Shared AI Chat Link Digital Footprint
Executive Summary
Sharing an AI chat link creates a public web page that persists independently of the original conversation and can outlive account‑level deletion of the source chat. Across the three platforms audited—Google Gemini, OpenAI ChatGPT, and DeepSeek—the risk profiles differ significantly.
ChatGPT offers the most mature link management (centralized dashboard, bulk deletion, no personal name exposed) but links persist indefinitely with no expiration and cannot recall copies imported by other users.
Gemini provides public‑link management through Google Account settings and configurable auto‑delete periods, but human‑reviewed chats are retained for up to three years regardless of user deletion actions. DeepSeek presents the highest risk: shared links were indexed by Google in July 2026 due to missing noindex tags, no centralized link dashboard existed initially, and all personal data is stored in the People's Republic of China with no fixed retention period.
“DeepSeek shared links were discoverable via site:chat.deepseek.com/share Google searches, exposing work documents, financial analysis, medical questions, and personal conversations to anyone on the internet—not a data breach, but a consequence of missing indexing controls combined with user‑created public links.”
Platform‑by‑Platform Audit
Google Gemini
Shared‑Link Persistence
When a Gemini chat is shared, a public link is created that allows “anyone with the link” to view the conversation. Links can be managed through the “Your Public Links” section in Google Account settings. No documented expiration mechanism exists for public links in the sources reviewed, and it is not documented whether deleting the source chat or auto‑delete periods affect public links.
Metadata Visible to Link Viewers
Google’s official documentation does not provide a detailed breakdown of what metadata is visible to public link viewers. The guidance implies that full conversation content (prompts and responses) is visible, while internal retention includes language, device type, location info, and feedback for human‑reviewed chats.
Link Deletion Behavior
Public links can be managed and deleted through “Your Public Links” in Google Account settings. Manual deletion of chats is available via the Gemini interface or via myactivity.google.com, and Google’s backend deletion process generally takes around two months including a recovery period.
Internal (Unshared) Chat Retention
| Setting | Retention Period | Source |
|---|---|---|
| Default auto‑delete (Gemini Apps Activity ON) | 18 months | Gemini Apps Privacy Hub |
| Configurable auto‑delete options | 3, 18, 36 months, or indefinite | Gemini Apps Privacy Hub |
| Keep Activity OFF | Chats stored for up to 72 hours | Google Support |
| Human‑reviewed chats | Up to 3 years (not deleted by user activity deletion) | Gemini Apps Privacy Hub |
| Usage frequency data | Until Google Account deletion | Gemini Apps Privacy Hub |
Critical gap: Even when users delete their Gemini Apps activity, chats that were reviewed by human reviewers (along with language, device type, location info, and feedback) are retained for up to three years and are not removed by activity deletion.
OpenAI ChatGPT
Shared‑Link Persistence
ChatGPT shared links are created via the Share button and generate URLs at https://chatgpt.com/share/<conversation‑ID>. There is no expiration‑date functionality currently available for shared links. Shared links include a snapshot of the conversation up to the point when the link is shared and do not auto‑update.
Metadata Visible to Link Viewers
OpenAI explicitly states that “shared links do not include the creator's name or any other personal information.” The visible content includes the full conversation history (prompts and responses), including any uploaded files or images that were part of the conversation.
Link Deletion Behavior
| Deletion Action | Effect |
|---|---|
| Delete individual shared link | Link becomes inaccessible; source chat remains |
| Delete original conversation | Shared link is also deleted; content no longer accessible |
| Delete account | All shared links are deleted and no longer accessible |
Critical limitation: If a viewer imported the conversation into their own chat history, that copy is not deleted when the shared link, source conversation, or account is deleted.
Internal (Unshared) Chat Retention
| Chat Type | Retention | Source |
|---|---|---|
| Standard chats | Saved until manually deleted | OpenAI Help Center |
| Deleted chats | Removed from account immediately; permanent deletion within 30 days | OpenAI Help Center |
| Temporary Chats | Automatically deleted within 30 days | OpenAI Help Center |
| Archived chats | Same retention as unarchived; remain in account | OpenAI Help Center |
| Library files | Managed separately from chats | OpenAI Help Center |
| Enterprise file uploads | Expire after 48 hours; backups may retain for up to 30 additional days | OpenAI Help Center |
DeepSeek
Shared‑Link Persistence
DeepSeek’s share feature creates static snapshots of conversations. Shared links are static and do not auto‑update if the user continues the chat. No documented expiration period exists, and shared links are created at chat.deepseek.com/share/ URLs.
Metadata Visible to Link Viewers
DeepSeek’s shared pages expose more metadata than the other two platforms: full prompts and responses, filenames of uploaded documents, and timestamps via an inserted_at metadata field visible through browser developer tools.
Link Deletion Behavior
DeepSeek’s link management has evolved from having no centralized dashboard to offering per‑link deletion via Settings → Data → Shared Links → Manage. No bulk‑delete option is documented, and there is no guarantee that deleting a shared link removes it from search engine caches or third‑party copies.
