Tool Reviews

AI Assistant Data Retention and Deletion: A 2026 Guide

Compare AI memory, chat retention, training, temporary chats, coding context, exports, deletion, and enterprise controls.

  • #AI privacy
  • #data retention
  • #AI memory
  • #data deletion
  • #enterprise AI

An AI assistant can remember too little, remember too much, or remember the wrong thing in the wrong place. Those are product problems. They are also data-governance problems, because the word “memory” can refer to saved preferences, searchable chat history, project files, repository indexes, administrator-visible records, provider safety logs, or a model context assembled for one request.

The most visible failure is almost comic: tell an assistant about one hobby once, and it starts bending unrelated brainstorming sessions around that hobby. The same mechanism becomes serious when a past health concern appears in a work chat, a client name leaks into another project, or old repository assumptions guide a coding agent after the architecture has changed.

This guide separates those mechanisms. It compares five provider families across ten data concepts, then gives decision paths for personal brainstorming, confidential client work, source code, health or financial notes, and regulated enterprise use. Product facts were checked against official documentation on 2026-07-24. Controls, rollouts, contracts, and regional availability can change; the “Unknowns” column is part of the answer, not a defect to be ignored.

This is an operational privacy guide, not legal advice. Do not use it as a substitute for a data-processing agreement, sector-specific review, or advice from qualified counsel.

The demand signal: users want continuity without unwanted carryover

Public complaints do not prove prevalence, and they are not authoritative sources for product behavior. They do show what buyers are trying to solve.

  • Users describe assistants bringing unrelated past topics into a new conversation, making personalization feel intrusive rather than helpful (memory annoyance thread).
  • Another discussion describes persistent fixation on old conversations and the difficulty of getting a genuinely fresh answer (past-conversation fixation thread).
  • Coding-agent users report long investigations filling the available context and then losing direction, showing that “more repository access” and “better working context” are not the same thing (coding-agent context thread).
  • Subscription users also report sessions stopping after heavy context use, making retention, context size, and plan limits part of one purchase decision even though they are technically separate controls (subscription limit thread).

Treat those links as anecdotal demand evidence. Use official provider documentation for the facts in the comparison below. For a focused treatment of the repeated-hobby problem, read AI Memory Without the Awkward Coworker Effect. For the engineering distinction between working, episodic, and semantic memory, see the AI agent memory guide.

First principle: similarly named controls are not equivalent

Five separations prevent most bad decisions:

  1. Saved memory is not chat history. A provider may store a derived preference separately from the chat that produced it.
  2. No training is not no retention. Content can be excluded from model training while remaining in chat storage, safety logs, files, indexes, backups, or administrator exports.
  3. Temporary is not immediate deletion. Temporary or incognito modes can hide a chat from the user interface while the provider retains it for a documented period.
  4. Local execution is not local inference. A coding agent may run commands on your machine while sending prompts, file excerpts, tool results, or repository context to a remote model service.
  5. User deletion is not enterprise erasure. A retention policy, legal hold, compliance export, connected application, copied file, or derived memory may survive a user-visible deletion.

The detailed LLM API data retention checklist applies the same separation to provider logs, application state, caches, and backups. Use it when a chat product is only one component in a larger system.

How to read the comparison

Each table covers one data concept. Every row names:

  • the plan or commercial arrangement;
  • the exact product surface;
  • the last-checked date;
  • the official source used;
  • the unresolved questions that must be verified in the account, contract, or deployment.

“No documented equivalent” means the cited official material did not establish an equivalent control for that surface. It does not mean the provider stores nothing. “Not applicable” means the product category is different, not that a privacy question disappears.

1. Saved memory and durable personalization

ProviderPlanProduct surfaceWhat the official documentation establishesLast checkedOfficial URLUnknowns
OpenAIChatGPT consumer plans; availability can vary by account and planChatGPT saved memories and reference chat historySaved memories and chat-history-derived context are distinct. Deleting a chat does not by itself delete a saved memory; complete removal can require deleting both the memory and the source chat.2026-07-24OpenAI Memory FAQExact rollout, controls visible in a specific region, and whether an account uses the latest memory experience must be checked in that account.
AnthropicClaude Free, Pro, and Max; Team and Enterprise have rollout and admin differencesClaude web, desktop, and mobile memoryClaude can create categorized memory entries and separate project memories. Users can pause or reset memory. Current documentation distinguishes new and legacy experiences.2026-07-24Claude chat search and memoryRollout state, organization policy, and the exact effect of deleting a source chat differ by memory experience and must be verified in the visible interface.
GooglePersonal Google Account, eligible adult user; not a work, school, or supervised accountGemini Apps Personal Intelligence and past-chat MemoryPast-chat Memory requires Keep Activity to be on. Removing remembered information can require deleting every chat containing it; connected-app information requires separate disconnection and deletion steps.2026-07-24Gemini past-chat MemoryFeature availability varies by surface and region, and Google warns that personalization can take time to reflect deletions or source changes.
MicrosoftMicrosoft Copilot with a personal Microsoft accountCopilot personalization and memoryUsers can disable personalization, inspect remembered information, delete specific memories, or delete all memory. Deleting memory does not delete conversation history.2026-07-24Microsoft Copilot privacy controlsAvailability varies by country and account. The documentation does not make personal Copilot memory equivalent to Microsoft 365 Copilot memory.
GitHubAll paid Copilot plans; managed plans require policy enablementCopilot cloud agent, code review, and Copilot CLI MemoryCopilot Memory stores repository facts and user preferences. Repository facts stay repository-scoped; unused entries are automatically deleted after 28 days, with the timer potentially resetting after use and validation.2026-07-24GitHub Copilot MemoryThe feature is in public preview. Preview behavior, exact export coverage, and whether all agent surfaces use the same memory type can change.

