An AI assistant can remember too little, remember too much, or remember the wrong thing in the wrong place. Those are product problems. They are also data-governance problems, because the word “memory” can refer to saved preferences, searchable chat history, project files, repository indexes, administrator-visible records, provider safety logs, or a model context assembled for one request.
The most visible failure is almost comic: tell an assistant about one hobby once, and it starts bending unrelated brainstorming sessions around that hobby. The same mechanism becomes serious when a past health concern appears in a work chat, a client name leaks into another project, or old repository assumptions guide a coding agent after the architecture has changed.
This guide separates those mechanisms. It compares five provider families across ten data concepts, then gives decision paths for personal brainstorming, confidential client work, source code, health or financial notes, and regulated enterprise use. Product facts were checked against official documentation on 2026-07-24. Controls, rollouts, contracts, and regional availability can change; the “Unknowns” column is part of the answer, not a defect to be ignored.
This is an operational privacy guide, not legal advice. Do not use it as a substitute for a data-processing agreement, sector-specific review, or advice from qualified counsel.
The demand signal: users want continuity without unwanted carryover
Public complaints do not prove prevalence, and they are not authoritative sources for product behavior. They do show what buyers are trying to solve.
- Users describe assistants bringing unrelated past topics into a new conversation, making personalization feel intrusive rather than helpful (memory annoyance thread).
- Another discussion describes persistent fixation on old conversations and the difficulty of getting a genuinely fresh answer (past-conversation fixation thread).
- Coding-agent users report long investigations filling the available context and then losing direction, showing that “more repository access” and “better working context” are not the same thing (coding-agent context thread).
- Subscription users also report sessions stopping after heavy context use, making retention, context size, and plan limits part of one purchase decision even though they are technically separate controls (subscription limit thread).
Treat those links as anecdotal demand evidence. Use official provider documentation for the facts in the comparison below. For a focused treatment of the repeated-hobby problem, read AI Memory Without the Awkward Coworker Effect. For the engineering distinction between working, episodic, and semantic memory, see the AI agent memory guide.
First principle: similarly named controls are not equivalent
Five separations prevent most bad decisions:
- Saved memory is not chat history. A provider may store a derived preference separately from the chat that produced it.
- No training is not no retention. Content can be excluded from model training while remaining in chat storage, safety logs, files, indexes, backups, or administrator exports.
- Temporary is not immediate deletion. Temporary or incognito modes can hide a chat from the user interface while the provider retains it for a documented period.
- Local execution is not local inference. A coding agent may run commands on your machine while sending prompts, file excerpts, tool results, or repository context to a remote model service.
- User deletion is not enterprise erasure. A retention policy, legal hold, compliance export, connected application, copied file, or derived memory may survive a user-visible deletion.
The detailed LLM API data retention checklist applies the same separation to provider logs, application state, caches, and backups. Use it when a chat product is only one component in a larger system.
How to read the comparison
Each table covers one data concept. Every row names:
- the plan or commercial arrangement;
- the exact product surface;
- the last-checked date;
- the official source used;
- the unresolved questions that must be verified in the account, contract, or deployment.
“No documented equivalent” means the cited official material did not establish an equivalent control for that surface. It does not mean the provider stores nothing. “Not applicable” means the product category is different, not that a privacy question disappears.
1. Saved memory and durable personalization
| Provider | Plan | Product surface | What the official documentation establishes | Last checked | Official URL | Unknowns |
|---|---|---|---|---|---|---|
| OpenAI | ChatGPT consumer plans; availability can vary by account and plan | ChatGPT saved memories and reference chat history | Saved memories and chat-history-derived context are distinct. Deleting a chat does not by itself delete a saved memory; complete removal can require deleting both the memory and the source chat. | 2026-07-24 | OpenAI Memory FAQ | Exact rollout, controls visible in a specific region, and whether an account uses the latest memory experience must be checked in that account. |
| Anthropic | Claude Free, Pro, and Max; Team and Enterprise have rollout and admin differences | Claude web, desktop, and mobile memory | Claude can create categorized memory entries and separate project memories. Users can pause or reset memory. Current documentation distinguishes new and legacy experiences. | 2026-07-24 | Claude chat search and memory | Rollout state, organization policy, and the exact effect of deleting a source chat differ by memory experience and must be verified in the visible interface. |
| Personal Google Account, eligible adult user; not a work, school, or supervised account | Gemini Apps Personal Intelligence and past-chat Memory | Past-chat Memory requires Keep Activity to be on. Removing remembered information can require deleting every chat containing it; connected-app information requires separate disconnection and deletion steps. | 2026-07-24 | Gemini past-chat Memory | Feature availability varies by surface and region, and Google warns that personalization can take time to reflect deletions or source changes. | |
| Microsoft | Microsoft Copilot with a personal Microsoft account | Copilot personalization and memory | Users can disable personalization, inspect remembered information, delete specific memories, or delete all memory. Deleting memory does not delete conversation history. | 2026-07-24 | Microsoft Copilot privacy controls | Availability varies by country and account. The documentation does not make personal Copilot memory equivalent to Microsoft 365 Copilot memory. |
| GitHub | All paid Copilot plans; managed plans require policy enablement | Copilot cloud agent, code review, and Copilot CLI Memory | Copilot Memory stores repository facts and user preferences. Repository facts stay repository-scoped; unused entries are automatically deleted after 28 days, with the timer potentially resetting after use and validation. | 2026-07-24 | GitHub Copilot Memory | The feature is in public preview. Preview behavior, exact export coverage, and whether all agent surfaces use the same memory type can change. |
The repeated-hobby complaint is a scope failure, not merely a storage failure. A useful durable preference should say when it applies. “I like cycling” is not a reason to frame a contract summary around cycling. “When planning my personal weekend exercise, prefer cycling routes” is bounded and testable.
