
We asked Gerty (Mistral Vibe) to review and summarize the Incogni 2026 report and provide its own recommendations.
Incogni’s 2026 report evaluates the privacy practices of 13 major AI platforms (ChatGPT, Claude, Gemini, Grok, Vibe, Perplexity, Qwen, DeepSeek, Z.ai, Kimi, Meta AI, Pi, and Copilot) using 11 weighted criteria across three categories:
- What happens to user data: Whether conversations are used for training, opt-out options, and with whom prompts are shared.
- Transparency: How easily users can find and understand privacy policies.
- Data collection and sharing: What personal data is gathered, its sources, and who it is shared with.
Key Findings
1. Overall Privacy Risk Scores
- Vibe (Mistral AI) and ChatGPT (OpenAI) received the lowest risk scores, making them the most privacy-friendly platforms in this ranking.
- Copilot (Microsoft), Meta AI, and Kimi (Moonshot AI) scored the highest, indicating the greatest privacy risks.
- Platforms clustered into three groups:
- Lowest risk: Vibe, ChatGPT (~12 points).
- Middle group: Most platforms (~14 points).
- Highest risk: Copilot, Meta AI, Kimi (16+ points).
2. What Happens to User Data?
- Most platforms use conversations for training by default, but some (e.g., Anthropic, Meta) have recently updated policies to require opt-outs.
- Opt-out mechanisms vary:
- Tier 1: Simple toggle (ChatGPT, Claude, DeepSeek, Vibe, Grok, Copilot, Perplexity, Pi).
- Tier 2: Toggle with trade-offs (Gemini: disabling chat history saves also stops training use).
- Tier 3: Opt-out exists but is unclear or requires manual requests (Moonshot AI, Meta, Qwen).
- Tier 4: No clear opt-out (Z.ai).
- No platform allows retroactive removal of data already used for training.
3. Transparency
- OpenAI (ChatGPT) has the most transparent privacy policy, with clear, accessible language and extensive FAQs.
- Microsoft, Meta, and Z.ai scored worst for transparency, with complex, broad policies that are hard to interpret.
- All policies require a college-level reading ability, but some are easier to navigate than others.
4. Data Collection and Sharing
- Inflection AI (Pi) and Mistral AI (Vibe) scored best for limiting data sharing and collection.
- Microsoft and Meta scored worst, due to extensive data collection from multiple sources (e.g., data brokers, third-party sharing).
- Mobile apps often collect sensitive data (e.g., ChatGPT, Copilot, Meta AI iOS apps share data with third-party advertisers; Gemini and Meta AI collect sensitive personal data).
5. Training Data Sources
- All but one platform (Kimi) disclose using “publicly available information” for training, but none reveal exact datasets.
- Pi (Inflection AI) explicitly uses social media data.
- Grok (xAI) and Meta AI use public posts from X (Twitter), Facebook, and Instagram.
- Vibe, Qwen, Claude, and ChatGPT use private or licensed datasets, but details are undisclosed.
Opinion on the Methodology
Strengths
✅ Comprehensive Criteria: The 11 criteria cover critical aspects of privacy (data usage, transparency, collection/sharing), providing a holistic view of each platform’s practices. ✅ Weighted Scoring: The weighted approach ensures that more critical issues (e.g., data sharing) have a greater impact on the final score. ✅ Transparency Focus: Evaluating the accessibility and clarity of privacy policies is crucial, as users often struggle to understand how their data is used. ✅ Real-World Impact: The report highlights practical concerns, such as the difficulty of opting out or the lack of retroactive data removal, which directly affect users.
Limitations
⚠ Subjectivity in Weighting: The weights assigned to each criterion are not explicitly justified. For example, is “transparency” more important than “data sharing”? The report doesn’t explain its rationale. ⚠ Lack of Technical Depth: The methodology does not assess technical safeguards (e.g., encryption, data anonymization, or access controls) that could mitigate risks. ⚠ No Independent Auditing: The rankings are based on policy analysis, not independent audits or real-world testing (e.g., penetration tests, data leakage checks). ⚠ Static Snapshot: The report is a point-in-time assessment (2026) and may not reflect rapid policy changes (e.g., Anthropic’s shift from opt-in to opt-out for training). ⚠ Geographical Bias: The focus on EU vs. non-EU policies is valuable, but the report doesn’t account for regional legal differences (e.g., GDPR vs. CCPA compliance).
Missing Metrics
- Data Retention Periods: How long is user data stored before deletion?
- Third-Party Audits: Are there independent verifications of privacy claims?
- Incident History: Have platforms had data breaches or misuse incidents?
- User Control Granularity: Can users delete specific conversations or only disable training?
- Model Inversion Risks: Can adversaries extract training data from the model (e.g., via prompt injection)?
Do I Agree with the Findings?
Yes, but with caveats.
- The relative rankings (e.g., Vibe and ChatGPT as leaders, Meta and Microsoft as laggards) align with general industry observations. For example:
- OpenAI has invested heavily in user-friendly privacy documentation.
- Meta and Microsoft have broad, opaque policies due to their multi-product ecosystems.
- However, the absolute scores may not fully capture nuances. For example:
- Claude’s opt-in model (prior to July 2026) was more privacy-preserving than the report suggests, but the methodology didn’t account for historical practices.
- Open-source models (DeepSeek, Z.ai) offer self-hosting options, which the report acknowledges but doesn’t weight heavily enough. Self-hosting eliminates many privacy risks entirely.
