Three You Can Take Back. One You Can't.

When you tell an AI something personal, it lands in four different places, the conversation, product memory, provider systems, and training, and only three of them let you take it back.

4:20 video5 min readWatch on YouTube

Someone assumes they can just delete what they told an AI. That is the wrong question to ask, because there is not one place that detail goes, there are four, and only three of them let you take it back.

Four places, not one

Take a single sentence containing three ordinary facts: you have a partner, they hike, you live near Denver. None of it is alarming on its own, but together it is enough to place you roughly on a map. That sentence does not go to one destination. It lands in four places at once, stacked on top of each other, and each level down keeps less of what you said while keeping it for longer. This four-level breakdown borrows a taxonomy that Anthropic's education team laid out, and the framing is correct as far as it goes. What it does not draw out on its own is the axis that actually determines how careful you should be: not where the data goes, but which of these places you can walk back out of.

Level one: the conversation itself

The first level is the conversation itself. While the chat window is open, the model is working with whatever you have told it. When you close that window, it is not quietly holding onto those facts somewhere else, because it was never storing them anywhere beyond the conversation to begin with. Open a new chat tomorrow and it starts blank. The model has no idea your partner hikes and no way to find out unless you tell it again. This door swings both ways at no cost. Close the tab, and the detail is gone from the only place it was ever living. The overwhelming majority of what people type into an AI never goes further than this.

Level two: product memory

The second level is where the language around "memory" gets loose, and it is worth being precise about the mechanism rather than the marketing. The model itself did not remember you. A file attached to your account did, and that file gets read back into a fresh chat before you finish typing your first word. That distinction matters because a memory you can open is a memory you can edit. In most products, you can read that file, change a line in it, clear it entirely, or switch the feature off. This door still swings both ways, but someone else set the latch before you arrived, memory may be on by default or waiting for you to switch it on, and that is a setting worth checking rather than assuming.

Level three: provider systems

The third level is not the model at all. It is the provider's own operational machinery: keeping the service running, reviewing for abuse, fixing bugs, doing research, and in some cases supporting commercial uses. Your facts sit inside that machinery for a retention period that is real and usually written down somewhere, but it is not a period you set yourself. This door still opens both ways, technically, past a clock you do not wind. You can request deletion, but you do not control the interval. This is the first level where being "in control" stops meaning you can undo something immediately and starts meaning you can file a request and wait for it to take effect.

Level four: training

The fourth level is training, and it is the one that does not swing back open. Some providers use conversations to improve future models. Personal details are generally stripped out first, and that hedge, "generally," belongs to the provider, not to any guarantee you can rely on. Once a conversation is used this way, your sentence stops being a sentence and becomes a tiny statistical adjustment to how likely certain words are to follow other words. Nobody can read your original words back out of a trained model, which is a genuine form of reassurance. But it is also the one door that does not open backward: you cannot untrain a model on a conversation it has already learned from. Where providers do train on conversations, most offer an opt-out toggle, and it is worth finding it, but understand what it actually buys you. It protects every conversation after you flip it. It does nothing for any conversation before.

Pricing the worst case

Four levels, three reversible doors, one that is not. That gives you a simple rule: price what you share against the least reversible place it could end up, not the place it is most likely to end up. Most of what you type never leaves level one, but deciding as though it might is the safer habit, and it costs nothing. If a tool does not actually need someone's real name to do its job, do not give it the real name. A placeholder works exactly as well when you are just asking for help rewording an email.

Key takeaways

  • Data you share with an AI lands in four stacked places: the conversation, product memory, provider systems, and training.
  • The conversation itself and product memory are both fully reversible, close the tab or edit and clear the memory file.
  • Provider systems hold data on a retention period you can request deletion against but cannot directly control.
  • Training is the one level that does not reverse; you cannot untrain a model on a conversation it has already learned from.
  • Opt-outs from training are forward-looking only, they protect future conversations, not past ones.
  • The right question to ask is which of the four levels you could reverse tomorrow, not where the data technically lives.

Try it yourself

Open the privacy and data settings for the AI tool you use most and check four specific things: whether it keeps conversation history, whether it has a memory feature and whether it is switched on, what retention period it states, and whether training on your conversations is on or off. Then ask yourself which of those four you could reverse tomorrow, and which one you could not, that last question is the whole exercise, and it takes about five minutes to run against your own account. This walkthrough is part of the Claude Basics series from Humanitarians AI, aimed at giving people a clear, mechanism-level understanding of how their everyday AI tools actually handle their data.

