Vibe, Not Pi, Tops Incogni's 2026 AI Privacy Ranking
The confusion started with a report this week that said Pi, "not Mistral AI's Vibe", had the lowest overall score. Incogni's own report says otherwise: Vibe received the lowest overall risk score among the platforms evaluated, making it the most privacy-friendly platform in this ranking. Incogni's press release from August 20, 2026 says the same. Microsoft Copilot, Meta AI, and Kimi received the three highest overall risk scores, while Mistral AI's Vibe received the lowest overall privacy-risk score, followed closely by ChatGPT.
The mix-up probably comes from the wording of one sub-ranking. In the third category, data collection and sharing, which is worth up to 6 points, Incogni writes that Inflection AI "claimed the top spot" with the lowest "cumulative privacy-risk score", followed by Mistral AI and Z.ai. That phrase refers to one category, not the overall table. Pi won that category because it shares little with third parties and its apps collect little data. Vibe won overall, and it also led the "what happens to user data" category, scoring just under 4 of a possible 9 points.
Incogni doesn't publish a full numeric table in the report text. It groups the platforms into three clusters. The two lowest-risk platforms, Vibe and ChatGPT, scored around 12 points each. Most of the field sits around 14. Copilot, Meta AI and Kimi scored 16 or more.
The 13 platforms were ChatGPT, Claude, Gemini, Grok, Vibe (formerly Le Chat), Perplexity, Qwen, DeepSeek, Z.ai, Kimi, Meta AI, Pi and Copilot. The scores are based on 11 criteria in three categories: what happens to user data (whether conversations may be used for training, whether users can opt out, and who prompts may be shared with); how transparent platforms are; and what personal data is gathered, where it comes from, and who it reaches. Data was collected between 15 June and 6 July 2026. Incogni warns that policies may have changed since then.
Outlets such as VKTR, IntelligentHQ and Digital Journal repeated the headline results, but all of that coverage comes from Incogni's own release. It shows the findings were reported consistently, not that anyone checked them independently. IntelligentHQ frames it correctly: the rankings are Incogni's assessment based on its own methodology, rather than an independent regulatory judgement of the platforms.
Why Microsoft Copilot Lands Among the Highest-Risk AI Platforms
Copilot's poor result comes mostly from the transparency and data-collection categories, not from how Copilot handles training. Microsoft came last on transparency, just behind Meta and Z.ai. Incogni says the worst performers were dragged down by very poor scores on how accessible their privacy policies are, which made up most of their risk.
The core complaint is that Microsoft's policy covers far too much. Microsoft, Google and Meta all have broad privacy policies that span many products and say little specifically about their AI services. For someone using Copilot, Gemini, or Meta AI, finding out what applies specifically to that tool can require interpreting rules written for an entire corporate ecosystem. Incogni notes that these broad policies allow a lot of data collection and use, which may or may not apply to someone who only uses the AI product.
In the data-collection category, Microsoft and Meta were the two worst performers. Incogni cites their reliance on wide sources of user information and heavy third-party sharing. Its specific concerns about Microsoft are these:
- Microsoft's privacy policy says the company gets data from data brokers.
- Copilot's iOS App Store privacy label says some user data is used to help third-party advertisers.
- Microsoft may share user data with ad networks when users have opted in.
- Copilot's app is one of two in the sample, along with Kimi's, that Incogni says uses data to track users.
These findings need careful reading. Microsoft buying data from brokers is a company-wide practice described in its general policy. It doesn't show that Copilot prompts are bought or sold, or that any particular chat went to an advertiser. The week's coverage said Copilot was "found to share data with third-party advertisers and to purchase data from data brokers." That compresses a finding about Microsoft's disclosed practices into a claim about Copilot conversations that the evidence doesn't support.
The report also found a contradiction in Microsoft's own app listings. Copilot's Google Play entry said no user data is collected or shared, while its Apple App Store entry said some data is. Incogni decided the Play Store entry was probably wrong and scored the Android app the same as the iOS app. That's a judgment call, but the contradiction itself shows why Incogni marked Microsoft down on transparency.
