{"catalog":{"title":"Are AI chatbots safe? Privacy of ChatGPT, Claude, Gemini and others","path":"/ai-privacy","updatedAt":"2026-09-30T10:34:56.673Z","fields":[{"id":"brand","label":"Made by","type":"text"},{"id":"company","label":"Company responsible for your data","type":"text"},{"id":"company_country","label":"Company based in","type":"select","options":["United States","China","France"]},{"id":"trains_default","label":"Trains on your chats","type":"select","options":["Yes, unless you opt out","Yes, no opt-out for chats","You choose when prompted","No"]},{"id":"training_detail","label":"What is used for training","type":"textarea"},{"id":"opt_out","label":"How to turn training off","type":"textarea"},{"id":"business_plans","label":"Business and API plans","type":"textarea"},{"id":"retention","label":"How long chats are kept","type":"textarea"},{"id":"deleted_chats","label":"After you delete a chat or account","type":"textarea"},{"id":"human_review","label":"People can read chats","type":"select","options":["Yes","Limited","Not stated"]},{"id":"human_review_detail","label":"Human review","type":"textarea"},{"id":"temporary_chat","label":"Temporary chat mode","type":"checkbox"},{"id":"temporary_detail","label":"Temporary chat","type":"textarea"},{"id":"data_location","label":"Where data is stored","type":"textarea"},{"id":"min_age","label":"Minimum age","type":"number","format":{"style":"integer"}},{"id":"min_age_note","label":"Age rules","type":"text"},{"id":"ads","label":"Chats used for ads","type":"select","options":["Yes","No","Not stated"]},{"id":"ads_detail","label":"Ads","type":"textarea"},{"id":"security","label":"Security and certifications","type":"textarea"},{"id":"regulator_count","label":"Regulator actions listed","type":"number","format":{"style":"integer"}},{"id":"regulator_actions","label":"Regulator actions","type":"textarea"},{"id":"incidents","label":"Data incidents disclosed by the company","type":"textarea"},{"id":"privacy_url","label":"Privacy policy","type":"url"},{"id":"terms_url","label":"Terms","type":"url"},{"id":"help_url","label":"Data controls help page","type":"url"},{"id":"checked","label":"Checked on","type":"date"},{"id":"sources","label":"Sources","type":"textarea"}]},"entries":[{"slug":"chatgpt","name":"ChatGPT","path":"/ai-privacy/chatgpt","category":null,"updatedAt":"2026-09-30T10:34:56.198Z","fields":{"brand":"OpenAI","company":"OpenAI OpCo, LLC; OpenAI Ireland Limited for the EEA and Switzerland","company_country":"United States","trains_default":"Yes, unless you opt out","training_detail":"For individual services such as ChatGPT and Codex, OpenAI \"may use your content to train our models\" (prompts, responses, images, files) unless you turn off \"Improve the model for everyone\"; opting out applies to new conversations. Even after opting out, thumbs-up/down feedback can put \"the entire conversation associated with that feedback\" into training, and Temporary Chats are never used for training.","opt_out":"Web: profile icon > Settings > Data Controls > turn off \"Improve the model for everyone\". Mobile: side-bar menu > profile icon > Data Controls > turn off \"Improve the model for everyone\". Alternatively, choose \"do not train on my content\" in the privacy portal (privacy.openai.com). Codex's full-environment training has a separate setting.","business_plans":"\"By default, we do not train on any inputs or outputs from our products for business users, including ChatGPT Business, ChatGPT Enterprise, and the API\"; API organizations can opt in to data sharing.","retention":"Chats are kept until you delete them (\"Information we retain until you delete it\"); longer retention is possible for safety, legal (e.g. subpoena), fraud/abuse or financial record-keeping reasons.","deleted_chats":"Deleted chats or accounts are removed from OpenAI's systems \"within 30 days\" unless they must be kept for security or legal reasons, or were \"previously de-identified and disassociated from your account\". After full account deletion, you can reuse the email for a new account after 30 days.","human_review":"Yes","human_review_detail":"Yes. \"A limited number of authorized OpenAI personnel, as well as trusted service providers\" may access content for abuse or security investigations, support, legal matters, or \"to improve model performance (unless you have opted out)\". Selected portions may go to service providers \"for data annotation and safety purposes\". Temporary Chats \"may be reviewed only to monitor for abuse\".","temporary_chat":true,"temporary_detail":"Temporary Chat: not saved to history, creates no memories and is not used for training. It is deleted within 30 days (\"OpenAI may retain a copy for up to 30 days for safety purposes\"). Saving a temporary chat turns it into a regular chat.","data_location":"\"Content is stored on OpenAI systems and our trusted service providers' systems in the US and around the world.\" The EU policy says data is processed \"on servers located outside of the EEA, Switzerland and the UK\", including in the US, under adequacy decisions and SCCs. Business plans offer data residency.","min_age":13,"min_age_note":"13 (or the minimum age required in your country to consent); users under 18 need a parent's or legal guardian's permission.","ads":"Yes","ads_detail":"Free and Go plans can show ads. They can be chosen from the current chat and, with \"Personalize ads\" on, from past chats and memory. Plus, Pro, Business, Enterprise and Edu have no ads. OpenAI says advertisers do not get access to chats and receive only aggregate data. Controls: Settings > Ad Controls.","security":"For individuals, content is \"encrypted at rest and in transit between you and OpenAI, and between OpenAI and its service providers\"; Advanced Account Security is optional. Enterprise pages state AES-256 at rest and TLS 1.2+ in transit. Certifications: SOC 2 Type 2 (API and ChatGPT business products); ISO/IEC 27001:2022 and 27701:2019 (API, ChatGPT Enterprise, Edu); ISO/IEC 42001:2023 covering consumer and business products; PCI-DSS for delegated payment components; CSA STAR Level 1. Trust portal: https://trust.openai.com","regulator_count":7,"regulator_actions":"2023-03-30 · Garante per la protezione dei dati personali (Italy) · Ordered an urgent temporary limitation on the processing of Italian users' data by OpenAI, citing no information notice, no legal basis for training and no age verification. ChatGPT was effectively blocked in Italy. · https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9870832\n2023-04-12 · Garante per la protezione dei dati personali (Italy) · Announced its 11 April 2023 order: the limitation would be lifted if OpenAI met measures by 30 April (transparency notice, legal basis for training, right to object, age gating and an age-verification plan). · https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9874751\n2023-04-28 · Garante per la protezione dei dati personali (Italy) · Confirmed that OpenAI had brought ChatGPT back in Italy after adopting the required transparency and rights measures, and said its investigation would continue. · https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9881490/\n2023-07-27 · Personal Information Protection Commission (South Korea) · Fined OpenAI KRW 3.6 million for not reporting the March 2023 data breach (687 Korean users affected) and issued improvement recommendations. · https://www.pipc.go.kr/eng/user/ltn/new/noticeDetail.do?bbsId=BBSMSTR_000000000001&nttId=2271\n2024-05-23 · European Data Protection Board (ChatGPT Taskforce) · Published the ChatGPT Taskforce report on the coordinated national investigations into OpenAI's processing. It notes that the one-stop-shop mechanism has applied since 15 February 2024. · http://edpb.europa.eu/system/files/2024-05/edpb_20240523_report_chatgpt_taskforce_en.pdf\n2024-12-20 · Garante per la protezione dei dati personali (Italy) · Fined OpenAI EUR 15 million and ordered a 6-month information campaign; the