The repeated-hobby complaint is a scope failure, not merely a storage failure. A useful durable preference should say when it applies. “I like cycling” is not a reason to frame a contract summary around cycling. “When planning my personal weekend exercise, prefer cycling routes” is bounded and testable.

2. Chat history and searchable past conversations

ProviderPlanProduct surfaceWhat the official documentation establishesLast checkedOfficial URLUnknowns
OpenAIChatGPT consumer and managed workspacesChatGPT chats, archives, files, projects, and LibraryOrdinary chats remain until deleted. Archiving hides rather than deletes. Files saved to Library can be managed separately from the chat that introduced them.2026-07-24ChatGPT chat and file retentionLegal or security exceptions, workspace policy, Library availability, and feature-specific file expiry must be checked separately.
AnthropicClaude paid plans for past-chat search; memory availability variesClaude chat search, projects, and historyClaude can search past chats on supported paid plans. Searches outside projects and searches inside a project have different boundaries; incognito chats are excluded from user-visible history and memory.2026-07-24Claude chat search and memoryTeam and Enterprise may remain on a legacy experience during rollout. Admin exports and retention can include content users do not see.
GooglePersonal Google Account with Keep Activity onGemini Apps Activity and recent chatsGemini Apps Activity can store prompts and shared files or media. The default auto-delete period documented for eligible personal activity is 18 months, with 3, 18, 36 months, or no auto-delete available.2026-07-24Manage Gemini Apps activityThe exact activity types, age rules, regional controls, and work or school behavior differ. Connected services can retain separate copies.
MicrosoftMicrosoft Copilot personal accountCopilot conversation historyMicrosoft documents that personal Copilot conversation history is retained for 18 months and can be deleted by item or in full. Memory is a separate control.2026-07-24Microsoft Copilot privacy controlsProduct variants, browser data, uploaded-file copies, and work-account records are outside this single personal-surface statement.
GitHubCopilot plans with CLI, Chat, or cloud agent accessCopilot CLI session state, GitHub chat surfaces, and repository contextCopilot CLI keeps local session state; if sessions are synced, deleting local files does not delete the GitHub-hosted synced copy. Repository indexing and Copilot Memory are additional stores.2026-07-24Copilot CLI configuration directoryThe retention period for each synced session surface and the relationship to organization policies require product- and contract-specific confirmation.

Do not treat a sidebar as an inventory. An archived chat, a project file, a synced coding session, a saved memory, and a connected-app index can all be absent from the main history while still existing.

3. Model training and product-improvement controls

ProviderPlanProduct surfaceWhat the official documentation establishesLast checkedOfficial URLUnknowns
OpenAIChatGPT and Codex consumer services; Business, Enterprise, Edu, and API under business termsChatGPT, Codex tasks, Codex full environments, and APIConsumer content may be used to improve models unless the user opts out. Codex has a separate full-environment training control. Business and API inputs and outputs are not used for training by default unless an organization opts in.2026-07-24How OpenAI uses data to improve modelsFeedback submissions can have different treatment. A ChatGPT toggle may not control Codex full-environment sharing, so both surfaces must be checked.
AnthropicClaude Free, Pro, and Max; commercial Team, Enterprise, API, and third-party platformsClaude chat and Claude CodeConsumer users can choose whether new chats and coding sessions are used to improve Claude. Commercial data is not used to train generative models unless the customer affirmatively participates in a program.2026-07-24Claude Code data usageFeedback, development-partner programs, trust-and-safety records, and model-training runs already in progress have separate rules.
GooglePersonal Gemini Apps with Keep Activity on or offGemini Apps activity, feedback, audio, Live media, and human reviewWith Keep Activity on, activity can be used to provide, develop, and improve services, including generative AI models, with documented human review. With Keep Activity off, future chats are not used to train models unless feedback is sent.2026-07-24Gemini Apps Privacy HubAudio and Live media have additional controls. Region, age, feedback, and data already reviewed by service providers change the result.
MicrosoftMicrosoft Copilot personal account; Microsoft 365 work account differsCopilot conversation activity and voice training controlsPersonal users can opt out of training on conversation activity and voice conversations. This does not describe Microsoft 365 Copilot under enterprise data protection.2026-07-24Microsoft Copilot privacy controlsSeparate settings may govern ads, personalization, diagnostic data, and work-account processing. Confirm each rather than inferring from one toggle.
GitHubCopilot Individual, Business, and EnterpriseCopilot repository indexes and Copilot product dataGitHub states that indexed repositories are not used for model training. This is narrower than a provider-wide statement about every prompt, feedback submission, or third-party model.2026-07-24GitHub repository indexingThe selected model provider, feedback path, organization policy, and preview feature may add terms not covered by the indexing statement.

The safest label in an internal decision record is not “no training.” Write the actual scope: “Business workspace prompts and outputs excluded from foundation-model training by default; feedback path disabled; connected service terms reviewed separately.”

