Your Boss Can Read Your Claude Incognito Chats

You told Claude about your divorce. Now picture your boss scrolling through that conversation. If you did it on a Team plan, he actually can. I read this post twice and it honestly made my stomach drop a little, so read this before your next “private” chat.

The post’s author spent a long time researching what happens to a prompt after you hit send. What this AI professional found is simple and uncomfortable: both ChatGPT and Claude have an incognito mode, but on a Team plan the workspace owns the data, not you.

Anthropic says it right in their policy: “Incognito chats are included in organizational data exports available to account Owners.”

So incognito isn’t a lock. It’s a curtain. And the account owner has the key to the room.

The story that started the whole investigation

What pushed the original poster into all this research is one of the wildest AI stories I’ve seen this year. Tristan Buckmaster, a mathematician at NYU, spent a year working on Navier–Stokes with Codex. That’s a Millennium Prize problem. Crack it and you get $1M.

  • August 15: he had his result.
  • September 1: OpenAI heard a rumor, pointed 10,000 agents at the problem, and 88 hours later, OpenAI had it too.

He asked the obvious question: did you train on my sessions?

OpenAI’s answer: “No human being opened them and no agent looked.”

Then he asked a sharper one: does OpenAI train on de-identified user data?

“Yes. And so does every LLM company.”

That includes whatever you typed this week. Your health questions. Your salary negotiation draft. That message to your lawyer you asked the model to soften. All of it can end up as de-identified training data.

Three ways your chats leave your control

This is the part of the post that really stuck with me. The creator lays out three doors your “private” chats can walk out through, and none of them need your permission:

  • Your boss: on a Team plan, an account Owner can export all your personal chats, incognito included.
  • A court: 20 million ChatGPT chats went to the New York Times’ lawyers during discovery.
  • Google: around 100,000 shared chats got indexed and became searchable.

The expert admits they use Claude and ChatGPT for personal stuff too. Health. Money. Divorce. Most of us do. The point isn’t to stop. The point is to stop doing it in the wrong place.

The rule the author now lives by

This is the defensive playbook the LinkedIn user prescribes, and it’s short enough to remember:

  1. Personal things: personal account, data training off, incognito on, and no thumbs up on responses. Feedback clicks can send that conversation to human reviewers.
  2. Client work: business account. Or nowhere at all.

Two lines. That’s the whole thing. I’d add one habit of my own: before you paste anything sensitive, ask “would I be fine with this in a spreadsheet my employer can download?” If the answer is no, switch accounts first.

Why this matters more than it looks: most people treat a chat window like a private notebook. It isn’t. It’s a hosted service with an admin panel, retention rules, and legal obligations. The tools aren’t evil, but the defaults aren’t built around your privacy, and Team plans are built around the company’s control by design.

As the post’s author puts it, your boss shouldn’t learn about your divorce from an export. Check out the full LinkedIn post for the rest of the story and the exact checklist this savvy professional uses now!

Scroll to Top