What “Deleting Your AI Therapy Data” Actually Means
Deleting your data from an AI therapy or wellness app is not necessarily one action. It may require separate requests to the chatbot provider, the app company, its cloud infrastructure provider, and any third parties that received or derived information from your conversations. A visible “Delete chat” button often removes the conversation only from that interface; it may not erase voice recordings, account records, support tickets, analytics, model-training datasets, backups, or information retained to meet legal and safety duties. The first step is therefore to identify every place your data was entered and which entity controls each copy.
Also worth reading: Is AI Therapy Data Safe for Private Mental Health Conversations? · How Do AI Therapy Privacy Settings Protect Your Conversations in 2026? · Is Safe AI Therapy Use Possible for Stress, Anxiety, and Depression in 2026?
The exact deletion process depends on whether the service is a standalone AI companion, a mental-health app with an AI feature, a general chatbot configured for emotional support, or a platform connected to a therapist directory. Consumer chatbots may offer account-deletion controls, while regulated health products can face medical-record retention requirements. Even then, privacy rules usually do not require indefinite storage merely because sensitive information was once discussed. The relevant distinction is whether information is being kept as an active health record, ordinary business data, safety evidence, or a legally required financial or security record.
No reputable provider should promise that one button permanently erases every trace everywhere unless it can explain the scope, backup schedule, processors, and lawful-retention exceptions. “Delete from my history” and “delete my account” are different operations, and neither automatically equals deletion from all derived datasets. As of October 1, 2026, users should ask for written confirmation identifying the categories removed, categories retained, third parties notified, and the date deletion became effective.
Why AI Therapy Conversations Are Especially Sensitive
AI therapy conversations can contain more obvious identity data than most shopping records. A person may disclose their name, address, relationships, employment status, medications, diagnoses, trauma, suicidal thoughts, sexual orientation, financial stress, or details about another person. Some systems also infer psychological traits from writing style, voice, timing, and behavioral patterns. The American Psychological Association has warned about generative-AI chatbots and wellness applications used for mental health, emphasizing that these tools can create privacy, safety, bias, and dependency concerns.
The risk comes from several collection channels rather than from AI alone. Text chat, microphone input, camera use, voice transcription, attachments, geolocation, device identifiers, cookies, crash reports, and support messages can all create records. A platform may also place information in a general account database, transmit it to a model host, retain it for abuse monitoring, or send limited event data to advertising and analytics vendors. The data may later be accessed by administrators, contractors, researchers, corporate buyers, or parties involved in litigation and regulatory requests.
Regulation and industry practice remain uneven across jurisdictions. Vermont’s reported 2026 action concerning AI-only therapy and data-broker practices shows why consumers should not assume that an emotional-support chatbot is legally or technically equivalent to licensed behavioral healthcare. Rules governing consumer health data, state privacy rights, medical records, children’s information, and automated decision-making can apply differently depending on the service and user location. This means a deletion request should be grounded in the provider’s actual terms and applicable law, not an assumption that every AI conversation receives medical-record protections.
How to Request Deletion From an AI Mental-Health Service
Begin inside the service by looking for Settings, Privacy, Data Controls, Download My Data, Delete Account, or “Manage your information.” Export anything you need before deletion, because some providers disable account access immediately after accepting a request. Take screenshots of the relevant policy, account identifiers, conversation history, consent settings, and confirmation message. Use your registered email address so the request is linked unambiguously to the account.
If self-service controls are insufficient, send a direct, written request to the privacy or data-protection team. Identify the service, account email, approximate date range, and the exact scope requested: chats, voice files, account profile, inferred profiles, support records, analytics identifiers, training copies, and downstream processors. Ask the company to confirm whether the deletion request covers human review logs, backups, and information previously disclosed to model-training systems. A clear request prevents the provider from merely closing the account while retaining the underlying conversation archive.
For an app distributed by a larger company, send the same request to both the visible app developer and parent corporation. Mobile-app listings can reveal the publisher, and a privacy-policy page often lists subprocessors, cloud vendors, and data-protection contacts. If you used a general chatbot in a therapy-like role, disable custom-memory features and training controls first; those settings may affect future use but may not retroactively remove stored records. If you are a minor or the account belongs to a child, state that fact because additional deletion duties may apply.
