The Privacy Settings Checklist
10 Toggles to Flip in Every AI App You Use

Published August 9, 2026 · Facts last verified August 9, 2026

This article is general information, not legal advice. For advice about your own situation, consult a qualified lawyer.

Nobody chose their AI privacy settings. They were chosen for you, once, by a product team with a growth target, and you have been living with that decision ever since across five or six different apps.

That is not a conspiracy — it is just how defaults work. A default is a company's preference expressed as your configuration. And in AI apps the gap between the two is unusually wide, because almost every setting on this page has the same shape: leaving it alone makes the product better for the company, and flipping it makes the product safer for you.

The good news is that the list is finite. There are not fifty things to fix. There are ten, they repeat with minor variations across every major assistant, and once you know what each one is actually called you can walk a new app in about ten minutes and know exactly what you have agreed to.

Here is the honest framing before we start, because a checklist that oversells itself is worse than no checklist: flipping every toggle below reduces how much of you a company accumulates. It does not make your conversations private. Your words still travel to a server, still get stored for some period, and can still be read under a legal order. Settings manage exposure. They do not create secrecy. The last section is about the one gap no toggle closes.

How to Use This Checklist

Work through it once per app, per account. Settings are account-level, so you do not need to repeat them on every device — with one exception, number nine, which is a phone thing and genuinely per device.

Two warnings that will save you time. First, menu labels move constantly. Every path below was verified on the date at the top of this article, and some of them will have drifted by the time you read it. Treat them as a map, not a screenshot: if a label is gone, look for the nearest equivalent in the same settings area. Second, a toggle you flipped last year is not necessarily still flipped. New features arrive switched on, and defaults get renegotiated — Anthropic moved consumer Claude to training-unless-you-opt-out in August 2025, and ads arrived in ChatGPT for free users in February 2026. Re-walk this list every few months.

The Ten Toggles at a Glance

#ToggleWhat it controlsUsually lives in
1Model trainingWhether your chats teach the next modelData controls / Privacy
2Memory & cross-chat recallWhether a profile of you accumulatesPersonalization / Memory
3Retention windowHow long history is kept before auto-deleteActivity / Data controls
4Temporary chatPer-conversation opt-out of all of the aboveThe chat window itself
5Ad personalizationWhether chats become targeting signalsAds controls / Privacy
6Share linksLive public URLs of past conversationsPrivacy → Shared chats
7Connectors & integrationsWhat files and accounts the AI can readConnectors / Apps
8Voice & audioRecordings, governed separately from textPrivacy (its own toggle)
9Phone permissionsMic, photo library, locationYour OS, not the app
10Account security2FA, live sessions, export, deletionSecurity / Data controls

1. "Improve the Model" — the Training Toggle

The headline setting, and the one most people have already heard of. On consumer tiers it is typically on unless you turned it off, which means your conversations are candidate material for training the next version.

Where it lives, at the time of writing:

  • ChatGPT: Settings → Data Controls → "Improve the model for everyone."
  • Claude: Settings → Privacy → the "help improve Claude" toggle. This one is a two-for-one: leaving it on also stretches retention from around 30 days to up to five years.
  • Gemini: Settings → "Keep Activity" (the setting formerly called Gemini Apps Activity).
  • Grok: Settings → Data Controls in the app, or Settings → Data on grok.com → "Improve the model."
  • Perplexity: Settings → Preferences → "AI data retention."
  • Microsoft Copilot: profile → Privacy → "Model training on text." Then keep reading, because there is a second one — see number eight.

Two limits worth internalising. It is future-only: nothing already absorbed into a trained model comes back out. And it is not the same as deletion — opting out of training leaves your history exactly where it was. We keep the full per-platform walkthrough, including Meta, LinkedIn, GitHub Copilot, Mistral and DeepSeek, in how to opt out of AI training.

One caveat that deserves more attention than it gets: an opt-out is a promise with carve-outs. Anthropic's privacy policy, effective July 8, 2026, states plainly that even for users who have opted out, inputs and outputs will still be used for model improvement where a conversation is "flagged for safety review" or where the user reported the material themselves. That is a defensible policy. It is also a reminder that "opted out" means "opted out of the ordinary path," not "excluded under all circumstances."

