Skip to content

Blogs

From Our Blog

Check our some recent articles and posts from our blog.

AI chatbot privacy: What your AI may know about you

You probably tell an artificial intelligence chatbot things you would never post publicly. Maybe you ask about a health concern. Perhaps you need help sorting through a financial decision or dealing with something happening at work. Because the conversation feels one-on-one, it can be easy to forget how personal it has become.

Now, AI companies are giving their assistants more ways to remember what you tell them. In some cases, AI can also draw from activity beyond a single conversation. That raises a bigger privacy question. What happens when an AI assistant can build a more detailed understanding of you over time?

The answer depends on the service you use and the settings you choose. Your information may help personalize future responses. In some cases, your AI activity can also influence recommendations or advertising.

New! Free live CyberGuy class: Protect Your Money From Today’s Biggest Threats

Join us Saturday, Aug. 29, at 10 a.m. ET for a free CyberGuy LIVE class covering five simple steps to help defend yourself against AI scams, fraud, identity theft and financial hacks. Kurt "CyberGuy" Knutsson will explain how to set up bank alerts, strengthen your account logins, protect your phone number, freeze your credit and help secure your retirement savings against unauthorized transfers. No technical experience is needed. You’ll also receive our financial protection checklist, and every registrant will get a link to the class recording afterward.

Reserve your free spot today at CyberGuyLive.com.

WHAT YOUR INTERNET PROVIDER, WEBSITES AND ADVERTISERS SEE

For years, one of the biggest AI privacy questions has been whether companies use your conversations to train future models. That still matters. However, training is only part of the picture. AI assistants can use memory to personalize future conversations. Some can draw context from connected services. Others can use certain AI interactions to help decide what content or ads you see.

So, turning off model training does not necessarily turn off memory or every form of personalization. For example, OpenAI has separate controls for model training, memory and advertising personalization. Meta also has its own rules about how interactions with Meta AI can influence content and ads.

We have previously covered the dangers of over-sharing with AI tools. As these assistants learn more about us, being selective about what you share becomes even more important. The more information an AI service can connect about you, the more personalized it can become. That can be useful. It can also create a much more detailed digital picture of your interests, routines and concerns.

OpenAI added Computer History to the ChatGPT desktop app for macOS on Aug. 13. The optional feature lets ChatGPT and Codex use selected activity from apps and websites as context. Instead of capturing screenshots or screen recordings, OpenAI says Computer History records interaction events. It also excludes private browsing.

However, Computer History isn’t available to every ChatGPT user. OpenAI currently offers it to Pro, Business and Enterprise users. Business and Enterprise administrators must enable access before individual members can choose to turn it on. The feature is off by default.––

You can decide which apps and websites contribute information. You can also pause collection, inspect your timeline and delete history. Computer History requires Memories to work.

There are some privacy details worth knowing. OpenAI says temporary interaction-event files remain on your Mac for up to 48 hours. The company processes those events on its servers to generate memories. It says it does not retain the temporary event files after processing, unless required by law, and does not use those files for training.

Generated memory files stay on your Mac until you delete them. OpenAI also says those files are plain-text Markdown files and Computer History does not encrypt them itself. Other programs running under your macOS user account may be able to access them. That makes the feature useful, but it also gives you another reason to exclude sensitive apps and websites.

Google is also expanding what can become part of your Search Services History. If Search Services History and its Save Media setting are enabled, Google can save media from your Search interactions. That can include images, files and audio or video recordings you upload or create while using supported Search services.

Google says saved media can help personalize your experience. The company may also use it to develop and improve its AI models and other technologies. If Google selects saved media for AI training, it says it disconnects that media from your Google Account first. Google says training data may then remain for up to four years. It also says it uses filters designed to remove identifying or sensitive personal information.

However, you have controls. Turning off Save Media stops Google from saving media from future Search interactions to your Search Services History. Google says future media will then stay out of generative AI training unless you submit it as feedback.

Previously saved media does not disappear when you simply turn the setting off. You need to delete it separately if you want it removed from your account. Media already selected for AI training may remain in Google's training systems after it has been disconnected from your account. That is a good example of why changing a privacy setting and deleting previously collected data are not always the same thing.

