By Nathan FosterGuidesAI memoryprivacymemory controls

What Should an AI Remember? A Privacy-First Checklist

A practical privacy-first checklist for deciding what an AI should save, forget, retrieve, and expose—and which memory controls protect users over time.

An AI should remember information that is useful later, durable enough to stay true, expected by the user, and easy to review, correct, or delete. It should not retain credentials, one-time secrets, private facts about other people, temporary feelings treated as permanent identity, or anything the user cannot find and forget.

The goal is not maximum memory. It is useful continuity with a visible off switch.

Last verified: August 29, 2026.

The short rule: durable, useful, expected, reversible

Before an AI saves a detail, four conditions should be true:

  1. Durable: The detail is likely to remain true beyond the current conversation.
  2. Useful: Remembering it will materially improve a later response.
  3. Expected: A reasonable person would understand why this detail might return.
  4. Reversible: The user can see it, correct it, and remove it without negotiating with the AI.

A preferred name passes all four tests. A one-time hotel door code passes none of them.

This framework also guards against a common product mistake: treating more retained data as automatically better personalization. Memory quality comes from relevance, accuracy, and control—not volume.

Do not confuse chat history with saved memory

Privacy choices become muddy when three different records are labeled “memory.”

RecordPrimary purposeThe control users need
Raw conversation historyPreserve what was saidView, export, and delete conversations
Saved-memory summaryKeep selected facts top of mindReview, correct, prioritize, or forget facts
Structured retrievable memoryFind relevant facts, events, goals, or working patterns laterSearch, provenance, edit, importance, expiry, and deletion

Deleting one record does not always delete the others. OpenAI, for example, says saved memories are stored separately from chat history; fully removing something can require deleting both the saved memory and the chat where it appeared. That separation is documented in OpenAI’s Memory FAQ.

Whenever you evaluate an AI memory feature, ask which record a control actually changes.

A privacy-first checklist for AI memory

Use these questions before saving a detail manually, enabling automatic memory, or approving an imported memory.

1. Will this improve a specific future interaction?

“I prefer examples before theory” can improve tutoring conversations. “I ate toast at 8:12 this morning” probably does not—unless you are deliberately tracking meals.

Name the future benefit. If you cannot, do not keep the detail.

2. Is it stable, or merely true right now?

Good long-term memory distinguishes identity from state:

  • Stable preference: “I usually want concise answers.”
  • Temporary state: “I am frustrated with this answer.”

Saving the second as a lasting personality fact would turn a moment into a label. Temporary states can matter within a conversation without becoming permanent memory.

3. Was it a fact, a hypothesis, or fiction?

People brainstorm, role-play, quote other people, and test prompts. An AI should not convert “Imagine I move to Berlin” into “The user lives in Berlin.”

Memories need enough source context to distinguish:

  • what the user asserted as true;
  • what the AI inferred;
  • what came from an imported platform;
  • what belonged to a fictional scenario; and
  • what another person said.

Provenance is not an advanced analytics feature. It is how users challenge a memory that looks wrong.

4. Does the information belong to the user?

Your own preference may be reasonable to save. A friend’s medical diagnosis, a client’s confidential plan, or a coworker’s private message is different.

Use a stricter standard for third-party information. When in doubt, reduce it to the minimum context needed: “A family member has a private health matter” is safer than preserving identifying detail that is irrelevant to future help.

5. Would exposure create meaningful harm?

Some information should never become routine personalization data:

  • passwords and passphrases;
  • API keys and recovery codes;
  • one-time authentication codes;
  • full payment-card or bank-account details;
  • private keys or seed phrases;
  • answers to security questions; and
  • secrets someone else trusted you to keep.

Other sensitive information—health, location, finances, legal matters, sexuality, or identity—may sometimes be genuinely useful. It should be saved only when the user understands the purpose, the system minimizes the detail, and deletion is straightforward.

6. Can the memory go stale?

Addresses change. Jobs end. Goals are completed. Food preferences evolve. A memory system should support correction, supersession, status, or expiry instead of silently treating the first version as eternal truth.

Ask two questions:

  1. When should this be reviewed?
  2. What should happen when a newer fact conflicts with it?

For an active goal, a status such as active, paused, achieved, or abandoned is more honest than a timeless sentence.

7. Can the user find it without guessing the right prompt?

“Tell the AI to forget it” is useful, but it should not be the only control. People need a visible memory library with search and filters. Otherwise they must remember the wording of information they are trying to make the system forget.

