What ChatGPT Really Knows About You: A Tool Makes the Hidden Data Trail Visible

Smartphone mit Chat-App, symbolisch für Datenspuren in KI-Unterhaltungen
Photo by lonely blue on Unsplash

Anyone who has used ChatGPT or Claude for months like a digital diary leaves behind a profile that extends far beyond individual answers. Security company Proton has released a free analysis tool called AI Paper Trail to expose exactly that blind spot: it reads an exported chat history and produces a report showing what picture emerges from it, including a dollar value for your own data.

Key takeaways

  • Proton has released AI Paper Trail, a free browser-based tool that analyzes exported chat histories from ChatGPT and Claude.
  • The report generates a “Privacy Type,” an “AI Exposure Score,” and an estimated dollar value of your data to AI companies.
  • A test by German outlet t3n found a real account scored 31 out of 100 on the exposure score, with an estimated data value of $15.
  • On a test account seeded with half-marathon training data, the tool flagged four warning signals, including recovery and nutrition details.
  • Proton says uploaded data is deleted immediately after analysis and never stored on its own servers.

How the analysis works

The process is deliberately low-friction: users export their chat history from ChatGPT’s or Claude’s privacy settings as a ZIP or JSON file and upload it directly in the browser to AI Paper Trail, no account required. The tool is built on Proton’s own AI assistant, Lumo, and processes one file per run. From the text, it extracts interest profiles, health information, financial details, diet and training data, and personal goals and appointments, information users typically share in passing, without ever considering how much it adds up to.

The final report centers on three key figures: the “Privacy Type,” a kind of personality label for a user’s approach to data privacy; the “AI Exposure Score,” a number between 0 and 100 based on how many data points were extracted and how revealing they are; and an estimated dollar value that data would carry for an AI company. Users can optionally share the report, for instance to raise awareness among family or colleagues who may not realize the scope of what they’ve shared.

The test exposes a gap between gut feeling and reality

t3n writer Marco Engelien tested the tool on two accounts. Running his own, months-old ChatGPT history through it produced an exposure score of 31 out of 100 and an estimated data value of $15, a figure that looks modest at first glance but emerged purely from everyday conversation, without ever deliberately touching sensitive topics. On a second test account deliberately seeded with half-marathon training data, the tool flagged four separate warning signals, including recovery-phase and nutrition details, data that, combined, can reveal a person’s health status.

Proton’s own description of the tool warns explicitly about exactly this effect: once individual details have been inferred from a chat history, they can be used for targeting, profiling, and decisions about the person involved, regardless of whether that information was originally shared on purpose. That lines up with a survey finding that 43 percent of Germans worry about data security with AI providers, as t3n reported citing its own research.

What actually happens to the data at OpenAI and Anthropic

The context in which AI Paper Trail is drawing attention isn’t a coincidence. As kabel-salat.info reported, OpenAI is currently testing ad placements for free ChatGPT users, in part based on chat content. The macOS “Computer History” feature, which logs clicks and keystrokes, also points to a broader trend toward ever more comprehensive activity tracking by AI assistants. According to Proton, deleted chats at major providers can also remain on servers for up to 30 days before final removal, and depending on account settings, part of a conversation history feeds into model training.

For users who find that unacceptable, adjusting privacy settings in ChatGPT and Claude is one option, but switching to locally run models is another. As kabel-salat.info has previously covered, tools like Ollama let people run language models directly on their own machine, so sensitive conversations never reach an outside server, though with the well-known trade-offs in model size and compute power compared to the big cloud providers.

What it means

AI Paper Trail doesn’t reveal a new technical insight, security researchers have long understood that language models can infer personality profiles from casual, incidental statements. The tool’s real value lies in making that abstract risk tangible using a person’s own, real chat history, rather than leaving it as a theoretical privacy concern. Anyone who has seen their own score is likely to think twice about what details actually belong in a chat window, precisely because the threshold for oversharing tends to feel lower in a text box than it would in a form that openly asks for health or financial information.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top