4. Temporary, incognito, and memory-off chats

ProviderPlanProduct surfaceWhat the official documentation establishesLast checkedOfficial URLUnknowns
OpenAIChatGPT plans where Temporary Chat is availableChatGPT Temporary ChatTemporary Chats do not appear in history, do not use or create memories, and are not used to train models. OpenAI documents automatic deletion from its systems within 30 days, subject to stated exceptions.2026-07-24OpenAI Temporary Chat FAQCustom instructions can still apply, third-party GPT actions have their own policies, and legal developments or workspace controls can affect retention.
AnthropicClaude Free, Pro, Max, Team, and EnterpriseClaude incognito chats outside projectsIncognito chats are not saved to user chat history or memory and are not used for training. They are retained for 30 days by default; Enterprise custom retention can be longer, and organization exports can include them.2026-07-24Claude incognito chatsProfile information can still influence the session. Enterprise visibility and exact retention depend on organization policy.
GooglePersonal Gemini AppsGemini Temporary Chat and Keep Activity offGoogle documents that when Keep Activity is off, chats are still saved with the account for up to 72 hours to provide the service, process feedback, and protect users. Temporary Chat is not the same as deleting other Google-service copies.2026-07-24Gemini Apps activity controlsThe exact Temporary Chat interface, surface availability, feedback behavior, and connected-service copies must be checked in the current account.
MicrosoftMicrosoft 365 Copilot work or school accountMicrosoft 365 Copilot temporary chatMicrosoft warns that temporary chat data can still follow the organization’s retention policy and may be accessible to the IT administrator during that period.2026-07-24Microsoft 365 Copilot memoryConsumer Copilot and Microsoft 365 Copilot have different controls. Purview holds and tenant configuration can change deletion timing.
GitHubCopilot Individual, Business, and EnterpriseCopilot Chat, CLI, cloud agent, and code reviewThe reviewed GitHub documentation does not establish a provider-wide temporary-chat mode equivalent to ChatGPT Temporary Chat, Claude incognito, or Gemini Temporary Chat. Local CLI history and synced sessions have separate deletion paths.2026-07-24Copilot CLI context managementWhether a specific IDE offers an editor-level ephemeral mode and how it maps to GitHub retention must be verified for that client and version.

Temporary mode is useful for preventing future personalization. It is not a vault. If the material should not reach the provider at all, do not enter it merely because the chat is temporary.

5. API retention and stateful endpoints

ProviderPlanProduct surfaceWhat the official documentation establishesLast checkedOfficial URLUnknowns
OpenAIAPI organizations; special controls require eligibility and approvalOpenAI API abuse-monitoring logs and application stateAPI data is not used for training by default. Abuse-monitoring logs may retain customer content for up to 30 days by default. Some endpoints store application state until deletion or for feature-specific periods. ZDR and Modified Abuse Monitoring have eligibility and endpoint limits.2026-07-24OpenAI API data controlsEndpoint, tool, file, caching, background mode, region, and legal exceptions must be evaluated line by line.
AnthropicAnthropic API commercial customersMessages API and longer-lived customer-controlled featuresAnthropic states API inputs and outputs are deleted from its backend within 30 days by default, with exceptions for longer-lived features, agreed ZDR, policy enforcement, and law.2026-07-24Anthropic commercial retentionFiles, batches, feedback, covered models, third-party platforms, and negotiated agreements can differ.
GoogleGoogle Cloud customers using managed models on Vertex AIVertex AI generative AI, grounding, caching, and live session resumptionGoogle states it does not train managed models on customer data without permission or instruction. Some features retain data: Search or Maps grounding has documented 30-day storage, and Live session resumption can cache data for up to 24 hours.2026-07-24Vertex AI zero data retentionAbuse-monitoring scope, preview models, third-party models, in-memory caching, and regional configuration require separate review.
MicrosoftAzure customers using Azure Direct Models in Microsoft FoundryFoundry inference, Responses, Assistants, stored completions, batch, and fine-tuningBase inference models are stateless and prompts and completions are not used to train base models. Stateful features can store message history or uploaded data in the customer’s Foundry resource, and deployment type affects processing location.2026-07-24Microsoft Foundry data privacyPreview features, abuse monitoring, Global or DataZone processing, selected model provider, and customer-managed logging need deployment-specific confirmation.
GitHubCopilot plans and GitHub-hosted agent products; not a general-purpose model APIGitHub Copilot Chat, cloud agent, CLI, repository indexes, and memoryGitHub Copilot is not documented as a drop-in general-purpose API retention equivalent to the four model platforms above. It has product-specific indexes, session state, memories, audit records, and model-provider choices.2026-07-24GitHub Copilot conceptsRetention must be assembled from the exact Copilot surface, selected model, account agreement, and organization policy; a single API number would be misleading.

For an application, inventory your own gateway, traces, error reports, caches, vector database, and backups too. Provider retention is only one segment of the request path. Before sending personal data, use redaction before an LLM API and test that the redacted fields cannot be reconstructed from retained metadata.

