Meta AI Has Three Privacy Routes. They Do Not Do the Same Job

Last updated: August 9, 2026

Tier B · Hands-on, single account

FSR registered one new individual Meta account and used meta.ai in a browser from Japan on 8 August 2026, in Japanese locale, with no social account linked. Meta’s developer and privacy pages were opened and captured the same day. Incognito Chat was not tested. The mobile apps, other regions, other locales, and business accounts were not tested.

Meta AI and Meta Model API do not expose the same privacy controls, and the consumer product itself is not one thing. Meta Model API lists two Muse Spark 1.2 model IDs at different prices with different stated data treatment. Meta separately markets Incognito Chat, a consumer mode it describes as unreadable by Meta and not saved. FSR audited the third route, ordinary chat on the web, and reports what one account exposed.

Verdict in one line: The three routes control different things, so pick the route by what has to be controlled and recorded, not by which product is closest to hand.

Best for

  • Security and procurement reviewers writing an employee AI policy that has to name a permitted route
  • Developers deciding between the standard and contributor model IDs
  • Teams that must record which model produced a given output
  • Anyone who has read that Meta AI cannot be opted out of and wants the control map behind that claim

Not for

  • Output quality comparison. FSR did not score writing, reasoning, or coding
  • Anyone needing a legal conclusion. This is an evidence audit, not advice
  • Readers wanting an Incognito review. FSR did not test that mode
  • Mobile app users and readers outside Japan. Every screen finding is from one web account in one locale

Three routes, side by side

DimensionOrdinary chat (tested)Incognito Chat (not tested)Meta Model API (docs read)
Surfacemeta.ai in a browserWhatsApp and the Meta AI app, per press reportsDeveloper API
User selects the modelNot present in the tested interfaceNot establishedModel ID is a request parameter
Model identifier visibleNot present in the tested interfaceNot establishedTwo named IDs are published
Stated data-use treatmentMeta says AI interactions can be used to train AI modelsMeta says the conversation is not readable by Meta and is not savedStated per model ID in the price table
PersistenceConversations persisted in the tested accountPress reports describe messages disappearing when the chat closesBuyer holds the request and response
What a buyer could auditHistory and export exist. Model provenance was not visibleEphemeral by design, so no record to auditWhatever the buyer chooses to log

Column 1 is FSR observation from one account on 8 August 2026. Column 2 is drawn from Meta’s May 2026 announcement as reported by the technology press and was not tested by FSR. Column 3 is drawn from Meta’s published developer pages.

Two model IDs, two data terms

Meta’s Muse Spark 1.2 model page publishes a pricing table with two rows at the same listed one-million-token context length. Each row carries a sentence describing what Meta does with the traffic. The contributor row reads “Used to improve our products.” The standard row carries the negated form of the same sentence.

Meta Model API, Muse Spark 1.2, per million tokens

Model IDInputCached inputOutput
muse-spark-1.2
Labeled: not used to improve Meta’s products
$1.25$0.15$4.25
muse-spark-1.2-contributor
Labeled: used to improve Meta’s products
$0.10$0.002$0.20

Table as published by Meta and read by FSR on 8 August 2026. Both rows list a one-million-token context window.

The standard ID costs 12.5 times more for input, 75 times more for cached input, and 21.25 times more for output. Those ratios are FSR arithmetic on Meta’s figures. Meta does not publish ratios.

Call this a priced data-use option rather than priced consent. Consent is a legal conclusion and this table does not supply one. What the table establishes is narrower and still useful: Meta attaches different commercial terms and a different stated data treatment to two model IDs, and a developer selects between them by writing one string into the request.

The table also does not establish retention periods, subprocessor access, deletion rights, or whether the two IDs run an otherwise identical deployment. A buyer comparing the contributor price against a competitor that commits to no training is not comparing like with like.

On availability, the timeline matters. Meta’s July launch described the Model API as a public preview for developers in the United States. Meta’s research blog announcing Muse Spark 1.2 states it is available through Meta Model API with expanded global access. The defensible position is therefore neither “US only” nor “available everywhere.” Broader access was announced, and country-level eligibility still needs confirmation at the time of purchase.

