Privacy

AI Chat Privacy 101: What's Actually Private When You Talk to AI

A beginner's guide to AI chat privacy: why no AI chatbot is truly end-to-end encrypted, the 5 questions to ask, and how to tell if a tool is safe enough for sensitive content.

The Refrakto team13 min read
A padlock resting on an open paper notebook in warm neutral tones — the metaphor for honest, partial privacy: locked, but not invisible.

In 2026, no AI chat product is truly end-to-end encrypted — the AI has to read your message in order to respond. That's the honest floor. But there are five specific things you can ask any AI chat tool to know whether it's safe enough for sensitive content: who reads the message, whether it's stored, whether it trains the model, where it lives legally, and who else gets a copy. This is the beginner's guide.

If you've ever paused before typing something personal into ChatGPT, Gemini, Claude, or any other AI chat tool, this article is for you. The questions are answerable; the differences between products are real; and once you know what to look for, the privacy policy becomes a five-minute read instead of a forty-page anxiety. We'll also be honest about where Refrakto sits — including the things we deliberately don't claim.

For a deeper, more technical version focused on couples and relationship apps specifically, see our companion piece on couples app privacy red flags. This one stays at 101 level.

The basic mental model — what actually happens when you type

Every AI chat product, without exception, works in roughly the same way. Knowing the steps is the whole game.

  1. You type a message on your device. Locally, on your phone or laptop, in plain text.
  2. The message travels to the company's servers. Usually encrypted in transit (HTTPS / TLS) — the same encryption your bank uses. This protects you from someone snooping the wifi between your device and the company. It does not protect you from the company itself.
  3. The message reaches the AI model. The model — a large language model running on the company's (or a partner's) servers — reads your message. It has to. That is how it generates a response.
  4. A response goes back to you. Same route in reverse.
  5. The message may be logged, stored, retained. This is where products diverge. Some keep your messages forever to improve their models. Some keep them for a few weeks for safety review. Some delete them shortly after the response.
  6. The message may be used for training. A separate decision from retention. The company may use your content to fine-tune future versions of the model — sometimes by default, sometimes only if you opt in, sometimes never.
  7. Other things may be attached. Ad-tech pixels (Meta, Google) may know you visited the page. Analytics tools may log that you sent a message. None of this is about the content of your message — but for sensitive topics, even the metadata matters.

The privacy of any AI chat tool is essentially a set of choices about steps 5, 6, and 7. The product's marketing copy tells you what they want you to know. The privacy policy tells you what's actually true.

What "end-to-end encrypted" really means — and why no AI chatbot has it

End-to-end encryption, or E2E, is a specific technical thing. It means your message is encrypted on your device using a key the server does not have. The server stores ciphertext — bytes that look like random noise — and the only people who can decrypt the message are you and your intended recipient. Signal works this way for messages between two people. WhatsApp uses the same protocol for chats. iMessage between Apple devices works this way.

In all of those examples, the recipient is a person with a device that holds the other half of the key. The server never sees the plaintext, and the company running the service is technically incapable of reading your conversations.

Now think about an AI chat product. Your "recipient" is the AI model, which lives on the server. For the AI to respond, something on the server has to read your message in plaintext. There is no way around this. You can encrypt the message in transit, encrypt it at rest, build careful access controls — but at the moment the AI generates a response, the message is in plaintext somewhere on the company's infrastructure.

This is why a marketing line like "your AI coach is end-to-end encrypted" should make you suspicious, not reassured. Either the company is misusing the term — they probably mean encrypted in transit and at rest, which is real but different — or the AI isn't actually doing AI things, or there's a research-grade homomorphic-encryption setup behind the claim (vanishingly rare in 2026, and slow, and they'd be shouting about it).

The honest version: AI chat products can be encrypted in transit, encrypted at rest, and architecturally careful about who can access logs. They cannot be end-to-end encrypted in the Signal sense, because the AI on the server has to be one of the ends. Any product that blurs this line is either confused or hoping you are.

The spectrum of AI chat privacy — 5 levels from worst to best

There is no single "AI privacy." There is a spectrum, and the gap between the worst and best is enormous. Here's a beginner's map.

