I had the spreadsheet of all my stock holdings open on one monitor and a chatbot open on the other.
Every position. Share count, cost basis, the whole thing. I was about 10 seconds from pasting it in and asking one simple question: What advice do you have on my portfolio?
Then I stopped.
Not because I doubted the answer artificial intelligence might provide. Because it hit me that I had no idea where that information was about to go or who’d end up holding it.
I’ve been a CPA since 1981, and I spent 10 years on Wall Street. I know exactly what a complete picture of someone’s holdings is worth to the right buyer. So I spent a day finding out what actually happens to what you type into AI prompts.
Here’s what I learned, in the order I learned it.
Nobody is buying your chats
Let’s start with my fear, because it turned out to be the wrong one.
There’s no market where a hedge fund buys a file labeled with your name and your positions. The major AI companies state that they don’t sell personal data. Anthropic’s consumer terms say it in so many words. OpenAI says the same.
That’s not a law. It’s a promise. But it’s a promise these companies have built their reputations on, and breaking it quietly would be hard.
One caveat: That applies to the big-name platforms. The sketchier corner of the market — AI “companion” apps and the like — is a different animal, and some of those absolutely do harvest and resell what users share with them.
What they do instead is rent your attention
This is the part that’s changed fast, and it’s the part almost nobody has caught up to.
On Oct. 1, 2025, Meta announced that starting Dec. 16, 2025, conversations with Meta AI would feed its advertising engine across Facebook, Instagram, WhatsApp and Messenger. Ask the chatbot about hiking boots, start seeing hiking boot ads.
There’s no opt-out. Users in the EU, the U.K. and South Korea are carved out, because their privacy laws require it. Americans aren’t.
OpenAI followed. Ads started appearing for logged-in U.S. adults on the free and Go tiers on Feb. 9, 2026, and the company opened self-serve ad buying to businesses on May 5, 2026.
OpenAI says advertisers never see your chats, your history, your memories or your personal details. I believe that. But the targeting still runs on what’s in the conversation, and if you’ve got memory and personalized ads both switched on, stored memories can help pick which ad you see.
So no, nobody buys your portfolio. They just rent the right to advertise to the person who offered it up.
Your chats are training material unless you said otherwise
In August 2025, Anthropic changed its consumer terms and gave users until Oct. 8, 2025, to make a call: allow conversations to train future models, or don’t.
Say yes, and that data can sit in the pipeline for up to five years. Say no, and you keep the old 30-day window.
A lot of people clicked through that notice without reading it.
Google’s own documentation tells Gemini users that human reviewers may read consumer-tier conversations, and warns against entering anything you wouldn’t want a stranger to see. That’s not a leak. That’s the disclosed, working design.
Here’s the trap that surprised me most: Paying doesn’t automatically fix this. On the consumer tiers, a paid subscription buys you more usage and fewer ads. It doesn’t flip the training switch for you.
Quick thought — most financial “gurus” got rich selling advice, not following it. I’d rather show you what actually works, because I’ve lived it. Sign up for the free Money Talks Newsletter for money advice from someone who takes his own. 10 seconds, no spam.
‘Delete’ is a request, not a guarantee
This is where it gets uncomfortable.
On May 13, 2025, a federal judge in the New York Times copyright case ordered OpenAI to preserve all ChatGPT output logs — including chats users had deleted and chats marked temporary, the ones that normally vanish within 30 days.
OpenAI fought it, publicly and hard, and lost. By July, the plaintiffs were combing through the preserved logs.
Now here’s the line that stuck with me. Some ChatGPT users tried to intervene in the case to protect their own conversations. The court denied them. They were non-parties — they had no standing to object to what happened to their own words.
The order was eventually terminated for data going forward as of Sept. 26, 2025, and formally lifted on Oct. 9, 2025. But logs already captured under it still exist.
Think about what that means. A dispute between two companies unrelated to you reached into millions of private conversations, and the people who wrote them weren’t allowed a seat at the table.
Why a portfolio isn’t a grocery list
You aren’t anonymous when you type. You’re logged in, under your real name, with your email and a credit card on file.
A complete portfolio isn’t one fact. It’s a dossier containing your net worth, your concentration risk, your cost basis, your unrealized gains, roughly when you plan to retire and roughly how scared you are right now.
That’s the exact profile a phishing crew or an elder-fraud operation would kill for. And it sits in an account protected by whatever password you’ve been reusing since 2019.
I made a similar point when OpenAI started encouraging people to upload their medical records. The pattern’s identical. The protections you assume travel with sensitive data don’t follow it into a chat window.
What I did
I didn’t quit. AI is genuinely useful for money questions, and I’ve written about how investors are using it well. I just changed how I feed it.
- Strip the identifiers. I pasted tickers, share counts and cost basis. No name, no account numbers, no brokerage, no birth year.
- Turn off training. ChatGPT: Settings, Data Controls. Claude: Privacy Settings. Gemini: Keep Activity. Take two minutes to turn off training on all three.
- Use temporary chats for money. Every platform has a mode that stays out of history and training. Use it for anything financial.
- Ask the general question. “How should someone with 40% of their portfolio in one stock think about trimming it?” gets you the same answer as handing over the whole file.
- Assume it’s permanent. Not because the company is lying, but because a court, a breach or a policy rewrite can override the promise. Type accordingly.
The bottom line
The scary version of this story — AI companies quietly auctioning off your financial life — isn’t happening.
What’s happening is smaller and more permanent. Your most candid questions, the ones you’d never post anywhere, are being logged under your real identity, used to shape what you’re sold, and held for years under rules the company can rewrite and a court can override.
I still asked my question. I just didn’t hand over my name to ask it.

Add a Comment