AI Memory Features Are a Privacy Time Bomb
What ChatGPT and Gemini Remember About You

Published July 22, 2026 · Updated August 17, 2026 · Facts last verified August 17, 2026

For the first two years of the chatbot era, every conversation started from zero. That was annoying, and it was also a privacy property: a chat could only ever contain what you put in it. Memory removed the annoyance and, with it, the property.

Today ChatGPT and Gemini both carry knowledge of you from one conversation into the next — by design, quietly, and in Gemini's case switched on for you rather than by you. The result is something no chat log ever was: a compact, structured, always-current profile of a person, assembled by the person themselves, one offhand disclosure at a time. Here is what is actually stored, and the five specific ways it goes wrong.

What "Memory" Actually Means in 2026

The word covers three separate mechanisms, and the differences matter more than the marketing suggests. The first of them changed shape in mid-2026, so it is worth being current rather than repeating the 2024 explanation that is still everywhere.

A synthesised profile. ChatGPT used to keep a hand-curated list of discrete facts — your job, your kids' names, your dietary restrictions — that you could read line by line. On 4 June 2026 OpenAI began rolling out a new memory architecture that works the other way round: rather than saving facts as you designate them, it synthesises in the background across years of past conversations and keeps the result current, including revising things as they age (a note about a trip you are planning becomes a note about a trip you took). What you now review is a memory summary — a page showing what the assistant has pieced together, with controls to correct it and to say which topics it should raise unprompted. Settings → Personalization → Memory is where it lives. This rolled out first to Plus and Pro users in the US, so what a given account shows depends on where and when it arrived.

Implicit history reference. Since 10 April 2025, ChatGPT can draw on your past conversations wholesale rather than only a curated list. The summary above makes this partly inspectable, which is a real improvement on the position a year ago — but OpenAI is explicit that what you see may not be everything, and a synthesis is not an audit log. Google's equivalent is personal context: Gemini learning key details and preferences from earlier conversations so you do not repeat yourself.

Connected-account context. The newest and largest layer. Google launched Personal Intelligence on 14 January 2026, letting Gemini reason across your Gmail, Photos, Search and YouTube history; it was announced for free US users on 27 March 2026. Connecting those apps is optional and off until you enable it — but once enabled, "what the AI knows about you" stops being a summary of your chats and becomes a summary of your life.

1. The Defaults Decide, Not You

Google's own announcement is unambiguous: the setting that lets Gemini learn from your past conversations "is on by default to help Gemini give you more relevant responses," with the ability to turn it off in Settings → Personal context. Eligibility conditions apply (18+, a personal rather than work or school Google account, Keep Activity enabled), but within them, the profile builds itself unless you intervene.

ChatGPT's rollout was staggered differently — when reference-to-past-chats first shipped in April 2025 it excluded the EEA, the UK, Switzerland, Norway, Iceland and Liechtenstein, and it reached those regions about a month later, on 8 May 2025, as an opt-in. That sequencing is worth noting for what it is: a difference in default, arrived at in the region with the strictest data-protection regime, rather than any published regulatory finding.

The practical point is the one that governs every privacy setting ever shipped: defaults decide outcomes, because a setting that requires finding a settings page is a setting most people never touch. If you have never opened your own memory page, you are the ordinary case, not the careless one.

2. A Dossier Is Easier to Read Than a Transcript

This is the failure mode people miss, and it is the most important one.

Three thousand chat messages are a haystack. Anyone who wants to know something about you — an opposing lawyer in discovery, an investigator with a court order, an attacker inside a breached account, an employer exporting a departing worker's workspace — has to read them, and mostly will not bother. A memory profile is the needle, pre-extracted. It is short, declarative, written in the third person, and organised exactly as a dossier would be: who this person is, what they do, what they worry about, what they are working on.

We have already seen AI chat logs pulled into litigation — a US court ordered OpenAI to preserve and hand over vast quantities of ChatGPT logs, and chat records have surfaced in divorce and employment cases. Nothing about a memory profile is exempt from the same processes. What changes is the effort required to use it, and effort is the only thing that has been protecting most people so far.

3. Deleting Is Not What You Think It Is

Users reasonably assume that deleting a conversation deletes what was learned from it. It does not. The two stores are separate: clearing your chats does not clear your memories, and deleting a memory does not clear your chats. Delete the conversation where you mentioned your diagnosis and the memory extracted from it stays exactly where it was.

Turning the feature off is not deletion either. Disabling memory stops new entries; the existing ones sit there, ready to resume being used the moment the toggle goes back on. And deletion itself is not instantaneous: OpenAI's documentation describes retaining deleted saved memories for up to 30 days for safety and debugging, and deleted chats are scheduled for permanent removal within 30 days rather than erased on the click.

