# What AI assistant memory stores, and why viewing, editing and forgetting it matters

> ChatGPT, Gemini and Claude now remember users. What their memory keeps, how forgetting works, what embeddings leak, and what keeping memory on a Mac changes.

FireAI Security & Research Team (HisnLabs) · Published 2026-10-08
Canonical: https://hisnlabs.com/en/blog/ai-assistant-memory-what-it-stores-and-how-to-forget

Since 2024, the major AI assistants have added “memory”: facts about the user that persist from one conversation to the next. Memory makes an assistant more useful and also turns it into a profile of its user, held by whoever runs the assistant. This note describes, from the providers’ own documentation, what three assistants remember and how a user can see, correct and delete it; summarises two peer-reviewed results on what the vector representations behind memory search reveal; and recalls a documented attack that writes false memories through prompt injection. It then sets out what AISir, a HisnLabs planner and voice assistant for the Mac, stores, where, and what it does not solve.

## Background

Assistant memory usually has two layers. Short-term memory is the current conversation, or a summary of it, passed to the model with each new message. Long-term memory is a store of facts kept between conversations, such as “prefers morning calls” or “works as an architect”. To use long-term memory, the assistant must find which stored facts are relevant to a new message. This is commonly done with embeddings: a model turns each fact into a vector of numbers, so that texts with similar meaning have nearby vectors, and a vector search returns the closest facts. The vectors are then stored next to, or instead of, the text. Two privacy questions follow: who holds the store, and how much the vectors themselves reveal.

## Findings

### ChatGPT: saved memories, chat history, and deletion in two places

OpenAI’s update of 10 April 2025 states that memory “now references all your past conversations” and “now works in two ways: ‘saved memories’ you’ve asked it to remember and ‘chat history’, which are insights ChatGPT gathers from past chats to improve future ones”. Saved memories are a separate store: “Deleting a chat doesn’t erase its memories; you must delete the memory itself”. The same page adds: “We may use content that you provide to ChatGPT, including memories, to improve our models for everyone. If you’d like, you can turn this off through your Data Controls” [[1]](https://openai.com/index/memory-and-new-controls-for-chatgpt/). OpenAI’s Memory FAQ says that even after a saved memory is forgotten, “We may retain a log of deleted Saved Memories for up to 30 days for safety and debugging purposes”, and that the notepad of saved memories is “stored separately from your chat history”, so that “even if you delete a chat, any saved memories from it can still be used in future conversations” [[2]](https://help.openai.com/en/articles/8590148-memory-faq).

### Gemini: memory derived from chats, and forgetting by deleting them

Google’s help page explains that users “can ask Gemini to remember details simply by talking to it”, for example “Remember that I am vegetarian.” It also warns: “Instructions for Gemini to forget or avoid topics in chats doesn’t always work perfectly. To make sure Gemini stops mentioning a topic, delete any chats about it from your Gemini Apps Activity” [[3]](https://support.google.com/gemini/answer/16598625). In other words, the reliable way to make Gemini forget is to delete the source conversations, not to instruct the model.

### Claude: a memory summary the user can view and edit

Anthropic’s announcement of 11 September 2025, extended to Pro and Max plans on 23 October 2025, states that “Claude uses a memory summary to capture all its memories in one place for you to view and edit”, that memory is project-scoped (“each project has its own separate memory”), and that “Incognito chat gives you a clean slate for conversations that you don’t want to preserve in memory”. Users can also “export your memory from Claude for backup or migration” [[4]](https://www.anthropic.com/news/memory).

### Memory as an attack surface

A memory that the model writes by itself can be written by content the model reads. On 22 May 2024, the security researcher Johann Rehberger described how an attacker could “manipulate your AI assistant (chatbot or agent) to remember false information, bias or even instructions, or delete all your memories”, through indirect prompt injection, that is, instructions hidden in a document or web page the assistant processes [[5]](https://embracethered.com/blog/posts/2024/chatgpt-hacking-memories/). A false memory persists: it influences every later conversation until the user notices and deletes it.

