> ## Content Index
> Fetch the complete content index at: https://theseguysknow.io/llms.txt
> Use this file to discover other available public pages before exploring further.

# You Uploaded a Private File to an AI Tool. What Happens Next?
- URL: https://theseguysknow.io/what-happens-to-files-uploaded-to-ai-tools/
- Published: 2026-09-10T11:45:00.000Z
- Updated: 2026-09-10T11:46:18.000Z
- Description: Uploading a file to an AI tool can leave copies in chats, libraries, projects and connected services. We checked what ChatGPT, Claude, Gemini, Copilot and Perplexity say about training, storage, human review and deletion.
- Author: Mike Hazard
- Tags: Things to Use, Apps & Tools, AI & Tech, AI Tools & Models

I upload documents and screenshots to AI tools regularly, and I have sent a few personal files too even though I knew it was not the cleverest idea. The upload button makes the exchange feel temporary, as if the model looks at a PDF and then politely forgets it, but a cloud service normally receives a copy, processes its contents and keeps some combination of the file, conversation and activity data under that product’s rules.

Keeping business in AI chats and personal material somewhere else is a sensible start, although it is not a reliable privacy rule on its own, because an ordinary personal receipt may reveal very little while a client contract, unpublished spreadsheet or database export can expose an entire company. The better question is whether the file could cause harm if it were retained longer than expected, included in model improvement, opened during a safety or support review, or sent to another service you connected.

This guide compares the published rules for ChatGPT, Claude, Gemini, Microsoft Copilot and Perplexity, checked on 9 September 2026, while separating consumer accounts from business and API products because their protections can be very different.

## Quick answer

When you upload a file to a cloud AI tool, the service sends it to the provider’s systems, reads the material needed for your request and may keep the upload with a chat, library, project, repository or activity record. Consumer settings can allow model improvement, while business and API products more commonly exclude customer data from training by default; neither promise tells you how long the file is stored.

Turning off training does not delete an upload, and deleting a chat may leave a separate copy in ChatGPT Library, a Perplexity Project or another saved workspace. Where they are offered, Temporary and Incognito modes can shorten normal retention and prevent ordinary model-training use, although the file is still processed and may remain briefly for safety or legal reasons. For ordinary documents, remove whatever the model does not need and delete both the chat and stored file afterwards; passports, bank details, passwords, API keys, medical records, signed legal papers and confidential client material should stay out of a consumer account unless you have permission and an approved service with suitable written protection.

## What consumer AI accounts say about uploaded files

There is no single “AI privacy policy,” because storage, training and deletion can change between services and even between two features inside the same service.

| Service               | Published consumer-account rule                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| --------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **ChatGPT**           | OpenAI may use individual-account files and images to improve models unless the user opts out; Temporary Chats are excluded. Deleted chats are scheduled for deletion within 30 days, with limited exceptions, but [Library files are separate](https://help.openai.com/en/articles/8983778-how-are-files-vs-chats-retained?ref=theseguysknow.io), so deleting the chat does not delete that file. Project and custom-GPT files remain until their container is deleted.                                                                                                                                                                                                                                                                                   |
| **Claude**            | Anthropic uses consumer chats for model improvement when the user allows it, explicitly opts in or a conversation is safety-flagged; Incognito chats are excluded. Deleted conversations reach back-end deletion within 30 days, while training data with identifying details removed can remain for up to five years and [longer exceptions apply](https://privacy.claude.com/en/articles/10023548-how-long-do-you-store-my-data?ref=theseguysknow.io) to flags, feedback and legal requirements.                                                                                                                                                                                                                                                         |
| **Gemini**            | For adults, Keep Activity is on by default and activity is automatically deleted after 18 months unless the user changes that period to 3 or 36 months, turns automatic deletion off, or deletes it manually. Google says a subset of chats is human reviewed and reviewed material can remain for up to three years even after the user deletes Gemini activity. With Keep Activity off, or in a Temporary Chat, conversations remain for up to 72 hours and are not used to train Google’s AI models unless feedback is submitted, although safety processing and limited human review can still occur.                                                                                                                                                  |
| **Microsoft Copilot** | Microsoft says consumer conversation activity is stored for 18 months by default and can be excluded from model training through the user’s settings, while uploaded files are retained for no longer than 18 months. Its [file-upload page](https://support.microsoft.com/en-us/microsoft-copilot/file-upload-in-microsoft-copilot?ref=theseguysknow.io) says uploaded file content is not used for model training, but its [privacy FAQ](https://support.microsoft.com/en-us/microsoft-copilot/privacy-faq-for-microsoft-copilot?ref=theseguysknow.io) says the file and related conversation are subject to the user’s model-training choice. Those statements do not line up cleanly, so the stricter reading is safer until Microsoft clarifies them. |
| **Perplexity**        | AI Data Retention is enabled by default for Free, Pro and Max users, who can opt out of future training use; a later opt-out does not remove previously collected training data. Session uploads remain for 30 days, while Project and personal-repository files stay until deleted. Public sessions expose their attachments to anyone with the link.                                                                                                                                                                                                                                                                                                                                                                                                     |

These rules concern the named consumer products rather than every service made by the same company, and they explain why “I pay for Pro” is not enough information: a paid personal subscription can still follow consumer rules instead of the commercial agreement sold to organizations.

