Is ChatGPT End-to-End Encrypted? What That Means for You

Is ChatGPT End-to-End Encrypted? What That Means for You

No. ChatGPT encrypts your messages on their way to OpenAI and while they’re stored on its servers, but it isn’t end-to-end encrypted. OpenAI holds the keys, and its servers read your message in plain form, because the model has to read your words to answer them. The same is true of Gemini, Claude, Copilot and nearly every cloud chatbot. If you want AI chat where no company can read your conversation, the model has to run on your own device.

What does end-to-end encryption actually mean? #

“Encrypted” gets used for several very different protections:

TermWhat it protects againstWho can still read your messages
Encryption in transit (HTTPS)Someone snooping on your Wi-Fi or networkThe company at the other end
Encryption at restSomeone stealing the company’s disksThe company, which holds the keys
End-to-end encryptionEveryone except the sender and recipient, including the companyOnly the people in the conversation

Messaging apps like Signal, WhatsApp and iMessage use end-to-end encryption between people: the service carries the message but can’t read it. Cloud chatbots use the first two layers. Those matter, but the company running the chatbot can still read what you wrote.

Why can’t a cloud chatbot be end-to-end encrypted? #

In an encrypted chat between two people, the “ends” are your phone and your friend’s phone. In a chatbot, the other end is the company’s server. The AI model runs there, and it needs your text in readable form to generate a reply. So the company’s computers must see your message, and whatever the company allows, such as logging, safety review, human review or training, can happen to it.

There are designs that narrow who can see it. Apple’s Private Cloud Compute, which handles larger Apple Intelligence requests, is built so that data is used only to answer the request, isn’t stored afterwards, and runs software that outside researchers can inspect. That’s a meaningful step beyond an ordinary cloud chatbot, but your request still leaves the phone and is readable by the server that answers it. We explain it in is Apple Intelligence private.

Who can see your ChatGPT conversations? #

Because chats are readable on the company’s side, a few groups can end up seeing them:

  • The company’s systems, for safety checks and, depending on your settings, to improve its models.
  • Human reviewers. Google, for example, says a subset of Gemini chats is reviewed by trained reviewers. See do humans read your AI chats for how each service handles it.
  • Courts and law enforcement, through subpoenas and other legal process. We cover that in can your ChatGPT chats be used in court.
  • Attackers, if the company’s systems or your account are breached.

How do the main chatbots compare? #

ServiceEnd-to-end encrypted?Notable privacy details
ChatGPTNoStored on OpenAI’s servers; a data control setting decides whether chats improve its models
GeminiNoSubset reviewed by humans; with Keep Activity off, chats are still kept for 72 hours
ClaudeNoKept 30 days if you decline training, five years if you allow it
Apple IntelligenceNo, but Private Cloud Compute doesn’t store requestsOn-device requests never leave the phone
On-device AI appNot needed: nothing is transmittedChats exist only on your phone

A trap with encrypted messengers #

End-to-end encryption protects a message between you and the person you sent it to. The moment you copy that message into a cloud chatbot, to summarize a group chat or ask how to reply, it’s no longer protected by that encryption. It’s now on the chatbot company’s servers, under its policies. The same applies to AI features built into messaging apps: an AI can only answer a message it can read, so check how the app describes where that processing happens.

This matters most when the message belongs to someone else, like a friend’s worries, a colleague’s details or a family argument.

How to get AI chat no company can read #

Run the model on your phone. When the AI runs on your own device, there’s no server in the conversation, so there’s nothing for anyone else to decrypt, store or review.

Personal LLM works this way. It runs open models such as Qwen 3.5, Gemma 4, Ministral 3 and GLM 4.6V Flash on your phone’s own chip. You download a model once from Hugging Face, and after that your chats, the photos you attach and the documents you ask about never leave the phone, even with the network on. There’s no account and the app has no server. The only network traffic is the model download and, in the free version, ads from Google AdMob while you’re online.

Your phone’s own protection then does the rest. Modern iPhones and Android phones encrypt their storage and tie it to your passcode, so a strong passcode is what guards your local chats.

The honest trade-off: a phone-sized model is less capable than ChatGPT on hard problems and can’t search the web. For drafting replies, thinking through something personal, or summarizing a sensitive message, it’s usually enough, and it’s the only setup where no company can read the conversation. For other privacy-focused options, see private ChatGPT alternatives.

If you keep using cloud chatbots #

  1. Turn off model training in each service’s data or privacy settings.
  2. Use temporary or no-history chats for sensitive questions, knowing they’re still kept for a while.
  3. Leave out names, numbers and identifying details. Our guide to keeping personal data out of AI chatbots shows how.
  4. Protect your account with a strong password and two-factor authentication, since anyone in your account can read your history.
  5. Delete what you don’t need. See how to delete your data from AI chatbots.

Frequently asked questions #

Is ChatGPT encrypted? #

Yes, in transit and at rest: your messages are protected on the way to OpenAI and on its servers. But it isn’t end-to-end encrypted, so OpenAI can access your conversations.

Can OpenAI read my chats? #

OpenAI’s systems process your chats in readable form to answer them, and the company can access stored conversations under its policies, for example for safety, legal requests or, if your settings allow it, improving its models.

Is there an end-to-end encrypted AI chatbot? #

Not in the usual sense for cloud chatbots, because the server has to read your message to reply. Some services limit what the server keeps or who can inspect it. The way to make sure no company can read your chats is to run the model on your own device.

Is Apple Intelligence end-to-end encrypted? #

No, but on-device requests never leave your phone, and Apple says Private Cloud Compute uses your data only to answer the request and doesn’t store it. Requests you send to ChatGPT through Apple Intelligence are handled by OpenAI instead.

Are chats in a local AI app encrypted? #

They’re stored on your phone, which modern iPhones and Android phones encrypt when you use a passcode. More importantly, they’re never sent anywhere, so there’s no copy on a company’s server to protect in the first place.