An office at dusk, a closed laptop next to blank pages and an empty filing tray, at the end of a working day

AI conversations: where your messages go and who keeps them

Thursday, 6:15 pm. The executive assistant is tidying up the minutes of that morning's committee meeting. Her notes are a jumble: two possible departures, quarterly revenue that has not been announced yet, the name of a supplier in trouble. She pastes everything into a consumer AI tool, asks it to "turn this into clear minutes", and the document is ready before the last train.

The next day, a colleague asks her a simple question: "What you pasted yesterday, where is it now?" She can't answer. Most people can't. This guide answers that question and the ones that follow, first for consumer AI tools, then for IA Confidential.

Conversations with a consumer AI tool: the journey of a message

Where does the text go when I press Send?

To the provider's servers, usually in another country. The model that answers does not run on your computer: your message, your attachments and the answer travel through an infrastructure you did not choose. With most consumer services, the conversation is then stored there and attached to your account. That is what lets you find it on your phone the same evening: if your history follows you from one device to another, it is stored somewhere other than your devices.

How long are my conversations kept?

It depends on the service's terms, and they change. As a rule, the history stays until you delete it. Some services also keep a copy for a period of their own choosing, for security, abuse detection or legal obligations, even after you have deleted the conversation on your side. The only reliable source is the service's privacy policy, and it is rarely short. The AI can help you read it:

Read the privacy policy at this link: [link]. Answer in ten lines at most: what is kept from my conversations, for how long, whether they are used to improve the models, whether people can read them, and how to delete them. For each point, quote the exact sentence from the text, and say clearly when the text does not answer.

In IA Confidential, a web page is read from its link pasted into the question. Still check the quoted passages: the AI can misread or make things up, especially in a legal text.

Are my conversations used to train the AI?

Sometimes. Depending on the service and the plan, conversations may be used to improve the models, with or without a setting to opt out, switched on or off by default. The risk is not that an AI will recite your minutes word for word to a stranger; it is that your text leaves your control for good, for a use you did not decide on. For an internal document, that is already a disclosure to a third party.

Can anyone read my conversations?

Potentially, several people. The provider's staff, when its terms allow excerpts to be reviewed for quality or safety. The authorities, on request: the big American services are subject to the CLOUD Act, which allows US authorities to demand data held by these companies, even when it is hosted outside the United States. And anyone who gets into your account: one reused password, and the whole history can be read at once. Not to mention share links to a conversation, which sometimes travel far beyond the intended recipient.

Does deleting a conversation really erase it?

Not necessarily straight away, and not everywhere. Deleting a conversation removes it from your visible history; what the provider keeps afterwards, and for how long, is governed by its own rules. A copy may also exist elsewhere: an export, a shared link, the memory the service has built from your exchanges. Clearing your history does not put the text back in the box it came out of.

What these answers change at work

Is it a problem if I don't paste anything secret?

The problem starts earlier than you think. A client's name, an amount, a date, a remark about a colleague: these are personal data, and both the GDPR and the Swiss Federal Act on Data Protection (FADP) require you to know where they go and why. For professions bound by professional, medical or official secrecy, criminal law punishes breaches of secrecy, in Switzerland (Swiss Criminal Code Art. 321 and Art. 320) as in most other countries, and it is the content of the file that is protected, not just the client's name. On top of that come your employer's internal rules, which often forbid sending information to a service that has not been approved. The list of what must never go out is in our guide to data you should never paste into an AI.

Is removing the names enough?

Rarely. A job title, a small town, a sequence of dates are often enough to recognise someone. Removing names is pseudonymising, not anonymising: the difference is explained in our guide anonymisation vs pseudonymisation.

Your conversations with IA Confidential: what really happens

So where is the history?

In your browser, and nowhere else. Your conversations and your personal memory are kept on your device; there is no copy of their content on our servers. Even if we were asked for it, we would have nothing to hand over. Your account knows your email address and your plan, never what you wrote.

When you delete a conversation, it disappears from your browser, and no copy remains on our side, since we never had one.

What does the server see along the way?

Your question does have to be read by a model to get an answer. By default, it is handled by confidential models: open models installed on servers in Switzerland, under Swiss data protection law, outside the reach of the CLOUD Act. They pass nothing on to third parties, and nothing is kept once the answer has been sent. The message passes through; it is not stored.

What if I choose an external model?

The service offers three families of models: local and specialised, both confidential, and external, more powerful for some tasks. The choice is made automatically or by hand, and an external model is always your decision.

Before anything is sent to an external model, the Confidentiality filter detects the sensitive data in your message. It then offers to answer with a confidential model, message intact, to send an anonymised version that you review and correct, or to send it as it is if you accept the consequences. Whatever goes out is then processed by that model's provider, under its own rules: that is precisely why the filter comes first. Your personal profile is never sent to external models.

Does the AI keep a memory of me?

Yes, and you can read it. Your personal profile (tone preferences, fields of work, constraints such as professional secrecy) is kept in your browser. You can view it, edit it or reset it, and switch off its automatic enrichment. Confidential models use it to tailor their answers.

What happens if I change computers or clear my browser?

That is the trade-off of a history that stays with you: it does not follow you from one device to another, and clearing your browser data erases it for good. Nobody can restore it for you, not even us.

To keep it or move it, "Save my history" writes all your spaces and your profile to a file on your device, without going through our servers. On the other computer, or in the installed version, the "Import" button in the sidebar loads that file, without creating duplicates. This file contains your conversations in plain text: store it like a confidential document.

Should I keep my conversations forever?

No. An AI history is not an archive: the reference file stays in your business software or your usual filing system. A good habit is to pull out what matters before clearing things up:

Summarise this conversation as a note of ten lines at most: the decisions taken, the figures agreed, the questions still open and the next deadline. Do not write any person's name; replace each one with their role. I will file the note in our records and delete the conversation.

Read the note again: the AI can leave out a point or distort a figure, and it is your name that will be on it.

What stays confidential

With a confidential model, your questions and the answers are processed on servers located in Switzerland, and nothing is kept on our side: the history, the profile and the memory stay in your browser.

With an external model, nothing goes out without passing through the Confidentiality filter, and you choose between the reviewed anonymised version and sending the message as it is. Whatever goes out is then subject to its provider's rules. Your personal profile never goes out.

Two precautions remain in your hands. On a shared computer, the history can be read by anyone who uses the same browser session: keep a personal session and log out when you leave. And a backup file, an export or a copy-paste into an email are outside this setting: they are only as well protected as the place where you keep them.

If your employer restricts or bans AI, our guide when your employer says no helps you propose an acceptable tool. The plans are described on the plans page.

To see where your history lives, try it on a fictitious text: open the chat.