Most mainstream AI chatbots in 2026 quietly log your prompts, retain them for weeks or years, and use them to train future models unless you find and flip a buried setting. The privacy gap between the best and worst is now large enough that your choice of chatbot meaningfully changes your risk. This article identifies the current winners, losers, and worst offenders on AI privacy, and shows exactly what to switch on or off to protect yourself.

Key Takeaways

  • Default training is the norm: ChatGPT, Claude, Gemini, Grok, Perplexity and others all train on consumer chats by default unless you actively opt out.
  • Best-in-class privacy: ChatGPT’s zero-retention API, Anthropic Claude’s Incognito mode, and Perplexity’s enterprise tiers offer the strongest practical protections today.
  • Most invasive mainstream bots: Microsoft Copilot, Meta AI, and X’s Grok tie prompts to rich behavioral profiles and advertising or social feeds, with opt-outs that are partial or hard to find.
  • Worst offender for everyday users: X + Grok is the most hostile combination to privacy, folding public posts, likes and Grok prompts into an opt-out training regime tightly linked to your identity.
  • Actionable protection: Turn off training toggles, use private/incognito modes, avoid free-ad tiers for sensitive work, and separate consumer chatbots from your company’s data.

Who ChatGPT is for: Privacy-conscious individuals and businesses that want a mainstream general-purpose chatbot with clear policies, zero-retention options on the API, and ad-free enterprise tiers for sensitive use.

Who Claude is for: Users and teams who care about strong safety norms and want a consumer-friendly private mode (Incognito) plus a simple training toggle to keep day-to-day chats out of long-term training.

Who Gemini is for: Heavy Google ecosystem users who value tight integration with Docs, Gmail, and Drive, and are willing to trade more data collection and human-review sampling for convenience.

Who Perplexity is for: Researchers and professionals who need grounded answers and web search, and who are ready to configure AI data-retention and consider enterprise tiers for work content.

Who Grok is for: X power users who prioritize edgy tone and social-context answers over privacy, and who are either willing to opt out of training or accept broad use of their public posts and prompts.

How PCMag Ranked AI Privacy - and What’s Changed Since

The PCMag leaderboard: three privacy tiers

PCMag’s August 2026 investigation ranked 13 major chatbots on how invasive they are with your prompts and personal data. It grouped them into three tiers: a “best” group (including ChatGPT and Vibe), a “worst” group (led by Microsoft Copilot, Meta AI, and Kimi), and a middle tier (Claude, DeepSeek, Gemini, Grok, Perplexity, Pi, Qwen, Z.ai). The key scoring dimensions were whether prompts are used for training by default, how long they’re retained, whether there is a clear LLM-specific privacy policy, and how much behavioral and personal data is pulled into personalization and advertising.

What has shifted since PCMag’s scoring is less the direction than the intensity: most providers have added more granular toggles and clearer statements, but the default for consumer accounts remains training-on with multi-purpose data use.

Core privacy dimensions for ranking bots

To meaningfully compare these systems, you need to look at six privacy dimensions:

  • Training default: Are your prompts and outputs used to train models unless you opt out?
  • Retention window: How long are prompts stored when training is off vs on?
  • Human review: Are your chats ever sampled for human review, and under what conditions?
  • Advertising & profiling: Are prompts or chat context used to target ads, or linked to wider behavioral profiles?
  • Private modes: Is there a true “no-training” mode that’s easy to activate for sensitive sessions?
  • Enterprise guarantees: Are business-tier conversations guaranteed to be excluded from training and ads?

With those criteria, we can identify genuine privacy winners and clear losers, and call out the worst offender model for everyday users.

Privacy Winners: Strongest Protections in 2026

OpenAI ChatGPT: clear policies, zero-retention API, controlled ad use

OpenAI’s current ecosystem includes consumer ChatGPT tiers (Free, Go, Plus, Pro), business and enterprise offerings, and a widely used API. Across these, the privacy story has become more explicit in 2026, especially around ads and retention.

