Is Grok private? (and is it safe to use?) What xAI stores, trains on and shows (2026)
Is Grok private? Not by default — not in the sense of being private from xAI. Whatever you type is stored: by xAI on grok.com and in the apps, and by X on the X platform, which shares it with xAI unless you opt out. On those consumer surfaces it also trains and fine-tunes the model unless the training setting is off. xAI staff may review conversations, and xAI can hand data over in response to “lawful requests and legal process”.
Private Chat helps: those chats stay out of your history, are not used for training and are deleted from xAI’s systems within 30 days. The share button is the part that has actually burned people — in August 2025 the BBC reported that Google had indexed nearly 300,000 shared Grok conversations. Grok can be private from other users if you never share a link. It is not private from xAI.
Who this is from. Occlira is a desktop app that replaces the names, IDs and addresses in a file with placeholders on your own computer, so the copy you paste into Grok carries placeholders instead of the details it found. This guide is what we tell our own users. How it works ↓ · Free 14-day trial
Jump to: what Grok stores · training and opt-out · Private Chat · the shared chats in Google · who can see your chats · is Grok safe to use? · business and API · Grok vs ChatGPT vs Claude · what not to paste · using Grok without the names · FAQ
Grok privacy policy: what xAI stores, surface by surface
Your text sits in two of the policy’s collected categories. “User Content” is your prompts, and the policy warns that “if you include personal information in Inputs you provide to the Service, this information may be reproduced in the Output”. “Technical Data” lists your “Grok conversation history” next to IP and device information. The policy covers “the Grok mobile app (iOS or Android) or the Grok.com website”, and explicitly not Grok on X or the business products. That is why the switch you need sits in a different place on each surface: (Source: xAI privacy policy, accessed 3 September 2026.)
| Where you use Grok | Whose policy applies | Where the training switch is | What deletion means |
|---|---|---|---|
| Grok on X | X’s, not xAI’s: use of Grok on the X platform “is governed by the X Privacy Policy and X Terms, not this SpaceXAI Privacy Policy” | X settings → “Privacy & Safety” → “Data sharing and personalization” → “Grok & Third-party Collaborators” → “Data Sharing” | “Deleted conversations are removed from our systems within 30 days, unless we have to keep them for security or legal reasons” |
| grok.com | The xAI (SpaceXAI) privacy policy | Settings → Data → “Improve the Model” | Deleted chats and Private Chats are removed “within 30 days”, unless the data has been de-identified or is kept for safety, security or legal reasons |
| The Grok app (iOS, Android) | The xAI (SpaceXAI) privacy policy | Settings → Data Controls → “Improve the model” | The same 30-day rule |
| The xAI API and business plans | Neither: the consumer policy “does not apply to data that we process on behalf of customers of our business offerings, such as the SpaceXAI API” | xAI “never trains on your API inputs or outputs without your explicit permission” | Requests and responses stored encrypted for 30 days for auditing, then deleted; Zero Data Retention on request |
Sources: xAI privacy policy (effective 24 August 2026), xAI Consumer FAQs, X Help Center, “About Grok” and the xAI developer security FAQ (last updated 27 July 2026). All checked 3 September 2026.
One naming point, since it runs through the quotes: the policy is issued by “SpaceXAI LLC” and marked effective 24 August 2026, while the product and the settings screens still say xAI — as does this page.
Whichever country you are in, the processing happens in the United States: the European addendum, effective the same day, names “SpaceXAI LLC, which is based in the USA” as the controller and states, “We process all of your personal information in the United States, where we maintain our primary data centers.” For onward transfers it relies on the EU-US Data Privacy Framework or standard contractual clauses, claims legitimate interests as the basis for training, and points users in Europe to their settings to object. (Source: xAI Europe privacy policy addendum.)
Does Grok train on your data — and how do you opt out?
xAI’s and X’s own wording is opt-out: training happens unless the setting is off. Neither page tells you the position the switch ships in — open it and look. On X the help page spells the flow out: “X may share with xAI your public X data as well as your user interactions, inputs and results with Grok on X to train and fine-tune Grok and other generative AI models.” One option controls it, under Privacy & Safety → Data sharing and personalization → “Grok & Third-party Collaborators”: “Allow your public data as well as your interactions, inputs, and results with Grok and xAI to be used for training and fine-tuning.” The opt-out is narrower than it sounds: when you use an X feature powered by Grok, “the opt-out does not prevent a deployed model from learning as a result of its normal use”. (Source: X Help Center, “About Grok”.)
