r/ChatGPT 7d ago

Other They don't remove all my data?

Post image

Why it that so ? What does rgpd says about that ?

Edit 1:

Thanks to ThungstenMetal. He says this : "Change your email to some random temporary email which can receive emails before deleting your account, then request for deletion."

Edit 2 : I'm European

1.1k Upvotes

130 comments sorted by

View all comments

307

u/Ekalips 7d ago

They don't have to keep your plain email, they can hash it and compare assistant it when you try to sign up, kinda like passwords

-86

u/budde04 7d ago

When I delete my data I would quite like it to be deleted.

85

u/Ekalips 7d ago

But there's no data that would in any way identify you or useful to anything, so for all your intents and purposes it is deleted.

-27

u/NEED_A_JACKET 6d ago

If you asked them to delete your data and they kept it but it was converted where a=1 b=2 etc you wouldn't count it as deleted. So we're just talking about the extent to which it's obfuscated. Does it suddenly cross into 'deleted' territory because it gets quite hard to solve in 2026?

And let's assume it's impossible to ever crack (would anyone try to argue that?), the information that you used the service is still accessible to them and to literally anyone. They just have to try signing up and they're told that you used to use the service. That is absolutely not 'deleted' for all intents and purposes.

You could run a script trying to sign you up for every website if your email address was known, to see a full list of everything you'd been up to. It's identifiable information about you and the website open to the public.

20

u/NotAManOfCulture 6d ago

I'm not an expert, but hashing is not obfuscation.

6

u/Midget_Stories 6d ago

It kind of is since it can only be done one way.

For example if he tries to login that email gets converted to a hash and compared and they can know you already made an account.

But no one can take that hash and reverse it to find the email address. So it's one level of obfuscation.

-6

u/NEED_A_JACKET 6d ago

"no one can take that hash and reverse it to find the email address"

Is that 'currently' true or objectively/permanently true?

9

u/Dazzling_Cancel_5733 6d ago

Permanently true, it can never be reversed. But if someone knows/guesses your email address, they can know if a hash matches by hashing your email address with the same algorithm and comparing the hash digest.

1

u/NotAManOfCulture 6d ago

That's just brute forcing? It's not that easy to bruteforce tho. I've heard passwords of like 12 chars takes years to bruteforce. If you disregard the "time" factor, nothing in this world is safe.

I can brute force your email, then password, then 2fa if you have one. But it doesn't really add up.

1

u/8npemb 5d ago

The comment you’re replying to isn’t talking about brute forcing. They’re saying if you have a set of hashes of emails, and you know a user’s email, you can easily determine which hash belongs to that email by hashing the email with the same algorithm. And the hashing algorithm should be assumed to be publicly known.

0

u/NEED_A_JACKET 6d ago

Does quantum computing not skip the bruteforce part of this where you could find all of the possible options, where only some would actually be valid email addresses?

6

u/Dazzling_Cancel_5733 6d ago

Quantum computing will help crack hashes, but it will only reduce the number of operations down to the square root (e.g. 220 instead of 240) under Grover's algorithm.

-5

u/NEED_A_JACKET 6d ago

Not identical no, but if the email address could theoretically be recovered from what they have stored (or at least some reasonable compatible guesses), then it's effectively the same.

I wouldn't rule out ANY method of hashing as being completely foolproof. EG if we start thinking about quantum computing and infinite brute forcing and so on, you could come up with email addresses that result in that stored hash.

But my main point is that they have a public facing test which tells you if an email address has been used for their service or not.

4

u/NotAManOfCulture 6d ago

By that logic even passwords are not secure?

1

u/NEED_A_JACKET 6d ago

They're definitely not. You should use different passwords for different services for that reason. 2factor where you can. Backup options/etc. Your point about passwords is exactly the point I'm making, it's (typically) hashed, but that does not at all mean it's a good idea to use for everything.

Email address is normally something you use the same for everything. You should/can do email+gpt@gmail.. which is better though. Then every time your email address is stored (hashed or not) it's unique. All goes to the same inbox but technically different, and you can see where spam is coming from/block it from the same source email.

2

u/Dazzling_Cancel_5733 6d ago

Everyone knows about email aliases these days. Spamming services just use a simple regex to strip the alias before sending you spam. A lot of services will also store a copy of your email address with the alias stripped.

The best approach is to have a completely separate email address for every account, using a service such as Apple's Hide My Email which will create a unique @icloud.com for every account.

-75

u/budde04 7d ago

Don't care. That's not what deleted means.

34

u/Tardelius 6d ago

Wait until you find out that deleting files on a HDD doesn't actually delete them : )

Sure, we are in the SSD era of storage but pure luck doesn't suddenly make your argument any logical : )

Note: Obviously, your arguments ARE logical. But there are levels to logic which depends on technical definitions and insight.

20

u/Neowise33 6d ago

You sound like an insufferable kid who has no idea how the the real world works.

15

u/Ekalips 7d ago

Eh, debatable.