2. Memory and Cross-Chat Recall

If you only flip one thing on this page, consider making it this one rather than training. Training scatters your words into a statistical average of millions of people. Memory does the opposite — it concentrates them into a compact, readable, permanent summary of you, sitting in your account.

Memory is now usually two separate features with two separate switches, and turning off the one you noticed does nothing about the one you did not:

  • ChatGPT: Settings → Personalization → Memory, where "Reference saved memories" (the explicit, editable list) and "Reference chat history" (implicit recall across old conversations) toggle independently.
  • Claude: Settings → Memory → "Search and reference chats" plus "Generate memory from chats," which offers both Pause (keep what exists, stop adding) and Reset (delete the lot). On older accounts the same controls sit under Settings → Capabilities → Preferences. Anthropic's newer memory experience covers the Free, Pro and Max plans, so an account you set up earlier may have gained the feature without you doing anything.
  • Gemini: the Memory / personalization-from-past-chats controls in Gemini settings.

Read your saved memories before you delete them — it is the single most clarifying two minutes in this whole exercise. Most people find at least one entry they never intended to write down. Our longer argument for why this layer deserves the most caution is in AI memory is a privacy time bomb.

3. Your Retention Window

A quieter setting, and the one people are most surprised to learn is adjustable. Separately from training and memory, the provider keeps your history for a period — and you can often shorten it.

Gemini is the clearest illustration. With Keep Activity on, activity auto-deletes after a default of 18 months, which you can shorten to 3 months, lengthen to 36, or disable entirely so nothing expires. Almost nobody chose 18 months; it simply was not changed. Turn Keep Activity off and chats are instead held about 72 hours to serve the request.

Two footnotes that matter more than the number you pick. Deleting activity does not necessarily reach everything: on Gemini, conversations that were sampled for human review are retained up to three years and are not removed when you delete your activity. And on the other side of the ledger, providers can be ordered to preserve data regardless of the window you configured — which is not hypothetical, as the litigation over ChatGPT logs shows.

4. Temporary Chat — as a Habit, Not a Rescue

Every major assistant now has an off-the-record mode, and they are genuinely useful: no history, no memory write, no training.

  • ChatGPT: Temporary Chat — not saved to history, not used for training, deleted from OpenAI's systems within about 30 days.
  • Claude: incognito chats, via the ghost icon at the top right of a new chat outside a project. Available on every plan, and excluded from memory and chat search.
  • Grok: Private Chat, also reached by a ghost icon; kept out of your history and out of training.
  • Gemini: Temporary Chats, kept about 72 hours, excluded from Activity, personalization and training.

The mistake is treating this as an emergency brake. It is a mode you must remember to enter before you type, and the sensitive sentence is usually already three messages into an ordinary conversation by the time it occurs to you. If a category of your usage is sensitive, start that category in temporary mode by default rather than switching mid-thought.

Also note the plain reading of "temporary": not saved to your history. The message still reaches the provider's servers, is still processed there, and still sits in a short retention window. We go through the exact boundaries in the fine print of temporary chat, and the unrelated-but-constantly-confused browser feature in incognito mode won't protect your AI chats.

5. Ad Personalization — the Newest Toggle on This List

This one did not exist when most people last audited their settings, and it is the biggest change of the past year: the assistant business has started monetising conversations directly.

ChatGPT. Ads began appearing for free users in February 2026 and have expanded since. The controls sit under Settings → Ads controls, and there are two, which is the part to notice: one governs ad personalization in general, and a separate one governs whether past chats and memory feed ad targeting. Turn the second off and ads lean on your current thread instead of your accumulated history. Turning personalization off does not remove ads — that is a different question, addressed by paid ad-free tiers. In the EU, OpenAI moved to serving personalized ads only to users who explicitly opt in, from June 8, 2026.

Meta AI. The strictest case, because there is no toggle to find. Since December 16, 2025, interactions with Meta AI across Facebook, Instagram and WhatsApp feed ad targeting, and Meta has not offered an opt-out. The EU, the UK and South Korea are excluded, and Meta says some sensitive categories are held out of targeting. Everywhere else, the only available control is what you type into it.

Gemini. Worth stating plainly so you do not go hunting for a setting that is not there: the standalone Gemini app is not ad-supported. Google publicly disputed a 2026 report that ads were coming to it, while declining to rule them out in future. Ads presently run in Search surfaces such as AI Overviews and AI Mode, not in the Gemini assistant.