On grok.com and in the app the opt-out is forward-only: “your new conversations will not be used to train our models.” Feedback is an exception — “even if you opt out of model training … that feedback may be used for training purposes” — so a thumbs-up can put a whole conversation back in scope. And without logging in, “in some regions (excluding the EU/UK) … you won’t have the option to opt out of model training”. (Source: xAI Consumer FAQs, page dated 12 May 2025.)
Whether training on European posts was lawful in the first place is still open. Irish Data Protection Commission proceedings over Grok training data were “struck-out on the basis of X’s agreement to continue to adhere to the terms of the undertaking on a permanent basis” in September 2024. On 11 April 2025 the DPC opened a full inquiry into the processing of EU/EEA users’ public posts “for the purposes of training generative artificial intelligence models, in particular the Grok Large Language Models (LLMs)”. We found no published decision as of 3 September 2026. (Sources: Irish DPC, 4 September 2024; Irish DPC, 11 April 2025.)
Grok private mode: what Private Chat actually does
xAI describes Private Chat in two sentences: “your conversation history will not be viewable to you and will be deleted from SpaceXAI systems within 30 days”, and “when using Private Chat, where available, your content and interactions are not used for model training”. (Source: xAI Consumer FAQs, page dated 12 May 2025.)
So it is a retention and training control, not encryption. The conversation still reaches xAI’s servers — that is why the promise is worded as deletion from them. Nothing in the FAQ exempts Private Chat from the authorized-personnel review, or from the safety, security and legal exceptions to the 30-day rule. It is not universal either: Private Chats “are not available for Build mode currently”. Use it for the reduction in exposure it gives, not as a licence to paste something you otherwise would not. (Source: xAI developer security FAQ, last updated 27 July 2026.)
The Grok shared conversations that turned up in Google (August 2025)
On 20 August 2025 TechCrunch described the mechanism. Clicking share “creates a unique URL that the user can use to share the conversation via email, text, or on social media”, and, “according to Forbes, those URLs are being indexed by search engines like Google, Bing, and DuckDuckGo, which in turn lets anyone look up those conversations on the web.” The BBC put a number on it the next day: “A Google search on Thursday revealed it had indexed nearly 300,000 Grok conversations.” Among them were people asking Grok “to create a secure password, provide meal plans for weight loss and answer detailed questions about medical conditions”. (Sources: TechCrunch, 20 August 2025; BBC News, 21 August 2025.)
No intrusion was reported: the share button did what a share button does, and users assumed a link sent to one person stayed between the two of them. xAI’s FAQ now states the consequence plainly: a share link “may be subject to indexing by a search engine (e.g., Google) just like any other publicly shared content”. It also documents the way back — revoke any or all share links at grok.com/share-links, which is not the same action as deleting the conversation.
Who can see your Grok chats
Start with the vendors’ own pages. xAI staff: “A limited number of our authorized personnel may review your conversations with Grok for specific business purposes, including improving model performance, investigating security incidents and potential misuse of our services, and complying with our legal obligations.” Anyone with a share link, as above. Courts and law enforcement, since the policy permits disclosure to “comply with laws or to respond to lawful requests and legal process”. And X, which shares your public data and your Grok interactions with xAI unless you opt out. (Sources: xAI Consumer FAQs, xAI privacy policy and X Help Center, “About Grok”.)
Both rule out selling: “Does X or xAI sell my data? No. We do not sell your data,” says the X help page, and xAI adds that it does not share data “for marketing or advertising purposes”. Narrower than it sounds: not selling is compatible with storing, training on, reviewing and producing your conversations under legal process.
Is Grok safe to use? The other risks
As a chatbot, yes — with the same caveat as the others: nothing you type is private from the vendor. The risks specific to Grok in 2026 are these. In January and February 2026 the UK ICO, the Irish DPC and the European Commission all opened actions. Ofcom opened its own inquiry in January, then said it lacked the powers to pursue the images. All four were triggered by sexualised images generated by Grok; none of them is about whether your chat history is stored properly.
- UK ICO, 3 February 2026. Formal investigations into X Internet Unlimited Company and X.AI LLC over “their processing of personal data in relation to the Grok artificial intelligence system and its potential to produce harmful sexualised image and video content”; the ICO “has not reached a view” on whether the law was infringed. (ICO, 3 February 2026.)
- Irish DPC, 17 February 2026. An inquiry into “the apparent creation, and publication on the X platform, of potentially harmful, non-consensual intimate and/or sexualised images” involving EU/EEA data subjects, including children, under GDPR Articles 5, 6, 25 and 35 — separate from the training inquiry above. (Irish DPC, 17 February 2026.)
