When somebody types something into an artificial intelligence tool, the question almost nobody asks is the most important one: what happens to that text afterwards? The answer is rarely what people assume. It does not evaporate when the tab closes, it does not disappear when the conversation is deleted, and it is not always out of reach of third parties.
There are at least three distinct layers of retention in play, and they are worth telling apart because different rules govern each. There is what the provider keeps to deliver the service, which usually includes the conversation history. There is what it keeps by legal obligation or under a court order, which can survive a deletion the user requested. And there is what may be used to train models, which depends on the plan and sometimes on a setting nobody has reviewed.
The delete button rarely does what its name suggests. In most services it removes the conversation from the user's view and starts a deletion process with its own timescale, its own exceptions and its own intermediate copies. It is not a deception: it is how any distributed system with backups works. But the difference between "I deleted it" and "I asked for it to be deleted" matters a great deal when what was in that conversation belonged to a customer.
There is also a route of exposure that does not depend on the provider at all: sharing. Public links to conversations and to generated artifacts have ended up indexed by search engines more than once, with no security breach involved. There was a button, a mistaken expectation about what it did, and a crawler doing its job.
What does depend entirely on the organisation is what leaves. Data that is never sent needs no retention policy, no processor agreement and no trust in the provider. That is why anonymising before sending resolves the problem at source rather than managing it afterwards. You can try it in the anonymiser, which runs in your own browser.

