ChatGPT vs Gemini vs Claude Privacy: 5-Year Data Gap [2026] – tech-insider.org

Welcome to the forefront of conversational AI as we explore the fascinating world of AI chatbots in our dedicated blog series. Discover the latest advancements, applications, and strategies that propel the evolution of chatbot technology. From enhancing customer interactions to streamlining business processes, these articles delve into the innovative ways artificial intelligence is shaping the landscape of automated conversational agents. Whether you’re a business owner, developer, or simply intrigued by the future of interactive technology, join us on this journey to unravel the transformative power and endless possibilities of AI chatbots.
The EU AI Act’s Article 50 transparency rule went live on 2 August 2026, and it changed the ground rules for every chatbot an Irish user opens. ChatGPT, Gemini and Claude now have to make it obvious that you’re talking to a machine unless that’s already obvious from the setting. But disclosure is the easy part. The harder question, the one that actually decides which tool you should trust with a client contract, a medical query or a line of proprietary code, is what each company does with your data after you hit send. That’s where the three diverge sharply, and where most comparison articles stop short.
This piece looks at ChatGPT, Gemini and Claude through a single lens: data retention, training defaults, human review, and how each vendor is responding to EU AI Act enforcement now that Ireland’s Data Protection Commission (DPC) sits as lead supervisory authority for two of the three. Anthropic’s retention window on opted-in data runs to five years. Google’s default auto-delete for Gemini sits at 18 months, adjustable but not eliminated. OpenAI splits behaviour by plan tier. None of the three is simply “safe” or “unsafe” and the right pick depends heavily on who you are and what you’re typing into the box.
Don't miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
For most of 2024 and 2025, chatbot comparisons were a benchmark arms race, the kind covered in depth in our AI models hub: who scored higher on reasoning tests, who had the bigger context window, who answered coding questions faster. That race hasn’t stopped, Anthropic’s Claude Opus 5 landed within 0.5% of its own Claude Fable 5 flagship on the CursorBench 3.2 coding benchmark while cutting the cost per task in half, and Google’s Gemini 3.6 Flash shipped on 21 July 2026 using roughly 17% fewer output tokens for equivalent answer quality. But raw capability stopped being the deciding factor for a lot of Irish users and businesses the moment Article 50 became enforceable.
From 2 August 2026, the European Commission’s AI Office has formal legal power to investigate AI vendors operating in the EU, demand documentation, order corrective measures and issue fines for Article 50 non-compliance, reportedly up to €15 million or 3% of global annual turnover. That’s a materially different environment to the one these three chatbots launched into. It also means the question “which chatbot should I use” now has a compliance dimension that didn’t really exist eighteen months ago, particularly for anyone in Ireland handling client data, health information or anything covered by GDPR.
There’s also a live regulatory backdrop worth knowing about before you pick a tool. Ireland’s DPC opened a formal, cross-border statutory inquiry into X’s Grok chatbot on 17 February 2026 over its handling of personal data and its potential to generate harmful sexualised imagery, with fines of up to €20 million or 4% of global turnover on the table if breaches are confirmed. Grok isn’t part of this comparison, but the inquiry matters here because it’s the clearest evidence yet of how seriously the Irish regulator is willing to go after a mainstream AI chatbot, a concern that also shapes how these platforms handle younger users, covered separately in our Character.AI vs ChatGPT vs Claude age verification comparison. ChatGPT, Gemini and Claude are all watching that case closely, because the DPC is lead authority for OpenAI in the EU too.
Before getting into privacy specifics, here’s how the three stack up on the fundamentals that shape a privacy decision, model version, context window, EU legal entity, and default data behaviour.
A few things jump out immediately. Anthropic is the only one of the three with a clearly published, fixed retention period for data you actively opt in to sharing, five years, which is longer than it sounds but at least gives you a number to plan around. Google’s 18-month default is shorter on paper, but the caveat that human-reviewed chats can survive deletion for up to three years complicates any simple “shortest window wins” comparison. OpenAI’s structure is the most tier-dependent of the three: what happens to your data changes meaningfully depending on whether you’re on Free, Plus or Pro.
