When you type something into an AI tool, your words are sent to the company's servers. In many cases, unless you turn off a setting, that text can be used to improve the AI — meaning it may become part of what the model learns from. GDPR gives you the right to ask what a company holds about you, demand deletion, and object to your data being used for training. The key steps are: find the privacy settings, turn off training if you can, and know how to ask for erasure.
Every time you type a question or a problem into an AI chatbot, those words leave your device and travel to a company's server. That part is unavoidable — the AI lives there, not on your phone or laptop. But what happens to those words after they arrive? That is where it gets important, and where your rights as a European resident come in.
Data privacy is the top concern many Europeans have about AI tools. That concern is well founded — and this guide will help you understand what is actually going on, in plain English.
What "Your Prompts May Train the Model" Actually Means
When you type something into a consumer AI chatbot and press send, your message goes to the company's servers. The AI generates a reply, which comes back to you. So far, so normal — this is how almost every web service works.
The extra step is this: many consumer AI services, by default, keep a record of that conversation and may use it to improve their model. "Improving the model" means the company's engineers review patterns in conversations (sometimes with human reviewers) and use those patterns to make the AI smarter over time.
In practice, this means words you typed — your questions, your worries, your personal situation — could become part of what the AI learns from. Not in a way that lets someone search for your exact message, but your words do contribute to the model's future behaviour.
This is not a secret. It is in the terms of service. Most people just never read them.
The Difference One Setting Makes
Almost every major AI service now has a privacy or data settings page. In that page, there is usually an option along the lines of: "Use my conversations to improve the model." It is often on by default for free accounts.
Turning it off takes about thirty seconds, and it means your new conversations will not be used for training.
What it does NOT do:
- It does not delete conversations already stored on the server.
- It does not prevent the company from keeping the conversation for safety monitoring or legal reasons.
- It may not apply to conversations you had before you changed the setting.
To actually remove stored data, you need to use your GDPR rights — explained below.
Your Three Core GDPR Rights, in Plain English
GDPR stands for General Data Protection Regulation. It is EU law that gives you real, enforceable control over your personal data. Here are the three rights most relevant to AI tools.
1. The Right to Access
You can ask any company: "What personal data do you hold about me?" This is Article 15 of GDPR. They must tell you within one month, and they must give you a copy in a usable format; for complex or numerous requests they can extend that by a further two months, but only if they tell you within the original month and explain why. This is called a Subject Access Request (SAR).
For an AI tool, this might include: your account details, your conversation history, and any inferences the company has drawn from your use.
2. The Right to Erasure (the "Right to Be Forgotten")
Under Article 17, you can ask a company to delete the personal data it holds about you, with the same one-month-plus-two-months timeline as above. This right is not absolute: Article 17(3) lets them refuse in limited circumstances — for example, if they are legally required to keep the data, or need it to establish or defend a legal claim — but they must explain why.
For AI tools, this typically means: deleting your account, your stored conversations, and any training data derived from your conversations (though this last part can be technically complicated, and companies may not be able to remove your influence from an already-trained model).
3. The Right to Object
Under Article 21, you can tell a company: "Stop using my data for this purpose." For AI training, this means objecting to your conversations being used to improve the model. The company must stop, unless they can show a compelling reason to continue.
In practice, many companies make it easier to use the privacy settings toggle than to go through a formal objection process — but both routes are available to you.
What If a Company Doesn't Respond?
If a company misses the deadline on a request to access, delete, or object, or you think their response falls short, you can complain to a supervisory authority. In the UK, that's the ICO (Information Commissioner's Office); in the EU, it's the national data protection authority for the country the company is established in, or where you live. The authority can investigate the complaint and order the company to fix the problem — but it does not settle disputes over compensation between you and the company, or pay damages on your behalf. If you believe you suffered actual harm and want compensation, that has to go through the courts.
Concrete Steps You Can Take Today
Here is a simple checklist. You do not need to do all of these — even one or two make a real difference.
Step 1 — Find the privacy settings. In ChatGPT, go to Settings → Data Controls. In other tools, look for Settings → Privacy or Help → Privacy Policy → Your Rights.
Step 2 — Turn off training. Toggle off any option that says "improve the model," "use conversations for training," or similar. Save.
Step 3 — Delete your conversation history. Most AI tools let you delete individual chats or all history. Deleting them from your view also removes them from the company's training pipeline going forward.
Step 4 — Send a deletion request if you want a clean slate. Use the company's privacy request form (usually in the Help Centre or Privacy page). State clearly: "I am exercising my right to erasure under GDPR. Please delete all personal data held about me, including conversation history."
Step 5 — Use a more private mode for sensitive topics. Some tools offer an "incognito" or "temporary chat" mode that does not save the conversation at all. Use this when discussing anything you would not want stored.
"I would like to ask a question about my personal situation but I want to keep it private. Is there a way to use you without saving this conversation?"
You can literally ask the AI this — it will tell you what modes or settings are available.
What to Watch Out For
Never paste medical, financial, or ID details. Even with training turned off, your text is stored on the company's servers during the session. A full name plus a medical condition plus a date of birth is exactly the kind of combination that makes personal data sensitive. Use general descriptions instead.
Screenshots and voice recordings are data too. If you share a photo or use a voice assistant, that image or audio goes to the server. Be just as careful with visual and audio input as you are with typed text.
"Free" tools and your data. When a service costs nothing, the company has to pay its bills somehow. For many AI tools, one answer is using what users share to make the product better — which they can then sell to businesses. This is not automatically bad, but it is worth being aware of.
Phishing and fake "data deletion" forms. You will occasionally see emails or messages claiming to help you delete your AI data. Always go directly to the official website — never click a link in an unexpected email. Legitimate GDPR requests go through the company's own privacy page.
Training off ≠ data gone. Turning off training is an important step, but it is not the same as asking for your data to be deleted. If you want a full clean slate, you need to submit a formal erasure request.
What to Try Next
Once you have sorted your privacy settings, the next step is understanding exactly what data these tools already hold about you — and how to see it. Our guide What Does AI Know About Me? walks through how to request a full data export from major AI services.
If you use ChatGPT specifically, the step-by-step walkthrough in ChatGPT Privacy Settings shows you every toggle in plain language.
And if you want to go further — opting out of training across multiple services at once — How to Opt Out of AI Training and Request Deletion of Your Data covers the full process.
Sources
- Regulation (EU) 2016/679 (GDPR) — full text — EUR-Lex, Art. 12 (deadlines), Art. 15 (access), Art. 17 (erasure), and Art. 21 (objection)
- Art. 17 GDPR – Right to erasure ('right to be forgotten') — GDPR-info.eu (readable version with commentary on the Art. 17(3) exceptions)
- Making a complaint — UK Information Commissioner's Office
- Right of access — UK Information Commissioner's Office



