The button is right there, in the three-dot menu next to the conversation name. "Delete chat." You click it, a confirmation dialog appears, and the conversation drops off the list. The feeling is unambiguous: that thing is gone.
What actually happened is more modest. You stopped seeing the conversation. How long it keeps existing, in how many systems and for what purpose, is a different question, and the answer is almost never in the interface.
Deletion is a product feature. It is not a guarantee about the data.
Three layers that do not disappear together
It helps to separate what happens into three planes, because they behave very differently.
The visible layer is your history: the list of conversations you see when you log in. That is what the button acts on, and it usually acts immediately.
The service layer is the records the provider generates in order to operate: request traces, metrics, backups, processing queues. Those systems have their own lifecycles and have no idea you clicked something in the interface. That is why almost every policy describes a gap between deletion and actual disappearance. Thirty days is the usual figure: Anthropic's privacy center states that a deleted conversation leaves its back-end storage within thirty days.
The safety and abuse layer is the most persistent one. Providers keep material to detect prohibited use, and that retention serves a different purpose from the service itself. It can outlive a user deletion precisely because its whole point is not to depend on the user. In the same document, Anthropic explains that when a conversation is flagged for a possible usage policy violation, inputs and outputs are kept for up to two years, and trust and safety classification scores for up to seven.
Three clocks, three purposes, one button. That is the entire problem.
Human review exists, and it is in the contract
Some conversations get reviewed by a person. This is not a secret or a leak: it is written into almost every provider's terms, in similar language, sampling to improve the service, verification of safety incidents, quality evaluation.
It is also worth not assuming that what you signed a year ago still holds. On 28 August 2025, Anthropic changed its consumer terms: conversations on the personal plans (Free, Pro and Max) became eligible for model training, with retention extended to five years for anyone who accepts, and every user had to make an explicit choice before 8 October in order to keep using the product. Work, Education and Government plans, and the API, were left out. The change was public and announced. The problem is how many organizations find out in time.
The relevant question for a company is not how many conversations get reviewed, but whether it is acceptable that theirs could be one of them. That is a legitimate decision in either direction. What is not defensible is making it without knowing you are making it.
When deletion stops being the provider's call
There is one scenario that surprises a lot of people and is worth keeping in mind: litigation can force a provider to preserve data its own privacy policy said would be deleted.
This is not hypothetical. In the case between The New York Times and OpenAI, a court ordered in May 2025 that output logs be preserved even where the user had asked for deletion. The order was partially lifted in October of that year, but everything retained while it was in force remained available in the proceeding.
The provider was not breaking its policy. It was complying with a higher obligation. For the customer the practical effect is the same, the data is still there, except the reason is no longer a commercial decision anyone can negotiate into a contract.
And sometimes the provider is the one that changes its mind
In September 2025 Anthropic cut API log retention from thirty days to seven. Nine months later it moved the other way. Since 9 June 2026, prompts and outputs from its most capable models, the ones it calls covered models, are retained for thirty days to support safety work, and that retention applies even to organizations with zero data retention agreements, including those going through AWS Bedrock, Google Cloud or Microsoft Foundry.
The stated reason is a good one: some attacks are only visible across many requests, and detecting them means being able to look at those requests together. But for a compliance lead the headline is different. A contractual commitment to store nothing stopped applying because the provider decided so, with notice, and the only remaining option on the customer side is to not use those models.
What you actually get to decide
None of this is fatalistic. There are real decisions here, and they are worth understanding before you need them.
History. Almost every product lets you turn it off. It usually costs you memory and personalization features.
Training. This is a separate toggle from history, however often the two get conflated. On enterprise accounts it is usually off by default. On personal accounts, not always.
Account type. The difference between a consumer plan and an enterprise one is not just price: it changes the contract, the retention commitments, and who is accountable when something goes wrong.
What gets sent. The only layer you control completely. Data that never leaves needs no retention policy.
The uncomfortable conclusion
The first three decisions depend on a provider: on its terms, its infrastructure, and legal obligations that can change without warning. The fourth depends on nobody but your own organization.
And it does not take a lawsuit for data to end up where it should not. We have already seen shared Claude conversations turn up in search engines with no breach involved: all it took was a share button and a technical control that never did what it looked like it did. Before that we went through the five routes data takes out of a company without anyone actually deciding anything.
So when someone asks us how long a given tool keeps their data, we tend to answer with a question of our own: what are you sending it? Because of the four levers, that is the only one still yours after you click the button.
Sources
Everything this article claims comes from here. If something does not add up, go check.
What the providers say
- Anthropic, Privacy Center: How long do you store personal data? Source of the thirty days for a deleted conversation, the two years for flagged inputs and outputs, and the seven years for classification scores.
- Anthropic, 28 August 2025: Updates to Consumer Terms and Privacy Policy The change on personal plans, five-year retention for users who allow training, the 8 October 2025 deadline, and the exclusion of Work, Education and Government plans and the API.
- Anthropic, Help Center: Data retention practices for Covered Models The thirty days in force since 9 June 2026 for covered models, and the fact that they override zero data retention agreements.
The court case
- Simon Willison, 23 October 2025: OpenAI no longer has to preserve all of its ChatGPT data Timeline of the preservation order and its partial lifting.
- Engadget, 23 October 2025: OpenAI no longer has to preserve all of its ChatGPT data, with some exceptions The same news, with detail on what is still being kept.
Previously on Moviwa
- Nobody hacked anything... but information still leaked
- Shadow AI: five ways your data leaves, and only one has a culprit
The lever you can pull today
Of the four, deciding what gets sent is the only one that requires negotiating with nobody. That is what we built the anonymizer for: it replaces the personal data in a text before it leaves your machine, runs entirely in the browser, and is free.
It does not fix anyone's retention policy. It makes it matter less. And it is worth saying what it does not do: it protects personal data, not your own know-how, so an internal architecture draft would still be perfectly readable on the other side.
If you want to look at what is leaving your organization for a chatbot today, get in touch. That audit takes an afternoon and it almost always surprises people.

