Know the enemy's filing system
What AI actually knows about you — and where each piece sits.
"Delete my data" fails when you aim at the wrong layer. Here's the full inventory of what an AI service holds on you, from verbatim transcripts to statistical ghosts.
Layer 1 — verbatim: your account and conversations
Everything you've typed, uploaded and dictated: chats, files, images, voice transcripts, plus account metadata (email, payment, device, IP-derived location). This is ordinary personal data on a server, and it's the layer with the strongest deletion rights. Delete a conversation and providers purge it from systems within ~30 days; delete the account and everything tied to it follows. If you do only one thing, audit this layer: open your chat list and read it as a stranger would.
Layer 2 — distilled: memory and personalization
Memory features convert conversations into standing facts — the difference between a transcript that mentions your divorce and a profile line that says "user is going through a divorce." ChatGPT has saved memories plus chat-history referencing; Gemini has Gemini Apps Activity and personalization; Claude offers project context; Grok and Copilot have their own variants. This layer is small, readable and fully deletable — clear it here, and see chatgptmemory.com for the mechanics.
Layer 3 — diffused: trained model weights
If your data was used for training (you didn't opt out, or it was scraped from the public web), its statistical patterns are spread across billions of parameters. Two honest facts follow. First: an individual private chat almost never becomes a retrievable memory in the model — memorization needs repetition, which is why famous people are "known" and you probably aren't. Second: whatever did make it in cannot be selectively deleted with today's technology. Machine unlearning is a research field, not a product. Regulators therefore accept output suppression — the provider filters what the model will say about you — as the practical remedy. That's what OpenAI's personal-data-removal form does. How to use it →
Layer 4 (bonus) — inferred: what was never said
Models and products also generate new data about you: inferred interests, demographics, emotional states, orientation, health status. Inferences are personal data under GDPR just like stated facts — often the most sensitive kind. They live partly in memory features (deletable) and partly in the moment-to-moment processing of your stored chats (deleted when the chats are). The sensitive-inferences guide walks through a concrete case.
Personal data inventory
What to look for before you delete anything.
Do a quick inventory first. It tells you which deletion lever to use and gives you evidence if you file a formal request.
Name, email, phone, location
Often appears in account data, pasted emails, resumes, support tickets and generated cover letters.
Employer, role, clients, secrets
Shows up in drafts, meeting notes, code snippets, sales emails and uploaded documents.
Partners, children, private conflicts
Can appear in relationship advice, school emails, travel planning and therapy-style prompts.
Symptoms, diagnoses, medication
High-risk special-category data. Delete chats and memory, then consider a formal erasure request.
Religion, politics, union views
May be inferred from questions, donations, drafts, posts or debate prompts.
Habits, fears, purchases, intentions
AI can infer patterns from repeated prompts even when you never state the conclusion directly.
Risk ranking
Not all AI knowledge about you is equally dangerous.
| Data type | Risk level | Why it matters | Best action |
|---|---|---|---|
| Old generic chats | Medium | May reveal interests and habits but usually low sensitivity. | Delete in batches; turn off training. |
| Saved memory profile | High | Condenses identity and preferences into a persistent, reusable profile. | Review, screenshot if needed, then clear memory and disable future memory. |
| Health, sex life, religion, politics | Very high | Special-category data under GDPR and high reputational or emotional risk. | Delete chats, clear memory, file erasure/objection request. |
| Company/client data | High | May create contractual, trade-secret or confidentiality problems. | Contain the account, file provider request, move team to governed workspace. |
| Public posts scraped by AI | Medium to high | Depends on whether posts include personal data, images or business content. | Remove at source, block crawlers, request output suppression. |
FAQ
Inventory questions.
Does ChatGPT keep a profile of me?
With Memory on, effectively yes — a plain-language list of facts distilled from your chats, plus optional referencing of your whole chat history. You can read the exact list at Settings → Personalization → Memory → Manage, which is the honest way to see 'your profile.'
Can AI companies see my deleted chats?
Deleted conversations are queued for permanent removal, typically completed within 30 days, unless a legal hold applies. Staff access to live chats is restricted and audited; some providers use limited human review of sampled conversations (Google discloses reviewed Gemini chats can be kept up to 3 years, stored separately from your account).
Does the model itself know my name?
Only if your name appeared often enough in training data (public figures, prolific posters) or you told it this session. A single private chat does not survive into model weights as a retrievable fact — memorization requires repetition. The bigger day-to-day risk is layers 1 and 2: stored chats and memory.
What does an AI infer that I never said?
Patterns: writing level, likely age bracket, profession, location hints, emotional state, and — from sensitive questions — health conditions or sexual orientation. Inference is covered by GDPR as personal data too; see the sensitive-inferences guide.