Sources: Meta, accessed 8 August 2026 · Meta, 8 July 2026 · Meta AI Research, August 2026

What the tested settings exposed

FSR opened all six sections of the meta.ai settings panel and the full account menu behind them, on a logged-in account created the same day, before sending any message.

General held a link to Accounts Center, a language selector, and a theme selector. Apps listed seven connectable services, all unlinked. Data and privacy held three entries: manage your information, recommend your prompts in other apps, and an item named AI data training that opened an explanatory page rather than a setting. Terms and safety notices and Help and support held outbound links and a report form. About AI from Meta held one outbound link and two lines of disclaimer.

Under manage your information, the destructive actions offered were deleting public posts and deleting all chats and media.

The finding is therefore specific rather than sweeping. In these locations, on this account, Meta offered record management. FSR did not find a persistent setting that declines future use of new ordinary-chat interactions for model improvement, and did not find a model name or version anywhere in the interface, including the mode selector, the artifacts view, and the AI identification page.

Meta AI mode selector on meta.ai, expanded to show Quick mode
and Thinking mode. Neither option names a model or version.
The mode selector on the tested account offered two options,
described by response speed and answer quality. Neither names
a model or a version. The list at left is FSR’s own test session.

Two limits sit on that. Other surfaces exist and were not searched. And one observed state should not be read as a global default: under recommend your prompts in other apps, Facebook and Instagram were both enabled on an account that had never been used, and FSR did not change the setting, but a single account does not establish what every account receives.

Meta’s Privacy Center supports the general direction. It states that interactions with AI features can be used to train AI models, giving messages, questions, and requested images as examples. A separate page in the same dialog set, covering a user’s public content, offers audience management and past-activity management. Those are controls over a different object.

Sources: FSR direct observation, meta.ai settings and account menu, 8 August 2026 · Meta Privacy Center, accessed 8 August 2026 · Meta Privacy Center, accessed 8 August 2026

Incognito Chat is the counterevidence

A reader who stops at the previous section would conclude that Meta gives consumers no privacy-oriented route. That conclusion is wrong, and this section exists to prevent it.

In May 2026 Meta announced Incognito Chat for WhatsApp and the Meta AI app. As reported by the technology press at announcement, the mode runs on the Private Processing architecture, Meta says it cannot read the conversation, the conversation is not saved, messages disappear when the chat closes, and the session ends when the app is closed or the phone is locked. Rollout was described as gradual over the following months, and the mode was described as text only at launch.

FSR did not test Incognito. It was not part of the audit design, which was set before this counterevidence was identified. That is a gap in this briefing and it is named here rather than buried.

What the existence of Incognito changes, and what it does not:

It changes the question. Meta does offer consumers a privacy-oriented mode, so the useful question is not whether one exists but which object each control governs.

It does not close the provenance gap. A mode that keeps no record cannot supply an audit trail. Confidentiality by ephemerality and auditability are opposite properties, and an organization that must show what an assistant was asked and which model answered gains nothing from a session that disappears.

It does not resolve surface coverage. Press coverage of the announcement describes WhatsApp and the Meta AI app. FSR tested meta.ai in a browser, and whether the mode reaches that surface, that account type, and that region is unestablished here.

It does not carry independent verification. Meta’s privacy properties for this mode are Meta’s claims about its own architecture. FSR has not evaluated them and does not repeat them as verified.

Sources: TechCrunch, 13 May 2026 · gHacks, 17 May 2026. FSR has not opened Meta’s own announcement page for this feature and has not tested the mode.

Five things “delete” can mean

Most confusion in this area comes from one word covering five different operations. They are not interchangeable, and a control that performs one does not perform the others.

1Removing a conversation from your own visible history
2Resetting the details the assistant has saved about you
3Deleting the provider’s copy of the conversation
4Declining future use of new interactions for model improvement
5Removing already-learned information from a trained model

Meta addresses the fifth directly. Its explanation of how generative AI models work states that deleted information is not used in subsequent training, and that deleting information a model has already learned does not change the model at that moment. Exclusion from future training and removal from an existing model are different outcomes, and Meta says so.

