privacy research · August 2026
Your AI chatbot trains on you. The API running the same model doesn't.
Ask ChatGPT, Claude or Gemini a question in the app and you are on the weakest privacy tier that company offers. Send the exact same prompt to the exact same model through its developer API and you are on a materially better one.
Not because API companies are nicer — because the defaults differ. Consumer tiers train on your conversations; API tiers don't, and they cap retention where consumer tiers don't cap it at all.
And the part the marketing skips: the API is not private in ways that matter. Prompts still arrive in plaintext. Abuse pipelines log them for weeks regardless of any setting. A court can override the published policy — that already happened. And your key is bound to your name and card.
The scale
Two billion people, on the weakest defaults offered
Consumer defaults matter because of how many people sit inside them. Best available figures, August 2026 — units differ and the estimates carry 2–10× spreads, so read the direction, not the decimals.
Meta’s number counts passive encounters inside WhatsApp and Instagram — one tracker puts daily actives near 40M. Grok’s includes usage embedded in X. Copilot estimates span 33M to 420M. Only ChatGPT and Gemini are company-disclosed.
The ladder
Five places a prompt can go
Every privacy claim in this post is really a claim about which rung you’re on. Higher rungs don’t ask you to trust harder — they give the provider less to be trusted with.
- 01Consumer chat appTrains by default · retention measured in account lifetimes · human review sampled
- 02Consumer app, toggles offNo training. Retention floors and safety carve-outs survive the toggle anyway
- 03Standard API tierNo training by default · 30-day ceiling for abuse monitoring · human review on flagged content
- 04Zero data retentionNothing stored. Gated by approval at most providers; self-serve at Groq and xAI
- 05Confidential computing or on-deviceThe operator cannot read it — architecture, not policy. Metadata still visible except on-device
Rung 4 is the one the NYT preservation order could not reach — you cannot be ordered to preserve what was never stored.
Decompression
”Your data is safe with us” is seven claims
Split them and most provider marketing turns into specific, checkable statements — some true, some not. No training ≠ no logging ≠ no human access. Conflating those three is where the marketing lives.
Training default
Used to train by default? The axis everyone argues about — and only one of seven.
Retention
How long they keep it, and separately, what deletion actually does. Those are different events, sometimes years apart.
Human access
Employees and contractors reading conversations. Review pipelines have their own clock your delete button can’t reach.
Abuse-monitoring retention
Typically 30 days, regardless of your training setting. This is how “we don’t train” coexists with “we’re storing your prompt right now.”
Legal hold
A court order outranks every published policy. Not hypothetical — see the NYT order.
Zero data retention
“ZDR exists” and “you can have ZDR” are different claims. Check who qualifies.
Residency & jurisdiction
Whose law, which subprocessors, which country. The API tier can improve the policy without changing the venue.
Metadata
Who, when, how often, how many tokens. No tier, toggle, or ZDR agreement hides it. Only moving inference does.
The evidence
Same company, same model, different rules
Read the training column down the page: every consumer row says yes or forced choice, and every API row says no except the Gemini API free tier, which trains like a consumer product because it is priced like one.
On either side of the consumer/API line, the tier you don’t pay for with money is the tier you pay for with data. Read retention: consumer says account life, API says 30 days or less. That’s the honest claim — a difference in defaults and limits, not in kind.
