Your AI Assistant Knows More Than You Think: How to Protect Your Privacy on Muse, ChatGPT, Claude, Perplexity and More
By Ravinder Cheema, Clicks Dynasty · Published September 30, 2026 · About 8 minutes to read
Okay, we need to talk about the Muse thing.
This week a tech journalist opened Meta's new Muse AI app on his Mac, and it started talking about private iMessages he never gave it permission to read. When he asked how it knew, Muse said something about syncing "device notifications." Meta says that's flat-out impossible without three separate opt-ins. The internet is not convinced.
Whoever turns out to be right, the lesson is the same. AI apps are hungry for data, and most of us are feeding them way more than we realize. Your chats, your files, your screen, sometimes your whole inbox.
I'm not telling you to delete everything and move to a cabin. I use these tools every day, and so does our team. But I dug into what the big ones actually collect, and some of it surprised me. Here's what you need to know, plus the exact settings I changed on my own devices.
AI privacy by the numbers
Contents
1. The numbers are kind of wild
We're telling AI stuff we won't tell our own families, and most of us have no idea where it ends up.
Half of U.S. adults don't know their AI chats train the model
Share of respondents, DuckDuckGo survey of 1,944 U.S. adults, June 2026
It's not just Americans. Proton surveyed 4,014 people across the US, UK, France and Germany and found 66% have talked to a chatbot about something sensitive: money, mental health, relationships, sex. Only 11–20% say they really trust the companies holding that info.
And things are going wrong more often. Stanford's 2026 AI Index counted 362 documented AI incidents in 2025, up 55% from 233 the year before.
2. App by app: what you're actually signing up for
Meta Muse
Muse is an AI agent, not just a chatbot. It can hook into your Mac's Messages, files and more if you let it. The journalist's story suggests notification banners might be a side door. Meta denies it. My take: until this is settled, don't give Muse Full Disk Access, and turn off notification previews.
Meta AI (in Facebook, Instagram and WhatsApp)
Since December 16, 2025, Meta uses your chats with Meta AI to target ads. In the US there's no opt-out. Topics like health, religion and politics are supposedly excluded, and the EU, UK and South Korea are exempt. Assume anything you type to Meta AI helps sell you stuff.
ChatGPT
The good news: ChatGPT ranked #2 for privacy in Incogni's 2026 ranking, with the clearest opt-out instructions. The catch: it still trains on your chats by default. And in 2025, thousands of "shared" chats ended up in Google search because people ticked a "make discoverable" box. OpenAI killed that feature, but share links still exist.
Claude
In September 2025 Anthropic changed its rules: Free, Pro and Max users now choose whether their chats train the model. Say yes and chats can be kept for five years. Say no and it's 30 days. The pop-up had the toggle switched on, so check what you clicked.
Perplexity
The search chatbot itself sits in Incogni's middle tier, with an easy opt-out. Nice touch: switching off training doesn't wipe your chat history, which stays in your Library tab. The bigger worry is its Comet AI browser. In August 2025 Brave showed that a hidden instruction on a web page could trick Comet into leaking a user's emails and login codes. That's called prompt injection, and it's a risk for every AI browser and agent.
Google Gemini
By default Gemini keeps your chats for 18 months. Some get read by human reviewers, and those are kept for up to three years, even if you delete your history. Never paste anything into Gemini you wouldn't want a stranger to read.
Microsoft Copilot
Copilot landed in Incogni's highest-risk group, mostly because Microsoft's privacy policy is broad and hard to pin to AI specifically. It has two training toggles (text and voice), and you need to turn off both.
Grok
In August 2025, more than 370,000 Grok conversations turned up on Google. Every time someone hit "share," the link became searchable. Some had passwords and personal details in them. Grok also trains on public posts on X.
3. Cheat sheet: where to flip the switch
Most of these apps train on your chats unless you tell them not to. Here's where the off switch lives. The risk tier comes from Incogni's 2026 ranking of 13 AI platforms.
| App | Trains on your chats by default? | Where to turn it off | Incogni risk tier |
|---|---|---|---|
| ChatGPT | Yes | Settings → Data Controls → "Improve the model for everyone" | Lowest (#2) |
| Claude | You choose, but the toggle starts on | Settings → Privacy → "Help improve our AI models" | Middle |
| Perplexity | Yes | Account Settings → Preferences → turn off "AI data retention" | Middle |
| Grok | Yes | Settings and privacy → Privacy and safety → Grok & Third-Party Collaborators | Middle |
| Gemini | Yes, while Keep Activity is on | Settings → Activity → turn off "Keep Activity" | Highest |
| Copilot | Yes | Settings → Privacy → turn off both "Training on…" toggles | Highest |
| Meta AI | Yes, and it's used for ads | No opt-out in the US (EU and UK users can object) | Highest |
One thing nobody tells you: opting out only covers future chats. Anything already used for training stays there (Engadget). So do this today, not "someday." Menu names change often, so if you can't find one, search the app's help page for "training."
4. My 10-minute privacy checklist
This is exactly what I did on my own phone and laptop.
- Turn off training in every AI app you use (the table above has the paths).
- Use temporary or incognito chats for anything personal. ChatGPT, Claude and Gemini all have one.
- Never paste the dangerous stuff: passwords, bank or card numbers, Social Security or ID numbers, medical records, other people's private info.
- Swap real details for fake ones. "My friend Sam" works just as well as your coworker's full name.
- Stop using share links for personal chats, and delete old ones you've already made.
- Audit what AI apps can reach. On a Mac, go to System Settings → Privacy & Security and check Full Disk Access, Accessibility and Screen Recording. On a phone, check Settings → Privacy.
- Hide notification previews (System Settings → Notifications → Show previews → When Unlocked or Never). That shuts the side door from the Muse story.
- Be careful with AI browsers and agents. Don't let them run while you're logged into email or banking, and never let one act on a page you don't trust.
- Delete old chat history you don't need, and set auto-delete to the shortest option.
- Treat every chat like it could be read later. It can be kept for years, reviewed by humans, or subpoenaed. Only 25% of people know that last one.
Bottom line
AI tools are great. I'm not quitting them, and you don't have to either. Just remember the deal: you're paying with your data. Spend 10 minutes on the checklist above and you'll be ahead of most people.
If this helped, send it to the one friend who tells ChatGPT everything. You know who. And if you run a business that's figuring out how to show up in AI answers without cutting corners, take a look at our AI SEO services.
5. Frequently asked questions
Did Meta's Muse read private messages without permission?
Do AI chatbots train on my conversations?
Which AI app is the most private?
Does opting out delete my old chats from AI training?
What should I never share with an AI chatbot?
Sources: TechCrunch (Muse), DuckDuckGo, Proton, Stanford AI Index 2026, Incogni, Tom's Guide, Engadget, TechCrunch (Anthropic), Decrypt, Google Gemini Privacy Hub, Forbes.
Muse, Meta AI, ChatGPT, Claude, Perplexity, Gemini, Copilot and Grok are trademarks of their respective owners. Clicks Dynasty is an independent digital marketing agency and is not affiliated with or endorsed by any of these companies. Settings menus change often; check each app's help pages for the latest steps.
Related reading: Digital Marketing in the AI Era: 30 Questions Answered · AI SEO Guide 2026: Free Tools, Strategy and Agencies