Incogni privacy ranking: the big players are risky, except ChatGPT

Incogni, a broker data removal service, published yesterday a report titled “Gen AI and LLM Data Privacy Ranking 2026” that ranks 13 AI platforms by user privacy risk. The prominent finding is that the larger the platform, the more invasive it is, with a single notable outlier, ChatGPT by OpenAI, which landed at the top of the ranking alongside Vibe by Mistral AI. Gemini by Google and Meta AI received the worst scores, i.e., the highest risk.
The assessment relied on three axes: what happens to user data (whether conversations are fed into training, whether an opt-out is possible, whether prompts are passed to a third party), how accessible and clear the privacy policy is, and what personal information is collected, its source, and where it flows if shared. Each point added to the score reflects a more invasive practice, so a lower score indicates better privacy.
Vibe (formerly Le Chat) by Mistral AI led the table thanks to a privacy policy that is easy to understand, privacy-friendly mobile apps, collection only from public sources, and sharing conversations with a minimal number of third parties. ChatGPT placed second with a clear policy, accessible FAQ, a simple opt-out from model training, and a disclosed statement that data may be used for security and marketing purposes.
Pi by Inflection AI ranked third: its policy is complex and separates European users for GDPR purposes, and it may share data with corporate, commercial and research partners, although the app itself is considered privacy-friendly. Perplexity closes the first quintile with a lightweight policy that is easy to track but not detailed enough, making it hard to understand the full scope of collection and sharing.
Gemini and Meta AI received the highest scores in the report, i.e., the highest privacy risk. The report does not detail the full rationale for each platform ranked below the first quintile, which include Claude, Grok, Qwen, DeepSeek, Z.ai, Kimi and Copilot, but the trend is clear: platforms from tech giants tend to collect more, share more, and make it harder for users to understand what happens to their data.
The report arrives against a backdrop of deep penetration of everyday language models, from financial advice to medical decisions, as users feed sensitive prompts without reading fine print. Incogni, whose revenue model is based on broker data removal, points to the gap between convenience and transparency. Disclosure: Zeph Davis, the parent company of ZDNet that released the news, noted an April 2025 lawsuit against OpenAI alleging copyright infringement in training.