## Business and API accounts are different products

Business plans cost more partly because organizations need written controls, administrator settings and a clearer answer about training, although “not used to train the model” still does not mean “never processed or stored.”

| Service                   | Published business, enterprise or API rule                                                                                                                                                                                                                                                                                    |
| ------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **OpenAI**                | ChatGPT Business, Enterprise, Edu, Healthcare and the API exclude inputs and outputs from training by default. Many API endpoints can keep data for up to 30 days, while qualifying customers can request tighter or eligible zero-data-retention controls.                                                                   |
| **Anthropic**             | Claude for Work and the API exclude customer inputs and outputs from training by default. Standard API data reaches back-end deletion within 30 days unless a longer-lived feature, separate agreement, safety check or legal requirement applies.                                                                            |
| **Google Workspace**      | Google says chats and uploaded files in the Gemini app are not human reviewed or used to train generative AI models outside the organization’s domain without permission. Gemini is covered by the organization’s Workspace agreement, but Google warns that third-party apps connected to Gemini can follow different terms. |
| **Microsoft 365 Copilot** | Prompts, responses and Microsoft Graph data do not train foundation models. Interaction history follows the organization’s Microsoft 365 retention policies, while external agents can introduce other privacy terms.                                                                                                         |
| **Perplexity Enterprise** | Enterprise data does not train Perplexity or its outside model providers. Session files remain for seven days, although Project files stay until deleted and larger organizations can receive configurable retention.                                                                                                         |

The account badge matters as much as the company name, so anyone handling employer or client data should confirm that they are inside the approved workspace rather than a personal account using the same email address. Administrators can also change retention, disable features or connect outside services.

## Training, storage, human review and deletion are four different questions

Privacy pages become confusing when these ideas are treated as synonyms, because a company can promise not to train on a file while still storing it for the product to work, then remove a chat from your screen before back-end deletion finishes.

| Action                              | What it changes                                                                                | What it does not guarantee                                                                            |
| ----------------------------------- | ---------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------- |
| **Turn off model training**         | Stops eligible future content from being used for model improvement under that product’s rules | It does not erase chat history, remove an upload or stop safety and service processing                |
| **Delete the chat or session**      | Removes the visible conversation and normally begins a deletion process                        | It may not remove a separate Library, Project, repository, Gem, public link or connected-source copy  |
| **Delete the original file**        | Removes the copy on your device, Drive or OneDrive account                                     | It does not remove a copy already uploaded to an AI service                                           |
| **Use Temporary or Incognito mode** | Usually prevents normal history and model-training use while shortening retention              | It does not make cloud processing local, and short safety or legal retention can remain               |
| **Delete the account**              | Starts the provider’s broad account-deletion process                                           | Removal is not necessarily instant, and legal, security, de-identified or backup exceptions may apply |

Feedback is another easy detail to miss, because OpenAI says a conversation attached to thumbs-up or thumbs-down feedback may be used for training even when normal training is disabled, Anthropic can retain the related conversation for up to five years, and Google can human-review Gemini feedback with its associated conversation and files, then retain it for up to three years. If a chat contains something sensitive, do not press a feedback button out of habit before reading what it sends.

## Can a human read an uploaded AI file?

Limited human access is possible on several consumer services, although that does not mean an employee is casually browsing everybody’s PDFs. OpenAI allows a limited number of authorized staff and service providers to access content when needed for abuse, security, support, legal matters or model improvement when the user has not opted out; Google says trained reviewers inspect a subset of Gemini data; Microsoft human-reviews some Copilot conversations for improvement, safety or suspected violations; and Anthropic can review conversations flagged by its safety systems. Perplexity says uploaded files stay private and are used to tailor responses unless the session is shared, but every service should still be judged by its full terms and account controls rather than the word “private” alone.

## Connected apps can send the information somewhere else

This is where the difference between an [AI model, tool, platform and provider](https://theseguysknow.io/ai-model-vs-tool-vs-platform-vs-provider/) stops being a terminology exercise, because the interface on your screen may call another model provider, retrieve a document from cloud storage or send part of the conversation to an outside app that performs an action.

OpenAI says enabled apps can receive relevant chat context, memories and basic device information, with transferred data then handled under that app’s own terms. Google excludes third-party Gemini apps from its Workspace privacy explanation, Microsoft tells organizations to inspect each agent’s terms, and Perplexity says its agreements stop outside model providers from retaining its data or using it for training. Before sending a confidential document through any connector, check which service can read it, whether another copy is stored and which deletion control applies on each side, because disconnecting an app should not be assumed to erase data already transferred.