Keep the request and all replies. Most deletion workflows take days rather than months, but a longer period can be reasonable for identity verification, archived-account review, and routine backup rotation. As of October 1, 2026, a practical follow-up point is 14 days after the initial request, followed by a formal complaint if the provider has not supplied a meaningful status or retention schedule. Avoid sending new medical details in a support ticket; refer only to the conversation already stored by the company.
What Providers Should Delete, Processors, and Retain
The proper response should remove data for which there is no continuing legal need. In many services, that includes active chat transcripts, generated summaries, uploaded attachments, remembered facts, account identifiers no longer required, and psychological profile attributes inferred for personalization. Deletion notices should also address data held by contractors and cloud vendors under contract. Some providers can remove live production records immediately, while backup copies expire under an ordinary rotation cycle that may run from approximately 30 to 365 days.
Retention is not automatically misconduct, but it must be specific. A provider may need to preserve a small subset of billing evidence, tax records, fraud-prevention signals, or legally required health records for a stated period. Safety logs may also be retained when there is a documented legal basis. These exceptions should be narrow and disclosed rather than used to preserve the entire emotional conversation indefinitely. The provider should be able to distinguish searchable operational records from de-identified, aggregated, or irreversibly transformed statistics.
AI-training data is the hardest category because the company may need to locate the relevant dataset, determine whether the text was used directly, and distinguish operational storage from future-model safeguards. Asking for “deletion from all databases” is useful, but a credible answer should explain whether the request can reach unopened training files, statistical derivatives, or examples already incorporated into a trained model. A company may be unable to reverse an already trained model, yet it can still promise not to use the information for future training where technically and legally feasible.
| Feature | Consumer AI chatbot | AI-enabled therapy app | Licensed therapy practice | Human-led treatment using approved AI tools |
|---|---|---|---|---|
| Typical deletion route | Settings, support, privacy request | App controls plus account request | Private health information request to practice | Request to both practice and software vendor |
| Main stored data | Chats, memory, voice, identifiers | Chats, symptom journals, notes, attachments | Clinical notes and regulated records | Clinical records plus limited technical data |
| Backup deletion | Often stated as a retention cycle | Often stated as a retention cycle | Governed by policy and law | Separate vendor and practice schedules |
| Training-data response | Depends on provider settings and architecture | Varies; app training consent may be relevant | Generally not used for external model training without authorization | Must follow consent, confidentiality, and vendor terms |
| Best protection | Minimal disclosures and verified deletion | Clear in-product controls and written confirmation | Formal records and privacy procedures | Purpose-limited tools with a covered entity controlling disclosure |
The safest way to reduce the stored AI-therapy footprint is not necessarily to seek a more elaborate chatbot. It is to choose a service that needs less data for its intended function. A meditation timer without conversation, a journaling app with local storage, or a crisis-resource directory may answer a limited need without building a detailed behavioral profile. No-storage promises must still be checked because crash reports, authentication records, and aggregate analytics can remain.
For personality exploration, general-purpose AI tools can be configured with instructions not to retain memory or use chats for training where those controls exist. Temporary or incognito-style modes may reduce conversational history, but they do not guarantee that the company cannot recover content from security logs or infer traits during processing. Browser-based tools from established providers may offer account-wide controls that are easier to verify than an unidentified app with no public privacy documentation.
Human-led support remains a distinct alternative rather than a direct substitute. A licensed therapist or qualified clinician can provide crisis assessment, diagnosis, and treatment that an AI-only product should not imply it can deliver. AI may assist some professional workflows, but its use introduces questions about privilege, consent, note accuracy, vendor access, and secondary use. People in acute danger, suspected abuse, psychosis, mania, severe substance withdrawal, or immediate suicide risk should contact local emergency services or a crisis service instead of relying on a deletion or chatbot workflow.