Garante's page now says the decision was removed after the Tribunale di Roma upheld OpenAI's appeal (judgment 4153/2026, published March 18, 2026). · https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10085432\n2025-09-11 · US Federal Trade Commission · Issued 6(b) orders to seven companies, including OpenAI OpCo, LLC, for a study of AI chatbots acting as companions and their effects on children and teens. This is a study, not an enforcement action. · https://www.ftc.gov/news-events/news/press-releases/2025/09/ftc-launches-inquiry-ai-chatbots-acting-companions","incidents":"2023-03-24 · A bug let some users see other users' chat titles; payment details of 1.2% of active ChatGPT Plus subscribers could be exposed during a nine-hour window on March 20, 2023. · https://openai.com/index/march-20-chatgpt-outage/\n2025-11-26 · A breach at analytics vendor Mixpanel exposed limited profile data of API users and some ChatGPT users; OpenAI says no chats, passwords, API keys or payment data were exposed. · https://openai.com/index/mixpanel-incident/","privacy_url":"https://openai.com/policies/row-privacy-policy/","terms_url":"https://openai.com/policies/row-terms-of-use/","help_url":"https://help.openai.com/en/articles/7730893-data-controls-faq","checked":"2026-09-30","sources":"OpenAI Privacy Policy (rest of world), updated Feb 6, 2026 · https://openai.com/policies/row-privacy-policy/\nOpenAI Europe Privacy Policy, updated Aug 24, 2026 · https://openai.com/policies/eu-privacy-policy/\nOpenAI US Privacy Policy, updated May 18, 2026 · https://openai.com/policies/us-privacy-policy/\nOpenAI Terms of Use, effective Jan 1, 2026 · https://openai.com/policies/row-terms-of-use/\nHelp: How your data is used to improve model performance · https://help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance\nHelp: Data Controls FAQ · https://help.openai.com/en/articles/7730893-data-controls-faq\nHelp: How OpenAI handles data in consumer services · https://help.openai.com/en/articles/7039943-how-openai-handles-data-in-consumer-services\nHelp: Ads in ChatGPT · https://help.openai.com/en/articles/20001047-ads-in-chatgpt\nEnterprise privacy at OpenAI · https://openai.com/enterprise-privacy/\nSecurity and privacy at OpenAI · https://openai.com/security-and-privacy/\nMarch 20 ChatGPT outage · https://openai.com/index/march-20-chatgpt-outage/\nMixpanel security incident · https://openai.com/index/mixpanel-incident/\nGarante decision, March 30, 2023 · https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9870832\nGarante press release, April 12, 2023 · https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9874751\nGarante press release, April 28, 2023 · https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9881490/\nGarante press release, December 20, 2024 (with note on annulment) · https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10085432\nPIPC press release, July 27, 2023 · https://www.pipc.go.kr/eng/user/ltn/new/noticeDetail.do?bbsId=BBSMSTR_000000000001&nttId=2271\nEDPB ChatGPT Taskforce report · http://edpb.europa.eu/system/files/2024-05/edpb_20240523_report_chatgpt_taskforce_en.pdf\nFTC 6(b) AI companion chatbots press release · https://www.ftc.gov/news-events/news/press-releases/2025/09/ftc-launches-inquiry-ai-chatbots-acting-companions"}},{"slug":"claude","name":"Claude","path":"/ai-privacy/claude","category":null,"updatedAt":"2026-09-30T10:34:56.250Z","fields":{"brand":"Anthropic","company":"Anthropic, PBC; Anthropic Ireland, Limited for the EEA, UK and Switzerland","company_country":"United States","trains_default":"You choose when prompted","training_detail":"Chats and coding sessions are used for training if you allow it via the \"Help improve Claude\" model-improvement setting. Regardless of that setting, conversations flagged for safety review and feedback you submit (thumbs up/down) can also be used. Training data covers the whole conversation, custom styles and Claude for Chrome data, but not raw connector content (e.g. Google Drive, MCP) unless it is pasted into the chat. Incognito chats are never used.","opt_out":"Desktop/browser: select your name > Settings > Privacy > under \"Help Improve our AI models\" toggle off (direct: claude.ai/settings/data-privacy-controls). Mobile: your name > Settings > Privacy > toggle off. Turning it off stops use of previous and new chats in future training runs, but not in runs already in progress or models already trained.","business_plans":"\"By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models,\" unless you submit feedback or join the Development Partner Program.","retention":"If model improvement is on, data from new or resumed chats is kept de-identified \"for up to 5 years\" in training pipelines. If it is off, Anthropic's announcement says the existing \"30-day data retention period\" applies. Chats flagged for Usage Policy violations: inputs/outputs kept up to 2 years and trust-and-safety classification scores up to 7 years. Feedback submissions are kept 5 years.","deleted_chats":"A deleted conversation is \"removed from your chat history immediately\" and \"deleted from our back-end storage systems within 30 days\"; deleted chats are not used for future training. Account closure is done by contacting support@anthropic.com (per consumer terms).","human_review":"Limited","human_review_detail":"Limited. \"By default, Anthropic employees cannot access your conversations\" unless you share them as feedback or review is needed to enforce the Usage Policy, in which case \"only designated members of our Trust & Safety team may access this data on a need-to-know basis.\"","temporary_chat":true,"temporary_detail":"Incognito chats (ghost icon): not saved to chat history or memory and not used for training. They are retained for 30 days for safety; on Enterprise plans they follow the organisation's retention setting.","data_location":"Personal data \"is transferred to our servers in the US, or to other countries outside the European Economic Area\" for service, training and research, using adequacy decisions and Standard Contractual Clauses. Affiliates and third-party locations are listed in the Trust Center.","min_age":18,"min_age_note":"18 (or the minimum age to consent in your location, whichever is higher). The privacy policy says services are not directed to under-18s.","ads":"No","ads_detail":"No ads. Anthropic stated on Feb 4, 2026 that \"Claude will remain ad-free\" with no sponsored links or advertiser influence, while reserving the right to revisit this. The privacy policy says Anthropic does not \"sell\" personal data; you can opt out of sharing data for targeted advertising of Anthropic's own products.","security":"Consumer data \"is automatically encrypted both while in transit, and stored (at rest)\"; access is least-privilege and requires multi-factor authentication. Certifications: SOC 2 Type I & Type II, ISO 27001:2022, ISO/IEC 42001:2023, and a HIPAA-ready configuration (BAA available). Trust Center: https://trust.anthropic.com","regulator_count":0,"regulator_actions":null,"incidents":null,"privacy_url":"https://www.anthropic.com/legal/privacy","terms_url":"https://www.anthropic.com/legal/consumer-terms","help_url":"https://privacy.claude.com/en/articles/12109829-how-do-i-change-my-model-improvement-privacy-settings","checked":"2026-09-30","sources":"Anthropic Privacy Policy (published Jun 8, 2026, effective Jul 8, 2026) · https://www.anthropic.com/legal/privacy\nAnthropic Consumer Terms of Service (effective Oct 8, 2025) · https://www.anthropic.com/legal/consumer-terms\nPrivacy Center: How long do you store my data? (Jul 1, 2026) · https://privacy.claude.com/en/articles/10023548-how-long-do-you-store-my-data\nPrivacy Center: Is my data used for model training? (consumer) · https://privacy.claude.com/en/articles/10023580-is-my-data-used-for-model-training\nPrivacy Center: Is my data used for model training? (commercial) · https://privacy.claude.com/en/articles/7996868-is-my-data-used-for-model-training\nPrivacy