### Embeddings are not anonymous

Storing vectors instead of text does not hide the text. Morris and colleagues showed at EMNLP 2023 that “a multi-step method that iteratively corrects and re-embeds text is able to recover” 92 per cent “of 32-token text inputs exactly”, and that their model “can recover important personal information (full names) from a dataset of clinical notes” [[6]](https://arxiv.org/abs/2310.06816). Earlier, Song and Raghunathan found that attacks on popular sentence embeddings recover between 50 and 70 per cent of the input words, and that “Attributes such as authorship of text can be easily extracted by training an inference model on just a handful of labeled embedding vectors” [[7]](https://arxiv.org/abs/2004.00053). A memory store’s vectors should therefore be treated as being as sensitive as the facts they encode.

### What the law expects of forgetting and export

Where the GDPR applies, Article 17 gives a person “the right to obtain from the controller the erasure of personal data concerning him or her without undue delay”, for example where the data “are no longer necessary”, and Article 20 a right to receive data they provided “in a structured, commonly used and machine-readable format” [[9]](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679). These rights bind a provider that holds the data. A store kept on the user’s own device involves no provider to ask: the user exercises the equivalent controls directly.

| Assistant | Where memory is kept | View and edit | Forgetting | Export |
| --- | --- | --- | --- | --- |
| ChatGPT | OpenAI’s servers; may be used for training unless turned off | View and delete saved memories in Settings | Delete the memory and the chats; deleted memories logged up to 30 days | Not described on the cited pages |
| Gemini | Google’s servers, derived from chats (Keep Activity on) | Correct by telling Gemini | Instructions to forget “doesn’t always work perfectly”; delete the chats | Not described on the cited page |
| Claude | Anthropic’s servers, per project | A memory summary to view and edit | Edit the summary; incognito chats are not saved to memory | Export for backup or migration |
| AISir | The Mac (Application Support/AISir) | Settings › Memory: search, edit, delete | Delete one, “forget that…”, or Forget everything | Export as a JSON file |

*Long-term memory in four assistants, as their documentation describes it (checked 8 October 2026)*

> AISir keeps its memory on your Mac, where Settings › Memory lists every fact it holds. You can search it, edit it, export it, or say “forget that…”, and nothing is kept until you say yes. [Download FireAI for Mac](https://hisnlabs.com/fireai/en/download)

## Implications for Mac users

Three properties distinguish one memory design from another. The first is who writes to it: memories written only on explicit request or confirmation are harder to poison than memories the model infers on its own. The second is whether deleting really deletes: when memory is derived from chats, or logged after deletion, forgetting is layered and delayed. The third is where the store sits: a cloud store is subject to the provider’s retention, training and review policies, while a local store is subject to the security of the device and of the other apps running on it. A local store is not automatically safe; it moves the responsibility to the user and the operating system.

## Recommendations

1. Open the memory settings of every assistant you use and read what it holds about you; delete what is wrong or unnecessary.
2. Where memory is derived from chats, delete the chats that contain what you want forgotten, not only the memory entry.
3. Turn off training on your content where the provider allows it, and use incognito or temporary chats for confidential matters.
4. Be wary of assistants that save memories from documents or web pages without asking; check memory after processing untrusted content.
5. Treat exported memory files and local memory databases as sensitive: keep them on an encrypted disk and out of shared folders.

