What Data AI Collects

Understanding what data AI services collect is the first step to protecting yourself.

Common Data Collection

Most AI services collect:
  • Conversations/Prompts: Everything you type into the AI
  • Metadata: Time, date, and frequency of your interactions
  • IP Address: Your internet connection's location
  • Device Info: Browser, OS, device type
  • Usage Patterns: Which features you use, how long you interact
  • Account Information: Email, name, payment details if provided

Why Do They Collect This Data?

  • Model Improvement: Training data to make AI better
  • Safety and Abuse Prevention: Detecting harmful use
  • Service Analytics: Understanding user behavior
  • Advertising: Targeting ads to your interests
  • Third-Party Sales: Selling data to advertisers (depends on terms)

Privacy Settings for Major AI Tools

ChatGPT Privacy Settings

Key Settings to Configure:

  1. Go to Settings → Privacy
  2. Toggle "Improve model for everyone" OFF if you don't want your data used for training
  3. Go to Data Controls and set history preferences
  4. Review and delete past conversations you want removed

What to know: Even with these settings, OpenAI may retain some data for abuse prevention. If you need maximum privacy, don't store sensitive information in ChatGPT.

Google Gemini Privacy Settings

  • Account Settings → Data & Privacy
  • Disable "Web & App Activity" to reduce data collection
  • Manage Activity Controls for Gemini specifically
  • Delete activity history regularly

Claude (Anthropic) Privacy

Claude's privacy approach is stricter than most. Check account settings for:

  • Data retention policies
  • Conversation storage preferences
  • Research use opt-out options

Opt-Out Options

Global Opt-Out Strategies

1. Use Private/Incognito Browsing

When accessing AI tools in incognito mode, your browser doesn't store cookies or history locally. Note: The AI service still knows it's you if you log in.

2. Create Separate Accounts

Use one account for sensitive work, another for casual use. This limits what data is tied to your identity.

3. Delete Data Regularly

Most AI platforms let you delete conversation history. Make it a habit, monthly data purges are reasonable.

4. Disable Cookies

In browser settings, block all cookies or use selective cookie blocking. Trade-off: some websites may not work properly.

Service-Specific Opt-Outs

Service Opt-Out Option Effectiveness
ChatGPT Settings → Privacy → Disable training data use High (but not 100%)
Google Gemini Account Settings → Activity Controls High
Microsoft Copilot Privacy Settings → Data sharing preferences Medium
Perplexity AI Account → Privacy settings High

Data Minimization Strategies

1. Don't Overshare in Prompts

Avoid including personal information in your prompts if unnecessary.

Instead of: "I live at 123 Main St, Springfield and work at Acme Corp. Can you help me with..."

Try: "Can you help me with [question]?"

2. Use Pseudonyms and Fake Details

If you need examples, use fictional names and companies instead of real ones.

3. Separate Work and Personal Accounts

Don't mix professional and personal AI usage on the same account. Different logins create separate data trails.

4. Review Data Requests

Regularly check what data platforms have collected. Most EU users have the right to request their data under GDPR.

VPN Basics for Privacy

What a VPN Does (and Doesn't Do)

A VPN DOES:

  • Hide your IP address from websites and ISP
  • Encrypt your traffic from your device to the VPN server
  • Make it harder to track your browsing across sites

A VPN DOES NOT:

  • Protect you from the AI service knowing who you are (if you log in)
  • Encrypt data after it reaches the AI service
  • Hide your data from the VPN provider itself

Choosing a VPN

Reputable VPN providers:

  • Mullvad: No logging, open-source, free trial
  • ProtonVPN: Swiss-based, strong privacy focus
  • Wireguard-based VPNs: Faster, more modern protocol

Avoid: Free VPNs often log your data and sell it to advertisers. Premium providers are worth the cost.

Browser Privacy Settings

Firefox (Most Private Option)

  • Settings → Privacy & Security
  • Enable "Enhanced Tracking Protection"
  • Set to "Strict" mode
  • Disable cookies in exceptions only where needed

Brave Browser (Built-In Privacy)

Brave blocks trackers by default and has built-in VPN options. Recommended for privacy-conscious users.

Chrome (Limited but Better Than Nothing)

  • Settings → Privacy and security
  • Enable "Do Not Track"
  • Block third-party cookies
  • Use Incognito mode for sensitive searches

General Browser Practices

  • Disable autofill for sensitive forms
  • Use HTTPS-only (most browsers now default to this)
  • Clear browsing data regularly
  • Disable location services

Local AI Alternatives

For maximum privacy, run AI models locally on your computer. No data leaves your device.

Popular Local AI Tools

Tool What It Runs Difficulty Hardware Needs
Ollama LLaMA, Mistral, other models Easy 8GB RAM minimum
LMStudio Multiple models with GUI Very Easy 4GB RAM minimum
GPT4All CPU-optimized models Very Easy 2GB RAM minimum
Stable Diffusion (local) Image generation Moderate 4GB VRAM GPU recommended

Trade-Offs

Pros: Complete privacy, no data sent anywhere, works offline

Cons: Slower responses, less capable models, requires more setup, uses local computing power

Understanding Your GDPR Rights

What is GDPR?

GDPR (General Data Protection Regulation) is EU law protecting personal data. If you're in the EU or the company serves EU users, you have these rights:

Your Rights Under GDPR

Key GDPR Rights:
  • Right to Access: Request what data a company has about you
  • Right to Deletion: Ask for your data to be deleted ("Right to be Forgotten")
  • Right to Portability: Get your data in a portable format
  • Right to Rectification: Correct inaccurate data
  • Right to Restrict Processing: Limit how your data is used
  • Right to Object: Opt out of certain data processing

How to Exercise Your Rights

  1. Identify the company's privacy officer or data protection contact
  2. Submit a Data Subject Access Request (DSAR) in writing
  3. Include your full name, email, and specific request
  4. Companies must respond within 30 days (often extended to 90)
  5. If denied, escalate to your local Data Protection Authority

Other Privacy Laws

  • CCPA (California): Similar to GDPR, applies to California residents
  • LGPD (Brazil): Brazilian data protection law
  • Canada's PIPEDA: Similar privacy protections
Bottom Line: Privacy requires active management. Configure privacy settings, minimize data sharing, delete conversation history, and consider local AI for sensitive work. You have rights: understand and exercise them. Use tools like VPNs and private browsers as additional layers, but remember they're not perfect solutions alone. The most effective privacy strategy combines multiple approaches.