The FireAI Security Blog

By FireAI Security & Research Team · Published

What AI assistant memory stores, and why viewing, editing and forgetting it matters

What AI assistant memory stores, and why viewing, editing and forgetting it matters

Since 2024, the major AI assistants have added “memory”: facts about the user that persist from one conversation to the next. Memory makes an assistant more useful and also turns it into a profile of its user, held by whoever runs the assistant. This note describes, from the providers’ own documentation, what three assistants remember and how a user can see, correct and delete it; summarises two peer-reviewed results on what the vector representations behind memory search reveal; and recalls a documented attack that writes false memories through prompt injection. It then sets out what AISir, a HisnLabs planner and voice assistant for the Mac, stores, where, and what it does not solve.

Background

Assistant memory usually has two layers. Short-term memory is the current conversation, or a summary of it, passed to the model with each new message. Long-term memory is a store of facts kept between conversations, such as “prefers morning calls” or “works as an architect”. To use long-term memory, the assistant must find which stored facts are relevant to a new message. This is commonly done with embeddings: a model turns each fact into a vector of numbers, so that texts with similar meaning have nearby vectors, and a vector search returns the closest facts. The vectors are then stored next to, or instead of, the text. Two privacy questions follow: who holds the store, and how much the vectors themselves reveal.

Findings

ChatGPT: saved memories, chat history, and deletion in two places

OpenAI’s update of 10 April 2025 states that memory “now references all your past conversations” and “now works in two ways: ‘saved memories’ you’ve asked it to remember and ‘chat history’, which are insights ChatGPT gathers from past chats to improve future ones”. Saved memories are a separate store: “Deleting a chat doesn’t erase its memories; you must delete the memory itself”. The same page adds: “We may use content that you provide to ChatGPT, including memories, to improve our models for everyone. If you’d like, you can turn this off through your Data Controls” [1]. OpenAI’s Memory FAQ says that even after a saved memory is forgotten, “We may retain a log of deleted Saved Memories for up to 30 days for safety and debugging purposes”, and that the notepad of saved memories is “stored separately from your chat history”, so that “even if you delete a chat, any saved memories from it can still be used in future conversations” [2].

Gemini: memory derived from chats, and forgetting by deleting them

Google’s help page explains that users “can ask Gemini to remember details simply by talking to it”, for example “Remember that I am vegetarian.” It also warns: “Instructions for Gemini to forget or avoid topics in chats doesn’t always work perfectly. To make sure Gemini stops mentioning a topic, delete any chats about it from your Gemini Apps Activity” [3]. In other words, the reliable way to make Gemini forget is to delete the source conversations, not to instruct the model.

Claude: a memory summary the user can view and edit

Anthropic’s announcement of 11 September 2025, extended to Pro and Max plans on 23 October 2025, states that “Claude uses a memory summary to capture all its memories in one place for you to view and edit”, that memory is project-scoped (“each project has its own separate memory”), and that “Incognito chat gives you a clean slate for conversations that you don’t want to preserve in memory”. Users can also “export your memory from Claude for backup or migration” [4].

Memory as an attack surface

A memory that the model writes by itself can be written by content the model reads. On 22 May 2024, the security researcher Johann Rehberger described how an attacker could “manipulate your AI assistant (chatbot or agent) to remember false information, bias or even instructions, or delete all your memories”, through indirect prompt injection, that is, instructions hidden in a document or web page the assistant processes [5]. A false memory persists: it influences every later conversation until the user notices and deletes it.

Embeddings are not anonymous

Storing vectors instead of text does not hide the text. Morris and colleagues showed at EMNLP 2023 that “a multi-step method that iteratively corrects and re-embeds text is able to recover” 92 per cent “of 32-token text inputs exactly”, and that their model “can recover important personal information (full names) from a dataset of clinical notes” [6]. Earlier, Song and Raghunathan found that attacks on popular sentence embeddings recover between 50 and 70 per cent of the input words, and that “Attributes such as authorship of text can be easily extracted by training an inference model on just a handful of labeled embedding vectors” [7]. A memory store’s vectors should therefore be treated as being as sensitive as the facts they encode.

What the law expects of forgetting and export

Where the GDPR applies, Article 17 gives a person “the right to obtain from the controller the erasure of personal data concerning him or her without undue delay”, for example where the data “are no longer necessary”, and Article 20 a right to receive data they provided “in a structured, commonly used and machine-readable format” [9]. These rights bind a provider that holds the data. A store kept on the user’s own device involves no provider to ask: the user exercises the equivalent controls directly.