2. Chat history and searchable past conversations
| Provider | Plan | Product surface | What the official documentation establishes | Last checked | Official URL | Unknowns |
|---|---|---|---|---|---|---|
| OpenAI | ChatGPT consumer and managed workspaces | ChatGPT chats, archives, files, projects, and Library | Ordinary chats remain until deleted. Archiving hides rather than deletes. Files saved to Library can be managed separately from the chat that introduced them. | 2026-07-24 | ChatGPT chat and file retention | Legal or security exceptions, workspace policy, Library availability, and feature-specific file expiry must be checked separately. |
| Anthropic | Claude paid plans for past-chat search; memory availability varies | Claude chat search, projects, and history | Claude can search past chats on supported paid plans. Searches outside projects and searches inside a project have different boundaries; incognito chats are excluded from user-visible history and memory. | 2026-07-24 | Claude chat search and memory | Team and Enterprise may remain on a legacy experience during rollout. Admin exports and retention can include content users do not see. |
| Personal Google Account with Keep Activity on | Gemini Apps Activity and recent chats | Gemini Apps Activity can store prompts and shared files or media. The default auto-delete period documented for eligible personal activity is 18 months, with 3, 18, 36 months, or no auto-delete available. | 2026-07-24 | Manage Gemini Apps activity | The exact activity types, age rules, regional controls, and work or school behavior differ. Connected services can retain separate copies. | |
| Microsoft | Microsoft Copilot personal account | Copilot conversation history | Microsoft documents that personal Copilot conversation history is retained for 18 months and can be deleted by item or in full. Memory is a separate control. | 2026-07-24 | Microsoft Copilot privacy controls | Product variants, browser data, uploaded-file copies, and work-account records are outside this single personal-surface statement. |
| GitHub | Copilot plans with CLI, Chat, or cloud agent access | Copilot CLI session state, GitHub chat surfaces, and repository context | Copilot CLI keeps local session state; if sessions are synced, deleting local files does not delete the GitHub-hosted synced copy. Repository indexing and Copilot Memory are additional stores. | 2026-07-24 | Copilot CLI configuration directory | The retention period for each synced session surface and the relationship to organization policies require product- and contract-specific confirmation. |
Do not treat a sidebar as an inventory. An archived chat, a project file, a synced coding session, a saved memory, and a connected-app index can all be absent from the main history while still existing.
3. Model training and product-improvement controls
| Provider | Plan | Product surface | What the official documentation establishes | Last checked | Official URL | Unknowns |
|---|---|---|---|---|---|---|
| OpenAI | ChatGPT and Codex consumer services; Business, Enterprise, Edu, and API under business terms | ChatGPT, Codex tasks, Codex full environments, and API | Consumer content may be used to improve models unless the user opts out. Codex has a separate full-environment training control. Business and API inputs and outputs are not used for training by default unless an organization opts in. | 2026-07-24 | How OpenAI uses data to improve models | Feedback submissions can have different treatment. A ChatGPT toggle may not control Codex full-environment sharing, so both surfaces must be checked. |
| Anthropic | Claude Free, Pro, and Max; commercial Team, Enterprise, API, and third-party platforms | Claude chat and Claude Code | Consumer users can choose whether new chats and coding sessions are used to improve Claude. Commercial data is not used to train generative models unless the customer affirmatively participates in a program. | 2026-07-24 | Claude Code data usage | Feedback, development-partner programs, trust-and-safety records, and model-training runs already in progress have separate rules. |
| Personal Gemini Apps with Keep Activity on or off | Gemini Apps activity, feedback, audio, Live media, and human review | With Keep Activity on, activity can be used to provide, develop, and improve services, including generative AI models, with documented human review. With Keep Activity off, future chats are not used to train models unless feedback is sent. | 2026-07-24 | Gemini Apps Privacy Hub | Audio and Live media have additional controls. Region, age, feedback, and data already reviewed by service providers change the result. | |
| Microsoft | Microsoft Copilot personal account; Microsoft 365 work account differs | Copilot conversation activity and voice training controls | Personal users can opt out of training on conversation activity and voice conversations. This does not describe Microsoft 365 Copilot under enterprise data protection. | 2026-07-24 | Microsoft Copilot privacy controls | Separate settings may govern ads, personalization, diagnostic data, and work-account processing. Confirm each rather than inferring from one toggle. |
| GitHub | Copilot Individual, Business, and Enterprise | Copilot repository indexes and Copilot product data | GitHub states that indexed repositories are not used for model training. This is narrower than a provider-wide statement about every prompt, feedback submission, or third-party model. | 2026-07-24 | GitHub repository indexing | The selected model provider, feedback path, organization policy, and preview feature may add terms not covered by the indexing statement. |
The safest label in an internal decision record is not “no training.” Write the actual scope: “Business workspace prompts and outputs excluded from foundation-model training by default; feedback path disabled; connected service terms reviewed separately.”