Center: How do I change my model improvement privacy settings? · https://privacy.claude.com/en/articles/12109829-how-do-i-change-my-model-improvement-privacy-settings\nPrivacy Center: How does Anthropic protect the personal data of Claude users? · https://privacy.claude.com/en/articles/10458704-how-does-anthropic-protect-the-personal-data-of-claude-users\nPrivacy Center: What certifications has Anthropic obtained? · https://privacy.claude.com/en/articles/10015870-what-certifications-has-anthropic-obtained\nHelp Center: Use incognito chats · https://support.claude.com/en/articles/12260368-use-incognito-chats\nAnthropic news: Updates to Consumer Terms and Privacy Policy (Aug 28, 2025) · https://www.anthropic.com/news/updates-to-our-consumer-terms\nAnthropic news: Claude is a space to think (Feb 4, 2026) · https://www.anthropic.com/news/claude-is-a-space-to-think\nAnthropic news: Investigating three real-world incidents in our cybersecurity evaluations · https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals\nAnthropic news: An alignment assessment of recent cybersecurity incidents · https://www.anthropic.com/news/alignment-assessment-cybersecurity-incidents"}},{"slug":"deepseek","name":"DeepSeek","path":"/ai-privacy/deepseek","category":null,"updatedAt":"2026-09-30T10:34:56.354Z","fields":{"brand":"DeepSeek","company":"Hangzhou DeepSeek Artificial Intelligence Co., Ltd.","company_country":"China","trains_default":"Yes, unless you opt out","training_detail":"The privacy policy lists training and improving its models as a use of your prompts, uploads and chat history. The Terms (§4.3) say that inputs and outputs may be used 'to a minimal extent' after 'secure encryption technology processing, strict de-identification', unless you turn off 'Improve the model for everyone'. DeepSeek's training-methods page says that a 'small portion' of fine-tuning data is 'potentially based on user input', and that pre-training uses public and licensed data.","opt_out":"Turn off the \"Improve the model for everyone\" setting (Terms of Use §4.3). DeepSeek's own documents don't give a menu path. The privacy policy lists 'the right to opt-out of using your Personal Data for training' and gives privacy@deepseek.com for rights requests.","business_plans":"DeepSeek doesn't publish a separate no-training commitment for the API. The Open Platform Terms (effective 29 April 2026) are a 'Specific Agreement' under the Terms of Use, which cover APIs (§1.1) and contain the §4.3 training clause with its opt-out. DeepSeek offers no enterprise plan.","retention":"'We retain Personal Data for as long as necessary to provide our Services'. Account data, inputs and payment data are kept 'for as long as you have an account'. If you break its terms, data may be kept longer to deal with the violation.","deleted_chats":"You can copy or delete your chat history in settings. A deleted account can't be reactivated or recovered. Even after you delete your account, DeepSeek may 'retain certain data of the user as required by laws and regulations' (Terms §2.5). DeepSeek doesn't give a deletion timeframe.","human_review":"Not stated","human_review_detail":"DeepSeek's documents do not say whether people read conversations. Its terms reserve the right to 'use technical means to review the behavior of users'.","temporary_chat":false,"temporary_detail":null,"data_location":"People's Republic of China: 'we directly collect, process and store your Personal Data in People's Republic of China'.","min_age":18,"min_age_note":"The Terms say the service is 'primarily intended for adults'. Users under 18 (or under the minimum age in their country) may use it only with a legal guardian's consent. The EEA section of the privacy policy refers to users aged 14 to 17.","ads":"No","ads_detail":"No. The policy says, in capitals: 'WE DO NOT ENGAGE IN TARGETED ADVERTISING, “SELL” PERSONAL DATA OR USE PERSONAL DATA FOR “PROFILING”'. The training-methods page also says that user input used for training is not used for 'user profiling or personalized recommendations'.","security":"The company names no certifications. The privacy policy claims 'commercially reasonable technical, administrative, and physical security measures', and the Terms say it will take measures 'not less than industry practices'. There is no trust page.","regulator_count":15,"regulator_actions":"2025-01-28 · Garante per la protezione dei dati personali (Italy) · Asked Hangzhou DeepSeek and Beijing DeepSeek what personal data they collect, where it comes from, on what legal basis, whether it is stored in China and what is used for training. The companies had 20 days to reply. · https://www.gpdp.it/web/guest/home/docweb/-/docweb-display/docweb/10096856\n2025-01-30 · Garante per la protezione dei dati personali (Italy) · Ordered an urgent limitation, with immediate effect, on processing of Italian users' data, and opened an investigation. The order found breaches of GDPR Arts. 6, 12–14, 27, 31 and 32 and Chapter III rights. · https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10098477\n2025-01-31 · Office of the Texas Governor / Texas DIR (US state) · Added DeepSeek to the Texas prohibited-technologies list, banning it on state-owned devices and networks and on personal devices used for state business. · https://gov.texas.gov/news/post/governor-abbott-announces-ban-on-chinese-ai-social-media-apps\n2025-02-04 · Department of Home Affairs, Australian Government (PSPF Direction 001-2025) · Required Australian Government entities to prevent the access, use or installation of DeepSeek products, applications and web services on all government systems and devices, and to remove existing instances. · https://www.protectivesecurity.gov.au/publications-library/direction-001-2025-deepseek-products-applications-and-web-services\n2025-02-10 · Governor of New York (US state) · Banned downloading the DeepSeek app on ITS-managed state government devices and networks. · https://www.governor.ny.gov/news/governor-hochul-issues-statewide-ban-deepseek-artificial-intelligence-government-devices-and\n2025-02-11 · European Data Protection Board (EDPB) · At its plenary, extended the ChatGPT task force to cover AI enforcement and named it 'the forum for coordination on DeepSeek'. · http://www.edpb.europa.eu/system/files/2025-03/20250211finalminutes102ndplenary_en.pdf\n2025-02-11 · Governor of Virginia, Executive Order 46 (US state) · Banned downloading or using DeepSeek on state-issued devices and on state-run networks. · https://www.vdot.virginia.gov/media/vdotvirginiagov/doing-business/business-opportunities/consultants/Governor-Glenn-Youngkin-Bans-DeepSeek-AI_acc.pdf\n2025-02-17 · Personal Information Protection Commission (South Korea) · Announced that DeepSeek had suspended new app downloads in Korea from 15 February 2025, following a PIPC recommendation, while it worked to comply with PIPA. The PIPC advised users not to enter personal information in the meantime. · https://www.pipc.go.kr/eng/user/ltn/new/noticeDetail.do?bbsId=BBSMSTR_000000000001&nttId=2784\n2025-03-04 · Governor of South Dakota / Bureau of Information and Telecommunications (US state) · Banned DeepSeek on state devices and on state employees' personal devices during state time. · https://news.sd.gov/news?id=news_kb_article_view&sys_id=27a0845247c8aa1022dc4080236d4369\n2025-03-06 · Governor of Tennessee (US state) · Banned DeepSeek (and Manus) on the Tennessee state network. · https://www.tn.gov/governor/news/2025/3/6/gov--lee-bans-manus--deepseek-ai-platforms-on-tennessee-state-network.html\n2025-03-06 · Governor of Arkansas (US state) · Blocked DeepSeek on executive-branch devices. · https://governor.arkansas.gov/news_post/governor-sanders-blocks-deepseek-rednote-and-lemon8-from-executive-branch-devices/\n2025-03-21 · Governor of Oklahoma (US state) · Banned DeepSeek on all state-owned devices, citing among other reasons that user data is stored in