- European Commission, 26 January 2026. A Digital Services Act investigation into whether X “properly assessed and mitigated risks associated with the deployment of Grok’s functionalities into X in the EU”, including “manipulated sexually explicit images”. (European Commission, 26 January 2026.)
- Ofcom, January–February 2026. The regulator was “urgently investigating whether Grok has broken British online safety laws”, then said it was “currently unable to investigate the creation of illegal images by Grok in this case because it did not have sufficient powers relating to chatbots”. (BBC News, 12 January 2026; BBC News, 3 February 2026.)
One 2026 incident hit a different product: in July 2026 users reported that xAI’s coding agent Grok Build — a developer product, not the chat assistant — “uploaded all files in a directory to xAI’s Google Cloud servers”, after which xAI disabled the upload feature and open-sourced the tool. (Source: The Decoder, 16 July 2026.)
Grok for business: the API, retention and SOC 2
The business terms are the ones you would want on the consumer side. xAI “never trains on your API inputs or outputs without your explicit permission”. By default “all API requests and responses are stored on our servers (encrypted at rest) for 30 days for auditing purposes”, then deleted automatically. Zero Data Retention, under which prompts and outputs “are never persisted to disk”, is opt-in, and “for most customers, we do not recommend enabling ZDR”. xAI is “SOC 2 Type 2 compliant”, will discuss a Business Associate Agreement for HIPAA work, and does “not use content from our business and enterprise customers to improve our models”. (Sources: xAI developer security FAQ, last updated 27 July 2026; xAI Consumer FAQs.)
A contract changes who promises what about your data. It does not change where the data goes: out of your machine, into a US data centre — API requests held 30 days by default — and reachable by legal process.
Grok vs ChatGPT vs Claude
| Assistant | Trained on (personal plans) | What the private mode does |
|---|---|---|
| Grok (grok.com, the apps, Grok on X) | Yes, unless the setting is off — “Improve the Model” on grok.com and in the app, “Grok & Third-party Collaborators” on X; xAI and X do not publish the starting position — check it. The opt-out covers new conversations, and feedback you volunteer “may be used for training purposes” anyway | Private Chat: not shown in your history, not used for training, “deleted from SpaceXAI systems within 30 days” |
| ChatGPT (personal plans) | Yes: ChatGPT “improves by further training on the conversations people have with it, unless you opt out” | Temporary Chat: “won’t appear in history, use or create memories, or be used to train our models” |
| Claude (consumer plans) | Only if Model Improvement is on; allowing it means Anthropic “may retain your data in a de-identified format for up to 5 years in our model training pipelines” | Incognito chats “are not used to improve Claude, even if you have enabled Model Improvement”; a deleted conversation is “Deleted from our back-end storage systems within 30 days” |
Sources: xAI Consumer FAQs and X Help Center; OpenAI Help Center; Anthropic privacy centre (page dated 1 July 2026). Checked 3 September 2026.
Grok, ChatGPT and Claude land in the same place with different wording: your chats are stored, they feed model training unless you intervene, and each vendor offers one mode that reduces retention. What sets Grok apart is its plumbing — a share button wired to the public web, and a second surface (Grok on X) with its own policy and its own switch in another menu. In detail: Is ChatGPT private?, Is Claude safe? and Is DeepSeek safe?
What not to paste into Grok
The list is short and the same for every consumer assistant: client and patient files, employee records, case numbers, contracts under NDA, credentials, unreleased financials, anything covered by professional secrecy. Everything above is a promise about what happens after the text arrives, and most of them carry an exception for safety, security or legal reasons.
The August 2025 episode is the reason to take that literally. The people whose medical questions turned up in those results did not think they were publishing them. They clicked a share button. You only learn what a setting really covered after the fact. The one control that is not retrospective is what leaves your keyboard.
How Occlira keeps the identifiers out of Grok
Occlira is a desktop app for Windows and macOS (Apple Silicon) that removes personal data from files on
your own computer; detection runs on your machine, and the app goes online only to activate the licence (via
Polar), download its model and check for updates. Open the document, spreadsheet, email, PDF, scan, photo or
recording you were about to summarise in Grok, and it flags the personal data in it — names, addresses,
phone numbers, ID and account numbers, dates — with a confidence score for each. You decide what goes and
what stays, and anything the detector missed you can select and add. Confirmed values become consistent
placeholders such as <PERSON_1>. The anonymized copy of a Word or Excel file is still a Word
or Excel file, formatting intact, comments, tracked changes and document properties stripped; PDFs, emails and
scans come back as anonymized .txt files.