4. Temporary, incognito, and memory-off chats
| Provider | Plan | Product surface | What the official documentation establishes | Last checked | Official URL | Unknowns |
|---|---|---|---|---|---|---|
| OpenAI | ChatGPT plans where Temporary Chat is available | ChatGPT Temporary Chat | Temporary Chats do not appear in history, do not use or create memories, and are not used to train models. OpenAI documents automatic deletion from its systems within 30 days, subject to stated exceptions. | 2026-07-24 | OpenAI Temporary Chat FAQ | Custom instructions can still apply, third-party GPT actions have their own policies, and legal developments or workspace controls can affect retention. |
| Anthropic | Claude Free, Pro, Max, Team, and Enterprise | Claude incognito chats outside projects | Incognito chats are not saved to user chat history or memory and are not used for training. They are retained for 30 days by default; Enterprise custom retention can be longer, and organization exports can include them. | 2026-07-24 | Claude incognito chats | Profile information can still influence the session. Enterprise visibility and exact retention depend on organization policy. |
| Personal Gemini Apps | Gemini Temporary Chat and Keep Activity off | Google documents that when Keep Activity is off, chats are still saved with the account for up to 72 hours to provide the service, process feedback, and protect users. Temporary Chat is not the same as deleting other Google-service copies. | 2026-07-24 | Gemini Apps activity controls | The exact Temporary Chat interface, surface availability, feedback behavior, and connected-service copies must be checked in the current account. | |
| Microsoft | Microsoft 365 Copilot work or school account | Microsoft 365 Copilot temporary chat | Microsoft warns that temporary chat data can still follow the organization’s retention policy and may be accessible to the IT administrator during that period. | 2026-07-24 | Microsoft 365 Copilot memory | Consumer Copilot and Microsoft 365 Copilot have different controls. Purview holds and tenant configuration can change deletion timing. |
| GitHub | Copilot Individual, Business, and Enterprise | Copilot Chat, CLI, cloud agent, and code review | The reviewed GitHub documentation does not establish a provider-wide temporary-chat mode equivalent to ChatGPT Temporary Chat, Claude incognito, or Gemini Temporary Chat. Local CLI history and synced sessions have separate deletion paths. | 2026-07-24 | Copilot CLI context management | Whether a specific IDE offers an editor-level ephemeral mode and how it maps to GitHub retention must be verified for that client and version. |
Temporary mode is useful for preventing future personalization. It is not a vault. If the material should not reach the provider at all, do not enter it merely because the chat is temporary.
5. API retention and stateful endpoints
| Provider | Plan | Product surface | What the official documentation establishes | Last checked | Official URL | Unknowns |
|---|---|---|---|---|---|---|
| OpenAI | API organizations; special controls require eligibility and approval | OpenAI API abuse-monitoring logs and application state | API data is not used for training by default. Abuse-monitoring logs may retain customer content for up to 30 days by default. Some endpoints store application state until deletion or for feature-specific periods. ZDR and Modified Abuse Monitoring have eligibility and endpoint limits. | 2026-07-24 | OpenAI API data controls | Endpoint, tool, file, caching, background mode, region, and legal exceptions must be evaluated line by line. |
| Anthropic | Anthropic API commercial customers | Messages API and longer-lived customer-controlled features | Anthropic states API inputs and outputs are deleted from its backend within 30 days by default, with exceptions for longer-lived features, agreed ZDR, policy enforcement, and law. | 2026-07-24 | Anthropic commercial retention | Files, batches, feedback, covered models, third-party platforms, and negotiated agreements can differ. |
| Google Cloud customers using managed models on Vertex AI | Vertex AI generative AI, grounding, caching, and live session resumption | Google states it does not train managed models on customer data without permission or instruction. Some features retain data: Search or Maps grounding has documented 30-day storage, and Live session resumption can cache data for up to 24 hours. | 2026-07-24 | Vertex AI zero data retention | Abuse-monitoring scope, preview models, third-party models, in-memory caching, and regional configuration require separate review. | |
| Microsoft | Azure customers using Azure Direct Models in Microsoft Foundry | Foundry inference, Responses, Assistants, stored completions, batch, and fine-tuning | Base inference models are stateless and prompts and completions are not used to train base models. Stateful features can store message history or uploaded data in the customer’s Foundry resource, and deployment type affects processing location. | 2026-07-24 | Microsoft Foundry data privacy | Preview features, abuse monitoring, Global or DataZone processing, selected model provider, and customer-managed logging need deployment-specific confirmation. |
| GitHub | Copilot plans and GitHub-hosted agent products; not a general-purpose model API | GitHub Copilot Chat, cloud agent, CLI, repository indexes, and memory | GitHub Copilot is not documented as a drop-in general-purpose API retention equivalent to the four model platforms above. It has product-specific indexes, session state, memories, audit records, and model-provider choices. | 2026-07-24 | GitHub Copilot concepts | Retention must be assembled from the exact Copilot surface, selected model, account agreement, and organization policy; a single API number would be misleading. |
For an application, inventory your own gateway, traces, error reports, caches, vector database, and backups too. Provider retention is only one segment of the request path. Before sending personal data, use redaction before an LLM API and test that the redacted fields cannot be reconstructed from retained metadata.
6. Coding-agent repository context
| Provider | Plan | Product surface | What the official documentation establishes | Last checked | Official URL | Unknowns |
|---|---|---|---|---|---|---|
| OpenAI | Codex consumer plans and managed Business, Enterprise, or Edu workspaces | Codex local, IDE, cloud tasks, and connected GitHub repositories | Consumer Codex tasks can be subject to training controls, and full-environment sharing has a separate setting. Enterprise Codex inherits managed security, retention, residency, Compliance API, and no-training defaults. | 2026-07-24 | Codex enterprise admin guide | The exact files selected for a task, cloud environment lifetime, local transcript storage, and connector index retention require the current Codex documentation and workspace policy. |
| Anthropic | Claude Free, Pro, Max, Team, Enterprise, and API-backed Claude Code | Claude Code local and web sessions | Local Claude Code sends prompts and model outputs over the network and can send code or file contents included in context. Local session transcripts are stored in plaintext by default for 30 days. Cloud sessions clone the repository into an isolated VM under the account’s retention policy. | 2026-07-24 | Claude Code data usage | Model-provider routing, feedback submission, telemetry, local cleanup configuration, and which files are read in a particular session must be checked. |
| Gemini CLI authenticated through supported Google plans or API routes | Gemini CLI project context | GEMINI.md files from global, workspace, and just-in-time locations are concatenated and sent as model context. The CLI can also include a directory tree and additional directories according to configuration. | 2026-07-24 | Gemini CLI context files | Retention and training depend on the authentication route and applicable Google terms; the context-file documentation alone does not establish those policies. | |
| Microsoft | Microsoft Foundry or Microsoft 365 developer workflows; no single universal coding surface | Azure Direct Models and Microsoft-managed development environments | Microsoft documents the data path for Azure model inference and stateful features. Repository access performed by an IDE, extension, GitHub agent, or third-party agent must be analyzed as a separate surface. | 2026-07-24 | Microsoft Foundry data privacy | The editor, extension, repository host, telemetry stack, and model deployment can each add copies beyond Foundry. |
| GitHub | Copilot Free, Pro, Pro+, Business, and Enterprise, depending on feature | Copilot Chat, repository indexing, cloud agent, code review, CLI, and Memory | GitHub repositories can be indexed for semantic code search. Non-GitHub repository indexing uploads data to GitHub and is disabled by default for managed plans until enabled by policy. Repository memories are separately stored and validated. | 2026-07-24 | GitHub repository indexing | Index lifecycle, branch coverage, content exclusions, model routing, synced session data, and preview memory behavior require separate confirmation. |
Never write “the code stays on your laptop” because an agent executes locally. The exact path must be proven. Anthropic explicitly documents networked model processing for local Claude Code. Gemini CLI explicitly says context files are supplied to the model. GitHub documents that non-GitHub semantic indexing uploads workspace data. A local shell and a remote inference service can be parts of the same product.
