Most “most private AI” rankings score vibes: interface polish, whether the company feels trustworthy, how the marketing reads.
This one uses one input only — what each vendor’s own policy documents state about retention, training defaults, and the limits of opting out. Every figure below links to the source, and the whole page carries a check date.
📋 Key Takeaways
- Google keeps human-reviewed Gemini chats up to 3 years — and deleting your activity does not remove them
- Anthropic keeps trust-and-safety classification scores for up to 7 years on flagged sessions
- Claude's retention swings 60x on one toggle: 30 days opted out, 5 years opted in
- DeepSeek publishes no fixed retention period and processes data in the People's Republic of China
- Opting out of training never means opting out of storage — every vendor treats these separately
The Comparison Table
| Assistant | Default retention | If you opt out of training | Trains by default? | Data location |
|---|---|---|---|---|
| Proton Lumo | Guest chats erased at session end; saved history zero-access encrypted | n/a — never trains on chats | No | Proton-controlled servers |
| DuckDuckGo Duck.ai | Not retained for training; provider-side abuse exceptions may apply briefly | n/a | No | Via model providers, anonymised |
| Claude (Free/Pro/Max) | 5 years | 30 days | Yes, unless you opt out | Anthropic infrastructure |
| ChatGPT (Free/Plus/Pro) | Until deleted; 30 days after deletion | Same 30 days — opt-out is training-only | Yes, unless you opt out | OpenAI infrastructure |
| Gemini (consumer) | 18 months default (3 or 36 months, or indefinite, selectable) | 72 hours with Keep Activity off | Yes, unless Keep Activity off | Google infrastructure |
| DeepSeek | ”As long as necessary” — no stated period | Opt-out right stated, no period given | Yes | People’s Republic of China |
Sources: Anthropic Privacy Center · OpenAI Help Center · Google Gemini Apps Activity · DeepSeek Privacy Policy · Proton Lumo privacy. Last checked 22 July 2026.
The Numbers That Do Not Appear in Marketing
Three retention rules sit in policy documents rather than product pages, and each one outlives the thing you were told to click.
Google: three years for human-reviewed chats
Google states that conversations reviewed by human reviewers — along with related data such as your language, device type and location info — “are not deleted when you delete your activity. Instead, they are retained for up to three years.”
Read that against the delete button. Clearing your Gemini Apps Activity removes what you can see. It does not reach anything a reviewer has already touched.
Anthropic: seven years for safety scores
Anthropic retains inputs and outputs for up to two years when a chat is flagged under its Usage Policy, and trust-and-safety classification scores for up to seven years.
The scores outlast the conversation by five years. A privacy policy update published 8 June 2026 and effective 7 July also confirms that safety-flagged conversations may be used for training regardless of your opt-out setting.
Anthropic: one toggle, sixty times the retention
Leave training enabled on Free, Pro or Max and Anthropic may retain data in de-identified form for up to five years. Opt out and the retention period is 30 days.
Same product, same account, 60x difference — decided by a signup prompt most users clicked through in 2025.
The Privacy-First Options
Proton Lumo
The strictest published position of any assistant here. Proton states: “Our no-logs policy ensures we keep no logs of what you ask, or what Lumo replies,” and “Lumo doesn’t use your chats to train the AI models. We run the models on servers we control and never send your data to any third parties.”
Saved chat history syncs under zero-access encryption, meaning Proton cannot read it. Guest conversations are erased at the end of each session.
The trade-off is capability. Lumo runs open models on Proton’s own hardware, so it will not match Claude or Gemini on hard reasoning or long-document work.
DuckDuckGo Duck.ai
Routes you to models from OpenAI and Anthropic while stripping identity — no account required, conversations not retained for training. Provider-side abuse exceptions can apply briefly.
You get mainstream model quality without a mainstream account attached to it. You give up memory, file uploads and most tooling.
DeepSeek: the outlier
DeepSeek’s policy states plainly: “we directly collect, process and store your Personal Data in People’s Republic of China,” and retains data “for as long as necessary to provide our Services.”
No fixed period is published. Under Chinese law, companies operating in the PRC can be compelled to provide data to authorities. An opt-out right is stated, without an attached retention period.
That is not a claim about model quality — DeepSeek’s models are strong and cheap. It is a statement about where the text goes and how long it stays.
Choosing by Threat Model
There is no single “most private,” because the question depends on what you are protecting against.
| Your concern | Best fit |
|---|---|
| Vendor storing and training on your text | Proton Lumo, or Duck.ai |
| Mainstream capability with minimum retention | Claude with training opted out (30 days) |
| Work or client-confidential material | A business tier — Team, Enterprise or API |
| Your ISP or network operator seeing your traffic | A VPN — this is the one a VPN actually solves |
| Data leaving your jurisdiction | Avoid DeepSeek; check where your vendor processes |
If you want a VPN for the network-layer reasons, ZoogVPN and Proton VPN publish no-logs policies and have free tiers, so you can verify behaviour before paying.
What Changes Your Exposure Most
Ranked by actual effect, not by how much effort it feels like:
- Do not type it. No setting beats not entering the data.
- Opt out of training where retention is tied to it — on Claude this alone is 5 years down to 30 days.
- Use the right tier. Business plans exclude your content from training by default.
- Use ephemeral modes — ChatGPT Temporary Chat, Gemini with Keep Activity off, Lumo guest mode.
- Set a shorter auto-delete window where the vendor offers one. Gemini defaults to 18 months; 3 is available.
- Check your defaults again after policy updates. Anthropic’s 2025 change and its June 2026 clarification both moved the line under existing users.
Methodology
Every figure comes from the vendor’s own published policy or help documentation, linked at the point of use. Nothing here is derived from testing — we have not audited any vendor’s infrastructure, and no one outside these companies can verify from the outside that stated retention matches actual practice.
What this page compares is what each company has committed to in writing. That is a meaningful floor, and it is enforceable in a way that marketing copy is not. It is not proof of behaviour.
Policies change without notice. This page carries a check date for that reason, and figures are re-verified on update.
Also see: Is ChatGPT private? · Claude vs ChatGPT 2026 · AI Tool Finder
FAQ
Which AI chat is the most private?
By published policy, Proton Lumo — no-logs, zero-access encrypted history, no training on chats. Among mainstream assistants, Claude with training opted out has the shortest stated retention at 30 days.
Is there a confidential version of ChatGPT?
ChatGPT Enterprise and the OpenAI API exclude business data from training by default. On consumer plans, Temporary Chat is the closest equivalent — not used for training and deleted within 30 days.
How private is Claude AI?
It depends entirely on one setting. With training enabled, Anthropic may retain data up to five years. Opted out, retention is 30 days. Flagged sessions are an exception: inputs and outputs up to two years, safety classification scores up to seven.
Does deleting my chats actually delete them?
Usually within 30 days, with exceptions that matter. Google retains human-reviewed Gemini conversations up to three years regardless of deletion. Legal preservation orders can override any vendor’s policy, as the New York Times litigation did for OpenAI.
Which AI chatbot is the least restricted?
Restriction and privacy are different axes, and a permissive content policy often comes with weaker data protection. DeepSeek is permissive on content but publishes no fixed retention period and processes data in China.
Do paid plans get better privacy than free ones?
Sometimes, and not in the way people assume. On Google’s API, free-tier content is used to improve products while paid-tier content is not. On ChatGPT and Claude consumer plans, paying does not change the training default — the toggle does.