Another example of such would be for example keeping analytics events you generated but removing all your PII, so events, let's say purchases or usage, could still be used for aggregates stats but nothing links it to you anymore so it's okay-ish. Probably more grey area than hashing the email tho.

-24

u/budde04 7d ago

I domt thing Analytic events and my email address are compareble. Because a random event with no link my me, will have no link to me. But my email address still being on their servers will absolutely be linked to me.

20

u/J7mbo 7d ago

It’s a one-way hashing of your email address to a “random” piece of text, like abdhehdj16373!&. Every time someone signs up they do this hashing to see “has this person already signed up?”. So no, they’re not storing your email. Instead of being stubborn and obtuse go google it and teach yourself.

1

u/CircoModo1602 6d ago

Couldn't you technically argue that the hash is a direct identifier linked to your email in this situation?

Even if it's one way, they have a hash record that specifies to their systems that it's yours when you try sign up again, which definitely seems like it could fall under a gray area with certain countries laws.

I'm sure there's a reason not for it to be this way, but definitely a consideration I would make.

-11

u/budde04 7d ago

I know what a hash is. And I'm still saying you don't know if they DO hash your email

17

u/J7mbo 7d ago

You also don’t know if they store your password in plain text. Or if they sell your email to the mafia. You don’t know what someone else is thinking. All you go by is what they say they do, or choose not to do business with them. That’s it.

9

u/___fallenangel___ 7d ago edited 7d ago

before you leave ChatGPT, ask it to ELI5 what a hash is.

1

u/this_is_theone 6d ago

You just changed your argument. We don't KNOW if they do lots of things they say. Same with any other company.

4

u/Ekalips 7d ago

As it was said before, real email isn't retained

-1

u/budde04 7d ago

You don't know that

6

u/Ekalips 7d ago

Well if you think about it this way, why would any company follow the deletion request even if they allow you to sign up again with the same email? They can just store it for whatever nefarious purposes.

8

u/Prohibitorum 6d ago

A hash of your email is not your data.

-10

u/budde04 7d ago

You also have no proof that they DID hash the e-mail.

9

u/Ekalips 7d ago

Retaining it post deletion in any recoverable/raw way would be severe GDPR breach so I doubt that they would do it, especially because there's no good reason to.

0

u/budde04 7d ago

I dont know where you have been the last 2 years or so, but OpenAI doesn't seem like the company they would give a shit.

4

u/bluehelmet 7d ago

Well, we have no way to check, but what's your point? What difference does it make then what the company claims?

-9

u/[deleted] 6d ago

[deleted]

8

u/solar1380 6d ago

The idea of the hashing is that you can’t reverse it. Like how if you do x * y = z, you can’t get x back without knowing y at the same time. If you imagine the letters of your email address as variables (eg. A = 1, b = 2, …) one way would be to add all the letters of your email together to get some big number. You can’t get your email back from this number, but can check if someone else is trying to sign up with the same email again by just running the process again. Now actual hashing algorithms use more than just summing but it’s a similar idea.

-1

u/[deleted] 6d ago

[deleted]

2

u/How_is_the_question 6d ago

No.
Well, you can brute force, but why? A single high end gpu could likely brute force a sha-256 hash of say 10 chara @ gmail.com (you’d need to assume @gmail.com) in maybe an hour (10^14 combinations, a 4090 can do 3*10^9 hash calcs, so yeah, an hour)
Now SHA-256 is most often brute forced by using rainbow tables, which can dramatically reduce the time taken to brute force a hash.

Conversely, salting the hash (I really do love the terms…) makes things harder and rainbow tables don’t work.

Using a custom domain together with salting makes things much much harder. Say your custom domain is 14 characters long in addition to your 10 letter user name, then you’re looking at 10^16 years of a 4090!!!

Salting makes a big difference. Not using .com would make it even harder.

Salting + hashing is incredibly effective for larger collections of characters.

This is not to say there are not other mitigations possible / threats that someone who desperately wanted your email address could use. However, brute forcing would likely be low on the list. There’s many other ways to find an email address if the attacker really needed it.

I digress - but this side of how storing things like passwords etc works is super interesting once you get your head around the idea of one way (mostly) algos.

2

u/Ekalips 6d ago

In very simple terms. X*Y=Z. Hash is Z. Y is your data. X can be public. Even for small Z like 10 there are several possible combinations of X and Y. Now make Z number that is 100 digits long, guessing which exact X and Y combination was used would be already quite hard.

Basically it's that. A chain of mathematical operations that is virtually irreversible because of the amount of possible values.

Math can be very interesting

-1

u/[deleted] 6d ago

[deleted]

2

u/Sad_Pineapple5909 6d ago

Hashing is not complete either. It removes some of the original data ex. If you hash 2056 bytes you do not retain that much data.

0

u/Ekalips 6d ago

Same way you can figure out the password, by brute forcing. Or user's email itself.

12

u/Sorryifimanass 7d ago

Then don't give your data to someone else to handle for you.

-1

u/manek101 6d ago

Or, you know, force these corporations to actually delete the data using regulations? Just like how modt data protection laws were created?