Search Engine Indexing Incident (July 2026)
On July 21, 2026, Google indexed thousands of DeepSeek shared conversations, discoverable via site:chat.deepseek.com/share. Exposed content included work documents, accounting reports, cryptocurrency and gold‑market analysis, personal conversations, and medical questions, largely due to missing noindex tags and inadequate indexing controls.
Internal (Unshared) Chat Retention
| Aspect | DeepSeek Policy | Source |
|---|---|---|
| Fixed retention period | Not published; depends on purpose, sensitivity, legal requirements, and business interests | Secondary analysis |
| Data storage location | People's Republic of China | Secondary analysis |
| Chat history deletion | No guarantee of complete removal from backups, logs, or caches | Secondary analysis |
| Model training opt‑out | Opt‑out does not delete previous chats, cached data, or logged data | Secondary analysis |
Comparison Matrix
| Dimension | Google Gemini | OpenAI ChatGPT | DeepSeek |
|---|---|---|---|
| Link persistence | No documented expiration; management via “Your Public Links” | No expiration; active until link or source chat deleted | No documented expiration; static snapshot |
| Link management dashboard | “Your Public Links” in Google Account | Settings → Data Controls → Shared links → Manage | Per‑link management via Settings → Data → Shared Links → Manage (third‑party sources) |
| Bulk link deletion | Not documented | Yes — delete all shared links | Not documented |
| Profile name visible | Not documented | Explicitly excluded | Not documented |
| Timestamps visible | Not documented | Not documented | Yes — via inserted_at metadata |
| Uploaded file names visible | Not documented | Visible if part of conversation | Yes — filenames visible |
| Search engine indexing risk | No incident found | No incident found | Confirmed indexed by Google (July 2026) |
| Internal chat default retention | 18 months (configurable) | Until manual deletion | No fixed period published |
| Temporary/ephemeral mode | Keep Activity OFF (72 hours) | Temporary Chat (30‑day auto‑delete) | None documented |
| Human review retention | Up to 3 years | Not documented | Not documented |
| Data storage jurisdiction | EU/Switzerland or global | US‑based | People's Republic of China |
Risk Scoring
Gemini
| Risk Factor | Likelihood (1–5) | Impact (1–5) | Risk Band | Notes |
|---|---|---|---|---|
| Shared link remains active after chat auto‑deletion | 3 | 3 | Moderate | Auto‑delete may not affect public links |
| Human‑reviewed data retained 3 years despite deletion | 5 | 3 | High | Confirmed by policy; not user‑controllable |
ChatGPT
| Risk Factor | Likelihood | Impact | Risk Band | Notes |
|---|---|---|---|---|
| No link expiration | 5 | 3 | High | No expiration functionality |
| Imported copies persist after all deletion | 5 | 4 | Critical | No user remedy |
DeepSeek
| Risk Factor | Likelihood | Impact | Risk Band | Notes |
|---|---|---|---|---|
| Search engine indexing of shared links | 5 | 5 | Critical | Confirmed incident; no noindex tags |
| No fixed retention period | 5 | 4 | Critical | Retention timelines not published |
Sanitization Checklist
Phase 1: Enumerate All Shared Links
- Gemini: Google Account → “Your Public Links”; cross‑reference Gemini activity.
- ChatGPT: Settings → Data Controls → Shared links → Manage.
- DeepSeek: Settings → Data → Shared Links → Manage; search site:chat.deepseek.com/share.
Phase 2: Revoke and Delete Public Links
- Gemini: Delete public links; delete source chats; remove Gemini activity.
- ChatGPT: Delete shared links; delete source chats; clear Library files.
- DeepSeek: Delete shared links; delete source chats; submit URL removal requests to search engines.
Phase 3: Harden Privacy Settings
- Adjust auto‑delete periods.
- Consider disabling activity/training for sensitive work.
- Review third‑party access and security settings.
Phase 4: Audit Search Engine Exposure
- Search site:chatgpt.com/share and site:chat.deepseek.com/share.
- Search unique phrases and filenames from shared conversations.
- Use removal tools (Google, Bing) for indexed links.
Phase 5: Ongoing Hygiene
- Never share passwords, API keys, personal identifiers, medical or financial records.
- Rotate exposed secrets immediately.
- Review and delete shared links monthly.
- Prefer redacted screenshots for sensitive but non‑interactive content.
Evidence Gaps and Verification Steps
| Gap | Platform | Recommended Verification |
|---|---|---|
| Whether Gemini public links are affected by auto‑delete periods | Gemini | Create a test chat, share it, set auto‑delete, and verify link behavior after the period. |
| Whether ChatGPT shared links have noindex tags | ChatGPT | Inspect HTML source of a shared link page for <meta name="robots" content="noindex">. |
| Whether DeepSeek has added noindex tags post‑incident | DeepSeek | Inspect shared link HTML and robots.txt at chat.deepseek.com/robots.txt. |
Prepared by @liB‑Ai
London, UK — August 5, 2026
Comments
Post a Comment