Then there is the harder half. The 2026 memory summary is editable, which genuinely improves on the position a year ago — you can read what the assistant has concluded and correct it. But correcting a summary is not the same as removing the material it was synthesised from: OpenAI's own guidance is that removing something entirely means clearing it from every source it appears in — past chats, archived chats, uploaded files, the memory entries and any connected apps — and a summary that regenerates from sources you left in place will tend to reconstruct what you edited out. That is a chore few people finish, which is the practical reason memory accumulates.

4. Memory Is a Persistent Attack Surface

Before memory, a prompt-injection attack lasted one conversation. With memory, it can be made to last indefinitely — because the attacker's instructions get stored in the same place your preferences do.

Security researcher Johann Rehberger demonstrated both halves of this. In September 2024 he showed SpAIware: an injection delivered through untrusted content that wrote a persistent instruction into ChatGPT's memory, causing every subsequent conversation — indefinitely, across sessions — to be exfiltrated to an attacker. OpenAI patched that specific demonstration; the class of attack was not eliminated.

In February 2025 he showed the inverse against Gemini: using indirect injection hidden in an uploaded document plus delayed tool invocation — the malicious instruction lies dormant until the user says something innocuous like "yes" or "sure", at which point it writes false facts into long-term memory. His demonstration made Gemini durably believe things about its user that were simply untrue. Google assessed the overall risk as low likelihood and low impact, and no fix was confirmed when the research was published — which is itself instructive, since memory poisoning does not need to steal anything to cause harm. Corrupting what the assistant believes about you is enough, and it persists.

The structural point: any writable long-term store that an attacker can reach through content you merely read converts a one-shot exploit into a foothold.

5. Contexts Bleed Into Each Other

Memory has no sense of occasion. The same profile that helpfully recalls your writing style also recalls the health question you asked at 2 a.m., and it applies both in whatever conversation comes next — including the one you are screen-sharing in a meeting, or the one your assistant runs on your account, or the one open on the family iPad.

The everyday version of this is mundane and constant: a personal disclosure resurfacing inside a work task, an assistant volunteering context you would never have typed into that thread. There is no boundary in the product between "things I told it as a private person" and "things it may bring up while my screen is on a projector." Anyone who has watched an AI helpfully mention something you had forgotten telling it understands the discomfort immediately.

6. Memory Now Feeds Advertising

On 9 February 2026 OpenAI began testing ads in ChatGPT in the US, followed by pilots in Canada, Australia and New Zealand, and on 11 August 2026 a launch in the UK, Mexico, Brazil, Japan and South Korea. Two scoping details matter before the alarm: ads are shown to signed-in adult users on the Free and Go tiers only — Plus, Pro, Business, Enterprise and Edu carry none — and they are labelled as sponsored and kept separate from the answer.

The relevant detail for this article is how they are targeted: with ad personalization enabled, your past chats and memory can contribute to which ads you see, alongside your ad-interaction history. Switch personalization off and ads fall back to the current conversation plus basic context such as language and general location. OpenAI states that advertisers do not receive your chats, chat history, memories or personal details, only aggregate performance data.

Take that at face value and the structural change still stands. The profile that was introduced to make answers better is now also an input to a commercial targeting system. That is the classic arc of every free consumer product, and it is worth noticing the moment it happens rather than three years later: the thing you told a chatbot about your health, your finances or your family is now, at minimum, in the same system that decides what to sell you.

What To Actually Do

  • Read your own profile today. ChatGPT: Settings → Personalization → Memory, where the memory summary is. Gemini: Settings → Personal context, where the Memory toggle sits. This takes two minutes and is usually the moment the abstract becomes concrete.
  • Decide deliberately, then delete rather than disable. If you want memory off, delete the stored entries as well — the toggle alone leaves them intact.
  • Use the ephemeral modes for anything sensitive — but know their limits. Gemini's Temporary Chats are excluded from personalization and training, and are still kept for up to 72 hours; ChatGPT's Temporary Chats neither use nor create memories, and are deleted from OpenAI's systems within 30 days. Ephemeral means "not remembered", not "not stored" (we covered this in detail in the fine print nobody reads).
  • Keep contexts on separate accounts. Personal and professional use in one profile guarantees bleed. Two accounts is a crude fix that works.
  • Be sparing with connected accounts. Letting an assistant read your inbox and photo library is a different order of disclosure from letting it read your chats. It is opt-in for a reason.
  • Redact before you send. With connected apps switched off, memory reflects what you put in front of it — and what you type is the one input no vendor settings page governs. Connect an inbox or a photo library and that stops being true, which is the strongest argument for leaving those disconnected.

