
Seven of nine AI chatbots train on your chats without asking
We opened every AI privacy statistic below at the company, regulator or research group that published it. The date column shows when a survey ran or the data was gathered, not when someone repeated it.
| Statistic | Figure | Source | Date |
|---|---|---|---|
| Major consumer AI chatbots that train on your chats without asking | 7 of 9 | Whizi Research, from each vendor's own policy pages | 7 Oct 2026 |
| US adults who think AI will make their personal information less secure | 71% | Pew Research Center | Feb 2026 |
| Adults who trust companies using AI to protect their personal data | 47% across 32 countries, 34% in the US | Ipsos AI Monitor 2026 | Mar to Apr 2026 |
| Generative AI users who enter personal or confidential information | 30% | Cisco Consumer Privacy Survey | Jun 2024 |
| Employees using AI at work who have uploaded company information into public AI tools | 48% | KPMG and the University of Melbourne | Nov 2024 to Jan 2025 |
| Data movements into AI tools that involve sensitive data | 39.7% | Cyberhaven, a vendor study | 2025 |
| Organizations whose privacy programs grew because of AI | 90% | Cisco 2026 Data and Privacy Benchmark | Sep 2025 |
| Breached organizations that had a breach targeting AI models or apps | more than 20% | IBM Cost of a Data Breach 2026 | Mar 2025 to Feb 2026 |
| AI incidents logged by the AI Incident Database | 362, up from 233 in 2024 | Stanford AI Index 2026 | 2025 |
| OECD AI incidents and hazards tagged privacy and data governance | about 7,577 of 18,123 (41.8%) | OECD AI Incidents Monitor, Whizi share | 7 Oct 2026 |
| Italy's GDPR fine on OpenAI over ChatGPT | €15 million, annulled by a Rome court | Garante | Dec 2024, annulled Mar 2026 |
Each row has its own base. Pew asks US adults, Ipsos asks people in 32 countries and KPMG asks employees. Cyberhaven measures what its customers' staff move into AI tools, and IBM studies only organizations that had a breach. The incident counts cover every kind of AI harm, privacy or not.
Which AI chatbots use your conversations for training?
Six of the nine train on consumer chats until you switch it off: ChatGPT, Gemini, Perplexity, Mistral's Vibe, Grok and DeepSeek. Meta AI trains on chats too, and it offers no settings switch. Anthropic makes every Claude user choose. Microsoft says its updated Copilot app doesn't use chats to train foundation models. We read each company's own help and policy pages on 7 October 2026.
| Chatbot | Trains on your chats? | How to stop it | How long chats are kept |
|---|---|---|---|
| ChatGPT (OpenAI) | Yes, unless you opt out | Settings, Data controls, "Improve the model for everyone" | Until you delete them, then gone within 30 days |
| Gemini (Google) | Yes, Keep Activity is on by default for adults | Turn off Keep Activity | Deleted after 18 months by default |
| Perplexity | Yes, "AI Data Retention is enabled by default" | Preferences, "AI data retention" | While your account is active |
| Vibe (Mistral, formerly Le Chat) | Yes, users "are not opted out by default" | The training toggle in settings | Until you delete the chat or the account |
| Grok (SpaceXAI) | Yes, unless you opt out, with no default stated | "Improve the model" in Grok, plus a separate setting on X | "For as long as you wish" |
| DeepSeek | Yes, unless you opt out | "Improve the model for everyone" in settings | As long as you have an account, stored in China |
| Meta AI | Yes, interactions "will also be used to train" | No switch; EU users got an objection form | No period in Meta's posts; chats shape ads since 16 Dec 2025 |
| Claude (Anthropic) | Only if you allow it, and everyone must choose | Settings, Privacy, "Help improve our AI models" | Up to 5 years if training is on; deleted chats gone within 30 days |
| Copilot (Microsoft) | Not for foundation models, in the app updated 18 Aug 2026 | Nothing to switch off | No period on the updated app's pages |
We had to make a call on Grok. SpaceXAI, the company behind Grok, says it "may use your content" for training and that you control it, but it names no default. X's help page calls its own Grok setting an opt-out. DeepSeek's privacy policy lists training as a purpose. Its terms of use, last updated 27 March 2026, say you "can opt out by turning off" a setting called "Improve the model for everyone".