OpenAI’s approach to privacy is best described as tiered rather than uniform. On the Free and Plus plans, prompts are used to train OpenAI’s models by default, and users have to actively opt out through Data Controls in settings. That’s a meaningful detail for anyone assuming a paid subscription automatically buys privacy, it doesn’t, at least not on Plus. Pro subscribers get a materially better default: consumer prompts are excluded from training without needing to change any setting.
Memory is where ChatGPT differs most from its rivals, a gap explored in more depth in our separate ChatGPT vs Claude vs Gemini memory comparison. Even Free-tier users get a persistent Memory feature that carries context, preferences and facts across separate conversations until the user deletes it. That’s genuinely useful for continuity, but it also means ChatGPT is quietly building a longer-lived profile of a Free user than either Gemini or Claude typically does at the equivalent tier. Temporary Chat mode exists as an escape hatch: it isn’t used for training, keeps no history, and chats are generally deleted within 30 days, but it has to be manually selected each time rather than being the default.
For enterprise and developer use, OpenAI offers Zero Data Retention to eligible API customers on frontier models, meaning prompts and responses aren’t retained once a request is processed. That’s the strongest privacy posture OpenAI offers, but it’s gated behind API access and approval rather than available to a Plus subscriber typing into the consumer app. On the legal side, OpenAI Ireland Limited is now recognised as the EU controller for EEA and Swiss users, and the Irish DPC has been confirmed as OpenAI’s lead supervisory authority in the EU since February 2024, a status that was reinforced in March 2026 when a Rome court annulled the Italian Garante’s earlier €15 million GDPR fine against OpenAI specifically because Ireland, not Italy, held jurisdiction by the time the penalty was issued.
Google structures Gemini’s data handling around the account-wide Keep Activity setting, which is on by default for most users. With it enabled, Google states it uses your Gemini activity to “provide, develop and improve its services, including training generative AI models.” Turning it off stops future chats from being used for training, though feedback you submit manually can still be used regardless of the toggle.
The retention structure is the most granular of the three vendors. Google’s default auto-delete window for Gemini Apps activity is 18 months, but it’s adjustable down to 3 months or up to 36 months, or set to keep data indefinitely if a user chooses. The complication is human review: Google discloses that a subset of Gemini conversations can be read by human reviewers as part of quality processes, and that reviewed material can be retained for up to three years even after the underlying chat has been deleted by the user. That’s an important asterisk on the “18 months” headline figure that a lot of comparison pieces gloss over.
Google updated its Gemini Apps Privacy Notice on 1 July 2026 to explicitly disclose data collection from third-party services connected through Model Context Protocol (MCP) server tools, reflecting how Gemini’s growing plugin and agent ecosystem pulls in data beyond the chat window itself. Temporary chats remain available and are excluded from the pool Google uses to improve its AI. Separately, Gemini’s EU regulatory exposure in 2026 has mostly come through competition law rather than GDPR: the European Commission opened formal Digital Markets Act proceedings in January 2026 over whether Google was unfairly privileging Gemini through exclusive Android integrations, and by 16 July 2026 EU regulators had ordered Google to open up that architecture and begin sharing search data with rival AI services.
Anthropic’s public position is the most narrowly scoped of the three: data is only used to improve Claude if a user actively opts in, and Anthropic states plainly that where a user does opt in, “we’ll retain this data for 5 years.” That is the longest single retention figure of any of the three vendors when you compare like for like, but it only applies to the subset of users who’ve explicitly agreed to it. For everyone else, Anthropic doesn’t use conversations for model training by default.
