AI Privacy Report Card
Issue dated: August 16, 2026 · Week 33, 2026 · Methodology v1.1 · Sources reviewed through: August 16, 2026
GPTAnon reviews major AI companies using the privacy practices they publicly document. Each company is evaluated using the same five weighted categories: data collection, training data use, opt-out options, transparency, and breach history.
Grading Categories
Data Collection (25%)
What the service collects by default: prompts, metadata, device and usage data.
Training Data Use (25%)
Whether your conversations are used to train models, and on which tiers.
Opt-Out Options (20%)
How real and reachable the opt-out controls are for a typical user.
Transparency (15%)
Quality and specificity of public privacy documentation and disclosures.
Breach History (15%)
Track record on security incidents and how they were handled.
This Week's Report
Anthropic — Overall Grade: B+
Anthropic provides some of the clearest consumer privacy documentation in the market. Claude users control model improvement, Incognito chats are excluded from training, and deleted chats are removed from back-end storage within 30 days. The tradeoff is that training opt-in, feedback, safety flags, legal obligations, and abuse prevention can produce much longer retention windows.
| Category | Grade | Notes |
|---|---|---|
| Data Collection | B | Consumer chats remain until deletion; deleted chats are removed from back-end storage within 30 days |
| Training Data Use | B+ | User-controlled model-improvement setting; Incognito chats are excluded |
| Opt-Out Options | A- | Training preferences can be changed at any time in Privacy Settings |
| Transparency | A- | Publishes specific deletion, training, feedback, and safety-retention windows |
| Breach History | A- | No major Claude consumer breach identified in this review; safety-retention exceptions remain |
Red flags: Model-improvement opt-in can retain de-identified data for up to 5 years; Policy-violation inputs and outputs may be retained up to 2 years; classification scores up to 7 years; Feedback-related data may be retained for 5 years; Legal and abuse-prevention exceptions can extend retention
Green flags: Claude Incognito chats are not used for model improvement; Deleted conversations are removed from back-end storage within 30 days; Consumer model-training preference is user controlled; Retention exceptions are documented in plain language
xAI — Overall Grade: B-
xAI now offers clearer controls than this report previously reflected. Grok users can disable model improvement or use Private Chat, and xAI says deleted or Private Chat conversations are generally removed within 30 days. Important caveats remain around authorized human review, feedback, signed-out use, safety exceptions, and optional personalization with X data.
| Category | Grade | Notes |
|---|---|---|
| Data Collection | C+ | Grok processes prompts, searches, responses, device/account data, and optional X personalization |
| Training Data Use | B- | Training can be disabled for new chats; Private Chat is excluded |
| Opt-Out Options | B | Controls are available on Grok.com and mobile; some signed-out users may lack an opt-out |
| Transparency | B | Consumer FAQ explains human review, training, deletion, and retention |
| Breach History | B- | No major Grok account-data breach confirmed in first-party sources reviewed |
Red flags: Limited authorized personnel may review conversations for model improvement, security, misuse, and legal compliance; Signed-out users in some regions may not have a training opt-out; Feedback can be used for training even after a general opt-out; Safety, security, legal, de-identified, or pseudonymized data may outlast deletion
Green flags: Private Chat conversations are not used for model training; Users can disable Improve the Model for new conversations; Deleted or Private Chat conversations are generally removed within 30 days; xAI says it does not sell data or share it for third-party marketing
OpenAI — Overall Grade: B-
OpenAI has substantially improved consumer controls. Users can disable model improvement, and Temporary Chats are excluded from training, visible history, and memory. These modes are not complete anonymity: normal history can remain after training is disabled, Temporary Chats may be held up to 30 days, and separate safety, memory, connected-tool, and legal rules still apply.
