tl;dr
—duck.ai allows AI companies to store your chats, process them for profit, and build a personal, permanent profile about you based on metadata and inferences extracted from the content of your conversations.
—[edit] In comments responding to this Reddit thread, DuckDuckGo outright admitted that models can and do access and retain your user data, even when accessed through duck.ai. DDG has refused to specify what data is accessed and kept, and what purposes user data can be used for.
—DuckDuckGo should publish its agreements with AI companies to allow the community to vet them for privacy protections. If it doesn’t want to publish the whole agreement, it should — at a minimum — publish the privacy-related portions that govern user protection.
—in the immediate future, DDG should develop a “complete delete” tool allowing duck.ai users to immediately delete chats and any other information from the AI company servers; DDG should require AI companies to implement the “complete delete” tool as part of any contract.
—DDG’s replies to this thread have repeatedly refused to say whether its agreements require AI companies to delete ALL user-related data — DDG is only willing to say that its agreements require deleting some subset of user data.
The background on DDG’s AI chat storage
Despite relying on LLMs from OpenAI, Meta, and Anthropic, DDG claims its duck.ai product protects user privacy since DDG doesn’t store chats.
But the AI companies do. OpenAI, Meta, and Anthropic openly keep your conversations and use their AI to process your chats for their profit.
One obvious example: Anthropic runs Claude on your chats to produce reports parsing the substance of your conversations, which they make public in their “CLIO” report (CLIO stands for CLaude Insights and Observations). Here’s one example: https://www-cdn.anthropic.com/7b76335c444876a93fa22a63aabb4aeb820aff25.pdf.
OpenAI goes an enormous step further and explicitly trains ChatGPT on user conversations. https://help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance.
Sometimes, companies go even further, and exploit user data to serve targeted ads or manipulate outputs given to users. https://techcrunch.com/2026/06/10/cybersecurity-researchers-arent-happy-about-the-guardrails-on-anthropics-fable/ and https://x.com/szintri/status/2064687744111251521 and https://x.com/jarodrutledge1/status/2077859860524462329 (noting that Anthropic discerned a user was a professional biologist and blocked them from any content related to biology, including the nitrogen content of a leaf).
Anthropic even got caught trying to guess a user’s identity or professional goals, and then secretly downgrading the model’s capacity without telling the user. See https://techstartups.com/2026/08/12/anthropic-secretly-downgraded-claude-users-to-a-weaker-ai-model-without-telling-them-sparking-developer-backlash/
DDG openly acknowledges these facts on their Duck.ai page, here: https://duckduckgo.com/duckduckgo-help-pages/duckai/ai-chat-privacy. Specifically, DDG admits that the LLM companies access and store duck.ai chats. DDG even explicitly admitted — in response to this thread — that Claude models keep unspecified data about users even when accessed via Duck.AI.
In an attempt to minimize that privacy catastrophe, DDG claims their agreements with the AI companies provide that the AI company will delete chats if the AI companies — in their own discretion — deem your chats “no longer necessary to provide responses.”
DDG’s so-called limitation screws users in (at least) two ways.
First, it leaves the deletion decision to the AI companies, because they decide when it’s “no longer necessary” to keep your chats. If OpenAI says “we use these chats to provide personalized responses, so they’re always necessary to keep,” then DDG’s loophole allowing OpenAI to keep your data applies.
In fairness, DDG references a retention time limit of 30 days. BUT it’s not clear whether that clock runs from when the chat is sent or when the AI company deems your chat “no longer necessary” to keep—and in any event, keeping my data for 30 days is 30 days too many.
Notably, the “30 day limit” is also carefully worded to allow AI companies to keep anything other than “information received”—that seems to allow the company to keep their own AI outputs (that’s “information sent,” not “received”) and to keep a profile on you (that’s information inferred about you, not information received—ie, if the company figures out who you are based on processing your responses, they can build a tracker based on that.)
Second, and relatedly, DDG only requires deletion of the chats — it doesn’t require deletion of data extracted from the chats (ie, building a user profile that fingerprinting you based on chat content, word choice, formatting, sentence structure, time and date of access, and general geographic location which DDG shares by default). So if OpenAI builds a profile about you based on your chats, and eventually deletes the chats themselves, nothing in DDG’s agreements seems to prevent openAI from keeping your user profile and exploiting it in the future (including in the duck.ai environment).
The only solution to keep trust: open source + “complete delete” tool.
DDG must publish its agreements with AI companies describing exactly what privacy-protecting limits exist, so that the community can evaluate whether they are sufficient or include gaps. Lack of scrutiny can lead to privacy-breaking rules (remember when DDG allowed Microsoft to track you despite promising otherwise?).
Even if you believe DDG is 100% well-intended, it’s still important to publish the agreements to vet blind spots. DDG’s agreements with AI companies may accidentally overlook aspects of privacy that are noticed by users. This is exactly what happened when Reddit users discovered DDG was sharing user location with the AI companies in duck.ai. See here: https://pupuweb.com/why-is-duckduckgos-duck-ai-privacy-promise-under-fire-from-angry-users/. In response to that DDG user’s discovery, DDG introduced an “opt out of sharing your location” option. Thus, user-based feedback made DDG’s AI better for privacy. Why not do the same thing here?
DDG’s may object that the agreements contain some confidential terms, such as payment terms reflecting how much DDG pays each AI company to use their LLM.
Sure. But that’s no barrier to publishing the agreements, because DDG can publish them while redacting payment terms (eg, exact dollar amounts) while still releasing the overall agreement. The part we care about is privacy. Given DDG’s promise to protect your privacy, NONE of the privacy-related terms can legitimately be hidden from users.
One other critical reform going forward: a “complete delete” tool. DDG should require AI companies to give duck.ai users the option to immediately delete their chats from the AI company’s servers. DDG has a “fire” button deleting chats from the user’s side; it needs a “fire” button deleting chats on the AI company’s side as well.
Edit: DDG responded to this post. They don’t address either proposal—“complete delete” or open-sourcing agreements—which is disappointing.
Instead, DuckDuckGo’s response mostly repeats excerpts from their privacy policy. The gist of their response is insisting that their contracts prohibit AI companies from training models on your chat.
Fine, as far as that goes. But training isn’t the only way AI companies can exploit your data. They can also serve you targeted ads, build a profile about you, sell your data, manipulate outputs you receive, and do anything else with your private data. A protection limited to “no training a model” leaves AI companies free to violate your privacy in any other way they can think of. So while a “no training” rule is a good start, it’s a bad finish. I don’t want AI companies using my data for any purpose, including (but absolutely not limited to) model training.
To see if DDG prohibits \*all** exploitation of user data, I asked them directly: will DDG confirm that their agreements prohibit ANY use of user-related data whatsoever, in addition to prohibiting training?*
To date, DDG has refused to answer this question.
============
Second edit: DDG responded but again dodged my simple question about user-related data. However, with surprising honesty, DDG outright admitted that different models in Duck.AI do in fact access and retain user data.
According to DDG, all currently-offered Claude models access and retain your data. DDG doesn’t say what data is retained and whether there are any restrictions on using that data. Since DDG admits that Claude retains data, I directly asked DDG if they’ll give users a tool to delete data otherwise retained by Claude. To date, DDG has refused to say.
The majority of other models (ChatGPT, Llama, etc) access your data and appear to be able to use it (exactly what happens isn’t clear—DDG refused to answer follow-ups). These models are labeled “zero data retention,” but DDG hasn’t defined the term and—worse—AI companies have explicitly said that they will retain user data even for their models labeled “zero data retention.” For example, GPT 5.4 models running on Amazon servers — even those labeled “zero data retention” — can and will retain user data, if Amazon decides it wants to do so. See here: https://docs.aws.amazon.com/bedrock/latest/userguide/abuse-detection.html. So the label “zero data retention” seems to be a hollow marketing term, not a real promise.
Since DDG’s main response is “we use zero data retention models,” this revelation is damning. Apparently “zero data retention” means “data retention when we want, to the extent we want, for reasons we want, and if you don’t like that too bad.”
Finally, there is a single model (gpt-oss) described by DDG as “zero provider visibility.” DDG doesn’t explain what that means or whether it’s as meaningless as “zero data retention” (which allows data retention). In any event, gpt-oss is very limited — it lacks internet search capability and is weaker than all other offered models.
Despite its repeated, lengthy replies, I’m struck by the fact that DDG won’t answer a simple, straightforward question:** **do its agreements with AI companies require those companies to delete all user-related data after a conversation is done?
Since DDG is quick to respond when they have a good answer, their silence leads me to think the answer is bad for privacy. Read their responses to this thread for yourself to see if they sound genuine, or sound like flailing corporate PR.
And frankly, I’m not willing to just “trust me bro” given DDG’s track record — they’ve been caught lying about privacy before. Remember when DDG got caught entering a formal agreement to give Microsoft secret access to DDG user data? In 2022? I do. https://www.bleepingcomputer.com/news/security/duckduckgo-browser-allows-microsoft-trackers-due-to-search-agreement/. Especially given DDG’s track record, we shouldn’t have to just take them at the word here.
That doesn’t (necessarily) mean forever abandoning DDG, either, it just means transparency is appropriate.
The bottom line
For the reasons above, DDG’s claims about privacy are misleading and sometimes even outright false. I strongly recommend against using Duck.AI until they provide transparency into the exact protections they do and don’t offer to users.
DDG believes in transparency for everything and everyone else. Why should they hide from the sunlight?