What Happens to Your Data When You Use AI — GDPR Explained Simply

Safety & scams Guide8 min read·Updated July 17, 2026
The short answer

When you type something into an AI tool, your words are sent to the company's servers. In many cases, unless you turn off a setting, that text can be used to improve the AI — meaning it may become part of what the model learns from. GDPR gives you the right to ask what a company holds about you, demand deletion, and object to your data being used for training. The key steps are: find the privacy settings, turn off training if you can, and know how to ask for erasure.

Every time you type a question or a problem into an AI chatbot, those words leave your device and travel to a company's server. That part is unavoidable — the AI lives there, not on your phone or laptop. But what happens to those words after they arrive? That is where it gets important, and where your rights as a European resident come in.

Data privacy is the top concern many Europeans have about AI tools. That concern is well founded — and this guide will help you understand what is actually going on, in plain English.

What "Your Prompts May Train the Model" Actually Means

When you type something into a consumer AI chatbot and press send, your message goes to the company's servers. The AI generates a reply, which comes back to you. So far, so normal — this is how almost every web service works.

The extra step is this: many consumer AI services, by default, keep a record of that conversation and may use it to improve their model. "Improving the model" means the company's engineers review patterns in conversations (sometimes with human reviewers) and use those patterns to make the AI smarter over time.

In practice, this means words you typed — your questions, your worries, your personal situation — could become part of what the AI learns from. Not in a way that lets someone search for your exact message, but your words do contribute to the model's future behaviour.

This is not a secret. It is in the terms of service. Most people just never read them.

The Difference One Setting Makes

Almost every major AI service now has a privacy or data settings page. In that page, there is usually an option along the lines of: "Use my conversations to improve the model." It is often on by default for free accounts.

Turning it off takes about thirty seconds, and it means your new conversations will not be used for training.

What it does NOT do:

  • It does not delete conversations already stored on the server.
  • It does not prevent the company from keeping the conversation for safety monitoring or legal reasons.
  • It may not apply to conversations you had before you changed the setting.

To actually remove stored data, you need to use your GDPR rights — explained below.

Your Three Core GDPR Rights, in Plain English

GDPR stands for General Data Protection Regulation. It is EU law that gives you real, enforceable control over your personal data. Here are the three rights most relevant to AI tools.

1. The Right to Access

You can ask any company: "What personal data do you hold about me?" This is Article 15 of GDPR. They must tell you within one month, and they must give you a copy in a usable format; for complex or numerous requests they can extend that by a further two months, but only if they tell you within the original month and explain why. This is called a Subject Access Request (SAR).

For an AI tool, this might include: your account details, your conversation history, and any inferences the company has drawn from your use.

2. The Right to Erasure (the "Right to Be Forgotten")

Under Article 17, you can ask a company to delete the personal data it holds about you, with the same one-month-plus-two-months timeline as above. This right is not absolute: Article 17(3) lets them refuse in limited circumstances — for example, if they are legally required to keep the data, or need it to establish or defend a legal claim — but they must explain why.

For AI tools, this typically means: deleting your account, your stored conversations, and any training data derived from your conversations (though this last part can be technically complicated, and companies may not be able to remove your influence from an already-trained model).

3. The Right to Object

Under Article 21, you can tell a company: "Stop using my data for this purpose." For AI training, this means objecting to your conversations being used to improve the model. The company must stop, unless they can show a compelling reason to continue.

In practice, many companies make it easier to use the privacy settings toggle than to go through a formal objection process — but both routes are available to you.

What If a Company Doesn't Respond?

If a company misses the deadline on a request to access, delete, or object, or you think their response falls short, you can complain to a supervisory authority. In the UK, that's the ICO (Information Commissioner's Office); in the EU, it's the national data protection authority for the country the company is established in, or where you live. The authority can investigate the complaint and order the company to fix the problem — but it does not settle disputes over compensation between you and the company, or pay damages on your behalf. If you believe you suffered actual harm and want compensation, that has to go through the courts.

Concrete Steps You Can Take Today

Here is a simple checklist. You do not need to do all of these — even one or two make a real difference.

Step 1 — Find the privacy settings. In ChatGPT, go to Settings → Data Controls. In other tools, look for Settings → Privacy or Help → Privacy Policy → Your Rights.

Step 2 — Turn off training. Toggle off any option that says "improve the model," "use conversations for training," or similar. Save.

Step 3 — Delete your conversation history. Most AI tools let you delete individual chats or all history. Deleting them from your view also removes them from the company's training pipeline going forward.