Meta takes a more direct approach to using some AI interactions for personalization. The company announced in 2025 that interactions with its generative AI features could become signals for the content and ads people see across Meta products. Those changes took effect on Dec. 16, 2025, in most supported regions. For example, Meta says chatting with Meta AI about hiking could signal that you are interested in hiking. As a result, you could later see related recommendations or advertisements.

Meta places limits around certain sensitive subjects. The company says it does not use information from AI conversations about health or political views to show you ads. Meta also excludes religious views and several other sensitive categories from ad personalization.

Still, regular Meta AI interactions can become another source of information used to personalize your experience. That makes it worth checking your Meta privacy and ad settings before sharing something personal.

DEM SENATOR PRESSES OPENAI, ANTHROPIC FOR ANSWERS IN AI HACKING PROBE

Meta has also taken a different approach for people who want a more private AI conversation. On May 13, 2025, Meta announced Incognito Chat for Meta AI on WhatsApp and in the Meta AI app. The feature is rolling out over several months, so it may not yet appear for everyone.

Meta says Incognito Chat processes conversations inside a secure environment that the company itself cannot access. It also says those conversations are not saved, and messages disappear by default. That gives you a very different privacy experience from a regular Meta AI conversation.

We took a closer look at the feature in our guide to Meta AI's private Incognito Chat. If you have the feature, it is worth considering whenever the subject is especially personal.

Apple uses a more device-centered architecture for Apple Intelligence. When you make an Apple Intelligence request, an on-device model first determines whether your device can handle the task itself. If the request needs a larger model, Apple can send relevant information to Private Cloud Compute.

Apple says Private Cloud Compute receives only the information needed to complete the request. According to Apple, the content isn’t stored or made accessible to Apple. The system processes it for the request and does not retain it afterward. However, those protections apply to Apple's own Apple Intelligence system.

Apple also lets you send certain requests to third-party services such as ChatGPT. If you use ChatGPT through Apple's integration without signing into a ChatGPT account, OpenAI says it does not receive your IP address, store your requests or use them to train its models.

The situation changes if you connect your ChatGPT account. In that case, your existing OpenAI account settings apply. Your interactions may also appear in your ChatGPT history depending on your settings. So, even inside Apple Intelligence, pay attention to which AI service is actually handling your request.

Advertising inside AI conversations is already here. OpenAI began testing ads in ChatGPT in the U.S. on Feb. 9. Eligible Free and Go users can see ads in regions where the program is available. Plus and Pro plans remain ad-free, along with Business, Enterprise and Education plans.

OpenAI also offers Free users an ad-free option with reduced usage limits and reduced access to some tools. The privacy controls around those ads are especially relevant here. OpenAI says ads can take the context of your current conversation into account. If you enable personalized ads, past chats and memory can also contribute to ad relevance.

However, OpenAI says advertisers do not receive your conversations, chat history or memories. The company says it does not sell your data to advertisers. Advertisers receive aggregated performance information such as views or clicks. OpenAI also says ads do not influence ChatGPT's answers and remain separate from the response.

You can turn off ad personalization under ChatGPT's Ad Controls. If you do, OpenAI says ads can still use the context of your current chat, but other chat threads and memory will not inform the ads you see. That makes advertising another privacy setting worth reviewing separately from model training.

HALLUSQUATTING AI ATTACK COULD HIJACK YOUR COMPUTER

The U.S. still does not have one comprehensive federal privacy law governing how all companies collect and use personal data. Instead, federal sector-specific laws exist alongside a growing collection of state privacy requirements. Existing consumer protection laws still apply to AI companies.

The Federal Trade Commission has warned AI companies that privacy and confidentiality promises carry legal consequences. The agency has said deceptive or unfair data practices can violate existing consumer protection laws. The FTC has also investigated consumer-facing AI chatbots, including their advertising, safety and data-handling practices. So, company privacy policies matter. They tell you what a service says it can do with information you may consider deeply personal.

You do not need to give up AI tools to protect your privacy. However, you should decide how much information each service really needs before you start typing.

Treat a general-purpose chatbot differently from a private notebook. Avoid entering passwords or Social Security numbers. Do not paste complete banking or investment account details either. If you upload a document, review it first. Remove information the chatbot does not need.

