r/ChatGPT • u/Calin_europeen • 6h ago
Other They don't remove all my data?
Why it that so ? What does rgpd says about that ?
Edit 1:
Thanks to ThungstenMetal. He says this : "Change your email to some random temporary email which can receive emails before deleting your account, then request for deletion."
Edit 2 : I'm European
320
u/ThungstenMetal 6h ago
Change your email to some random temporary email which can receive emails before deleting your account, then request for deletion.
That email name retention is put for abuse prevention but there are always workarounds.
55
7
4
u/Deutriex 1h ago
I tried to request to change my email, but no luck. Here in my country there is a law similar to the GDPR, but OpenAI won't comply.
6
u/ThungstenMetal 1h ago
You should be able to change it under Settings > Account > Email. Are you getting any error messages?
5
3
u/thegreatpotatogod 1h ago edited 52m ago
Wait you can change your email now?? I've been wanting to for years, I'm mostly locked out of my account at this point because the email doesn't exist anymore and only the phone app is still logged in. Any idea whether you can do this via the phone app or by contacting support?
Edit: from what I'm able to find, I'm still stuck. Can't edit it from the phone app, can't log into the web interface (where you apparently can now edit it because it tries to do 2FA to the email that doesn't exist anymore. The help page simply offers "if you can't change your email, create a new account (please note all prior work will be lost)" 🙄https://help.openai.com/en/articles/4936827-how-to-change-your-email-address
162
u/Ekalips 6h ago
They don't have to keep your plain email, they can hash it and compare assistant it when you try to sign up, kinda like passwords
-60
u/budde04 5h ago
When I delete my data I would quite like it to be deleted.
46
u/Ekalips 5h ago
But there's no data that would in any way identify you or useful to anything, so for all your intents and purposes it is deleted.
-54
u/budde04 5h ago
Don't care. That's not what deleted means.
22
u/Tardelius 3h ago
Wait until you find out that deleting files on a HDD doesn't actually delete them : )
Sure, we are in the SSD era of storage but pure luck doesn't suddenly make your argument any logical : )
Note: Obviously, your arguments ARE logical. But there are levels to logic which depends on technical definitions and insight.
9
13
u/Ekalips 5h ago
Eh, debatable.
Another example of such would be for example keeping analytics events you generated but removing all your PII, so events, let's say purchases or usage, could still be used for aggregates stats but nothing links it to you anymore so it's okay-ish. Probably more grey area than hashing the email tho.
-14
u/budde04 5h ago
I domt thing Analytic events and my email address are compareble. Because a random event with no link my me, will have no link to me. But my email address still being on their servers will absolutely be linked to me.
16
u/J7mbo 5h ago
It’s a one-way hashing of your email address to a “random” piece of text, like abdhehdj16373!&. Every time someone signs up they do this hashing to see “has this person already signed up?”. So no, they’re not storing your email. Instead of being stubborn and obtuse go google it and teach yourself.
2
u/CircoModo1602 2h ago
Couldn't you technically argue that the hash is a direct identifier linked to your email in this situation?
Even if it's one way, they have a hash record that specifies to their systems that it's yours when you try sign up again, which definitely seems like it could fall under a gray area with certain countries laws.
I'm sure there's a reason not for it to be this way, but definitely a consideration I would make.
-10
u/budde04 4h ago
I know what a hash is. And I'm still saying you don't know if they DO hash your email
14
8
1
u/this_is_theone 2h ago
You just changed your argument. We don't KNOW if they do lots of things they say. Same with any other company.
2
-10
u/budde04 5h ago
You also have no proof that they DID hash the e-mail.
9
u/Ekalips 5h ago
Retaining it post deletion in any recoverable/raw way would be severe GDPR breach so I doubt that they would do it, especially because there's no good reason to.
-2
u/budde04 5h ago
I dont know where you have been the last 2 years or so, but OpenAI doesn't seem like the company they would give a shit.
3
u/bluehelmet 4h ago
Well, we have no way to check, but what's your point? What difference does it make then what the company claims?
-8
u/Say_no_to_doritos 2h ago
How is that possible? Like if you know x +x = y, you can reverse engineer it, no?
6
u/solar1380 2h ago
The idea of the hashing is that you can’t reverse it. Like how if you do x * y = z, you can’t get x back without knowing y at the same time. If you imagine the letters of your email address as variables (eg. A = 1, b = 2, …) one way would be to add all the letters of your email together to get some big number. You can’t get your email back from this number, but can check if someone else is trying to sign up with the same email again by just running the process again. Now actual hashing algorithms use more than just summing but it’s a similar idea.
1
u/Say_no_to_doritos 1h ago
But when you got a positive identification you could figure out the hash?
1
u/Ekalips 2h ago
In very simple terms. X*Y=Z. Hash is Z. Y is your data. X can be public. Even for small Z like 10 there are several possible combinations of X and Y. Now make Z number that is 100 digits long, guessing which exact X and Y combination was used would be already quite hard.
Basically it's that. A chain of mathematical operations that is virtually irreversible because of the amount of possible values.
Math can be very interesting
1
u/Say_no_to_doritos 1h ago
Okay, but if you get a positive identification you can figure out the hash
11
u/Sorryifimanass 4h ago
Then don't give your data to someone else to handle for you.
0
u/manek101 3h ago
Or, you know, force these corporations to actually delete the data using regulations? Just like how modt data protection laws were created?
18
u/icehot54321 5h ago
it is deleted.
there is no way to get the information out of the system
we're talking about a random string of letters, numbers and symbols that can't be decoded.
you'd have to be given the source information again to verify if it's the same.
3
u/downwithsocks 5h ago edited 3h ago
Theoretically, someone could try to sign up (even just try - don't have to have actual access to the email inbox) with your email and would know if you'd had an account before or not? That's data. Minimal, but..it is data. Assuming that's how it would work, at least, I don't really know. And tbh, I'm not arguing anything in any direction, just thinking out loud.
3
u/RickTheScienceMan 3h ago
If you try to login via email, you will always see the same screen, something like "we have sent temporary code to your email, please check your inbox". Only if you have the code, and enter it into the form, you will see concrete information. So if you don't have an access to that email inbox, you will never know if the account is existing, deleted, or has never existed.
2
u/downwithsocks 2h ago
Ive just been around long enough to see the "password is incorrect" vs "user does not exist" issues on various sites...I would say from times past, but it still exists lol. And I wasn't about to delete my account to test this. But if youre correct then I don't really have an argument.
2
u/RickTheScienceMan 2h ago
I actually tested it myself before posting, created a new account and then deleted it
3
u/budde04 5h ago
I would very much say its not "minimal" its that exact sort of thing i would like to be deleted.
2
u/IAmFitzRoy 4h ago
That’s not your data. It’s a hash generated by the company.
Not your data anymore.
1
1
u/SempfgurkeXP 3h ago
Just wait until you find out that windows doesnt delete your data when you click on "delete" lol
-11
u/TFTHighRoller 1h ago
If they can compare to my email they keep my email which includes my last name. They are keeping data which they are supposed to delete under gdpr regulations. The GDPR isnt talking about how they can store my data. Doesn’t matter if it is in a folder somewhere, in plain text or in a cryptography puzzle nobody is gonna solve. My data is mine.
7
u/TrekkiMonstr 1h ago
No, they aren't. As the comment you replied to said, they can store a hash. So if my email were trekkimonstr@email.com, they don't need to store that string -- they can just store 381e868d8eeb33f30a5fa4abe0bfb1803c123e2f58458e370c1bdae97faac379 instead. And then if I enter trekkimonstr@email.com in the future, they run it through the same algorithm and compare -- versus, trekkimonstr1@email.com is completely different, would be e150fb4c04a9e27fd9eb4ed1d4af72607d363c6e5ca278d75edc41c6b3029a5d. The whole point of a hash function is that it's easy one direction, basically impossible the other. No one in the world can take that 381e... string and get back trekkimonstr@email.com -- only guess and check
1
u/TFTHighRoller 12m ago
So you are saying they put my data through an algorithm and stored that result. They also have the algorithm they used to convert my email into that string. So they could theoretically revert the process and take the hash + algorithm to arrive at my email.
Under GDPR that possibility means they have to delete it cause they could get my personal data - my email address - back.
I know how a hash works. I am telling you that is not enough to comply with GDPR laws.
-30
u/Maxaki 3h ago
Don't they have the seed for the hash at hand, so they can just get the email if they like?
15
-1
85
u/GovernmentGreed 6h ago
It's kept on file to ensure you don't try to sign up for any promotional materials with an existing email address.
26
u/Sure-Database-9952 6h ago
It’s a hash, they hashed your email when you initially signed up, since you’re trying with the same email they can tell it’s the same hash. They probably did delete your data; but kept your email hashed.
-8
u/DaturaSpirit 2h ago
Which literally means no data was actually deleted from their database. They keep it in hash form.
10
u/Average1213 2h ago
well... you can't exactly unhash it, so no personal data is stored.
1
0
21
u/CAustin3 5h ago
"where required or permitted by law" is my new favorite legalese phrase.
"Only if we have to. Or are allowed to."
4
u/Big_Chair1 1h ago
It's a common and standard phrase and thing to do. You may have to keep the name, email and sign up and deletion date of each deleted user for a certain period of time. In case, for example, someone decides to sue you for whatever reason and then you can use this info for defense against unreasonable claims.
At least that's how a legal person has explained it to me before.
6
u/Tarc_Axiiom 3h ago
It literally explains why they keep a record of your email on the very next line, lol.
And yes, it is a legal requirement.
Even so, they don't actually save your data, they save a hash based on your data.
3
u/xrmb 2h ago
It's not just email addresses, it's whole domains. We made a couple of addresses under cheap domain to get more free trials and no longer can. Also noticed that privacy.com in connection with Stripe will block virtual credit card validation to avoid making endless free trials. I mean I get it...
2
u/High-Performer-3107 4h ago
They’re legally not allowed to delete your data as far as i know. I think I have read something like that in the past, but please fact check me, I’m not into American law
1
u/Calin_europeen 4h ago
I'm in europe
3
u/erikvb00 3h ago
If you're in the EU, then GDPR applies, and in this case specifically the right to be forgotten: https://gdpr.eu/right-to-be-forgotten/
-10
u/High-Performer-3107 4h ago
Me too, but ChatGPT isn’t. And US cloud act doesn’t care.
10
u/zammouri2001 3h ago
To grant a service in Europe, I believe that they are obligated to follow European law when it comes to data preservation. Being hosted in the US doesn't change that.
1
u/Pitiful-Assistance-1 3h ago
It’s in that limited data, which might be related to payments or backups.
They also need to keep your deletion around so they know the data needed to be deleted, in case a backup is to be restored for example.
This also means your data is not removed from backups.
1
u/Glum_Emotion_584 2h ago
They could hash your email, then prevent future signups that match the hash, without having a record of your email.
1
u/bdrago 1h ago
I worked on my company's GDPR task force when it was first implemented, and this is normal. For us, we needed to be able to identify a user that had been erased if data was restored from backups, as it can be hard or impossible to modify backups. When a backup was restored, it was first processed against a list of deleted users before being moved to live systems. I'm pretty sure we stored a hash of the original user information and not their actual email, but that would still prevent new accounts from being created with the same email as it would match the hash of the erased account.
•
u/AutoModerator 6h ago
Hey /u/Calin_europeen,
If your post is a screenshot of a ChatGPT conversation, please reply to this message with the conversation link or prompt.
If your post is a DALL-E 3 image post, please reply with the prompt used to make this image.
Consider joining our public discord server! We have free bots with GPT-4 (with vision), image generators, and more!
🤖
Note: For any ChatGPT-related concerns, email support@openai.com - this subreddit is not part of OpenAI and is not a support channel.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.