The reason this category matters more than its novelty suggests: a training corpus is an anonymised aggregate, whereas an ad profile is designed to be about one identifiable person and to be acted upon commercially. It is the one use of your chat history built to point back at you.

6. Share Links and Published Artifacts

Not a privacy setting so much as an audit, and the one that has produced the most genuinely painful incidents — because "anyone with the link" gets read as "only the person I sent it to," and that is not what it means.

The pattern has now repeated across nearly every vendor. In August 2025 OpenAI withdrew a "make this chat discoverable" option after roughly 4,500 shared conversations turned up in Google, an experiment its security chief described as short-lived. Google removed indexed Bard conversation pages back in September 2023. And over the weekend of July 26, 2026, shared Claude conversations and Artifacts were found in Google results — reportedly including crypto wallet keys, names, addresses and work notes. Anthropic's position was that only conversations users had explicitly chosen to share were affected, which is true and is also precisely the problem: people share a chat to show one person one answer, without registering that they have minted a public URL.

Two things to do. Review your existing share links and revoke the ones you have finished with — on Claude that list is at Settings → Privacy → Shared chats, and every major app has an equivalent. And understand that revoking a link is a separate action from deleting a chat: fixing indexing does not retract a URL, and a live link keeps working for anyone who already has it, or who saved it, long after the conversation left your sidebar.

7. Connectors, Integrations and App Permissions

The fastest-growing surface, and the one where the privacy question stops being about storage and becomes about reach. Connectors let an assistant read your Drive, your mailbox, your repositories, your calendar. Every one you grant widens what a single bad prompt can touch.

This is not theoretical. Research presented at Black Hat 2025 demonstrated a zero-click attack against ChatGPT connectors in which a single poisoned document — malicious instructions hidden in near-invisible text — could cause data from connected storage to be exfiltrated without the user clicking anything. Prompt injection sits at the top of OWASP's Top 10 for LLM applications for exactly this reason: the model cannot reliably tell your instructions from instructions embedded in content it was asked to read.

Google's Personal Intelligence, launched in beta on January 14, 2026, is the credit-where-due example of how this should be presented. It connects Gemini to Gmail, Photos, YouTube and Search history — and it is off by default, opt-in, per-app, revocable at any time under Settings → Personal Intelligence, with Google stating the personalization data is not used to train models. That is the right shape. Your job is still to grant the narrowest scope that makes the feature useful, and to revisit the list, because connectors accumulate: you granted it for one afternoon's task and it has been live ever since.

8. Voice and Audio — the Toggle Nobody Finds

The most commonly missed item on this list, because it hides behind a reasonable assumption: that turning off training covered everything.

It frequently does not. Microsoft Copilot ships two independent training settings — "Model training on text" and "Model training on voice" — and switching off the text one does not stop voice conversations being used. Gemini's Keep Activity, when on, explicitly encompasses audio and Gemini Live recordings alongside typed chats.

So after you flip the training toggle, go back and look for a second one with the word voice in it. Voice input also tends to be the most unguarded way people use these tools — you talk to an assistant the way you talk to a person, in full sentences, with names in them, while walking. It is the input mode most worth having settled.

9. Phone Permissions — the One That Is Per Device

These are not in the app's settings at all; they are in your operating system, which is why they escape every audit. Three are worth a minute each:

  • Microphone: "while using the app," never "always."
  • Photos: grant selected photos rather than the whole library. Full-library access is the default ask and is almost never what the task needs.
  • Location: off unless a feature you actually use breaks without it.

While you are here, remember that an uploaded file carries more than its contents — a photo can arrive complete with GPS coordinates and a device serial number, and a document with its author and revision history. That travels with the upload no matter how your in-app toggles are set; see the metadata in your uploads.

10. Account Security, Export and Deletion

Last, the unglamorous four, which quietly protect more than the nine above if things go wrong. Every chat you have ever had is sitting behind one password.

  • Turn on two-factor authentication. Your AI account has become one of the most revealing accounts you own, and it is often still protected by a reused password.
  • Check active sessions and sign out devices you no longer recognise or use.
  • Export your data once, and read it. Nothing else demonstrates the scale of what has accumulated as effectively. In the EU and UK, GDPR gives you rights of access and erasure you can use here — with real limits, which we cover in the right to erasure and AI chatbots.
  • Delete what you no longer need. Old conversations have no upside and a long tail of risk.