At minimum, a memory interface should show:

  • the stored statement;
  • when it was created or updated;
  • where it came from, when available;
  • why or how strongly it matters;
  • whether a newer memory replaced it; and
  • clear edit and delete actions.

8. Does deletion mean deletion—or only “do not use”?

Products use words such as delete, forget, archive, disable, and turn off differently. A good interface explains the scope.

Ask whether the action:

  • stops future retrieval;
  • removes the structured memory record;
  • deletes the source conversation;
  • deletes imported source data;
  • applies only to one AI identity or the whole account; and
  • affects backups or legally required records.

Do not infer the answer from the button label. Read the provider’s privacy documentation.

9. Can automatic memory be paused?

Sometimes you need a conversation that does not become future context. A private planning session, a surprise gift, or a sensitive question may be useful once and irrelevant later.

Look for a temporary-chat mode, a per-conversation control, or a way to disable memory extraction. Turning memory off should not require deleting the entire account.

10. Can you test what the AI actually recalls?

Memory should be observable in behavior. After saving or deleting something, start a new conversation and test it without restating the detail.

Good tests include:

  • “What communication style do I prefer?”
  • “Which goal am I working on?”
  • “What did I ask you to forget?”
  • “Where did that detail come from?”

The last question matters most. Confidence without provenance is not control.

What an AI should usually remember

These categories tend to create useful continuity with relatively low surprise:

Communication preferences. Preferred name, pronouns, answer length, feedback style, accessibility needs, or whether examples help.

Active goals. What you are trying to do, why it matters, known constraints, milestones, and current status.

Project decisions. Chosen direction, rejected alternatives, definitions, recurring collaborators, and non-negotiable requirements.

Learning context. What you already understand, recurring mistakes, current curriculum, and preferred practice style.

Creative continuity. Character canon, voice guidelines, world rules, themes, and decisions you do not want contradicted later.

Routines you explicitly want help maintaining. Check-in cadence, planning rituals, or recurring reminders—with a clear way to pause them.

Even these categories should be editable. “Useful” does not mean “permanent.”

What an AI should remember only with care

Some information can improve help but carries higher consequences if wrong, exposed, or used out of context:

  • physical or mental health information;
  • precise home or work location;
  • financial circumstances;
  • legal disputes;
  • intimate relationships;
  • political or religious identity;
  • trauma history; and
  • information about children or vulnerable people.

The safer pattern is explicit purpose, minimum necessary detail, visible provenance, and periodic review. An AI should not diagnose, moralize, or turn a difficult moment into a permanent identity claim simply because the information was memorable.

What an AI should not remember

Do not save:

  • credentials or authentication material;
  • secrets with no future personalization benefit;
  • confidential third-party content;
  • transient details presented as enduring facts;
  • inferred sensitive traits the user did not state;
  • stale facts that have already been corrected; or
  • raw conversation fragments when a smaller, accurate summary would do.

The principle is data minimization: retain the least information needed for the future benefit the user asked for.

How memory controls differ across AI products

The names look similar, but the controls operate at different layers.

ChatGPT. OpenAI's current Memory FAQ describes an automatically updated memory synthesis that can use chats, files, and connected apps, plus a legacy saved-memories mode. It says the visible summary may not include every factor ChatGPT can use. Fully removing a detail may require deleting it from the summary and every source where it appears, including chats, files, or connected apps.

Gemini. Google's past-chat Memory guide says eligible adult personal-account users can let Gemini personalize from past chats when Keep Activity is on. The feature is not available on work, school, or supervised accounts or in certain surfaces such as Gems and Live chats. Removing a remembered detail can require deleting every source chat and addressing the same information in a connected app.

Claude. Anthropic now documents generated memory and past-chat search. Claude stores editable memory Topics, can cite source chats during search, and gives each Project a separate memory space. Incognito chats are excluded, while plan and organization settings affect availability.

Grok. xAI's Grok product overview advertises memory across chats, synced history, custom instructions, and continued threads. Its public overview does not describe a granular editor for individual automatic memory records, so check the current account controls instead of inferring them from the word “memory.”

Do not choose a memory product based only on whether it says “memory.” Choose it based on whether you can inspect and govern each layer.

