AI Privacy Scorecard
How five AI tools handle your data. Scored, sourced, and honest.
Every claim below links to official documentation or court records. Where a company's own statements are the only source, that's noted. Where the law is unsettled, that's noted too. Ask Safely is included and graded by the same rules, including its gaps.
| Dimension | ChatGPT Free/Plus/Pro |
Claude Free/Pro |
Gemini Free/Plus/Pro |
Perplexity Free/Pro |
Ask Safely Essential/Expert |
|---|---|---|---|---|---|
| Training default | Poor On by default. Opt-out forward-only. | Weak Opt-out, not opt-in. Toggle pre-set to on at the Oct 2025 deadline. Safety carve-out remains. | Poor On by default. Opt-out forward-only. Once in the training corpus, data can't be removed. | Poor On by default. July 2026 policy removed written opt-out description while keeping the toggle. | Strong Never trains. Bedrock contract prohibits it. No toggle needed. |
| Retention after deletion | Adequate 30 days post-deletion. NYT case forced preservation of "deleted" chats for months in 2025. | Adequate 30 days if training off. Up to 5 years de-identified if on. Safety-flagged content: up to 2 years. | Poor Up to 18 months default. Reviewed conversations: up to 3 years. Activity off: still 72 hours. | Poor July 2026 policy replaced "30 days" with "as long as reasonably necessary." No timeline. | Strong User-chosen timer: 8h / 7d / 30d. Database TTL index. Gone when the timer expires. |
| Human review | Adequate Not routine for consumer, but feedback conversations may be reviewed. TaskUS is an annotation subprocessor. | Adequate Not routine, but safety-flagged content is reviewed by Trust & Safety. Access logged and limited. | Poor Routine random sampling. Google says human reviewers "read, annotate, and process" conversations. Warns users not to enter confidential info. | Adequate Not explicitly disclosed at the routine level. SOC 2 Type II suggests formal access controls. | Strong No human review of conversations. |
| Encryption | Adequate AES-256 at rest, TLS 1.2+ in transit. Infrastructure-level, not per-user. | Adequate AES-256 at rest, TLS 1.2+ in transit. Infrastructure-level. Customer-managed keys on Enterprise only. | Adequate AES-256 (storage layer), TLS in transit. Standard Google Cloud encryption. | Adequate SOC 2 Type II attested. Specifics not publicly detailed. | Strong AES-256-GCM with per-user data encryption keys. KMS envelope encryption. Memory system fail-closed. |
| Advertising identifiers | Adequate No IDFA ad tracking. But privacy label declares Health, Location, Contact Info, Identifiers linked to identity. | Adequate No ad trackers. But privacy label declares Location, Contact Info, Identifiers, Usage Data linked to identity. | Weak No direct ad tracking in Gemini, but lives inside a Google Account with Ads Personalization across all Google services. | Poor 2026 lawsuit alleged Meta Pixel, Google Ads, DoubleClick embedded. Perplexity denied. Case dismissed without resolution. | Strong No IDFA/GAID. No ATT prompt. No ad identifiers. No location, contacts, or photos. |
| Memory controls | Weak Memory on by default. Visible summary "will not include everything ChatGPT remembers." "Dreaming V3" updates memory autonomously. | Adequate On by default since March 2026. Extractive, categorized. View/edit/delete individual entries. No hidden layer disclosed. | Adequate "Saved Info" (manual) + "Personal context" (automatic, on by default). Can connect Gmail, Calendar, Drive, Photos, YouTube, Search. | Weak History retained for personalization. Limited public documentation on granular user controls. | Strong Off by default. Opt-in per-fact. Every entry visible, editable, deletable. Declined facts hard-deleted. No autonomous synthesis. |
| Cross-product data use | Adequate GPT Actions can send data to third parties. Apple Intelligence integration governed by Apple's terms. No cross-product ecosystem. | Adequate MCP connectors can access external data. Connected data excluded from training. No broader product ecosystem. | Poor Gemini can access Gmail, Calendar, Drive, Photos, YouTube, Search, Contacts. Google warns connected data "may relate to sensitive topics." | Weak Comet browser history collected since July 2026. Email/calendar access if Email Assistant connected. | Strong Isolated. No external account connections. No cross-product data flow. |