One nuance worth flagging for anyone assuming a paid plan buys stronger privacy across the board: publicly available privacy comparisons note that paying for Claude Pro does not, by itself, change the default data-use setting versus a Free account. The meaningful privacy upgrades at Anthropic live further up the stack, in Zero Data Retention arrangements available to some Claude Platform and Claude Code Enterprise customers, subject to Anthropic’s approval on a case-by-case basis. That makes Claude’s strongest privacy tier effectively enterprise-only, similar to OpenAI’s API-gated ZDR offering.
Anthropic Ireland Limited publishes Claude’s EU Digital Services Act transparency report, most recently covering Claude.ai usage across the EU from 1 May to 31 December 2025, which details content moderation activity within DSA scope. On the frontier-model side, Anthropic’s Claude Mythos, a model focused on uncovering software vulnerabilities, has drawn direct European Commission attention: the Commission has held multiple meetings with Anthropic since April 2026 and said in July 2026 it would “intensify” discussions after Anthropic’s offer to give the EU’s cybersecurity agency, ENISA, access to the model hadn’t yet translated into practical access, partly due to a separate US export restriction. Separately, Reuters reported on 31 July 2026 that the Commission was in talks with both OpenAI and Anthropic after AI-agent-related hacking incidents, framed by officials as monitoring rather than formal enforcement.
Privacy and price aren’t cleanly separable in any of these three products. Stronger data protections tend to sit behind higher tiers, but not always the tier you’d expect. Here’s the current published pricing structure as of August 2026.
The pattern across all three: Zero Data Retention and the strongest contractual privacy guarantees sit in the enterprise or API tier, not in the consumer subscription most Irish readers are actually paying for. If you’re a Claude Pro or ChatGPT Plus subscriber assuming your €20 a month buys the same privacy posture as a corporate Data Processing Agreement, it doesn’t. That gap is arguably the single most useful thing to understand from this whole comparison.
Privacy policy shouldn’t be the only input into which chatbot you use, and recent benchmark data shows the three remain closely matched on raw capability even as they diverge on data handling. According to industry tracker Thursd’AI’s July 2026 release roundup, Claude Opus 5 landed within 0.5% of Anthropic’s own flagship Claude Fable 5 on the CursorBench 3.2 coding benchmark, while cutting the cost per completed task roughly in half, with per-token pricing unchanged at $5/$25.
On the Gemini side, a July 2026 roundup from The AI Sidekick newsletter reported that Google’s Gemini 3.6 Flash, shipped 21 July 2026, reaches equivalent answer quality to its predecessor while using approximately 17% fewer output tokens per response, a meaningful efficiency gain for anyone running Gemini through the API at volume. And on the OpenAI side, official release notes confirm ChatGPT’s Thinking mode now supports up to 256k tokens of total context (128k input plus 128k max output), a jump that matters for anyone feeding long documents or codebases into the model.
None of these efficiency and capability gains change the privacy calculus directly, but they’re relevant context: a business weighing whether to accept Gemini’s 18-month default retention window in exchange for output-token savings at scale, or whether Claude Opus 5’s near-flagship coding performance at half the cost justifies a five-year opt-in training commitment, is making a genuinely different trade-off than someone purely optimising for data minimisation.
Abstract policy language is one thing. Here’s how these differences have shown up in actual, documented 2026 events.
1. The Italian fine that Ireland effectively overturned. Italy’s Garante fined OpenAI €15 million in December 2024 over GDPR issues. In March 2026, the Court of Rome annulled that fine on jurisdictional grounds, ruling that OpenAI Ireland Limited already existed and the Irish DPC had already become lead supervisory authority for OpenAI in the EU by the time the penalty was issued. It’s a direct, concrete example of Ireland’s outsized regulatory role over one of these three companies.
2. The Grok inquiry as a live test case. The Irish DPC’s formal cross-border statutory inquiry into Grok, opened 17 February 2026 over harmful sexualised imagery and personal data handling, is the clearest current example of how aggressively Ireland’s regulator can move against a chatbot. Grok isn’t ChatGPT, Gemini or Claude, but the case sets a visible precedent for what the DPC considers actionable.