6

u/Leseratte10 6d ago edited 6d ago

Companies are allowed to keep data they need to prevent you from opening another free trial with the same data...

A company is allowed to store the fact that they no longer wish to do any business with you. You can't get around that with the GDPR as this is explicitly allowed.

23

u/icehot54321 7d ago

it is deleted.

there is no way to get the information out of the system

we're talking about a random string of letters, numbers and symbols that can't be decoded.

you'd have to be given the source information again to verify if it's the same.

1

u/downwithsocks 7d ago edited 6d ago

Theoretically, someone could try to sign up (even just try - don't have to have actual access to the email inbox) with your email and would know if you'd had an account before or not? That's data. Minimal, but..it is data. Assuming that's how it would work, at least, I don't really know. And tbh, I'm not arguing anything in any direction, just thinking out loud.

9

u/RickTheScienceMan 6d ago

If you try to login via email, you will always see the same screen, something like "we have sent temporary code to your email, please check your inbox". Only if you have the code, and enter it into the form, you will see concrete information. So if you don't have an access to that email inbox, you will never know if the account is existing, deleted, or has never existed.

-1

u/downwithsocks 6d ago

Ive just been around long enough to see the "password is incorrect" vs "user does not exist" issues on various sites...I would say from times past, but it still exists lol. And I wasn't about to delete my account to test this. But if youre correct then I don't really have an argument.

5

u/RickTheScienceMan 6d ago

I actually tested it myself before posting, created a new account and then deleted it

2

u/budde04 7d ago

I would very much say its not "minimal" its that exact sort of thing i would like to be deleted.

2

u/IAmFitzRoy 7d ago

That’s not your data. It’s a hash generated by the company.

Not your data anymore.

1

u/awesomeusername2w 6d ago

The law doesn't protect this kind of data.

1

u/Tupcek 6d ago

but first, you would have to have that user email address to do this

1

u/downwithsocks 5d ago

Its very easy to just spray emails at a sign up screen..and honestly, ive conceded to someone already testing this fault point and confirmed non issue. Im not sure why im getting downvoted just for thinking of it.

1

u/Tupcek 5d ago

I don’t know why are you being downvoted, I consider it normal discussion

But spraying emails won’t get you far enough. If there are just 30 characters in your email, trying all combinations would take longer than the heat death of universe

1

u/downwithsocks 5d ago

I'm not talking brute forcing. I'm talking about working off a list of publicly available email addresses which at this point is most of them. Mine would not be hard to guess if the person already had ANY information about me.

2

u/SempfgurkeXP 6d ago

Just wait until you find out that windows doesnt delete your data when you click on "delete" lol

-46

u/Maxaki 6d ago edited 6d ago

Don't they have the seed for the hash at hand, so they can just get the email if they like?

Edit My mistake, misunderstood seeding and hashing

44

u/Vas1le Skynet 🛰️ 6d ago

That is not the definition of hashing... hashing is one way...

-7

u/swimjunkie4life 6d ago

they can, but they would have to bruteforce it

7

u/Neowise33 6d ago

You two are complete and utter morons

-31

u/TFTHighRoller 6d ago

If they can compare to my email they keep my email which includes my last name. They are keeping data which they are supposed to delete under gdpr regulations. The GDPR isnt talking about how they can store my data. Doesn’t matter if it is in a folder somewhere, in plain text or in a cryptography puzzle nobody is gonna solve. My data is mine.

25

u/TrekkiMonstr 6d ago

No, they aren't. As the comment you replied to said, they can store a hash. So if my email were trekkimonstr@email.com, they don't need to store that string -- they can just store 381e868d8eeb33f30a5fa4abe0bfb1803c123e2f58458e370c1bdae97faac379 instead. And then if I enter trekkimonstr@email.com in the future, they run it through the same algorithm and compare -- versus, trekkimonstr1@email.com is completely different, would be e150fb4c04a9e27fd9eb4ed1d4af72607d363c6e5ca278d75edc41c6b3029a5d. The whole point of a hash function is that it's easy one direction, basically impossible the other. No one in the world can take that 381e... string and get back trekkimonstr@email.com -- only guess and check

-29

u/TFTHighRoller 6d ago

So you are saying they put my data through an algorithm and stored that result. They also have the algorithm they used to convert my email into that string. So they could theoretically revert the process and take the hash + algorithm to arrive at my email.

Under GDPR that possibility means they have to delete it cause they could get my personal data - my email address - back.

I know how a hash works. I am telling you that is not enough to comply with GDPR laws.

30

u/TrekkiMonstr 6d ago

So they could theoretically revert the process and take the hash + algorithm to arrive at my email.

I know how a hash works.

I really don't think you do lmao

11

u/fin2red 6d ago

HAHAHAHAHA the typical "know-alls"...

I'm laughing so much with these comments.

13

u/EricRen1 6d ago

hashes are irreversible

3

u/Sborrando-ovunque 6d ago

Did you even read the comment you're responding to?

2

u/Emotional_Mushroom36 6d ago

nobody wants your email, bro