Chapters

  1. 0:00The naive framing: can I just delete it?
  2. 0:08Four places, stacked — not one
  3. 0:44Level 1 — the conversation (reversible)
  4. 1:16Level 2 — product memory (reversible, but the latch was already set)
  5. 1:54Level 3 — provider systems (partial — a clock you don't set)
  6. 2:29Level 4 — training (the one that doesn't swing)
  7. 3:10What follows: price the worst case
  8. 3:36Carry-out
  9. 3:53Your turn
  10. 4:15Outro
Full transcript(auto-generated, with timestamps)

The naive framing: can I just delete it?

[0:00]Someone assumes they can just delete what they told an AI. Wrong question. There are four places and only three let you take it back. So, which one can't you undo?

Four places, stacked — not one

[0:08]Start with the detail. One sentence, three facts. You have a partner, they hike, you live near Denver. Harmless on its own. Also enough to put you roughly on a map. Those three facts don't go to one place, they go to four and the four are stacked. Each level is narrower than the one above it because each level keeps less of what you said and keeps it for longer. Anthropic's education team laid these four out and the taxonomy is correct. I'm borrowing it. What they don't draw is the axis that actually decides how careful you should be. Not where does it go, which of these can I walk back out of? Every level has a door. Three of them open both ways.

Level 1 — the conversation (reversible)

[0:44]Level one is the conversation itself. While the window is open, the model is working with your three facts. When the window closes, it isn't holding them anywhere because it wasn't holding them anywhere else to begin with. Open a fresh chat tomorrow and it starts blank, not discreet and empty. On its own, the model has no idea your partner hikes and no way to find out unless you tell it again. So, the first door swings both ways. Close the tab and the detail is gone from the only place it was living. Level one costs you nothing. Almost everything you ever type stops here.

Level 2 — product memory (reversible, but the latch was already set)

[1:16]Level two is where the language gets loose. So, let's ask for the mechanism instead of the marketing. Here's what that phrase hides. The model did not remember you. A file on your account did and that file gets read into the blank chat before you finish typing your first word. That distinction isn't pedantry, it's the whole point. A memory you can open is a memory you can edit. In most products, you can read the file, change a line, clear it, or switch the whole thing off. Second door still swings both ways, but somebody set the latch before you got here. Depending on the product, memory is on by default or waiting to be switched on. That's a setting and settings are checkable.

Level 3 — provider systems (partial — a clock you don't set)

[1:54]Level three isn't the model at all. It's the provider's own machinery keeping the service up, reviewing for abuse, fixing bugs, research, and depending on the company, commercial uses, too. Your three facts sit in that machinery for a retention period, and here is the part worth saying plainly. The period is real, it's usually written down, and it is not yours. Third door still opens both ways past the clock you don't wind. You can ask for deletion, you don't set the interval. But notice what changed. This is the first level where being in control stops meaning you can undo it and starts meaning you can file a request and wait.

Level 4 — training (the one that doesn't swing)

[2:29]Level four is training. Some providers use conversations to improve the next model. Personal details are generally stripped out first, generally, and that hedge belongs to them, not to me. And then your sentence stops being a sentence. It becomes a very small adjustment to how likely certain words are to follow other words, not a record of you, a pattern. That's offered as reassurance, and it is one. Nobody can read your words back out. It's also the door that doesn't swing. You cannot untrain a model on a conversation it has already learned from. Where providers train on conversations, most let you opt out, and you should go find that toggle, but understand what it buys. It protects every conversation after you flip it, not one before.

What follows: price the worst case

[3:11]Four levels, three doors that open both ways, one arch. That gives you a rule to work from. Price what you share against the least reversible place it could reach, not the most likely one. Most of what you type never leaves level one. Decide as though it might. And the cheapest habit on the list costs you nothing. If the tool doesn't need the real name to do the job, don't give it the real name. Rewording an email works exactly as well with a placeholder in it.

Carry-out

[3:36]Four places, and they are not the same kind of place. The conversation forgets when you close it. Memory is a file you can open and edit. Provider systems hold it on a clock you don't set. Training turns it into a pattern, and that one is permanent. Opt-outs are forward-looking. Everything else is a setting you can go check in about 5 minutes. Your turn,

Your turn

[3:54]Open the privacy and data settings for the AI tool you use most and find four specific things. Whether it keeps conversation history, whether it has a memory feature and whether it's on, what retention period it states, and whether training on your conversations is on or off. Then ask which of those four you could reverse tomorrow and which one you couldn't. That last clause is the whole exercise. You'll find the first three are toggles and the fourth is a date.

Outro

[4:15]Three you can take back when you can't lie them in for bear.

More from HAI

Humanitarians AI Lyrical Literacy Project