Copilot's Training Opt-Out Is Better Than Its Overall Score Suggests
The overall rank hides one thing Copilot does well. Incogni sorted the platforms into four tiers by how easy it is to stop your chats being used for model training. Copilot is in Tier 1, along with ChatGPT, Claude, DeepSeek, Vibe, Grok, Perplexity and Pi. All of them offer one simple toggle with no trade-off.
The competition does worse here. Gemini, in Tier 2, ties the control to "Gemini Apps Activity": turning off training also stops future chats from being saved to your history. Moonshot AI and Meta are in Tier 3. Kimi's opt-out requires emailing support and verifying your identity, and Meta's policy says users can object to AI training without explaining how. Qwen also requires a submitted request. Z.ai is alone in Tier 4, with no working opt-out that addresses training specifically.
Incogni also describes an industry pattern. Consumer accounts are usually included in training by default, while business, enterprise and API tiers are excluded. Microsoft, OpenAI, Google, Perplexity AI and Mistral AI all follow it. The whole ranking covers consumer tiers only. It says nothing directly about Copilot under a work or school account.
Copilot Privacy Settings for Personal Microsoft Accounts After the August 18 App Update
Microsoft's current support guidance fills in the practical side, within clear limits. An updated Copilot app for web, desktop and mobile has been available since August 18, 2026, and Microsoft's privacy-controls page for individuals covers only that version. It also covers only people signed in with a personal Microsoft account. It does not cover work, school or organizational (Microsoft Entra) accounts, or Copilot inside Microsoft 365 apps, which have separate guidance.
For personal accounts on the updated app, the controls sit in one place:
- Open Microsoft Copilot and sign in with your Microsoft account.
- Open Settings, then select Personalization.
- Review the toggles: Saved memories, One shared experience, Web search and Allow ads personalization.
Each toggle does something different, and some behave in ways you might not expect.
- Turning off Saved memories stops Copilot saving new memories but doesn't delete existing ones. To remove them, select Manage next to the toggle, then delete individual memories or use Delete all memories.
- One shared experience controls whether your activity in Bing, Edge and MSN personalizes Copilot, and whether your Copilot chats personalize those services. Microsoft's example: chatting about vacation ideas can shape what Bing and MSN show you. This toggle does not control personalized ads.
- Allow ads personalization is a separate switch. Microsoft says generic ads are based on the most recent content of the current conversation, while personalized ads may use your chat history, saved memories and other Microsoft data you've chosen to share. Ads may appear if you don't have a Microsoft 365 subscription. Users under 18 never get personalized ads in Copilot, whatever their settings.
- To turn off personalized advertising across all Microsoft services, go to the Microsoft privacy dashboard and turn off the toggle under "See ads and offers that interest you."
To delete one conversation, select it in the Chats list, choose ...More, then Delete. Deleting your whole Copilot history is done through the Microsoft privacy dashboard.
One gap is worth knowing about. Incogni credits Copilot with a single model-training toggle, but Microsoft's privacy-controls page for the new app covers memory, shared experiences, chat history, web search, advertising and Edge data import, and doesn't describe that toggle. Don't assume that turning off memory or ad personalization also stops your chats being used for training. The US-only "Import browser data" option under Settings > Web browsing can pull in Edge cookies, history, payment details, passwords and autofill data. Leave it off unless you want that data consolidated in Copilot.
Claude's July 2026 Consumer Training Change and What Anthropic Actually Retains
The other concrete change in this story is Anthropic's. According to Incogni, Anthropic's March 2026 documentation said Claude conversations were used for improvement only if a user allowed it. A July 2026 policy update reversed that: consumer inputs and outputs are now used for training unless the user opts out. The coverage this week gave an effective date of July 8. Anthropic's retention page is dated July 1, 2026, and no other outlet has reported the July 8 date.
The scope is narrower than a headline suggests. Anthropic's Privacy Center says the consumer rules cover Claude Free, Pro and Max, including Claude Code used from those accounts. Commercial products such as Claude for Work and the Anthropic API follow separate terms. The coverage also said Amazon Bedrock and Google Cloud Vertex AI customers are excluded, a claim attributed to Cyberdelegate. That fits Anthropic's split between consumer and commercial products.