Meta told Europeans in April 2025 that interactions with Meta AI "will also be used to train and improve our models", and said that's how it had trained them elsewhere since launch. Since 16 December 2025 it has also used those chats to pick the posts and ads people see, in most regions. Meta says more than 1 billion people use Meta AI every month.
Two companies moved in opposite directions within a year. Anthropic started asking Claude users to allow training in August 2025, and TechCrunch reported that the toggle shown to existing users came preset to on. Microsoft went the other way. Its Copilot app, updated on 18 August 2026, says prompts, responses and files "aren't used to train foundation models". People still on the older Copilot app keep the old rule, which trains on chats unless they opt out. You'll find more on both companies in our Claude statistics and Gemini statistics.
Paid business plans are the real dividing line. OpenAI says it doesn't train on ChatGPT Business, Enterprise, Edu or API traffic by default, and Anthropic says the same of Claude for Work and its API. Google's Gemini API splits the same way: its pricing page says free tier content is "used to improve our products" and paid tier content isn't. Whizi, which publishes this page, doesn't use your prompts, files or chats to train Whizi-owned models, but each message still goes to the provider of the model you pick, as our data and privacy page explains. For the settings themselves, vendor by vendor, see the most private AI chatbot comparison.
How long do AI chatbots keep your chats?
Most AI chatbots keep your chats until you delete them or close your account. Five of the nine say so in plain words: OpenAI, SpaceXAI, Perplexity, Mistral and DeepSeek, which keeps chat inputs "for as long as you have an account". Google is the only one of the nine that states a default expiry for its current app: 18 months. You can cut that to 3. Microsoft's older Copilot app stores conversations for 18 months too.
Deleting a chat doesn't erase every copy. OpenAI, Anthropic and SpaceXAI say a deleted chat leaves their systems within 30 days. Anthropic keeps de-identified chats in its training pipelines for up to five years when training is on. Google keeps the chats its reviewers read for up to three years, cut off from your account, even after you delete your activity.
Opting out doesn't reach back, either. "Previously collected training data cannot be deleted or removed," Perplexity says. Anthropic says your data stays in models that have already been trained. A thumbs up can undo an opt-out, too: OpenAI says feedback can send "the entire conversation" to training, and Anthropic keeps feedback for up to five years.
A court can also stop a deletion. In May 2025 a US magistrate judge ordered OpenAI to preserve ChatGPT output logs it would otherwise have deleted, in The New York Times copyright case. OpenAI says that duty ended on 26 September 2025. In November 2025 the same judge ordered OpenAI to hand over 20 million de-identified ChatGPT logs, and a district judge upheld the order in January 2026, Bloomberg Law and the ABA Journal reported.
How worried are people about AI and privacy?
Most Americans expect AI to make their data less safe. Pew Research Center found that 71% of US adults think AI will make their personal information less secure, and just 3% think it'll be more secure. It surveyed 5,119 adults from 17 to 23 February 2026 (Pew). In the same survey, 59% weren't confident that US companies will develop and use AI responsibly. And 67% had little or no confidence in the government to regulate it.
Americans want a say, too. In June 2025, 61% of US adults told Pew they'd like more control over how AI is used in their lives, up 6 points from 2024 (Pew). Pew's 2023 numbers still circulate widely. That year, 70% of Americans who'd heard of AI had little or no trust in companies to use it responsibly, and 81% of those familiar with it expected their personal information to be used in ways they wouldn't like (Pew).
It isn't only Americans who worry. Ipsos asked 23,532 adults in 32 countries, between 20 March and 3 April 2026, whether they trust companies that use AI to protect their personal data. On average 47% agreed. In the US it was 34%, in Canada 27% and in France 26%. On average across the 32 countries, 50% said AI products and services make them nervous. In the US, 64% did.
KPMG and the University of Melbourne surveyed 48,340 people in 47 countries between November 2024 and January 2025. Of those, 82% were at least moderately concerned about losing privacy or intellectual property to AI. The IAPP's 2023 survey of nearly 5,000 consumers in 19 countries found that 57% see AI's use of personal data as a significant threat to privacy (IAPP).
How much sensitive data do employees put into AI tools?