LevelWhat it looks likePrivacy posture
1. Free consumer chatbot, ad-fundedA free tool with no clear business model, or one funded by ads. Your conversations may train models by default. Ad-tech pixels may fire on the page. Policy is broad and vague.Worst. Treat as public.
2. Free chatbot with user-controlled opt-outFree or freemium, but you can turn off "improve the model" in settings. Default is often opt-in; opt-out is buried but real.Better, but only after you find and toggle the switch. Most users never do.
3. Paid product on an API tier with no-training commitmentA paid app built on top of OpenAI, Anthropic, or similar — using the API tier where the provider contractually does not train on customer content. No advertising trackers on the chat route. Retention is short and scoped to providing the service.Genuinely much better. The floor most thoughtful apps sit on.
4. API tier with a DPA, EU hosting, and granular consentAll of the above, plus: a Data Processing Agreement between the app and its processors, data physically hosted in the EU (strictest privacy regime), explicit GDPR Article 9 consent for sensitive content, and one-tap export and deletion.This is what a thoughtful 2026 product looks like. Refrakto sits here.
5. Fully on-device LLMThe model runs on your phone or laptop. Your message never leaves your device. Apple Intelligence's on-device tasks work this way for narrow features.Theoretically the strongest privacy. In practice, on-device models in 2026 are smaller and less capable than the best server-side ones, so most useful AI chat still lives at level 3 or 4.

Most people, asked to picture "AI chat," picture level 1 or 2 — because those are the free products everyone has heard of. They assume the spectrum doesn't go further. It does, and the difference is meaningful when the content is personal.

The 5 must-ask questions for any AI chat tool

You don't need a law degree. You need five questions. If a product's website or policy can't answer them clearly, that itself is the answer.

1. Is my message used to train the AI model? Search the privacy policy for the words train, improve our models, or service improvement. The good answer is "no, never" or "only if you explicitly opt in." The bad answer is "we may" with no opt-out. The worst answer is no mention at all.

2. How long is my message retained, and who can read it? Some products keep messages forever. Some keep them 30 days for safety review. Some delete shortly after the response. Inside the company, ask: who has access to the logs? A good product names access controls. A bad one is vague.

3. Where is the data physically stored? For EU users, EU hosting matters — it brings the conversation under GDPR with no jurisdictional ambiguity. For everyone, ask: is the data in a jurisdiction where the government can compel access without your knowledge? (The US CLOUD Act, for example, can reach data stored by US companies anywhere in the world.)

4. Is there advertising or third-party tracking on the page where I chat? A product that runs Meta Pixel or Google Analytics on the chat route is telling those companies that you used it, even if the message content stays private. For sensitive content, the metadata is part of the privacy story.

5. Can I delete my data, and how fast? A good product has one-tap deletion in settings, runs in under a minute, and confirms the deletion. A bad one buries deletion behind an email to support, with a 30-day wait. GDPR Article 17 gives you the right; the product's implementation tells you whether they take it seriously.

If you can answer these five questions for a product, you know its privacy posture better than 95% of its users.

ChatGPT, Gemini, and the major chatbots — what they actually do

A quick beginner's read on the most-asked products, as of mid-2026. (Privacy policies change; always check the live version.)

  • ChatGPT (consumer product). Default: conversations are retained and may train models. You can opt out of training in Data Controls in settings. Temporary chats don't appear in history but may still be retained briefly for abuse review. Free tier and Plus tier have the same baseline policy.
  • ChatGPT Enterprise / Team / API. A different beast. OpenAI contractually does not train on this content. Retention is scoped. Most thoughtful apps built on top of OpenAI use the API tier specifically because of this commitment.
  • Google Gemini. Default: conversations retained for up to 18 months by default; reviewed by humans to improve the service unless you turn off Gemini Apps Activity. Workspace Gemini (paid) has stricter commitments.
  • Anthropic Claude (consumer claude.ai). Default: conversations are not used to train models unless you opt in via feedback. Retention is shorter than ChatGPT's default. API customers have a contractual no-training commitment.
  • Meta AI (in Instagram, WhatsApp, Facebook). Default: content used to improve Meta's models. Integrated with Meta's broader ad-tech ecosystem. The least private of the major chatbots for sensitive content.
  • Microsoft Copilot. Depends heavily on which Copilot — consumer Copilot has different defaults than Copilot for Microsoft 365 (enterprise), which has stricter commitments.

None of these is "private" the way Signal is private. All of them are reading your messages on the server side. The question is what they do with the messages afterward, and the answers vary a lot.

What Refrakto does (and what we explicitly don't claim)

Since this is our blog, the honest disclosure. Here's exactly where Refrakto sits on the spectrum, in plain language.