Cost can affect the decision. Consumer AI subscriptions often range from free tiers to roughly $20–$30 per month, while premium plans can reach about $200 per month. A privacy-focused service may not cost more; the stronger evidence is the available deletion control, transparent retention period, limited collection, and clear use of subprocessors. Paying more does not itself erase a conversation, and a cheap service is not necessarily unsafe if it genuinely avoids training and allows verified account deletion.
Mistakes That Leave Sensitive Data Behind
A common mistake is assuming that deleting the conversation immediately removes the account. A user may clear the visible chat and leave the account, inferred memory, uploaded documents, payment history, and support messages intact. The opposite mistake is requesting deletion while still expecting personalized therapy to continue; once core context is erased, a chatbot may lose continuity because that context was the “memory” holding the relationship together.
Another mistake is relying on an opt-out setting that affects only future training. A setting described as “Do not train on my chats” may not control abuse monitoring, account security, service improvement with consent, or a separate health-app integration. Users should review the exact setting’s temporal scope and ask whether existing data is covered. Removing an app from a phone also does not delete server-side records, so uninstalling should come after, or alongside, a documented deletion request.
Do not post the sensitive conversation publicly while seeking help, even if fragments are “anonymized.” Names can be removed while combinations of workplace, relationships, dates, location, and rare health facts still identify someone. Do not claim that every provider must delete every record at once; the legally accurate request asks for deletion where required, restriction where deletion cannot lawfully occur, and disclosure of the retention period. Finally, do not accept vague reassurance that data is “encrypted.” Encryption protects data during storage or transmission; it does not prevent a service or authorized processor from reading it.
When to Escalate, and How Long Deletion Should Take
Escalate when the provider cannot identify its data categories, offers no privacy contact, denies that a deletion happened after a valid request, or retains a full transcript without a stated legal basis. First use the company’s privacy or consumer-protection complaint process. If the delay continues, contact the relevant privacy authority or consumer-protection agency in the user’s jurisdiction. Payment, app-store, and developer complaints can also create an official record, although they do not replace legal remedies.
The appropriate timeline depends on verification and the complexity of the request. A simple consumer account may be closed within 24–30 days, while a health-record request may follow a formal process lasting up to 30 days or another period required by applicable law. Complex requests involving backups, litigation holds, or multiple processors can take longer. The crucial factual question is not whether a standard number was exceeded; it is whether the provider acknowledged the request, made a decision within a lawful period, and explained any exception.
A deletion request from 2026 should generate a dated receipt. Follow up after 14 days for ordinary consumer services if there has been no response, and sooner if data could cause immediate harm. Preserve the account identifier, policy versions, screenshots, emails, and reference numbers without duplicating the therapy content yourself. If a breach or unauthorized disclosure may have occurred, a deletion request is still important, but it does not replace changing passwords, revoking sessions, reporting the incident, or seeking advice about identity theft and privacy rights.
A Sensible Privacy Standard for AI Psychological Support
By October 1, 2026, responsible AI psychological-support services should be judged by operational evidence rather than marketing language. Users need to know what is collected, whether conversations are used for model training, which vendors receive data, where records are stored, how long they remain, and how to delete them. The service should not condition basic privacy on a subscription, and it should offer a process that reaches both the account and the underlying personal information. Any refusal or limitation should identify a specific legal or technical reason.
Psychological profiling adds another risk. A chat model can create plausible observations about attachment, personality, diagnosis, or future behavior, but those outputs may be wrong and become damaging if stored as fact. A responsible service should distinguish a user’s own disclosures from model inference, provide a way to inspect or remove inferred attributes, and avoid treating sensitive estimates as verified mental-health conclusions. The goal is not to make mental-health support risk-free—every online service has security risks—but to prevent unnecessary collection from becoming permanent.
The most defensible process is simple: use the product, export anything needed, turn off memory and training permissions where available, submit a written deletion request, and demand a scoped confirmation. Do not upload third-party secrets merely because a model “forgets” after a new conversation. The least exposed service is often the one designed for a narrow purpose and obligated to retain the least amount. For crisis situations or treatment decisions, human clinical care should remain the reference point, while AI tools should be treated as optional aids with bounded functions and verifiable data controls.