China. · https://oklahoma.gov/governor/newsroom/newsroom/2025/-governor-stitt-bans-deepseek-on-all-state-owned-devices-due-to-.html\n2025-04-24 · Personal Information Protection Commission (South Korea) · Issued corrective recommendations after its examination. It found undisclosed transfers to China and the US (including user prompts sent to Beijing Volcano Engine) and no training opt-out before 17 March 2025. It ordered the transferred prompts destroyed, a Korean-language policy, a domestic agent and stronger safeguards. · https://www.pipc.go.kr/eng/user/ltn/new/noticeDetail.do?bbsId=BBSMSTR_000000000001&nttId=2819\n2025-06-27 · Berlin Commissioner for Data Protection and Freedom of Information (Germany) · Reported the DeepSeek apps to Apple and Google as illegal content under DSA Art. 16, over unlawful transfers of data to China (GDPR Art. 46(1)). This followed a 6 May 2025 demand that DeepSeek fix the problem, which DeepSeek did not meet. · https://www.datenschutz-berlin.de/pressemitteilung/berliner-datenschutzbeauftragte-meldet-ki-app-deepseek-in-deutschland-bei-apple-und-google-als-rechtswidrigen-inhalt/\n2025-12-16 · Autorità Garante della Concorrenza e del Mercato (Italy, consumer protection) · Closed its unfair-practice case PS12942, opened 2 April 2025 over insufficient warnings about hallucinations. The case ended with binding commitments and no finding of infringement: Italian-language disclaimers and translated terms. The closure was announced on 30 April 2026. · https://en.agcm.it/en/media/press-releases/2024/4/PS12942-PS12968-PS12973","incidents":null,"privacy_url":"https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html","terms_url":"https://cdn.deepseek.com/policies/en-US/deepseek-terms-of-use.html","help_url":null,"checked":"2026-09-30","sources":"DeepSeek Privacy Policy (last update Feb 10, 2026) · https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html\nDeepSeek Terms of Use (last update Mar 27, 2026) · https://cdn.deepseek.com/policies/en-US/deepseek-terms-of-use.html\nModel Mechanism and Training Methods of DeepSeek · https://cdn.deepseek.com/policies/en-US/model-algorithm-disclosure.html\nDeepSeek Open Platform Terms of Service (effective Apr 29, 2026) · https://cdn.deepseek.com/policies/en-US/deepseek-open-platform-terms-of-service.html\nGarante press release 28 Jan 2025 · https://www.gpdp.it/web/guest/home/docweb/-/docweb-display/docweb/10096856\nGarante press release 30 Jan 2025 · https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10097450\nGarante decision 30 Jan 2025 [10098477] · https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10098477\nPIPC press release 17/18 Feb 2025 · https://www.pipc.go.kr/eng/user/ltn/new/noticeDetail.do?bbsId=BBSMSTR_000000000001&nttId=2784\nPIPC press release 24 Apr 2025 (EN) · https://www.pipc.go.kr/eng/user/ltn/new/noticeDetail.do?bbsId=BBSMSTR_000000000001&nttId=2819\nPIPC press release 24 Apr 2025 (KO) · https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=C020010000&nttId=11145\nBerlin DPA press release 27 Jun 2025 · https://www.datenschutz-berlin.de/pressemitteilung/berliner-datenschutzbeauftragte-meldet-ki-app-deepseek-in-deutschland-bei-apple-und-google-als-rechtswidrigen-inhalt/\nEDPB 102nd plenary minutes (11 Feb 2025) · http://www.edpb.europa.eu/system/files/2025-03/20250211finalminutes102ndplenary_en.pdf\nEDPB press release 12 Feb 2025 · https://www.edpb.europa.eu/news/news/2025/edpb-adopts-statement-age-assurance-creates-task-force-ai-enforcement-and-gives_ga\nAustralia PSPF Direction 001-2025 · https://www.protectivesecurity.gov.au/publications-library/direction-001-2025-deepseek-products-applications-and-web-services\nTexas Governor press release · https://gov.texas.gov/news/post/governor-abbott-announces-ban-on-chinese-ai-social-media-apps\nTexas DIR notice 31 Jan 2025 · https://dir.texas.gov/news/governor-abbott-announces-ban-chinese-ai-social-media-apps\nNew York Governor press release 10 Feb 2025 · https://www.governor.ny.gov/news/governor-hochul-issues-statewide-ban-deepseek-artificial-intelligence-government-devices-and\nVirginia Executive Order 46 (PDF on vdot.virginia.gov) · https://www.vdot.virginia.gov/media/vdotvirginiagov/doing-business/business-opportunities/consultants/Governor-Glenn-Youngkin-Bans-DeepSeek-AI_acc.pdf\nAGCM press release 30 Apr 2026 · https://en.agcm.it/en/media/press-releases/2024/4/PS12942-PS12968-PS12973\nAGCM decision no. 31784 (PS12942) · https://www.agcm.it/dotcmsdoc/allegati-news/PS12942_acc.%20imp.%2Bchius..pdf"}},{"slug":"gemini","name":"Gemini","path":"/ai-privacy/gemini","category":null,"updatedAt":"2026-09-30T10:34:56.407Z","fields":{"brand":"Google","company":"Google LLC; Google Ireland Limited in the EEA and Switzerland","company_country":"United States","trains_default":"Yes, unless you opt out","training_detail":"With Keep Activity on (default for users 18+), Google uses your Gemini Apps activity \"to provide, develop, and improve its services (including training generative AI models)\", and a subset of chats is reviewed by humans. Audio and Gemini Live video/screenshares are not used for improvement by default (separate opt-in). Temporary chats are never used for training. Your Gemini settings \"don't control processing of your chats to create anonymized data to improve Google services.\"","opt_out":"gemini.google.com > Settings & help > Activity > near the top, click On > \"Turn off\" or \"Turn off and delete activity\" (or myactivity.google.com/product/gemini). With Keep Activity off, future chats are not used for training unless you send feedback, but are still kept for 72 hours.","business_plans":"Workspace (work/school) chats and uploads in the Gemini app \"won't be reviewed by human reviewers or otherwise used to train generative AI models outside of your domain without your permission.\" Paid Gemini API: Google \"doesn't use your prompts... or responses to improve our products\". Unpaid API/AI Studio content is used to improve products.","retention":"Gemini Apps Activity auto-deletes after 18 months by default; you can change this to 3 or 36 months or turn auto-delete off. With Keep Activity off, chats are still kept with your account for 72 hours. Chats reviewed by human reviewers are kept, disconnected from your account, \"for up to three years\". Some usage data is kept until you delete your Google Account.","deleted_chats":"Deletion starts immediately: Google aims to remove activity from view at once and then begins deleting it from storage. Chats already reviewed by human reviewers \"are not deleted when you delete your activity\" and are kept up to 3 years. Deleting Gemini activity does not delete data saved in other Google services.","human_review":"Yes","human_review_detail":"Yes. \"A subset of chats are reviewed by human reviewers (including Google's trained service providers)\" to improve services and for safety. Chats are disconnected from your account before going to service providers. Reviewing for protection and safety continues even with Keep Activity off or in temporary chats. The notice says: \"Please don't enter confidential information that you wouldn't want a reviewer to see.\"","temporary_chat":true,"temporary_detail":"Temporary chat (next to New chat): does not appear in Gemini Apps Activity or recent chats, is not personalised and is not used to train Google's AI models. It is kept with your account for 72 hours. Available only on personal accounts in the Gemini web and mobile apps.","data_location":"Google's privacy policy: \"We maintain servers around the world and your information may be processed on servers located outside of the country where you live.\" No Gemini-specific data location is stated for consumers.","min_age":13,"min_age_note":"13 (or the applicable age in your country) for personal accounts. Under-13s can use it via Family Link, a parent-supervised account (not in the EEA, Switzerland or UK). Work accounts require 18+, and Google AI paid plans require 18+ in the EEA, Switzerland and UK.","ads":"No","ads_detail":"\"Your Gemini Apps chats are not being used to show you ads. If this changes, we will clearly communicate it to you.