The retention rules also need correcting. The coverage described a simple split: five years if you allow training, 30 days if you opt out. Anthropic's page is more detailed:
- If you allow your chats or coding sessions to improve Claude, Anthropic may keep that data in de-identified form for up to five years in its training pipelines. This applies only to new or resumed chats after you turn the setting on.
- When you delete a conversation, it disappears from your history immediately and is deleted from backend storage within 30 days. The 30-day figure is about deletion, not a general retention period for people who opt out.
- Turning off model improvement stops previous and new chats being used for future training. Data already in training runs that are in progress, or in models already trained, stays there.
- Incognito chats are never used for improvement, even if the model improvement setting is on.
- If automated trust-and-safety systems flag a chat as breaking Anthropic's usage policy, inputs and outputs can be kept for up to two years and classification scores for up to seven.
- Data attached to feedback you submit, such as a thumbs up/down or a bug report, is kept for five years.
Taken together, Claude's opt-out works for future training, but "opting out" doesn't guarantee a short retention period in every case.
Opt-Outs Across All 13 Platforms Only Work Going Forward
The most important point in the study applies to every platform on the list. No platform lets users remove data that has already been used for training, and opting out only prevents future conversations from being included. Incogni also found that no provider disclosed the exact datasets its models were trained on. All but one say they train on "publicly available information," which means most accessible web content, social media included.
Some platform-specific disclosures stand out. Pi is the only platform that openly says it uses social media profiles and content for training. xAI says Grok is trained partly on public X posts and on engagement data such as likes, reposts and view counts. Meta AI trains on public Facebook and Instagram content, and Meta says its group-chat conversations with Meta AI aren't used for training, a claim users can't verify. Nine of the 13 platforms keep separate privacy disclosures for EU users. Kimi, Z.ai, Qwen and Meta AI don't.
The top of the table has barely moved in a year. In the 2025 ranking, Le Chat by Mistral AI was the least privacy-invasive platform, with ChatGPT and Grok following closely behind, and Meta AI was the worst, followed by Gemini and Copilot. Copilot being near the bottom again reflects a problem Incogni has now flagged twice: Microsoft's AI privacy terms are hard to separate from its general corporate privacy policy.
What this means for you
If you use Copilot with a personal Microsoft account, check your settings now. Enterprise admins should look to Microsoft's organizational Copilot documentation, because nothing in this study applies to them. A high rank on Incogni's list reflects disclosed practices and how readable a policy is. It isn't a finding that a service is unsafe, and it doesn't replace checking the specific product and account type you use.
Incogni's information security manager, Miguel Forn??s, gives advice that applies across every platform. Treat anything you type into a chatbot as information handed to a third-party service. Leave out passwords, financial details, confidential work material and medical records, and strip names and other identifiers where you can. He also suggests the web version over a mobile app for sensitive tasks, and a locally run model when data needs to stay on the device.
- On the updated Copilot app with a personal Microsoft account, go to Settings > Personalization and review Saved memories, One shared experience, Web search and Allow ads personalization separately. Each controls something different.
- Turning off Copilot's Saved memories doesn't delete what's already stored. Use Manage > Delete all memories as well.
- Work and school Copilot through Entra, and Copilot in Microsoft 365 apps, are covered by separate Microsoft data-protection guidance. Don't give staff the consumer-app steps.
- Claude Free, Pro and Max users who don't want their chats used for training need to opt out in their privacy settings. Incognito chats are excluded from training either way.
- Opting out on any of the 13 platforms only stops future training use. Anything you've already shared in a consumer chatbot may already be part of a trained model.
- Keep confidential work data in services your organization has approved. Incogni found that business and enterprise tiers are generally excluded from training, and consumer tiers are not.
Incogni's research window closed on July 6, 2026, before Microsoft's August 18 Copilot app update, so this year's Copilot score reflects the policies and disclosures that existed before that update. The bigger fix for Microsoft is a privacy statement written specifically for Copilot. Until it publishes one, Copilot's transparency score will keep holding it near the bottom, whatever its training toggle does.