Use the coding-agent sandbox guide for execution permissions, then use the terminal coding agents comparison for context-file and tool differences. Privacy and sandboxing overlap, but neither substitutes for the other.
7. Connectors, apps, MCP servers, and third-party copies
| Provider | Plan | Product surface | What the official documentation establishes | Last checked | Official URL | Unknowns |
|---|---|---|---|---|---|---|
| OpenAI | ChatGPT Business, Enterprise, and Edu | ChatGPT apps with sync and non-synced apps | Synced app indexes are separate from chat history, so workspace chat-retention settings do not apply to them. Disconnecting makes the index inaccessible and schedules underlying OpenAI index data for deletion within 30 days. Third-party app policies still apply. | 2026-07-24 | OpenAI app admin controls | The connected provider can retain source records, tool calls, or outputs. Residency support differs by app and region. |
| Anthropic | Claude plans with connectors or MCP; Enterprise policy varies | Claude connectors, MCP integrations, Claude Code tools, and shared chats | Anthropic documents product-specific connector and MCP behavior; its chat-sharing guidance warns that shared snapshots can include messages and artifacts while attached-file handling differs. Connector destinations require their own retention review. | 2026-07-24 | Claude share and unshare chats | No single connector statement covers every MCP server, third-party service, authentication route, and copied result. Review each destination’s policy. |
| Personal Gemini Apps and Google Workspace accounts | Gemini Connected Apps and Workspace data | Deleting Gemini activity does not delete data in other Google services. Removing remembered connected-app information can require both deleting relevant chats and disconnecting the app. Workspace administrators and source permissions constrain access. | 2026-07-24 | Gemini past-chat Memory and connected apps | Source-service retention, public links, imported content, app-specific logs, and delay before source changes affect Gemini remain separate. | |
| Microsoft | Microsoft 365 Copilot commercial accounts | Microsoft Graph grounding, Microsoft 365 data, plugins, and organizational controls | Enterprise data protection applies identity, permissions, sensitivity labels, retention, audit, and administrative settings to Copilot prompts and responses. Source files and generated copies remain governed by their own Microsoft 365 locations. | 2026-07-24 | Microsoft 365 Copilot enterprise data protection | Third-party agents, plugins, external actions, and non-Microsoft destinations may have additional terms and retention. |
| GitHub | Copilot Individual and managed plans; enterprise MCP policy differs | GitHub MCP server, third-party MCP servers, Copilot CLI, IDEs, and cloud agent | MCP can connect Copilot to files, databases, scripts, and external APIs. Managed plans can block MCP or restrict discovery to an approved registry, but policy coverage varies by surface. | 2026-07-24 | GitHub MCP management | Each MCP server is a separate data recipient. Registry listing is not proof of retention, deletion, residency, or contractual fitness. |
An integration can create three copies: the source record, context sent to the model, and an output written back to another service. Disconnecting the integration usually stops future access; it does not automatically erase all three. Apply the MCP security checklist to permissions, secrets, logging, and tool output.
8. Enterprise administrator retention, export, and legal holds
| Provider | Plan | Product surface | What the official documentation establishes | Last checked | Official URL | Unknowns |
|---|---|---|---|---|---|---|
| OpenAI | ChatGPT Enterprise, Edu, and Healthcare; Business has different controls | Managed ChatGPT workspace, Compliance API, files, and Codex | Workspace administrators can control retention for eligible managed plans. Managed-account administrators may access, export, audit, retain, or delete prompts, files, outputs, history, and metadata under workspace controls. | 2026-07-24 | Managed ChatGPT account data access | Contract, role configuration, Compliance API coverage, app indexes, legal exceptions, and backup periods must be confirmed. |
| Anthropic | Claude Enterprise | Claude conversations, projects, memory data, incognito chats, and organization exports | Enterprise owners can configure custom retention. Memory-related data and incognito chats are subject to organization retention and exports; disabling organization memory can permanently delete memory synthesis data. | 2026-07-24 | Anthropic Enterprise retention controls | Minimums, contract exceptions, safety retention, covered products, and ZDR eligibility must be confirmed with the account team. |
| Google Workspace editions with Gemini | Gemini Apps for work or school, Workspace admin controls, and Google Vault where applicable | Work or school activity settings are controlled by the Workspace administrator. Users may not be able to change retention or see the configured period. Source data access follows Workspace permissions and admin restrictions. | 2026-07-24 | Gemini access to Workspace data | Edition, Vault coverage, region, history configuration, user deletion availability, and side-panel behavior require tenant-specific testing. | |
| Microsoft | Microsoft 365 commercial plans with Purview capabilities | Microsoft 365 Copilot interactions, Exchange-backed records, Purview retention, audit, and eDiscovery | Purview retention policies can retain or delete Copilot prompts and responses. Holds and retention policies can override ordinary deletion, and Copilot interactions can be searched through eDiscovery. | 2026-07-24 | Purview management for Microsoft 365 Copilot | Licensing, policy precedence, distribution delay, sovereign cloud behavior, and every copied file or downstream record must be checked. |
| GitHub | Copilot Business and Enterprise | Copilot Memory, audit log, organization repositories, and enterprise policies | Administrators can enable memory policy, inspect repository facts, export or delete user preferences, and audit certain memory events. User preferences are tied to the active billing entity. | 2026-07-24 | Administer GitHub Copilot Memory | Public-preview changes, export freshness, organization transfer, repository deletion, and broader Copilot transcript retention need separate evidence. |
For regulated work, administrator visibility is a feature, not a privacy failure, when it is disclosed and governed. It becomes a failure when employees think “temporary” or “deleted” means “invisible to compliance” and the organization’s policy says otherwise.