ChatGPT's Temporary Chat does not use existing memories or create new ones. OpenAI also says Temporary Chats do not appear in your history or train its models. OpenAI says Temporary Chats are deleted from its systems after 30 days. Meanwhile, Meta is rolling out Incognito Chat for supported Meta AI users. Meta says those conversations are not saved. Use these modes when you do not want a conversation feeding future personalization.

OpenAI now lets you review a Memory summary under Settings > Personalization > Memory. You can also ask ChatGPT what it remembers about you. OpenAI says the summary may not display every detail the system can draw from your past conversations. If you find something you do not want remembered, remove it. Keep in mind that deleting one memory may not erase every source containing that information. OpenAI says fully removing information can require deleting related chats, files or other sources as well.

On the web, go to Profile > Settings > Data Controls. Then turn off Improve the model for everyone. OpenAI says your conversations will remain in your chat history, but new conversations will not train its models. The setting applies across your account. We also have a broader walkthrough showing how to opt out of AI data collection in popular apps.

If you use Google's AI-powered Search features, review Search Services History in your Google Account. Then look for the Save Media setting. Turning Save Media off prevents future media from being saved to that history. Google says it also prevents future media from being used to train its generative AI models unless you submit feedback. Remember to review previously saved material too. Turning the switch off does not automatically delete what is already there.

AI becomes far more personal when it can reach information outside the conversation. So, periodically review connected apps and services. Remove connections you no longer need. If you use ChatGPT, memory can also include relevant information accessed through connected apps when that feature is enabled. You should also protect the account itself. Our guide on how to lock down your ChatGPT account walks through additional security controls.

Do not assume that disabling AI training also turns off advertising personalization. OpenAI separates its training, memory and ad controls. Meta also provides its own ad preference controls. Take a few minutes to review each one. The more AI services know about you, the more valuable those settings become.

AI gets much more useful when it remembers who you are. I can see why people want that. Repeating your preferences every time you open a chatbot gets old fast. An assistant that remembers your work or picks up where you left off can save a lot of time. Still, I would not treat personalization as an automatic yes. We're entering a period when the information surrounding an AI conversation can become almost as valuable as the prompt itself. Your memories, connected services and activity can give these systems a much deeper picture of your life. Advertising adds another layer. OpenAI now says past chats and memories can help personalize ads when you allow it. Meta already uses certain AI interactions as signals for content and advertising. For me, the safest approach is to give an AI assistant the context it needs without handing over everything it could possibly learn. Check what it remembers. Review the services you connected. Then decide whether the convenience is worth the added exposure.

Would you be comfortable with an AI assistant knowing years of your conversations if it made the service much more useful, or is there a point where personalization becomes too personal? Let us know by writing to us at CyberGuy.com

Sign up for my FREE CyberGuy Report

Copyright 2026 CyberGuy.com. All rights reserved.

Your bank may stop texting you six-digit codes

If you bank online, you probably know the routine. You enter your password and then wait for a six-digit code to arrive by text. That extra step is supposed to help prove you are really you. Unfortunately, scammers have learned how to turn those codes against us.

A fake bank representative may call and persuade you to read the code aloud. A phishing site can trick you into typing it in. A SIM-swap attack can give a criminal control of your phone number, potentially putting those texted security codes within reach.

The Federal Trade Commission says people reported losing $15.9 billion to fraud in 2025, compared with $12.5 billion in 2024. Imposter scams were the most frequently reported fraud category in 2025, accounting for more than $3.5 billion in reported losses.

Now, a new type of phone-based verification could eventually make those texted codes much less common. Glide.id has launched the public beta of MagicalAuth, a cryptographic authentication system available across AT&T, T-Mobile and Verizon on iOS and Android. Banks and other services still have to integrate the technology before you would encounter it during a login.

Here's how the system works and what it could mean for the way you log in to your bank down the road.

New! Free live CyberGuy class: Protect Your Money From Today’s Biggest Threats

Join us Saturday, Aug. 29, at 10 a.m. ET for a free CyberGuy LIVE class covering five simple steps to help defend yourself against AI scams, fraud, identity theft and financial hacks. Kurt "CyberGuy" Knutsson will explain how to set up bank alerts, strengthen your account logins, protect your phone number, freeze your credit and help secure your retirement savings against unauthorized transfers. No technical experience is needed. You’ll also receive our financial protection checklist, and every registrant will get a link to the class recording afterward.

