Privacy
The People in Your AI's Memory Never Agreed to Be There
You consented to your assistant's memory. The people you mention in it did not. What happens to a third party's details once they land there.
When you tell an assistant that your friend is going through a divorce, two people’s information enters that conversation and only one of them agreed to it. Every consumer AI memory system has a consent model with exactly one party in it, and it is not the party being described.
This is not an argument against writing things down about people. It is an argument about where those things live. The assistants differ in the detail, and what ChatGPT, Claude, Gemini and DeepSeek remember sets out what each one keeps. The details that make relationship context worth having are almost always somebody else’s to give, and the difference between a store you control and a store you rent shows up entirely in what happens to them next.
The consent model has one party in it
Look at what you can do with your own memory in any of the major assistants. You accepted the terms. You can open a settings page and read what is held. You can edit an entry, delete it, pause the whole system, or export the lot.
Now apply that list to the person you described. They did not accept anything. They cannot read the entry. They cannot correct it when it is wrong, and it will sometimes be wrong, because it is a summary of your recollection of something they said once. They cannot delete it, and in most cases they have no idea it exists.
DeepSeek’s privacy policy addresses this directly. It asks you to obtain the other person’s explicit consent before sharing their information, and says the service is not designed to process sensitive personal data, whether about you or about anyone else. It is a reasonable ask. It is also one that essentially nobody performs, because the whole appeal of asking an assistant for advice about a difficult conversation is that you can do it at eleven at night without convening the other participant.
What happens to a sentence about someone else
The interesting question is not whether the sentence is stored. It is what the sentence does afterwards, and there are four mechanisms worth understanding.
It outlives the conversation. Memory and chat history are separate stores. Deleting the chat does not remove a saved memory that came out of it, which is exactly the behaviour most people assume works the other way round.
It gets rewritten without you. ChatGPT’s Dreaming synthesizes memory in the background, revising entries as time passes so they stay current. That is a genuine improvement for facts about you. Applied to a third party, it means a detail you mentioned once can be re-summarized, carried forward, and kept fresh by a process you never triggered and do not watch.
It may be training data. DeepSeek’s policy states that content is used to train and improve its models, with a stated right to opt out. Whether that opt-out is exercised is a decision the account holder makes, and the person described is not consulted.
It has a jurisdiction. DeepSeek’s policy also states that it collects, processes and stores personal data in the People’s Republic of China. Your friend’s diagnosis now has a data residency, and they had no say in choosing it.
None of this makes these tools reckless. Each behaviour is defensible and mostly documented. The point is narrower: the consent that authorized all four came from someone who was not the subject.
The tier of fact that matters is the tier with the most at stake
Here is the uncomfortable part. The relationship details worth keeping are, almost by definition, the sensitive ones.
Nobody needs a memory system to recall that a colleague works in finance. What you actually want to remember six months later is that they are interviewing quietly, that their partner’s visa renewal is stuck, that they are the one person you know who has been through the same diagnosis your brother just got. Those facts are the reason relationship memory is useful, and they are the same facts with a real cost if they surface somewhere unexpected.
There is a strange asymmetry in how carefully we handle them. Most people would never post any of it. The same people will paste all of it into a chat window, because the window feels like thinking rather than publishing.
A standard you can actually apply
Absolutism does not survive contact with real life. You are going to ask an assistant for help with a hard message to a real person, and you should. Four questions keep that useful without being careless.
- Is this mine to tell? A fact you observed is different from a fact you were trusted with. The second one deserves more care in every system, not just this one.
- Do I need the name? Most drafting help works perfectly on “a friend who has just left their job”. Names are what turn a general question into a durable record about an identifiable person.
- Does it need to persist? If you want help right now and nothing after, use a temporary or incognito chat. Every major assistant has one, and it is the single most under-used privacy control they ship.
- Does it need to be in this tool? Drafting can happen in the assistant. The durable record does not have to live in the same place.
The de-identifying habit is the one that pays off most and costs least. Strip the name, keep the shape of the problem, and the draft you get back is just as good. For a fuller treatment of keeping only what earns its place, see data minimization for relationship notes.
Where the durable version belongs
The notes themselves are not the problem. Remembering that a friend’s mother was ill, and asking about her in November, is the entire substance of being a good friend at scale. The problem is a general assistant being the only place that record exists.
A store built for this holds the same sentence under different terms. Notes live on your device with encrypted snapshots rather than in a general-purpose conversational corpus. The assistant answers from what you wrote and says so when something is not there, instead of filling the gap with a plausible guess. Nothing is enriched or scraped from public profiles, so the record contains what you were told and nothing you were not. And every note is yours to export or delete, which is the one control that actually maps onto a request from the person described.
That last point is the practical difference. When a friend says they would rather you did not keep something, you need to be able to act on it. Deleting one dated note is a thing you can do. Removing a person from a synthesized profile that has been rewritten in the background for eighteen months is not.
Key takeaway: AI memory is built around a single consenting account holder, so third-party details inherit a retention policy, a synthesis process, a training posture and a jurisdiction that the person described never agreed to. Use assistants for drafting, de-identify by default, and keep the durable record of other people in a private store you can delete from on request.
FAQ
Is it safe to tell ChatGPT about other people?
For general advice with names removed, it is a reasonable use. For durable, identifiable detail about someone’s health, finances or personal situation, be deliberate: memory can outlive the chat it came from, it is summarized in the background over time, and the person described has no way to see or correct it. Use a temporary chat when you only need help in the moment.
Does deleting a chat delete what the AI remembered from it?
Not necessarily. Saved memories are stored separately from chat history, so a memory created during a conversation can persist after that conversation is deleted. To clear it you have to remove the memory entry itself, or reset memory entirely, in the assistant’s settings.
Is DeepSeek safe for notes about other people?
Its privacy policy states that personal data is collected, processed and stored in the People’s Republic of China and used to train and improve its models, with a stated right to opt out. It also asks users to get explicit consent before sharing another person’s information, and not to provide sensitive personal data about anyone. Read those terms before pasting third-party detail.
Do I need someone’s permission to keep notes about them?
Personal notes for your own recall are ordinary and usually lawful, and most people keep them in some form already. The considerations change with sensitivity, with who else can see the store, and with whether the contents feed anything beyond your own recall. Keeping notes private, minimal and deletable covers the great majority of the concern. See private relationship notes for how that works in practice.
What is the safest way to get AI help with a sensitive message?
Describe the situation without the name, ask for the draft, and keep the durable record somewhere else. You get the same quality of writing help, and the identifiable version of the story never enters a store you cannot fully control.
Can I get relationship memory without sending notes to a general AI?
Yes. A dedicated app can keep notes on device with encrypted snapshots and answer from them directly, which is a different arrangement from pasting the same material into a general assistant. Privacy-first AI relationship memory covers what to check before trusting any tool with this.
Intriq keeps relationship notes private by default, answers only from what you wrote, and lets you export or delete any of it. Start with the personal CRM hub or read more on private by default notes.