3. Gemini’s Android integration under EU order. By 16 July 2026, EU regulators concluded that Google’s practice of giving Gemini privileged access to Android system features, while denying equivalent access to competing AI assistants, breached the Digital Markets Act. Google was ordered to open up that architecture and begin sharing search data with rivals, a direct regulatory consequence tied to how deeply Gemini is woven into the Android operating system.
4. Claude Mythos and the ENISA access standoff. Anthropic offered the EU’s cybersecurity agency ENISA access to its Claude Mythos vulnerability-research model, but as of July 2026 that access “had not yet concretely materialized,” partly due to a US export restriction, prompting the European Commission to say it would intensify discussions with Anthropic to resolve the impasse.
5. The joint OpenAI-Anthropic hacking briefing. Reuters reported on 31 July 2026 that the European Commission was in talks with both OpenAI and Anthropic following AI-agent-related hacking incidents involving their models, with officials citing the episode as justification for closer monitoring of high-risk AI systems under the AI Act, even though no formal enforcement action followed.
6. Anthropic’s own transparency reporting. Anthropic Ireland Limited published a Digital Services Act transparency report covering Claude.ai’s EU usage from May to December 2025, a concrete, published example of a chatbot vendor proactively documenting its content-moderation activity ahead of an enforcement deadline rather than waiting to be compelled.
7. OpenAI’s tiered training defaults in practice. A Plus subscriber and a Pro subscriber typing the identical prompt into ChatGPT on the same day get different data outcomes by default, one trains OpenAI’s models unless they manually opt out, the other doesn’t. It’s a real, current example of how much a single subscription tier can change your privacy exposure inside the same product.
There’s no single winner here, the right pick depends on what you’re actually doing with the tool.
Solo consultants and freelancers handling client information: Claude Pro is the safer default, since standard use isn’t trained on unless you actively opt in. Pair it with a habit of avoiding pasting identifying client details directly into prompts regardless of which tool you use.
Software engineers working with proprietary or client codebases: None of the three consumer tiers are ideal here. Push for API-level Zero Data Retention, available from OpenAI and Anthropic to approved customers, or Gemini Enterprise’s negotiated terms, rather than relying on a personal Plus, Pro or Google AI subscription.
Small and medium Irish businesses needing a Data Processing Agreement: Gemini Business at roughly $21/user/month is the cheapest entry point into a formal enterprise-grade agreement among the three, though ChatGPT Business and Claude Team both offer comparable per-seat structures starting near $20-25/seat/month.
Healthcare, legal or other regulated-data professionals: Default to Temporary Chat on ChatGPT, a Temporary Chat on Gemini, or manually avoid entering identifiable personal data into any of the three consumer tiers. None of the standard consumer tiers are built for regulated health or legal data without a signed enterprise agreement.
Marketing and content teams working on public-facing material: Data sensitivity is lower here, so any of the three Free or entry-paid tiers is reasonable. ChatGPT Go at $8/month is worth a look for budget-conscious teams needing paid-tier speed without the full Plus price.
Public sector bodies and government contractors in Ireland: Procurement should specifically confirm Article 50 disclosure compliance and request a signed DPA rather than relying on a standard consumer or even Business/Team tier, given the heightened scrutiny public bodies face under GDPR. Teams weighing an EU-hosted alternative for stricter data-residency requirements should also see our Mistral AI vs ChatGPT vs Claude comparison.
Students and researchers: Google AI Pro at $19.99/month has the strongest practical integration with Google Workspace and Drive for citation-heavy academic work, but be conscious of the 18-month default retention and adjust it down if you’re working with sensitive research data. If deep research capability matters more than privacy defaults for your workflow, see our separate ChatGPT vs Gemini vs Perplexity deep research comparison.
Most readers of a comparison piece like this one already have an account with at least one of these three chatbots, which makes the more useful exercise auditing what you’ve already agreed to rather than picking a brand-new tool. Each vendor buries the relevant toggles in a slightly different place, and none of the three make the process especially intuitive.