## Relevance to AISir

AISir 1.0.1 has both layers of memory, and both stay on the Mac. Short-term memory is the current conversation: typed and spoken questions share it, long conversations are summarised, and it is “kept in memory only and forgotten when AISir quits”. Long-term memory holds “clients, preferences, habits and routines”. A fact is kept when the user says or types “remember that…”, or answers yes when AISir asks “Shall I remember that?”: “nothing is kept until you say yes or click Remember”. With Remember habits automatically on (on by default, and it can be turned off), AISir also keeps the user’s usual working hours, worked out from tasks; routines are kept only if the user clicks Make it a routine. Its Help states that memory “stays on this Mac, in its database in Application Support/AISir”, and that it “never keeps anything about health, religion, politics or sexuality”. Memory search uses sqlite-vec, which its authors describe as “An extremely small, ‘fast enough’ vector search SQLite extension” [[8]](https://github.com/asg017/sqlite-vec), and Apple’s on-device NaturalLanguage embedding, part of macOS. Settings › Memory offers search, edit, delete, Export (a JSON file) and Forget everything, and by voice “forget that…” or “oublie tout”. Web lookups, off by default, never send memories. Details are on the [AISir page](https://hisnlabs.com/aisir/en).

AISir does not encrypt its database beyond what macOS provides, so FileVault and the user account protect it. Recall for Arabic notes is weaker: AISir’s roadmap notes that Apple’s Arabic contextual embedding model is not installed by default. The model is small and makes mistakes, answers take about four seconds, and AISir runs only on Apple silicon with macOS 15. An exported JSON file leaves AISir’s control once saved.

> Ask AISir “when should I call Benali?” and it answers from the memory on your Mac, found with an on-device vector search. Try AISir 1.0.1 free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/fireai/en/download)

## Limitations

This note relies on documentation, not on tests of the assistants. Provider pages change often, and both OpenAI pages were read through archived copies because the live pages refuse automated readers. The embedding-inversion results were obtained on specific models and text lengths and do not measure any assistant named here. The memory-injection report describes ChatGPT in 2024; OpenAI may have changed its behaviour since. AISir’s description comes from its own Help and roadmap, and HisnLabs makes AISir, which readers should weigh. Related reading: [prompt injection and AI agents](https://hisnlabs.com/en/blog/prompt-injection-ai-agents-lab) and [poisoned prompts and embedded AI](https://hisnlabs.com/en/blog/poisoned-prompts-phantom-data-embedded-ai).

## How FireAI and HisnLabs fit in

A memory kept on the device is private only while the apps on that device keep it there. FireAI shows, per app, every connection your Mac opens, so an AI app that uploads more than it should is visible, and can be blocked.

FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac.

You can read the technical decisions behind it, or try FireAI for 17 days, at [FireAI, by HisnLabs](https://hisnlabs.com/fireai/en/download).

## Sources

- [OpenAI: “Memory and new controls for ChatGPT”, 13 February 2024, updated 10 April 2025 (read through the Wayback Machine)](https://openai.com/index/memory-and-new-controls-for-chatgpt/)
- [OpenAI Help Center: “Memory FAQ” (no absolute date shown; read through the Wayback Machine)](https://help.openai.com/en/articles/8590148-memory-faq)
- [Google: “Manage what Gemini remembers about you and customize responses”, Gemini Apps Help (no date shown)](https://support.google.com/gemini/answer/16598625)
- [Anthropic: “Bringing memory to Claude”, 11 September 2025, updated 23 October 2025](https://www.anthropic.com/news/memory)
- [Rehberger, “ChatGPT: Hacking Memories with Prompt Injection”, Embrace The Red, 22 May 2024](https://embracethered.com/blog/posts/2024/chatgpt-hacking-memories/)
- [Morris, Kuleshov, Shmatikov and Rush, “Text Embeddings Reveal (Almost) As Much As Text”, EMNLP 2023, arXiv:2310.06816](https://arxiv.org/abs/2310.06816)
- [Song and Raghunathan, “Information Leakage in Embedding Models”, ACM CCS 2020, arXiv:2004.00053](https://arxiv.org/abs/2004.00053)
- [sqlite-vec README, GitHub repository asg017/sqlite-vec (no date shown)](https://github.com/asg017/sqlite-vec)
- [Regulation (EU) 2016/679 (General Data Protection Regulation), EUR-Lex, articles 17 and 20](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679)
- [HisnLabs: AISir product page](https://hisnlabs.com/aisir/en)
