Rankings · AI Assistants

Which AI can you trust with what you type?

Every consumer assistant, judged on privacy alone — what the company does with what you type, on its normal setting. Start with the one question that splits them, then read the full table. New here? The issue explainer covers why this matters.

A ground rule for this page: we rank these tools on privacy only — what each company does with what you type. An institutional deal doesn't count here. (Pitt's enterprise agreement with Anthropic is real and worth using, but that's a campus thing, not a point in Claude's favor on the open market.)

Set the deals aside and most consumer AI lands in the same place. Paying $20 a month doesn't fix it: personal Plus and Pro plans usually still train on you. The tiers that don't are enterprise/education accounts (contractually excluded) and models you run yourself (nothing leaves your device).

The field

Where does your prompt actually go?

One question splits every AI apart. If what you type never leaves your device, privacy is simply a fact. The moment it reaches a company, you're left with a promise — or, at best, a promise you can check. And once it's with a company, the law protects it far less than what stays on your device — that's the third-party doctrine.

Show
ServiceSees who you areTrains by defaultOpt-outAdsRetentionJurisdiction
On your deviceThe model runs on your machine — nothing is sent, so nothing else applies.
Janlocal · open sourceNo
Ollamalocal runnerNo
llama.cpplocal engineNo
GPT4AllNomic · localNo
LM Studiolocal appNo
Open WebUIself-hosted UINo
Odysseusself-hosted workspaceNo
VerifiableA secure enclave lets you cryptographically confirm the company can’t read your prompt.
Tinfoil15secure enclave · USNoNoNoneUS · enclave
Apple PCC14Apple · enclaveNoNoNoneUS · enclave
Brave Leo (TEE)13Brave · NEAR AINoNoNoneUS · enclave
Doesn’t see youAn anonymizing proxy strips your identity before the model ever sees the prompt.
Duck.ai12DuckDuckGo · USProxied12NoNoLocal / 30 dUS
Kagi Assistant11Kagi · USProxied11NoNo~1 dayUS
Brave Leo13Brave · USProxied13NoNoNone / 30 dUS
Sees you, won’t trainTied to your account, but pledged not to train — under EU or Swiss law.
Proton Lumo9Proton · SwitzerlandYesNoNoNoneEU / Switzerland
Infomaniak Euria10Infomaniak · SwitzerlandYesNoNoNot statedSwitzerland
Trains by default — you can opt outMainstream assistants: training is on until you find the toggle.
Claude2Anthropic · USYesYesYesNo30 days / 5 yrUS
ChatGPT1OpenAI · USYesYesYesNo30 daysUS
Perplexity6Perplexity · USYesYesYesNoUntil you deleteUS
Grok5xAI · USYesYesYesNo30 daysUS
Mistral Le Chat8Mistral · FranceYesYesYesNoUntil you deleteEU · France
Gemini3Google · USYesYesYesNo1818 mo / 3 yrUS
Trains, and feeds ad profilesSame as above, wired into an advertising system.
Copilot4Microsoft · USYesYesYesYes418 monthsUS
Meta AI7Meta · USYesYesNoYes7IndefiniteUS
Trains, no opt-out, foreign lawConsumer Chinese assistants, under China’s security laws.
Eight Chinese assistants17DeepSeekQwenErnieDoubaoHunyuanGLMKimiYiYesYesNoNoIndefiniteChina · Beijing

No services match that filter.

How to read this. Judged on privacy alone, on each service’s ordinary consumer setting — a pitt.edu login, or any enterprise or education account, is usually far more private than what’s shown here. Sees who you are — whether the service can tie what you type to your identity: No (nothing leaves, or an enclave it cannot read), Proxied (an anonymizing relay hides you from the model host), or Yes. Trains by default is what happens if you change nothing; Opt-out is whether you can turn training off. Ads flags a service wired into an advertising profile. Retention is how long what you type is kept; two values mean default / exception, so Claude’s “30 days / 5 yr” is 30 days if you opt out of training and five years if you don’t. Jurisdiction is whose law can compel the data. A dash (—) marks a question that doesn’t apply because nothing leaves your device. The eight Chinese assistants are grouped: under China’s National Intelligence, Cybersecurity, and Data Security laws their consumer defaults and reach are effectively identical. Each service links to its source below. The Sees who you are and Ads columns are read from that same per-service source; the notable calls — “Proxied,” and which services feed ad profiles — carry their own reference.Last reviewed July 12, 2026 — terms and policies change often; verify current details before relying on this. General information, not legal, financial, or tax advice.

Sources & notes

Every service above carries a number linking to its source here. On-device tools (Jan, Ollama, llama.cpp, GPT4All, LM Studio, Open WebUI, Odysseus) run the model on your own machine; nothing is sent to a provider, so training, review, retention, and jurisdiction don't apply — the dashes in those rows are structural, not gaps in our research. Consumer defaults are shown; enterprise, education, and API tiers are typically far more private.

