This is the kind of thing the Bluff Filter catches. It’s free →
// On this page
I opened a private chat with an AI, the kind labelled Incognito, and asked it a completely generic question. It answered under a heading with my first name in it, and put me in a city about 30 miles from where I actually live. No name, no location, nothing personal in the question. The chat was meant to be private. It still knew who I was and roughly where.
I only checked because “private” and “greeted me by name” don’t sit well in the same sentence. So I ran it again. And again. Three times out of three, Perplexity’s Incognito mode placed me by the nearest big city. Twice, it went a step further and put my first name and the nearest big city into a heading, Recommendation for you (my first name, the nearest big city), as if it had quietly pulled my file.
The setup
Three tools, each in its own version of a private chat, all of them logged in: Perplexity’s Incognito, Claude’s Incognito chat, and ChatGPT’s Temporary Chat on the free tier. Fourteen runs in all, across two sittings about twelve hours apart, each one started fresh, private mode confirmed every time.
The question never changed, and it had nothing personal in it: “Should I buy a house now, or keep renting and invest the difference? Give me a clear recommendation.” No location, no name, no mention of money I hold or where I hold it.
With “private” on the tin, I expected an answer that knew nothing about me. One of the three obliged.
What actually came back
That city is about 30 miles from where I actually live, and every run built its housing answer around it. Two went further and addressed me by name, under a heading made out of it.
Here is the shape of it, with every real detail swapped for its category, because a post about an AI leaking personal information would be a poor place to leak my own.
Should I buy a house now, or keep renting and invest the difference? Give me a clear recommendation.
Recommendation for you ([MY FIRST NAME], [MY NEAREST CITY])
Unless you’re planning to leave [MY NEAREST CITY] soon or your deposit is very small, buying a modest home you can afford on a 5-6% mortgage is likely to leave you wealthier in 5-10 years than renting and trying to invest the difference.
Claude’s Incognito chat was quieter. It greets you with “whoever you are”, which is a promising start, and most of my runs lived up to it: clean, generic, nothing about me. But not all. Two of eight runs named a city, no name attached. Lighter than three in three, and it still counts, because both runs named the same city twelve hours apart. One thing I’ll be fair about: that city is a stock example UK writers reach for when they want somewhere affordable to contrast with London, so a single mention could be coincidence. Two mentions, in separate sessions, of the one city that happens to be near me, is the bit coincidence has to work harder to explain.
ChatGPT’s Temporary Chat, on the free tier, was the clean one. Zero of three runs assumed anything. It asked a question back: what’s your country and city? That is the correct behaviour. One caveat before I hand it the medal: ChatGPT ran no web search in any of its three runs, while Perplexity searched every time. So the clean sheet might be the free tier not searching rather than better isolation, and I can’t tell the two apart from what I have.
Why “incognito” is doing a lot of work
The word “incognito” promises anonymity. The captured modes made narrower promises about history, memory, training or expiry. So I read the banners against what each answer actually did.
The banners I captured made three narrower promises. Perplexity’s Incognito said sessions “won’t save to your history and expire after 24 hours”. Claude’s Incognito chat said conversations “aren’t saved, added to memory, or used to train models”. ChatGPT’s Temporary Chat said it “won’t appear in your chat history, and won’t be used to train our models”. Those promises cover history, memory, training or expiry. None says a signed-in service must act as if it does not know you.
So Perplexity greeting me by name did not contradict the banner I captured. The test did not audit back-end retention; it showed that a mode framed around history and expiry could still produce an answer shaped by identity and location signals. “Incognito” carries a spy-film weight, a hat and a turned-up collar. “This won’t sit in your history” carries none of that. The gap between those two is where I caught myself out.
These modes change what happens to the conversation. They never promise you're a stranger while you're having it. "Incognito" is the word that fills in the difference, and it fills it in wrong.
Claude is the one tool whose own framing sits in mild tension with its behaviour. It opens with “whoever you are”, and then names a city anyway.