  • Training defaults: OpenAI’s core position is that customer content from its enterprise and business offerings is not used for training unless there’s an explicit opt-in. A recently highlighted “Zero Data Retention” option for eligible API customers guarantees that prompts and responses are not retained after the request is processed, and are not available for staff review.
  • Consumer chat training: For ordinary ChatGPT users, OpenAI still states that inputs and outputs may be used to improve services, including model training, unless you opt out via data controls. Opt-out applies going forward; it does not retroactively remove already-used training data.
  • Ad personalization and privacy: In 2026, OpenAI introduced ads to Free and Go plans in multiple regions. Its updated privacy policy clarifies that ads are not shown to under-18 accounts and that advertisers do not receive chats, chat history, memories or personal details. Instead, OpenAI internally uses chat context, approximate location, device type, prior ad interactions, and - if you opt into personalization - stored memories and past chats to choose ads. Paid tiers (Plus, Pro, Business, Enterprise, Education) remain ad-free. In the EU and UK, personalized ads require explicit opt-in consent; without consent, only contextual ads based on the current conversation and rough location are served.
  • Retention & controls: Users across regions can turn off personalized ads and, in some cases, opt out of ads entirely in exchange for lower usage quotas. Data controls allow exporting and deletion requests under privacy law. OpenAI’s privacy documentation for Europe enumerates specific legal bases for processing: providing and maintaining services, personalization, research and improvement, fraud prevention, and compliance.
  • Enterprise guarantees: ChatGPT Enterprise and Business are contractually framed as zero-training environments, with synced data connections being removed or restricted further in mid-August release notes to reduce accidental data exposure.
OpenAI is one of the few providers offering a true zero-retention API mode plus ad-free, no-training enterprise tiers, which now set the bar for what “privacy-respecting” LLM deployment looks like.

Anthropic Claude: incognito mode and a simple training toggle

Anthropic’s Claude sits in PCMag’s middle tier, but in practice is one of the more privacy-conscious mainstream bots, largely because its controls are clear and its ad exposure minimal.

  • Training default: Since an August 2025 terms update, consumer Claude accounts (Free, Pro, Max) have a “Help Improve our AI models” setting turned on by default. With it on, Anthropic’s policy states that your inputs and Claude’s outputs can be retained in de-identified form for up to five years and used to train future models.
  • Opt-out and retention: Turning the training toggle off in Settings → Privacy drops retention of ordinary chats to roughly 30 days and stops their use for model training. Deleted conversations are removed from your history immediately and purged from back-end systems within about 30 days. However, content already used in completed training runs is not clawed back.
  • Incognito mode: Claude’s standout feature is an Incognito mode accessed via a ghost icon. Incognito conversations are never used for training even if the main training toggle is on, skip long-term history and memory, and are retained for only a short operational window (around 30 days) before being purged.
  • Safety-flagged content carve-out: A June 2026 clarification states that conversations flagged for safety review may still be retained and used to improve models even if the training toggle is off. Safety-flagged content can be held for up to two years, and classifier scores for up to seven years.
  • Ads and data sales: Anthropic does not run ads in Claude’s consumer interface and states it does not sell user data. Its July 2026 privacy policy enumerates collected data (inputs, outputs, device data, payment info, verification signals) and emphasizes its non-advertising posture.

For privacy-conscious individuals, Claude’s combination of a clear training toggle and Incognito mode for genuinely sensitive conversations makes it one of the best choices among mainstream chatbots.

Perplexity Enterprise and Sonar API: strict limits for organizations

Perplexity’s consumer-facing product is more invasive by default, but its enterprise and API offerings are privacy-strong enough to count among the winners for organizational use.

