AI Memory Features Are a Privacy Time Bomb
What ChatGPT and Gemini Remember About You

Published July 22, 2026 · Facts last verified July 22, 2026

For the first two years of the chatbot era, every conversation started from zero. That was annoying, and it was also a privacy property: a chat could only ever contain what you put in it. Memory removed the annoyance and, with it, the property.

Today ChatGPT and Gemini both carry knowledge of you from one conversation into the next — by design, quietly, and in Gemini's case switched on for you rather than by you. The result is something no chat log ever was: a compact, structured, always-current profile of a person, assembled by the person themselves, one offhand disclosure at a time. Here is what is actually stored, and the five specific ways it goes wrong.

What "Memory" Actually Means in 2026

The word covers three separate mechanisms, and the differences matter more than the marketing suggests.

Explicit saved memories. ChatGPT keeps a list of discrete facts about you — your job, your kids' names, your dietary restrictions, the tone you prefer. You can open Settings → Personalization → Manage memories and read the list. Most people find it longer, and more personal, than they expected.

Implicit history reference. Since April 2025, ChatGPT can also draw on your past conversations wholesale, not just the curated fact list — OpenAI describes it as insights gathered from past chats to make future ones more relevant. This layer has no list to inspect. You cannot audit what it concluded about you, because it was never written down as a sentence. Google's equivalent is personal context: Gemini learning key details and preferences from your earlier conversations so you do not repeat yourself.

Connected-account context. The newest and largest layer. Google launched Personal Intelligence in January 2026, letting Gemini reason across your Gmail, Photos, Search and YouTube history; it reached free US users in March 2026. This one is opt-in and off until you enable it — but once enabled, "what the AI knows about you" stops being a summary of your chats and becomes a summary of your life.

1. The Defaults Decide, Not You

Google's own announcement is unambiguous: the setting that lets Gemini learn from your past conversations "is on by default to help Gemini give you more relevant responses," with the ability to turn it off in Settings → Personal context. Eligibility conditions apply (18+, a personal rather than work or school Google account, Keep Activity enabled), but within them, the profile builds itself unless you intervene.

ChatGPT's rollout was staggered differently — when reference-to-past-chats first shipped in 2025 it deliberately excluded the EEA, the UK, Switzerland, Norway, Iceland and Liechtenstein while regulatory review ran, which tells you how the feature was assessed under European data-protection law.

The practical point is the same one that governs every privacy setting ever shipped: a feature that is on by default is used by the overwhelming majority of people, and a feature that requires reading a settings page is not. Most users of both products have a profile they have never looked at.

2. A Dossier Is Easier to Read Than a Transcript

This is the failure mode people miss, and it is the most important one.

Three thousand chat messages are a haystack. Anyone who wants to know something about you — an opposing lawyer in discovery, an investigator with a court order, an attacker inside a breached account, an employer exporting a departing worker's workspace — has to read them, and mostly will not bother. A memory profile is the needle, pre-extracted. It is short, declarative, written in the third person, and organised exactly as a dossier would be: who this person is, what they do, what they worry about, what they are working on.

We have already seen AI chat logs pulled into litigation — a US court ordered OpenAI to preserve and hand over vast quantities of ChatGPT logs, and chat records have surfaced in divorce and employment cases. Nothing about a memory profile is exempt from the same processes. What changes is the effort required to use it, and effort is the only thing that has been protecting most people so far.

3. Deleting Is Not What You Think It Is

Users reasonably assume that deleting a conversation deletes what was learned from it. It does not. The two stores are separate: clearing your chats does not clear your memories, and deleting a memory does not clear your chats. Delete the conversation where you mentioned your diagnosis and the memory extracted from it stays exactly where it was.

Turning the feature off is not deletion either. Disabling memory stops new entries; the existing ones sit there, ready to resume being used the moment the toggle goes back on. And deletion itself is not instantaneous: OpenAI's documentation describes retaining deleted saved memories for up to 30 days for safety and debugging, and deleted chats are scheduled for permanent removal within 30 days rather than erased on the click.