The consumer controls FSR found act on one and two. Whether any control in the tested interface performs three or four was not established.

This taxonomy also corrects a test FSR ran and reports here rather than quietly dropping. FSR sent a reset command that the assistant had described as a way to delete recent messages. The command returned a reply, the visible conversation list retained its entries, and one new conversation was added. Because the expected target of the command was not defined against Meta’s documented semantics before the test, that observation cannot support a conclusion that the reset failed. Sidebar history is operation one. The command may have acted on operation two or three, neither of which is visible from the sidebar. The correct status is unresolved, and a valid retest would need a post-reset behavior check or a downloadable data comparison rather than a glance at the list.

Sources: Meta Privacy Center, accessed 8 August 2026 · FSR direct testing, 8 August 2026

Following the assistant’s instructions

When asked how to stop training use, the assistant produced URLs, settings paths, a chat command, and a named legal document. FSR followed all of it. Those items are not comparable to each other, so this section reports them by failure type rather than as a success rate.

TypeItemWhat it does and does not show
ReachedPrivacy Center pages and the privacy policyReachable from the test environment. Content still needs reading by the user
ReachedSettings path to delete all chats and mediaPath exists as described on the tested surface
Wrong scopeA regional terms document cited as the basis for a Japan-resident answerThe page opened. Its own header block describes coverage for other regions. Applicability is contested and FSR preserves it as an open conflict rather than resolving it
Unreachable hostA request portal hostnameDid not resolve in the FSR test environment. FSR did not test other networks or resolvers
Unavailable pageA help center article ID and a legal page pathReturned unavailable on the day. Does not establish that either was ever wrong
Missing UI pathA settings route with an intermediate step that does not exist on the web panelAbsent on the tested surface. May exist in the mobile apps
Not locatedAn objection form described as sitting at the foot of a Privacy Center pageNot found in the Japanese logged-in view or the US English view of that page
UnresolvedThe reset commandEffect on the provider-side copy was not observable. See section 04

All attempts made by FSR on 8 August 2026 from Japan on the web version, except one page also checked in US English.

The buyer consequence is not a percentage. It is that self-help guidance from the assistant can point to the wrong surface, the wrong region, or a control whose semantics differ from what the answer implies. A privacy reviewer who treats those answers as a checklist will spend time confirming items that do not confirm.

Meta discloses its data processing in policy documents. The audit question here is different: whether the relevant control is reachable at the point of use by the path the product itself supplies.

Sources: FSR direct testing, 8 August 2026 · Meta, effective 13 May 2026 · Meta, effective 13 May 2026

What the assistant says about itself

Asked which model was responding, the assistant named Muse Spark 1.1 in both quick mode and thinking mode, and said users cannot select a version. Meta had said in July that Muse Spark 1.1 was available in Thinking mode in the Meta AI app and on meta.ai. That is a dated vendor statement, not a description of what served any particular request on 8 August.

Three propositions need to stay separate, because collapsing them is the most common error in this area:

The tested interface did not display a model identifier. That is an FSR observation.

The assistant named a model when asked. That is an observed self-report and evidence about disclosure design.

Which model actually served the request was not verified. Asked directly whether external verification was possible, the assistant said no mechanism for it exists on the consumer interface and pointed to the developer API, where the model identifier is part of the exchange. FSR records that answer as a self-report as well.

A related mismatch appeared in the same test set. The assistant returned approximate city-level location context that matched the test location and described it as coming from the Meta AI app. The session was a desktop browser. One reply advised turning off location permission in the app or on the device, which is not an action available in that session. Meta’s privacy policy lists location-related information and IP address among the categories it processes, so the processing itself is disclosed. The gap is between the disclosure and the explanation given at the point of use.

FSR did not inspect network traffic and makes no claim about how the location reached the session.

Sources: FSR direct testing, meta.ai, 8 August 2026 · Meta, 9 July 2026 · Meta, 23 July 2026

Choosing a route

The routes are not tiers of one product. Moving from ordinary chat to the API is not an upgrade, it is a different product with a different data path, a different contract surface, and a different set of things a buyer can record.

