Proton launches privacy tool to reveal AI Inferences from chat logs amid rising data concerns

Swiss privacy firm Proton introduces a tool to expose what AI services like ChatGPT and Claude may infer from user conversations, highlighting growing concerns over data handling and personal privacy in AI interactions.

A new tool from the Swiss privacy company Proton is meant to show people what ChatGPT and Claude may have inferred from their conversations, turning chat logs into a plain-language privacy report. The idea lands at a time when concern about data handling in AI services is rising. Bitkom, the German digital industry group, said in a survey of 1,003 people aged 16 and above that 43% of respondents worry that personal data is not safely stored by AI providers, while 34% of those who use AI said they turn to chatbots for health-related questions.

Proton’s AI Paper Trail only works with exported conversation files from ChatGPT or Claude. Users first have to request their data from the provider, wait for the archive to be prepared, then upload the resulting JSON or ZIP file into Proton’s browser-based tool. The service then highlights what it thinks the model may have learned about interests, habits, goals, routines and other personal details, presenting the result as a score and a summary that can be shared.

In testing, the tool can produce very different results depending on the account and the amount of detail in the chats. For a lightly used account, Proton described the data as hard to read and assigned a relatively low exposure score. For a more heavily used account, the analysis flagged more specific themes, including diet and recovery, and inferred goals, equipment research and event dates. Proton says such details can be used for profiling, targeting and decisions about a person, often without clear transparency or consent.

The company also stresses an important limit: its tool only analyses what is written in the chat export. It cannot show what may have ended up in a model’s memory system, nor can it reveal every inference a provider might derive from backend signals or product settings. That distinction matters, because the visible transcript is only part of the data picture.

Users who are uncomfortable with what the report reveals can delete chats afterwards, although retention rules differ by provider. Proton says Anthropic removes deleted chats from the visible history straight away but may keep them on servers for at least 30 days, while OpenAI says deleted data can still be retained if it has been de-identified, separated from an account or must be kept for security or legal reasons. Proton’s wider privacy pitch is tied to its own AI assistant, Lumo, which it says does not keep server-side chat logs and does not use conversations for training. The company has also faced scrutiny before: in its transparency reporting, Proton has said it has complied with thousands of Swiss legal requests for Proton Mail data, even as it says it does not hand information directly to foreign authorities.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.