On ChatGPT, open Settings, then Data Controls. Check whether “Improve the model for everyone” is switched on, that’s the training toggle, and switch it off if you’re on Free or Plus and don’t want your prompts used for training. While you’re there, review the Memory panel and delete any saved facts you no longer want persisted. If you’re handling anything sensitive in a single session, start it with Temporary Chat from the model picker rather than the default chat window.
On Gemini, the relevant control lives in your Google Account’s Gemini Apps Activity page rather than inside the chat interface itself. Look for Keep Activity and either turn it off or set a shorter auto-delete window than the 18-month default, three months is a reasonable baseline for most personal use. The same page lets you bulk-delete existing history rather than waiting for the auto-delete window to catch up, which is worth doing if you’ve been using Gemini for a while without touching these settings.
On Claude, the setting sits under Settings, then Privacy, where you’ll find the option to allow or disallow use of your conversations to improve Anthropic’s models. It’s off by default for standard accounts, so if you never opted in, there’s nothing to change, but it’s worth confirming rather than assuming, particularly if you’ve clicked through onboarding screens quickly in the past. Anthropic doesn’t currently offer a one-click temporary-chat mode in the consumer app, so the practical equivalent is simply avoiding pasting identifying information into prompts you don’t want retained at all.
Doing this audit takes about ten minutes across all three platforms, and it’s a more productive use of time than debating which vendor’s marketing page sounds more trustworthy. Settings change, defaults get reset after major product updates, and the only way to know your actual exposure is to go and look.
If you’re moving from one of these three to another, or simply tightening up your settings on the one you already use, work through this sequence.
Pros: Pro-tier consumer prompts are excluded from training by default; Zero Data Retention available for approved API customers; OpenAI Ireland Limited gives a clear, established EU legal entity and jurisdiction; largest ecosystem of integrations and third-party tools; Temporary Chat mode auto-deletes within roughly 30 days.
Cons: Free and Plus tiers train on prompts by default, requiring manual opt-out; Memory persists indefinitely on Free unless manually cleared; abuse-monitoring retention of up to 30 days applies even with training disabled; strongest privacy protections are gated behind Pro pricing or API-only access.
Pros: Granular retention control, from 3 months up to indefinite; Temporary Chat mode fully excluded from AI improvement; tightest integration with Google Workspace, Drive and Android for productivity workflows; competitive per-seat enterprise pricing starting near $21/user/month.
Cons: Keep Activity is on by default, requiring an active opt-out; human-reviewed chats can be retained for up to three years even after user deletion; under active EU Digital Markets Act enforcement over Android integration practices, adding regulatory uncertainty; MCP tool connections expanded the scope of data collection as of July 2026.
Pros: Not used for training by default unless the user explicitly opts in; clearest published enterprise ZDR pathway for approved Platform and Code customers; published EU Digital Services Act transparency reporting via Anthropic Ireland Limited; strong recent benchmark performance (Opus 5 near-matching Fable 5 on CursorBench 3.2 at roughly half the cost).
Cons: Five-year retention on opted-in training data is the longest fixed figure among the three; paying for Pro doesn’t change the default data-use setting versus Free; no dedicated temporary-chat toggle in the standard consumer product; Claude Mythos frontier-model oversight remains an open, unresolved question with EU regulators.
On pure default-behaviour terms, Claude is the strongest starting point for privacy-conscious individual users, since it’s the only one of the three that doesn’t train on your conversations unless you actively say yes, and the trade-off, a five-year window if you do opt in, is at least clearly disclosed rather than buried. Gemini offers the most granular user control once you go looking for it, but its default settings and the three-year human-review carve-out mean it demands more active management than Claude to reach an equivalent privacy posture. ChatGPT sits in the middle: genuinely strong at the Pro tier and above, but its Free and Plus defaults are the least private of the three out of the box.
