
Anyone who uses an AI chatbot regularly often outsources more than isolated questions. Between recipes, work drafts, travel plans, and sensitive requests for advice, a history accumulates that can reveal interests, routines, and life circumstances. Proton wants to make that effect tangible with its free AI Paper Trail tool: users upload an export from ChatGPT or Claude and receive an analysis of what the conversations may disclose about them.
That is a useful change of perspective, but it is not a forensic view into providers’ databases. The tool reads a user’s own export and turns it into a profile. It therefore shows, above all, what can be inferred from material the user has supplied. That is precisely its value: an abstract privacy debate becomes a question of which details actually add up in one’s own chats.
Key takeaways
- AI Paper Trail analyzes exported ChatGPT and Claude conversations and summarizes possible inferences about identity, habits, and interests.
- The analysis is not an independent measurement of what a provider permanently stores or uses for advertising and model training.
- ChatGPT and Claude both offer data exports. ChatGPT also provides settings for training and temporary chats.
- The most practical value is not the tool’s score, but noticing sensitive patterns in one’s prompting and changing them.
A profile emerges from many harmless questions
A single prompt rarely reveals much. Over months, however, a surprisingly detailed picture can emerge. Someone who revises a job application, asks about medication interactions, discusses a breakup, and then plans a trip provides more than pieces of text. The history may suggest their profession, approximate life stage, family situation, health concerns, consumer interests, and locations. Uploaded files and recurring work tasks can make that picture even sharper.
Proton organizes these traces into personal data points, an exposure score, and an estimate of data value. That presentation is necessarily pointed: a calculated dollar amount is not a verifiable market price for an individual user. It works better as a warning against the convenient assumption that a chat is merely a fleeting web search. Anyone using the analysis should therefore treat its categories as prompts for reflection, not proof of a competitor’s specific business practices.
An export shows your history, not the full data reality
This limit matters. An export can include chat history and other account data, but it does not by itself answer which information a service processes in backups, security logs, or separate product features. Nor can an export determine whether a model-improvement setting applied to every past conversation. Privacy is not a single download button. It is the combined result of history, memory features, account settings, retention periods, and the way a service is used.
OpenAI says that ChatGPT users can use a Data Controls setting to exclude new conversations from model improvement. Those chats can still remain in history. According to OpenAI, Temporary Chats do not appear in history, do not create memories, and are not used to improve models; they may be retained for up to 30 days for safety purposes. That is a useful mode for an occasional sensitive conversation, but it does not replace checking what data is truly necessary before sending it.
Claude also offers an official data export. Anthropic directs individual accounts to the Privacy area of the web or desktop app; the export includes account and conversation data. That makes it possible to inspect one’s own trail. It does not automatically mean every usage scenario follows the same privacy rules. Teams and businesses in particular should assess their workspaces, administrator access, and contractual settings separately rather than applying a private self-test to an organization.
The useful test is the cleanup that follows
AI Paper Trail can help identify patterns: names in copied documents, private notes in uploads, customer details in work questions, or repeated health and financial topics. The more important work starts afterward. Users can archive or delete old chats, review saved memories, and choose temporary conversations for sensitive one-off matters. When confidential text must be edited, it should be anonymized where possible: placeholders instead of full names, broad locations instead of addresses, and no complete customer files in a prompt.
The consequence is even more practical for businesses. An employee who uses a chatbot as a quick editor may enter confidential project information without recognizing the step as a data transfer. Clear rules for approved tools, data classes, and approvals are therefore more effective than a general request to be careful. A screenshot from a private analysis tool replaces neither a data protection impact assessment nor contracts and technical controls.
Outlook: More transparency helps, simple scores do not always
The new tool addresses a real concern because AI chats can turn everyday language into usable structure. Its strongest point is not that it knows the precise price of a person. It is that a profile can be assembled from many supposedly trivial exchanges. Anyone who sees that in their own export will likely ask more precisely, use data controls more deliberately, and copy sensitive content into a text box less casually. That would be progress, even though Proton’s presentation also promotes its own service.
The debate connects with our analysis of why ChatGPT advertising makes the data question more visible and with the need for accountable rules discussed in OpenAI’s reversal on AI regulation.