Personal prompts with nothing sensitive in them. Ordinary chat is a consumer convenience and the standard data path described in Meta’s privacy materials applies. Nothing in this audit argues against that use.

A private personal conversation. Incognito Chat is Meta’s stated answer. Confirm it is actually available on your account and surface before relying on the claim, and treat Meta’s privacy properties as Meta’s claims until independently examined.

Client data, source code, or regulated material. The consumer interface is the wrong baseline. Neither ordinary chat nor an ephemeral mode gives an organization a model identifier it can record.

Work that must be reproducible or auditable. The API is the route that supplies a named model ID and a stated data condition per ID. Logging remains the buyer’s responsibility. The API supplies the identifier; it does not supply the audit process.

Choosing between the two API IDs. The standard ID is the default comparison point for anything that cannot accept product-improvement use. The contributor ID is a deliberate decision about data whose use under that stated condition has been approved, not a discount.

Two checks belong in any evaluation. Confirm country eligibility for the API at the time of purchase, since expanded access was announced without a published country list. And confirm which terms document governs the buyer, since Meta publishes separate AI terms for some regions and the applicable document affects what rights are available.

Sources: Meta, accessed 8 August 2026 · Meta AI Research, August 2026 · FSR direct testing, 8 August 2026

FAQ

Does Meta AI use ordinary chats to improve models?

Meta’s Privacy Center states that interactions with AI features can be used to train AI models, and gives chat messages, questions, and requested images as examples. FSR read the Japanese localization of that page on 8 August 2026.

Does Meta AI have a private mode?

Yes. Meta announced Incognito Chat in May 2026 for WhatsApp and the Meta AI app, describing it as unreadable by Meta and not saved. FSR did not test it and cannot confirm availability on any particular account, surface, or region.

Can I opt out of training in ordinary Meta AI settings?

FSR did not find such a setting in the six settings sections and account menu it opened on one Japan-based web account. Record management was offered instead. Other surfaces and regions were not searched, so this is not a claim about the product overall.

Does deleting a chat stop future training use?

Those are different operations. Meta states that deleted information is not used in subsequent training, and separately that deleting information a model already learned does not change the model at that moment. Removing a record and declining future use are not the same control.

Can I verify which model answered?

Not from the interface FSR tested, which displayed no model identifier. The assistant named a model when asked, but a self-report is not verification. On the API route, the model ID is part of the exchange and a buyer can record it.

What is the difference between the standard and contributor model IDs?

Price and stated data treatment. Meta labels the contributor ID as used to improve its products and the standard ID as not used. The standard ID costs 12.5 times more for input and 21.25 times more for output, by FSR arithmetic on Meta’s published figures.

Is the Model API available outside the United States?

Meta’s July launch described a US public preview. Its August announcement for Muse Spark 1.2 describes expanded global access. No country list accompanied that wording in the material FSR reviewed, so eligibility should be confirmed at the time of purchase.

Do the same terms apply everywhere?

No. Meta publishes separate AI terms for some regions. FSR encountered conflicting indications about which document governs which reader and preserves that as an open question rather than resolving it. Confirm the governing document before relying on any right described in it.

Methodology and limits

FSR registered one new individual Meta account with an email address, a password, and a date of birth, with no social account linked. Before sending any message, FSR captured the default state of the settings panel and account menu so that observed values would not be the result of FSR’s own changes. No setting was altered.

Testing ran on 8 August 2026 between roughly 09:00 and 22:30 Japan Standard Time, on macOS, in Chrome, at meta.ai, in Japanese locale, from Japan. One later check used a private browser window. Each test prompt was sent from a fresh chat, with identical wording across the two modes. Meta’s developer, legal, and Privacy Center pages were opened in the browser and captured.

Every direct observation in this briefing corresponds to a timestamped screen capture held by FSR, recorded with the surface, locale, account type, and time. Captures containing account identifiers are redacted before release and are available to vendors and researchers on request.

Two items in this briefing did not come from FSR’s own reading. The Incognito Chat description and the expanded global access statement were identified during a source check on 9 August 2026 after an external review flagged both as missing. FSR has not opened Meta’s own Incognito announcement and has not tested the mode. Both are marked in the text as vendor or press descriptions and neither is presented as an FSR observation.

