saturday, september 5, 2026 · the day's ai, attributed published by trilot llc · wyoming
guide · working with ai

What your AI assistant records, and how to decide what it keeps

Work out exactly what ChatGPT, Claude, Gemini and Windows Recall capture and keep, then set the memory and retention controls once instead of clicking through them.

Published 2026-09-05 · Updated 2026-09-05 · Read 9 min · Reviewed by Rami Steitieh

Verified 2026-09-05 · Rami
on this page · 0 / 0 checked

You switched on memory in ChatGPT because re-explaining your business every morning had got old. Then Claude offered the same thing. Then the desktop app on your Mac offered to keep a record of what you click. Each toggle looked small on its own. Together they mean a description of your working life now sits in at least three places, assembled partly from material you never deliberately typed into a chat box.

The useful question is not whether to trust the vendors. It is narrower and answerable: what does each feature put on disk, in what form, for how long, and who else can read it. Those four answers differ enormously between features that all get filed under the same word. What follows walks through them for the tools a small operation actually runs, and ends with a settings pass you do once. It is not written for anyone with a security team, device management and a data loss prevention policy. If that describes you, this decision already belongs to someone else and you should ask them.

Three different things get called memory

The first is chat memory. ChatGPT’s version, when enabled, “helps ChatGPT automatically remember useful context from your chats, files, and connected apps to personalize your experience” [2]. Claude’s is “fully optional”, switched on in Settings, and it reached Team and Enterprise plans before Pro and Max got it on 23 October 2025 [4]. Both draw on material you brought into the assistant yourself: conversations, uploads, and in ChatGPT’s case whatever you connected [2][4]. Neither reads your screen.

The second is ambient capture. This is software that records what you do outside the chat window and turns it into something the assistant can read later. ChatGPT’s Computer History does this on macOS [1]. Windows Recall does it on Windows machines that clear its hardware bar [7]. The input is a stream of events from your machine rather than the text of your conversations [1].

The third is the one people forget: the vendor’s own retention, which runs whether or not you use either of the first two. Google keeps Gemini Apps Activity for 18 months by default, and you can change that to 3 months, 36 months, or indefinite [6]. That clock ticks on ordinary conversations with no memory feature switched on at all.

Confusing the three is how people end up reassured by the wrong fact. Turning off chat memory does nothing to a retention window. Turning off activity does not stop a local capture feature. They are separate switches on separate systems, and each needs its own decision.

Ambient capture reads a surface your chat box never touched

Computer History builds summaries from interaction events, which OpenAI’s documentation lists as “clicks, typing, keyboard shortcuts, app switches, and context that macOS exposes through its accessibility system” [1]. It is narrower than it sounds in one direction. It “does not include screenshots in your history or record microphone input or system audio”, and “private-mode web browsing activity is never included” [1]. The raw events are temporary: “ChatGPT and Codex delete these event files after 48 hours” [1].

The controls are real ones. The feature is “off by default for ChatGPT Pro, Business, and Enterprise users in the ChatGPT desktop app on macOS” [1]. Your app and website permissions determine which sources can contribute interaction events [1]. There is a Pause control that stops collection until you resume it [1]. In Business and Enterprise workspaces it is “unavailable until an administrator explicitly grants access”, which is done through Enable Computer History under Workspace Settings > Permissions & roles [1].

Then comes the sentence that changes the calculation. The generated memory files live under a path that “typically resolves to ~/.codex/memories/extensions/skysight/”, and in OpenAI’s own words, “they are not encrypted by Computer History, and other programs running as your macOS user may be able to access them” [1]. That is an unencrypted account of your working day sitting in your home folder with the same protection as any other file you own. Unlike the 48-hour event files, it does not expire on its own: generated memory files “remain on your filesystem until you delete or clear them” [1].

Set that against Windows Recall, which captures far more and guards it harder. Recall saves “a snapshot of your active screen … every few seconds and when the content of your active window changes” [7]. Those snapshots “are saved and encrypted to your local hard drive”, Microsoft states that Recall “does not share snapshots or associated data with Microsoft or third parties, nor is it shared between different Windows users on the same device”, and they are “protected with Windows Hello, so that only the signed in user can access their Recall content” [7]. A sensitive information filter is enabled by default and tries to drop snapshots containing “passwords, credit cards, and more” [7]. It is also off until you opt in, and it needs a machine with a 40 TOPS neural processing unit, 16 GB of RAM and device encryption [7].

So Recall sees your screen and Computer History does not, but Recall’s record is encrypted behind a biometric check and Computer History’s is not. Which one deserves more caution depends entirely on what else runs on that machine and who else can sign into it. That is the question worth asking about any capture feature, and it is not the same question as whether the feature is opt-in.

Deleting is a request, and it has a floor

Delete removes something from your view first and from the vendor’s systems later, and the gap is usually 30 days. OpenAI’s stated practice is that “Deleted ChatGPT conversations and Temporary Chats will be automatically deleted from our systems within 30 days”, and API data “will also be automatically deleted after 30 days” [3]. Anthropic says deleted conversations are “Removed from your chat history immediately” and “Deleted from our back-end storage systems within 30 days” [5].

Two things push that floor further out. If you leave model improvement switched on with Claude, Anthropic “may retain your data in a de-identified format for up to 5 years” in its model training pipelines [5]. And if automated systems flag something as a usage policy violation, Anthropic retains “inputs and outputs for up to 2 years and trust and safety classification scores for up to 7 years” [5]. Google has its own version of the floor: with Gemini Apps Activity switched off, “future chats are still saved for 72 hours so Gemini can respond to you, process your feedback, and protect Google, its users, and the public” [6].