Reserve your free spot today at CyberGuyLive.com.

YOUR FAMILY COULD BE ONE PHONE CALL FROM A BANK SCAM

Your bank sends a texted one-time password, often called an SMS OTP, to your phone and expects you to enter it to prove you have access to that number. The problem is that the code passes through your hands. "A texted code is a shared secret," Eran Haggiag, founder and CEO of Glide.id, told CyberGuy. "It gets created, sent across the network, and then a person has to read it and type it in, and every one of those steps is a place it can be intercepted or tricked out of someone."

MagicalAuth takes a different approach. Rather than sending you a code, Glide says the system relies on cryptographic credentials associated with the SIM or eSIM in your phone. Eran said, "It relies on a secret that's built into the SIM in your phone and never leaves it, similar to the chip in a credit card."

During authentication, the bank or service can use the carrier network to confirm that the expected SIM is present instead of asking you to relay a secret. "That's what lets the carrier confirm it's really your SIM," Eran said.

Glide says each SIM contains a carrier-issued cryptographic key. MagicalAuth uses that key to answer a mathematical challenge during authentication. "There is no app to download, no setting to change, and nothing for the consumer to enroll in or configure," Eran told CyberGuy.

Instead, the bank or service integrates the system on its side. The first time you encounter it, Eran says you would see a consent screen explaining that your phone number and possession of your device are being used to verify your identity. After that, the process is designed to happen behind the scenes. Eran said that, unlike SMS, "there is no code sent and nothing to type in."

"After that, verification happens quietly in the background in a fraction of a second, so the experience is faster and smoother than waiting on a text," he said. For you, that could mean fewer moments spent staring at your Messages app waiting for a bank code to arrive.

A SIM-swap scam raises an obvious question about this technology. If the SIM is helping prove your identity, what happens when a crook gets your number transferred to another SIM?

In a SIM-swap attack, a criminal gets control of your phone number by moving it to another SIM or eSIM. Your phone may suddenly lose cellular service while calls and texts start reaching the attacker's device. We recently followed a real case on The CyberGuy Report podcast where a sudden loss of phone service led to a SIM swap and thousands of dollars being stolen.

Glide says MagicalAuth looks for recent SIM changes before allowing authentication. "We monitor for SIM changes in real time, so we know the moment a number moves to a new SIM," Eran said. "When that happens, we don't allow the new SIM to authenticate for a short window."

That temporary pause is designed to give the legitimate owner time to notice the problem and recover the number. "So a stolen number stops being enough on its own to take over your accounts," Eran said.

AT&T says the carrier network can also provide information about recent SIM activity before a sensitive login goes through. "From the carrier side, the key is that we can help verify what is happening on the network before a login is approved," Shawn Hakl, SVP and head of product at AT&T Business, told CyberGuy. "If a phone number was recently moved to a new SIM or eSIM, that is an important signal."

A bank could use that information to require another identity check or temporarily pause an action. "That matters because SIM-swap fraud often depends on speed," Shawn said. "A scammer is trying to move your number and use it before you realize your phone stopped working."

YOUR MICROSOFT TEXT CODES ARE GOING AWAY

Yes. Stronger authentication will not make social engineering disappear. A scammer can still pretend to work for your bank. AI-generated voices can make those calls more convincing too. I've also talked with JPMorgan Chase's head of scam prevention about how bank scammers manipulate people in real time and what families can do to stop them on The CyberGuy Report podcast.

MagicalAuth is designed to take one powerful piece of ammunition away from the scammer: the one-time code. "They can't reuse a stolen code, because there is no code to steal, and they can't phish something the user never sees or types," Eran said.

There is still a limit to what this protection can do. "It does not make fraud impossible, no security does," Eran said. A crook could still persuade someone to send money or approve a transfer themselves. That is a different kind of scam because the real account holder is authorizing the transaction.

"What it doesn't yet solve is a scammer tricking you into approving a transfer yourself, the way romance or investment scams do," Eran said. So, your judgment still counts. Better login security can make account takeover harder, but it cannot stop a scammer from manipulating you into moving money yourself.