What one account cannot establish. No mobile app test. No other country, locale, or account type, except one page checked in US English. No business or managed account. No network inspection. No independent verification of any Meta privacy claim. Low repetition counts, with most prompts run once per mode.

What is deliberately not claimed. That any control is absent from the product overall, rather than from the surfaces FSR opened. That any destination was never valid, rather than unavailable on the day. That the reset command failed, since its intended target was not defined before the test. That the two model IDs run the same or different deployments. That any region’s terms apply or do not apply to any reader. Any legal conclusion in any jurisdiction.

Statements the assistant made about itself are recorded as disclosure behavior and not as facts about the system. That applies to the model name, the description of where location context originated, and the claim that no external verification mechanism exists.

Freshness. Pricing, availability, feature rollout, and policy pages change. Every figure and page state carries an access date. This briefing should be rechecked when Incognito availability changes, when the Model API data-use wording or model IDs change, when applicable terms change, when ordinary-chat settings gain a control, or when Meta publishes country-level eligibility.

This briefing contains no affiliate links and no commercial relationship with Meta. FSR is not a law firm and nothing here is legal advice.

Sources: Meta, accessed 8 August 2026 · Meta, 8 July 2026 · Meta, 9 July 2026 · Meta AI Research, August 2026 · Meta Privacy Center, accessed 8 August 2026 · Meta Privacy Center, accessed 8 August 2026 · Meta Privacy Center, accessed 8 August 2026 · Meta Privacy Center, accessed 8 August 2026 · Meta, 23 July 2026 · Meta, effective 13 May 2026 · Meta, effective 13 May 2026 · Meta, accessed 8 August 2026 · TechCrunch, 13 May 2026

Verdict

Meta has not left consumers without a privacy route, and any article claiming otherwise is out of date. What Meta has done is build three routes that control three different objects.

Ordinary chat gives a user control over records. Delete a conversation, download the history, reset what the assistant has saved. In the settings FSR opened on one account, it did not give a control over whether the next conversation feeds model improvement.

Incognito Chat, as Meta describes it, gives confidentiality by not producing a record at all. For a person asking a health or financial question, that is the right shape. For an organization that has to demonstrate what was asked and what answered, a mode that leaves nothing behind is not a governance control.

The Model API gives provenance. Two named model IDs, a stated data treatment beside each, and an identifier the buyer can record. It is the only one of the three routes where the buyer holds the evidence afterward.

The practical failure mode is not that any single route is bad. It is that these three get discussed as one product called Meta AI. An employee opens the assistant in a browser while a security team assumes API terms apply, or a privacy reviewer sees the Incognito announcement and assumes it covers every surface. Both assumptions are cheap to make and expensive to hold.

Before permitting any of it for work, name the route and confirm it on the account and surface that will actually be used. This audit covered one of the three, on one account, on one day, and the two it did not cover are stated as open.

Related FSR briefings

Tier B briefings include hands-on testing on a registered or purchased account. Tier C briefings are document-first and disclose no hands-on use.

Contact

Corrections, vendor responses, and procurement questions

This briefing was rebuilt after an outside review found counterevidence the first draft had missed. We would rather hear that from you than publish past it. Every finding above carries a date, a locale, and a scope, so a different result is a useful result.

Reproduced something different

Send the surface, locale, account type, and date. Pages FSR could not reach may be reachable from where you are.

Writing an internal AI policy

Ask what FSR did and did not test before citing this briefing in a review. Scope questions get a direct answer.

Email FSR More FSR briefings

Vendor responses are published alongside the original claim, not in place of it.

Future Stack Reviews publishes structural audits of AI and SaaS products for technical buyers. Hands-on findings in this briefing come from one individual account on the meta.ai web version, in Japanese locale, from Japan, on 8 August 2026, and describe no other date, region, locale, surface, or account type. Incognito Chat was not tested. Pricing, availability, and policy pages change without notice. FSR is not a law firm and nothing here is legal advice. No affiliate relationship or commercial arrangement exists with Meta in connection with this briefing. Last updated 9 August 2026.