Field notes / 06 · Privacy in practice
AI Chat Exposure: Choose the Right Recovery Route
First identify what happened. A message you regret sending, a stolen login and a public conversation link need different responses. Avoid creating more copies of the exposed material while you investigate.

Match the first action to the situation
| Situation | Start here | Do not assume |
|---|---|---|
| You sent personal information | Identify the category and use the documented removal or privacy-request route. | A conversational “forget this” request equals system-wide deletion. |
| Someone accessed your account | Use official account recovery and secure the linked sign-in account. | A data-deletion request will remove an intruder’s access. |
| A conversation link is public | Revoke it if possible and contact the host’s removal channel. | Revoking a link recalls copies already saved by other people. |
| The provider reports an incident | Read its official notice and follow instructions relevant to the affected data. | Every user and every data category were necessarily affected. |
When a login is compromised
Navigate to the official app or website yourself rather than following an unexpected recovery message. Recover the account through its documented process. After regaining access, change the password, end other sessions where supported, enable two-factor authentication if available and inspect recovery details.
The FTC’s account-recovery guidance also emphasizes protecting email, because it can receive password-reset links. These are general recovery principles; the companion app’s controls and support process determine the exact steps. A reused password warrants attention on other accounts where you used it.
Keep the smallest useful incident record
Record the discovery time, affected service, relevant URL or request identifier, broad data category and action taken. For example: “Shared conversation URL accessible while signed out; revocation requested; ticket reference recorded.” Avoid copying the full conversation into the log.
If you need a screenshot to document a report, keep it privately and redact unrelated details before sharing it with verified support. Do not repost the exposed material to ask a public forum whether it is sensitive. When threats are involved, preserve relevant evidence before removing what you control.
When the information comes from an incident notice
Check whether the notice identifies affected accounts, data categories, dates and a verified contact. Separate confirmed facts from what is still under investigation. A headline or another user’s report does not establish that your own conversation was included.
Ask targeted questions: “Does this incident include my account or only a different system? Which categories were involved? What action is recommended for my account?” Do not send identity documents or chat archives to an unverified contact claiming to investigate the incident.
Contain access, then address retained data
Once access is under control, decide whether you want to keep the account, remove selected records or leave. Use the deletion plan for that separate decision. Neither account recovery nor deletion guarantees removal of copies already held by another person.
If the incident includes credible threats or immediate danger, prioritize your physical safety and contact appropriate local emergency services. For a content-removal request, use the platform’s official reporting process and share only the evidence it needs.
Make it practical
Keep your own record
Download the blank worksheet and fill it in privately. No account or upload is needed; nothing you write in the downloaded file is sent to this site.
Download worksheet · CSVScope: editorial guidance and official documentation checked on September 18, 2026. No in-app deletion tests or infrastructure audit were performed. Illustrative scenarios are fictional. Evidence method · Website privacy