Delete Is a Promise: A Security Researcher’s Look at AI Conversation Privacy A security researcher found that ChatGPT's Open Graph preview images at ogimg.chatgpt.com/conversation//response_multicolor_v1.png continued serving excerpts of deleted conversations without authentication, with one image still returning conversation-derived content more than 48 hours after deletion on September 5 despite response headers advertising max-age=86400 and stale-while-revalidate=3600. The researcher reported the issue to OpenAI through Bugcrowd, where it was marked a duplicate of a report filed six days earlier and rated P4; after an apparent fix, a retest on September 30 with a new conversation showed its preview image still returning conversation-derived content about 26 hours after deletion, and the report was moved back to Unresolved on October 4 before being marked Resolved on October 6. When you share a ChatGPT conversation, the share page gets an Open Graph preview image served from a separate hostname. I found that deleting the conversation correctly invalidated the share page, but the preview image kept being served without authentication, with an excerpt of the deleted conversation still in it. I reported it to OpenAI through Bugcrowd. It was a duplicate of a report filed six days before mine, and the submission has since been marked resolved. Every test described here used my own account and my own conversations. I have left the real conversation IDs out of this post. Creating a share link gives you a page at https://chatgpt.com/share/