Your AI assistant remembers things about you. Not in the conversation you are having — in a store that persists across every conversation you will ever have with it. ChatGPT calls it memory. Claude has project instructions and memory. Copilot has a memory store. Gemini has saved info. Every one of them is a small, invisible database of assertions about who you are and how you want to be treated, and almost nobody reads it.
That is a problem for three separate reasons, and only one of them is security.
The first is drift. You told it in March that you were writing a book proposal. It is October. The proposal shipped, the book died, and the assistant is still quietly steering every piece of writing you ask for toward a voice you no longer want.
The second is contamination. Memory entries get written from things you did, not just things you said. Summarise a web page, and some assistants will write what they inferred. A crafted page can, in documented cases, cause an assistant to persist an instruction the user never gave. Those entries survive password changes, session revocation and new devices, because they are not session state — they are your profile.
The third is leverage. A wrong memory does not fail loudly. It biases a thousand small outputs in a direction you cannot see, which is the most expensive kind of error there is.
The rule: anything that persists across sessions is configuration, not conversation. You review configuration on a schedule. You do not let it accumulate for two years and then wonder why the outputs feel off.
Step 1: Find every memory store you own (20 minutes, once)
You cannot audit what you cannot list. Open every AI tool you use and write down where its persistent state lives. The stores are usually in four places:
- Explicit memory. The settings page literally labelled memory, saved info, or personalisation. Read every entry.
- Custom instructions / system prompts. The “what should the assistant know about you” box. This is memory you wrote deliberately and then forgot about.
- Project and workspace context. Files, notes and instructions attached to a project or a custom GPT. These outlive the project by default.
- Connected app grants. Not memory exactly, but the same category of thing: standing permission you granted once and never revisited.
Write the list down in one place. A note, a doc, a page in whatever you use. You will re-read it quarterly and you will not remember it otherwise.
Step 2: Sort every entry into four buckets
Go entry by entry. Each one lands in exactly one bucket:
- Keep. Still true, still useful, still how you want to be treated. “Prefers metric units.” “Writes in British English.” Stable facts with a long shelf life.
- Expire. Was true, no longer is. A finished project, an old job title, a client you no longer have, a diet you stopped. Delete these without sentiment.
- Rewrite. Directionally right, badly worded. “User is working on a pitch deck” becomes “User builds pitch decks regularly; default to 12 slides, no bullet-point walls.” Specific beats vague every time.
- Unrecognised. You do not remember creating it and cannot explain how it got there. Delete it immediately, then check what you were doing around the time it was created.
That fourth bucket is the one that matters. Most people find one or two entries they cannot account for. Usually the explanation is boring — you said something offhand and the assistant generalised. Occasionally it is not.
Step 3: Write memory that actually holds up
Good memory entries share three properties: they are durable, specific, and falsifiable. Bad ones are vague, temporary, or aspirational.
Some worked examples:
- Bad: “User likes concise writing.” Good: “Default to under 400 words unless asked otherwise. No preamble, no summary of the question.”
- Bad: “User is a founder.” Good: “Runs a 6-person B2B services firm. Assume no engineering team and no budget for enterprise tooling.”
- Bad: “User is learning Spanish.” Good: “B1 Spanish. Correct errors inline without switching to English.”
- Bad: “User is training for a marathon in April.” Good: delete it in May. Dated goals do not belong in permanent memory at all.
Anything with a date attached should live in a project, not in memory. That single distinction eliminates most drift.
Step 4: The connector cut-back
Memory tells the assistant who you are. Connectors tell it what it can reach. The same audit logic applies, with a harder default: disconnect anything you have not used in 30 days. Reconnecting takes twenty seconds. Leaving a mail or drive grant standing for a year does not.
For each connector still on the list, ask one question: if a prompt I did not write ran inside this session, what could it reach? If the answer is your entire inbox, that connector needs to justify itself. Most do not.
Step 5: Put it on a schedule
Audits you do once are theatre. The cadence that works:
- Monthly, 5 minutes. Open the memory list. Skim for anything unrecognised. Delete expired entries. That is it.
- Quarterly, 20 minutes. Full four-bucket sort. Rewrite the vague ones. Run the connector cut-back.
- On trigger, immediately. After a password reset, after any security notice from an AI vendor, after you notice outputs behaving oddly, or after you use an assistant on a shared or borrowed device.
Put the monthly one in your calendar as a recurring five-minute block. It is genuinely five minutes after the first pass.
The diagnostic: three questions
If you want to know whether your memory store has gone bad without reading it line by line, ask the assistant directly:
- “List everything you currently remember about me, verbatim, with no commentary.”
- “Which of those would you consider outdated or low-confidence?”
- “Which of them are shaping how you answer me most often?”
The third answer is the useful one. It tells you which entries are doing the most work — and therefore which ones are most expensive to have wrong. Verify what comes back against the settings page rather than trusting the recital; the point is to find the gap between what it says it remembers and what is actually stored.
Five ways people get this wrong
- Treating memory as a feature to maximise. More memory is not better memory. A small store of durable, specific facts outperforms a large store of half-true ones.
- Auditing one tool. You probably use three or four assistants. The one you audit is rarely the one holding the stale profile.
- Confusing chat history with memory. Deleting conversations does not delete memory. They are separate stores with separate delete buttons.
- Assuming enterprise coverage protects the personal account. Work accounts often have audit logging and write-time checks that consumer tiers do not. The consumer account is where the unwatched state lives.
- Never testing. After a cleanup, run a task you do regularly and see whether the output changed. If nothing changed, your memory was not doing much — which is also worth knowing.
The 30-minute install
Block half an hour this week. Ten minutes to list every store. Fifteen to do the first four-bucket sort on your most-used assistant. Five to cut connectors you do not need. Then put a five-minute monthly review on the calendar and stop thinking about it.
The whole discipline rests on one idea: your assistants are carrying a version of you that you have never proofread. Proofread it.
