PrivacyPick
In This Article
AI Chat

Why Not Just Use ChatGPT?

ChatGPT is free, capable, and already open in a tab. What it genuinely does well, three places its architecture doesn't reach, and when that actually matters.

Published October 1, 2026By Juan Martinez

Why Not Just Use ChatGPT?

ChatGPT is open in a tab already. It answers in seconds, the free tier doesn’t meter ordinary text conversations, and it is the tool most people mean when they say they use AI at all. Against that, a list of privacy-focused assistants nobody has heard of is a hard sell.

The honest answer is that for a lot of what people type into a chat box, ChatGPT is fine. But the way it handles what you type is not an oversight to be fixed in a future update — it follows from how the product is built, and three parts of that are worth understanding before deciding the default is enough.

What ChatGPT actually does well

Start with the part that isn’t in dispute, because it’s most of the product.

The feature surface is the widest in the category and nothing else is close. Several model generations are selectable per tier, with web search built into the chat rather than bolted alongside it, file upload across documents and images and data files, image generation, voice, deep research runs that compile sourced reports, data analysis with code execution, Projects, scheduled tasks, custom GPTs, a coding agent, and extensions into spreadsheet and document software. The free tier is a usable product rather than a demo: unlimited text conversations on the base model, subject to abuse guardrails. Desktop apps cover macOS and Windows, mobile covers iOS and Android, and the web interface needs nothing installed.

The data controls are real too, and dismissing them would be unfair. Conversations can be exported and deleted, Memories can be managed and cleared one at a time, Temporary Chat gives a per-conversation mode excluded from training and deleted automatically, and the training opt-out is a single accessible toggle rather than a support ticket. OpenAI also holds a SOC 2 Type 2 report assessed by an independent third-party auditor plus four ISO certifications — in a category where independent assessment is otherwise close to nonexistent, that is a genuine distinction, and our ChatGPT review credits it as one. EEA, UK and Swiss users have OpenAI’s Irish entity as data controller, which puts them under GDPR with a European supervisory authority.

That is a lot of product. The gaps are narrower than the feature list, and they sit in a different place.

Gap 1: training on your conversations is the default, not the choice

OpenAI’s own help documentation states that for services for individuals — ChatGPT and Codex — it may use your content to train its models, and that opting out means turning off “Improve the model for everyone” in the data controls, or making the equivalent selection in its privacy portal. The opt-out works and it isn’t buried. But it is an opt-out, which means every Free, Go, Plus and Pro user’s conversations are training material until they go and change it.

There is a trap inside the opt-out that OpenAI documents itself. Even after opting out, giving feedback on a response — the thumbs up and thumbs down buttons under every answer — may result in the entire conversation attached to that feedback being used for training. Those buttons look like a product rating widget, not a consent mechanism. A user who deliberately opted out can put a whole conversation back into the training set with one click on something that reads as an opinion about answer quality.

⚠️ The thumbs-up and thumbs-down buttons are not a rating widget. Per OpenAI’s own documentation, using them can send the full conversation into training even on an account that has opted out.

What settles the question of whether this default is necessary is that OpenAI already ships the other one. By its own statement, it does not use inputs or outputs from its Business, Enterprise, Edu or API products to improve its models. The protective default exists, is implemented, and goes to the customers whose procurement teams negotiate data terms. The individual paying $20 a month — and more pointedly the one paying nothing — gets the opposite default and has to fix it by hand.

The contrast on the other side isn’t a better toggle, it’s not having a toggle to get wrong. Duck.ai binds all five of the model providers it routes to — Anthropic, OpenAI, Mistral, Azure and Tinfoil — contractually against training on conversations, with zero data retention on the provider side, and discloses the one exception rather than rounding it away: prompts may sit in volatile cache memory for up to an hour, never written to disk. Maple removes the counterparty instead of contracting with it, running open-weight models on its own infrastructure so there is no outside model vendor in the request path to extract a promise from.

Gap 2: the storage is server-side, and OpenAI holds the keys

Conversations are encrypted in transit with TLS and at rest with AES-256, per OpenAI’s own security FAQ. That is correct infrastructure hygiene and it protects against the right things — a stolen disk, a network attacker. It is not zero-access encryption. OpenAI holds the keys and can read conversation content: for abuse review, for model improvement where training is on, and in response to a valid legal demand.

The practical distinction matters more here than the cryptography does. With zero-access encryption the operator cannot produce plaintext even when compelled. With server-side encryption, who reads your chats is a policy question rather than a mathematical one — and conversations persist until you delete them, with Memory accumulating a durable profile by design.

Policy questions depend on the company’s instincts, which is where OpenAI’s record splits in two directions. The March 2023 Redis bug was handled about as well as an incident like that can be: self-detected, service taken offline, affected users notified individually, a detailed public post-mortem within days, a patch sent upstream to the open-source library at fault. The same year, an attacker reached an internal employee messaging system; executives briefed staff and the board, chose not to disclose publicly, did not contact law enforcement, and the public found out roughly sixteen months later through press reporting. No user data was involved in the second one and no law required disclosure — but what a company does when nothing compels it is exactly what you are trusting when the protection is policy rather than architecture.