6. Coding-agent repository context

ProviderPlanProduct surfaceWhat the official documentation establishesLast checkedOfficial URLUnknowns
OpenAICodex consumer plans and managed Business, Enterprise, or Edu workspacesCodex local, IDE, cloud tasks, and connected GitHub repositoriesConsumer Codex tasks can be subject to training controls, and full-environment sharing has a separate setting. Enterprise Codex inherits managed security, retention, residency, Compliance API, and no-training defaults.2026-07-24Codex enterprise admin guideThe exact files selected for a task, cloud environment lifetime, local transcript storage, and connector index retention require the current Codex documentation and workspace policy.
AnthropicClaude Free, Pro, Max, Team, Enterprise, and API-backed Claude CodeClaude Code local and web sessionsLocal Claude Code sends prompts and model outputs over the network and can send code or file contents included in context. Local session transcripts are stored in plaintext by default for 30 days. Cloud sessions clone the repository into an isolated VM under the account’s retention policy.2026-07-24Claude Code data usageModel-provider routing, feedback submission, telemetry, local cleanup configuration, and which files are read in a particular session must be checked.
GoogleGemini CLI authenticated through supported Google plans or API routesGemini CLI project contextGEMINI.md files from global, workspace, and just-in-time locations are concatenated and sent as model context. The CLI can also include a directory tree and additional directories according to configuration.2026-07-24Gemini CLI context filesRetention and training depend on the authentication route and applicable Google terms; the context-file documentation alone does not establish those policies.
MicrosoftMicrosoft Foundry or Microsoft 365 developer workflows; no single universal coding surfaceAzure Direct Models and Microsoft-managed development environmentsMicrosoft documents the data path for Azure model inference and stateful features. Repository access performed by an IDE, extension, GitHub agent, or third-party agent must be analyzed as a separate surface.2026-07-24Microsoft Foundry data privacyThe editor, extension, repository host, telemetry stack, and model deployment can each add copies beyond Foundry.
GitHubCopilot Free, Pro, Pro+, Business, and Enterprise, depending on featureCopilot Chat, repository indexing, cloud agent, code review, CLI, and MemoryGitHub repositories can be indexed for semantic code search. Non-GitHub repository indexing uploads data to GitHub and is disabled by default for managed plans until enabled by policy. Repository memories are separately stored and validated.2026-07-24GitHub repository indexingIndex lifecycle, branch coverage, content exclusions, model routing, synced session data, and preview memory behavior require separate confirmation.

Never write “the code stays on your laptop” because an agent executes locally. The exact path must be proven. Anthropic explicitly documents networked model processing for local Claude Code. Gemini CLI explicitly says context files are supplied to the model. GitHub documents that non-GitHub semantic indexing uploads workspace data. A local shell and a remote inference service can be parts of the same product.

Use the coding-agent sandbox guide for execution permissions, then use the terminal coding agents comparison for context-file and tool differences. Privacy and sandboxing overlap, but neither substitutes for the other.

7. Connectors, apps, MCP servers, and third-party copies

ProviderPlanProduct surfaceWhat the official documentation establishesLast checkedOfficial URLUnknowns
OpenAIChatGPT Business, Enterprise, and EduChatGPT apps with sync and non-synced appsSynced app indexes are separate from chat history, so workspace chat-retention settings do not apply to them. Disconnecting makes the index inaccessible and schedules underlying OpenAI index data for deletion within 30 days. Third-party app policies still apply.2026-07-24OpenAI app admin controlsThe connected provider can retain source records, tool calls, or outputs. Residency support differs by app and region.
AnthropicClaude plans with connectors or MCP; Enterprise policy variesClaude connectors, MCP integrations, Claude Code tools, and shared chatsAnthropic documents product-specific connector and MCP behavior; its chat-sharing guidance warns that shared snapshots can include messages and artifacts while attached-file handling differs. Connector destinations require their own retention review.2026-07-24Claude share and unshare chatsNo single connector statement covers every MCP server, third-party service, authentication route, and copied result. Review each destination’s policy.
GooglePersonal Gemini Apps and Google Workspace accountsGemini Connected Apps and Workspace dataDeleting Gemini activity does not delete data in other Google services. Removing remembered connected-app information can require both deleting relevant chats and disconnecting the app. Workspace administrators and source permissions constrain access.2026-07-24Gemini past-chat Memory and connected appsSource-service retention, public links, imported content, app-specific logs, and delay before source changes affect Gemini remain separate.
MicrosoftMicrosoft 365 Copilot commercial accountsMicrosoft Graph grounding, Microsoft 365 data, plugins, and organizational controlsEnterprise data protection applies identity, permissions, sensitivity labels, retention, audit, and administrative settings to Copilot prompts and responses. Source files and generated copies remain governed by their own Microsoft 365 locations.2026-07-24Microsoft 365 Copilot enterprise data protectionThird-party agents, plugins, external actions, and non-Microsoft destinations may have additional terms and retention.
GitHubCopilot Individual and managed plans; enterprise MCP policy differsGitHub MCP server, third-party MCP servers, Copilot CLI, IDEs, and cloud agentMCP can connect Copilot to files, databases, scripts, and external APIs. Managed plans can block MCP or restrict discovery to an approved registry, but policy coverage varies by surface.2026-07-24GitHub MCP managementEach MCP server is a separate data recipient. Registry listing is not proof of retention, deletion, residency, or contractual fitness.

An integration can create three copies: the source record, context sent to the model, and an output written back to another service. Disconnecting the integration usually stops future access; it does not automatically erase all three. Apply the MCP security checklist to permissions, secrets, logging, and tool output.

ProviderPlanProduct surfaceWhat the official documentation establishesLast checkedOfficial URLUnknowns
OpenAIChatGPT Enterprise, Edu, and Healthcare; Business has different controlsManaged ChatGPT workspace, Compliance API, files, and CodexWorkspace administrators can control retention for eligible managed plans. Managed-account administrators may access, export, audit, retain, or delete prompts, files, outputs, history, and metadata under workspace controls.2026-07-24Managed ChatGPT account data accessContract, role configuration, Compliance API coverage, app indexes, legal exceptions, and backup periods must be confirmed.
AnthropicClaude EnterpriseClaude conversations, projects, memory data, incognito chats, and organization exportsEnterprise owners can configure custom retention. Memory-related data and incognito chats are subject to organization retention and exports; disabling organization memory can permanently delete memory synthesis data.2026-07-24Anthropic Enterprise retention controlsMinimums, contract exceptions, safety retention, covered products, and ZDR eligibility must be confirmed with the account team.
GoogleGoogle Workspace editions with GeminiGemini Apps for work or school, Workspace admin controls, and Google Vault where applicableWork or school activity settings are controlled by the Workspace administrator. Users may not be able to change retention or see the configured period. Source data access follows Workspace permissions and admin restrictions.2026-07-24Gemini access to Workspace dataEdition, Vault coverage, region, history configuration, user deletion availability, and side-panel behavior require tenant-specific testing.
MicrosoftMicrosoft 365 commercial plans with Purview capabilitiesMicrosoft 365 Copilot interactions, Exchange-backed records, Purview retention, audit, and eDiscoveryPurview retention policies can retain or delete Copilot prompts and responses. Holds and retention policies can override ordinary deletion, and Copilot interactions can be searched through eDiscovery.2026-07-24Purview management for Microsoft 365 CopilotLicensing, policy precedence, distribution delay, sovereign cloud behavior, and every copied file or downstream record must be checked.
GitHubCopilot Business and EnterpriseCopilot Memory, audit log, organization repositories, and enterprise policiesAdministrators can enable memory policy, inspect repository facts, export or delete user preferences, and audit certain memory events. User preferences are tied to the active billing entity.2026-07-24Administer GitHub Copilot MemoryPublic-preview changes, export freshness, organization transfer, repository deletion, and broader Copilot transcript retention need separate evidence.

