The formal route
How to apply for deletion — GDPR, CCPA, and every provider's front door.
Settings toggles are self-service housekeeping. A formal privacy request is different: it's on the record, it has legal deadlines, and it reaches data the dashboard doesn't show. Here's exactly where to file for each provider, and what to demand.
What to ask for (the four demands)
Every effective request asks for the same four things, in writing:
- Erasure of all personal data associated with your account and any data about you as a data subject (GDPR Art. 17 / CCPA §1798.105).
- Exclusion from training — past-tense confirmation of whether your data was used, and a forward-looking do-not-train flag.
- Output suppression — that the model must not generate personal data about you (this is the practical right-to-be-forgotten remedy for layer 3).
- Confirmation in writing, including what was deleted, what was retained and on what legal basis.
Copy-paste letters for all of this are on the template page.
Where to file, provider by provider
| Provider | Portal / channel | Notes |
|---|---|---|
| OpenAI | privacy.openai.com → "Make a Privacy Request" | Options include: download my data, do-not-train, delete account. Separately, the personal-data-removal form requests suppression of model outputs about you. |
| Anthropic | privacy.anthropic.com / in-product support | Account deletion removes associated data; deleted chats aren't used for training. EU users can invoke GDPR explicitly. |
| Google (Gemini) | Google privacy tools + Gemini Apps Activity; formal requests via Google's data-subject forms | Delete activity yourself first; use the form for erasure beyond self-service. Reviewed-conversation retention (≤3 years) is disclosed and hard to shortcut. |
| Microsoft (Copilot) | account.microsoft.com/privacy dashboard + Microsoft privacy request form | Dashboard clears activity; the form handles formal GDPR/CCPA erasure. |
| Meta AI | Meta Privacy Center → Data Subject Rights form | EU/UK objection to AI training is the strongest lever; US options are thinner. Persistence pays here. |
| xAI (Grok) | xAI privacy policy contact + X data settings | Pair the formal email with the X-side data-sharing opt-out so the pipeline is closed both ends. |
Timelines and escalation
GDPR: response within one month (extendable to three with notice). CCPA: 45 days (extendable once). Silence or refusal → send one follow-up citing the deadline → then complain to your DPA (EU: your national authority; UK: ICO) or state AG. Complaints are free and providers resolve most cases before regulators engage.
Special case: sensitive data
If your request involves health, sexuality, religion or similar special-category data (GDPR Art. 9) — say, chats that reveal your orientation or a diagnosis — say so in the request. It heightens the provider's obligations and your DPA's interest. The sensitive-inferences guide explains what happens to that class of data.
Make the request harder to ignore
Evidence and wording that improves your odds.
Give the provider matching account details
Use the account email, username, phone number if attached, workspace name, billing email and any alternate login method. Vague requests slow down verification.
Describe the exact content category
Say whether the issue is chat history, memory, uploads, voice transcripts, image prompts, public search results, workplace files or model outputs about you.
Use screenshots and dates
Include memory screenshots, chat titles, approximate dates, output examples, URLs and any request IDs from prior support tickets.
Ask under multiple rights at once
Combine access, deletion, objection to processing, restriction of processing and do-not-sell/share where relevant. It reduces room for narrow replies.
Force the retention explanation
Request a written list of anything retained, the retention period and the legal basis. This is especially important for abuse logs, legal holds and reviewed samples.
Use the statutory clock
Ask for confirmation within one month under GDPR/UK GDPR or within 45 days under CCPA/CPRA. Put the date in your follow-up.
Response decoder
What the provider's reply usually means.
| Reply language | Meaning | What to do next |
|---|---|---|
| "We deleted account data" | Usually covers account records, visible chats and associated stored content. | Ask whether memory, files, reviewed samples and training exclusion were also handled. |
| "We cannot delete model weights" | Normal. Providers generally cannot surgically remove one person's contribution from a trained model. | Ask for output suppression and future training exclusion instead of arguing about weights alone. |
| "Some data retained for legal/security reasons" | Could mean abuse logs, invoices, fraud prevention, tax records, litigation hold or safety review data. | Ask for category, retention period and legal basis. Escalate if the answer stays vague. |
| "We cannot verify your identity" | The request does not match an account or public data subject strongly enough. | Reply with account email, usernames, dates, URLs and screenshots. Do not send unnecessary ID documents unless required. |
| "We removed search/model outputs" | The provider likely applied suppression or removed a visible generated result. | Test again after a few days and document whether the same output reappears. |
FAQ
Formal request questions.
Who can use GDPR deletion rights?
Anyone in the EU/EEA or UK (UK GDPR). Article 17 gives a right to erasure of personal data; Article 21 a right to object to processing. Providers typically answer within one month.
What are my rights in the US?
California's CCPA/CPRA grants deletion, access and opt-out rights (45-day response window), and a dozen-plus other states now have similar laws. Providers generally extend one process to all US users for simplicity.
What can the provider actually do about the trained model?
Delete your account data and memory fully; exclude you from future training; and apply output suppression so the model won't produce information about you. What they cannot do is edit the weights. A regulator-accepted reality, not a dodge — ask for all three explicitly.
What if they ignore me?
Escalate: reply citing the statutory deadline, then complain to your data protection authority (EU/UK) or state attorney general (US). Free, effective, and providers know it — most stalls end at the word 'complaint.'