| Provider | Trains by default | Retention | Human review | ZDR |
|---|---|---|---|---|
| ChatGPTFree / Plus / Pro | yes · opt-out | account life | sampled | — |
| OpenAI API | no | 30 days | flagged only | on approval |
| ClaudeFree / Pro / Max | forced choice | 5 yr on / 30 d off | flagged only | — |
| Anthropic API | no | ≤30 days | flagged only | by arrangement |
| Gemini app | yes · opt-out | 18 mo; 3 yr if reviewed | yes, sampled | no · 72 h floor |
| Gemini APIfree tier | yes | unpublished | annotation | — |
| Gemini paid / Vertex | no | 24 h cache | abuse only | config + exception |
| Meta AI | yes · no US opt-out | account life | yes | — |
| Copilotconsumer | yes · opt-out | account life | unclear | — |
| Azure OpenAI | no | 30 days, outside tenant | flagged only | gated application |
| Grokconsumer | disputed | account life | unclear | — |
| xAI API | no | 30 days encrypted | abuse only | self-serve toggle |
| DeepSeekapp · PRC servers | yes | "as long as necessary" | unclear | — |
| PerplexityFree / Pro / Max | yes · opt-out | unpublished since Jul 2026 | unclear | — |
Human-review and legal-hold are the columns where the two tiers converge. Any summary that skips them is selling the API tier, not describing it.
Bring your own key
Inference hosts make a different set of promises
With a bring-your-own-key client you often aren’t calling OpenAI or Google at all. These policies are their own, and they range from best-in-class to read-carefully.
| Provider | Trains | Logs prompts | The catch |
|---|---|---|---|
| Fireworks | no | no | Responses API state kept 30 d |
| Together | opt-in only | no | “Passthrough models” forward traffic under the upstream’s policy |
| Groq | no | no · 30 d if flagged | ZDR now self-serve; batch files kept 30 d |
| Replicate | no blanket promise | API 1 h · web indefinite | Web-run predictions persist until manually deleted |
| OpenRouter | router | no · opt-in for 1% off | Your effective policy is the upstream’s. Same model name can resolve to endpoints with different retention — use the ZDR routing parameter |
| AWS Bedrock | no | per-model modes | “Bedrock stores nothing” is stale; some models share data with the vendor |
| near.ai · Phala · Tinfoil | no | cannot | Trust moves to Intel/NVIDIA silicon and to you verifying the attestation. Metadata still visible |
Every row above except the last is a promise. The last is architecture: the operator cannot read the traffic, and attestation still does not review the code that runs once it is decrypted.
The ledger
What the API tier buys — and what it doesn’t
Buys you
- A no-training default at every major provider, with no toggle to remember.
- A retention ceiling — 30 days or less — instead of an indefinite one.
- A path to nothing-stored via ZDR or a TEE. Consumer apps don’t offer this at any price.
- Insulation from legal holds. ZDR API traffic was excluded from the NYT order because there was nothing to preserve.
Doesn’t buy you
- Plaintext protection. TLS protects the wire, not the endpoint. The provider still sees everything you send.
- Freedom from logging. 30 days is not zero, and flagged content can be read by a human.
- Anonymity. A key is bound to a billed identity with a payment method — arguably worse than a pseudonymous consumer account.
- Metadata privacy. Identical on both tiers.
- Freedom from your client. A bring-your-own-key app that phones home undoes everything the API tier bought.
The only data reliably outside a legal hold is data that was never stored.
If you’re staying put
Turn the training off
As of August 2026 — these UIs move. Three things no toggle does anywhere: delete what’s already collected, shorten abuse-monitoring retention, or undo training runs that already happened.
- ChatGPTSettings → Data Controls → “Improve the model for everyone” → offTemporary Chat still retained up to 30 days.
- ClaudeSettings → Privacy → “Help improve Claude” → offDrops retention 5 yr → 30 d. Thumbs feedback still kept 5 yr.
- Geminimyactivity.google.com → Gemini Apps Activity → off; auto-delete 3 monthsAlready-reviewed chats stay 3 yr. 72-hour floor regardless.
- Meta AIEU/UK: GDPR objection form. US: “third-party info” formUS requests are case-by-case, no guarantee. Don’t invite Meta AI into group chats.
- CopilotSettings → Privacy → conversation training and voice training → offTwo separate switches. Opt-out excludes “product improvement,” ads, safety.
- GrokSettings → Data Controls → off; use Private Chat. Separately on X: Privacy → GrokThe X setting governs your posts, not just your chats.