| Legal discoverability | Poor No legal privilege. Altman: "we could be required to produce that." NYT case: 20M logs ordered produced. | Adequate 30-day retention limits exposure window. No privilege. Case law is mixed on AI log protection. | Poor Up to 3-year retention of reviewed conversations creates a long discoverability window. No privilege. | Poor Indefinite retention under current policy language. No privilege. No documented litigation carve-out for consumer tiers. | Strong Can't produce what it doesn't keep. After the timer, there is nothing to subpoena. |
| SOC 2 / compliance | Adequate SOC 2 Type II for Enterprise/Business/API. Not in scope for Free/Plus/Pro. ISO 27001, 42001, PCI-DSS. | Adequate SOC 2 Type I & II for API/Team/Enterprise. ISO 27001, 42001. HIPAA BAA available. | Strong SOC 1/2/3, ISO 27001, 42001, FedRAMP High, HITRUST, PCI-DSS v4.0. Broadest compliance footprint. | Adequate SOC 2 Type II. HIPAA gap assessment. | Poor SOC 2 expected early 2027. Not yet certified. No BAA. |
| Breach history | None disclosed No public data breach of conversation content. A March 2023 bug briefly exposed chat titles and payment info; patched same day. | None disclosed | None disclosed | None disclosed | None disclosed |
How we scored this
Graduated, not binary. "Trains by default with an opt-out" is worse than "never trains" but better than "trains with no opt-out and a disappearing policy." Pass/fail collapses these real differences.
Weighted by what consumers actually fear. Training default, retention, human review, and legal discoverability carry the most weight because they rank highest in consumer privacy surveys (Malwarebytes: 90% concerned about AI using data without consent; Edelman: only 32% of Americans trust AI).
Source confidence matters. Every claim is tagged:
- Verified: traced to official documentation, privacy policy, or court record.
- Self-reported: vendor claim without independent audit. Ask Safely's own claims fall here.
- Ambiguous / changed recently: conflicting sources or a policy that changed in the last 12 months.
We graded ourselves by the same rules. Ask Safely scores "Poor" on SOC 2 because we don't have it. That's the fact. We expect it early 2027.
Enterprise tiers are different. ChatGPT Enterprise, Claude Team/Enterprise, Gemini Workspace, and Perplexity Enterprise all have stronger privacy terms (no training, admin controls, DPAs, in some cases BAAs). If your employer provides one of these, the consumer scores above don't apply to you. The scorecard grades the product most people actually use: the free or personal paid tier.
Law is unsettled. Legal discoverability scored "Poor" for products with long retention and no privilege, and "Strong" for Ask Safely's auto-delete architecture. But courts are still deciding whether AI chat logs qualify as work product in some circumstances. Two 2026 cases found protection may apply; others found it doesn't. No product, including Ask Safely, can guarantee legal privilege. We can only control how long data exists to be subpoenaed.
Scores go stale. AI privacy policies changed four times across these five products in the last twelve months alone. Every cell shows a "last verified" date. If you notice something outdated, email us and we'll update it the same day.
What this means
Three of the five products train on your conversations by default on their consumer tiers. All four competitors retain your data for at least 30 days after you delete it. One lets human reviewers read your chats and keeps the reviewed versions for three years. One removed its deletion timeline from its privacy policy in July 2026.
Ask Safely is the only product in this comparison that auto-deletes conversations on a user-chosen timer, never trains on user data at any tier, uses per-user encryption keys, and has no human review pipeline.
Ask Safely also doesn't have SOC 2 yet, doesn't offer a BAA, and has fewer than a thousand users. If those matter to your decision, they should.
Every product in this table is usable. The question is what you're comfortable leaving on someone else's servers, and for how long.