How to Use AI With Your Privacy Intact
AI chatbots like ChatGPT and Gemini are default-set to collect and store highly sensitive user data, posing significant privacy risks. A new generation of AI services, including Moxie Marlinspike's Confer, is emerging to offer privacy-preserving alternatives.
Intelligence analysis by Gemini 2.5 Flash

As AI chatbots become virtual confidantes, users are unknowingly sharing their most personal information with services that often retain and potentially share this data. This widespread data collection has prompted privacy advocates to compare AI interactions to the surveillance risks of unencrypted messaging, leading to the development of new tools and policies aimed at protecting us…
Imagine you have a super smart robot friend you can tell anything to. Usually, everything you tell it gets written down in a big book that the robot's creators can read. But now, some clever people are making special robot friends that promise to forget everything you say, or even use secret codes so only you and the robot know what you're talking about, keeping your secrets safe from everyone else.
Analysis
The proliferation of AI chatbots has inadvertently created a vast honeypot for personal data, with millions of users confiding their deepest secrets to systems designed by default to collect and store this information. This data, ranging from financial details to health concerns and relationship issues, is often retained with few restrictions on its use, sharing, or potential disclosure to third parties like law enforcement or advertisers. The privacy implications are profound, as users build extensive profiles of their lives within these AI interactions, often without full awareness of the data's fate.
Moxie Marlinspike
Cryptographer and software developer Moxie Marlinspike, known for creating the end-to-end encrypted messenger Signal, identifies AI interactions as the new frontier of privacy vulnerability. He argues that the surveillance dangers in the AI space are orders of magnitude more significant than those he addressed with text messaging a decade ago. Marlinspike's concern stems from the intimate nature of conversations users have with AI, which often delve into highly sensitive personal matters.
In response to these concerns, Marlinspike launched Confer, an AI chatbot specifically designed with privacy at its core. Confer employs cryptography to technically prevent its own servers from logging or surveilling user conversations, offering a robust technological guardrail against data exploitation. This initiative represents a significant step towards empowering users to explore ideas and seek assistance from AI without the constant worry that their private thoughts could be used against them in the future.
Zero Data Retention
For most mainstream AI chatbots, users should assume a baseline of minimal privacy, as service owners, partners, and legal entities may access conversation records. The strongest exception to this default is a contractual agreement known as Zero Data Retention (ZDR), typically offered to enterprise and developer accounts by major AI providers like OpenAI, Anthropic, and Google. ZDR policies generally mandate the immediate deletion of user interaction records once processed, providing a higher level of data protection for corporate clients.
However, ZDR policies are not without their limitations and exceptions. They are largely unavailable to average consumer users, who must rely on weaker, policy-based assurances. Furthermore, even enterprise ZDR has caveats; Anthropic, for instance, does not offer ZDR for its most sophisticated models due citing potential misuse like scamming or autonomous misbehavior. OpenAI's ZDR implementations also include a Private Safety Processing system that analyzes user activity for abuse prior to deletion, potentially alerting OpenAI staff without revealing conversation content, while Google logs some Gemini prompts for abuse monitoring, albeit without direct user identifiers.
Private Safety Processing
OpenAI has introduced a system called Private Safety Processing as part of its ZDR offerings, designed to detect abuse within user activity before conversation data is deleted. This processing occurs on the customer's systems rather than OpenAI's, aiming to maintain a degree of privacy while still addressing potential misuse. The system is engineered to flag suspicious activity for the customer organization, and in some cases, can even alert OpenAI's staff, though crucially, without exposing the actual content of the conversation to them.
This approach highlights the complex challenge of balancing user privacy with the need for safety and abuse prevention in AI systems. While ZDR aims to minimize data retention, mechanisms like Private Safety Processing demonstrate that even with strong privacy commitments, AI providers are implementing safeguards to prevent their tools from being exploited for harmful purposes. This continuous analysis, even if anonymized or localized, represents a nuanced layer of data handling that users, particularly enterprise clients, must understand when evaluating the true extent of their privacy protections.
Key points
- Mainstream AI chatbots like ChatGPT, Claude, and Gemini collect and store sensitive user data by default.
- Cryptographer Moxie Marlinspike, creator of Signal, launched Confer, an AI chatbot designed with cryptographic privacy protections.
- Zero Data Retention (ZDR) policies, which immediately delete user interaction records, are primarily available for paid enterprise and developer accounts.
- Even ZDR policies have exceptions, with providers like Anthropic and Google logging some data for abuse monitoring.
- New privacy-focused AI services are emerging, offering alternatives to the pervasive data collection of major platforms.
The emergence of privacy-focused AI tools like Confer and Lumo offers a promising path for users to engage with advanced AI capabilities without sacrificing their personal data. As competition in this space grows, it could drive mainstream AI providers to adopt stronger privacy defaults and offer more robust, technically enforced protections for all users.
Despite the availability of some privacy-preserving options, the default settings of most popular AI chatbots continue to collect vast amounts of sensitive user data, leaving the majority of users vulnerable. The limitations of enterprise-level Zero Data Retention policies and the ongoing need for abuse monitoring even within these systems suggest that true, comprehensive privacy for average AI users remains a significant challenge.