About half of employees who use AI at work have put company information into public AI tools. KPMG and the University of Melbourne found that 48% had uploaded company information, such as financial, sales or customer data, into public AI tools. And 70% used free, publicly available tools. The base is the employees in that 47 country survey who use AI at work (report PDF).
The vendors that watch this traffic say the share is climbing. Cyberhaven, which sells data security software, found that 10.7% of the corporate data employees put into AI tools in March 2023 was sensitive. That rose to 27.4% a year later and 34.8% in its April 2025 report (Cyberhaven). In its February 2026 report it counted each interaction instead, and it found sensitive data in 39.7% of data movements into AI tools, and 32.3% of ChatGPT use at work ran through personal accounts.
Harmonic Security counts prompts instead, and lands lower. It found sensitive data in 8.5% of prompts in late 2024, and customer data made up 45.77% of those (Harmonic). LayerX, a browser security company, wrote in October 2025 that "77% of users paste data into GenAI tools", and 82% of that pasting came from unmanaged accounts.
People do it at home as well. Cisco found that 30% of generative AI users enter personal or confidential information into the tools, though 84% worry that what they type could go public. It asked 2,600 consumers in 12 countries, in June 2024. Our list of what never to paste into an AI chatbot covers the safe side of that habit.
At the same time, companies are loosening their rules. In Cisco's 2026 benchmark of more than 5,200 IT, security and privacy staff, the share of organizations with outright AI bans and limits on what staff may type into generative AI fell from 28% to 7% in a year. And 90% said their privacy programs had grown because of AI.
How many AI privacy incidents and breaches are there?
The AI Incident Database logged 362 AI incidents in 2025, up from 233 in 2024, the Stanford AI Index 2026 reports. That's a 55% rise by our arithmetic, after a 56.4% rise the year before. The database counts every kind of AI harm, not just privacy, and its public list held more than 1,700 incidents on 7 October 2026 (AI Incident Database). Wrong answers are a separate problem, covered in our AI hallucination statistics.
Privacy is a big part of what the OECD tracks, too. Its AI Incidents and Hazards Monitor, built from news reports, listed 18,123 incidents and hazards on 7 October 2026. Of those, about 7,577, or 41.8% by our count, are tagged with the OECD AI principle "Privacy & data governance". An entry can carry more than one tag.
More of the breaches that companies suffer now hit their AI systems. IBM's 2026 Cost of a Data Breach report looked at 602 organizations that had a breach between March 2025 and February 2026. More than 20% had a breach targeting AI models or applications, and 92% of those lacked proper AI access controls. A year earlier IBM put those shares at 13% and 97% (IBM 2025). IBM's 2025 report also found one in five organizations had a breach tied to shadow AI, the tools staff use without approval. Those with lots of shadow AI paid $670,000 more per breach on average.
Some chatbots have spilled chats all on their own. A ChatGPT bug in March 2023 may have shown the payment details of 1.2% of ChatGPT Plus subscribers active in a nine-hour window, OpenAI said. Full card numbers weren't exposed. In July 2025 Fast Company found nearly 4,500 shared ChatGPT conversations in Google results, and OpenAI pulled the option that made them findable. A month later, Forbes reported that Google had indexed more than 370,000 Grok conversations.
Which regulators have fined AI companies over personal data?
Italy's data protection authority, the Garante, has fined at least three chatbot makers since December 2024. It fined OpenAI €15 million over ChatGPT that month, for training without a legal basis, failing to report a March 2023 breach and skipping age checks. A Rome court annulled that decision on 18 March 2026 (judgment). It held that the Garante lacked competence under the GDPR's one-stop-shop rules, and it didn't rule on OpenAI's other grounds.
The Garante fined Luka, the company behind Replika, €5 million in May 2025 (Garante), and Character.AI €158,000 in July 2026. It also ordered DeepSeek to stop processing Italians' data in January 2025. In South Korea, the Personal Information Protection Commission paused new downloads of DeepSeek from 15 February 2025. In April 2025 it found DeepSeek had sent users' prompts to a company in Beijing without separate consent (PIPC).
The largest amounts on this page come from cases about face recognition. The Dutch data protection authority fined Clearview AI €30.5 million in September 2024 over an illegal database of more than 30 billion photos (Dutch DPA). Texas settled with Meta for $1.4 billion in July 2024 over biometric data Facebook captured without the consent Texas law requires.