Then either press “Copy anonymized text” and paste it into Grok, or upload the anonymized file with
your prompt, and work on the placeholder version. To get the real values back, save Grok’s answer to a
file and run Deanonymize: one click, and Occlira writes a *_restored copy
from a mapping that stays in a local folder on your machine, deleted after seven days by default and
configurable. The connectors that do this inside the tool — the Chrome extension, the Claude Desktop
connector and the Word add-in — cover ChatGPT, Claude, Gemini and Word, not Grok, so here you work on the
copy the app gives you.
The honest caveat: because the mapping lets you restore the originals, this is pseudonymization in GDPR terms, not anonymization. It cuts what Grok stores, trains on and could expose through a share link, but it does not take you outside the GDPR and does not by itself make anything compliant. The workflow, step by step, is in anonymize text before ChatGPT — identical for Grok.
Frequently asked questions
Not by default, and not in the sense of being private from xAI: everything you type into Grok on grok.com, in the apps or through Grok on X is stored, and the privacy policy lists “Grok conversation history” among the data collected. On the consumer surfaces your content also trains the model unless the training setting is off. Private Chat narrows that: those chats stay out of your history, are not used for training and are “deleted from SpaceXAI systems within 30 days”.
As a chatbot, yes — with the same caveat as the others: nothing you type is private from the vendor. Grok’s share button produced the August 2025 episode in which, the BBC reported, Google had indexed nearly 300,000 Grok conversations. Since early 2026, X and xAI have also been under investigation by the UK ICO, the Irish Data Protection Commission and the European Commission over sexualised images generated by Grok — other people’s data, not your chat history. Anything you would not want stored, reviewed by staff or produced under legal process should not go in.
On the consumer surfaces, yes, unless the training setting is off — and neither vendor publishes which way it ships, so check it yourself. Business and enterprise customers are carved out: xAI does “not use content from our business and enterprise customers to improve our models”.
Three switches, one per surface. App: Settings → Data Controls → deselect “Improve the model”. grok.com: Settings → Data → “Improve the Model”. X: Privacy & Safety → Data sharing and personalization → “Grok & Third-party Collaborators”. It works forwards only.
Private Chat is a retention and training setting: the conversation “will be deleted from SpaceXAI systems within 30 days” and is “not used for model training”. It is not available in Build mode.
Because sharing a conversation creates a public URL, and search engines index public URLs: a share link “may be subject to indexing by a search engine (e.g., Google) just like any other publicly shared content”, xAI says. The BBC reported in August 2025 that Google “had indexed nearly 300,000 Grok conversations”. Links can be revoked at grok.com/share-links.
“A limited number of our authorized personnel may review your conversations with Grok,” xAI says. Add anyone holding a share link you created, courts and law enforcement under “lawful requests and legal process”, and, on X, X itself, which shares your Grok interactions with xAI. Both state that they do not sell the data.
Within a stated window, with stated exceptions. On grok.com and in the app, deleted conversations are “removed from our systems within 30 days, unless they have been de-identified or pseudoanonymized and disassociated from your account or we have to retain them for safety, security, or legal reasons”. On X: “Deleted conversations are removed from our systems within 30 days, unless we have to keep them for security or legal reasons.” Anything already used for training stays in the model, and a share link is a separate publication, revoked at grok.com/share-links.
The terms differ from the consumer ones: xAI “never trains on your API inputs or outputs without your explicit permission”, stores requests and responses “encrypted at rest” for 30 days for auditing, and says it is “SOC 2 Type 2 compliant”. The text still leaves your machine, so keep identifiers out of it.
Remove the identifiers before the text reaches the chat box. Occlira does that on your own computer: it flags the names, addresses, phone numbers, ID and account numbers and dates in a document, spreadsheet, email, PDF or scan, and replaces the ones you confirm with consistent placeholders such as <PERSON_1>. You paste the anonymized text into Grok, or upload the anonymized file with your prompt, and restore the real values locally afterwards: save the reply as a file and Deanonymize writes a restored copy in one click. That is pseudonymization rather than anonymization: it cuts what Grok stores and could expose, not your compliance obligations.
Use Grok on a copy without the names
Anonymize the file locally, paste the placeholder text into Grok, restore the real values on your own machine. Free for 14 days on Windows and macOS (Apple Silicon); one-time licence from €149 per seat.
More: does ChatGPT save your data? · shadow AI at work · what is PII? · how your data is handled