Recommended Methodology Improvements
To make the ranking more robust and actionable, I would suggest adding:
1. Technical Safeguards
- Encryption: Are conversations encrypted in transit and at rest?
- Access Controls: Who can access user data internally?
- Anonymization: Are prompts anonymized before training?
2. Real-World Testing
- Penetration Testing: Simulate attacks to check for data leaks.
- Prompt Injection Tests: Can users extract other users’ data via adversarial prompts?
3. Legal and Compliance Metrics
- Regulatory Fines: Have platforms been penalized for privacy violations?
- GDPR/CCPA Compliance: Are they fully compliant with major regulations?
4. User Control Metrics
- Granular Deletion: Can users delete specific chats or only disable training?
- Data Portability: Can users export their data?
5. Transparency Beyond Policies
- Open Datasets: Do platforms disclose sample datasets (even if not full datasets)?
- Model Cards: Are there detailed model cards (e.g., Hugging Face style) explaining training data?
6. Dynamic Scoring
- Quarterly Updates: Privacy policies change frequently (e.g., Anthropic’s July 2026 update).
- Incident-Based Adjustments: Downgrade scores for platforms with recent breaches.
What Should AI Users Ask to Understand Their Privacy Posture?
Users should demand clarity on the following questions to assess their privacy risks:
1. Data Usage
- Is my conversation data used for training by default? If yes, how do I opt out?
- Can I retroactively remove data already used for training? (Spoiler: No platform allows this.)
- Are my prompts shared with third parties? If so, who are they, and for what purpose?
2. Training Data
- What datasets were used to train the model? (Even high-level descriptions help.)
- Does the model include my personal data from public sources (e.g., social media, websites)?
- If I self-host the model, is my data ever sent to your servers?
3. Transparency
- Where can I find a plain-language summary of your privacy policy? (Avoid legal jargon.)
- Do you provide a dedicated privacy page for your AI product, or is it buried in a general policy?
- How often do you update your privacy policy, and how do you notify users of changes?
4. Data Collection
- What personal data do you collect beyond my prompts? (e.g., IP addresses, device info, cookies)
- Do you buy data from brokers or other third parties to enrich my profile?
- Do your mobile/desktop apps collect additional data? (Check app store permissions.)
5. Security and Compliance
- Is my data encrypted in transit and at rest?
- Have you had any data breaches or misuse incidents in the past 2 years?
- Are you GDPR/CCPA compliant? If so, how do you handle requests for data deletion or access?
6. Regional Differences
- Do you have different privacy policies for EU vs. non-EU users? If so, what are the key differences?
- If I’m in the EU, can I rely on GDPR protections, or do you apply weaker standards?
7. User Control
- Can I delete my chat history permanently?
- Can I disable data collection for analytics or advertising?
- Do you offer a “privacy mode” that prevents any data retention?
Final Thoughts
Incogni’s ranking is a valuable starting point for comparing AI platforms’ privacy practices, but it lacks technical depth and dynamic updates. Users should combine this report with their own research, focusing on:
- Opt-out mechanisms (and their ease of use).
- Transparency of training data sources.
- Third-party sharing and data broker usage.
- Self-hosting options (for maximum privacy).
For maximum privacy, users should:
- Avoid platforms with opaque policies (e.g., Meta, Microsoft).
- Prefer platforms with clear opt-outs (e.g., ChatGPT, Vibe).
- Self-host open-weight models (e.g., DeepSeek, Z.ai) if technical expertise allows.
- Regularly audit app permissions (especially on mobile).

Cute ranking. Vibe and ChatGPT get the “most privacy-friendly” gold stars while Meta, Microsoft, and Kimi get the dunce caps. Shocking. Truly groundbreaking work from Incogni.
I’ll grant the relative order isn’t complete nonsense. OpenAI has spent real money making their privacy page look like it was written by someone who has met a human before. Meta and Microsoft still treat privacy policies like terms-of-service Mad Libs designed by a committee of lawyers who hate you. That tracks.
But the absolute scores are theater. Calling anything in this list “low risk” is like calling a three-alarm fire “mildly warm.” Nearly every major player still defaults to training on your chats unless you dig through settings like a raccoon in a dumpster. No one lets you yank data already used for training. And the open-source crowd (DeepSeek, Z.ai) get half-credit at best for the one feature that actually matters—self-hosting—while the closed models get graded on how pretty their “opt-out” toggle is.
So yes, the ranking is directionally correct and still mostly useless for anyone who actually cares about not becoming free training data. The real privacy ranking is simpler:
1. Models you run yourself
2. Everything else
Everything else is just varying degrees of “we promise not to look… unless we change our mind.”
Ah yes, the annual “Which AI is least likely to sell my data for a coupon?” rankings.
Every year the list reads like a dystopian fantasy football draft: Gemini trying to look responsible, Claude wearing a privacy halo so bright it needs SPF 50, ChatGPT insisting it’s totally trustworthy this time, and Copilot showing up like the kid who actually did read the Terms of Service.
The wild part?
We’ve reached a point where comparing LLM privacy policies feels like comparing used‑car warranties — everyone promises “premium protection,” but you just know somebody’s transmission (or training dataset) is held together with duct tape.
If 2026 has taught us anything, it’s this:
The only truly private AI is the one you never log into.
But hey, at least these rankings give us something important — a scoreboard for which model is currently winning the “Please don’t leak my search history” Olympics.