Trust portals help with vendor assurance, but a certification does not answer a feature-level retention question. The OpenAI Trust Portal lists security and compliance materials for covered services, including public descriptions and gated reports. The Microsoft Trust Center provides Microsoft-wide security, privacy, data-location, and compliance resources. Use trust-center artifacts alongside the exact product documentation, contract, data-flow diagram, and tenant configuration.
9. Account deletion and content deletion
| Provider | Plan | Product surface | What the official documentation establishes | Last checked | Official URL | Unknowns |
|---|---|---|---|---|---|---|
| OpenAI | Consumer ChatGPT and API account | OpenAI account, chats, memories, files, and subscription | Account deletion is permanent. OpenAI says it deletes data within 30 days, subject to limited legal or permitted retention. Mobile-store subscriptions may need separate cancellation. Memories and chats also have separate deletion controls. | 2026-07-24 | Delete an OpenAI account | De-identified data, legal holds, connected-app copies, workspace-managed accounts, and mobile billing require separate treatment. |
| Anthropic | Claude Free, Pro, and Max consumer accounts | Claude account, subscription, and saved chats | Consumer deletion is permanent. Paid users must cancel and wait until the current subscription period ends before deleting in the documented flow. Third-party access paths require deletion through that third party. | 2026-07-24 | Delete a Claude account | Commercial organization deletion, training pipelines, feedback records, trust-and-safety exceptions, and third-party copies differ. |
| Personal Google Account | Google Account, Gemini Apps Activity, and product-specific data | Google allows deletion of activity, individual services, or the account. Activity deletion begins removal from the product and storage systems, with documented security, financial, legal, operational, and anonymized-data exceptions. | 2026-07-24 | How Google deletes account data | Deleting Gemini activity does not delete Gmail, Drive, Photos, public links, or other service data. Exact completion timing is not universal. | |
| Microsoft | Personal Microsoft account and work accounts have different owners | Microsoft privacy dashboard, Copilot history, and Microsoft account | Personal Copilot activity can be cleared through the privacy dashboard. Work-account Copilot history uses a separate deletion request and can be subject to organizational policy. | 2026-07-24 | Manage Copilot activity history | Account closure, tenant records, retention holds, saved files, browser data, and organizational copies require separate workflows. |
| GitHub | GitHub personal account and Copilot subscriptions | GitHub account, owned repositories, contributions, Copilot memories, and exports | Deleting a GitHub personal account removes owned resources, but contributions to others’ repositories remain associated with a ghost user. Copilot memories have separate user and admin deletion paths. | 2026-07-24 | GitHub personal account management | Forks, clones, Git history, backups, marketplace installations, organization-owned data, and model-provider records can survive account deletion. |
Account deletion is the broadest user action, but it is not always the fastest or most precise. For one bad memory, remove the memory and its source chats. For one client project, delete project files, chats, connected indexes, shares, and downstream copies. For a departing employee, use the organization’s retention and offboarding process rather than asking the employee to delete a managed account.
10. Export and migration
| Provider | Plan | Product surface | What the official documentation establishes | Last checked | Official URL | Unknowns |
|---|---|---|---|---|---|---|
| OpenAI | Consumer ChatGPT; Business and Enterprise exports differ | ChatGPT data export and Privacy Portal | Consumer users can request an export containing chat history and other relevant account data. OpenAI states that ChatGPT Business and Enterprise chat exports are not available through the same consumer flow. | 2026-07-24 | Export ChatGPT history and data | Export schema, memory completeness, app indexes, Codex environments, deleted items, and managed-workspace coverage must be inspected in the resulting archive or admin tools. |
| Anthropic | Claude Free, Pro, and Max; organization exports are owner-controlled | Claude data export | Individual exports include conversation data and account data. Team and Enterprise exports are available to the Primary Owner. Personal exports cannot be imported into another personal Claude account. | 2026-07-24 | Export Claude data | Export timing, memory format, attachments, deleted content, and organization migration rules require current verification. |
| Personal Google Account | Google Takeout, Gemini import, and Google account data | Google Takeout creates an archive but does not delete source data. Gemini can import supported memory or chat exports from other assistants, but availability has account, age, surface, and regional limits. | 2026-07-24 | Google Takeout | Gemini-specific export coverage, import fidelity, file-size limits, regional availability, and whether derived memories map correctly must be tested. | |
| Microsoft | Personal Microsoft account; work-account paths differ | Microsoft privacy dashboard and Copilot activity export | Personal users can export Copilot app and Microsoft 365 app activity history from the privacy dashboard, including CSV-based activity exports. | 2026-07-24 | Export or delete Copilot history | An activity CSV may not include every memory, file, administrator record, or tenant-held copy. Work-account export is organization-dependent. |
| GitHub | GitHub personal account; Copilot Business and Enterprise add admin memory export | GitHub account archive and Copilot Memory export | Users can request a tar.gz account archive. Managed Copilot administrators can separately export user-level preferences in JSONL. These are distinct exports with different owners and scopes. | 2026-07-24 | GitHub account data archive | Repository clones, LFS objects, Copilot transcripts, indexes, third-party agent data, and preview memory details need separate checks. |
An export is evidence of what the provider chose to include, not proof that the archive lists every internal copy. It is useful for migration, review, and preservation. It does not delete the source.
