ChatGPT, Gemini, and Claude can store personal details from conversations and reuse them in later answers. This matters if you rely on these services for work, job applications, research, or private questions. Recent cases also show that Artificial Intelligence (AI) can know too much about you, present false material convincingly, or accept nonsensical claims without objection.
Making stored data visible
ChatGPT, Google Gemini, and Claude all have a memory feature, meaning a store of selected information about you, according to a comparison of their memory functions. The services can incorporate these details into future answers to make their responses feel more personal and precise. However, talking frequently about your job, family, health, or finances also gives them correspondingly sensitive material.
Stored memories are not necessarily the same as a complete conversation history. The memory feature contains selected details that the service treats as relevant to later discussions. These may include facts you stated explicitly, such as your profession or interests, along with assumptions about your habits and how you use the chatbot.
In the reported test, a single prompt, meaning an instruction entered into the chatbot, was enough to ask ChatGPT, Gemini, and Claude what they had retained. ChatGPT listed interests in technology, AI, and gaming and inferred that the user treated it more as a research tool and sparring partner than as a source of simple factual answers. Such inferences are not verified facts: a guess about your age, job, or circumstances remains a guess even when presented in a tidy list.
A case involving Meta AI illustrated how uncomfortable the linking of personal content can become. The assistant asked a user to identify the child in a video, combined information from her posts with posts by relatives, and suggested further questions about her children’s ages and where the family lived. The user also said the assistant displayed a photo that she claimed to have deleted years earlier.
Meta responded that its system could only surface content the person making the query was already able to access. That statement does not resolve the apparent conflict concerning the allegedly deleted image. The company acknowledged that the suggested questions were inappropriate and said it was changing the suggestions.
Checking and deleting your data
The exact labels and menu paths may vary by service and product version. The basic process is still the same: first reveal what has been stored, review the list, and remove unwanted memories using the account’s available memory or data controls. You should then run the query again rather than relying only on the chatbot’s confirmation.
Step 1: Request your stored information
- Open a new conversation in the service whose memories you want to inspect.
- Ask the chatbot to list every detail it has stored about you.
- Tell it to include assumptions and to distinguish them clearly from facts you explicitly provided.
Step 2: Separate facts from inferences
- Pay particular attention to details about your work, family, health, finances, and location.
- Check which items you actually mentioned and which the chatbot inferred from your writing style or conversation topics.
- Treat the list as the system’s inventory, not as an objective description of you.
Step 3: Remove unwanted memories
- Open the account settings available for memory, personalization, or stored data.
- Delete individual sensitive entries or clear the offered memory store if you do not want personalization.
- Do not assume that deleting one chat automatically removes every separately retained memory; the supplied reports do not establish a uniform mechanism across the services.
Step 4: Verify the result
- Start a new conversation after deletion and repeat your request for stored information.
- Check whether the service continues to mention personal assumptions or use previous details in its answers.
- In the future, provide highly confidential information only when it is genuinely necessary for the task.
This type of request can only reveal what a service presents as retrievable memory. It is not independent technical proof that every piece of data has disappeared from all of the provider’s systems. The Meta case also suggests that visible, linked, and supposedly deleted content may not look like the same thing from a user’s perspective.
Verifying hallucinations consistently
A hallucination is a plausible-sounding AI output that is invented or factually wrong. Language models can present names, sources, quotations, and events with confidence even though their accuracy has not been reliably checked. Polished wording is therefore no substitute for evidence.
The consequences became unusually serious in an appeal involving a murder conviction in New Mexico. A lawyer submitted a ChatGPT-assisted brief that included fabricated witnesses, false police testimony, and other inaccurate claims. According to a report on the court’s decision, the New Mexico Supreme Court fined him $5,000 for failing to verify the factual claims and legal authorities.
A second account of the same case adds important details. Ars Technica reported that the lawyer fed a trial transcript into ChatGPT but did not verify the generated brief before filing it. The court held him in direct contempt, referred him to a disciplinary board, and noted that he had not informed his client about either the errors or his failure to check the document.
The standard is less dramatic in everyday work, but the principle is identical. If you ask AI to summarize meeting minutes, compare every name, decision, and deadline with the original record. When researching a presentation, locate each quotation, number, and claimed source in the underlying material; a fabricated reference does not become real because its formatting looks professional.
Recognizing manipulable bots
Not every problematic response is a classic hallucination. Some systems can be pushed into accepting a false premise through absurd or strategically phrased input. This becomes particularly risky when a bot evaluates people or contributes to decisions about them.