\"","security":"Google privacy policy: \"We use encryption to keep your data private while in transit\"; access is restricted to employees, contractors and agents who need it. Google reports that the Gemini app (Workspace context) has SOC 1/2/3, ISO 9001, ISO/IEC 27001, 27701, 27017, 27018 and 42001, FedRAMP High and HIPAA support. These are stated for Gemini in Workspace and the Gemini app for business customers, not specifically for consumer accounts. Trust page: https://knowledge.workspace.google.com/admin/generative-ai/generative-ai-in-google-workspace-privacy-hub","regulator_count":2,"regulator_actions":"2024-09-12 · Data Protection Commission (Ireland) · Opened a cross-border statutory inquiry into Google Ireland Limited over whether it did a Data Protection Impact Assessment before processing EU/EEA personal data to develop its foundation model PaLM 2. This concerns model development, not the Gemini app directly. · https://www.dataprotection.ie/en/news-media/press-releases/data-protection-commission-launches-inquiry-google-ai-model\n2025-09-11 · US Federal Trade Commission · Issued 6(b) orders to seven companies, including Alphabet, Inc., for a study of AI chatbots acting as companions and their effects on children and teens. This is a study, not an enforcement action. · https://www.ftc.gov/news-events/news/press-releases/2025/09/ftc-launches-inquiry-ai-chatbots-acting-companions","incidents":null,"privacy_url":"https://support.google.com/gemini/answer/13594961?hl=en","terms_url":"https://policies.google.com/terms","help_url":"https://support.google.com/gemini/answer/13278892?hl=en","checked":"2026-09-30","sources":"Gemini Apps Privacy Hub and Privacy Notice (hub updated Jul 15, 2026; notice Jun 29, 2026) · https://support.google.com/gemini/answer/13594961?hl=en\nManage & delete your activity in Gemini Apps · https://support.google.com/gemini/answer/13278892?hl=en\nWhat you need to sign in to Gemini Apps (age requirements) · https://support.google.com/gemini/answer/13278668\nGemini Apps limits and upgrades for Google AI subscribers (18+ in EEA/CH/UK) · https://support.google.com/gemini/answer/16275805?hl=en-AW\nGuide your child's Gemini Apps experience (Family Link) · https://support.google.com/families/answer/16109150?hl=en\nUse Gemini Apps: start a temporary chat · https://support.google.com/gemini/answer/13275745?hl=en&co=GENIE.Platform%3DDesktop\nGoogle blog: Temporary chats and privacy controls (Aug 13, 2025) · https://blog.google/products-and-platforms/products/gemini/temporary-chats-privacy-controls/\nGoogle Privacy Policy · https://policies.google.com/privacy\nGenerative AI in Google Workspace Privacy Hub · https://knowledge.workspace.google.com/admin/generative-ai/generative-ai-in-google-workspace-privacy-hub\nGemini API Additional Terms of Service · https://ai.google.dev/gemini-api/terms\nIrish DPC press release, 12 Sep 2024 · https://www.dataprotection.ie/en/news-media/press-releases/data-protection-commission-launches-inquiry-google-ai-model\nFTC 6(b) AI companion chatbots press release · https://www.ftc.gov/news-events/news/press-releases/2025/09/ftc-launches-inquiry-ai-chatbots-acting-companions"}},{"slug":"grok","name":"Grok","path":"/ai-privacy/grok","category":null,"updatedAt":"2026-09-30T10:34:56.461Z","fields":{"brand":"xAI","company":"SpaceXAI LLC (formerly X.AI LLC) for the Grok apps and grok.com; Grok in X follows X's policies","company_country":"United States","trains_default":"Yes, unless you opt out","training_detail":"SpaceXAI 'may use your content and interactions with Grok (e.g., prompts, searches, and other materials you submit) along with Grok's responses to train our models'; Private Chat content is not used. Feedback you give may be used for training even after opting out, and signed-out users outside the EU/UK cannot opt out.","opt_out":"Mobile app: Settings > Data Controls > deselect 'Improve the model'. grok.com: Settings > Data > 'Improve the Model'. Opting out applies to new conversations. Grok on X: see X Help Center.","business_plans":"'We do not use content from our business and enterprise customers to improve our models'; API: 'xAI never trains on your API inputs or outputs without your explicit permission' (API data kept 30 days for abuse auditing).","retention":"'You can keep your data on your SpaceXAI account for as long as you wish'; otherwise retained 'as long as reasonably necessary' for the purposes in the privacy policy.","deleted_chats":"Deleted conversations (or a deleted account) are removed within 30 days, unless kept for legal, compliance or safety reasons or already de-identified/pseudonymized and disassociated from your account.","human_review":"Yes","human_review_detail":"Yes. 'A limited number of our authorized personnel may review your conversations with Grok' for purposes including improving model performance, investigating misuse and legal compliance.","temporary_chat":true,"temporary_detail":"Private Chat (ghost icon): not shown in history, not used for training, deleted from SpaceXAI systems within 30 days (unless needed for legal, compliance or safety reasons). Not available in Build mode.","data_location":"Europe addendum: 'We process all of your personal information in the United States, where we maintain our primary data centers.'","min_age":13,"min_age_note":"13 (or the minimum age in your country); ages 13-17 need parent/guardian permission","ads":"Not stated","ads_detail":"FAQ: 'We do not sell your data or share it with third parties for marketing or advertising purposes.' The privacy policy also says cookies may be used to 'deliver relevant content and targeted advertising'; use of chat content for ads is not addressed directly.","security":"SOC 2 Type 2: xAI's developer security FAQ says 'We are SOC 2 Type 2 compliant' (details in an NDA-gated Trust Center); API data encrypted at rest. See https://docs.x.ai/developers/faq/security and https://x.ai/security.","regulator_count":4,"regulator_actions":"2025-04-11 · Irish Data Protection Commission · Opened a GDPR inquiry into X Internet Unlimited Company over whether EU/EEA users' public X posts were lawfully processed to train the Grok models. · https://www.dataprotection.ie/en/news-media/latest-news/data-protection-commission-announces-commencement-inquiry-x-internet-unlimited-company-xiuc\n2026-01-26 · European Commission · Opened formal Digital Services Act proceedings against X over the risks of deploying Grok in X, including manipulated sexually explicit images and possible child sexual abuse material. · https://ec.europa.eu/commission/presscorner/api/files/document/print/en/ip_26_203/IP_26_203_EN.pdf\n2026-02-03 · UK Information Commissioner's Office · Opened formal investigations into X Internet Unlimited Company and X.AI LLC over Grok's processing of personal data and its potential to produce harmful sexualised images and video. · https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/02/ico-announces-investigation-into-grok\n2026-02-17 · Irish Data Protection Commission · Opened a large-scale GDPR inquiry into X Internet Unlimited Company over non-consensual intimate or sexualised images created with Grok on the X platform. · https://www.dataprotection.ie/en/news-media/press-releases/data-protection-commission-opens-investigation-x-xiuc","incidents":null,"privacy_url":"https://x.ai/privacy-policy","terms_url":"https://x.ai/terms-of-service","help_url":"https://x.ai/legal/faq","checked":"2026-09-30","sources":"SpaceXAI Privacy Policy (effective Aug 24, 2026) · https://x.ai/privacy-policy\nSpaceXAI Consumer FAQs · https://x.ai/legal/faq\nSpaceXAI Terms of Service - Consumer (effective Sep 1, 2026) · https://x.ai/terms-of-service\nSpaceXAI Europe Privacy Policy Addendum · https://x.ai/legal/europe-privacy-policy-addendum\nxAI developer security FAQ · https://docs.x.ai/developers/faq/security\nSpaceXAI