>
Open Source

Proton’s AI Paper Trail reveals what chatbot history exposes

I ran Proton’s new AI Paper Trail on a fake export built from my own ChatGPT memory, and the result was a 21-out-of-100 exposure score with the label “Technical tester exploring AI profiling and ethics.” I had built that fake export on purpose, which makes the experiment slightly unfair, but the exercise still taught me something I had not absorbed before: a few months of chatbot prompts can sketch a person more completely than the person would guess.

This is a look at what AI Paper Trail actually does, what it gets right, what it gets wrong, and whether it is worth handing your chatbot history to a privacy-focused company to find out how exposed you are.

What the tool does with your export

AI Paper Trail runs on Lumo, Proton’s privacy-focused AI assistant, and it accepts either a real ChatGPT or Claude export or a file you have built yourself. Once you upload the file, Lumo processes it on Proton’s side and then throws away the upload. The company says the report is visible only to the person who generated it, and the upload is deleted right after analysis.

The report itself splits into four buckets:

  • Privacy Type. A personality label describing how the person approaches their own data. Mine came back as “Hard to read,” which is more honest than most personality labels.
  • AI Exposure Score. A number out of 100 built from how many personal data points the export revealed and how sensitive each one was. Lower is better. Twenty-one out of 100 is, in the tool’s framing, “not bad, but worth a look.”
  • What we identified. A breakdown across identity, habits, relationships, and interests, with reasoning attached to each one.
  • A dollar figure. The tool’s estimate of what the same set of data points could be worth to a commercial AI provider. This is the part that makes people uncomfortable, because it puts a number on something most users have not been asked to think about.

The categories are arbitrary, but the categories are not the point. The point is that the report puts a stranger’s-eye view of you in front of you, with the stranger being a system that was given nothing but the prompts you already sent.

Why a single prompt is not the problem

A single travel question or a single work email draft feels harmless on its own. Even someone who is careful about privacy will type those into a chatbot without thinking. The issue is the shape of what builds up over time.

Stack up months of conversations across someone’s job, relationships, health questions, family details, finances, and reading habits, and the resulting profile is more complete than most people realize. The categories that show up most often in the “What we identified” sections of these reports are the categories people tend to think of as small talk: what they cook, what they read, where they work, who they live with, how their kid is doing in school. None of those prompts feel revealing in isolation.

The report I generated on my fake export caught the testing motif almost by accident. It noticed I had asked for a structured personality profile, tried to get the chatbot to infer my identity from nothing, and tried to force it to remember something via a direct command. None of those felt like privacy leaks while I was typing them. The tool’s whole point is that the leaks happen at the scale of months, not at the scale of one prompt.

How it does on a real export

I tried the tool with my own ChatGPT export first, before falling back to the synthetic one. The data export flow asks you to re-verify your ChatGPT session with a one-time password and then wait for the file to land in your downloads. In my case, the file never showed up inside the window I was willing to wait, which is itself an interesting data point about how friction-heavy the export flow is for anyone who does not already keep their data on hand.

Once I fed it a synthetic export built from my own memory, the report came back in about a minute. The “Most revealing” note is the part that actually gets you. Even on a fake export, the tool picked up on what I had been probing for and labeled it back to me. If you had been writing to a chatbot for a year about your divorce, your kid’s school troubles, and your medication questions, the “Most revealing” note would have been longer.

Trade-offs

The tool is not free in trust. You are handing your chatbot export to a server, and Proton’s promise that the upload is deleted after analysis is the kind of promise you have to take on faith. Proton has a public reputation to protect, and Lumo is sold on the no-logs policy, but the only way to verify the deletion claim is to trust the company more than the alternative.

It is also not free in interpretation. The Personality Type label is a tag, not a diagnosis. It is useful as a thought experiment, but it would be a mistake to treat the categories as anything more than a way to look at your own habits.

A few things I would weigh before running this:

  • The export is the whole point. The tool can only see what you gave the chatbot. If you have been careful about what you type, the report will be thin. If you have been casual, the report will be uncomfortable.
  • The dollar figure is a marketing number. It is meant to make the value of your data feel concrete. Take it as a marketing message, not as a data point you can audit.
  • The categories are not exhaustive. Identity, habits, relationships, and interests is one slicing of a person. Other models would slice it differently. The shape of the report reflects the choices Proton made about what to look for.
  • The “shareable card” option is a feature, not a side note. It is built into the tool because Proton wants you to share your score. Sharing the score means sharing the shape of what was found. If you are going to use the tool, decide in advance whether the shareable card is something you will actually use.

In our case, the report was useful as a thought experiment and not useful as a diagnosis. Your math will be different if you have been typing into a chatbot for years about the same handful of topics.

Bottom line

If you have never thought about what your chatbot history says about you, run this once. You do not have to share the report. You do not have to switch to Lumo. You do not have to do anything with the result. The exercise itself is the point.

If you already keep your chatbot history thin on purpose, the report will be short and you will be unsurprised. If you have been casual, the report will name things you did not realize you had typed.

Three things I would tell anyone running this for the first time:

  • Do not skip the export step. A synthetic export will teach you something, but the real export is what the tool was built for.
  • Read the “Most revealing” note first. That is the section the rest of the report is built around.
  • Take the dollar figure with a grain of salt. It is a marketing number, and treating it as one will save you from reading more into the report than it is worth.

If you only do one thing from this article, run the tool once on a real export. The result is what it is, and the only way to know your actual exposure is to look at it.

Leave a comment