  • Consumer training default: On Free, Pro and Max consumer tiers, Perplexity’s own help and independent analyses state that “AI Data Retention” (model-improvement training) is enabled by default. You can opt out by toggling off AI data-retention in account preferences, but the opt-out applies only to future data and does not remove previously collected training data.
  • Enterprise training guarantees: Perplexity’s enterprise terms and Data Processing Addendum (last updated August 2026) explicitly state that it does not sell or share personal data, and that it does not send queries, prompts or conversation content to advertisers. Enterprise data is contractually excluded from AI training and is retained on much shorter timelines - about seven days for session file attachments by default.
  • Sonar API zero-retention: Perplexity’s Sonar API is documented as zero-retention: prompts and responses are discarded after the request is processed. This makes Sonar a strong choice for developers who need search-augmented responses without long-term prompt retention.
  • Advertising posture: Perplexity’s privacy notice and enterprise terms emphasize that it does not sell personal data or send queries, prompts or conversations to advertisers. Some restructuring of its privacy landing page in mid-August 2026 removed explicit reassurance language at the top, but underlying commitments not to sell personal data or share conversation content with advertisers remain in the detailed terms.
  • Retention details: Independent reviews highlight that consumer session files are typically held for about 30 days, enterprise session files for seven days, while project and repository files persist until deleted.

In short, Perplexity is a privacy winner if you are on enterprise or using Sonar; on consumer plans, it’s only mid-pack unless you actively disable AI data retention.

Middle of the Pack: Acceptable but Far From Private

Google Gemini: deeply integrated, heavily logged

Gemini is now deeply woven into Google’s ecosystem, from the standalone app to integrations with Docs, Gmail, and Drive. That integration brings both convenience and extensive data collection.

  • Keep Activity default: Gemini’s key control is “Gemini Apps Activity,” exposed through myactivity.google.com. When it is on - its default - your Gemini conversations are saved to your Google account and can be used to improve Google services, including AI model training. Samples can be reviewed by human contractors.
  • Turning it off: You can disable Gemini Apps Activity and set auto-delete windows (e.g., three months) so history does not accumulate indefinitely. However, even with activity disabled, Google still retains Gemini conversations for around 72 hours for operational reasons (generating responses, abuse detection) and may process anonymized data for service improvement and safety.
  • Human review carve-out: Independent reporting underscores that Google can randomly sample Gemini conversations for human review and keep those samples for up to three years, even if you later delete your account. Before review, conversations are separated from direct identifiers, but they remain content-complete.
  • Location and device data: Gemini collects device and location data linked with your Google account. Location can be approximate or precise depending on your wider Google settings.
  • Ecosystem access: Allegations have surfaced that Gemini may have surfaced details from private Google Docs in a conversation. Google’s stated position is that Gemini only accesses Docs when explicitly authorized (e.g., when you ask it to summarize a document) and treats that access as transient, but the perception risk is real: if users believe their private documents can become model fodder, trust erodes.

Gemini gives you more explicit toggles than some rivals, but given its scale (over 1 billion monthly active users) and deep integration with Google’s broader data ecosystem, it belongs firmly in the “acceptable but far from private” tier unless you actively lock down activity and sharing.

Anthropic Claude (consumer) and Perplexity (consumer): controlled but still training-by-default

Claude and Perplexity are privacy winners in their best modes, but for ordinary consumer users they still behave like typical middle-tier bots: training-by-default, opt-out controls that are easy to miss, and non-trivial retention windows.

  • Claude consumer mode: With the “Help Improve our AI models” toggle on, your de-identified chats can be retained for up to five years for training. Turning it off brings retention down to about 30 days and stops training, but safety-flagged content can still be held longer and used for improvement.
  • Perplexity consumer mode: AI data-retention is on by default; ordinary session files can be held for about 30 days; your queries and responses contribute to training unless you disable the setting. Opting out doesn’t remove older data.
  • Private modes & visibility: Claude’s Incognito mode and Perplexity’s project/repository model give you more control over where work lives and who can see it, but they don’t automatically change training defaults unless you explicitly use those modes.

If you’re a careful, technically literate user who will go into settings and flip the necessary toggles, both are solid. If not, you end up in the same middle ground as Gemini - better than the worst, but far from private.

Privacy Losers: Most Invasive Mainstream Chatbots

Microsoft Copilot: the weakest scores in PCMag’s audit

PCMag’s ranking put Microsoft Copilot at the bottom of the list for privacy among the 13 bots it evaluated. Copilot’s provider, Microsoft, is a major company with extensive existing telemetry and advertising systems, but the audit found that it failed to provide a clear privacy policy specifically for its LLM activities.