One footnote if the account is your employer's. On business and enterprise tiers, administrators can have access to conversations, uploaded files and memories through compliance tooling — for ChatGPT Enterprise, via its Compliance API. That is a legitimate governance feature, and it means nothing on this checklist makes a work account private from work. More in using AI on a work or shared computer.

The Eleventh Toggle — the One That Does Not Exist

Walk the ten and you have done real work: less accumulation, a shorter retention window, no ad profile built from your chats, no forgotten public links, a smaller blast radius if something goes wrong.

Now notice what every one of those settings has in common. Each is a request made to a company that knows exactly who you are, asking it to please be more restrained with what it learns about you. The account, the email, the payment method and the device stay attached to every message. There is no toggle anywhere in any of these apps labelled stop associating these conversations with me — which is the setting most people actually want.

That absent switch is what Secret Chat AI is built to be. It is an anonymizer and depersonalizer, and the design is deliberately narrow: no profile, no association, no training.

  • No profile of you. Registration takes an email, used only for account access and payment — never to store or associate your prompts with you. No behavioural profile is assembled across your chats.
  • No chat associated with you. Requests reach the leading models through their business APIs under our gateway's credentials, from our servers. Whatever a provider holds under its own terms, the record on that side carries our credentials and server address — not your name, your account or your IP. You use the model as a stranger.
  • Nothing kept under your name. Chat history lives in your own browser, not in a provider account, and a prompt exists on our side only for as long as it takes to fetch your answer — there is no stored chat archive on our servers. Each message gets a Session Privacy Report.
  • No training. Your queries are never used to train models.

And the honest boundary, which matters as much as the claim: Secret Chat AI is an anonymizer, not a content filter. "Anonymously" describes the link, not the words — no account identifier travels with your prompt, but the text is not altered. The provider still reads what you wrote in order to answer it. Write your own name or your case number into a message and it is all still sitting there in the message. Removing identifying details before you send is yours to do; what we remove is who is asking, not what is being asked.

Frequently Asked Questions

  1. If I only have five minutes, which toggles matter most?

    Memory and training, in that order, then ad personalization. Memory concentrates your history into a readable profile attached to your account, training scatters it into a future model, and ad personalization is the one use built to point back at you commercially. The other seven are worth a proper pass later.

  2. Do I have to repeat this on my phone and my laptop?

    The in-app settings are account-level, so once per account is normally enough. The exception is phone permissions — microphone, photo library and location are granted per device in your operating system, so check each phone and tablet separately.

  3. If I turn everything off, are my conversations private?

    No, and this is the important limit. Your messages still travel to the provider, are still processed and stored for some period, can still be reviewed for safety, and can still be compelled by legal process. These settings reduce how much a company accumulates about you over time; they do not make a conversation secret.

  4. Does opting out of training remove data already used?

    No. On every major platform the opt-out is future-only — it stops new data being used and does not pull anything back out of a model that has already been trained. Deleting your history is a separate action, and it is not retroactive over training either.

  5. Why do I need to check these settings again if I already did it?

    Because defaults get renegotiated and new features arrive switched on. Consumer Claude moved to training-unless-you-opt-out in August 2025, Meta AI began feeding ad targeting in December 2025, and ads reached free ChatGPT users in February 2026. A pass every few months is the realistic cadence.

  6. Is there a way to avoid this maintenance entirely?

    Not within the apps themselves — every toggle asks a company that knows who you are to be more restrained. The alternative is to not be identifiable in the first place. Secret Chat AI reaches the top models anonymously through their business APIs, with no profile, an email used only for access and payment, history kept in your browser, and no training on your queries. It is an anonymizer rather than a content filter, so keep identifiers out of what you write.

Conclusion

Ten toggles, ten minutes per app, and a re-check every few months. That is the whole job, and it is worth doing: the difference between a default account and a configured one is the difference between a company holding a detailed, indefinite, commercially useful record of your thinking and holding a thin, short-lived one.

Just be clear about what you have bought. A configured account is a quieter account, not an anonymous one. Every setting here is a limit you asked a company to place on what it learns about a person it can identify — and the identification itself is never on the menu. If that is the part you care about, the fix is not a toggle: it is reaching the models without your identity attached in the first place.

Sources