Getting a new phone, replacing a SIM or switching to an eSIM can change the information the carrier sees. That may trigger another verification check.

"If a customer gets a new phone, replaces a SIM or activates an eSIM, a carrier may need to re-check that the phone number and device are still properly matched before allowing a sensitive login or transaction," Shawn said. In normal situations, Shawn says that check should happen in the background.

However, if something does not match, the bank or app could ask you to verify your identity another way until the change is confirmed. "That extra step may feel like a little friction, but it is there for a reason," Shawn said. "It helps prevent a fraudster from moving your number to a new SIM and immediately using it to get into your accounts."

Not yet. Glide says MagicalAuth works across iOS and Android through AT&T, T-Mobile and Verizon, but that does not mean every wireless customer will be supported. Eran says some MVNOs, smaller carriers and many prepaid users are not supported yet.

The age of your phone may not be the deciding factor either. "The experience depends less on the age of the phone and more on whether the customer's carrier, plan and the app they are using are supported," Shawn said.

There may also be times when a network check cannot be completed. "In those cases, the bank or app should have a fallback identity check, so the legitimate customer is not locked out," Shawn said.

If your wireless carrier is helping verify a bank login, you may wonder what information is being shared. AT&T says the goal is to provide a verification signal without handing over more customer information than necessary. "Privacy has to be central to how this works," Shawn said. "The point of these APIs is verification, not sharing more personal information than necessary."

In a typical flow, a bank or app asks whether a phone number can be verified against information available through the carrier network. Shawn described the response this way: "It is closer to a yes-or-no trust signal than a transfer of customer data."

AT&T says the capabilities provide information about the service and SIM, rather than personal information about the customer. That network signal can then become one part of the bank's decision about whether a login should proceed.

Wireless carriers already have access to network signals that banks cannot see on their own. For example, a carrier can know that a phone number was recently moved to another SIM. Now, network APIs can allow trusted services to use some of those signals during authentication. "What's changed is that we're now bringing that same network-level intelligence into the way people verify their identities online," Shawn said.

For banks, that provides another way to judge whether the phone being used during a login matches what the network expects. For you, the interesting part is that the added check could happen without another app or another code to type.

There is no universal rollout date. Glide has made MagicalAuth available to businesses and developers, but banks have to adopt it individually. "Banks have to implement this on their end, and that's starting to happen now with some of the biggest and most innovative banks," Eran said.

Glide's longer-term goal is to move supported users away from SMS authentication rather than leaving text messages available as the easy fallback. "The intent is for this to be the authentication method for supported numbers, not one option among many," Eran said.

Your bank will decide whether and when it adopts SIM-based verification. Until then, you can tighten the security around accounts that still rely on texted codes.

If your bank or another sensitive account supports passkeys, consider using one. Passkeys are designed to resist phishing because you do not have a code or password that can be copied into a fake login page. Eran also recommends using passkeys while banks continue relying on one-time codes.

Set up a PIN or password with your carrier. Also check whether your provider offers a number lock or port-out protection feature. Those safeguards can make it harder for someone to move your number to another carrier or SIM without permission.

If your bank still sends security codes by text, keep them to yourself. If someone calls claiming to be from your bank and asks for one, hang up. Then contact your bank using the official number on its website, app or the back of your card. We've seen how convincing this type of manipulation can become. In one case covered on the podcast, a woman drove to her bank with a scammer still on the phone and nearly withdrew $15,000.

If your phone unexpectedly loses cellular service, contact your carrier. It could be an ordinary outage, but it can also be a warning sign that someone has tried to move your number to another SIM.

If a scammer gets enough of your personal information, the damage can extend beyond one bank login. An identity theft protection service can monitor for signs that your information is being misused and help you respond if something goes wrong. You can also freeze your credit for free with the three major credit bureaus to make it harder for someone to open new accounts in your name. See my tips and best picks on Best Identity Theft Protection at Cyberguy.com

SIM-based verification can make stolen text codes less useful, but scammers can still come after you through phishing links and malicious websites. Strong antivirus software can help detect malware and warn you about some dangerous links before they compromise your device or personal information. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com

Scammers can use details found online to make fake bank calls and other impersonation attempts sound more convincing. A data removal service can help reduce the amount of personal information available on people-search sites and data broker databases. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com

