Introduction: "It stays between us anyway"
Tuesday night, 11:10 p.m. You can't sleep. A pain in your side for three days now, a bank account taking a nosedive, a difficult conversation to prepare with your employer. You open a chat app and you type, with complete candour: your age, your exact symptoms, your company's name, the size of your overdraft, the first name of the person you're clashing with.
The answer arrives in four seconds — calm, structured, kind. You close the app, relieved. And you forget entirely that what you just wrote hasn't vanished: it's a piece of text, timestamped, tied to an account, stored on servers, potentially readable by humans, and — depending on settings you've never opened — liable to feed the training of a model.

In three years, conversational assistants have become the busiest confessional in the country. People deposit there things they wouldn't tell their own GP, because the machine doesn't judge, doesn't sigh, and doesn't know your in-laws. The tool isn't the problem: it's genuinely useful. The problem is that we use it with the trust we'd give a private diary, while it operates like any ordinary online service — with logs, subcontractors, retention obligations and accidents.
This guide won't ask you to give up AI. It invites you to treat it for what it is: a third-party service, very talkative, to which you don't tell everything.
What actually leaves your hands when you chat with an AI
Three layers of data, not one
A conversation with an assistant generates far more than the text you type.
| Layer | Content | Typical lifespan |
|---|---|---|
| The content | Your messages, attached files, images, code, pasted documents | As long as the history exists, often months |
| The metadata | Timestamp, IP address, device type, browser, session length, usage frequency | Technical and anti-abuse retention, often longer than the content |
| The usage signals | Thumbs up/down, regenerations, copies, abandoned conversations | Reused to improve the model |
The second layer is the one everyone systematically forgets. Even after deleting a conversation, there generally remains a record of the fact that at 11:10 p.m. on a Tuesday, from that particular connection, someone used the service for twelve minutes. That's no small thing: it's exactly the kind of data that lets someone reconstruct the rhythm of your life.
The "it's anonymous" myth
An AI assistant is almost never anonymous. It's tied to an account, itself tied to an email address, often to a phone number and to a payment method if you have a subscription. And above all: you are the one de-anonymising yourself, line after line. Your children's first names, the name of your street, the exact wording of a prescription, a contract reference. No pseudonymisation system protects against a user who writes their own identity into the body of the message.
Simple rule: assume that everything you type into an assistant is being sent to an external provider, in writing, with your name at the top. If that picture makes you uncomfortable, don't send it.
Humans in the loop
The major providers say so in their policies: some conversations may be reviewed by people, for security, moderation or quality-improvement purposes. That's documented practice, not a theory. The CNIL, in its work on AI systems, also points out that "human review" is a purpose that must be disclosed to users, and that it does constitute processing of personal data within the meaning of the GDPR.
Why this became a serious subject in 2026
Several trends converged over recent months.
First, data protection authorities began issuing rulings. In spring 2026, the joint investigation by the Office of the Privacy Commissioner of Canada and several provinces concluded that the operation of a major conversational assistant breached several Canadian privacy laws, notably on consent to the use of data for training. In Europe, the Italian authority (Garante) had led the way back in 2023 with a temporary suspension, followed by a fine. The message is consistent: training a model on users' conversations is not an acquired right.
Next, the CNIL published a 2025 review marked by a record number of complaints and sanctions, and made AI one of its priority areas, with a series of recommendations on the legal basis for training-related processing, informing individuals, and the exercise of their rights.
Finally, AI has stopped being an application you open. It's now in your phone's keyboard, in your browser's search bar, in your work email, in your office suite, in the speakers in your living room. You no longer "go" and talk to an AI: you talk to it without realising, because it's already there.

