Know the enemy's filing system

What AI actually knows about you — and where each piece sits.

"Delete my data" fails when you aim at the wrong layer. Here's the full inventory of what an AI service holds on you, from verbatim transcripts to statistical ghosts.

Layer 1 — verbatim: your account and conversations

Everything you've typed, uploaded and dictated: chats, files, images, voice transcripts, plus account metadata (email, payment, device, IP-derived location). This is ordinary personal data on a server, and it's the layer with the strongest deletion rights. Delete a conversation and providers purge it from systems within ~30 days; delete the account and everything tied to it follows. If you do only one thing, audit this layer: open your chat list and read it as a stranger would.

Layer 2 — distilled: memory and personalization

Memory features convert conversations into standing facts — the difference between a transcript that mentions your divorce and a profile line that says "user is going through a divorce." ChatGPT has saved memories plus chat-history referencing; Gemini has Gemini Apps Activity and personalization; Claude offers project context; Grok and Copilot have their own variants. This layer is small, readable and fully deletable — clear it here, and see chatgptmemory.com for the mechanics.

Layer 3 — diffused: trained model weights

If your data was used for training (you didn't opt out, or it was scraped from the public web), its statistical patterns are spread across billions of parameters. Two honest facts follow. First: an individual private chat almost never becomes a retrievable memory in the model — memorization needs repetition, which is why famous people are "known" and you probably aren't. Second: whatever did make it in cannot be selectively deleted with today's technology. Machine unlearning is a research field, not a product. Regulators therefore accept output suppression — the provider filters what the model will say about you — as the practical remedy. That's what OpenAI's personal-data-removal form does. How to use it →

Layer 4 (bonus) — inferred: what was never said

Models and products also generate new data about you: inferred interests, demographics, emotional states, orientation, health status. Inferences are personal data under GDPR just like stated facts — often the most sensitive kind. They live partly in memory features (deletable) and partly in the moment-to-moment processing of your stored chats (deleted when the chats are). The sensitive-inferences guide walks through a concrete case.

The audit in practice: read your memory list (layer 2), skim your chat history (layer 1), assume the model itself doesn't know you personally (layer 3) unless you're publicly prominent — and clean in that order. Then shut the training tap so layer 3 never becomes your problem.

Personal data inventory

What to look for before you delete anything.

Do a quick inventory first. It tells you which deletion lever to use and gives you evidence if you file a formal request.

Identity

Name, email, phone, location

Often appears in account data, pasted emails, resumes, support tickets and generated cover letters.

Work

Employer, role, clients, secrets

Shows up in drafts, meeting notes, code snippets, sales emails and uploaded documents.

Family

Partners, children, private conflicts

Can appear in relationship advice, school emails, travel planning and therapy-style prompts.

Health

Symptoms, diagnoses, medication

High-risk special-category data. Delete chats and memory, then consider a formal erasure request.

Beliefs

Religion, politics, union views

May be inferred from questions, donations, drafts, posts or debate prompts.

Behavior

Habits, fears, purchases, intentions

AI can infer patterns from repeated prompts even when you never state the conclusion directly.

Risk ranking

Not all AI knowledge about you is equally dangerous.

Data typeRisk levelWhy it mattersBest action
Old generic chatsMediumMay reveal interests and habits but usually low sensitivity.Delete in batches; turn off training.
Saved memory profileHighCondenses identity and preferences into a persistent, reusable profile.Review, screenshot if needed, then clear memory and disable future memory.
Health, sex life, religion, politicsVery highSpecial-category data under GDPR and high reputational or emotional risk.Delete chats, clear memory, file erasure/objection request.
Company/client dataHighMay create contractual, trade-secret or confidentiality problems.Contain the account, file provider request, move team to governed workspace.
Public posts scraped by AIMedium to highDepends on whether posts include personal data, images or business content.Remove at source, block crawlers, request output suppression.

FAQ

Inventory questions.

Does ChatGPT keep a profile of me?

With Memory on, effectively yes — a plain-language list of facts distilled from your chats, plus optional referencing of your whole chat history. You can read the exact list at Settings → Personalization → Memory → Manage, which is the honest way to see 'your profile.'

Can AI companies see my deleted chats?

Deleted conversations are queued for permanent removal, typically completed within 30 days, unless a legal hold applies. Staff access to live chats is restricted and audited; some providers use limited human review of sampled conversations (Google discloses reviewed Gemini chats can be kept up to 3 years, stored separately from your account).

Does the model itself know my name?

Only if your name appeared often enough in training data (public figures, prolific posters) or you told it this session. A single private chat does not survive into model weights as a retrievable fact — memorization requires repetition. The bigger day-to-day risk is layers 1 and 2: stored chats and memory.

What does an AI infer that I never said?

Patterns: writing level, likely age bracket, profession, location hints, emotional state, and — from sensitive questions — health conditions or sexual orientation. Inference is covered by GDPR as personal data too; see the sensitive-inferences guide.