  1. OpenAI · ChatGPT — consumer chats (Free, Plus, Pro) train the model unless you turn off “Improve the model for everyone” in Settings → Data Controls; deleted chats and Temporary Chats are purged within 30 days, and staff and vetted contractors may review conversations for safety and model improvement. openai.com
  2. Anthropic · Claude — since its 2025 consumer-terms change, Free/Pro/Max chats train Claude unless you switch off “Help improve Claude”; retention is 30 days if off and up to five years if on, only safety-flagged chats are human-reviewed, and Claude is ad-free with no data sold. anthropic.com
  3. Google · Gemini — Gemini Apps Activity is on by default and used to improve models with routine human review; turning it off stops both. Default retention is 18 months (72 hours even when off), but conversations seen by human reviewers are kept up to three years. support.google.com
  4. Microsoft · Copilot (personal account) — consumer Copilot trains on your conversation activity unless you opt out, some chats get automated and human review, history is kept 18 months, and it is tied to Microsoft's advertising ecosystem. This is the consumer product at copilot.microsoft.com, not Microsoft 365 Copilot Chat on a work or school account (see On Campus). support.microsoft.com
  5. xAI · Grok — on grok.com, conversations train Grok by default with an opt-out in Settings → Data Controls; staff may review chats for safety regardless of that setting, and deleted chats are removed within about 30 days. x.ai
  6. Perplexity — “AI Data Retention” is on by default for Free, Pro, and Max and can be turned off in Settings; chats are kept until you delete them, and deleting your account purges data within 30 days. perplexity.ai
  7. Meta · Meta AI — interactions are used to train Meta's models and there is no simple toggle; users can only file an objection request that Meta reviews, and the data is tied to your Meta profile and ad systems. cloaked.com
  8. Mistral · Le Chat — free and consumer chats train Mistral's models by default with an opt-out under Data & Account Controls → Privacy; conversations are kept until you delete the chat or your account; the company is French and operates under the GDPR. legal.mistral.ai
  9. Proton · Lumo — no server-side logs and no training; saved chat history is zero-access encrypted so only you can open it, on European infrastructure under Swiss law. proton.me
  10. Infomaniak · Euria — a Swiss-hosted assistant that pledges never to use your exchanges for training and keeps data in Switzerland under the GDPR and Swiss law; protection is contractual rather than end-to-end encrypted, so Infomaniak can technically access chats. infomaniak.com
  11. Kagi · Assistant — does not train on your conversations, does not pass your identity to the model providers, and acts as an anonymous proxy; threads are deleted after about a day by default. wysor.io
  12. DuckDuckGo · Duck.ai — strips your IP and identifying metadata before forwarding your prompt; provider contracts forbid training and cap retention at 30 days, and your chat history stays in your browser. how2shout.com
  13. Brave · Leo — requests are routed through an anonymizing proxy, not stored on Brave's servers, and not used for training (a provider such as Anthropic holds queries about 30 days); the TEE option adds a verifiable secure enclave. brave.com
  14. Apple · Private Cloud Compute — stateless computation that retains nothing after a request, with no privileged access and verifiable transparency that outside researchers can check. security.apple.com
  15. Tinfoil — runs models inside attested secure enclaves, so prompts and completions are never logged or accessible to Tinfoil, its cloud providers, or subprocessors, and clients cryptographically verify the code on every connection. tinfoil.sh
  16. DeepSeek — trains on inputs by default with no meaningful opt-out; data is stored on servers in China and kept as long as your account exists, with no fixed deletion schedule. deepseek.com
  17. Chinese providers · jurisdiction — DeepSeek, Qwen, Ernie, Doubao, Hunyuan, GLM, Kimi, and Yi operate under China's National Intelligence Law (2017), Cybersecurity Law, and Data Security Law, which can compel disclosure to authorities; consumer versions generally train on inputs and moderate content, and individual retention windows are often unpublished. proton.me
  18. Google · Gemini and ads — Google states that data from connected Google apps can personalize ads based on your settings, but that your Gemini app chats themselves are not used to show you ads. cape.co

The spectrum

Everyday to airtight

Same shape as the rest of our Tools: start where you are, move up as the stakes rise.

Everyday

Cloud AI, tightened

Keep using the big tools, but turn training off in settings, use temporary/incognito chats for anything sensitive, and never paste what you'd hate to see leaked.

Reduces the leak. Doesn't close it.

More private

Enterprise tier or a proxy

Enterprise, education, and Team accounts are contractually excluded from training — this is exactly what a Pitt login buys you (see On Campus). Or use a front-end like DuckDuckGo's AI Chat that proxies your request so the model host never sees who you are.

Maximum

Run it yourself

Load an open-weight model on your own machine with Ollama or LM Studio — Llama, Mistral, Qwen, Gemma. Nothing leaves the device, so there's nothing to train on, retain, subpoena, or leak.

The trade-off: laptop-sized models are weaker than the frontier, and the strong ones want a real GPU. Maximum privacy, not maximum power.

Get involved

It’s free, open to everyone at Pitt, and joining takes about a minute.

No dues, no experience needed. Come to a meeting, or leave your name and we’ll tell you when the next one is.