What Data AI Collects
Understanding what data AI services collect is the first step to protecting yourself.
Common Data Collection
- Conversations/Prompts: Everything you type into the AI
- Metadata: Time, date, and frequency of your interactions
- IP Address: Your internet connection's location
- Device Info: Browser, OS, device type
- Usage Patterns: Which features you use, how long you interact
- Account Information: Email, name, payment details if provided
Why Do They Collect This Data?
- Model Improvement: Training data to make AI better
- Safety and Abuse Prevention: Detecting harmful use
- Service Analytics: Understanding user behavior
- Advertising: Targeting ads to your interests
- Third-Party Sales: Selling data to advertisers (depends on terms)
Privacy Settings for Major AI Tools
ChatGPT Privacy Settings
Key Settings to Configure:
- Go to Settings → Privacy
- Toggle "Improve model for everyone" OFF if you don't want your data used for training
- Go to Data Controls and set history preferences
- Review and delete past conversations you want removed
What to know: Even with these settings, OpenAI may retain some data for abuse prevention. If you need maximum privacy, don't store sensitive information in ChatGPT.
Google Gemini Privacy Settings
- Account Settings → Data & Privacy
- Disable "Web & App Activity" to reduce data collection
- Manage Activity Controls for Gemini specifically
- Delete activity history regularly
Claude (Anthropic) Privacy
Claude's privacy approach is stricter than most. Check account settings for:
- Data retention policies
- Conversation storage preferences
- Research use opt-out options
Opt-Out Options
Global Opt-Out Strategies
1. Use Private/Incognito Browsing
When accessing AI tools in incognito mode, your browser doesn't store cookies or history locally. Note: The AI service still knows it's you if you log in.
2. Create Separate Accounts
Use one account for sensitive work, another for casual use. This limits what data is tied to your identity.
3. Delete Data Regularly
Most AI platforms let you delete conversation history. Make it a habit, monthly data purges are reasonable.
4. Disable Cookies
In browser settings, block all cookies or use selective cookie blocking. Trade-off: some websites may not work properly.
Service-Specific Opt-Outs
| Service | Opt-Out Option | Effectiveness |
|---|---|---|
| ChatGPT | Settings → Privacy → Disable training data use | High (but not 100%) |
| Google Gemini | Account Settings → Activity Controls | High |
| Microsoft Copilot | Privacy Settings → Data sharing preferences | Medium |
| Perplexity AI | Account → Privacy settings | High |
Data Minimization Strategies
1. Don't Overshare in Prompts
Avoid including personal information in your prompts if unnecessary.
Instead of: "I live at 123 Main St, Springfield and work at Acme Corp. Can you help me with..."
Try: "Can you help me with [question]?"
2. Use Pseudonyms and Fake Details
If you need examples, use fictional names and companies instead of real ones.
3. Separate Work and Personal Accounts
Don't mix professional and personal AI usage on the same account. Different logins create separate data trails.
4. Review Data Requests
Regularly check what data platforms have collected. Most EU users have the right to request their data under GDPR.
VPN Basics for Privacy
What a VPN Does (and Doesn't Do)
A VPN DOES:
- Hide your IP address from websites and ISP
- Encrypt your traffic from your device to the VPN server
- Make it harder to track your browsing across sites
A VPN DOES NOT:
- Protect you from the AI service knowing who you are (if you log in)
- Encrypt data after it reaches the AI service
- Hide your data from the VPN provider itself
Choosing a VPN
Reputable VPN providers:
- Mullvad: No logging, open-source, free trial
- ProtonVPN: Swiss-based, strong privacy focus
- Wireguard-based VPNs: Faster, more modern protocol
Avoid: Free VPNs often log your data and sell it to advertisers. Premium providers are worth the cost.
Browser Privacy Settings
Firefox (Most Private Option)
- Settings → Privacy & Security
- Enable "Enhanced Tracking Protection"
- Set to "Strict" mode
- Disable cookies in exceptions only where needed
Brave Browser (Built-In Privacy)
Brave blocks trackers by default and has built-in VPN options. Recommended for privacy-conscious users.
Chrome (Limited but Better Than Nothing)
- Settings → Privacy and security
- Enable "Do Not Track"
- Block third-party cookies
- Use Incognito mode for sensitive searches
General Browser Practices
- Disable autofill for sensitive forms
- Use HTTPS-only (most browsers now default to this)
- Clear browsing data regularly
- Disable location services
Local AI Alternatives
For maximum privacy, run AI models locally on your computer. No data leaves your device.
Popular Local AI Tools
| Tool | What It Runs | Difficulty | Hardware Needs |
|---|---|---|---|
| Ollama | LLaMA, Mistral, other models | Easy | 8GB RAM minimum |
| LMStudio | Multiple models with GUI | Very Easy | 4GB RAM minimum |
| GPT4All | CPU-optimized models | Very Easy | 2GB RAM minimum |
| Stable Diffusion (local) | Image generation | Moderate | 4GB VRAM GPU recommended |
Trade-Offs
Pros: Complete privacy, no data sent anywhere, works offline
Cons: Slower responses, less capable models, requires more setup, uses local computing power
Understanding Your GDPR Rights
What is GDPR?
GDPR (General Data Protection Regulation) is EU law protecting personal data. If you're in the EU or the company serves EU users, you have these rights:
Your Rights Under GDPR
- Right to Access: Request what data a company has about you
- Right to Deletion: Ask for your data to be deleted ("Right to be Forgotten")
- Right to Portability: Get your data in a portable format
- Right to Rectification: Correct inaccurate data
- Right to Restrict Processing: Limit how your data is used
- Right to Object: Opt out of certain data processing
How to Exercise Your Rights
- Identify the company's privacy officer or data protection contact
- Submit a Data Subject Access Request (DSAR) in writing
- Include your full name, email, and specific request
- Companies must respond within 30 days (often extended to 90)
- If denied, escalate to your local Data Protection Authority
Other Privacy Laws
- CCPA (California): Similar to GDPR, applies to California residents
- LGPD (Brazil): Brazilian data protection law
- Canada's PIPEDA: Similar privacy protections