A step-by-step breakdown of what happens to your prompts after you type them into ChatGPT or Claude, illustrated through the Navier–Stokes controversy.
Adapted from @rubenhassid# Claude & ChatGPT read your chats: Tristan Buckmaster paid for his own ChatGPT ‘Codex’ subscription. He’s a mathematician at NYU. For a year, he and Levent Alpöge (who works at Anthropic, but did this on his own time) went after Navier–Stokes, a Millennium Prize problem. There are seven. Solve any of them and the Clay Institute hands you a million dollars. Grigori Perelman did it in 2003. Nobody has since. On August 15, they had their result using Codex. On September 1, OpenAI heard a rumor that someone had cracked it. It pointed ten thousand agents at the problem. 88 hours later, OpenAI had cracked it too. Buckmaster got on a call and asked the only question that mattered. Had the model been trained on his sessions? Meaning, did OpenAI read his chats to then solve the problem before him? No, OpenAI’s research chief said. No human opened the chats. No agent looked at his data. Then came the sentence I have read twenty times. Does OpenAI use de-identified user data to improve ChatGPT and Codex? “Yes. And so does every LLM company,” answers OpenAI. This includes you. Whatever you typed into ChatGPT or Claude or Gemini this week is stored somewhere, and a model will learn from it. What happens when we type a prompt? Who has access to it, and how? Let’s follow the ‘Life of a Prompt’. Skip to ‘2. How to set up your AI’ if you just want the instructions. # 1. The Life of a Prompt. It is 3 pm. You upload a client contract into ChatGPT or Claude (it does not matter for the rest of the article, so let’s say Claude). And you type “summarize the risks for me.” The prompt will go through 9 stops. ## Stop 1. It leaves your laptop locked. You type a prompt into Claude. The prompt does not stay on your computer. It travels through the internet to the servers of Anthropic. Only Anthropic has the key. When your prompt arrives at their servers, they unlock it. This is the only stop where your prompt is private. ## Stop 2. It becomes a record. Your prompt is now a row in a database. Your account, a timestamp, the contract. This is true on Free, Plus, Pro, Max, Team, Enterprise. Every plan. ## Stop 3. The model answers. And forgets. The model is frozen. It reads your prompt, writes a reply, and moves on. It does not file your chat anywhere inside itself. And this is the biggest misconception of AI: people think that the more you prompt it, the more other users have access to your chats. Anthropic puts it well: models “do not store text like a database” and “do not have access to or pull from the original training data once the models have been trained.” Think of a cookbook, not a group chat. So the question “does another user see my chat?” is almost always no. But it is not the same as “nobody keeps my chat.” ## Stop 4. A safety scanner reads it. Automated classifiers check every conversation for abuse. Weapons, child safety, fraud, self-harm, building biological weapons. Anthropic keeps flagged chats “for up to 2 years” and the safety scores “for up to 7 years.” ## Stop 5. A human may read a sample. Safety teams, and at some companies, outside contractors, read a subset of conversations. To check the classifiers. To investigate abuse. To rate answers. And if you leave a thumb up/down on your answer, it will be used to train their models. So do not rate a chat you would not want a stranger to read. ## Stop 6. It sits in memory. - Your history is a database of your chats. - Memory is a smaller database of facts the model wrote down about you. - Backups are copies of both. In 2023, the New York Times sued OpenAI. The Times says ChatGPT learned from its articles and sometimes repeats them back to users. To prove it, the Times’ lawyers needed to see real conversations. Not OpenAI’s. Yours. So in May 2025, Judge Ona Wang told OpenAI to stop deleting chats. Every ChatGPT log had to be kept, including the ones users had already deleted, in case the Times needed them as evidence. Then she told OpenAI to hand over 20 million consumer chats, with names stripped out, to the Times’ lawyers. ## Stop 7. You delete it. You can delete a chat. Delete hides the chat from you immediately. OpenAI then schedules it for “permanent deletion from OpenAI systems within 30 days, unless: The chat has already been de-identified and disassociated from you, or OpenAI must retain it longer for security or legal obligations.” If your chat was already copied into the training pile, stripped of your name, deleting the original does nothing to the copy. Probably what happened to our mathematicians. ## Stop 8. Only if the toggle is on. You can turn on or off a “data training” toggle. ChatGPT. On by default. You can turn it off. Claude. On by default. You can turn it off. There is still no public case of a stranger pulling a specific person’s unique chat out of a later model. What is possible, and what OpenAI admitted it cannot rule out, is something else. Your work makes the next model better at your work: “De-identification may remove a name; it does not remove the intellectual content of a mathematical idea.” ## Stop 9. The side doors. This is where it gets really tricky now. Share. A share link is a web page. OpenAI’s said: “Shared link pages are not intended for search-engine indexing, but this does not make a link private.” In July 2025, Google indexed nearly 100,000 shared ChatGPT conversations. In July 2026 it was Claude’s turn: shared chats and Artifacts, found with one search operator, including medical records and children’s data. Share is publish. Extensions. In December 2025, two Chrome extensions with more than 900,000 combined downloads were caught stealing ChatGPT and DeepSeek conversations. So be careful which Chrome extension you use. Incognito mode. Both ChatGPT and Claude have incognito mode. But on a Team or Enterprise plan, the workspace owns the data. Anthropic: “Incognito chats are included in organizational data exports available to account Owners.” Incognito hides the chat from your sidebar. Not from your boss. The state. Warrants are rare. OpenAI received 75 requests for chat content in the second half of 2025 and disclosed in 62 cases. Anthropic received 2. # 2. How to set up your AI. For maximum safety & privacy: 1. Mostly use a Business tier (min. 2 seats). 1. Toggle off Data training in your settings. 1. Never use the thumbs up/down on any chats. 1. Never share a link to a personal account chat (not business). 1. Use Temporary Chat / Incognito for anything personal (still kept 30 days for safety, never trained). 1. Turn off Memory (it is a second file on you, and it trains unless the toggle is off). 1. Delete the share links you already created (Settings → Privacy → Shared Chats in Claude; Settings → Data Controls → Shared Links in ChatGPT). 1. If you use Codex, turn off the second switch in Codex Settings (training on full environments). The ChatGPT toggle does not reach it. 1. Never install a “ChatGPT sidebar” browser extension. 1. Real secrets (health, legal, client work, unreleased IP) never go in a personal account at all. Business, API, or nowhere. Using AI can feel daunting: you don’t want to make a mistake, and no one gave you proper training. It’s crazy how everyone is using it, and no one cared to show the very basics. They seem to have figured it out. They haven’t. So I sat down with my team to make you go from zero to mastering most of it in less than an hour. You’ll leave with a prompt that works the first time, a way to check the answer, and how to upskill on your own (yes, we are replacing ourselves too). Can’t make it live? You get the recording. Either way, you get the session. Your seat at the live session is waiting at how-to-ai.guide. # A message from the author, Ruben. This article exists because 95,000+ people decided AI is too important to leave aside. Not only that, but they shared it around them. They understand they are the sum of the 5 people around them. So better have them using AI. If this helped you — or if it’ll help someone you know — forward it to them. That’s how this grew. Just readers like you sending it to people like them. And if you're new here, follow me on X →@rubenhassid (also free!) (https://x.com/@rubenhassid)