Then there is the layer with no delete button at all. You can prune a list of saved memories; you cannot prune an inference a model drew from the shape of your conversations. To genuinely remove something the system knows about you, you have to find every place it appears — past chats, archived chats, uploaded files, the memory list, any connected apps — and remove it from each. In practice almost nobody completes that.

4. Memory Is a Persistent Attack Surface

Before memory, a prompt-injection attack lasted one conversation. With memory, it can be made to last indefinitely — because the attacker's instructions get stored in the same place your preferences do.

Security researcher Johann Rehberger demonstrated both halves of this. In September 2024 he showed SpAIware: an injection delivered through untrusted content that wrote a persistent instruction into ChatGPT's memory, causing every subsequent conversation — indefinitely, across sessions — to be exfiltrated to an attacker. It was reported and patched; the class of attack was not.

In February 2025 he showed the inverse against Gemini: using indirect injection hidden in an uploaded document plus delayed tool invocation — the malicious instruction lies dormant until the user says something innocuous like "yes" or "sure", at which point it writes false facts into long-term memory. His demonstration made Gemini durably believe things about its user that were simply untrue. Memory poisoning does not need to steal anything to cause harm; corrupting what the assistant believes about you is enough, and it persists.

The structural point: any writable long-term store that an attacker can reach through content you merely read converts a one-shot exploit into a foothold.

5. Contexts Bleed Into Each Other

Memory has no sense of occasion. The same profile that helpfully recalls your writing style also recalls the health question you asked at 2 a.m., and it applies both in whatever conversation comes next — including the one you are screen-sharing in a meeting, or the one your assistant runs on your account, or the one open on the family iPad.

The everyday version of this is mundane and constant: a personal disclosure resurfacing inside a work task, an assistant volunteering context you would never have typed into that thread. There is no boundary in the product between "things I told it as a private person" and "things it may bring up while my screen is on a projector." Anyone who has watched an AI helpfully mention something you had forgotten telling it understands the discomfort immediately.

6. Memory Now Feeds Advertising

In February 2026 OpenAI began testing ads in ChatGPT in the US, expanding to further countries through the year. The relevant detail for this article is how they are targeted: with ad personalization enabled, your past chats and memory can contribute to which ads you see, alongside your ad-interaction history. Switch personalization off and ads fall back to the current conversation's topic. OpenAI states that advertisers do not receive your chats, chat history, memories or personal details, only aggregate performance data.

Take that at face value and the structural change still stands. The profile that was introduced to make answers better is now also an input to a commercial targeting system. That is the classic arc of every free consumer product, and it is worth noticing the moment it happens rather than three years later: the thing you told a chatbot about your health, your finances or your family is now, at minimum, in the same system that decides what to sell you.

What To Actually Do

  • Read your own profile today. ChatGPT: Settings → Personalization → Manage memories. Gemini: Settings → Personal context. This takes two minutes and is usually the moment the abstract becomes concrete.
  • Decide deliberately, then delete rather than disable. If you want memory off, delete the stored entries as well — the toggle alone leaves them intact.
  • Use the ephemeral modes for anything sensitive — but know their limits. Gemini's Temporary Chats are excluded from personalization and training, and are still kept for up to 72 hours; ChatGPT's temporary mode neither reads nor writes memory, and is also retained for a period. Ephemeral means "not remembered", not "not stored" (we covered this in detail in the fine print nobody reads).
  • Keep contexts on separate accounts. Personal and professional use in one profile guarantees bleed. Two accounts is a crude fix that works.
  • Be sparing with connected accounts. Letting an assistant read your inbox and photo library is a different order of disclosure from letting it read your chats. It is opt-in for a reason.
  • Redact before you send. Memory only ever contains what you typed. This is the one control that never depends on a vendor's settings page.

How Secret Chat AI Fits — Including What We Don't Do

Secret Chat AI takes the opposite architectural position, and on this topic it is worth being precise about both what that gives you and what it costs you.

