ChatGPT, Claude, and other Artificial Intelligence (AI) services can build a fairly detailed picture of your interests, habits, and concerns from conversations. That applies to private health questions as well as workplace documents and internal processes. A new tool from Swiss provider Proton is designed to show what could be inferred from exported chat histories.
What traces do you leave in a chatbot?
A single request often appears harmless. Across many conversations, however, details about your diet, hobbies, work, and health can reinforce one another. Someone who regularly describes symptoms, requests meal plans, and asks about medication provides far more context than someone asking one isolated question.
A Bitkom survey cited in the main report about Proton’s AI Paper Trail illustrates how common sensitive use has become. The survey covered 1,003 people in Germany age 16 and older. Among respondents who use AI, 34 percent consult chatbots about health questions, while 43 percent of all respondents worry that AI providers may not keep personal data safe.
According to the report, OpenAI and Anthropic say they do not use customer data to build advertising profiles. Depending on the settings, however, prompts may be used for model training, meaning the further improvement of an AI model. Stored information could also reach unauthorized third parties in a successful hacker attack.
The central issue is therefore not simply whether you enter your name. A combination of indirect clues may also be revealing: your profession, a rare medical condition, a specific project, and recurring appointments can form a recognizable pattern. A provider does not need to create a conventional advertising profile for stored conversations to offer a deep view into your life.
What does Proton’s AI Paper Trail show?
AI Paper Trail is intended to analyze your chat history and summarize what ChatGPT or Claude might have learned about you. The tool comes from Proton, a provider based in Switzerland, and the report says it supports only those two chatbots. Other AI services cannot currently be examined with it.
To run the analysis, you first have to request a copy of your data from the relevant service. The export may be especially informative for beginners because it brings many separate conversations together in one place. The supplied source text does not specify which languages AI Paper Trail supports or how Proton processes uploaded exports.
Step 1: Export your ChatGPT data
- Open the settings through your ChatGPT profile.
- Select the section for data controls.
- Use the data export function to request your export.
Step 2: Export your Claude data
- Open the settings in Claude.
- Go to the privacy section.
- Select the option to export your data.
This type of analysis is better understood as a personal data check than a complete security audit. It can identify subjects and details in your conversations, but it does not necessarily reveal how each provider handles every piece of information internally. The tool’s findings have not been independently verified in the supplied sources.
The export itself may contain exactly the information you are trying to protect. Before transferring it to another tool, you should review what that service says about processing, storage, and deletion. Proton’s Swiss base gives users in Switzerland a direct local connection, but it does not remove the need to assess the specific service.
Why are privacy promises not enough?
AI privacy has several layers. Your prompts are only one part; storage by the provider, use in training, the detectability of generated text, and possible inferences from a trained model also matter. A promise about advertising profiles therefore does not answer every other privacy question.
Anthropic is planning a change for corporate customers using its powerful Mythos and Fable models. Since June, all customer data from these models has been retained for 30 days on Anthropic’s servers to help detect new cyberattacks, according to the report on Anthropic’s storage plans. The 30-day period is expected to remain, but the data would be held in the customer’s cloud rather than by Anthropic.
The system is reportedly being developed with more than 100 customers in regulated industries and is due in the fall. Anthropic itself acknowledged that the current rule is unpopular and poses a business risk. The planned approach could give companies greater data sovereignty, meaning more control over where their information is stored, but the change has not yet been implemented or independently assessed in operation.
A separate case demonstrates the value of authentic communication for AI training. Google bought a package from the Spirit Airlines bankruptcy for $10 million that included about 100 million emails and 500 million Microsoft Teams conversations. According to the report on the Spirit data set, another company is expected to remove all personally identifiable information before transfer, and Google says the material could improve its products and AI models.
The purchase does not involve ordinary consumer chatbot histories, but it makes the economic value of real workplace communication visible. Such material can reflect actual business processes, which makes it attractive for training. The practical lesson for your job is straightforward: internal emails, Teams conversations, pricing information, and project documents should not be pasted into a public chatbot without prior review.