Memory makes deletion harder in a second way, because the same fact ends up in several places at once. OpenAI is unusually direct about this. To fully delete something ChatGPT may know about you, you need to “delete every source where it appears, including past chats, archived chats, files, the memory summary, and disconnect any connected apps” [2]. Saved memories are “stored separately from your chat history”, so clearing your chats leaves them standing [2]. If you have ever pasted a client contract into a chat and later deleted the chat, that is the sentence to reread.

One more line worth quoting, because it is a vendor telling you what its tool is not for. Google notes that “a subset of chats are reviewed by human reviewers (including Google’s trained service providers)” to improve its services, and asks you not to “enter confidential information that you wouldn’t want a reviewer to see or Google to use to improve our services” [6].

A court order can suspend the delete button

In 2025 the plaintiffs in the New York Times litigation asked a court to make OpenAI “retain consumer ChatGPT and API customer data indefinitely” [3]. For a period, deletion stopped meaning deletion for anyone on a “ChatGPT Free, Plus, Pro, and Team subscription or if you use the OpenAI API” [3]. OpenAI’s update of 22 October 2025 records that the obligation ended on 26 September 2025 and that the company is “no longer under a legal order to retain consumer ChatGPT and API content indefinitely” [3], though it still holds limited April to September 2025 data that “will not be turned over to the New York Times, the Court, or anyone else at this time” [3].

That episode is closed. The lesson it teaches is not. A retention policy describes what a company does when nothing external forces it to do otherwise, and it can be overridden by a court in a case you are not party to and did not hear about until afterwards. Plan on that basis. If a category of information genuinely must not exist in two years, the control that works is not creating it, rather than deleting it later.

The plan you are on decides more than the toggles do

The same preservation order that swept in Free, Plus, Pro and Team explicitly did not cover “ChatGPT Enterprise or ChatGPT Edu customers” or anyone using Zero Data Retention endpoints [3]. That is the clearest available illustration of a rule that holds generally: your account type sets the outer boundary, and the settings screen only rearranges things inside it.

The same split shows up in who gets a feature at all. Computer History is documented for ChatGPT Pro, Business and Enterprise users in the macOS desktop app, and on Business and Enterprise an administrator must grant access before a member can switch it on [1]. Claude’s memory reached Team and Enterprise before it reached Pro and Max [4]. If you handle client material under a contract that says anything about confidentiality, sub-processors or data location, read what your tier actually commits to before you spend an afternoon on toggles.

The client data on your machine is your responsibility

If you hold personal data about people in the EU or the UK and you decide what happens to it, you are the controller for it. The GDPR requires that such data be “adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed” and “kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed” [8]. Article 5(2) adds that “the controller shall be responsible for, and be able to demonstrate compliance with” those principles [8].

Switching on a feature that reads your accounting app, your inbox and your CRM through the accessibility layer is a processing decision, and you made it [1]. Demonstrating compliance means being able to say which apps were allowed to contribute, why, and where the resulting files sit. This is why the per-app permission list in Computer History matters more than the master switch [1]. An allowlist of two or three tools you could justify to a client is defensible. Everything on, because that was the path of least resistance during setup, is not.

checklist
Your quarterly AI privacy pass
0 of 7 · saved in this browser only
calculator
Activity sitting on disk
h of captured activity

machines × hours × days. Computer History's generated memory files remain on your filesystem until you delete or clear them. Computed in the page; nothing is sent anywhere.

What still goes wrong

You cannot audit what you cannot read, and here you mostly can. The Computer History memory files sit unencrypted on your filesystem and can be revealed from the History timeline [1], and the memory summaries in ChatGPT and Claude are both viewable and editable from settings [2][4]. Open them once. What people find is rarely alarming and often wrong, which is its own problem: a memory that says you work in insurance when you left insurance two years ago will quietly skew every answer until you correct it.

Availability and defaults move under you. The Computer History documentation currently lists supported regions as “including the European Economic Area (EEA), Switzerland, and the United Kingdom” [1], and lines like that change as compliance work catches up with shipping. The same goes for which plans get a feature and what an administrator can enforce. Anything you write down about this is a snapshot of one day, so check the vendor page rather than your notes when a decision depends on it.

The largest hole is not a setting at all. A local, unencrypted record of your work is only as private as the machine, and the machine is only as private as everyone who can sign into it, every application you have installed, and every airport lounge you leave it in. Everything above is something you can configure. Whether a laptop is a reasonable place to keep an unencrypted account of your clients’ business is a judgement no configuration screen will make for you.

sources
  1. 01OpenAI — Computer Historylearn.chatgpt.com
  2. 02OpenAI — Memory FAQhelp.openai.com
  3. 03OpenAI — How we're responding to The New York Times' data demandsopenai.com
  4. 04Anthropic — Bring your context with Claude's memoryclaude.com
  5. 05Anthropic — How long do you store my data?privacy.claude.com
  6. 06Google — Gemini Apps Activitysupport.google.com
  7. 07Microsoft — Retrace your steps with Recallsupport.microsoft.com
  8. 08GDPR Article 5 — Principles relating to processing of personal datagdpr-info.eu
next guide
When to split a job across parallel agents
10 min · verified 2026-09-05
related guides