11. Regional storage, processing, and feature differences
| Provider | Plan | Product surface | What the official documentation establishes | Last checked | Official URL | Unknowns |
|---|---|---|---|---|---|---|
| OpenAI | Eligible API and managed ChatGPT customers; availability and approvals vary | API project data residency, regional processing, and managed ChatGPT residency | OpenAI distinguishes storage at rest from regional inference processing. API residency is configured per project, applies only to supported services, and excludes system data and third-party services. A region offering storage does not necessarily offer regional processing. | 2026-07-24 | OpenAI API data residency controls | Eligibility, model and endpoint coverage, non-US approval, system data, failover, and connected-app routing must be confirmed for the selected project. |
| Anthropic | Consumer, Team, Enterprise, and API arrangements | Claude feature rollout, Enterprise retention, and API or third-party deployment routes | Anthropic documents different memory rollouts across plans and separate data paths for the Anthropic API, Amazon Bedrock, Google Vertex AI, and Microsoft Foundry. A Claude feature name does not make those routes equivalent. | 2026-07-24 | Claude Code data usage and provider routes | Storage region, processing region, subprocessor access, model availability, and retention depend on the contract and selected provider route. |
| Personal Google accounts, Workspace accounts, and Google Cloud projects | Gemini Apps features, Gemini import, Workspace administration, and Vertex AI regions | Personal past-chat Memory is unavailable for work, school, and supervised accounts. Gemini import has documented regional exclusions. Vertex AI region and feature configuration is a separate cloud decision from consumer Gemini availability. | 2026-07-24 | Gemini import availability | Account country, age, Workspace edition, staged rollout, model location, grounding feature, and data-residency configuration must be checked separately. | |
| Microsoft | Microsoft Copilot personal accounts, Microsoft 365 commercial tenants, and Azure deployments | Consumer memory, Microsoft 365 Copilot, and Foundry Global, DataZone, or regional deployments | Personal Copilot memory has documented country exclusions. Microsoft Foundry states that Global and DataZone deployment types can process data outside a single selected region while stored data remains governed by the resource geography. | 2026-07-24 | Microsoft Foundry processing locations | Sovereign-cloud features, model availability, preview controls, tenant geography, failover, and third-party model routes require deployment-specific evidence. |
| GitHub | Copilot Individual, Business, and Enterprise; feature availability varies by client | GitHub-hosted repositories, non-GitHub semantic indexing, CLI, IDEs, cloud agent, and MCP | GitHub documents different policy coverage across clients. Non-GitHub semantic indexing uploads workspace data to GitHub when enabled, while MCP registry and allowlist enforcement differ across CLI, IDE, and cloud-agent surfaces. | 2026-07-24 | GitHub Copilot context and indexing | Data-location commitments, selected model route, enterprise geography, editor telemetry, MCP destination region, and preview-feature rollout need contract and client-level confirmation. |
Regional language is easy to overread. “EU data residency” may describe storage but not inference, system metadata, support access, a connected application, or an optional grounding feature. Record each of those as a separate field.
Decision guide by scenario
Scenario 1: personal brainstorming
Recommended posture: use a personal account with memory limited to stable, low-risk preferences. Use a fresh temporary or incognito chat when you want an outside perspective.
Keep:
- enduring format preferences;
- recurring project names that are not sensitive;
- accessibility needs you deliberately want applied across sessions.
Do not keep:
- a one-off hobby, fictional character, or mood as a global preference;
- temporary relationship, employment, health, or financial details;
- instructions that should apply to only one creative project.
Test the assistant with an unrelated prompt after saving a preference. If it drags the preference into the answer without a reason, narrow or delete it. A good memory system should improve relevance without making every answer sound like the same person at the same meeting.
Plan limits also matter. A subscription may provide more usage or context without changing the underlying privacy default. Buy capacity only after verifying the memory, training, and retention controls on that plan; do not assume “paid” means “confidential.”
Scenario 2: confidential client work
Recommended posture: use an organization-approved business or enterprise surface under a contract that excludes training by default, with connectors disabled until reviewed. Do not use a personal subscription merely because it has a temporary mode.
Before the first real document:
- Classify the client data and identify contractual restrictions.
- Confirm the exact workspace, plan, account owner, region, and retention policy.
- Confirm whether administrators can export the conversation and whether that is acceptable.
- Disable or prohibit unnecessary memory, past-chat search, public sharing, feedback, and unreviewed connectors.
- Redact direct identifiers and secrets that the task does not need.
- Run a synthetic pilot and deletion test.
If the client forbids third-party model processing, the correct answer is not a shorter retention period. Use an approved deployment path or do not send the content.
Scenario 3: source code and coding agents
Recommended posture: keep authoritative context in versioned repository files, not only in provider memory. Use least-privilege repository access, exclude secrets and generated assets, and review the agent’s actual data path.
A repository context file can make switching easier:
Purpose: rules that every approved coding agent may read
Scope: this repository only
Contains: build commands, architecture constraints, test commands
Must not contain: secrets, customer records, access tokens, private URLs
Owner: engineering team
Review trigger: architecture or toolchain change
OpenAI Codex, Claude Code, Gemini CLI, and GitHub Copilot use different instruction files and discovery rules. The operational pattern is portable; the exact implementation is not. The Claude Code vs OpenAI Codex comparison covers workflow differences, but always recheck current official privacy documentation before connecting a private repository.
Do not rely on .gitignore alone. A tool may read untracked files, follow imported instructions, index workspace files, or receive tool output containing secrets. Test with a harmless canary file that should be excluded, inspect available context controls, and confirm the canary never appears in the response or provider-side artifact.
Scenario 4: health or financial notes
Recommended posture: do not place identifiable medical or financial records in a general consumer assistant. For low-risk personal reflection, minimize details, use a temporary mode, disable training where available, and assume short-term provider retention still exists.