## What I would upload, redact or keep out

I still use AI for ordinary documents and screenshots because the time saving is real, but I now judge the file by sensitivity rather than whether it feels personal or professional. Public reports, my own drafts, clean product screenshots and anonymized tables are normally reasonable after a quick check, while contracts, client work, financial records, legal correspondence, medical information and private source code need an approved business account or a carefully reduced extract.

For a normal consumer AI account, I would keep these out entirely:

- Passwords, recovery codes, private keys, API keys and authentication files.
- Passports, driving licences, tax documents and complete identity scans.
- Bank statements, card details and unredacted financial records.
- Medical documents that identify a patient.
- Signed contracts, legal case files or correspondence containing names, addresses, signatures and reference numbers.
- Customer databases, confidential client material, unpublished accounts and anything covered by an NDA or employer policy.

Legal and medical questions rarely require the complete original file, so copy the relevant clause or paragraph, replace names with neutral labels, remove addresses, signatures, account numbers and case references, and explain only the facts needed. If a 20-page contract contains one confusing paragraph, the model rarely needs the other 19 pages and everybody’s home address.

A screenshot needs the same inspection as a PDF because browser tabs, email addresses, account names, notifications and file paths can reveal more than the subject you intended to show. Exporting a clean copy also avoids sending comments, revision history or hidden spreadsheet tabs that have nothing to do with the task.

## A 60-second check before you press Upload

1. **Identify the account:** Is this a consumer plan or an approved business workspace with written data terms?
2. **Reduce the file:** Can you send one page, one clause, a crop or anonymized text instead of the complete document?
3. **Remove secrets:** Check names, addresses, signatures, IDs, payment details, health data, passwords, keys, comments and metadata.
4. **Check the route:** Will a connector, custom app, agent or third-party model provider receive any part of it?
5. **Check the controls:** Review training, temporary-chat, retention, project, repository, sharing and deletion settings before the upload.
6. **Use the damage test:** If this file appeared in the wrong hands tomorrow, would the result be embarrassing, expensive, legally serious or dangerous to somebody else? If yes, stop and use a safer route.

## Final Verdict

An AI upload should be treated as sending another copy to a company rather than opening a private document in a local editor, because it may be stored with the chat, placed in a library or project, reviewed in limited circumstances, passed to a connected service and retained after the visible conversation disappears. The exact combination depends on the service, account type and settings you chose.

I have uploaded personal material before despite knowing the risk, so this is not advice written from a spotless privacy bunker. My rule now is to remove whatever the model does not need from ordinary documents and screenshots, while sensitive files stay outside consumer AI accounts unless an approved business product, clear permission and proper written controls make the use sensible. Turning off training is worth doing, but the stronger habit is to send the smallest clean extract that can answer the question, then delete the chat and every separately stored upload when the work is finished.

Policies change, features differ by region and organization settings can override the defaults described here, so verify the linked documentation before handling regulated or highly confidential material. This guide is practical privacy information rather than legal advice.

---

#### Sources

- ****OpenAI:** [Chat and File Retention Policies in ChatGPT](https://help.openai.com/en/articles/8983778-how-are-files-vs-chats-retained?ref=theseguysknow.io); [Data Usage for Consumer Services FAQ](https://help.openai.com/en/articles/7039943-data-usage-?ref=theseguysknow.io); [How your data is used to improve model performance](https://help.openai.com/en/articles/5722486-chatgpt-privacy-policies?ref=theseguysknow.io); [Business data privacy, security and compliance](https://openai.com/business-data/?ref=theseguysknow.io); [Apps in ChatGPT](https://help.openai.com/en/articles/11487775-apps-in-chatgpt?ref=theseguysknow.io).
- ****Anthropic:** [Consumer model-training rules](https://privacy.claude.com/en/articles/10023580-is-my-data-used-for-model-training?ref=theseguysknow.io); [Consumer data retention](https://privacy.claude.com/en/articles/10023548-how-long-do-you-store-my-data?ref=theseguysknow.io); [Commercial model-training rules](https://privacy.claude.com/en/articles/7996868-is-my-data-used-for-model-training?ref=theseguysknow.io); [Commercial data retention](https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data?ref=theseguysknow.io).
- ****Google:** [Gemini Apps Privacy Hub](https://support.google.com/gemini/answer/13594961?ref=theseguysknow.io); [Manage and delete Gemini Apps activity](https://support.google.com/gemini/answer/13278892?ref=theseguysknow.io); [Generative AI in Google Workspace Privacy Hub](https://knowledge.workspace.google.com/admin/generative-ai/generative-ai-in-google-workspace-privacy-hub?ref=theseguysknow.io).
- ****Microsoft:** [Privacy FAQ for Microsoft Copilot](https://support.microsoft.com/en-us/microsoft-copilot/privacy-faq-for-microsoft-copilot?ref=theseguysknow.io); [File upload in Microsoft Copilot](https://support.microsoft.com/en-us/microsoft-copilot/file-upload-in-microsoft-copilot?ref=theseguysknow.io); [Data, privacy and security for Microsoft Copilot](https://learn.microsoft.com/en-us/microsoft-365/copilot/microsoft-365-copilot-privacy?ref=theseguysknow.io).