For regulated work, administrator visibility is a feature, not a privacy failure, when it is disclosed and governed. It becomes a failure when employees think “temporary” or “deleted” means “invisible to compliance” and the organization’s policy says otherwise.

Trust portals help with vendor assurance, but a certification does not answer a feature-level retention question. The OpenAI Trust Portal lists security and compliance materials for covered services, including public descriptions and gated reports. The Microsoft Trust Center provides Microsoft-wide security, privacy, data-location, and compliance resources. Use trust-center artifacts alongside the exact product documentation, contract, data-flow diagram, and tenant configuration.

9. Account deletion and content deletion

ProviderPlanProduct surfaceWhat the official documentation establishesLast checkedOfficial URLUnknowns
OpenAIConsumer ChatGPT and API accountOpenAI account, chats, memories, files, and subscriptionAccount deletion is permanent. OpenAI says it deletes data within 30 days, subject to limited legal or permitted retention. Mobile-store subscriptions may need separate cancellation. Memories and chats also have separate deletion controls.2026-07-24Delete an OpenAI accountDe-identified data, legal holds, connected-app copies, workspace-managed accounts, and mobile billing require separate treatment.
AnthropicClaude Free, Pro, and Max consumer accountsClaude account, subscription, and saved chatsConsumer deletion is permanent. Paid users must cancel and wait until the current subscription period ends before deleting in the documented flow. Third-party access paths require deletion through that third party.2026-07-24Delete a Claude accountCommercial organization deletion, training pipelines, feedback records, trust-and-safety exceptions, and third-party copies differ.
GooglePersonal Google AccountGoogle Account, Gemini Apps Activity, and product-specific dataGoogle allows deletion of activity, individual services, or the account. Activity deletion begins removal from the product and storage systems, with documented security, financial, legal, operational, and anonymized-data exceptions.2026-07-24How Google deletes account dataDeleting Gemini activity does not delete Gmail, Drive, Photos, public links, or other service data. Exact completion timing is not universal.
MicrosoftPersonal Microsoft account and work accounts have different ownersMicrosoft privacy dashboard, Copilot history, and Microsoft accountPersonal Copilot activity can be cleared through the privacy dashboard. Work-account Copilot history uses a separate deletion request and can be subject to organizational policy.2026-07-24Manage Copilot activity historyAccount closure, tenant records, retention holds, saved files, browser data, and organizational copies require separate workflows.
GitHubGitHub personal account and Copilot subscriptionsGitHub account, owned repositories, contributions, Copilot memories, and exportsDeleting a GitHub personal account removes owned resources, but contributions to others’ repositories remain associated with a ghost user. Copilot memories have separate user and admin deletion paths.2026-07-24GitHub personal account managementForks, clones, Git history, backups, marketplace installations, organization-owned data, and model-provider records can survive account deletion.

Account deletion is the broadest user action, but it is not always the fastest or most precise. For one bad memory, remove the memory and its source chats. For one client project, delete project files, chats, connected indexes, shares, and downstream copies. For a departing employee, use the organization’s retention and offboarding process rather than asking the employee to delete a managed account.

10. Export and migration

ProviderPlanProduct surfaceWhat the official documentation establishesLast checkedOfficial URLUnknowns
OpenAIConsumer ChatGPT; Business and Enterprise exports differChatGPT data export and Privacy PortalConsumer users can request an export containing chat history and other relevant account data. OpenAI states that ChatGPT Business and Enterprise chat exports are not available through the same consumer flow.2026-07-24Export ChatGPT history and dataExport schema, memory completeness, app indexes, Codex environments, deleted items, and managed-workspace coverage must be inspected in the resulting archive or admin tools.
AnthropicClaude Free, Pro, and Max; organization exports are owner-controlledClaude data exportIndividual exports include conversation data and account data. Team and Enterprise exports are available to the Primary Owner. Personal exports cannot be imported into another personal Claude account.2026-07-24Export Claude dataExport timing, memory format, attachments, deleted content, and organization migration rules require current verification.
GooglePersonal Google AccountGoogle Takeout, Gemini import, and Google account dataGoogle Takeout creates an archive but does not delete source data. Gemini can import supported memory or chat exports from other assistants, but availability has account, age, surface, and regional limits.2026-07-24Google TakeoutGemini-specific export coverage, import fidelity, file-size limits, regional availability, and whether derived memories map correctly must be tested.
MicrosoftPersonal Microsoft account; work-account paths differMicrosoft privacy dashboard and Copilot activity exportPersonal users can export Copilot app and Microsoft 365 app activity history from the privacy dashboard, including CSV-based activity exports.2026-07-24Export or delete Copilot historyAn activity CSV may not include every memory, file, administrator record, or tenant-held copy. Work-account export is organization-dependent.
GitHubGitHub personal account; Copilot Business and Enterprise add admin memory exportGitHub account archive and Copilot Memory exportUsers can request a tar.gz account archive. Managed Copilot administrators can separately export user-level preferences in JSONL. These are distinct exports with different owners and scopes.2026-07-24GitHub account data archiveRepository clones, LFS objects, Copilot transcripts, indexes, third-party agent data, and preview memory details need separate checks.