For businesses, the calculation shifts. Zero Data Retention agreements, DPAs and enterprise contracts flatten most of the differences between the three, since you’re negotiating specific terms rather than accepting consumer defaults (the same logic applies to other assistants worth weighing, as covered in our Meta AI vs Perplexity vs DeepSeek comparison). The more useful differentiator at that level becomes each vendor’s regulatory standing, and by that measure OpenAI currently has the cleanest 2026 record among the three, following the annulment of its Italian fine and no new confirmed EU penalty, while Google faces the most active enforcement pressure through the ongoing DMA proceedings over Gemini’s Android integration.
The honest takeaway for Irish readers: check your account settings today, not just the vendor’s marketing page. All three companies have shipped material privacy-policy changes in 2026 alone, and the gap between what a chatbot does by default and what it’s capable of doing when properly configured is often the whole story.
Yes. Article 50 of the EU AI Act took effect on 2 August 2026 and requires chatbots and other AI systems interacting directly with people to disclose that users are dealing with AI, unless that’s already obvious from the context. All three vendors are subject to this rule for EU and Irish users.
Gemini has the shortest configurable default at 18 months, adjustable down to 3 months. However, Google discloses that human-reviewed chats can be retained for up to three years even after deletion, which complicates a straightforward comparison. Claude doesn’t train on standard conversations by default at all, which for many users functions as an even shorter effective retention outcome for training purposes specifically.
Not always. ChatGPT Plus still trains on your prompts by default, the same as the Free tier, unless you manually opt out; the meaningful upgrade happens at the Pro tier. Claude Pro also does not change the default data-use setting compared with Claude Free. Gemini’s behaviour is tied to the account-wide Keep Activity setting rather than the specific plan tier.
No confirmed 2026 fine has been reported against ChatGPT, Gemini or Claude specifically as of late August 2026. The DPC’s most prominent 2026 chatbot enforcement action is its formal inquiry into Grok, opened 17 February 2026, which is separate from these three products but relevant as a sign of the DPC’s willingness to act.
Zero Data Retention (ZDR) means a vendor doesn’t retain your prompts or responses once a request is processed. OpenAI and Anthropic both offer it, but only to approved API or enterprise customers, subject to case-by-case approval, not to individual Plus, Pro or Free subscribers using the standard consumer app.
Gemini Business, starting around $21 per user per month with an annual commitment, is currently the lowest-priced entry point into a formal DPA-backed tier among the three. ChatGPT Business and Claude Team both offer comparable structures starting near $20-25 per seat per month, so the right pick often comes down to which ecosystem your business already uses.
It varies by vendor. ChatGPT Free and Plus train by default, requiring an opt-out. Gemini’s training use is tied to the Keep Activity setting, which is on by default. Claude is the exception among the three, it does not use standard conversations for training unless the user actively opts in.
OpenAI is directly regulated by the Irish DPC as lead supervisory authority, since OpenAI Ireland Limited is its EU controller. Anthropic operates Anthropic Ireland Limited for its EU Digital Services Act reporting. Google’s Gemini-related EU scrutiny in 2026 has come primarily through Digital Markets Act proceedings at the European Commission level rather than DPC-specific GDPR action, though Google Ireland Limited remains part of its EU operational structure.
Sources: European Commission, AI Act transparency enforcement, RTE News, Euronews, Anthropic privacy policy updates, Google Gemini Apps Privacy Hub, Tech Times, and Anthropic pricing.
Niamh Kelly is the iGaming Editor at Tech Insider, where she previously worked as a freelance fashion journalist for The Irish News for three years and honed her media skills during her time at the BBC. At Tech Insider, she leads Ireland’s coverage with hands-on experience testing consumer and business technology, delivering in-depth analysis on AI, cybersecurity, cloud computing, and hardware trends shaping the future. Kelly was featured in RSVP online as part of their “Women of Style” series and has interviewed notable figures such as Katie Price and Louise Redknapp for major beauty product launches.
Tech Insider delivers in-depth coverage of the technologies shaping the future: AI, cybersecurity, cloud computing, hardware, and the trends that matter.

source

Scroll to Top