Which AI chatbot is worst for privacy? In Incogni's 2026 Gen AI and LLM Data Privacy Ranking, Microsoft Copilot, Meta AI, and Moonshot AI's Kimi posted the highest privacy-risk scores of the 13 chatbots tested, which puts them at the bottom of the table. The safest AI chatbot by the same yardstick was Mistral's Vibe, with ChatGPT a close second on the strength of the clearest privacy policy in the study.
That result surprises most people, so read it slowly. The chatbot with the scariest reputation, ChatGPT, scored as one of the least risky, while the tool many offices trust by default, Microsoft Copilot, landed dead last. The ranking does not measure whether a bot is good or evil. It measures how much of your data each platform collects and shares, and how honestly each one tells you about it. Those are two different questions, and mixing them up is why the headlines feel backwards.
So what does privacy risk mean in this context? Treat it as the odds that something you share ends up somewhere you did not expect: fed into training a model, passed to advertisers, or tied to a profile that follows you across the web. A low-risk chatbot narrows those odds and is honest about the ones that remain. A high-risk one widens them and often buries the terms where you will never read them.
Which AI chatbot is worst for privacy in 2026?
Microsoft Copilot ranked worst for privacy in 2026, followed closely by Meta AI and Kimi. Incogni, a data-removal service owned by Surfshark, scored 13 chatbots against 11 weighted criteria using data gathered between June 15 and July 6, 2026. The criteria fall into three groups: what happens to the data you feed a bot, how the platform collects and shares data more broadly, and how clearly its privacy policy explains all of it. The full field was ChatGPT, Claude, Gemini, Grok, Vibe, Perplexity, Qwen, DeepSeek, Z.ai, Kimi, Meta AI, Pi, and Copilot.
- Copilot came last on overall risk. Reviewers flagged that it shares some user data with third-party advertisers and tracks people across other apps and websites, while its privacy policy scored poorly for plain-language clarity.
- Meta AI collects sensitive categories of data, trains on public Facebook and Instagram content, and provides no separate EU privacy framework.
- Kimi makes you email support and verify your identity before you can opt out, and it does not spell out where its training data comes from beyond your own content.
A pattern runs through the bottom of the list: the biggest platforms often carry the biggest risk. When a chatbot is one feature inside a sprawling product empire, your data can flow into advertising, cross-app tracking, and social feeds that have nothing to do with the chat itself. Reach and integration are selling points for the company and a liability for you.
What is the safest AI chatbot for privacy?
Mistral's Vibe was the safest AI chatbot in the 2026 ranking, with the lowest privacy-risk score, and ChatGPT finished second. OpenAI earned the highest transparency marks of any platform tested. Its privacy policy is written so a normal person can follow what happens to their data, helped by a long FAQ section, rather than hiding the details behind legal language. Vibe led overall despite Mistral placing only fifth-lowest for transparency, which shows how differently each platform can behave across the three scoring areas.
The rest of the field mostly clustered in the middle, which is its own warning. Perplexity, Qwen, DeepSeek, and Pi sat between the winners and the worst, and Pi openly admits it uses social media profiles and posts for training. A middle score is not a clean bill of health. It usually means a platform does one thing well, such as offering a clear opt-out, while collecting plenty of account, device, or marketing data elsewhere.
A low privacy-risk score does not mean a chatbot leaves your data alone. It means the company is comparatively honest about what it collects and gives you a real way to opt out. Even the top scorers still train on your conversations by default on their consumer tiers.
The twist: the giant everyone fears beat the enterprise-safe one
Here is the honest contradiction in the data. ChatGPT, the product most people picture when they worry about AI and privacy, scored as one of the safest, while Copilot, the assistant sold as the work-friendly option built into Microsoft 365, ranked worst. Size and reputation did not decide the outcome. Disclosure did. ChatGPT scored well because OpenAI explains its practices clearly and offers a simple opt-out, not because it collects less than everyone else. Copilot scored badly largely because its data handling is spread across Microsoft's huge ecosystem and its policy is hard to read. The lesson is uncomfortable but useful: a familiar brand or an enterprise label tells you nothing about how a chatbot treats your data.
The privacy paradox: popular does not mean protected
The wider pattern the 2026 study exposes is a privacy paradox. The chatbots with the largest audiences and deepest pockets often scored among the riskiest, because their data practices reach across search, social, advertising, and device ecosystems that a standalone tool never touches. Popularity buys polish and convenience. It does not buy restraint with your data, and in the biggest platforms it can work against you.
What the ranking measures, and what it cannot
The ranking measures privacy risk and disclosure, not safety in the way most people assume. A high transparency score tells you the company is upfront, not that your chats stay private. Three findings from the 2026 study make that distinction concrete and apply to every name on the list, including the winners:
- None of the 13 providers disclosed the exact datasets used to train their models. Every one leaned on vague phrases like publicly available information or private datasets.
- No platform lets you remove data once it has already been used for training. Opting out only stops future conversations from being included.