An export is evidence of what the provider chose to include, not proof that the archive lists every internal copy. It is useful for migration, review, and preservation. It does not delete the source.

11. Regional storage, processing, and feature differences

ProviderPlanProduct surfaceWhat the official documentation establishesLast checkedOfficial URLUnknowns
OpenAIEligible API and managed ChatGPT customers; availability and approvals varyAPI project data residency, regional processing, and managed ChatGPT residencyOpenAI distinguishes storage at rest from regional inference processing. API residency is configured per project, applies only to supported services, and excludes system data and third-party services. A region offering storage does not necessarily offer regional processing.2026-07-24OpenAI API data residency controlsEligibility, model and endpoint coverage, non-US approval, system data, failover, and connected-app routing must be confirmed for the selected project.
AnthropicConsumer, Team, Enterprise, and API arrangementsClaude feature rollout, Enterprise retention, and API or third-party deployment routesAnthropic documents different memory rollouts across plans and separate data paths for the Anthropic API, Amazon Bedrock, Google Vertex AI, and Microsoft Foundry. A Claude feature name does not make those routes equivalent.2026-07-24Claude Code data usage and provider routesStorage region, processing region, subprocessor access, model availability, and retention depend on the contract and selected provider route.
GooglePersonal Google accounts, Workspace accounts, and Google Cloud projectsGemini Apps features, Gemini import, Workspace administration, and Vertex AI regionsPersonal past-chat Memory is unavailable for work, school, and supervised accounts. Gemini import has documented regional exclusions. Vertex AI region and feature configuration is a separate cloud decision from consumer Gemini availability.2026-07-24Gemini import availabilityAccount country, age, Workspace edition, staged rollout, model location, grounding feature, and data-residency configuration must be checked separately.
MicrosoftMicrosoft Copilot personal accounts, Microsoft 365 commercial tenants, and Azure deploymentsConsumer memory, Microsoft 365 Copilot, and Foundry Global, DataZone, or regional deploymentsPersonal Copilot memory has documented country exclusions. Microsoft Foundry states that Global and DataZone deployment types can process data outside a single selected region while stored data remains governed by the resource geography.2026-07-24Microsoft Foundry processing locationsSovereign-cloud features, model availability, preview controls, tenant geography, failover, and third-party model routes require deployment-specific evidence.
GitHubCopilot Individual, Business, and Enterprise; feature availability varies by clientGitHub-hosted repositories, non-GitHub semantic indexing, CLI, IDEs, cloud agent, and MCPGitHub documents different policy coverage across clients. Non-GitHub semantic indexing uploads workspace data to GitHub when enabled, while MCP registry and allowlist enforcement differ across CLI, IDE, and cloud-agent surfaces.2026-07-24GitHub Copilot context and indexingData-location commitments, selected model route, enterprise geography, editor telemetry, MCP destination region, and preview-feature rollout need contract and client-level confirmation.

Regional language is easy to overread. “EU data residency” may describe storage but not inference, system metadata, support access, a connected application, or an optional grounding feature. Record each of those as a separate field.

Decision guide by scenario

Scenario 1: personal brainstorming

Recommended posture: use a personal account with memory limited to stable, low-risk preferences. Use a fresh temporary or incognito chat when you want an outside perspective.

Keep:

  • enduring format preferences;
  • recurring project names that are not sensitive;
  • accessibility needs you deliberately want applied across sessions.

Do not keep:

  • a one-off hobby, fictional character, or mood as a global preference;
  • temporary relationship, employment, health, or financial details;
  • instructions that should apply to only one creative project.

Test the assistant with an unrelated prompt after saving a preference. If it drags the preference into the answer without a reason, narrow or delete it. A good memory system should improve relevance without making every answer sound like the same person at the same meeting.

Plan limits also matter. A subscription may provide more usage or context without changing the underlying privacy default. Buy capacity only after verifying the memory, training, and retention controls on that plan; do not assume “paid” means “confidential.”

Scenario 2: confidential client work

Recommended posture: use an organization-approved business or enterprise surface under a contract that excludes training by default, with connectors disabled until reviewed. Do not use a personal subscription merely because it has a temporary mode.

Before the first real document:

  1. Classify the client data and identify contractual restrictions.
  2. Confirm the exact workspace, plan, account owner, region, and retention policy.
  3. Confirm whether administrators can export the conversation and whether that is acceptable.
  4. Disable or prohibit unnecessary memory, past-chat search, public sharing, feedback, and unreviewed connectors.
  5. Redact direct identifiers and secrets that the task does not need.
  6. Run a synthetic pilot and deletion test.

If the client forbids third-party model processing, the correct answer is not a shorter retention period. Use an approved deployment path or do not send the content.

Scenario 3: source code and coding agents

Recommended posture: keep authoritative context in versioned repository files, not only in provider memory. Use least-privilege repository access, exclude secrets and generated assets, and review the agent’s actual data path.

