AI chatbots are becoming trusted spaces for conversations about health, finances, relationships and personal fears. That makes the data they process unusually sensitive—and creates a privacy risk when services retain chats, use them to improve models or disclose them through legal processes.
Johns Hopkins computer science professor Matt Green says repeated conversations can form a detailed profile of a user. Cryptographer and software developer Moxie Marlinspike, who created Signal in 2014, argues that AI interactions now represent a larger privacy weakness than text messaging once did.
The strongest contractual protection
For most people using ChatGPT, Claude or Gemini, the safest assumption is that records could be accessed by the service provider, business partners, contractors, law enforcement or a party obtaining them through a civil lawsuit.
A major exception is 0 data retention (ZDR), a contractual arrangement that generally requires a provider to delete interactions after processing. OpenAI, Anthropic and Google offer ZDR for enterprise versions, but these plans are aimed at paid business and developer customers rather than typical individual users.
ZDR does not remove every privacy concern. Anthropic excludes its most advanced “Mythos-class” models, including Fable 5.1, from the policy because of concerns about misuse and autonomous behaviour. OpenAI's Private Safety Processing can examine activity before deletion and flag suspected abuse for a customer organisation. In some cases, OpenAI staff may be alerted without seeing the conversation content.
Google also says some Gemini prompts can be logged for abuse monitoring under ZDR. The records do not include a user's Google ID or IP address, but identifying details written into a prompt may still point to a particular person.
Policies are not technical barriers
Consumer services often rely on promises not to record chats rather than systems that make recording impossible. Proton's Lumo, for example, describes its conversations as private but does not provide the same end-to-end encryption guarantees associated with Proton Mail or Proton Drive. Its protection depends on the company following its policy.
Duck.ai and Venice.ai also promote no-log approaches. Both can act as proxies, forwarding requests to other services such as Claude or ChatGPT. This can limit what the underlying model knows about the user, but the text itself may still reveal identity. A request about nearby coffee shops, for example, can disclose where someone lives.
Duck.ai allows users to select a third-party model. Venice.ai may route requests to different services or process some queries on its own infrastructure, and its public explanations do not always make the selected model clear.
Cryptography and local processing
Technical restrictions offer stronger protection than a policy alone. AI systems still generally need unencrypted prompts to process requests, so their conversations cannot yet receive the same end-to-end encryption model used by Signal or WhatsApp messaging.
Some services instead use a trusted execution environment (TEE). This approach processes prompts inside isolated hardware and uses cryptographic checks to demonstrate that other parts of the server cannot access the protected data.
Confer, launched by Marlinspike, uses Nvidia-based TEE technology, passkey authentication and open-source code. Meta uses a TEE for an Incognito option in WhatsApp's “Ask Meta AI or Search” feature. Meta says the system is designed not to retain a record, but it is not the same as WhatsApp's end-to-end encrypted messaging.
Meta's Muse AI agent does not yet have a TEE-based privacy system. It runs in a separate cloud virtual machine, and Meta says it is developing Muse Confidential VM to cryptographically and verifiably prevent access to user data.
Apple uses Private Cloud Compute (PCC) for server-processed Apple Intelligence and Siri requests. A user's device checks that the server is running an unaltered version of Apple's code, which is designed to keep no logs and isolate the data. Simple requests can instead be handled on the device, where the information does not leave the phone, computer or smartwatch. Requests sent to ChatGPT or another third-party service do not receive the same PCC protection.
Local tools such as Ollama, LMStudio and LocalAI keep data on the user's computer. That improves privacy because the information does not leave the device, but Green warns that these systems can be less capable and more likely to produce incorrect answers than cloud-based models.
Privacy comes with trade-offs
Stronger privacy can mean higher prices. Confer provides roughly 20 to 25 free queries a day before charging $34.99 a month for its cheapest tier. Claude and ChatGPT charge $20 a month for their cheapest paid plans.
Marlinspike says Confer's higher price reflects the cost of operating an AI service without relying on future data monetisation or advertising subsidies. Green says the wider business model for private AI remains uncertain because frontier systems require substantial energy and hardware.
Users therefore face several choices: trust a provider's policy, pay for a contractual guarantee, rely on cryptographic safeguards or accept the lower capability of a local model. No single option combines every privacy, performance and cost advantage.
Conclusion
Private AI is possible, but the level of protection depends on the service's contract, technical design and handling of third-party requests. Stronger safeguards may require enterprise access, specialised infrastructure, local processing or a higher monthly price.
Frequently Asked Questions
Q. Are ChatGPT, Claude and Gemini private by default?
The article advises assuming little real privacy if someone with a legal route seeks access to conversation records. Their enterprise versions offer 0 data retention under specified conditions.
Q. What is 0 data retention?
0 data retention is a contractual policy that generally requires a provider to delete chatbot interactions after processing. OpenAI, Anthropic and Google offer it for enterprise versions.
Q. Does 0 data retention prevent every form of monitoring?
No. Anthropic excludes some advanced models, while OpenAI and Google describe limited abuse-monitoring practices that can involve activity or prompts.
Q. Are Duck.ai and Venice.ai fully private?
They promote no-log protections, but they can relay requests to other AI services. The content of a chat may still reveal identifying information even when metadata is removed.
Q. What is a trusted execution environment?
A TEE processes AI prompts inside isolated hardware and uses cryptographic checks to restrict access by the rest of the server.
Q. Does Apple Private Cloud Compute protect third-party AI requests?
No. Requests sent through Apple Intelligence or Siri to ChatGPT or another third-party service do not receive the same PCC protection.
Q. Are local AI tools more private?
They can keep data on the user's computer because the information does not leave the device. Their performance may be weaker than that of cloud-based models.
Q. How much does Confer cost?
Confer offers roughly 20 to 25 free queries a day, then charges $34.99 a month for its cheapest tier. Claude and ChatGPT charge $20 for their cheapest paid plans.














