The hardest thing to put in a chatbot

People ask a search engine about the weather. They tell an AI assistant about their marriage. The same text box takes both, and the second one leaves a copy on someone else's computer.

That is the tension behind journaling in ChatGPT. The product is good at it: always available, patient, and able to hold a thread across months. It is also a general-purpose cloud service with a privacy policy, a retention period, and a training pipeline. Nothing in the interface stops you from typing the most personal paragraph of your week into it.

So the honest version of "is it safe" is not yes or no. It is a set of specific questions. Is this conversation used to train a model? How long is the copy kept? What does delete actually mean? Can a person read it? The answers live in policy documents, which is why we read them.

What the policies actually say

The table covers consumer plans on default settings, checked and quoted on October 3, 2026. Business, enterprise, education, and API accounts have different terms, and those differences are noted where they matter. Every row links to the source document, and the sections below quote each policy's own words.

Assistant Training on your chats Deletion and retention Where the control lives Sources
ChatGPT On by default for consumer plans. Opting out excludes new conversations; feedback can still be used. Deleted data removed within 30 days, with legal and safety exceptions. Temporary chats kept up to 30 days. Settings, Data controls, Improve the model for everyone; Temporary chat Privacy policy, Data controls
Gemini On while Keep Activity is on, the default, with human review. Off means no training unless you send feedback. 18 months auto-delete by default, adjustable to 3 or 36 months or never. 72 hours when activity is off. Reviewed chats kept up to 3 years. Gemini Apps Activity, Keep Activity; Temporary chat Privacy Hub, Google Privacy Policy
Claude On unless you opt out in account settings. Safety-flagged content and explicit feedback are used regardless. Deleted conversations leave history immediately and the backend within 30 days. Privacy settings, training opt-out Privacy policy, Retention FAQ
Copilot On unless you opt out. Covers conversation activity and voice, plus uploaded images and files. Some markets are excluded while Microsoft expands the controls. Conversation history retained 18 months by default. Individual items and the full history can be deleted. Profile, Privacy, Training on conversation activity and Training on voice conversations Privacy controls, Privacy FAQ
Grok On unless you opt out. Private Chat is never used for training. Signed-out users in some regions have no opt-out. Deleted conversations and accounts removed within 30 days. Private Chat conversations deleted within 30 days. Settings, Data Controls, Improve the model; Private Chat Privacy policy, Consumer FAQ

ChatGPT: training is on until you turn it off

OpenAI's privacy policy says it collects "your prompts and other content you upload" and may use Content "to improve our Services, for example to train the models that power ChatGPT." The help center is more direct about who that applies to: "When you use our services for individuals, such as ChatGPT and Codex, we may use your content to train our models."

The control is Settings, Data controls, Improve the model for everyone, or "Do not train on my content" in the OpenAI privacy portal. After you opt out, new conversations are excluded from training. Three things that catches people out:

  • Opting out does not delete or hide saved chats. Archiving a chat does not change whether it can be used for training.
  • Feedback overrides the setting. OpenAI says that if you rate a response, "the entire conversation associated with that feedback may be used to train our models," even after you opted out.
  • Codex has its own setting for full environments that the ChatGPT toggle does not change.

On deletion, the privacy policy says data you choose to delete is removed from OpenAI's systems "within 30 days" unless it needs to keep it longer for legal, safety, fraud, or financial record-keeping reasons, or it has already been de-identified and disassociated from your account through training. Temporary chats do not appear in history, do not create memories, and are not used to train models, but "may be retained for up to 30 days for safety purposes."

If you use a business, enterprise, education, or API account, the default is the opposite: OpenAI says it does not use those inputs and outputs to train its models unless an organization opts in.

Gemini: activity is the switch

Google splits its consumer terms on one setting, Keep Activity. With it on, which is the default, chats are saved to your Google account and used "to provide, develop, and improve its services (including training generative AI models), as well as to protect Google, its users, and the public with the help of human reviewers."

The human review is worth pausing on. Google's notice carries its own warning: "Please don't enter confidential information that you wouldn't want a reviewer to see or Google to use to improve our services." Reviewed chats are retained for up to three years, and those copies are disconnected from your account, which means deleting your activity does not delete them.

Retention works in tiers. With Keep Activity on, the default auto-delete period is 18 months, adjustable to 3 months, 36 months, or never. With it off, future chats are not used to train models unless you submit feedback, but Google still keeps them for 72 hours to respond and to protect its systems. Temporary chats follow the same 72-hour rule and are not used to improve Google's AI.

Claude: an opt-out in your account settings

Anthropic's privacy policy, effective September 10, 2026, states it plainly: "We may use your Inputs and Outputs to train and improve Anthropic AI models, unless you opt out through your account settings." The opt-out lives in Claude's privacy settings, and Anthropic lists Inputs and Outputs from users as one of its training data sources "unless users opt out."

The exceptions are explicit. Even after opting out, Anthropic says it uses Inputs and Outputs for model improvement when a conversation is flagged for safety review, or when you explicitly report or rate it through feedback. When feedback is used for training, it is disassociated from your user ID.

Deletion is defined here too: deleting an individual conversation removes it from your history immediately and is "automatically deleted from our back-end within 30 days." Business customers, and the API, are governed by separate agreements and are not trained on by default.

Copilot: consumer chats can train Microsoft's models

Microsoft runs its consumer Copilot under different terms than Microsoft 365 Copilot. The consumer privacy FAQ says: "Except for certain categories of users or users who have opted out, Microsoft uses data from Bing, MSN, Copilot, and interactions with ads on Microsoft for AI training. This includes de-identified search and news data, interactions with ads, and your voice and conversation activity with Copilot, including the images or files you upload."

