normal chats are deleted on a clear timetable. Reviewed chats are a separate track, and on at least one major platform that track runs for years.

The part almost everyone gets wrong

Deleting a conversation does not necessarily remove what the assistant learned from it.

The memory is a separate store. If a chat produced an entry about your job, your client or your preferences, deleting the chat does not automatically delete that entry. You have to open the memory settings and remove it there, as its own action.

This is the single most useful thing to know about AI memory and privacy, and it follows directly from how memory works: it keeps a summary of you rather than your words, held apart from the conversations that produced it. That mechanism, and what it costs you, is the subject of what AI actually remembers.

The second thing people get wrong is subtler. Searching your history and knowing what an assistant holds about you are not the same operation. You can scroll the sidebar all afternoon and never see the profile, which is why finding is not remembering matters here too.

What to do this week

Read your memory, once, properly. Every major assistant has a settings page listing what it has stored about you. Ten minutes there is more informative than any article, including this one. People routinely find entries they do not remember creating and details that are simply wrong.

Delete the entries you would not want read aloud. Not the chats, the entries. Do both if you like, but the entries are the part that persists.

Use the private mode for the sensitive things. Health, finances, anything about another person who did not agree to be in your chat. Temporary or incognito mode exists for exactly this and costs you nothing except memory of that conversation.

Decide once what never goes in at all. Credentials, government numbers, other people's private details. There is no setting that makes those safe, and a rule you decide in advance is more reliable than judgement at eleven at night.

What to ask of anything that holds your memory

If you use a separate tool to keep memory across assistants, you are adding another place your text lives. That is a reasonable trade, and the questions to ask are simple.

Where is the text kept, on your machine or on their servers, and is it readable by them. Some tools keep everything local by design, which is the strongest answer available and worth preferring for sensitive work.

Can you see every item and delete any of it, one by one. If you cannot inspect it, you cannot correct it, and you will end up not trusting it.

Can you export everything and leave. A memory you cannot take with you is a memory someone else controls. The manual version of that is covered in moving context by hand.

What happens when you delete. Removed everywhere, or hidden from your view. Ask it plainly, and prefer the tool that answers plainly.

Which of these matters most depends on the form the tool takes, since an extension, a hub and a developer API each sit in a different place relative to your data. Which form solves which problem covers that difference.

The uncomfortable summary is that all of this already applies to you. Memory arrived switched on, the conversations are already stored, and a profile has already been built. The only real choice left is whether you look at it.

Frequently Asked Questions

Q1: Does an AI memory tool store my conversations on someone else’s servers?
It depends on the tool, and it is the first thing to ask. Some keep everything in your own browser or on your own machine, and sync only if you ask them to. Others store centrally so the same memory is available on every device. Both are defensible, but they are different promises, and the difference should be stated on the page rather than buried.
Q2: If I delete a chat in ChatGPT, does the memory tool still have it?
Yes, if it captured that conversation before you deleted it. That is the point of a separate memory, and it is also the reason to be able to delete items inside that tool as easily as you delete chats in the assistant. Check that item level deletion exists before you rely on anything.
Q3: Is a local only memory better for privacy?
For sensitive work, keeping the text on your machine is the strongest available answer, because it does not depend on anyone else’s policy. The trade is that a local store is harder to use across devices and easier to lose. What matters is knowing which one you picked.
Q4: What should a memory hub show me about my own data?
Every item, when it was captured, where it came from, and a way to edit or delete it. A hub that shows you a search box but not a list is asking for trust it has not earned. Being able to correct an entry matters as much as being able to remove it, because a wrong note that stays gets quietly reused.
Q5: Does any of this change when tools and agents can read my memory directly?
It raises the stakes, because software is then reading it without you watching. The protections are the same ones: you can see every item, you can correct or remove any of it, and you decide which tools get access. Anything that reads on your behalf should be something you can audit afterwards.
Back to all posts