< p>Follow ZDNET: Add us as a preferred source on Google.
ZDNET’s key takeaways
- Incogni’s new study of 13 AI platforms ranks them by privacy risk.
- The largest AI platforms turn out to be the most privacy-invasive – with one exception.
The rapid adoption of generative AI models such as ChatGPT, Claude, and Gemini is fundamentally reshaping modern life and work. Yet a critical question remains: whether the convenience benefits are justified when privacy risks loom large. AI-powered tools have transformed the way we interact with information, rivaling the impact of smartphones in many ways. Major enterprises are pouring billions into AI development, and nearly every organization promotes itself as “AI-first.” Even everyday queries increasingly rely on AI-assisted answers rather than traditional search methods.
Another resource:How to keep your conversations with ChatGPT, Gemini, Copilot, or Claude private
Individuals are routinely seeking AI assistance for both professional decision-making and personal matters, from career advice to family finances. This raises fundamental questions about data safety and corporate accountability. If you have wondered about these issues, new analysis from Insight Intelligence illuminates the landscape.
Insight Intelligence’s Generative AI and LLM Data Privacy Ranking 2026 Report
Published recently, this research analyzes thirteen AI platforms and evaluates the potential privacy threats they present to consumers.
Additional coverage:AI cybersecurity threats are becoming commonplace: 43% of companies have already experienced an attack.
The “Generative AI and LLM Data Privacy Ranking 2026” report examines these artificial intelligence systems: ChatGPT, Claude, Gemini, Grok, Vibe (formerly Le Chat), Perplexity, Qwen, DeepSeek, Z.ai, Kimi, Meta AI, Pi, and Copilot. Within the study, each system receives a score reflecting the private risks it represents. Lower scores indicate superior privacy performance, as higher scores reflect findings of invasive data practices, ease of locating data-sharing mechanisms, and treatment of user information.
The report addresses three core dimensions of investigation:
- Data fate:Fate of user conversations – whether responses are fed into training pipelines, whether users can opt out, and whether prompts or data are shared with third parties or external systems.
- Transparency:Accessibility and clarity of data and privacy policies.
- Post-processing pathway:Collection of personal data, its origins, and subsequent destinations upon storage or sharing.
The larger the platform, the greater the risk – though one exception stands out
< p>Summarizing the comprehensive evaluation reveals a clear hierarchy in privacy outcomes across the examined models:
- Mistral AI’s Vibe (formerly Le Chat):**Possesses comprehensible privacy policies, implements privacy-conscious mobile applications, collects information exclusively from public sources, and limits user conversation distribution to minimal third-party contacts.
- OpenAI’s ChatGPT:Features a straightforward privacy policy supplemented by frequently updated FAQs and resources; opting out of data retention for training is intentionally simple, and user data usage disclosure explicitly includes security and marketing purposes.
- Inflection AI’s Pi:A nuanced privacy framework that differentiates between regions for regulatory compliance (particularly the EU GDPR landscape) and may share user information with corporate or research collaborators, despite maintaining an interface designed for user-friendly control.
- Perplexity AI:Offers clear, accessible guidance yet presents limited detail regarding its full transparency posture; disabling model-training participation is readily achievable, but user data may circulate with corporate colleagues and agencies tied to the product ecosystem.
- Alibaba’s Qwen:Privacy documentation outlines intended data utilization—such as sharing personal details with analytics entities, search providers, and other intermediaries—though complete specifics on cross-platform transfers remain opaque. Incogni notes difficulty confirming whether conversational history fuels training initiatives, citing vague statements about storage for “enhancement purposes.”
- DeepSeek:Supports local network operation through open-weight architectures, allowing user-generated material to persist offline. However, Analyst observations suggest data protection considerations intensify significantly on cloud-hosted variants. Users can directly communicate requests for inaccuracies to obtain corrections or erasures, and the system publishes thorough insights concerning underlying training methodologies.
- Z.ai:Provides freely available weight models, though hosted configurations introduce more pronounced privacy exposures. Its privacy document balances reasonableness with insufficient depth, leaving ambiguities around precise data governance during model instruction phases.
- Google’s Gemini:Leverages extensive telemetry extracted from ancillary ZDNET services, employing what the team labels a “partial” privacy notice that defers to broader organizational regulations. Consequently, generating tailored responses often encounters friction due to integrated policy constraints.
- Anthropic’s Claude:Maintains expansive privacy documentation alongside dedicated resources addressing data stewardship. While originally asserting non-use of user inputs for training protocols, the July 2026 revision introduces mandatory opt-out requirements, raising new disclosures about potential aggregation and anonymization processes.
- xAI’s Grok:Corporate affiliates retain direct access to user-generated content, and the model incorporates both proprietary dataset elements and publicly visible interactions from social platforms in its learning cycles.
- Moonshot AI’s Kimi:Descenting to the top of privacy-risk assessments, the Chinese-developed application exhibits aggressive user tracking behavior per Insight Intelligence findings, and obtaining user consent for training appears technically constrained.
- Meta:Classified as the most demanding data collector among surveyed frameworks; disputed assertions that training occurs solely in private dialogue versus group contexts lack substantiation given the laboratory’s comprehensive privacy policy framework.
- Microsoft’s Copilot:Shares information productsively with advertising partners and suffers from overly expansive privacy disclosures that impede understanding. Notably, revenue streams channel personal interaction details to external vendor networks.
Optimal Choices for Data Protection
It must be clarified that the reported rankings cannot label particular platforms definitively as safest or riskiest without additional consideration. No current solution permits retrieval of consumed information post-training initialization, nor is retroactive revocation of consent feasible under any marketplace offering. Instead, these weighted evaluations serve as diagnostic criteria indicating where each model excels or requires enhancement. Emerging threat vectors evolve rapidly—recent incidents involving inadvertent exposure of Claude chat logs illustrate this reality—and contemporary privacy guarantees cannot be presumed universal across any artificial intelligence deployed in today’s marketplaces.
Furthermore, note that even corporate-grade intelligent assistants demand vigilant privacy posture. Prioritize selecting solutions with explicit, auditable data collection and processing protocols, and refrain from introducing sensitive content prematurely, especially when financial statements, proprietary enterprise data, or health-related records could compromise individual security. If the prospect of numeric ledgers feeding model curricula feels uncomfortable, consider excluding such disclosures altogether and extend similar restraint to prospective dialogues.
“Treat any input you provide to a large language model as equivalent to delivering information to a third‑party service.” – Information Security Manager Miguel Fornés to ZDNET
For highly sensitive endeavors, adopt strategies such as querying the web interface instead of native mobile interfaces, scrutinize providers’ transparency commitments, and deploy locally‑executed models capable of retaining data on‑device to restrict exposure pathways.