A repository context file can make switching easier:

Purpose: rules that every approved coding agent may read
Scope: this repository only
Contains: build commands, architecture constraints, test commands
Must not contain: secrets, customer records, access tokens, private URLs
Owner: engineering team
Review trigger: architecture or toolchain change

OpenAI Codex, Claude Code, Gemini CLI, and GitHub Copilot use different instruction files and discovery rules. The operational pattern is portable; the exact implementation is not. The Claude Code vs OpenAI Codex comparison covers workflow differences, but always recheck current official privacy documentation before connecting a private repository.

Do not rely on .gitignore alone. A tool may read untracked files, follow imported instructions, index workspace files, or receive tool output containing secrets. Test with a harmless canary file that should be excluded, inspect available context controls, and confirm the canary never appears in the response or provider-side artifact.

Scenario 4: health or financial notes

Recommended posture: do not place identifiable medical or financial records in a general consumer assistant. For low-risk personal reflection, minimize details, use a temporary mode, disable training where available, and assume short-term provider retention still exists.

Temporary mode cannot turn a consumer product into a regulated record system. It also cannot guarantee clinical correctness or financial suitability. If the task involves protected health information, account numbers, tax records, insurance claims, investment holdings, or a professional duty of confidentiality, use a specifically approved product and contract.

Separate the note from identity:

  • remove names, exact dates of birth, account numbers, addresses, and document IDs;
  • replace exact institutions or clinicians with neutral labels when they are not needed;
  • omit unrelated history;
  • do not connect email, cloud storage, health, or financial services merely to save copy-and-paste effort;
  • do not submit feedback on a sensitive conversation because feedback may follow different data-use rules.

Meeting transcripts add voice, attendee, and calendar copies. Use the AI meeting notes privacy checklist before recording any sensitive discussion.

Scenario 5: regulated enterprise use

Recommended posture: treat the assistant as a governed information system. Select a specific enterprise product, approved feature set, region, retention schedule, administrator model, and contract. Prohibit unapproved surfaces even when the same provider name appears on them.

Minimum approval packet:

  • data-flow diagram for prompts, outputs, files, memory, indexes, logs, tools, and exports;
  • product and feature inventory with plan and region;
  • training, retention, deletion, backup, residency, and subprocessor evidence;
  • identity, SSO, provisioning, least-privilege roles, and offboarding;
  • audit, eDiscovery, legal hold, incident response, and deletion procedures;
  • connector and MCP allowlist;
  • documented prohibited data and approved use cases;
  • synthetic deletion test and evidence-retention policy;
  • review date and change triggers.

Use conditional approval language:

Approved for redacted internal policy search in the named managed workspace with past-chat memory disabled, approved regional storage, organization retention applied, and only the reviewed document connector enabled. Not approved for raw health records, payment credentials, legal-privileged material, or personal accounts.

For tenant separation and retrieval authorization, use the multi-tenant RAG security guide. A provider’s enterprise certification does not repair a cross-tenant application bug.

How to verify deletion without overstating proof

Deletion verification has hard limits. A user usually cannot inspect provider backups, abuse-monitoring systems, model-training pipelines, de-identified datasets, legal holds, or every subprocessor. Even an administrator export is not a complete map of internal storage.

Use a layered verification record:

  • User interface: Delete the synthetic chat, file, memory, project, or session and refresh every relevant view. Keep a timestamped record of the object ID, action, and visible result. This does not prove backend erasure, backup expiry, legal-hold release, or third-party deletion.
  • Retrieval: Start a fresh ordinary chat and ask a neutral question that previously retrieved the synthetic canary. Record repeated tests where the canary is no longer returned. This does not prove absence from storage because retrieval can fail for other reasons.
  • Export: Request a new export after the provider’s documented processing window and search for the canary. Keep the export date, archive hash, searched fields, and result. This does not prove the export covers every internal system.
  • API or administrator tool: Query the object, compliance endpoint, memory panel, index, or eDiscovery location where supported. Keep the not-found response, audit event, policy state, or purge result. This does not cover unexposed backups, third-party tools, or copied outputs.
  • Connected systems: Search the source app, destination app, logs, CRM, ticketing system, and object storage. Keep the result for each inventoried system. This says nothing about a system omitted from the inventory.
  • Provider and contract: Retain the official policy version, support response, data-processing clause, and trust artifact. This documents the provider’s commitment but does not prove a specific deletion executed correctly.

Use synthetic canaries, not real secrets. A good canary is unique enough to search, harmless if exposed, and mapped to a single test identity. Record where it was entered and every derived artifact expected.

Do not write “permanently deleted everywhere” unless you have authority and evidence for every layer. Prefer:

Removed from the user interface and no longer retrievable through the tested chat, memory, export, and connector paths as of 2026-07-24. Provider backup, safety, legal-hold, and de-identified-data handling remain subject to the cited policy and contract.

Migration without importing the mess

Moving assistants is a chance to reduce stale memory rather than copying it wholesale.