A satirical video about an automated job interview provides a clear example. The applicant responded to an AI avatar with a string of meaningless terms, including supposed experience with “raccoon protocols” and two gauze bandages. Instead of challenging the illogical answers, the bot incorporated them into the continuing interview and reacted approvingly, according to the report on the manipulable recruiting chatbot.
The video is satire, not a systematic assessment of every recruiting product. It nevertheless demonstrates a relevant failure pattern: a system optimized for fluent conversation may continue talking even after the factual basis has collapsed. If human resources teams use such bots for initial interviews or candidate screening, conversational fluency should not be mistaken for judgment.
Manipulation can also occur without deliberate intent. An applicant might exaggerate, a customer might build a request on a false assumption, or an internal document might contain contradictory details. A bot that politely accepts everything may then turn inconsistent material into a coherent narrative. Coherence is pleasant to read, but it is not a certificate of quality.
Pros and Cons of personalized AI
Pros:
- Less repetition – The chatbot can account for known preferences and work contexts in later conversations.
- More relevant responses – Stored details can help tailor suggestions to your tasks and interests.
- Continuity – For longer projects, you may not need to explain every starting point again in each conversation.
- A visible inventory – A direct request provides at least some insight into retrievable memories and inferred details.
Cons:
- Privacy exposure – Discussions about health, family, or finances can create a detailed personal context.
- Incorrect profiles – Inferred interests, habits, or age estimates may be wrong and distort later responses.
- Unclear deletion – A displayed memory, a chat history, and other linked content may not be the same thing from the user’s perspective.
- Misplaced trust – Personalized answers often feel especially relevant but can still be hallucinated or manipulated.
What this means for you and Switzerland
For beginners: Start by taking an inventory in the chatbot you use most often. Ask for stored facts and assumptions, remove unnecessary personal details, and check at least the names, numbers, and sources in any important response. A minor inaccuracy may only be inconvenient when you are polishing routine wording, but it carries far greater weight in health matters, job applications, contracts, or professional decisions.
For advanced users: Separate tasks by risk and establish a consistent review process. You can let AI prepare a draft, then compare every verifiable statement with the original material. For recruiting or other assessment systems, you can also test contradictory and obviously nonsensical inputs to see whether the bot identifies them or merely processes them elegantly.
In Switzerland, control extends beyond chat windows. The Zurich cantonal government has been asked to examine ways to prevent covert image and audio recording in locations such as pools, saunas, fitness centers, and childcare facilities, according to a report on smart glasses in public facilities. Smart glasses are wearable glasses with an integrated camera or microphone; the case illustrates how data collection can happen discreetly before the material is connected to digital services.
The canton of Bern is taking a tiered approach to government security. Its new Information and Cybersecurity Act establishes four protection levels for information and communications technology (ICT) resources, according to a description of Bern’s security rules. Higher levels require security and data protection plans, while cyberattacks must be reported within 24 hours and incidents involving personal data within 72 hours.
These cantonal examples do not directly regulate which memories ChatGPT, Gemini, or Claude retain. They do illustrate a useful principle: safeguards should reflect the sensitivity of the data and the potential consequences of an error. Drafting a harmless invitation requires less scrutiny than handling an employee file, medical history, or legal brief.
Personalized AI can save you work when you understand which information it uses and where its claims require verification. The greater risk lies not in every isolated error, but in the combination of extensive personal data, persuasive language, and missing oversight. It remains unclear how completely providers make stored or linked information transparent and remove it from their systems.
Sources
- Was ChatGPT, Gemini und Claude über dich wissen – und wie du es löschst – t3n, 2026-09-11
- Meta says it’s changing AI suggestions after posing invasive personal questions – The Verge, 2026-09-11
- Zürcher Regierung soll Smartbrillen unter die Lupe nehmen – Netzwoche, 2026-09-11
- Update: Berner Cybersicherheitsgesetz kommt im November – Netzwoche, 2026-09-11
- Lawyer fined $5K over AI-hallucinated witnesses in a murder case – The Verge, 2026-09-11
- ChatGPT-using lawyer punished for citing fake testimony from made-up witnesses – Ars Technica, 2026-09-11
- KI-Bewerbungsgespräche: Wenn der HR-Chatbot auf Waschbären-Protokolle hereinfällt – t3n, 2026-09-11


Image: Airam Dato-on via Pexels