How Secret Chat AI Fits — Including What We Don't Do

Secret Chat AI takes the opposite architectural position, and on this topic it is worth being precise about both what that gives you and what it costs you.

No profile exists to leak. We do not build a profile of you, and no conversation is ever associated with you. Your prompt reaches the model through our gateway, so the provider receives the gateway's request rather than an account belonging to you — there is no per-user memory store on their side to accumulate, poison, subpoena, or target ads from. Registration takes an email, but it is used only for account access and payment; your queries are never stored against it. Retention may still apply at the provider — but your query arrives anonymized, not linked to your identity. You use the model as a stranger, every time.

Your history stays on your machine. Chats, threads and files live in your own browser's local storage (IndexedDB and OPFS). A prompt does pass through the gateway in order to be answered; that request record is deleted the moment your browser collects the reply, and an hourly sweep clears any orphaned by a closed tab. There is no server-side chat archive to breach or produce in discovery.

What we do store, plainly. A random anonymous device token in your browser (for free-tier limits and marketing attribution — clearable at any time, never sent to the model providers), plus basic visit data against it: referring site, landing page, UTM parameters, user-agent string and a two-letter country code. Never an IP address, never linked to your conversations.

The honest trade-off. You do not get cross-chat memory. If you want the assistant to know your writing style or your project context, you paste it in — a persistent profile is exactly the thing we are declining to build. For continuity within your own work you can keep global instructions and per-project context, which live under your control rather than as a vendor-side dossier.

And what we cannot do. Secret Chat removes you from your queries — it does not remove the data from your messages. Your text reaches the provider verbatim, anonymously. Redacting identifying details before sending remains your responsibility, as our Terms of Service and Disclaimers set out.

Frequently Asked Questions

  1. Does deleting a ChatGPT conversation delete what it remembered from it?

    No. Chat history and memory are stored separately: deleting a chat does not remove memories saved from it, and deleting a memory does not remove the chat. Since June 2026 the memory summary is editable, but editing it is not the same as removing the underlying material: to remove something entirely you have to clear it from past chats, archived chats, uploaded files, the memory entries and any connected apps, or the summary can simply be rebuilt from what you left behind.

  2. Is Gemini's memory on by default?

    Yes, for eligible accounts. Google states the setting that lets Gemini learn from your past conversations is on by default, and can be turned off in Settings → Personal context. Eligibility requires being 18+, using a personal Google account, and having Keep Activity enabled. The separate Personal Intelligence feature, which connects Gmail and Photos, is opt-in and off until you enable it.

  3. Can AI memory be hacked?

    It has been demonstrated twice by security researcher Johann Rehberger. The 2024 SpAIware attack wrote a persistent exfiltration instruction into ChatGPT's memory via prompt injection, and OpenAI patched that demonstration. The February 2025 Gemini attack used a poisoned document plus delayed tool invocation to plant false long-term memories; Google assessed it as low likelihood and low impact, and no fix was confirmed at the time of disclosure. Either way, any writable long-term memory turns a one-off injection into a lasting foothold.

  4. Does ChatGPT use my memory to target ads?

    It can, on the tiers that carry ads. OpenAI began testing ads in the US in February 2026 and extended them to the UK, Mexico, Brazil, Japan and South Korea on 11 August 2026; they appear for signed-in adults on the Free and Go tiers only, not on Plus, Pro, Business, Enterprise or Edu. With ad personalization enabled, past chats and memory can contribute to ad selection; with it disabled, ads rely on the current conversation plus basic context such as language and general location. OpenAI says advertisers receive only aggregate performance data, not your chats or memories.

  5. Does Secret Chat AI remember me between chats?

    No, and that is deliberate. We build no profile and never associate a conversation with you; your queries reach the models anonymously, so there is no per-user memory store on either side. Your chat history stays in your own browser, and continuity comes from global instructions and project context you control — not a vendor-held dossier.

Conclusion

Memory is not a bad feature. It is a genuinely useful one, sold on convenience and delivered on it — which is precisely why it spread so fast and why so few people have read what it holds. The problem is that it quietly converts a pile of conversations into a profile: something short enough to be read by anyone who gains access, durable enough to survive the deletion of the chats that produced it, writable enough to be attacked, and now wired into an advertising system. None of that was true of a chatbot that forgot you at the end of every session.

Go and read your own memory list this week — it is the single most informative two minutes available on this topic. Then decide whether you want a machine keeping a running file on you at all. Secret Chat AI is built on the assumption that you do not.

Related reading: what Google actually keeps from Gemini chats · does ChatGPT store your conversations · how chatbots fingerprint you without an account · how to opt out of AI training

Sources