No profile exists to leak. We do not build a profile of you, and no conversation is ever associated with you. Your prompt reaches the model through our gateway, so the provider receives the gateway's request rather than an account belonging to you — there is no per-user memory store on their side to accumulate, poison, subpoena, or target ads from. Registration takes an email, but it is used only for account access and payment; your queries are never stored against it. Retention may still apply at the provider — but your query arrives anonymized, not linked to your identity. You use the model as a stranger, every time.

Your history stays on your machine. Chats, threads and files live in your own browser's local storage (IndexedDB and OPFS). A prompt does pass through the gateway in order to be answered; that request record is deleted the moment your browser collects the reply, and an hourly sweep clears any orphaned by a closed tab. There is no server-side chat archive to breach or produce in discovery.

What we do store, plainly. A random anonymous device token in your browser (for free-tier limits and marketing attribution — clearable at any time, never sent to the model providers), plus basic visit data against it: referring site, landing page, UTM parameters, user-agent string and a two-letter country code. Never an IP address, never linked to your conversations.

The honest trade-off. You do not get cross-chat memory. If you want the assistant to know your writing style or your project context, you paste it in — a persistent profile is exactly the thing we are declining to build. For continuity within your own work you can keep global instructions and per-project context, which live under your control rather than as a vendor-side dossier.

And what we cannot do. Secret Chat removes you from your queries — it does not remove the data from your messages. Your text reaches the provider verbatim, anonymously. Redacting identifying details before sending remains your responsibility, as our Terms of Service and Disclaimers set out.

Frequently Asked Questions

  1. Does deleting a ChatGPT conversation delete what it remembered from it?

    No. Chat history and memory are stored separately: deleting a chat does not remove memories saved from it, and deleting a memory does not remove the chat. To remove something entirely you have to clear it from past chats, archived chats, uploaded files, the memory list and any connected apps.

  2. Is Gemini's memory on by default?

    Yes, for eligible accounts. Google states the setting that lets Gemini learn from your past conversations is on by default, and can be turned off in Settings → Personal context. Eligibility requires being 18+, using a personal Google account, and having Keep Activity enabled. The separate Personal Intelligence feature, which connects Gmail and Photos, is opt-in and off until you enable it.

  3. Can AI memory be hacked?

    It has been demonstrated twice by security researcher Johann Rehberger. The 2024 SpAIware attack wrote a persistent exfiltration instruction into ChatGPT's memory via prompt injection; the 2025 Gemini attack used a poisoned document plus delayed tool invocation to plant false long-term memories. Both were reported and fixed, but any writable long-term memory turns a one-off injection into a lasting foothold.

  4. Does ChatGPT use my memory to target ads?

    It can. OpenAI began testing ads in ChatGPT in February 2026; with ad personalization enabled, past chats and memory can contribute to ad selection, and with it disabled ads rely mainly on the current conversation. OpenAI says advertisers receive only aggregate performance data, not your chats or memories.

  5. Does Secret Chat AI remember me between chats?

    No, and that is deliberate. We build no profile and never associate a conversation with you; your queries reach the models anonymously, so there is no per-user memory store on either side. Your chat history stays in your own browser, and continuity comes from global instructions and project context you control — not a vendor-held dossier.

Conclusion

Memory is not a bad feature. It is a genuinely useful one, sold on convenience and delivered on it — which is precisely why it spread so fast and why so few people have read what it holds. The problem is that it quietly converts a pile of conversations into a profile: something short enough to be read by anyone who gains access, durable enough to survive the deletion of the chats that produced it, writable enough to be attacked, and now wired into an advertising system. None of that was true of a chatbot that forgot you at the end of every session.

Go and read your own memory list this week — it is the single most informative two minutes available on this topic. Then decide whether you want a machine keeping a running file on you at all. Secret Chat AI is built on the assumption that you do not.

Related reading: what Google actually keeps from Gemini chats · does ChatGPT store your conversations · how chatbots fingerprint you without an account · how to opt out of AI training

Sources