Two of the reviewed alternatives move that question out of policy entirely. Lumo stores saved history under zero-access encryption — each conversation keyed separately, those keys wrapped by a master key, that master key wrapped by your own keypair and unlocked only by your password — so a demand served on the operator returns ciphertext it has no means to open, and it runs its models on its own servers rather than forwarding prompts to anyone. Maple encrypts messages on the device before they leave it and decrypts them only inside a hardware-isolated enclave, with the running code measured at boot and attested by signed hardware, and both the client and the enclave-side server code published so the attestation can be checked against a build from source. Duck.ai takes the simplest route of all: chats live in your own browser storage and never reach a server, which also means no sync between devices — the cost of the design rather than a flaw in it.

Each of those answers the same question differently: encryption you hold the key to, hardware you can verify, or nothing stored at all.

Gap 3: there is no anonymous way in, and no claim your IP is ever separated

An account is required before the first message, which ties every conversation to an email address or a linked identity from the outset. That is the durable identifier a history accumulates against — and ChatGPT’s history is designed to accumulate, which is what makes Memory useful across weeks instead of minutes.

Underneath the account, there is a second layer worth naming because it is an absence rather than a weakness. OpenAI’s privacy policy lists IP address, browser type and settings, device information, usage data and location inferred from IP among what it receives through normal use, and nothing in the documentation claims the IP address is separated from the request before processing. That absence is meaningful rather than neutral: products that do strip identity at a proxy layer say so explicitly and describe the mechanism, because it is the kind of claim worth making.

Duck.ai is the clean contrast on both layers at once. No email, no phone number, no card before the first message, so there is nothing for a profile to attach to. And its documentation states that metadata containing personal information — IP address being the example given — is removed before the model is prompted, so the provider sees requests arriving from DuckDuckGo rather than from you, with the company’s privacy policy adding that IP addresses are never logged to disk in a form that could be tied back to a user. Lumo splits the difference deliberately: a guest mode that needs no signup and erases the conversation when the session ends, or an account that buys synced history under encryption the operator cannot read. You pick per use rather than once at signup.

Worth being precise about the limits. Maple requires an account too, because its encryption key is derived from the account credentials — that follows from the design rather than being an arbitrary gate. And neither Duck.ai nor Lumo publishes a separate IP-handling claim in the same form the other does, so this isn’t a field where every alternative beats the default.

The things it simply doesn’t have

Beyond those three gaps, a few things aren’t available at any consumer price:

  • Zero-access storage on any plan. Free, Go, Plus and Pro share the same storage model. There is no tier where OpenAI stops being able to decrypt your conversations.
  • An anonymous entry point. No guest mode, no account-free path, nothing equivalent to opening a page and typing.
  • A published audit a reader can open. The SOC 2 report is real, but access runs through a request process aimed at enterprise buyers, and its period and issue date are not stated publicly — so a Plus subscriber cannot check what the auditor examined or how recently.
  • Better data handling as something you can buy. Paying more adds capability, not protection: the training default, the storage model and the account requirement are identical across every individual tier. The protective default arrives only at the organisational plans.

When ChatGPT is genuinely fine

It is the right answer, not a trap, when:

  • Your use is casual and non-sensitive — drafting, brainstorming, explaining things, code you’d paste into a public forum anyway.
  • You’ve turned the training toggle off and you leave the thumbs buttons alone.
  • You use Temporary Chat for the conversations you’d rather not have persist.
  • You need the capability: the frontier models, deep research, the tool ecosystem. Nothing in the privacy-first set matches that bench, and pretending otherwise would be dishonest.

For a large number of people that describes their actual use, and “just use ChatGPT” is a defensible answer — the free tier especially is a good deal measured in capability per dollar.

Reach for a privacy-first assistant when you want

  • Conversations stored in a form the operator cannot read, so a legal demand returns ciphertext rather than text.
  • No account, or an explicit choice between a session that leaves nothing behind and a history that syncs under your own key.
  • Your IP separated from the request before any model sees it.
  • No-training as the starting position — a contract with the provider, or no outside provider at all — rather than a toggle you have to find.
  • A guarantee resting on hardware and public source code rather than on a policy page.

One caveat belongs here and not in a footnote: no AI chat assistant in this category currently has an independent third-party security audit, ChatGPT’s enterprise-gated SOC 2 included. The privacy-first products trade a capability deficit for an architectural guarantee, and that guarantee still rests largely on each operator’s own description of its systems — in Maple’s case, on a verification chain that only helps users who actually run the comparison.

ChatGPT logo

ChatGPT

The capability benchmark in this category

5.4
out of 10

This link earns us nothing — no tracking, just the review.

Duck.ai logo

Duck.ai

No account, IP stripped, nothing stored server-side

7.5
out of 10

This link earns us nothing — no tracking, just the review.

Lumo logo

Lumo

Zero-access encrypted history, Swiss entity

7.5
out of 10

This link earns us nothing — no tracking, just the review.

Maple logo

Maple

Hardware-attested, zero-access by design

7.6
out of 10

This link earns us nothing — no tracking, just the review.

Summary

ChatGPT is the capability benchmark in this category and nowhere near its privacy benchmark, and both halves of that are meant literally. Its features, free tier, platform coverage and working data controls are real, and so is the audit it holds. Where it doesn’t reach: training on consumer conversations is on by default and a thumbs-up can undo an opt-out, storage is server-side in a form OpenAI can decrypt, an account is mandatory, and no documentation claims your IP is ever separated from your request. None of that is fixable with a setting, because none of it is a setting. If your use is casual and the toggle is off, the default is fine. If you’d rather the question of who can read what you type not be a policy question at all, start with the AI assistants we’ve reviewed.