  • Lack of LLM-specific policy: Copilot’s data practices are largely folded into broader Microsoft and Windows policies, making it hard for ordinary users to see at a glance what’s logged, how long it’s retained, and how extensively prompts may be used for training.
  • Personalized data: PCMag noted that Copilot scored worst for direct handling of personalized data, reflecting how closely it can tie prompts and outputs to your broader Microsoft account and device footprint.
  • Enterprise vs consumer: Some enterprise Copilot deployments come with stronger contractual controls, but most consumers encounter Copilot through Windows, Edge, or web properties where training and telemetry are on by default and opt-outs are partial.

Copilot is usable for low-sensitivity queries, but if you care deeply about prompt privacy, it is currently one of the worst mainstream options.

Meta AI: aggressive data fusion and ad ecosystem alignment

Meta AI inherits the company’s long history of behavioral profiling and advertising-driven data use. In PCMag’s scoring, Meta AI landed near the bottom, just above Copilot.

  • Integrated across Meta properties: Meta AI is embedded in Facebook, Instagram, WhatsApp, and Messenger, meaning prompts can exist alongside deep behavioral profiles, social graphs, and ad-targeting infrastructure.
  • LLM policy gaps: PCMag highlighted that Meta lacks a clear, separate LLM privacy policy spelling out what is logged and how prompts relate to training and ads. Instead, users are left to infer from broader Meta privacy terms, which are notoriously complex.
  • Advertising linkage: While Meta does not publicly state that prompts themselves are shared directly with advertisers, its business model is to use almost every signal it can to improve targeting. The risk profile is therefore higher than for providers with explicit no-ad clauses around prompts.

For privacy-conscious users, Meta AI is best treated as an extension of Meta’s broader tracking regime: powerful but not a place to paste sensitive or work-related data.

Kimi and other regional players: opaque training and retention

PCMag also singled out Kimi as a privacy loser, noting that it “maxed out on demerits” for handling user data for training. The core issue is opacity: Kimi’s policies do not clearly separate model-training, retention and personalization, and do not offer the kind of incognito or zero-retention modes seen in Claude and OpenAI’s APIs.

Other regional bots may behave similarly: they are fast to market, but slow to provide detailed, user-friendly privacy documentation. If your provider is not explicitly enumerating training settings, retention timelines, and review practices, the safest assumption is that your prompts are being used for training and kept for a long time.

The Worst Offender: X + Grok’s Opt-Out Training and Social Graph Fusion

Why Grok stands out negatively

Among the bots in PCMag’s middle tier, Grok is uniquely risky for everyday users because it is tightly coupled with X’s social graph and has training defaults that are opt-out rather than opt-in.

  • Training default: xAI’s consumer FAQ states that the company may use your content and interactions with Grok, along with Grok’s responses, to train its models. Independent guides emphasize that training is opt-out, not opt-in: unless you take action, your prompts and Grok’s replies will be used for training.
  • Opt-out complexity: To opt out, you may need to toggle a “Improve the Model” setting in Grok’s app or on grok.com, or even email xAI directly, depending on product context. Private Chat / Incognito modes can exclude specific sessions from training, but they are not the default mode.
  • X data sharing: X’s terms and settings now treat Grok prompts, inputs and outputs as part of “Content,” similar to public posts. A documented setting under Privacy and Safety → Grok controls whether your public posts, likes, and sometimes photos are fed into xAI for training. The default is opt-in; you must actively disable “Allow your posts to improve Grok.”
  • Rich identity and behavior linkage: X can share your public profile, username, numeric ID, date of birth, Premium status and Grok-on-X conversation history with xAI. This makes Grok one of the bots where prompts are most tightly bound to your public identity and long-lived social record.
  • Location and media: Grok infers your general location from IP by default, and can use more precise location if you’ve enabled it in X or the app. Its mobile app collects and may share photos and app activity with third parties under standard app-store data-sharing disclosures.
Because Grok is both a chatbot and a lens onto your social media life, and because training is opt-out and heavily intertwined with X’s content, it is the single worst choice for anyone who wants prompts to be private by default.

