VPNs Hide Location, Not ChatGPT or Claude Prompts, TechRadar Reports
A VPN masks a user's IP address and keeps internet providers from seeing ChatGPT or Claude traffic, but it cannot stop OpenAI or Anthropic from reading, storing or training on prompts, TechRadar says.
The report said that without a VPN, OpenAI and Anthropic can typically see considerable information about a connection. An IP address reveals approximate geographic location. Device metadata follows, including browser type, operating system and unique device identifiers.
OpenAI's privacy policy states that the company collects IP address, device information including unique identifiers, cookie data, location, email address and payment information, according to TechRadar. Anthropic's policy covers location, connection details and device usage patterns, especially on the mobile app. The report said the wording differs but the result is similar: both companies can see roughly where a user is and what device is being used.
A VPN helps with part of this. It masks the real IP address from the AI platform and encrypts traffic so the ISP cannot see that AI services are being used. The protection stops there, the report said. Once the encrypted tunnel ends at the VPN server, the AI company still sees everything that arrives at its servers.
The limitation is critical, according to TechRadar. A VPN protects data while it travels across the internet, but that protection ends when a prompt arrives on OpenAI or Anthropic servers. The message must be decrypted for the AI to process it. Once decrypted, the data sits on the AI company's systems and is governed by its policies rather than the user's.
A VPN does nothing to hide the content of prompts, files or images uploaded, account details, conversation history or payment information, the report said. The encryption protects the connection between the user and the servers, not what happens afterward. No matter how strong the VPN tunnel is, everything typed is fully readable on the other end.
The report also described how long AI systems may remember conversations. Most consumer chatbots keep conversations on file indefinitely and may use them to train future models, according to TechRadar. Users must manually adjust settings and delete chats if they want them gone.
For ChatGPT, OpenAI may use content to improve services unless the user opts out, the report said. Users can go to Settings, then Data Controls, and toggle off the option to improve the model for everyone. Even with that disabled, chats may still be stored for safety and legal reasons.
Claude works similarly. Anthropic requires all consumer users to choose whether their chats can be used for training, and the toggle is on by default, according to the report. If enabled, data can be retained for up to five years, compared with 30 days if the user declines. The setting can be disabled anytime in account preferences, or users can use Incognito mode to keep conversations out of saved history. Paid business tiers come with stricter privacy agreements by default.
TechRadar said a VPN remains a solid first step for network security because it hides location from AI providers and keeps the ISP from monitoring activity. It will not stop AI companies from reading, remembering and learning from prompts.
For users who prioritize privacy, the report recommended turning off data training in both ChatGPT and Claude, using ChatGPT's temporary chats or Claude's Incognito mode, and avoiding sharing sensitive information. It also pointed to Proton AG's Lumo, built by the team behind Proton Mail and Proton VPN. The service uses zero-access encryption so only the user can decrypt saved conversations, keeps no logs on its servers and does not train on data unless the user opts in. It runs on European infrastructure under GDPR and Swiss privacy laws. A further option is to run open-source models offline with tools such as Ollama or LM Studio, keeping everything local so nothing leaves the machine.