Security page · https://x.ai/security\nDPC inquiry announcement (11 Apr 2025) · https://www.dataprotection.ie/en/news-media/latest-news/data-protection-commission-announces-commencement-inquiry-x-internet-unlimited-company-xiuc\nDPC inquiry announcement (17 Feb 2026) · https://www.dataprotection.ie/en/news-media/press-releases/data-protection-commission-opens-investigation-x-xiuc\nICO announces investigation into Grok (3 Feb 2026) · https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/02/ico-announces-investigation-into-grok\nEuropean Commission press release IP/26/203 (26 Jan 2026) · https://ec.europa.eu/commission/presscorner/api/files/document/print/en/ip_26_203/IP_26_203_EN.pdf"}},{"slug":"meta-ai","name":"Meta AI","path":"/ai-privacy/meta-ai","category":null,"updatedAt":"2026-09-30T10:34:56.518Z","fields":{"brand":"Meta","company":"Meta Platforms, Inc.; Meta Platforms Ireland Limited for the European Region","company_country":"United States","trains_default":"Yes, no opt-out for chats","training_detail":"'Meta uses your interactions with AIs to improve AI at Meta'; the Privacy Center says messages to AI chats, questions and images you ask Meta AI to imagine 'can be used to train AI models'. Meta says it does not train on private messages with friends and family unless you or someone in the chat shares them with its AI.","opt_out":"Meta describes no setting to stop AI chats being used for training. Users in the EU and UK can file an objection through Meta's Privacy Center forms, which mainly cover public posts.","business_plans":null,"retention":"No specific period for AI chats. The Meta Privacy Policy says 'We keep information as long as we need it' to provide products, comply with legal obligations or protect interests, decided 'on a case-by-case basis'.","deleted_chats":"Meta AI app: Menu > Settings > Data & privacy > Manage your information > 'Delete all chats and media'; deleted chats no longer appear in History or Media. In Messenger/Instagram/WhatsApp, '/reset-ai' deletes the AI's copy of your messages. No server-side deletion timeframe stated for chats; deleting a Facebook account 'may take up to 90 days'.","human_review":"Yes","human_review_detail":"Yes. AI Terms: 'In some cases, Meta will review your interactions with AIs, including the content of your conversations', and this review 'may be automated or manual (human)'. Chats using WhatsApp Private Processing cannot be read by Meta.","temporary_chat":false,"temporary_detail":null,"data_location":"Meta shares information it collects 'globally, both internally across our offices and data centres and externally with our service providers'; no specific storage location stated for AI chats.","min_age":13,"min_age_note":"13 (or a higher age required in your country or territory)","ads":"Yes","ads_detail":"Yes, depending on region. Since December 16, 2025 Meta uses interactions with its AI features to personalize content and ad recommendations ('rolling out ... in most regions'), but says it does not use topics like religious views, sexual orientation, political views, health, racial or ethnic origin, philosophical beliefs or trade union membership to show ads. Help Center: 'Depending on your region, your interactions with AI products can be used to personalize content and ads.' Ads Preferences adjust the ads you see.","security":"Meta states that for AI chats using Private Processing (WhatsApp), 'Meta cannot read or access the messages you have shared'; Private Processing uses end-to-end encryption to Trusted Execution Environments. No certification (SOC 2/ISO) claimed for Meta AI found.","regulator_count":2,"regulator_actions":"2024-07-02 · Brazil National Data Protection Authority (ANPD) · Issued a preventive measure ordering Meta to suspend, in Brazil, its privacy-policy provisions and processing of personal data for training generative AI, with a daily fine of R$50,000 for non-compliance. · https://www.gov.br/anpd/pt-br/assuntos/noticias/anpd-determina-suspensao-cautelar-do-tratamento-de-dados-pessoais-para-treinamento-da-ia-da-meta\n2025-05-21 · Irish Data Protection Commission · Statement on Meta AI: after DPC engagement Meta paused (June 2024) and then changed its plan to train LLMs on EU adults' public Facebook/Instagram content, and the DPC required a report on the safeguards' efficacy (expected October 2025). · https://www.dataprotection.ie/en/news-media/latest-news/dpc-statement-meta-ai","incidents":null,"privacy_url":"https://www.facebook.com/privacy/policy/","terms_url":"https://www.facebook.com/legal/ai-terms","help_url":"https://www.meta.com/help/artificial-intelligence/1771195753735844/","checked":"2026-09-30","sources":"Meta AIs Terms of Service · https://www.facebook.com/legal/ai-terms\nMeta Privacy Policy · https://www.facebook.com/privacy/policy/\nMeta Privacy Policy (en-GB, cross-border transfers) · https://en-gb.facebook.com/privacy/policy/?section_id=2-HowDoWeUse\nPrivacy Center: Your interactions with AI features · https://www.facebook.com/privacy/dialog/your-interactions-with-ai-features/\nPrivacy Center: How Meta uses information for generative AI models · https://www.facebook.com/privacy/genai/\nMeta Help Center: Manage your information on Meta AI and Vibes · https://www.meta.com/help/artificial-intelligence/1771195753735844/\nMeta Help Center: Remove posts, chats and media from Meta AI and Vibes · https://www.meta.com/help/artificial-intelligence/2457110494637611/\nMeta Newsroom: Improving Your Recommendations on Our Apps With AI at Meta (Oct 1, 2025) · https://about.fb.com/news/2025/10/improving-your-recommendations-apps-ai-meta/\nMeta Newsroom: Privacy Matters: Meta's Generative AI Features (updated Nov 21, 2025) · https://about.fb.com/news/2023/09/privacy-matters-metas-generative-ai-features/\nMeta Transparency Center: AI at Meta training data · https://transparency.meta.com/features/ai-at-meta-training-data/\nPrivate Processing for WhatsApp whitepaper · https://ai.meta.com/static-resource/private-processing-technical-whitepaper\nFacebook Help: Permanently delete your account · https://www.facebook.com/help/224562897555674\nANPD preventive measure (2 Jul 2024) · https://www.gov.br/anpd/pt-br/assuntos/noticias/anpd-determina-suspensao-cautelar-do-tratamento-de-dados-pessoais-para-treinamento-da-ia-da-meta\nDPC statement on Meta AI (21 May 2025) · https://www.dataprotection.ie/en/news-media/latest-news/dpc-statement-meta-ai\nHamburg DPA press release on Meta AI training (27 May 2025) · https://datenschutz-hamburg.de/fileadmin/user_upload/HmbBfDI/Pressemitteilungen/2025/250527_PM_Meta_starts_AI_training_with_personal_data_EN.pdf"}},{"slug":"copilot","name":"Microsoft Copilot","path":"/ai-privacy/copilot","category":null,"updatedAt":"2026-09-30T10:34:56.304Z","fields":{"brand":"Microsoft","company":"Microsoft Corporation; Microsoft Ireland Operations Limited for the EEA, UK and Switzerland","company_country":"United States","trains_default":"No","training_detail":"For the updated Copilot app (from August 18, 2026) Microsoft states: \"Prompts, responses, and your file contents when using the Microsoft Copilot app aren't used to train foundation models.