| Category | Grade | Notes |
|---|---|---|
| Data Collection | C+ | Prompts and account/device data are processed; history, memory, and connected tools add context |
| Training Data Use | B | Users can turn off Improve the model for everyone |
| Opt-Out Options | B+ | Training opt-out works signed-in and signed-out; Temporary Chat is available |
| Transparency | B | Data Controls explain training, Temporary Chat, history, and safety exceptions |
| Breach History | C | A 2023 bug exposed some chat titles and limited billing/account data; OpenAI published an incident report |
Red flags: Normal chats can remain in history when training is turned off; Temporary Chats may be retained for up to 30 days and reviewed for abuse monitoring; Memory and personalization are separate from model-training controls; Third-party GPT actions follow the recipient's privacy policy
Green flags: Training opt-out is available to signed-in and signed-out users; Temporary Chats are excluded from training, history, and memory; Training preference syncs across web and mobile; Business products provide additional data controls and no training by default
Google — Overall Grade: C
Google publishes unusually detailed Gemini privacy documentation, but the default data surface is broad. With Keep Activity on, chats may be saved for 18 months and used to improve services with human review. Temporary Chat or Keep Activity off reduces this: those chats are retained for 72 hours and are not used to train Google AI unless feedback is submitted. Reviewed chats can remain for up to three years.
| Category | Grade | Notes |
|---|---|---|
| Data Collection | D+ | Collects chats, uploads, device/app context, location, and connected-app data |
| Training Data Use | C+ | Keep Activity can enable model improvement and human review |
| Opt-Out Options | B- | Temporary Chat and Keep Activity off reduce training and visible history |
| Transparency | B+ | Detailed Privacy Hub documents retention, review, and connected-app behavior |
| Breach History | C+ | Wide connected-app surface increases exposure; no major consumer-chat breach confirmed in this review |
Red flags: Keep Activity saves chats for 18 months by default; Human reviewers may review a subset of chats; Reviewed chats and related data may be retained up to 3 years; Connected Apps can expose email, files, browser context, location, and device data
Green flags: Temporary Chats and chats with Keep Activity off are retained for 72 hours; Those chats are not used to train Google AI unless feedback is submitted; Users can change auto-delete to 3 months, 36 months, or indefinite and delete activity; The Privacy Hub clearly documents human-review and retention rules
Meta — Overall Grade: D+
Meta AI operates inside a much larger social, messaging, personalization, and advertising ecosystem. Meta says public adult content and AI interactions can be used to improve generative AI, with objection rights available in some regions. WhatsApp's ordinary personal messages remain end-to-end encrypted, but prompts intentionally shared with Meta AI are received and processed by Meta.
| Category | Grade | Notes |
|---|---|---|
| Data Collection | D- | Meta AI interactions join data collected across Meta products; prompts and related metadata are processed |
| Training Data Use | D | Meta says public adult content and AI interactions can improve generative AI |
| Opt-Out Options | C- | Objection rights exist in some regions; controls differ by product and location |
| Transparency | C | Meta publishes generative-AI privacy information, but product-specific rules are fragmented |
| Breach History | D- | Meta's broader platform history includes major incidents; no separate Meta AI breach confirmed in this review |
Red flags: AI interactions can be used to improve Meta's generative AI; Meta says AI interactions may personalize experiences and ads in some regions and products; Controls and objection rights vary by region; Prompts sent to third-party features may be governed by third-party policies
Green flags: Meta says ordinary personal WhatsApp messages remain end-to-end encrypted; Only messages mentioned to or shared with Meta AI are received by Meta AI in WhatsApp; Some users can object to future model-improvement use; Users can delete AI chats or request deletion of information shared with Meta AI
How Grades Are Assigned
Grades run from A (best) to F (worst). An A grade means the company offers strong, verifiable privacy protections and clear disclosure. An F means the company collects extensively, provides no meaningful opt-out, and buries disclosures. All grades are based on publicly documented policies and independently verifiable practices.
About GPTAnon's Own Practices
GPTAnon is not graded on this report card — the methodology covers model providers, not gateways. GPTAnon does not add your conversations to a saved server-side chat history. Prompt content is processed by the selected routing and model providers under their own privacy policies. See our privacy policy and technical overview for details.
Related Resources
Try AI chat with no saved history.
GPTAnon does not add conversations to a saved server-side chat history. GPTAnon account identity is not sent as part of the model request. GPTAnon still keeps the account and usage records needed to operate the service. Provider terms remain separate and are shown before you send.
Start chatting privately — it's free