News

What People Tell AI Chatbots — and Why They Don't Trust It

A Proton survey of 4,014 chatbot users across the US, UK, France and Germany found 66% have discussed a sensitive topic with an AI — finances, mental health, careers — while only 11–20% report high trust in the companies receiving it. The sharpest finding: users fear ad profiling more than model training.

· Oct 1, 2026
What People Tell AI Chatbots — and Why They Don't Trust It
Illustration generated by AI
Table of contents
  1. The headline numbers
  2. The finding that should change how you read AI privacy debates
  3. Trust is low, disclosure is high — and that is not irrational
  4. The other half of the problem: data you never agreed to give
  5. What actually follows from this
  6. FAQ
  7. Bottom line

People are telling AI chatbots things they would hesitate to tell a friend — and they do it without trusting the companies on the other end. A Proton survey of 4,014 chatbot users across the US, UK, France and Germany, published on September 24, 2026, puts hard numbers on that contradiction. The gap between what people disclose and what they believe happens to it is the most interesting privacy finding of the year.

The headline numbers

Finding Figure
Users who discussed at least one sensitive topic with a chatbot 66%
Highest / lowest by country US 68.4% / France 60.3%
Users reporting high trust in AI companies only 11–20%
Would share more if conversations were guaranteed not to train models 48%
Interested in an AI chatbot built for privacy 8 in 10 (71.1% DE – 82% UK)

The three most-discussed sensitive topics are personal finances, mental health and career problems — in that order. These are not idle queries. They are the categories people normally reserve for a partner, a doctor or a professional bound by confidentiality.

The survey was run unbranded, meaning respondents were not told which company commissioned it. That matters: a privacy company asking "do you want privacy?" under its own name produces a predictable answer, and Proton avoided that particular thumb on the scale.

The finding that should change how you read AI privacy debates

Here is the detail most coverage will skip. In the US, 65.3% were worried about their conversations being used for advertising profiles, against 57.6% worried about model training.

Ad profiling ranked higher than training. That inverts the usual public conversation, which fixates almost entirely on whether your data trains the next model.

It also suggests users are reasoning more precisely than they are usually given credit for. Model training is a diffuse harm — your words become a statistical smear across billions of parameters, and no individual output traces back to you. Ad profiling is specific. It links a named profile to the fact that you asked about debt, a lump, or leaving your job, and it acts on that link commercially. People appear to understand that the monetization of the data, not merely its storage, is the thing that bites.

Trust is low, disclosure is high — and that is not irrational

The obvious reading is that users are behaving stupidly: confiding in systems they distrust. A more accurate reading is that they have no alternative in front of them.

Low trust is widespread — France 47.7%, UK 41.6%, Germany 40.5%, US 38.8% report little or no trust in AI companies with private information. Yet two thirds still disclose. That is what happens when a tool is genuinely useful and the privacy-respecting version is not visible at the point of use.

The 48% figure is the actionable one. Nearly half say a no-training guarantee would make them share more. That is a product requirement stated out loud, not a vague preference.

Should you use a VPN with ChatGPT and other AI apps?

The other half of the problem: data you never agreed to give

The survey covers what people type. A second strand of this story covers what gets collected without anyone typing anything.

Proton's reporting on Ray-Ban Meta smart glasses sets out the structural issue: the glasses pair a camera on the wearer's face with speakers and an AI assistant, and vocal commands plus video can be sent to Meta's servers for processing. Meta created a humanoid robotics division inside Reality Labs in February 2025 — the same organisation that builds the glasses — and in May 2026 acquired Assured Robot Intelligence, a robotics lab co-founded by Lerrel Pinto. First-person footage of humans moving through real environments is exactly the training material embodied AI needs.

The privacy asymmetry is the part that cannot be fixed with a settings toggle: the wearer consents, everybody else in frame does not. Meta's own Project Aria research programme uses a visible light to indicate when audio and video are being collected; consumer glasses do not give bystanders that same reliable signal.

So the two stories meet in the same place. One is about information you volunteer under conditions you do not control. The other is about information collected from you by someone else's device.

What actually follows from this

Be precise about which tool solves which part, because they are not interchangeable.

A VPN does not stop an AI provider reading your prompts. It encrypts traffic between you and the network, and hides your IP from the sites and services you reach. Once you are signed into a chatbot account, the provider identifies you by that account. Anyone selling a VPN as the answer to the chatbot-privacy problem is selling the wrong tool for it.

What a VPN does solve is the layer underneath: your ISP and the operator of whatever Wi-Fi you are on seeing which AI services you use and how often, and the correlation of your activity to your home IP across every other site you visit. That is a real part of the profile the survey's respondents are worried about — and it is the part no chatbot privacy policy addresses.

What solves the prompt layer is a provider whose business model does not require reading them. A subscription-funded service has no advertiser to build a profile for. That is the structural answer the 48% are describing, and it is why "do you train on my conversations?" and "do you sell advertising?" are the only two questions worth asking a chatbot provider.

The practical stack, in order of what it actually changes: pick AI tools with a no-training guarantee in writing; keep genuinely sensitive categories — medical, financial, legal — out of general-purpose assistants regardless of their policy; and use a VPN for the network layer, where it does real work.

FAQ

How many people were surveyed?

4,014 chatbot users across the US, UK, France and Germany, published by Proton on September 24, 2026, and fielded unbranded.

What do people share most with chatbots?

Personal finances, mental health and career problems are the three most-discussed sensitive topics.

Do users trust AI companies?

Mostly not. Only 11–20% report high trust, while around four in ten report little or none.

Would a no-training guarantee change behaviour?

48% say they would share more sensitive information if conversations were guaranteed not to train models.

Does a VPN keep my chatbot conversations private?

No. It protects the network layer — your ISP and local Wi-Fi, and your IP. The provider still sees your prompts once you are signed in.

Bottom line

Two thirds of chatbot users have already handed over something they would not say out loud in an open-plan office, and barely one in six trusts the recipient. That is not a story about careless users; it is a story about a market that has not yet offered them the obvious alternative at the moment they need it.

The number to watch is the 48%. It says the demand for privacy-by-design AI is not hypothetical — it is a stated condition for deeper use. Whoever meets it credibly, in writing, gets the conversations everyone else is currently getting by default.

Try Proton VPN

Survey figures are Proton's own, from research published September 24, 2026 (4,014 respondents, US/UK/FR/DE, fielded unbranded). Smart-glasses details are from Proton's reporting and were accurate at publication.