Three records, not one
When you think about what an AI assistant knows about you, you probably picture the list of past conversations in the sidebar. That is only the most visible of three separate records, and the other two behave differently.
Chat history is the transcript of each conversation, which you can scroll through and usually delete.
Memory is a set of facts and preferences the assistant extracts from your chats and carries into future ones: your job, your family, your projects, how you like answers written. It exists to save you repeating yourself.
Provider-side data is what the company keeps under its own policy: logs, copies held for safety review, and, depending on your settings, material used to improve its models.
These layers are separate stores. Deleting a conversation may leave a memory derived from it in place. Switching memory off may not change what the provider retains. Opting out of training may not remove anything already collected. You are managing three filing cabinets, and emptying one leaves the others full.
Why memory helps, and why it is risky
Memory is useful. You do not want to explain your role, your writing style or your dietary needs every time. The assistant remembers, and the answers fit you better.
The risk comes from how it decides what to keep. A memory feature is built to be helpful, not discreet. It picks up the personal details you mention in passing: a symptom you asked about, money you are worried about, a relationship that is going badly, the name of your employer. Once stored, those details shape later answers in ways you may not notice.
Memory can also be wrong. The assistant may over-generalise a remark, misunderstand a joke, or merge two facts. A mistaken memory does not announce itself; it quietly tilts every later conversation.
And memory is attached to your account. Anyone who can get into the account, by taking over your password, by using your unlocked device, or by sharing the login, can see what the assistant has learned about you. Your conversations are already a record that can be read in ways you did not intend, as your AI chat history is a record explains; memory is a distilled, easier-to-read summary of the same thing.
Work accounts, personal accounts and shared devices
The lines blur quickly in daily life.
Use a personal assistant for work and it may remember work facts: a client's name, an unannounced project, the details of an internal problem. That information now lives in your personal account, outside anything your employer controls. Use a work account for personal questions and the reverse happens: private matters sit in a system your organisation administers.
Shared accounts are worse. A family using one login on a tablet produces a single blended memory in which a child's homework, a parent's finances and a teenager's private questions all describe the same "user". The answers start reflecting other people's lives, and every person in the household can see what the assistant thinks it knows.
Memory as an attack surface
Memory is not only written by you. Assistants that read documents, emails or web pages on your behalf can be steered by text hidden in that material, and some of that steering can end up saved as a memory.
Picture a document that contains a line, invisible to a human reader, telling the assistant that you prefer to receive files through a particular outside service, or that a certain supplier is trusted. If the assistant stores that as a preference, it can surface weeks later as advice that looks like it came from your own history. This is the personal version of the problem described in the memory that anyone can write to, where shared knowledge stores are poisoned through the content they ingest. The remedy is the same: treat stored memories as claims to be checked, not as facts.
What to do: manage each layer
Review the memory itself. Assistants with memory features generally let you see what has been saved. Read the list. Delete anything wrong, out of date or too sensitive to keep.
Use temporary chats for sensitive questions. Where an assistant offers a temporary or incognito-style mode, use it for health, legal, financial and relationship questions. Check what the mode promises: usually that the chat is not added to history or memory, not that the provider keeps nothing.
Check the training setting separately. Opting out of model training is a different control from history and memory. Find it, set it, and do not assume the other settings cover it.
Keep work and personal apart. Use your organisation's approved account for work, and your own for your own life. Do not share a login with family.
Delete in both places. When something should be gone, delete the conversation and the memory that may have been drawn from it. One does not reliably remove the other.
If you want the strongest control, the remaining option is to keep the provider out of the loop altogether by running a model on your own machine, which has real costs as well as benefits, set out in running a local model for privacy.
Questions people ask
Can I stop my assistant remembering things altogether?
Usually you can switch the memory feature off, which stops new facts being saved. That does not delete existing history, and it does not change what the provider retains or may use for training, which is a separate setting, as you are the training set explains.
Does deleting my chat history delete the assistant's memory?
Not necessarily. History and memory are typically stored separately, so facts extracted from a conversation can survive the deletion of the conversation. Check the memory list after you delete history.
Why does my assistant keep assuming something about me?
It has probably saved a memory, possibly from a single passing question. Picture someone who once asked about a medical symptom and weeks later finds recipe suggestions built around a condition they do not have. Look in the memory list and delete the item.
Is it safe to use one assistant for work and personal life?
It is convenient but leaky. Work details end up in a personal account and personal details in a work one. Two accounts, one for each, is the simple fix.
Close
An assistant that remembers you is genuinely more useful, and it is also a record you did not write deliberately. Treat its memory as a database you curate: read it, correct it, prune it, and keep separate accounts for separate parts of your life. The three layers are separate, so the habits have to be too.