I've warned many times about fake bank calls where someone tells you there is suspicious activity on your account. Before long, they're asking for the security code that just landed on your phone. For me, the promising part of SIM-based verification is pretty simple. If that code never shows up, a crook cannot talk you into reading it back. I also like that this approach does not ask you to install another app or become your own security expert. If your bank adopts it, the heavy lifting happens between the bank and the carrier network. But I would not lower my guard. A convincing scammer can still talk you into moving money yourself, and AI-generated voices can make those conversations harder to spot. For account takeover, though, getting rid of the six-digit code could take away one of the easiest tricks in a scammer's playbook.

Would you feel safer if your bank stopped texting security codes and went with this sort of technology? Let us know by writing to us at Cyberguy.com

Sign up for my FREE CyberGuy Report

Copyright 2026 CyberGuy.com. All rights reserved.

Chinese humanoid robot breaks Usain Bolt's 100m dash record at 9.39 seconds

The world's fastest man record was shattered on the first day of the World Humanoid Robot Games in Beijing on Saturday.

Jamaican Usain Bolt's 100-meter dash record of 9.58 set in 2009 was edged by a Beijing-based X-Humanoid robot named Lightning Bolt, which ran 100 meters at 9:39 seconds before smashing into a blue wall.

Before the opening, a humanoid robot from Chinese smartphone company Honor completed a 100-meter sprint in a record of 9.32 seconds during a trial of the games, the company said, at a peak speed of 14.5 meters per second.

After smashing into the wall, the robots were placed on a stretcher, unlike Bolt, who was able to jog a lap to celebrate human achievement in 2009.

ROBOTS BEAT HUMANS IN HALF MARATHON

The World Humanoid Robot Games, in its second year, features more than 2,000 robots in 51 events and 1,000 competitions like running, table tennis and soccer. The five-day event highlights China's rapid progress in robotics amid a heated tech race with the U.S.

The games, which are taking place in the National Speed Skating Oval built for the 2022 Winter Olympics, opened the same week Beijing was holding the 2026 World Robot Conference, where companies showcased around 3,000 products, including humanoid robots.

CHINA IS BUILDING AN AI WAR MACHINE. WASHINGTON MUST WAKE UP BEFORE IT’S TOO LATE

In a standing high jump, a humanoid robot was able to reach 2.88 meters, well above the 0.95 meters best result by a humanoid in last year’s first edition of the games. It surpassed the human high jump record of 2.45 meters set by Cuba’s Javier Sotomayor in 1993.

Some spectators at the robot games said they were excited about the humanoid robots’ quickly improving abilities.

Humanoid robots are "evolving rapidly," said Li Yanfeng, an education worker and a Beijing resident.

UNITREE G1 HUMANOID ROBOT ICE SKATES AND ROLLERBLADES

"At first, I wasn’t very accepting of artificial intelligence. I was even a bit resistant to it, because of the possibility that it might replace or displace humans," she said. "But now that I see this development is unstoppable, I decided to come and take a look."

"These sports are perfectly normal for humans, but now robots can do them. I find it amazing," said Yang Shangzheng, another spectator.

NEW YORK SCHOOL DISTRICT TO DEPLOY HUMANOID ROBOT IN CLASSROOMS THIS FALL

Liu Tao, who was watching the games with his son, said he was hoping to see "the best robots China currently has to offer."

This year’s robot games — which the organizer said has 16 countries participating, among them Germany, Japan and the U.S. — also include other events such as weightlifting and tug of war.

The U.S. has stepped up scrutiny of robots from China, which makes the majority of the world's humanoid robots.

President Donald Trump's Federal Communications Commission (FCC) banned imports of new foreign-made humanoid robots, because they "pose unacceptable risks to the national security of the United States or the safety and security of United States persons."

"I welcome these Executive Branch national security determinations, and I am pleased that the FCC has now added foreign produced advanced robotics and power inverters to the FCC’s Covered List," FCC Chair Brendan Carr wrote in a statement last month. "Following President Trump’s leadership, the FCC will continue to do our part to secure America’s critical supply chains and, with today’s action, the FCC is acting in lock step with our national security agencies to do just that."

The Associated Press contributed to this report.