AI Chatbot Privacy: How to Protect Your Most Sensitive Conversations
If it’s technology The technology industry has tried to develop ways to persuade users to send their deepest, most sensitive secrets to servers in faraway data centers. But it would be difficult to create a more effective honeypot than an AI chatbot.
OpenAI’s ChatGPT, Anthropic’s Claude, Google’s Gemini, and countless smaller competitors have become therapists, counseling centers, and virtual confession booths for millions of people around the world. Almost all of these AI models are configured by default to collect and store sensitive data, often without clear restrictions on how that information can be shared or sold, used to train the tool, or turned over to plaintiffs in lawsuits or law enforcement agencies that request it through legal proceedings.
“You have this intelligent being staring back at you and basically telling you everything you need to know about your life one question at a time,” said Matt Green, a computer science professor at Johns Hopkins University who focuses on privacy and security. “You’re giving such a huge profile about yourself.”
Ten years ago, text messages probably represented the most personal and sensitive data most people shared from their devices, says cryptographer and software developer Moxie Marlinspike. The surveillance risks posed by unsecured text messages led him to create Signal in 2014, an end-to-end encrypted messenger now used by well over 100 million people. Today, he says, the critical point of privacy vulnerability has shifted to the interactions between people and AI.
“The same things I was concerned about with messaging are happening in AI, but on an order of magnitude larger scale,” Marlinspike said. “People are integrating AI into their personal lives. They talk to it about their deepest fears, finances, health, and relationships.”
Earlier this year, Marlinspike launched Confer, an AI chatbot designed to let users ask any questions they want while preserving their privacy. The service uses encryption to technically prevent its own servers from monitoring or recording conversations. “Confer is designed to be a service where you can explore ideas without the possibility that your own thoughts might one day conspire against you,” he wrote in a blog post. Let me introduce you to it.
Marlinspike’s private AI tools are one standout among a new generation of AI services that promise to address the widespread privacy violations associated with many chatbots. Some advertise a policy of never recording conversations. Others suggest anonymization. A few companies, including Confer, are trying to create technical guardrails that limit access to users’ secrets.
The early race to develop less-observable AI has produced a growing array of tools. Many offer confusing guarantees to users who want to adopt increasingly inevitable technology without losing control of their private information. Here’s WIRED’s guide to using AI while protecting your privacy.
What Is Zero Data Retention?
When you start typing into one of the three major AI chatbots—ChatGPT, Claude, or Gemini—the safest baseline assumption is that you have virtually no privacy from anyone who has a legal way to access your conversation records. This may include service owners, advertisers, business partners, contractors who help fine-tune the system, law enforcement, or anyone who successfully subpoenas records during a civil lawsuit.
The simplest and strongest exception is a contract between you—or, more likely, your employer—and the AI provider that legally prohibits the provider from retaining those records. This provision is known as Zero Data Retention, or ZDR. OpenAI, Anthropic, and Google all offer ZDR policies for their enterprise products. Enabling ZDR generally requires user interaction records to be deleted as soon as they have been processed.
Source: www.wired.com


