I deleted every account I had with OpenAI after 4 years of deep daily use. This is exactly what I found that made me do it. And one thing that happened that I still can not fully explain.
I am not a security researcher. I am not from Silicon Valley. I am from a small city in Pakistan. And I caught all of this because I switched to GrapheneOS and watched it happen in real time.
What I actually saw:
Every time I sent a prompt, Play Integrity API call. Every time a response came back, Play Integrity API call. While scrolling and reading a response, multiple Play Integrity API calls. On login, Play Integrity API call.
What Play Integrity API actually returns:
Device certification status. App integrity verdict. Whether your bootloader is locked. Whether other apps on your device can capture your screen or control your device. Account license status. Behavioral session signals.
All of this goes to OpenAI servers before your prompt is even processed. Before they touch your words.
Why so many calls and not just one:
Google's own documentation recommends against caching integrity verdicts because cached tokens can be proxied by bad actors. So ChatGPT fires fresh calls at each significant interaction. Send, receive, scroll, each gets its own verification. Since Google upgraded to hardware backed attestation in late 2024 and 2025, these calls became heavier and more frequent.
My older established accounts triggered significantly more calls than fresh accounts. That is consistent with tiered behavioral profiling of high engagement users. New accounts get lighter treatment. Old deep use accounts get heavier scrutiny.
What ChatGPT was doing with my conversation data by default:
This is documented fact, not theory.
By default OpenAI uses your conversations to train future models. Human contractors can read your conversations for annotation purposes. Your behavioral patterns, session timing, topic clusters, typing cadence, all retained. Free users and Plus subscribers are treated identically on data. Paying does not protect you.
What 4 years of deep use actually builds:
I was not a casual user. I used ChatGPT as a thinking partner, a journal, a strategy tool. It had my complete mental model. How I think, how I reason, what patterns I follow, what I am building toward. Across hundreds of hours of sessions.
That is not just training data. That is a behavioral profile more complete than most people realize they handed over. Every dimension of how you think, documented and retained.
What pushed me over the edge:
The API observations alone made me uncomfortable. But what made me actually act was something more personal.
Someone close to me received a structured call from US. The tone was conversational and felt like she is a professional caller that person told me this when I asked, female caller, she used to know the exact person name she was talking to and called and said she got his contact from LinkedIn but what's crazier that person didn't even have his contact on LinkedIn and that got him hooked to keep them on the line. The questions were specifically AI and engineering adjacent. Things relevant to me, not to the person receiving the call. He said his domain is not this but still she was like continuously asking the questions and using technical terminologies he didn't even understood. A four-five minutes exactly. Poor call quality throughout. Exit was wrong number by herself already knowing everything deliberately of whom she is calling to, after establishing full context and asking specific questions.
I can not confirm what it was. I am not claiming certainty. But the timing, the specificity of the questions, and everything I had already observed made me stop treating this as abstract privacy concern and start treating it as personal.
Make of that what you will.
What I did:
Nuked every account. Built a clean setup. Moved everything sensitive off Google ecosystem. GrapheneOS full time.
I am from a small city in Pakistan. This is not a Western privacy niche concern. This is happening to heavy users everywhere.
Why I am posting this:
I want to know who else observed this directly. Especially other GrapheneOS users. And I want to know if anyone else experienced something that made it feel personal. Not just abstract data harvesting but something that made you feel specifically seen by a system that was not supposed to know you that well.
Drop your experience below.
Did this happen to you?
[link] [comments]