- Nine of the 13 offer a straightforward toggle to stop training, but every policy examined was written at a college-graduate reading level, so most people never find or understand the setting.
ChatGPT vs Gemini vs Claude: how the big three handle your data
If you mostly choose between ChatGPT, Gemini, and Claude, the practical differences come down to defaults and where the off switch lives. All three train on consumer conversations unless you intervene. Claude changed most recently: Anthropic updated its policy in July 2026 so consumer input is used for training unless you opt out, reversing its earlier opt-in approach. Gemini ties training to Google's broader Gemini Apps Activity setting, so turning training off also stops your chats from being saved to your history. Grok sits outside this trio but earns a mention, because xAI trains it on public posts from X, including engagement signals like likes, reposts, and view counts.
| Privacy question | ChatGPT (OpenAI) | Gemini (Google) | Claude (Anthropic) |
|---|---|---|---|
| Incogni 2026 privacy-risk rank | Second-lowest risk, best of the major chatbots | Mid-pack | Mid-pack |
| Trains on your chats by default? | Yes on consumer tiers, with an opt-out | Yes when Gemini Apps Activity is on | Yes since July 2026, unless you opt out |
| How you turn training off | A dedicated toggle in Data Controls | Switch off Gemini Apps Activity, which also stops chat history | A toggle in your privacy settings |
| Privacy policy clarity | Highest transparency score, plain-language FAQ | Training control bundled into a broader activity setting | Readable, but the default flipped to opt-out in 2026 |
| Removes data already used to train? | No | No | No |
What to check and turn off today
You do not need to quit your favourite chatbot to cut your exposure. A few minutes in the settings changes what happens to everything you type next, and it costs nothing.
- Find the training or model-improvement toggle and switch it off. In ChatGPT it lives in Data Controls, in Gemini it sits inside Gemini Apps Activity, and in Claude it is in your privacy settings.
- Check whether turning off training also wipes your chat history, as it does in Gemini, and decide whether that trade is worth it for you.
- Delete old conversations you no longer need, while remembering that deletion does not pull your data back out of any model already trained on it.
- Never paste passwords, government IDs, bank details, medical records, or other people's personal information into any chatbot, no matter how well it ranked.
- On paid or business tiers, confirm the data terms separately, since consumer defaults and enterprise defaults often differ.
Some chatbots, including ChatGPT, offer a temporary chat mode that keeps a session out of your history and out of training. Reach for it whenever a question involves anything you would not want stored, and remember that it does not undo data collected at the account or device level. The habit that protects you most is not a single setting. It is asking, before you hit send, whether this particular thing needs to live inside a company's servers at all.
Treat every chatbot prompt as if a stranger could read it one day. The single most reliable privacy control is deciding what never goes into the box in the first place.
The privacy a chatbot ranking cannot score for you
A ranking can grade how a chatbot treats the text you type into it. It cannot grade what happens to the growing pile of personal things you actually want to keep: receipts, passport scans, voice notes, warranty photos, and screenshots of messages you will need later. Those do not belong in a chat window that trains on your input by default. That is the gap MemX is built for. MemX is a private memory app, not a chatbot in this ranking. You snap or save your documents, photos, voice notes, and messages, then ask questions later and get the answer with the original source attached. It is private by architecture: per-user isolation, encryption at rest, on-device processing where possible, and no training on your data. That is not the same as end-to-end encryption, and it does not need to be to keep your own memory separate from a model's training set. Ask it when your car insurance renews or what the plumber quoted last spring, and the answer comes from your own files rather than a shared model. Used alongside whichever chatbot you prefer, it gives you one place to store what matters that no privacy ranking has to warn you about.
Frequently asked questions
01Which AI chatbot is safest for privacy?
In Incogni's 2026 ranking, Mistral's Vibe scored the lowest privacy risk, and ChatGPT came second thanks to the clearest privacy policy of any platform tested. Both still train on consumer chats by default, so the practical safest option is any of them with the training toggle switched off.
02Is Microsoft Copilot really the worst for privacy?
In the 2026 Incogni study, Copilot posted the highest overall privacy-risk score, ahead of Meta AI and Kimi. It was flagged for sharing some data with advertisers, tracking users across apps and websites, and a hard-to-read privacy policy. That reflects disclosure and data sharing, not the quality of its answers.
03Does Claude train on my conversations?
Yes, by default on consumer tiers since July 2026. Anthropic changed its policy that month so your input is used for training unless you opt out, reversing its earlier opt-in stance. You can turn this off in your privacy settings, but data already used for training cannot be removed.
04Does turning off Gemini training delete my chat history?
It can. Gemini ties model training to Google's Gemini Apps Activity setting, so switching it off also stops new chats from being saved to your history. That coupling is one reason Gemini's controls scored as less clear than ChatGPT's in the 2026 ranking.
05Can I delete data an AI has already trained on?
No. The 2026 study found that no platform lets you remove information once it has been used to train a model. Opting out only prevents future conversations from being included. The safest move is to avoid putting sensitive details into any chatbot in the first place.