Safety and policy controversies

Beyond privacy, Grok has faced legal and policy controversies over internal prompts that allegedly allowed “no restrictions on adult sexual content or offensive content” in some contexts, even as xAI’s public Acceptable Use Policy forbids sexual depictions of real people and non-consensual intimate imagery. The tension between internal prompt engineering and external policy has led to lawsuits and calls for stricter enforcement, which in turn heightens the stakes of data retention: if you are not confident you understand how Grok’s safety systems work, you should assume that prompts may be retained and scrutinized.

Practical Takeaways: How to Protect Your Prompts Across Bots

1. Always flip the training toggle

Across nearly all major bots, a single setting governs whether your future conversations are used for training:

  • ChatGPT: Use account data controls to opt out of model training. For eligible API usage, request or enable “Zero Data Retention.”
  • Claude: In Settings → Privacy, turn off “Help Improve our AI models.” Use Incognito mode for anything sensitive.
  • Gemini: Go to myactivity.google.com / Gemini settings and turn off Gemini Apps Activity. Set auto-delete to three months or less.
  • Perplexity: In account preferences, disable AI Data Retention. For work, use Enterprise Pro/Max or Sonar API.
  • Grok: In Grok or X settings, turn off “Improve the Model” and “Allow your posts to improve Grok.” Use Private Chat for sensitive sessions.

Remember: these toggles almost always apply only to data collected after you change them. Previous training data is typically not retroactively removed.

2. Use private/incognito modes for genuinely sensitive conversations

Several providers now offer session-specific privacy modes:

  • Claude Incognito: Never used for training, limited retention, no memory.
  • Grok Private Chat: Keeps conversations out of visible history and training, depending on configuration.
  • OpenAI zero-retention API: Discards prompts and responses immediately after processing.

For anything involving credentials, health information, legal matters, unreleased IP, or highly personal topics, treat these modes as mandatory rather than optional.

3. Separate consumer chatbots from work data

Even privacy winners in the consumer space are best avoided for raw corporate data. Instead:

  • Use enterprise tiers: ChatGPT Enterprise/Business, Claude enterprise deployments, Perplexity Enterprise Pro/Max and similar offerings explicitly exclude customer content from training and ads.
  • Limit connectors: Be careful when linking email, calendars, drives or CRMs to bots. Confirm that enterprise agreements cover connected data and that retention windows match your compliance needs.

Never paste API keys, secrets or unreleased financials into consumer chat windows; use dedicated internal tools or well-audited enterprise environments.

4. Understand the human-review carve-outs

Data that is sampled for human review often lives on longer than ordinary logs and is harder to fully delete. Companies like Google and Anthropic explicitly reserve the right to sample conversations for safety and quality review, sometimes keeping them for years.

  • Avoid highly sensitive content: If you don’t want any chance of a human seeing it, do not paste it into a consumer chatbot.
  • Prefer enterprise channels: Enterprise agreements typically narrow human review to security and support contexts, with stricter controls.

Verdict

Verdict

If you care about prompt privacy, you should treat “private by default” as marketing fiction in 2026. Almost every major AI chatbot - from ChatGPT, Claude and Gemini to Grok and Perplexity - trains on consumer conversations unless you actively opt out, and several weave prompts into broad behavioral profiles and advertising systems.

Use ChatGPT Enterprise or API with zero-retention when you need the strongest mainstream privacy for business or development, and Claude with Incognito plus training off when you want a consumer-friendly assistant with clear controls and no ads. Perplexity Enterprise or Sonar are excellent for search-heavy professional use, provided you disable consumer AI data retention for personal accounts. Avoid Microsoft Copilot, Meta AI, and Grok on X for anything sensitive: Copilot and Meta offer weak, opaque LLM-specific privacy, and X + Grok is the worst offender, combining opt-out training with deep social graph and identity linkage. For everyday users, the practical rule is simple: turn off training toggles, use private modes religiously, and never assume your prompts are invisible - your protection comes from configuration and product choice, not defaults.

Sources