Asking ChatGPT has become routine for many people, whether it’s for a quick fact, personal advice, or even sharing sensitive information.
Because these tools feel conversational, it’s easy to forget they aren’t as private as they seem.
While AI can sometimes spot sensitive information, it can’t always tell what matters most in context—especially if you don’t treat it as private.
Instead of looking up answers, it generates responses based on patterns it has learnt between words, topics and intent.
A photograph of a face is personal data because it can help identify someone.
Asking ChatGPT has become routine for many people, whether it’s for a quick fact, personal advice, or even sharing sensitive information. Because these tools feel conversational, it’s easy to forget they aren’t as private as they seem.
Christina Pöpper, a cybersecurity expert at NYU Abu Dhabi, explains that there are four main types of data involved: what you type in, what the system figures out from your input, the metadata about your session, and the responses or files that get saved.
That data begins with the text users intentionally provide. This can include personal details such as addresses, phone numbers or medical information. While AI can sometimes spot sensitive information, it can’t always tell what matters most in context—especially if you don’t treat it as private. ChatGPT’s privacy policy is clear: don’t enter anything you wouldn’t want someone else to see or use.
What Data Do AI Chatbots Collect?
When you type something in, the system breaks your text into small pieces and runs it through a model trained on huge amounts of data. Instead of looking up answers, it generates responses based on patterns it has learnt between words, topics and intent.
Images introduce another layer. A photograph of a face is personal data because it can help identify someone. Depending on the file and service, an uploaded image may also contain metadata such as when it was taken, the device used and its location. Uploading a selfie does not automatically mean it will be stolen or turned into a deepfake, but it places another copy of the image in the hands of another company, under that company’s retention and training rules.
If you use these tools often, your prompts can start to form a pattern. Even without your name, your questions and topics can reveal your interests, habits or even your job, just by what you ask and how you ask it.