Temporary mode cannot turn a consumer product into a regulated record system. It also cannot guarantee clinical correctness or financial suitability. If the task involves protected health information, account numbers, tax records, insurance claims, investment holdings, or a professional duty of confidentiality, use a specifically approved product and contract.
Separate the note from identity:
- remove names, exact dates of birth, account numbers, addresses, and document IDs;
- replace exact institutions or clinicians with neutral labels when they are not needed;
- omit unrelated history;
- do not connect email, cloud storage, health, or financial services merely to save copy-and-paste effort;
- do not submit feedback on a sensitive conversation because feedback may follow different data-use rules.
Meeting transcripts add voice, attendee, and calendar copies. Use the AI meeting notes privacy checklist before recording any sensitive discussion.
Scenario 5: regulated enterprise use
Recommended posture: treat the assistant as a governed information system. Select a specific enterprise product, approved feature set, region, retention schedule, administrator model, and contract. Prohibit unapproved surfaces even when the same provider name appears on them.
Minimum approval packet:
- data-flow diagram for prompts, outputs, files, memory, indexes, logs, tools, and exports;
- product and feature inventory with plan and region;
- training, retention, deletion, backup, residency, and subprocessor evidence;
- identity, SSO, provisioning, least-privilege roles, and offboarding;
- audit, eDiscovery, legal hold, incident response, and deletion procedures;
- connector and MCP allowlist;
- documented prohibited data and approved use cases;
- synthetic deletion test and evidence-retention policy;
- review date and change triggers.
Use conditional approval language:
Approved for redacted internal policy search in the named managed workspace with past-chat memory disabled, approved regional storage, organization retention applied, and only the reviewed document connector enabled. Not approved for raw health records, payment credentials, legal-privileged material, or personal accounts.
For tenant separation and retrieval authorization, use the multi-tenant RAG security guide. A provider’s enterprise certification does not repair a cross-tenant application bug.
How to verify deletion without overstating proof
Deletion verification has hard limits. A user usually cannot inspect provider backups, abuse-monitoring systems, model-training pipelines, de-identified datasets, legal holds, or every subprocessor. Even an administrator export is not a complete map of internal storage.
Use a layered verification record:
- User interface: Delete the synthetic chat, file, memory, project, or session and refresh every relevant view. Keep a timestamped record of the object ID, action, and visible result. This does not prove backend erasure, backup expiry, legal-hold release, or third-party deletion.
- Retrieval: Start a fresh ordinary chat and ask a neutral question that previously retrieved the synthetic canary. Record repeated tests where the canary is no longer returned. This does not prove absence from storage because retrieval can fail for other reasons.
- Export: Request a new export after the provider’s documented processing window and search for the canary. Keep the export date, archive hash, searched fields, and result. This does not prove the export covers every internal system.
- API or administrator tool: Query the object, compliance endpoint, memory panel, index, or eDiscovery location where supported. Keep the not-found response, audit event, policy state, or purge result. This does not cover unexposed backups, third-party tools, or copied outputs.
- Connected systems: Search the source app, destination app, logs, CRM, ticketing system, and object storage. Keep the result for each inventoried system. This says nothing about a system omitted from the inventory.
- Provider and contract: Retain the official policy version, support response, data-processing clause, and trust artifact. This documents the provider’s commitment but does not prove a specific deletion executed correctly.
Use synthetic canaries, not real secrets. A good canary is unique enough to search, harmless if exposed, and mapped to a single test identity. Record where it was entered and every derived artifact expected.
Do not write “permanently deleted everywhere” unless you have authority and evidence for every layer. Prefer:
Removed from the user interface and no longer retrievable through the tested chat, memory, export, and connector paths as of 2026-07-24. Provider backup, safety, legal-hold, and de-identified-data handling remain subject to the cited policy and contract.
Migration without importing the mess
Moving assistants is a chance to reduce stale memory rather than copying it wholesale.
Migration steps
- Freeze new durable memory temporarily. Keep using the source service only for low-risk work while you take inventory.
- Export before deleting. Use the official export path and save the original archive read-only. Export does not delete source data.
- Inventory by category. Separate chats, saved memories, custom instructions, project files, repository context, shared links, connector indexes, and account metadata.
- Classify each item. Mark it keep, rewrite, project-only, archive-only, or delete.
- Rewrite durable memory. Convert broad preferences into scoped statements with an owner and review trigger.
- Remove secrets and stale facts. Do not import API keys, client data, sensitive inferences, old jobs, obsolete coding rules, or records without a continuing purpose.
- Test the destination with a small sample. Confirm what the import feature creates: a chat, a memory, a project file, or an account-level preference.
- Check regional and plan availability. Google, for example, documents regional and account restrictions for Gemini import; Claude states that personal exports cannot be imported into another personal Claude account.
- Validate behavior. Run one related prompt and one unrelated prompt. The imported context should help the first and stay out of the second.
- Delete source copies deliberately. Delete memories, source chats, project files, shares, and connector indexes separately. Close the account only if that broader action matches the goal.
- Re-export or re-query after the documented window. Search for the synthetic canary and record the limits of the proof.
- Keep a migration manifest. Store item counts, archive hashes, dates, provider URLs, unknowns, and the person who accepted residual risk.
Do not upload a full export to a new assistant just to ask it what should be migrated. That sends the entire old data set to the new provider before classification. Review locally or with an already approved tool, then import the minimum.
A compact buyer checklist
Before paying for a plan, connecting a repository, or approving an enterprise deployment, answer:
- Which account and plan will own the data?
- Is the surface consumer chat, managed chat, coding agent, API, or connector?
- What creates durable memory, and who can inspect or delete it?
- Is past-chat search separate from saved memory?
- Is training enabled by default, opt-out, opt-in, or contractually excluded?
- What does temporary mode omit, and how long is it still retained?
- Which API endpoints or tools create application state?