We are not end-to-end encrypted, and we will not claim to be. Refrakto is an AI coach. The AI needs to read your message in order to respond. Any AI chat product that markets itself as E2E is either misusing the term or running a setup that would make the AI useless. We chose to be honest about that tradeoff up front.

What we do instead:

  • Encrypted in transit and at rest. TLS 1.3 between your device and our servers, column-level encryption in our database.
  • EU-hosted. Supabase Frankfurt and Vercel EU. Your data physically lives in the EU, under GDPR.
  • Never trained on. We use Anthropic's API tier with a contractual no-training commitment. Your conversations are not used to train Claude, and they are not used to train any internal model of ours.
  • Never sold. No advertising relationships, no data brokers, no resale.
  • No trackers on signup, chat, or payment routes. No Meta Pixel, no Google Analytics, on the pages where you actually share anything sensitive.
  • GDPR Article 9 explicit consent. At signup, we ask for separate, explicit consent for processing relationship and emotional-wellness data. Not buried in a 40-page Terms of Service.
  • One-tap export, one-tap delete. From Settings, both run in under 30 seconds. Deletion is real deletion, not "scheduled" or "anonymized."

That's the architecture. Sitting it on the level table above, Refrakto is firmly at level 4. We'd like to get parts of it closer to level 5 over time (some on-device processing for crisis detection is already there), but we'll only claim what's actually true.

Try Refrakto free if that posture matches what you want. Or just keep reading.

A short note on "is this safe enough for couples?"

The most common version of this question we get is from people thinking about using an AI tool — Refrakto or otherwise — for relationship content. Conversations about a partner. Practice scripts for hard talks. Things they wouldn't want screenshotted.

The honest answer: it depends on the product, not on the category. A free general chatbot is the wrong place for that content. A paid, EU-hosted, no-training AI built specifically for relationship work is a much safer place. The questions above — retention, training, hosting, trackers, deletion — are the questions to ask.

What it's never safe for: crisis content. If you're in crisis, AI is not the right place. Refrakto is a coaching tool, not a substitute for licensed therapy or a crisis service. If you're in crisis, please reach out: 988 in the US, 116 117 in Germany, 116 123 (Samaritans) in the UK.

For the deeper question of when AI is even the right tool for relationship work, see AI relationship coach vs therapy.

A 5-minute checklist before you sign up to any AI chat product

Open the product's website in one tab and its privacy policy in another. Spend five minutes.

  1. Does the homepage promise "end-to-end encryption"? If so, does the privacy policy back it up with specifics, or does it walk it back to "encrypted in transit"?
  2. Search the privacy policy for train. Is there a clear opt-out, or better, is training off by default?
  3. Search for retain or retention. How long do they keep messages?
  4. Where is the data stored? If it matters to you, can they say EU with a straight face?
  5. Open the developer tools (or just trust your gut) — does the chat page run Meta Pixel, Google Analytics, or other ad-tech?
  6. Is there a delete button in settings, or do you have to email support?

If most of those come back well, the product is taking privacy seriously. If most come back vague, your instinct to hesitate is right.

For the same checklist applied specifically to couples and relationship apps — with red flags and green flags side by side — see couples app privacy. And for one of the most common surfaces where this matters most, perspective-taking in relationships walks through why the AI you choose to think through hard moments with deserves the same scrutiny you'd give a therapist.

The bottom line

In 2026, AI chat privacy is a spectrum, not a yes-or-no. No AI chat product can honestly claim end-to-end encryption — the AI is one of the ends, and it needs to read your message. What products can do is be careful about retention, training, hosting, trackers, and deletion. The differences between products are large enough to matter.

Five questions, five minutes. That's the literacy. Once you have it, the privacy policy becomes a tool you use, not a document you fear.

We built Refrakto trying to sit honestly at the better end of the spectrum, and to publish the architecture so you can check. Start free if that's the kind of product you want. Either way, ask the five questions of whatever tool you're using. Your private life deserves the audit.

Refrakto is a coaching tool, not a substitute for licensed therapy. If you are in crisis, please reach out to your local hotline: 988 (US), 116 117 (DE), 116 123 (UK Samaritans).

Refrakto is a coaching tool, not a substitute for licensed mental health care. If you’re in crisis, please contact a local hotline (988 in the US, 116 117 in Germany, 116 123 Samaritans in the UK) or a licensed professional.

Published June 15, 2026 · Refrakto