Step 4 — Send a deletion request if you want a clean slate. Use the company's privacy request form (usually in the Help Centre or Privacy page). State clearly: "I am exercising my right to erasure under GDPR. Please delete all personal data held about me, including conversation history."

Step 5 — Use a more private mode for sensitive topics. Some tools offer an "incognito" or "temporary chat" mode that does not save the conversation at all. Use this when discussing anything you would not want stored.

"I would like to ask a question about my personal situation but I want to keep it private. Is there a way to use you without saving this conversation?"

You can literally ask the AI this — it will tell you what modes or settings are available.

What to Watch Out For

Never paste medical, financial, or ID details. Even with training turned off, your text is stored on the company's servers during the session. A full name plus a medical condition plus a date of birth is exactly the kind of combination that makes personal data sensitive. Use general descriptions instead.

Screenshots and voice recordings are data too. If you share a photo or use a voice assistant, that image or audio goes to the server. Be just as careful with visual and audio input as you are with typed text.

"Free" tools and your data. When a service costs nothing, the company has to pay its bills somehow. For many AI tools, one answer is using what users share to make the product better — which they can then sell to businesses. This is not automatically bad, but it is worth being aware of.

Phishing and fake "data deletion" forms. You will occasionally see emails or messages claiming to help you delete your AI data. Always go directly to the official website — never click a link in an unexpected email. Legitimate GDPR requests go through the company's own privacy page.

Training off ≠ data gone. Turning off training is an important step, but it is not the same as asking for your data to be deleted. If you want a full clean slate, you need to submit a formal erasure request.

What to Try Next

Once you have sorted your privacy settings, the next step is understanding exactly what data these tools already hold about you — and how to see it. Our guide What Does AI Know About Me? walks through how to request a full data export from major AI services.

If you use ChatGPT specifically, the step-by-step walkthrough in ChatGPT Privacy Settings shows you every toggle in plain language.

And if you want to go further — opting out of training across multiple services at once — How to Opt Out of AI Training and Request Deletion of Your Data covers the full process.

Sources

Published July 17, 2026 · Updated July 17, 2026How we test →

Frequently asked questions

Can an AI company use what I type to train its model?
It depends on the service and your settings. Many consumer AI tools do use your conversations to improve the model by default. Most give you a way to turn this off in the privacy or data settings. Once you turn it off, new conversations are not used for training — though what happened before may still be on their servers. Check the specific tool's privacy settings page.
What is the GDPR right to erasure?
The right to erasure — also called the 'right to be forgotten,' set out in Article 17 — means you can ask a company to delete the personal data it holds about you. The company must respond within one month, extendable by two further months for complex requests if they tell you within the first month. It is not an unconditional right: under Article 17(3) they may refuse in limited cases, such as when they are legally required to keep the data or need it to defend a legal claim, but they must tell you why.
Does GDPR apply to AI tools made outside the EU?
If the service is offered to people in the EU — and you are in the EU — GDPR applies, even if the company is based in the USA or elsewhere. If you are in the UK, the equivalent law is UK GDPR, which works the same way and is enforced by the ICO rather than an EU authority. This is one reason major AI companies like OpenAI have European offices and privacy processes.
What is the difference between a consumer account and a business or API account?
Consumer accounts (free or paid personal subscriptions) often come with training enabled by default. Business-tier subscriptions and API access typically do not use your data for training. If privacy is important to you, check whether your workplace or service provider uses a business plan.
Is it safe to type medical or financial details into an AI chatbot?
It is safer to avoid it. Even with training turned off, your text is transmitted to and stored on the company's servers. If you must discuss something sensitive, use a vague description rather than exact figures, names, or ID numbers. Never paste a scan of an official document.
Where do I send a GDPR data request?
Look for a 'Privacy Request' or 'Data Subject Request' form in the AI tool's help centre or privacy page. You can also email the company's Data Protection Officer (DPO) — the address should be in their privacy policy. They have one month to reply, extendable by two further months for complex requests. If they don't reply, or you're unhappy with the reply, you can complain to your national supervisory authority — the ICO in the UK, or the equivalent data protection authority in an EU country — which can investigate and order the company to comply. It cannot award you compensation, though; a damages claim needs to go through the courts.
Radim S.
Founder & editor

Radim is a software developer who spends his days building with AI and his evenings explaining it to family members who don’t care how it works — only what it can do for them. The safety guides are checked claim by claim against primary sources before they go out.