- Which repository files, history, indexes, and local transcripts are in scope?
- Which connectors or MCP servers receive data?
- Can an administrator export, retain, hold, or delete user content?
- What must be deleted separately from the chat?
- What does the export include and omit?
- Where is data stored and processed, and does the selected region change both?
- What happens to data after a member leaves or an account is closed?
- What remains unknown, who owns the question, and when will it be rechecked?
If a vendor or internal owner cannot answer, do not replace the blank with a guess. Mark it unknown and restrict the workload until evidence exists.
Frequently asked questions
1. Does deleting a chat delete what the assistant remembers?
Not necessarily. OpenAI documents saved memories separately from chat history. Anthropic’s behavior depends on the current memory experience. Google may require deleting every relevant chat and disconnecting a source app. Delete the memory, source chats, projects, files, and connector copies that apply, then test retrieval.
2. Does turning memory off delete existing memory?
Usually not by itself. A toggle may stop future use or creation while keeping existing entries. Use the provider’s delete or reset control and verify the result in a fresh session.
3. Is a temporary or incognito chat immediately erased?
No general rule says that. OpenAI documents a period of up to 30 days for Temporary Chats. Anthropic documents 30 days by default for incognito chats, with enterprise policy differences. Google documents up to 72 hours in relevant activity-off behavior. Read the exact surface’s current rule.
4. Does “not used for training” mean the provider stores nothing?
No. Storage for chat history, safety, abuse monitoring, application state, files, feedback, support, billing, indexes, or legal obligations can remain. Training and retention are separate rows in a privacy review.
5. Are paid personal plans safe for confidential client work?
Payment alone does not create a confidentiality agreement or enterprise control set. Use the organization-approved plan and contract, confirm training and retention defaults, disable unreviewed connectors, and minimize the data before sending it.
6. Can my employer see a temporary work chat?
Possibly. Anthropic states that Enterprise incognito chats can be included in organization exports and follow organization retention. Microsoft warns that temporary Microsoft 365 Copilot data may be accessible to the IT administrator during the retention period. Check the managed-account notice and internal policy.
7. Do local coding agents keep source code on the device?
Do not assume so. A local agent may execute commands locally while sending prompts, file excerpts, tool results, or repository context to a remote model. Only claim device-only handling when official documentation proves the exact product path and configuration.
8. Does .gitignore prevent an AI coding agent from reading a file?
Not universally. Some tools respect ignore files for some discovery paths but can still access a file through explicit tools, imports, additional directories, or configuration. Use product-specific exclusions and test with a harmless canary.
9. Are repository memory and repository indexing the same?
No. GitHub, for example, documents semantic repository indexing separately from Copilot Memory. One helps retrieve code context; the other stores validated repository facts and user preferences. They have different controls and lifecycles.
10. Does disconnecting a connector delete everything it previously accessed?
No universal guarantee exists. OpenAI documents deletion behavior for its synced index, but the source system and any destination copies remain separate. Google states that deleting Gemini activity does not delete other Google-service data. Inventory all copies.
11. Can an export prove what a provider stores?
An export proves what the provider made available in that export at that time. It may omit backups, safety records, de-identified data, model-training artifacts, or product-specific stores. Use it as one evidence layer.
12. Should I delete my account to remove one unwanted memory?
Usually not. Remove the memory and its source chats first, then verify. Account deletion is irreversible and can affect subscriptions, repositories, API access, or organization data without guaranteeing deletion of copies held by others.
13. How should I move memory to another assistant?
Export, classify locally, rewrite broad preferences into scoped statements, remove sensitive and stale items, import a small sample, and test both relevant and unrelated prompts. Never upload the entire archive before reviewing it.
14. Which assistant is best for regulated data?
No provider name is sufficient. Choose an exact enterprise product, contract, approved region, retention schedule, administrator model, connector set, audit path, deletion procedure, and permitted use case. A consumer surface from the same company is not equivalent.
15. How often should these settings be reviewed?
Review after a plan change, major feature rollout, new connector, model or endpoint change, region change, contract renewal, account migration, deletion failure, or privacy incident. For ongoing sensitive use, assign a regular review date and owner.
Sources checked 2026-07-24
Official primary sources used for product facts:
- OpenAI, Memory FAQ.
- OpenAI, Temporary Chat FAQ.
- OpenAI, Chat and File Retention Policies.
- OpenAI, How your data is used to improve model performance.
- OpenAI, API data controls.
- OpenAI, Enterprise privacy.
- OpenAI, Managed ChatGPT account data access.
- OpenAI, ChatGPT data export.
- OpenAI, Account deletion.
- OpenAI, Apps admin controls.
- OpenAI, Trust Portal.
- Anthropic, Claude chat search and memory.
- Anthropic, Claude incognito chats.
- Anthropic, Consumer retention.
- Anthropic, Commercial retention.
- Anthropic, Enterprise custom retention.
- Anthropic, Claude Code data usage.
- Anthropic, Claude Code project memory.
- Anthropic, Claude data export.
- Anthropic, Claude account deletion.
- Google, Gemini Apps Privacy Hub.
- Google, Manage Gemini Apps activity.
- Google, Gemini past-chat Memory.
- Google, Gemini memory and chat import.
- Google, Google Takeout.
- Google, How Google deletes account data.
- Google Cloud, Vertex AI zero data retention.
- Gemini CLI, GEMINI.md context.
- Microsoft, Copilot privacy controls.
- Microsoft, Copilot activity history.
- Microsoft, Microsoft 365 Copilot enterprise data protection.
- Microsoft, Purview for Microsoft 365 Copilot.
- Microsoft, Foundry data privacy.
- Microsoft, Trust Center.
- GitHub, Copilot Memory.
- GitHub, Repository indexing.
- GitHub, MCP management.
- GitHub, Copilot Memory administration.
- GitHub, Account data archive.
- GitHub, Personal account management.
Demand evidence, used only to describe user concerns: