Proton’s AI Paper Trail Shows Hidden Privacy Risks in Everyday AI Conversations
What Happened — Proton released a free tool, AI Paper Trail, that ingests exported ChatGPT or Claude conversation archives, parses the most recent prompts, and generates a personal privacy report. The analysis of a journalist’s own ChatGPT history uncovered 47 inferred data points—including location, finances, relationships, and interests—yielding an AI Exposure Score of 58/100.
Why It Matters for Compliance & Audit Readiness —
- The report proves that routine AI chat logs can become personal data, invoking SOC 2 CC6.1, GDPR Art. 5, and CCPA obligations.
- It underscores the need for continuous inventory, data‑minimization, and DSAR readiness for AI‑derived information.
- Aligns with Verisq’s CookiePLUS Privacy capability, which automates consent mapping and provides audit‑ready evidence of AI data exposure.
Who Is Affected — SaaS platforms offering AI assistants, enterprises integrating ChatGPT/Claude into internal or customer workflows, and any organization that stores AI conversation histories.
Recommended Actions —
- Export and catalog AI conversation logs to identify personal data.
- Implement consent, retention, and DSAR processes that explicitly cover AI‑derived data.
- Leverage CookiePLUS to assess exposure, map controls, and generate audit evidence. Source: Help Net Security
Technical Notes — The service analyzes up to 200 recent prompts, infers data types via natural‑language processing, and deletes uploaded files after analysis. No vulnerabilities or CVEs are disclosed. Source: Help Net Security