Migration steps

  1. Freeze new durable memory temporarily. Keep using the source service only for low-risk work while you take inventory.
  2. Export before deleting. Use the official export path and save the original archive read-only. Export does not delete source data.
  3. Inventory by category. Separate chats, saved memories, custom instructions, project files, repository context, shared links, connector indexes, and account metadata.
  4. Classify each item. Mark it keep, rewrite, project-only, archive-only, or delete.
  5. Rewrite durable memory. Convert broad preferences into scoped statements with an owner and review trigger.
  6. Remove secrets and stale facts. Do not import API keys, client data, sensitive inferences, old jobs, obsolete coding rules, or records without a continuing purpose.
  7. Test the destination with a small sample. Confirm what the import feature creates: a chat, a memory, a project file, or an account-level preference.
  8. Check regional and plan availability. Google, for example, documents regional and account restrictions for Gemini import; Claude states that personal exports cannot be imported into another personal Claude account.
  9. Validate behavior. Run one related prompt and one unrelated prompt. The imported context should help the first and stay out of the second.
  10. Delete source copies deliberately. Delete memories, source chats, project files, shares, and connector indexes separately. Close the account only if that broader action matches the goal.
  11. Re-export or re-query after the documented window. Search for the synthetic canary and record the limits of the proof.
  12. Keep a migration manifest. Store item counts, archive hashes, dates, provider URLs, unknowns, and the person who accepted residual risk.

Do not upload a full export to a new assistant just to ask it what should be migrated. That sends the entire old data set to the new provider before classification. Review locally or with an already approved tool, then import the minimum.

A compact buyer checklist

Before paying for a plan, connecting a repository, or approving an enterprise deployment, answer:

  • Which account and plan will own the data?
  • Is the surface consumer chat, managed chat, coding agent, API, or connector?
  • What creates durable memory, and who can inspect or delete it?
  • Is past-chat search separate from saved memory?
  • Is training enabled by default, opt-out, opt-in, or contractually excluded?
  • What does temporary mode omit, and how long is it still retained?
  • Which API endpoints or tools create application state?
  • Which repository files, history, indexes, and local transcripts are in scope?
  • Which connectors or MCP servers receive data?
  • Can an administrator export, retain, hold, or delete user content?
  • What must be deleted separately from the chat?
  • What does the export include and omit?
  • Where is data stored and processed, and does the selected region change both?
  • What happens to data after a member leaves or an account is closed?
  • What remains unknown, who owns the question, and when will it be rechecked?

If a vendor or internal owner cannot answer, do not replace the blank with a guess. Mark it unknown and restrict the workload until evidence exists.

Frequently asked questions

1. Does deleting a chat delete what the assistant remembers?

Not necessarily. OpenAI documents saved memories separately from chat history. Anthropic’s behavior depends on the current memory experience. Google may require deleting every relevant chat and disconnecting a source app. Delete the memory, source chats, projects, files, and connector copies that apply, then test retrieval.

2. Does turning memory off delete existing memory?

Usually not by itself. A toggle may stop future use or creation while keeping existing entries. Use the provider’s delete or reset control and verify the result in a fresh session.

3. Is a temporary or incognito chat immediately erased?

No general rule says that. OpenAI documents a period of up to 30 days for Temporary Chats. Anthropic documents 30 days by default for incognito chats, with enterprise policy differences. Google documents up to 72 hours in relevant activity-off behavior. Read the exact surface’s current rule.

4. Does “not used for training” mean the provider stores nothing?

No. Storage for chat history, safety, abuse monitoring, application state, files, feedback, support, billing, indexes, or legal obligations can remain. Training and retention are separate rows in a privacy review.

5. Are paid personal plans safe for confidential client work?

Payment alone does not create a confidentiality agreement or enterprise control set. Use the organization-approved plan and contract, confirm training and retention defaults, disable unreviewed connectors, and minimize the data before sending it.

6. Can my employer see a temporary work chat?

Possibly. Anthropic states that Enterprise incognito chats can be included in organization exports and follow organization retention. Microsoft warns that temporary Microsoft 365 Copilot data may be accessible to the IT administrator during the retention period. Check the managed-account notice and internal policy.

7. Do local coding agents keep source code on the device?

Do not assume so. A local agent may execute commands locally while sending prompts, file excerpts, tool results, or repository context to a remote model. Only claim device-only handling when official documentation proves the exact product path and configuration.

8. Does .gitignore prevent an AI coding agent from reading a file?

Not universally. Some tools respect ignore files for some discovery paths but can still access a file through explicit tools, imports, additional directories, or configuration. Use product-specific exclusions and test with a harmless canary.

9. Are repository memory and repository indexing the same?

No. GitHub, for example, documents semantic repository indexing separately from Copilot Memory. One helps retrieve code context; the other stores validated repository facts and user preferences. They have different controls and lifecycles.

10. Does disconnecting a connector delete everything it previously accessed?

No universal guarantee exists. OpenAI documents deletion behavior for its synced index, but the source system and any destination copies remain separate. Google states that deleting Gemini activity does not delete other Google-service data. Inventory all copies.

11. Can an export prove what a provider stores?

An export proves what the provider made available in that export at that time. It may omit backups, safety records, de-identified data, model-training artifacts, or product-specific stores. Use it as one evidence layer.

12. Should I delete my account to remove one unwanted memory?

Usually not. Remove the memory and its source chats first, then verify. Account deletion is irreversible and can affect subscriptions, repositories, API access, or organization data without guaranteeing deletion of copies held by others.

13. How should I move memory to another assistant?

Export, classify locally, rewrite broad preferences into scoped statements, remove sensitive and stale items, import a small sample, and test both relevant and unrelated prompts. Never upload the entire archive before reviewing it.

14. Which assistant is best for regulated data?

No provider name is sufficient. Choose an exact enterprise product, contract, approved region, retention schedule, administrator model, connector set, audit path, deletion procedure, and permitted use case. A consumer surface from the same company is not equivalent.

15. How often should these settings be reviewed?

Review after a plan change, major feature rollout, new connector, model or endpoint change, region change, contract renewal, account migration, deletion failure, or privacy incident. For ongoing sensitive use, assign a regular review date and owner.

Sources checked 2026-07-24

Official primary sources used for product facts:

Demand evidence, used only to describe user concerns: