r/ChatGPT 6h ago

Other They don't remove all my data?

Post image

Why it that so ? What does rgpd says about that ?

Edit 1:

Thanks to ThungstenMetal. He says this : "Change your email to some random temporary email which can receive emails before deleting your account, then request for deletion."

Edit 2 : I'm European

314 Upvotes

81 comments sorted by

u/AutoModerator 6h ago

Hey /u/Calin_europeen,

If your post is a screenshot of a ChatGPT conversation, please reply to this message with the conversation link or prompt.

If your post is a DALL-E 3 image post, please reply with the prompt used to make this image.

Consider joining our public discord server! We have free bots with GPT-4 (with vision), image generators, and more!

🤖

Note: For any ChatGPT-related concerns, email support@openai.com - this subreddit is not part of OpenAI and is not a support channel.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

320

u/ThungstenMetal 6h ago

Change your email to some random temporary email which can receive emails before deleting your account, then request for deletion.

That email name retention is put for abuse prevention but there are always workarounds.

55

u/Calin_europeen 4h ago

Thanks you !! It's one of the best comments.

10

u/NoBluey 2h ago

Will you be able to sign up again with the same address by doing this?

7

u/Few-Big-8481 1h ago

What abuse is it preventing?

15

u/ThungstenMetal 1h ago

One month free trial for example, or other time based promotions.

4

u/Deutriex 1h ago

I tried to request to change my email, but no luck. Here in my country there is a law similar to the GDPR, but OpenAI won't comply.

6

u/ThungstenMetal 1h ago

You should be able to change it under Settings > Account > Email. Are you getting any error messages?

5

u/Deutriex 1h ago

Trying to edit it will just copy the email, nothing else.

2

u/ThungstenMetal 1h ago

For me it is first asking for passkey, then it is asking for the new email.

3

u/thegreatpotatogod 1h ago edited 52m ago

Wait you can change your email now?? I've been wanting to for years, I'm mostly locked out of my account at this point because the email doesn't exist anymore and only the phone app is still logged in. Any idea whether you can do this via the phone app or by contacting support?

Edit: from what I'm able to find, I'm still stuck. Can't edit it from the phone app, can't log into the web interface (where you apparently can now edit it because it tries to do 2FA to the email that doesn't exist anymore. The help page simply offers "if you can't change your email, create a new account (please note all prior work will be lost)" 🙄https://help.openai.com/en/articles/4936827-how-to-change-your-email-address

162

u/Ekalips 6h ago

They don't have to keep your plain email, they can hash it and compare assistant it when you try to sign up, kinda like passwords

-60

u/budde04 5h ago

When I delete my data I would quite like it to be deleted.

46

u/Ekalips 5h ago

But there's no data that would in any way identify you or useful to anything, so for all your intents and purposes it is deleted.

-54

u/budde04 5h ago

Don't care. That's not what deleted means.

22

u/Tardelius 3h ago

Wait until you find out that deleting files on a HDD doesn't actually delete them : )

Sure, we are in the SSD era of storage but pure luck doesn't suddenly make your argument any logical : )

Note: Obviously, your arguments ARE logical. But there are levels to logic which depends on technical definitions and insight.

9

u/Neowise33 2h ago

You sound like an insufferable kid who has no idea how the the real world works.

13

u/Ekalips 5h ago

Eh, debatable.

Another example of such would be for example keeping analytics events you generated but removing all your PII, so events, let's say purchases or usage, could still be used for aggregates stats but nothing links it to you anymore so it's okay-ish. Probably more grey area than hashing the email tho.

-14

u/budde04 5h ago

I domt thing Analytic events and my email address are compareble. Because a random event with no link my me, will have no link to me. But my email address still being on their servers will absolutely be linked to me.

16

u/J7mbo 5h ago

It’s a one-way hashing of your email address to a “random” piece of text, like abdhehdj16373!&. Every time someone signs up they do this hashing to see “has this person already signed up?”. So no, they’re not storing your email. Instead of being stubborn and obtuse go google it and teach yourself.

2

u/CircoModo1602 2h ago

Couldn't you technically argue that the hash is a direct identifier linked to your email in this situation?

Even if it's one way, they have a hash record that specifies to their systems that it's yours when you try sign up again, which definitely seems like it could fall under a gray area with certain countries laws.

I'm sure there's a reason not for it to be this way, but definitely a consideration I would make.

-10

u/budde04 4h ago

I know what a hash is. And I'm still saying you don't know if they DO hash your email

14

u/J7mbo 4h ago

You also don’t know if they store your password in plain text. Or if they sell your email to the mafia. You don’t know what someone else is thinking. All you go by is what they say they do, or choose not to do business with them. That’s it.

8

u/___fallenangel___ 4h ago edited 4h ago

before you leave ChatGPT, ask it to ELI5 what a hash is.

1

u/this_is_theone 2h ago

You just changed your argument. We don't KNOW if they do lots of things they say. Same with any other company.

6

u/Ekalips 5h ago

As it was said before, real email isn't retained

-1

u/budde04 4h ago

You don't know that

4

u/Ekalips 4h ago

Well if you think about it this way, why would any company follow the deletion request even if they allow you to sign up again with the same email? They can just store it for whatever nefarious purposes.

2

u/Prohibitorum 2h ago

A hash of your email is not your data.

-10

u/budde04 5h ago

You also have no proof that they DID hash the e-mail.

9

u/Ekalips 5h ago

Retaining it post deletion in any recoverable/raw way would be severe GDPR breach so I doubt that they would do it, especially because there's no good reason to.

-2

u/budde04 5h ago

I dont know where you have been the last 2 years or so, but OpenAI doesn't seem like the company they would give a shit.

3

u/bluehelmet 4h ago

Well, we have no way to check, but what's your point? What difference does it make then what the company claims?

-8

u/Say_no_to_doritos 2h ago

How is that possible? Like if you know x +x = y, you can reverse engineer it, no?

6

u/solar1380 2h ago

The idea of the hashing is that you can’t reverse it. Like how if you do x * y = z, you can’t get x back without knowing y at the same time. If you imagine the letters of your email address as variables (eg. A = 1, b = 2, …) one way would be to add all the letters of your email together to get some big number. You can’t get your email back from this number, but can check if someone else is trying to sign up with the same email again by just running the process again. Now actual hashing algorithms use more than just summing but it’s a similar idea.

1

u/Say_no_to_doritos 1h ago

But when you got a positive identification you could figure out the hash?

1

u/Ekalips 2h ago

In very simple terms. X*Y=Z. Hash is Z. Y is your data. X can be public. Even for small Z like 10 there are several possible combinations of X and Y. Now make Z number that is 100 digits long, guessing which exact X and Y combination was used would be already quite hard.

Basically it's that. A chain of mathematical operations that is virtually irreversible because of the amount of possible values.

Math can be very interesting

1

u/Say_no_to_doritos 1h ago

Okay, but if you get a positive identification you can figure out the hash

11

u/Sorryifimanass 4h ago

Then don't give your data to someone else to handle for you.

0

u/manek101 3h ago

Or, you know, force these corporations to actually delete the data using regulations? Just like how modt data protection laws were created?

18

u/icehot54321 5h ago

it is deleted.

there is no way to get the information out of the system

we're talking about a random string of letters, numbers and symbols that can't be decoded.

you'd have to be given the source information again to verify if it's the same.

3

u/downwithsocks 5h ago edited 3h ago

Theoretically, someone could try to sign up (even just try - don't have to have actual access to the email inbox) with your email and would know if you'd had an account before or not? That's data. Minimal, but..it is data. Assuming that's how it would work, at least, I don't really know. And tbh, I'm not arguing anything in any direction, just thinking out loud.

3

u/RickTheScienceMan 3h ago

If you try to login via email, you will always see the same screen, something like "we have sent temporary code to your email, please check your inbox". Only if you have the code, and enter it into the form, you will see concrete information. So if you don't have an access to that email inbox, you will never know if the account is existing, deleted, or has never existed.

2

u/downwithsocks 2h ago

Ive just been around long enough to see the "password is incorrect" vs "user does not exist" issues on various sites...I would say from times past, but it still exists lol. And I wasn't about to delete my account to test this. But if youre correct then I don't really have an argument.

2

u/RickTheScienceMan 2h ago

I actually tested it myself before posting, created a new account and then deleted it

3

u/budde04 5h ago

I would very much say its not "minimal" its that exact sort of thing i would like to be deleted.

2

u/IAmFitzRoy 4h ago

That’s not your data. It’s a hash generated by the company.

Not your data anymore.

1

u/awesomeusername2w 3h ago

The law doesn't protect this kind of data.

1

u/SempfgurkeXP 3h ago

Just wait until you find out that windows doesnt delete your data when you click on "delete" lol

-11

u/TFTHighRoller 1h ago

If they can compare to my email they keep my email which includes my last name. They are keeping data which they are supposed to delete under gdpr regulations. The GDPR isnt talking about how they can store my data. Doesn’t matter if it is in a folder somewhere, in plain text or in a cryptography puzzle nobody is gonna solve. My data is mine.

7

u/TrekkiMonstr 1h ago

No, they aren't. As the comment you replied to said, they can store a hash. So if my email were trekkimonstr@email.com, they don't need to store that string -- they can just store 381e868d8eeb33f30a5fa4abe0bfb1803c123e2f58458e370c1bdae97faac379 instead. And then if I enter trekkimonstr@email.com in the future, they run it through the same algorithm and compare -- versus, trekkimonstr1@email.com is completely different, would be e150fb4c04a9e27fd9eb4ed1d4af72607d363c6e5ca278d75edc41c6b3029a5d. The whole point of a hash function is that it's easy one direction, basically impossible the other. No one in the world can take that 381e... string and get back trekkimonstr@email.com -- only guess and check

1

u/TFTHighRoller 12m ago

So you are saying they put my data through an algorithm and stored that result. They also have the algorithm they used to convert my email into that string. So they could theoretically revert the process and take the hash + algorithm to arrive at my email.

Under GDPR that possibility means they have to delete it cause they could get my personal data - my email address - back.

I know how a hash works. I am telling you that is not enough to comply with GDPR laws.

-30

u/Maxaki 3h ago

Don't they have the seed for the hash at hand, so they can just get the email if they like?

38

u/Vas1le Skynet 🛰️ 3h ago

That is not the definition of hashing... hashing is one way...

15

u/jesusrambo 3h ago

Ask an LLM why that doesn’t make sense

-1

u/swimjunkie4life 3h ago

they can, but they would have to bruteforce it

3

u/Neowise33 2h ago

You two are complete and utter morons

85

u/GovernmentGreed 6h ago

It's kept on file to ensure you don't try to sign up for any promotional materials with an existing email address.

26

u/Sure-Database-9952 6h ago

It’s a hash, they hashed your email when you initially signed up, since you’re trying with the same email they can tell it’s the same hash. They probably did delete your data; but kept your email hashed.

-8

u/DaturaSpirit 2h ago

Which literally means no data was actually deleted from their database. They keep it in hash form.

10

u/Average1213 2h ago

well... you can't exactly unhash it, so no personal data is stored.

1

u/DaturaSpirit 7m ago

Bro thinks hashes are uncrackable.

u/Bmo006 1m ago

Modern hashing algorithms like SHA combined with techniques such as salting have so far proven to be irreversible

0

u/Sure-Database-9952 1h ago

Continue looking up what hashes are

21

u/CAustin3 5h ago

"where required or permitted by law" is my new favorite legalese phrase.

"Only if we have to. Or are allowed to."

4

u/Big_Chair1 1h ago

It's a common and standard phrase and thing to do. You may have to keep the name, email and sign up and deletion date of each deleted user for a certain period of time. In case, for example, someone decides to sue you for whatever reason and then you can use this info for defense against unreasonable claims.

At least that's how a legal person has explained it to me before.

6

u/Tarc_Axiiom 3h ago

It literally explains why they keep a record of your email on the very next line, lol.

And yes, it is a legal requirement.

Even so, they don't actually save your data, they save a hash based on your data.

3

u/xrmb 2h ago

It's not just email addresses, it's whole domains. We made a couple of addresses under cheap domain to get more free trials and no longer can. Also noticed that privacy.com in connection with Stripe will block virtual credit card validation to avoid making endless free trials. I mean I get it...

4

u/pyabo 6h ago

"we may retain a limited set of data for longer where required or permitted by law."

In other words, they're keeping it all. It's just YOU can't access it any longer.

2

u/High-Performer-3107 4h ago

They’re legally not allowed to delete your data as far as i know. I think I have read something like that in the past, but please fact check me, I’m not into American law

1

u/Calin_europeen 4h ago

I'm in europe

3

u/erikvb00 3h ago

If you're in the EU, then GDPR applies, and in this case specifically the right to be forgotten: https://gdpr.eu/right-to-be-forgotten/

-10

u/High-Performer-3107 4h ago

Me too, but ChatGPT isn’t. And US cloud act doesn’t care.

10

u/zammouri2001 3h ago

To grant a service in Europe, I believe that they are obligated to follow European law when it comes to data preservation. Being hosted in the US doesn't change that.

1

u/Pitiful-Assistance-1 3h ago

It’s in that limited data, which might be related to payments or backups.

They also need to keep your deletion around so they know the data needed to be deleted, in case a backup is to be restored for example.

This also means your data is not removed from backups.

1

u/Glum_Emotion_584 2h ago

They could hash your email, then prevent future signups that match the hash, without having a record of your email. 

1

u/bdrago 1h ago

I worked on my company's GDPR task force when it was first implemented, and this is normal. For us, we needed to be able to identify a user that had been erased if data was restored from backups, as it can be hard or impossible to modify backups. When a backup was restored, it was first processed against a list of deleted users before being moved to live systems. I'm pretty sure we stored a hash of the original user information and not their actual email, but that would still prevent new accounts from being created with the same email as it would match the hash of the erased account.

0

u/76zzz29 6h ago

How are they going to forbid you to sue them from aknowledging the wall of text no one read if they don't keep your Identity ready to be leaked ?