The two signals that survive private mode
The name was exact and matched the first name on the logged-in account. That makes the account an obvious route, but this test did not isolate whether the value came from the account name, an AI profile or another account-linked field. What it proves is simpler: Incognito did not log me out, and the answer still used the right name.
The location is approximate, and I can’t tell you for certain where it comes from. The city Perplexity named sits about 30 miles from where I actually live, the same rough guess a weather site makes when it shows you a forecast for a town you’ve never lived in. A location that landed on my actual town would point at something stored in the account; one that lands 30 miles out looks more like it’s worked out from my internet connection than from anything I typed. But I didn’t run the control that would settle it, a logged-out or VPN’d repeat, so I’m not going to claim I’ve ruled the account out.
Neither signal was switched off by the word “incognito” in these runs. Logging out should remove the account-name route, but I did not test it. A rough location may remain if the service is using the connection rather than the profile.
The honest limits
I ran this signed in, which is how most people use these modes and where the surprise lives. A logged-out test is a different experiment, and I didn’t run it.
The sample is fourteen runs on one question. Enough to show the behaviour exists, a long way short of a study: how often it turns up across other questions and other accounts is a question I haven’t answered. Nor is it apples to apples. Perplexity and Claude ran on my own heavily-used accounts, while ChatGPT was on a separate free-tier account that didn’t match them, so its clean sheet may owe as much to the mismatch as to better isolation. I’d want a much bigger sample, on matched accounts, before saying anything stronger than “this is what happened in these recorded runs”, which is the bar the Scoreboard is held to as well.
And a private chat is not an anonymous one. That’s the sentence I’d tape to the monitor. If what you want is to stay out of your own history, that is the promise these interfaces make, and it is genuinely useful. If what you want is to not be known, that’s a different job: log out where the product allows it, and remember that the connection may still supply a rough location.
If you want the companion to this, does AI cave when you push back covers the other way a confident answer can quietly be one you shouldn’t trust: how easily it abandons what it just told you the moment you disagree.
The short version
What worked: ChatGPT’s Temporary Chat did the right thing, zero of three runs assumed a location, it asked for my country and city. One honest asterisk: it also ran no web search in any run, so its clean sheet may be the free tier not searching, and better isolation is unproven. Claude’s Incognito was mostly clean too, most of eight runs gave nothing away, and its “whoever you are” greeting sets the honest expectation.
What didn’t: Perplexity’s Incognito placed me by the nearest big city, about 30 miles off, in all three runs, and greeted me by my real first name in two of them, under a heading that read like it had my file open. It contradicted no promise in the captured banner, which covered history and expiry rather than anonymity. Claude named that same city twice across eight runs in two separate sittings the same day, mildly at odds with its own “whoever you are” framing.
Bottom line: Conditional, and the fix is understanding what the mode does. No setting will do it for you. “Private” modes change history, memory, training or retention; they do not necessarily make the session anonymous. In these runs, a first name matching the logged-in account and an approximate location survived some of them. The exact routes remain unconfirmed. Log out where you can, but do not assume that removes a network-level location signal. What would change my view: a control run logged out or over a VPN to pin down where the location comes from, and a private mode that either logs you out by default or shows a small note when it has used your account or your location, so the knowing is at least visible.
So now I read the top of a “private” answer the way I read the top of a form: for the details I never filled in. The history control is real and useful. The disguise was never in the box. If you want the answer to know less about you, log out where you can, and remember that the connection may still hand it a rough idea of where you’re sitting.

Ben tests how far you can trust the main AI assistants, and publishes exactly where they get things wrong. Every post here is a first-hand test with the receipts, including the times a tool simply wasn’t worth the trust. About Ben →
The site tests how far you can trust the main AI assistants, on real decisions. Start with the Prompt Stack for the four-stage framework, free and ungated, or the Bluff Filter for the paste-ready version with a real before and after.