Table of contents
Your Secrets in AI’s Hands
This article was inspired by the study “User Privacy and Large Language Models:An Analysis of Frontier Developers’ Privacy Policies” available at arxiv.org/pdf/2509.05382 , which analyzed the privacy practices of major AI chatbot platforms.
In August 2025, ChatGPT surpassed 700 million users. It’s the fastest-growing application in history. Daily, millions of people entrust chatbots with their most personal matters, from health and finances to family dilemmas.
But there’s a fact rarely discussed. These conversations aren’t always private. They can be read by humans, stored indefinitely, and used to train new AI systems, often without your consent.
Digital Tracking Reimagined
The internet has operated on data collection principles for years. An AI privacy policy was supposed to act as a shield, but in practice, it’s often more fiction than fact. Experts estimate that reading all the policies we encounter in a year would take over 200 hours.
It’s like having to read an encyclopedia every time you install an app.

Why Chatbots Are a Different Level
Previously, the problem was cookies tracking clicks. Today, chatbots collect something much deeper.
Conversations reveal a complete picture of a person: emotions, problems, concerns, and even dreams. Asking Siri about weather is one fact. An hour-long exchange with ChatGPT about mental health is nearly a complete portrait of your psyche, and this falls directly under how an AI privacy policy governs usage.
Default Settings vs. AI Privacy Policy
The biggest companies – Amazon, Anthropic, Google, Meta, Microsoft, and OpenAI automatically use your conversations to train their models. You don’t have to agree because consent is “built into” their AI privacy policy and terms of service.
Anthropic was initially the only one requiring explicit “yes” from users (opt-in). But in September 2025, it changed its approach to opt-out. Now, if you don’t want this, you must search through settings and legal documents yourself to figure out how to disable it.
Manipulation Under the Guise of “Common Good”
OpenAI uses a known psychological trick. It’s AI privacy policy claims that sharing data “helps improve the model for everyone.” It sounds like an appeal to social responsibility, but in practice, it reinforces default settings.
Most users never change them. Companies know this well. It’s called decision inertia, people stick with what’s easiest.
What Companies Actually See
Amazon, Google, and OpenAI clearly state: they train their systems also on files uploaded by users documents, recordings, videos. Microsoft and Google go even further, analyzing voice data to improve speech recognition.
Only Microsoft declares it tries to remove personal data before training models. Other companies don’t provide details, so it’s unclear what happens to the most sensitive information.
People Are Looking at Your Conversations
Google and OpenAI openly admit: they employ people to review user conversations to improve their models. And they warn: don’t type anything you wouldn’t want to show a stranger.
Journalists revealed that Meta contractors had access to data allowing user identification. Companies talk about “anonymization,” but in practice, complete anonymity is difficult to achieve.
Two Classes of AI Privacy Policy
OpenAI applies double standards. Companies paying for business products have their data excluded from model training.
But millions of ordinary people using free versions don’t have this protection. It’s a digital class divide: privileged business clients and the rest of the users.
Data Without Expiration Date
Amazon, Meta, and OpenAI store user data indefinitely. No time limits, no real deletion option.
It’s like a time bomb. The longer data exists, the greater the risk it will be disclosed, stolen, or used in unforeseen ways. Do we really want our today’s conversations analyzed in ten years?
Law Can’t Keep Up
The US has no comprehensive national data privacy law. Only a patchwork of state regulations exists, with California’s CCPA being the strongest.
The European Union has GDPR, which requires privacy “by design” and user-friendly settings. Companies like Google or OpenAI boast SOC 2 Type II and ISO/IEC 27001 certifications, but certificates don’t replace real oversight.
Children as “Fuel” for AI
Four of six companies also train models on data from youth aged 13-18. Google went even further, adding users under 13 to the Gemini database.
Children cannot consciously consent to such practices. Research shows young people often enter para social relationships with chatbots, sometimes even of a sexualized nature. This raises serious ethical and legal questions.
Boundaries Are Blurring
Companies increasingly combine data from different services. Your emails, Google Drive documents, and search history can be linked with chatbot conversations.
This directly violates GDPR principles: data minimization and purpose limitation. But the pursuit of “omniscient” AI makes boundaries between products dissolve, and our digital life becomes one giant database.
What Can Be Done Better
- Consent Must Be Explicit– Require opt-in before using any data in training, as part of every AI privacy policy.
- Automatic Sensitive Data Filtering– Systems for removing personal information from training materials must be introduced. Microsoft is already trying – others should do this or go further.
- Privacy-Protecting Features– OpenAI offers temporary chats, Google has similar options, Apple doesn’t use user data in AI. It shows development and privacy can go together.
Our Future, Our Choice
For three decades, US law hasn’t kept pace with technology. Now, when chatbots have become places where people share their most personal thoughts, boundaries must be clearly set.
The core question: are AI benefits worth the risks created by weak or manipulative AI privacy policy?
The future of artificial intelligence requires trust and transparency. If people feel deceived, they’ll turn away from this technology regardless of its potential.
The choice is ours. And it’s time to make it.
FAQ
Can AI write my privacy policy?
Yes, but only as a draft. A lawyer should review it to make sure it fits the law and your business needs.
Is AI violating your privacy?
It might, if it gathers or stores personal data without consent or proper safeguards. The risk depends on what data is used, how the system is built, and whether it follows privacy rules.
Can ChatGPT make an AI privacy policy?
It can create a draft based on your input, but it can’t replace legal advice. Always ask a lawyer to review before you publish.
How does AI protect privacy?
AI can support privacy with tools like anonymization, encryption, and threat detection. But it must be designed with privacy in mind, or it could create new risks.
Leave a Reply