The opt-out is in your profile under Privacy, split into two switches: Training on conversation activity and Training on voice conversations. Opting out excludes future activity from training but, Microsoft notes, not from other product improvements, advertising, safety, security, and compliance uses.

Some accounts are excluded by default: work and school accounts signed in with an organizational (Entra) identity, and Copilot conversations inside Microsoft 365 consumer apps such as Word, Excel, PowerPoint, and Outlook. Conversation history is retained for 18 months by default, and you can delete individual items or the whole history.

Grok: opt out, or use Private Chat

Grok is run by SpaceXAI, the company formerly called xAI. Its privacy policy says prompts, files, images, audio, and other content may be used "to develop and improve our Service and to conduct research." The consumer FAQ is more direct: "We may use your content and interactions with Grok (e.g., prompts, searches, and other materials you submit) along with Grok's responses to train our models."

The opt-out is under Settings, Data Controls, Improve the model on the mobile app, and Settings, Data, Improve the Model on grok.com. Private Chat is the stronger option: those conversations do not appear in your history, are not used for training, and are deleted from SpaceXAI systems within 30 days. Deleting a conversation or your account works on the same 30-day clock, unless the data is retained for legal, compliance, or safety reasons.

One gap: in some regions outside the EU and UK, using Grok without logging in means there is no training opt-out at all. The policy also asks readers not to share personal or sensitive information in prompts, which is a strange sentence for a product people use to journal.

Training, retention, and memory are three different settings

These words get treated as one thing. They are not:

  • Training decides whether your words help improve the model, usually by adding them to a dataset after removing some identifying details.
  • Retention decides how long the service keeps your conversation at all, training aside.
  • Memory decides whether the assistant brings your past into future answers.

An opt-out usually addresses the first and touches neither of the others. ChatGPT has separate memory controls, and turning memory off does not stop safety systems using limited context in rare cases. Copilot lets you opt out of training while keeping personalization on, so the assistant still remembers recent conversations. Gemini's Keep Activity governs activity storage and training, but Gemini Memory is its own setting.

The practical rule: "off" is not global. If private journaling matters to you, check all three switches, and check whether the provider counts your account type as consumer or business.

What no policy can promise

A privacy policy is a set of promises about a copy that exists on someone else's server. That copy is what makes the service work, and it is what the policy governs. It is also what a subpoena asks for, what a breach exposes, and what a reviewer can open when a conversation is flagged.

  • Legal requests. Every provider here says it discloses data when legally required. OpenAI's policy adds that it may retain data beyond its normal deletion window if it receives a lawful subpoena.
  • Human review. Every provider here allows some level of human review, at minimum for safety and abuse enforcement, and by default for improvement.
  • Account security. No policy prevents someone with your password from reading the journal. Session theft and shared devices are outside the document's control.
  • Policy change. These documents get rewritten. OpenAI's is dated July 30, 2026, SpaceXAI's August 24, 2026, and Anthropic's September 10, 2026. Defaults can change with notice.

None of this makes cloud assistants reckless. It makes them hosted. The right question is not "is the policy good?" It is "do I want a server copy of this at all?"

What a safer journal looks like

If the risk you care about is the server copy, the fix is to not create one. A local-first journal keeps entries in the app's storage on your phone. There is still an app and a policy, but there is no operator-side copy of your journal to retain, review, or produce on request.

Merrin is built this way: a private AI you can talk to that remembers what matters. Conversations, journal entries, memories, and transcripts are designed to stay on your device during normal use, and the memory controls let you see, edit, and delete what it keeps. The engineering deep dive on the memory loop explains how recall works, and the privacy policy covers the limited network calls, such as model downloads and purchases.

It comes with two honest costs. First, if you lose the phone and have no backup, you lose the journal; a cloud service is a useful backup until it is a liability. Second, the models that run on a phone are smaller than frontier cloud models, so they are weaker on knowledge-heavy questions, and quality varies with the device. If your journaling is mostly about saying the thing once and finding it again three weeks later, that is a trade worth understanding before you make it.

Frequently asked questions

Does ChatGPT train on my journal entries?

For a consumer account, OpenAI may use your prompts and uploaded content to train its models unless you turn off Improve the model for everyone in Settings, Data controls, or select Do not train on my content in the privacy portal. Even after you opt out, feedback you submit, such as a thumbs up or thumbs down, can be used to train models.

If I delete a ChatGPT conversation, is it gone?

OpenAI says deleted content is removed from its systems within 30 days, unless it must retain it longer for legal, safety, fraud, or financial record-keeping reasons. Temporary chats are not used for training but can be retained for up to 30 days for safety purposes.

Does Gemini use my chats for training?

With the Keep Activity setting on, which is the default, Google saves your chats and uses them to provide, develop, and improve its services, including training generative AI models, with help from human reviewers. The default auto-delete period is 18 months. With Keep Activity off, new chats are retained for 72 hours and are not used to train models unless you submit feedback.

Does turning off training stop the assistant remembering me?

No. Training, retention, and memory are separate controls. ChatGPT has separate memory settings, Copilot lets you opt out of training while keeping personalization on, and Gemini memory is a separate setting from the activity and training controls.

What is the safest way to keep an AI journal?

The journal with the least exposure is one stored on your own device, because there is no operator-side copy to retain, review, or hand over. That shifts the risk to device loss, so keep your own backup. On-device models are also smaller than frontier cloud models and weaker on general knowledge questions.