Who can see your chats
What is private to you, what your administrators can and cannot see, and how long anything is kept
The short answer: your conversations are yours. Nobody else in your organisation sees them unless you share them, and administrators have no button that reveals them.
Your conversations
A chat belongs to the account that created it. It does not appear in anyone else's history, search results or exports.
Sharing is the only way a chat leaves your account, and it is always something you do deliberately — see Shared chats. A shared chat becomes a read-only link; you can revoke it again at any time.
What administrators can and cannot see
Your organisation's administrators manage settings, not content.
| They can | They cannot |
|---|---|
| Set which AI models are available | Read your conversations |
| Set a maximum retention period for the organisation | Search your chats |
| See usage figures — message counts, cost, which models were used | See what you asked or what the AI answered |
| See who did what in the audit log | See conversation content in the audit log |
Two related settings do exist, and both are narrower than they sound. An organisation can switch on visibility of unshared custom apps and unshared document folders for its administrators. Neither covers conversations: there is no equivalent setting for chats, and no administrator role grants one.
If your organisation runs the meeting assistant or dictation, those transcripts follow their own retention settings, which an administrator does control. Chats are separate.
How long anything is kept
Retention is measured in days and set in two places: by you, for your own account, and by your organisation, as a cap.
The stricter of the two always wins. If your organisation caps retention at 32 days you cannot choose to keep chats for a year; if you choose 7 days, your chats go after 7 even though the organisation would have allowed 32.
Available periods are 1, 7, 32, 95 and 365 days, or keep until I delete them. An organisation that has never set a cap is on "keep until deleted", so the only limit is your own choice.
Set yours under Data storage → General.
What deletion actually does
When the retention period elapses, the conversation is removed from the database — not hidden, not archived, and not recoverable by you or by support afterwards. The same applies when you delete a chat by hand or wipe your whole history.
Deleting an account works in two steps. The account is deactivated immediately — you can no longer sign in and you disappear from your organisation — and is then retained for 30 days before it is permanently deleted. Custom apps, projects and whole organisations follow the same pattern.
The 30 days exist so a deletion made in error can still be undone. After that the data is gone for good.
Deletion is not the same as recall. If you shared a chat as a link and someone copied the text out of it before you revoked the link, that copy is theirs and beyond our reach. Treat a shared link like any other document you have sent.
Where the data is
All processing and storage happens on European infrastructure. The precise controller, processors and legal basis for your organisation are set out in the privacy notice linked at the bottom of every page — and if your organisation runs DeutschlandGPT under its own branding, that link points at your organisation's own notice rather than ours.
For the contractual side — data processing agreement, sub-processors, certifications — talk to your organisation's administrator or contact us.