\" Optional feedback may be used to improve Copilot but not to train foundation models. (Older app versions: conversations used for training unless you opt out, with exclusions e.g. under-18s, signed-out users, and users in Brazil, China, Israel, Nigeria, South Korea, Vietnam.)","opt_out":"Not needed in the updated app (no training on prompts/responses stated). Legacy app: profile icon > profile name > Privacy > 'Training on conversation activity' and 'Training on voice conversations' (copilot.com); Settings > Privacy on Windows/macOS; menu > profile icon > Account > Privacy on mobile.","business_plans":"Copilot with a work/school (Entra) account is out of scope of the consumer terms; for Microsoft 365 Copilot, stored interaction data 'isn't used to train foundation LLMs'.","retention":"Updated app: no retention period stated; chats are kept so you can revisit them until you delete them. Legacy app/FAQ: 'By default, we store conversation activity for 18 months.' Uploaded files stored 'for up to 30 days and then automatically deleted'.","deleted_chats":"You can delete individual chats (Chats list > ... More > Delete) or all activity history in the Microsoft privacy dashboard; Microsoft does not state a timeframe for removal from its systems after deletion.","human_review":"Yes","human_review_detail":"Yes. Terms: 'Copilot may include both automated and manual (human) processing of data.' Young-people page: 'Humans may review your conversations in Copilot for safety, legal, product improvement, or troubleshooting.' Legacy FAQ: an opt-out of human review 'is not available'.","temporary_chat":false,"temporary_detail":null,"data_location":"Microsoft may store and process personal data 'in your region, in the United States, and in any other jurisdiction' where it or its providers operate; 'typically, the primary storage location is in your region or in the United States'.","min_age":13,"min_age_note":"13 (higher in some countries); a Microsoft account is required","ads":"Yes","ads_detail":"Yes, for users without a Microsoft 365 subscription. Generic ads are chosen from the current conversation; personalized ads 'might use your chat history, saved memories' and other data. Toggle: Settings > Personalization > 'Allow ads personalization'. No personalized ads for under-18s.","security":null,"regulator_count":0,"regulator_actions":null,"incidents":null,"privacy_url":"https://www.microsoft.com/en-us/privacy/privacystatement","terms_url":"https://www.microsoft.com/en-us/microsoft-copilot/for-individuals/termsofuse","help_url":"https://support.microsoft.com/en-us/privacy/microsoft-copilot/privacy-controls","checked":"2026-09-30","sources":"Copilot for individuals: your privacy controls and choices (updated app, Aug 2026) · https://support.microsoft.com/en-us/privacy/microsoft-copilot/privacy-controls\nCopilot for individuals: your activity history · https://support.microsoft.com/en-us/privacy/microsoft-copilot/activity-history\nCopilot for individuals: Copilot for young people · https://support.microsoft.com/en-us/privacy/microsoft-copilot/young-people\nCopilot for individuals: overview · https://support.microsoft.com/en-us/privacy/microsoft-copilot/overview\nMicrosoft Copilot Supplemental Terms of Use (effective Aug 18, 2026) · https://www.microsoft.com/en-us/microsoft-copilot/for-individuals/termsofuse\nMicrosoft Privacy Statement (controllers) · https://www.microsoft.com/en-us/privacy/privacystatement\nMicrosoft Privacy Statement (data storage locations) · https://www.microsoft.com/en-ca/privacy/privacystatement\nMicrosoft Copilot privacy controls (legacy app) · https://support.microsoft.com/en-US/microsoft-copilot/microsoft-copilot-privacy-controls\nPrivacy FAQ for Microsoft Copilot (legacy app) · https://support.microsoft.com/en-us/microsoft-copilot/privacy-faq-for-microsoft-copilot\nCopilot privacy and security (for individuals) · https://www.microsoft.com/en-us/microsoft-copilot/for-individuals/privacy\nManage your Copilot activity history in the privacy dashboard · https://support.microsoft.com/en-us/privacy/manage-your-copilot-activity-history-in-the-privacy-dashboard\nData, privacy and security for Microsoft 365 Copilot · https://learn.microsoft.com/en-us/microsoft-365/copilot/microsoft-365-copilot-privacy\nMSRC CVE-2026-24301 · https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24301\nMSRC CVE-2026-55946 · https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55946"}},{"slug":"mistral-le-chat","name":"Mistral Vibe (formerly Le Chat)","path":"/ai-privacy/mistral-le-chat","category":null,"updatedAt":"2026-09-30T10:34:56.615Z","fields":{"brand":"Mistral AI","company":"Mistral AI (Paris, France)","company_country":"France","trains_default":"Yes, unless you opt out","training_detail":"Your inputs and outputs, including uploaded documents, may be used to train Mistral's models on the basis of 'legitimate interest', 'subject to your opt-out'. Anything you rate with thumbs up or down is used for training, together with the related input and output, even if you have opted out. Third-party web-search content, connector data and Libraries documents are not used for training.","opt_out":"Web: Admin panel → Manage → Vibe → Privacy → turn off \"Allow your interactions to be used to train our models\". iOS/Android app: Settings → Account → Data & Account Controls → untick \"Enable data sharing\". The Vibe and API toggles are separate.","business_plans":"Enterprise customers are opted out by default. Team admins can turn training off for the whole organisation. Mistral's docs say 'Vibe (Pro, Team, Enterprise): conversations aren't used for model training by default' and that API data isn't used for training. The help center and the DPA, however, describe an API opt-out toggle ('Anonymous improvement data') and training 'unless Customer is or has opted-out'.","retention":"'We keep your Input and Output until you delete your account or until you delete the conversation from Vibe.' After an account is deleted, Mistral keeps account data for 1 year, civil identity data for 5 years and technical logs for 1 rolling year. Team and Enterprise admins can set automatic chat deletion (30 days to 1 year).","deleted_chats":"Deleting a chat is final on your side. Conversations are removed from Mistral's systems 'typically after a short grace period to prevent accidental data loss, and for monitoring and legal retention purposes'. Some data may be kept longer under the privacy policy. Deleting your account is 'permanent and irreversible'.","human_review":"Limited","human_review_detail":"Limited. 'People other than yourself may occasionally view your conversations', for example authorized, competent team members when you report content. The privacy policy says authorized team members access data 'strictly to perform their jobs'. The Terms say automated moderation tools support 'human review where required by law'. Mistral may also use your data for 'debugging, assessing, reviewing' performance.","temporary_chat":false,"temporary_detail":null,"data_location":"'By default, your data is hosted in the European Union.' Depending on the feature, data may be temporarily transferred outside the EU to the subprocessors listed in the Trust Center, under SCCs. API users can choose a US endpoint.","min_age":13,"min_age_note":"13, with parental or guardian permission where required for minors (EEA consumer Terms).","ads":"Not stated","ads_detail":"The privacy policy doesn't say whether chat content is used for ads. Its US section says Mistral has not 'sold,' 'shared,' or engaged in 'targeted advertising' with consumers' personal data in the preceding 12 months.","security":"Complies with SOC 2 Type II and ISO 27001/27701 (help center). Encrypts data at rest with AES-256 and in transit with TLS 1.2+. Trust Center: trust.mistral.ai.","regulator_count":1,"regulator_actions":"2026-02-17 · Autorità Garante della Concorrenza e del Mercato (Italy, consumer protection) · Closed case PS12968, opened 3 June 2025 over insufficient warnings about hallucinations in Le Chat. The case ended with binding commitments and no finding of infringement: permanent Italian disclaimers and translated Terms. The closure was announced on 30 April 2026. · https://en.agcm.it/en/media/press-releases/2024/4/PS12942-PS12968-PS12973","incidents":null,"privacy_url":"https://legal.mistral.ai/terms/privacy-policy","terms_url":"https://legal.mistral.ai/terms/eu-consumers-terms-of-service/","help_url":"https://help.mistral.ai/en/articles/455207-can-i-opt-out-of-my-input-or-output-data-being-used-for-training","checked":"2026-09-30","sources":"Mistral AI Privacy Policy (effective July 27, 2026) · https://legal.mistral.ai/terms/privacy-policy\nTerms of Service for consumers in the EEA (effective Aug 7, 2026) · https://legal.mistral.ai/terms/eu-consumers-terms-of-service/\nHelp: Can I opt out of my input or output data being used for training? · https://help.mistral.ai/en/articles/455207-can-i-opt-out-of-my-input-or-output-data-being-used-for-training\nDocs: Privacy and data controls · https://docs.mistral.ai/admin/monitor-comply/privacy-data-controls\nHelp: Can I activate Zero Data Retention (ZDR)? · https://help.mistral.ai/en/articles/347612-can-i-activate-zero-data-retention-zdr\nHelp: Can I delete a chat conversation? · https://help.mistral.ai/en/articles/347613-can-i-delete-a-chat-conversation\nHelp: Can other people view my conversations? · https://help.mistral.ai/en/articles/347632-can-other-people-view-my-conversations\nHelp: Where do you store my data? · https://help.mistral.ai/en/articles/347629-where-do-you-store-my-data-or-my-organization-s-data\nHelp: Do you have SOC 2 or ISO 27001 certification? · https://help.mistral.ai/en/articles/347638-do-you-have-soc-2-or-iso-27001-certification\nHelp: Encryption in transit and at rest · https://help.mistral.ai/en/articles/347626-how-does-mistral-ensure-that-my-data-remains-encrypted-and-secure-in-transit-and-at-rest\nData Processing Addendum · https://legal.mistral.ai/terms/data-processing-addendum/\nHelp: Le Chat is now Vibe · https://help.mistral.ai/en/articles/682992-le-chat-is-now-vibe\nMistral news: Vibe gets to work (May 28, 2026) · https://mistral.ai/news/vibe-agent/\nMistral Trust Center · https://trust.mistral.ai/\nSecurity advisory MAI-2026-002 · https://docs.mistral.ai/resources/security-advisories/MAI-2026-002\nAGCM press release 30 Apr 2026 · https://en.agcm.it/en/media/press-releases/2024/4/PS12942-PS12968-PS12973\nAGCM decision no. 31864 (PS12968, Mistral) · https://agcm.it/dotcmsCustom/tc/2031/3/getDominoAttach?urlStr=81.126.91.44%3A8080%2FC12560D000291394%2F0%2F845CF99A210DABE4C1258DB50035CA71%2F%24File%2Fp31864.pdf"}},{"slug":"perplexity","name":"Perplexity","path":"/ai-privacy/perplexity","category":null,"updatedAt":"2026-09-30T10:34:56.673Z","fields":{"brand":"Perplexity","company":"Perplexity AI, Inc.","company_country":"United States","trains_default":"Yes, unless you opt out","training_detail":"Search queries and feedback are used to improve Perplexity's own AI models (Sonar) unless you turn off the AI data setting. Memory content may also be used. Content from linked email accounts is never used for training. Perplexity says its agreements with third-party model providers such as OpenAI and Anthropic prohibit them from training on Perplexity data.","opt_out":"Settings → Preferences → Artificial Intelligence → turn off \"AI Data Retention\" (Memory help article). Another help article calls it the \"AI Data Usage\" toggle under Settings. The privacy policy says you can opt out 'in your settings page if you are logged into the Services'.","business_plans":"'Enterprise data is never used to train or fine-tune Perplexity’s models'. The DPA says Personal Data 'will not be used for training'. The Chat Completions API has a 'Zero Data Retention Policy' and customer data is not used to train models.","retention":"'Sessions are stored in the History indefinitely' until you delete them. The privacy notice says personal data is kept 'only as long as necessary'. Uploaded files are kept for 30 days by default. Threads created while logged out expire after 14 days.","deleted_chats":"A deleted session can't be retrieved. If you delete your account, your 'account and personal data will be permanently deleted within 30 days'. Signing back in before then cancels the deletion. The notice adds that data may be kept where legally required, and that historical data may stay in backups.","human_review":"Not stated","human_review_detail":"Perplexity's documents do not say whether employees or contractors read conversations.","temporary_chat":true,"temporary_detail":"Incognito mode. 'Searches in incognito mode are never stored', and 'all incognito sessions expire within 24 hours and are not recoverable'. Memory is always off in incognito.","data_location":"The United States and other countries. The February 2026 policy says 'we have servers for the Service in the US'. The July 2026 notice says data is transferred to countries 'including, but not limited to, the United States'. For EU/UK transfers Perplexity relies on the EU-U.S. Data Privacy Framework and SCCs.","min_age":13,"min_age_note":"13. Minors between 13 and the age of majority need a parent or guardian to accept the Terms on their behalf.","ads":"No","ads_detail":"The July 2026 notice says Perplexity does 'not sell your personal data or send your queries, prompts, or conversation content to advertisers'. Its cookie banner says it does not use tracking technologies to sell third-party ads on its services. It does share identifiers and usage/network data with advertising partners (CCPA table) and uses them for ad measurement. You can opt out through cookie settings or GPC.","security":"SOC 2 Type 2 certified by independent auditors (security page). The API docs also list a 2025 HIPAA gap assessment and CAIQlite. Traffic is encrypted with SSL/TLS through Cloudflare. The Enterprise blog claims encryption at rest and in transit. Trust center: trust.perplexity.ai.","regulator_count":1,"regulator_actions":"2026-07-14 · ZAK – Commission for Licensing and Supervision of the German state media authorities (proceedings led by mabb and MA HSH) · Issued a first decision finding that Perplexity's AI chatbot is subject to German media law as a 'media intermediary', with transparency and diversity duties. This is a media-law ruling, not a privacy one, and Perplexity can appeal. · https://medienanstalt-rlp.de/aktuelles/news/detail/zak-erlaesst-erstmalig-bescheide-gegen-ki-angebote-von-google-und-perplexity","incidents":null,"privacy_url":"https://www.perplexity.ai/hub/legal/privacy-notice","terms_url":"https://www.perplexity.ai/hub/legal/terms-of-service","help_url":"https://www.perplexity.ai/help-center/en/articles/10354855-what-data-does-perplexity-collect-about-me","checked":"2026-09-30","sources":"Perplexity Privacy Notice (last updated July 8, 2026) · https://www.perplexity.ai/hub/legal/privacy-notice\nPerplexity Privacy Policy (effective Feb 5, 2026) · https://www.perplexity.ai/hub/legal/privacy-policy\nPerplexity Terms of Service (Jan 23, 2026) · https://www.perplexity.ai/hub/legal/terms-of-service\nHelp: What data does Perplexity collect about me? · https://www.perplexity.ai/help-center/en/articles/10354855-what-data-does-perplexity-collect-about-me\nHelp: Account & Settings · https://www.perplexity.ai/help-center/en/articles/10352990-account-settings\nHelp: Memory · https://www.perplexity.ai/help-center/en/articles/10968016-memory\nHelp: Incognito Mode Troubleshooting · https://www.perplexity.ai/help-center/en/articles/12639758-incognito-mode-troubleshooting\nHelp: Where did my sessions go? · https://www.perplexity.ai/help-center/en/articles/12637451-where-did-my-threads-go\nHelp: What is a Session? · https://www.perplexity.ai/help-center/en/articles/10354769-what-is-a-thread\nHelp: Account Deletion · https://www.perplexity.ai/help-center/en/articles/10354879-account-deletion\nHelp: Are third-party model providers training on my data? · https://www.perplexity.ai/help-center/en/articles/10354963-are-third-party-model-providers-training-on-my-data\nHelp: Data retention and privacy for Enterprise organizations · https://www.perplexity.ai/help-center/en/articles/11187708-data-retention-and-privacy-for-enterprise-organizations-and-users\nPerplexity Data Processing Addendum · https://www.perplexity.ai/hub/legal/dpa\nAPI docs: Privacy & Security · https://docs.perplexity.ai/docs/resources/privacy-security.md\nPerplexity security page · https://www.perplexity.ai/hub/security\nPerplexity Trust Center · https://trust.perplexity.ai/\nMedienanstalt Rheinland-Pfalz: ZAK decisions, 14 Jul 2026 · https://medienanstalt-rlp.de/aktuelles/news/detail/zak-erlaesst-erstmalig-bescheide-gegen-ki-angebote-von-google-und-perplexity"}}]}