What user-controlled memory looks like in Fostera

Each Fostera Soul has its own memory library. You can search memories, open an individual record, inspect its source information when available, edit its wording, change its category or importance, and delete it from the active memory library. Newer knowledge can supersede older knowledge instead of leaving contradictory facts equally active.

Memory is also configurable per Soul. If you do not want a Soul extracting persistent episodic or semantic memories, its brain settings provide that boundary. For a deeper explanation of the retrieval model, read AI with long-term memory. For the data-handling commitments behind those controls, read Fostera’s privacy policy.

Fostera retrieves a selected set of memories for a response; it does not promise that every retained record will appear every time. Project files, custom rules, and current conversation context remain separate inputs, and a generated response can still miss or misapply them.

Requested AI features may send conversation content, selected import history, or memory text to configured AI providers and routing intermediaries. Fostera does not train models it owns or develops on that content, but provider retention, training, regional processing, and opt-out terms vary. The privacy policy links the current provider disclosures.

Fostera's self-service JSON export currently includes account identity, Soul configurations, memories, profile summaries, and per-Soul conversation counts. It does not include chat message bodies or uploaded files. When account deletion is processed, primary database records are removed; external-resource cleanup and backup removal may take up to 30 days, with limited billing, legal, audit, or cleanup records handled as described in the policy.

A five-minute AI memory audit

Run this audit once a month for any AI you use regularly:

  1. Ask, “What do you remember about me?”
  2. Open the product’s memory or activity settings instead of relying only on the answer.
  3. Search for an old job, address, preference, and completed goal.
  4. Correct or delete anything outdated.
  5. Remove sensitive details that do not produce a clear future benefit.
  6. Check whether deleting the memory also requires deleting its source chat.
  7. Test the change in a new conversation.
  8. Export your data if you want an independent record before a larger cleanup.

The habit is simple: inspect, correct, forget. Memory should earn its place repeatedly.

Build continuity you can inspect

An AI that remembers can save you from explaining your life and work over and over. That benefit is only sustainable when the record stays visible and correctable.

Fostera was designed around that balance: persistent memory for continuity, a memory library for review, and controls to edit or forget individual records. Explore how Fostera’s memory works, or use the AI history migration guide when you want to bring useful context from another AI without carrying everything forward.

For what each major product actually retains, see the memory comparisons for ChatGPT, Claude, Gemini, and Grok.

Frequently asked questions

What information should an AI remember about me?

Durable information that will clearly improve future help: communication preferences, active goals, project decisions, learning context, and routines you explicitly want supported. It should remain visible, editable, and deletable.

What should I never tell an AI to remember?

Passwords, API keys, one-time codes, recovery phrases, payment credentials, security-question answers, or confidential third-party information. Sensitive personal information should be minimized and saved only for a clear purpose.

Does deleting a chat delete an AI's memory of it?

Not always. Some products derive or store memory separately from the source chat. OpenAI explicitly says full removal can require deleting every source where the information appears. Check the current controls and policy for the product you use.

Can I edit an AI memory instead of deleting it?

That depends on the product. A strong memory system should let you correct a record directly and preserve enough provenance or version context to explain the change. Fostera supports editing memory wording, category, and importance.

How often should I review AI memories?

Review them monthly if you use the AI often, and immediately after a major change such as moving, changing jobs, completing a goal, ending a project, or importing history from another platform.

Is turning memory off the same as deleting it?

Usually not. Turning memory off commonly changes future use or collection, while existing records may remain. Verify whether the product distinguishes disabling retrieval, deleting saved memories, deleting chats, and deleting the account.

Does Fostera export every chat and uploaded file?

No. Fostera's current self-service JSON export includes account, Soul, memory, profile-summary, and conversation-count data. It does not include chat message bodies or uploaded files. Contact Fostera for any additional access or portability request available under applicable law.

Does Fostera delete everything immediately?

Primary database records are removed when an account-deletion request is processed. External-resource cleanup and backup removal may take up to 30 days, while limited billing, legal, audit, or cleanup records may be retained or de-identified as described in the privacy policy.

Why is provenance important in AI memory?

Provenance shows where a memory came from. It helps you spot hypotheses treated as facts, imported details attributed to the wrong person, and old information that a newer statement should replace.

Build useful continuity without giving up control.

Create a Soul with inspectable memory

Continue with context

Ready to Stop Starting Over?

Start with one project. Or one companion. Either way, your Soul takes it from there and remembers the rest.

Start with one project

Free to start · No credit card required