Medical information is particularly sensitive. Researchers from the Technical University of Munich, Imperial College London, and the Hasso Plattner Institute were able to associate certain patients with models with nearly 100 percent probability in specific data sets, according to a report on medical AI models. The finding applies only to particular cases, according to the source, but it shows that removing obvious identifiers does not eliminate every risk.
Generated text can carry traces as well. Anthropic has added an invisible marker to Claude that is intended to make AI-generated text easier to identify, according to a report on Claude’s invisible watermark. The measure is meant to address European Union transparency requirements, but it has unsettled users who do not want their AI use disclosed.
Examples in the report include students asking Claude to reorder paragraphs, journalists summarizing a 200-page transcript, and writers searching for synonyms during writer’s block. These tasks do not necessarily involve secret information. They show that data privacy, confidentiality, and the later detectability of AI assistance are separate issues.
What are the pros and cons of chatbot analysis?
Pros:
- Overview – A combined analysis can reveal which personal subjects have accumulated across many conversations.
- Awareness – Specific findings are often easier to understand than general warnings about data collection.
- Control – A data export gives you an opportunity to inspect your stored conversations yourself.
- Better habits – Recognized patterns can help you make future prompts shorter and less personally identifiable.
Cons:
- Additional disclosure – An external analysis may require you to send a large and sensitive export to another service.
- Limited coverage – AI Paper Trail supports only ChatGPT and Claude, according to the report.
- No complete internal view – Chat analysis shows content, but not every storage and training process used by the provider.
- Snapshot in time – Settings, retention rules, and features may change, as Anthropic’s planned move to customer-controlled cloud storage demonstrates.
How can you protect sensitive data in daily use?
If you are a beginner, start by reviewing your previous chats and identifying recurring sensitive subjects. Next, check the data and training settings of the service you use, and request an export if you need a broader overview. For new requests, provide only the details that are genuinely necessary to receive a useful response.
For a health question, you could describe symptoms in general terms without including names, a birth date, an address, or specific treatment records. A chatbot may help organize questions for a medical appointment, but the report on medical models shows that health data carries particular inference risks. An AI response also does not replace medical advice.
The same principle applies to internal workplace communication. If you want to summarize a long transcript or rearrange a paragraph, remove names, customer information, unpublished figures, and other unique details whenever the task permits. Before using confidential emails or Teams histories, your organization should establish whether the chosen service and its retention rules are approved for that material.
More advanced users can divide their work into risk categories. Routine wording tasks belong in a different category from medical records, confidential business documents, or communication containing personal data. It is also useful to compare exported data, current settings, and the provider’s retention terms at regular intervals.
For organizations, the technical environment is a major factor. Anthropic’s announced move to customer-controlled cloud storage could provide regulated businesses with more control, while ordinary consumer chatbot use does not automatically offer that option. A business product is not a blanket guarantee either; its retention period, storage location, and access rules still have to suit the specific use case.
AI Paper Trail may provide a useful view of the digital trail left by your chatbot conversations, but it is limited to two services and introduces another processing step. The greatest risks arise when many personal clues accumulate or when especially sensitive health and corporate information is involved. It remains unclear how reliably external analysis tools identify every possible inference and how their own data flows are arranged.
Sources
- Von Ernährung bis Hobbys: Tool analysiert, was KI-Chatbots über dich wissen – t3n, 2026-08-23
- Claude-Wasserzeichen sorgt für Aufruhr: Nutzer fürchten um ihre KI-Nutzung – t3n, 2026-08-23
- Anthropic-Pläne für Mythos-Modelle: Datenspeicherung wandert in die Kundencloud – THE DECODER, 2026-08-21
- Firmendaten für KI-Training: Google kauft Mails einer Pleite-Airline – t3n, 2026-08-22
- KI in der Medizin: Hohes Datenschutzrisiko für bestimmte Personengruppen entdeckt – MIT Technology Review, 2026-08-21


