Training, Retention, Memory — What ChatGPT Actually Does With Your Chats
You went into settings, turned off the switch that lets the AI train on your conversations, and reasonably assumed that was the job done. It wasn't. Training, retention and memory are three separate systems with three separate controls and three separate timelines — and the one switch everybody finds only touches the first.
The Promise
- The controls genuinely exist and they work. Training, retention and memory each have a real switch that does what it says — the problem is that there are three of them, not that any one is fake.
- Crossing from a consumer account to contracted terms changes four things at once: training is excluded by default, retention becomes contractually specified and can be zero, you get a data processing agreement — a promise with a remedy attached — and administration moves.
- This is a conflation problem, and it is not the user's fault. Vendors shipped one switch and labelled it privacy, so people reasonably concluded there was one thing to control.
The Risk
- Every vendor's training opt-out is forward-looking and none is retroactive. Text already inside a completed training run stays there, because weights cannot be unbaked. That's arithmetic, not a loophole.
- The training switch silently moves your retention clock. Under Anthropic's consumer terms, a deleted conversation leaves back-end systems within 30 days — but if you allowed chats to be used for model improvement, the hold becomes five years. Policy-flagged conversations sit for two years, and trust-and-safety scores for seven.
- Memory is the one almost nobody checks. It's a readable file the tool keeps about you and consults before answering, it persists indefinitely, and it has its own independent switch. Turn training off and memory keeps writing.
- A court can override a setting you used correctly. In May 2025 a federal magistrate ordered OpenAI to preserve output log data including conversations users had already deleted; the order wasn't terminated until October.
One switch, three systems
The vendors put a single control in place and called it privacy, so people reasonably concluded there was one thing to control. There are three, and they come apart sharply.
Training is whether the model learns from you. Retention is how long raw text sits on a server, under a separate policy. Memory is what the tool has written down about you and reads back before it answers — a completely separate system again.
Each has its own control, its own timeline, and its own owner. Turning one off does nothing to the other two.
I’ve watched this exact shape in cybersecurity for 25 years. A firewall rule, a retention policy and an access log are three different controls with three different owners, and the organisations that get breached are the ones that assumed the first implied the other two. Same mistake, new settings panel.
Training: forward-looking, never retroactive
When your conversation becomes training material, your text isn’t stored inside the model like a file in a folder. It contributes to adjusting the model’s weights — and weights cannot be unbaked once trained.
Anthropic states it plainly: turn the setting off and your chats won’t be used for future training. But data already included in a training run in progress, or in a model already trained, stays there.
Every vendor’s opt-out works this way. That isn’t a loophole. It’s arithmetic.
Retention: the clock the training switch quietly moves
Anthropic’s consumer terms, as published on 1 July 2026, give the clearest picture anyone has put in writing. Delete a conversation and it leaves your history immediately, and their back-end systems within 30 days.
But if you have allowed your chats to be used for model improvement, they hold data for five years. Thirty days becomes five years, and the thing that moved it is the training switch. That coupling is the part nobody expects.
There’s a tier below that, too. If an automated system flags your conversation as violating usage policy, inputs and outputs are retained for up to two years — and trust-and-safety scores for up to seven. Seven years for a score, from their own privacy page rather than from a critic.
And a court can override the whole arrangement. On 13 May 2025 a federal magistrate judge ordered OpenAI to preserve output log data that would otherwise have been deleted, including conversations users had already deleted. Deletion was a setting people had used correctly, and it stopped applying. Sam Altman said publicly that the company would fight any demand compromising user privacy, calling it a core principle. They fought it. The order wasn’t terminated until 9 October, and the data persisted throughout.
Memory: a file, not a model
Memory is the one almost nobody checks, and it isn’t training at all. It’s a file the tool keeps about you in readable sentences and consults before it answers: your job, your projects, how you like things phrased, something you mentioned once about your family.
It persists across conversations, it steers every response you get, and it has its own independent switch. Turn training off and memory keeps writing. Turn memory off and training carries on regardless.
The two interact badly. On consumer tiers, where conversations may feed model improvement, memories can travel — which puts the most personal material in the product on the surface with the loosest controls available.
The line that actually matters
Everything above describes the consumer product. The real division isn’t between vendors, it’s between consumer accounts and contracted terms — enterprise, education, and the API.
Cross that line and four things change. Training is excluded by default. Retention becomes contractually specified, and can be zero. You get a data processing agreement, which is a promise with a remedy attached. And administration control moves: an admin may be able to see member data.
Consumer accounts leak outward. Workspace accounts leak inward. Neither is private in the way the word is normally used. If a conversation would matter in a dispute, it doesn’t belong on a consumer account at any price tier — and that’s a terms question, not a settings question.
The needle sits just past centre toward promise. The controls genuinely exist and they work. What doesn’t exist is a single switch. When you ask someone which protection you have, ask which of the three systems the answer is about — usually they haven’t separated them either.