Long-term memory in four assistants, as their documentation describes it (checked 8 October 2026)
AssistantWhere memory is keptView and editForgettingExport
ChatGPTOpenAI’s servers; may be used for training unless turned offView and delete saved memories in SettingsDelete the memory and the chats; deleted memories logged up to 30 daysNot described on the cited pages
GeminiGoogle’s servers, derived from chats (Keep Activity on)Correct by telling GeminiInstructions to forget “doesn’t always work perfectly”; delete the chatsNot described on the cited page
ClaudeAnthropic’s servers, per projectA memory summary to view and editEdit the summary; incognito chats are not saved to memoryExport for backup or migration
AISirThe Mac (Application Support/AISir)Settings › Memory: search, edit, deleteDelete one, “forget that…”, or Forget everythingExport as a JSON file

Implications for Mac users

Three properties distinguish one memory design from another. The first is who writes to it: memories written only on explicit request or confirmation are harder to poison than memories the model infers on its own. The second is whether deleting really deletes: when memory is derived from chats, or logged after deletion, forgetting is layered and delayed. The third is where the store sits: a cloud store is subject to the provider’s retention, training and review policies, while a local store is subject to the security of the device and of the other apps running on it. A local store is not automatically safe; it moves the responsibility to the user and the operating system.

Recommendations

  1. Open the memory settings of every assistant you use and read what it holds about you; delete what is wrong or unnecessary.
  2. Where memory is derived from chats, delete the chats that contain what you want forgotten, not only the memory entry.
  3. Turn off training on your content where the provider allows it, and use incognito or temporary chats for confidential matters.
  4. Be wary of assistants that save memories from documents or web pages without asking; check memory after processing untrusted content.
  5. Treat exported memory files and local memory databases as sensitive: keep them on an encrypted disk and out of shared folders.

Relevance to AISir

AISir 1.0.1 has both layers of memory, and both stay on the Mac. Short-term memory is the current conversation: typed and spoken questions share it, long conversations are summarised, and it is “kept in memory only and forgotten when AISir quits”. Long-term memory holds “clients, preferences, habits and routines”. A fact is kept when the user says or types “remember that…”, or answers yes when AISir asks “Shall I remember that?”: “nothing is kept until you say yes or click Remember”. With Remember habits automatically on (on by default, and it can be turned off), AISir also keeps the user’s usual working hours, worked out from tasks; routines are kept only if the user clicks Make it a routine. Its Help states that memory “stays on this Mac, in its database in Application Support/AISir”, and that it “never keeps anything about health, religion, politics or sexuality”. Memory search uses sqlite-vec, which its authors describe as “An extremely small, ‘fast enough’ vector search SQLite extension” [8], and Apple’s on-device NaturalLanguage embedding, part of macOS. Settings › Memory offers search, edit, delete, Export (a JSON file) and Forget everything, and by voice “forget that…” or “oublie tout”. Web lookups, off by default, never send memories. Details are on the AISir page.

AISir does not encrypt its database beyond what macOS provides, so FileVault and the user account protect it. Recall for Arabic notes is weaker: AISir’s roadmap notes that Apple’s Arabic contextual embedding model is not installed by default. The model is small and makes mistakes, answers take about four seconds, and AISir runs only on Apple silicon with macOS 15. An exported JSON file leaves AISir’s control once saved.

Limitations

This note relies on documentation, not on tests of the assistants. Provider pages change often, and both OpenAI pages were read through archived copies because the live pages refuse automated readers. The embedding-inversion results were obtained on specific models and text lengths and do not measure any assistant named here. The memory-injection report describes ChatGPT in 2024; OpenAI may have changed its behaviour since. AISir’s description comes from its own Help and roadmap, and HisnLabs makes AISir, which readers should weigh. Related reading: prompt injection and AI agents and poisoned prompts and embedded AI.

How FireAI and HisnLabs fit in

A memory kept on the device is private only while the apps on that device keep it there. FireAI shows, per app, every connection your Mac opens, so an AI app that uploads more than it should is visible, and can be blocked.

FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac.

You can read the technical decisions behind it, or try FireAI for 17 days, at FireAI, by HisnLabs.

Sources