The red line: what you never write in a chatbot
This isn't about becoming paranoid, but about having a short, clear list, memorised once and for all.
Never enter:
- Social security number, tax identifiers, ID document numbers.
- Full bank details, PINs, passwords, recovery codes.
- Named medical documents (reports, test results with letterheads).
- Data concerning people other than yourself: your mother's medical file, your child's school report, an ex's messages. You don't have their consent, and the GDPR also applies to what you do with other people's data.
- Confidential work documents: unsigned contracts, client data, proprietary source code, internal strategy. Several companies have learned this the hard way.
- Admissions, draft complaints, material relating to an ongoing dispute. A conversation history is a document, and a document can be subpoenaed.
Handle with care:
- Health questions phrased in the first person. Describing a symptom generically ("possible causes of calf pain after a long-haul flight") doesn't raise the same issues as "I'm 42, I live in Tours, I've been on this medication since 2019." For health matters, official health-service and medical reference sites remain go-to sources that, unlike chatbots, don't keep a record of your story.
- Photos. An image often carries EXIF metadata: device model, date, sometimes GPS coordinates. Strip it before sending, or take a screenshot of the photo — the screenshot loses the original EXIF data.
- Administrative PDFs, riddled with identifiers in the footer.
The settings that genuinely make a difference
1. Turn off training on your data
This is the highest-yield and most overlooked setting. Most major services now offer an option along the lines of "improve the model for everyone" or "use my conversations for training," switched on by default on consumer plans. Disabling it doesn't delete your history, but it stops your exchanges from feeding the next versions.
Look in the settings under: Data controls, Privacy, Model improvement. Do it on every service, including the ones you barely use — a forgotten account keeps collecting.
2. Shorten how long your history is kept
Some services allow automatic deletion after 30 days, or offer a "temporary chat" mode that doesn't appear in your history. That mode remains imperfect (the data still transits, and is kept for a while for security reasons), but it prevents the build-up of a multi-year private diary on an account protected by nothing more than a password.
3. Lock the account down
An AI conversation history is one of the most intimate things an account can hold. It deserves at the very least a unique password and two-factor authentication. A FIDO2 security key plugged in via USB or used over NFC remains the most robust way to block a remote account takeover, and is fully justified once an account centralises this much.
4. Take back control of voice assistants
Smart speakers and phone assistants pose a different problem: accidental activation. One misheard word, and several seconds of living-room conversation get sent off for processing. Three useful moves:
- Disable the recording and retention of audio clips in the associated account's settings.
- Periodically delete your voice history (most providers offer a full purge in two clicks).
- Use the physical mic mute button where one exists. For a webcam, a simple adhesive webcam cover does the same job — more visibly, and therefore more reliably, than any software setting.
5. Compartmentalise your uses
The best protection isn't technical, it's organisational. One account for work, another for personal life, and nothing crossing over. Ideally, a dedicated email address, without your surname, reserved for AI services. A password manager makes that compartmentalisation sustainable, because multiplying accounts without a tool always ends with the same password everywhere.
Local AI: the rising option
Since 2025, it has become realistic to run a language model directly on your own computer, without any data leaving the machine. Mid-sized open models are more than enough for rephrasing, translation, document summarisation, drafting an administrative letter or help with sorting information — that is, 80% of real-world uses.
What it takes:
- A recent computer with a comfortable amount of RAM. An extra RAM module often turns a "borderline" machine into a comfortable one, for a fraction of the cost of a full replacement.
- Storage: models range from a few gigabytes to several dozen. An external NVMe SSD makes this painless and lets you move your environment from one machine to another.
- An hour of learning. Consumer-facing interfaces have become vastly simpler.
The benefit goes beyond privacy: no service outages, no changes to the terms of use, no retroactive deletion of your conversations because a provider revised its policy.

Your rights, in practice
The GDPR applies to AI assistants just as it does to any other service. Established providers all offer dedicated forms in their settings. Three rights are particularly useful here.
The right of access (Article 15). You can request a full export of your conversations. The exercise is instructive: many people discover two-year-old exchanges they thought were long forgotten. The provider has one month to respond.
The right to erasure (Article 17). It covers data about you held in the service's databases. Note one crucial nuance: deleting your conversations does not "unlearn" a model that has already been trained. That's precisely why the anti-training setting, switched on up front, is worth more than a belated deletion.
The right to object (Article 21). Where a provider invokes legitimate interest to train its models — the most common case in Europe — you can object, without having to provide lengthy justification. The forms exist; they're just discreet.
If you hit a wall, the CNIL accepts complaints online. Its 2025 activity report shows a record volume, a sign that the reflex is taking hold.
The case of truly sensitive conversations
There remains a category of situations where no setting is enough: when the mere fact that a conversation took place is already a problem. A search about domestic violence from a shared household. A legal question about your own employer from a workstation. A health query you don't want appearing in a family account's history.
In those cases, the right answer isn't to configure the assistant better, it's to change channel:
- Use a device and a connection that aren't your everyday ones.
- Go through a local, offline model.
- Or fall back on human, confidential channels: helplines for victims of domestic violence, free legal advice sessions at your town hall, legal access points, specialist charities.
And to get in touch with someone without exposing your number — warning a loved one, raising an alarm discreetly, putting a question to an organisation — sending a message with a hidden sender remains one of the few genuinely simple solutions. That's one of the roles this site fills.
For those who'd rather understand than follow a recipe, several recently published introductory books on personal data protection do a serious job, and an encrypted notebook — or even a plain paper one — remains, for certain reflections, the safest medium in existence.
Recap: the ten-minute routine
- Open the settings of every assistant you use and disable the use of conversations for training.
- Turn on automatic history deletion, or switch to temporary chat by default.
- Purge the voice history on your phone assistants and smart speakers.
- Create a dedicated email address, without your surname, for AI services.
- Enable two-factor authentication on those accounts.
- File an access request to see what's stored — once is enough to get the picture.
- Adopt the message rule: I write nothing I wouldn't put in a signed letter to a supplier.
- Try a local model for everyday tasks.
- Strip metadata from images before sending them.
- Do it all again every six months: policies change, and default settings come back.
In short
An AI assistant is neither a friend, nor a therapist, nor a notary. It's an online service remarkably good at creating the illusion of intimacy. The right stance isn't blanket suspicion — that would be absurd and self-defeating — but simple hygiene: turn off training, limit retention, compartmentalise accounts, and keep out of the machine the three or four categories of information that should never leave it.
The question to ask yourself before hitting Enter fits in a single sentence: if this conversation showed up tomorrow in a data breach, what would change in my life? If the answer is "nothing," write away. Otherwise, rephrase.