- DeepSeek“Improve the model for everyone” — region-dependent, may not appearYour data is in the PRC either way.
- PerplexitySettings → Preferences → AI → “AI Data Retention” → offRe-check after updates; the July 2026 rewrite moved commitments out of the policy.
paths as of August 2026
A consumer user who flips every toggle gets much of the API’s training posture. What they cannot get is the retention ceiling — and their deletion promises have already been overridden by a court once.
Disclosure
Where teemoon fits
teemoon is a private-AI chat app for iPhone, built on the ladder above. You bring the key — or no key. The app never sits in the middle, so every advantage and limit of the API tier applies. Inference runs wherever you point it:
- 01On the phone — Gemma 4 via LiteRT-LM. Nothing leaves the device.
- 02On a server you own — llama.cpp, Ollama, LM Studio, any OpenAI-compatible endpoint.
- 03Any provider with an OpenAI-compatible /chat/completions endpoint — OpenAI, Groq, Fireworks, OpenRouter, whoever. an Anthropic key does not work — Claude on near.ai does. teemoon is the client; the rung you land on is whichever one that provider offers.
- 04near.ai's confidential fleet — the most private of the remote options, and the most layered. the phone verifies the hardware itself — the TDX quote checked against Intel's chain, the GPU against NVIDIA's — then the software: image provenance and a measured compose hash that pin the exact code and weights, quantisation included. that settles identity, not behaviour; published source reads cover what the code does with your plaintext. the message itself is end-to-end encrypted to the enclave — near.ai only. a failed check blocks the send; a check that cannot finish asks first.
Attestation names the code that is running; a fable miniaudit asks one question of that code: does it copy the message anywhere but the model. The audit link is gated on the attested identity — if the exact running image is not in the index, no link appears, so a link can never overclaim. Expert view shows who can read the plaintext.
The reviews live at github.com/teemoonai/audits. They are AI-assisted reads by the teemoon project, not an independent audit.
Nothing to phone: no teemoon backend, no accounts, no analytics. Keys stay on the phone; history stays local. Destinations are labeled, including which paths are not end-to-end encrypted. Metadata is still visible to the provider and the network, wherever inference runs.
Open questions
What we haven’t settled
- Anthropic API retention — Privacy Center says ≤30 days; secondary reports describe a 7-day default with 30-day opt-in, and a 30-day floor for “Covered Models” even under ZDR.
- Grok consumer default — most guides say on-by-default; at least one legal source says opt-in. Needs a direct policy read.
- DeepSeek opt-out — whether a working non-EU toggle exists in-product is disputed.
- Perplexity Sonar ZDR — the immediate-deletion claim comes from third-party summaries only.
- Microsoft retroactivity — Microsoft’s own pages conflict on whether opting out covers past conversations.
- Bedrock per-model modes — newly restructured docs; the row is a snapshot, not a live pull.
- Human review at Meta, Copilot, Grok, DeepSeek, Perplexity is undocumented — marked “unclear” rather than guessed.
Primary sources · checked 11 Aug 2026
Sources and as-of dates
OpenAI API data controls · OpenAI on NYT data demands · NYT v. OpenAI preservation order · Order terminated, Oct 2025 · Anthropic consumer terms update · Anthropic retention · Anthropic ZDR scope · Gemini Apps Privacy Hub · Gemini API ZDR · Vertex data governance · Meta AI opt-out guide · Copilot privacy FAQ · Azure abuse monitoring · xAI API security FAQ · DeepSeek privacy policy · Perplexity data collection · Fireworks data handling · Together privacy · Groq your-data · Replicate retention · OpenRouter provider logging · Bedrock data retention · near.ai private inference · Phala confidential AI · Tinfoil · teemoon — teemoon.ai · app README, local checkout Aug 2026 · teemoonai/audits. The app source is public at teemoonai/teemoon-ios.