In the US, the Federal Trade Commission sent orders in September 2025 to seven companies with AI companion chatbots: Alphabet, Character.AI, Instagram, Meta, OpenAI, Snap and xAI. It asked how they use or share what people tell the bots (FTC). That's a study, not a penalty. Ireland's Data Protection Commission opened an inquiry in April 2025 into X's use of Europeans' posts to train Grok, and it hadn't published a decision as of October 2026.
Under the EU AI Act, the bans on prohibited AI practices have applied since 2 February 2025. Breaking them can cost a company up to €35 million or 7% of worldwide annual turnover, whichever is higher (European Commission).
How we compiled these numbers
We opened every figure at its source on 7 October 2026: vendor help and policy pages, regulator and court decisions, and the survey or report itself. For the default count, we took the six chatbots that Pew asked about in its February 2026 survey: ChatGPT, Gemini, Copilot, Meta AI, Grok and Claude. We added the next two by web traffic in Similarweb's August 2026 figures, which are DeepSeek and Perplexity. Mistral's Vibe is in as Europe's main entry. The market numbers behind that choice are on our AI chatbot market share page. We count a chatbot as training without asking when it uses consumer chats for training and never asks the user to choose. Claude asks, though TechCrunch reported that the toggle shown to existing users came preset to on. Count Claude in and the figure is eight of nine.
Cyberhaven, Harmonic, LayerX and IBM all sell security products or services, so we name their reports as vendor research. We left out what we couldn't open at its origin. That cut unsourced figures page one repeats, like "~40%" of organizations having an AI privacy incident and "~15%" of employees pasting sensitive data. It also cut Edelman's 2026 global AI trust figures, whose report we couldn't open, and a Brazilian order on Grok we could only read in the press. Every number, its wording at the source and the URL are in our research log.
Chatbot policies change, so read the default table as a snapshot of 7 October 2026. We'll recheck it when a vendor changes its terms.
How to cite these AI privacy statistics
You're free to use any figure or table on this page with a link back to it. Please credit the original source for numbers that came from someone else, too. A plain credit line like this one works:
Source: Whizi Research, "AI privacy statistics 2026: 7 of 9 AI chatbots train on your chats without asking", whizi.io/resources/ai-privacy-statistics, updated October 2026.
More from the same series: ChatGPT statistics, AI data center energy consumption statistics and AI in education statistics.
- Check whose answers a percentage counts: all adults, AI users, employees or organizations
- Name Cyberhaven, Harmonic, LayerX and IBM figures as vendor research
- Date every chatbot policy, since Anthropic, Meta and Microsoft all changed theirs between August 2025 and August 2026
- Say whether a fine still stands; Italy's €15 million OpenAI fine was annulled in March 2026
- Link the primary source, never a statistics aggregator
Frequently asked questions
Do AI chatbots use my conversations for training?
Most of them do it by default. As of 7 October 2026, ChatGPT, Gemini, Perplexity, Mistral's Vibe, Grok, DeepSeek and Meta AI all train on consumer chats without asking first, and Meta AI offers no settings switch. Claude asks every user to choose, and Microsoft's updated Copilot app doesn't use them to train foundation models. OpenAI and Anthropic exclude business and API plans by default.
What percentage of people are worried about AI and privacy?
About seven in ten Americans are: 71% of US adults think AI will make their personal information less secure, in Pew's February 2026 survey of 5,119 adults. Across 32 countries, Ipsos found in spring 2026 that only 47% trust companies using AI to protect their personal data, and just 34% in the US.
How many AI privacy incidents happen each year?
The AI Incident Database logged 362 AI incidents in 2025, up from 233 in 2024, per the Stanford AI Index 2026, though that counts every kind of AI harm. In the OECD's news-based monitor, 7,577 of 18,123 incidents and hazards on 7 October 2026 carried its privacy and data governance tag.
Can I stop an AI chatbot from keeping my chats?
Partly. You can delete chats, and OpenAI, Anthropic and SpaceXAI say deleted chats leave their systems within 30 days. Copies can survive: Google keeps chats its reviewers read for up to three years, and nothing removes what a model already learned. ChatGPT's temporary chats, Claude's incognito chats and Grok's Private Chat stay out of training.