Privacy-Focused ChatGPT Design Recommendations

Developing privacy-centered design improvements for AI chat interfaces

Project Focus

User research, UX design, wireframing

Design Team

3 person design team, independently directed capstone project

Tools

Figma, qualitative research methods

Timeline

2 months

ChatGPT interface and privacy-related UI

Overview

Project Goal

This capstone project focused on developing comprehensive design recommendations to enhance privacy protections and user control within ChatGPT and similar AI chat interfaces. Through user research and design analysis, our team identified key areas for improvement in privacy-conscious AI interactions.

Academic Context

Completed as an independently directed capstone project for a course on privacy and accessibility, examining the intersection of AI technology and user privacy rights.

Project Focus

User research, UX design, wireframing

Design Team

3 person design team, independently directed capstone project

Tools

Figma, qualitative research methods

Timeline

2 months

Problem

How can we enhance privacy protections and user control in AI chat interfaces while maintaining usability and functionality?

Solution

Through comprehensive research and design analysis, we developed targeted recommendations for improving privacy-conscious design patterns in ChatGPT and similar AI interfaces.

Research Foundation

Motivations

  • Conversational AI chatbots becoming more integrated into daily life
  • These tools collect and store user data, often without user being aware, which leads to privacy concerns

Questions

  • For what purposes do college students engage with conversational AI chatbots, and what can they do to safeguard their privacy while interacting with these systems?
  • How can the design of conversational AI chatbots make users more aware of how their data is being used and stored?

Approach

Our research methodology combined multiple approaches to comprehensively understand privacy concerns and develop actionable design solutions.

Literature Review

Research, privacy policy analysis, and conversational AI landscape exploration

Survey Research

Quantitative data collection from 60 college students across 14 universities

User Interviews

In-depth qualitative insights from 6 participants with hands-on privacy feature testing

Design Solutions

Privacy-focused UI recommendations and interactive prototyping


Literature Review

We conducted comprehensive research to understand the current landscape of conversational AI and privacy concerns, establishing a foundation for our design recommendations.


Defining Conversational AI Chatbots

Conversational AI chatbots are virtual agents that use "large volumes of data, machine learning, and natural language processing to help imitate human interactions." Examples include ChatGPT, Claude, Copilot, and Perplexity. Released at the end of 2022, ChatGPT immediately attracted attention for its ability to respond in-depth to natural language prompts, acquiring over 100 million users within two months.

Training involves pre-training (where the model learns grammar and general knowledge from large public datasets) and fine-tuning (where the model is refined using smaller, specialized datasets to improve specific behaviors). ChatGPT excels in text generation, often surpassing human performance in summarizing content, answering questions, and providing feedback. However, users must be cautious as it can make factual errors or hallucinate.

Privacy Consideration

Users must be aware of privacy implications and data sharing policies, as OpenAI collects, stores, and trains ChatGPT with an immense amount of user data.

Privacy Concerns of Chatbots

Conversational AI chatbots pose numerous privacy risks as they leverage user input data for contextually relevant interactions. These concerns stem from data collection and usage practices, lack of consent and transparency, and limited technical knowledge among users.

Privacy Policy Review of ChatGPT

We analyzed OpenAI's privacy policy to understand current transparency practices and identify areas for improvement.

Policy Structure and Accessibility

Privacy policies inform users about personal information collection, usage, protection, and user choices. In the United States, companies have discretion over disclosure levels due to the absence of nationwide privacy laws.

The ChatGPT privacy policy contains ten sections covering data collection, usage, and sharing practices.

Grammarly's Flesch reading-ease test scored OpenAI's privacy policy as 37, indicating it requires at least some college education to understand and may not be easy to read.

Main Privacy Concerns Identified

  • Amount of data collected
  • Data retention practices
  • How data is used
Readability score analysis of OpenAI's privacy policy showing Flesch Reading-Ease Test results

Privacy policy readability analysis from Grammarly


Survey

To understand student perceptions and usage patterns of AI chatbots, we conducted a comprehensive survey across multiple universities.


Participants and Methodology

60

Undergraduate students

14

Universities across the US

45

From Brown & RISD

The survey was designed to collect quantitative and qualitative data on undergraduate university students' usage and perceptions of generative conversational AI chatbots. It was developed by the research team in two rounds of drafting and discussion, with feedback provided by Dr. Diana Freed.

Survey Structure

The survey collected demographic information (university, major, graduation year, gender, and age) and included a mix of multiple-choice, multi-select, and short-answer questions focused on understanding perceptions of AI, usage patterns, and privacy considerations. Results were anonymous unless respondents volunteered for follow-up interviews by providing their email address.

Distribution and Outreach

Researchers used purposeful sampling to focus on undergraduate students across the United States, distributing the survey through individual outreach, EdStem classrooms for academic course communities, and Slack communities to reach diverse student groups.


User Interviews

Following the survey, we conducted in-depth interviews to gain deeper insights into student behaviors and privacy awareness when using AI chatbots.


Research Process

Participant Selection

Of the 14 respondents who expressed willingness to interview in the survey, we reached out to 6 participants representing diverse experiences, usage patterns, and opinions on AI chatbots.

Interview Participants

  • 6 total participants - all current undergraduate students
  • 5 from Brown University
  • 1 from Rhode Island School of Design

Interview Format

The six interviews were conducted over Zoom or in-person between individual participants and one researcher. Each session included:

  • Standard questions about AI chatbot thoughts and usage
  • Survey follow-ups to expand on previous responses
  • Personalized questions tailored to each respondent
  • Hands-on exploration of ChatGPT privacy features

Interview Process

Session Structure

  1. Usage Discussion: General AI chatbot usage patterns and platform preferences
  2. Screen Sharing: Permission-based observation of user interactions
  3. Feature Exploration: Guided discovery of privacy settings and controls
  4. Policy Review: Finding and reading ChatGPT's privacy policy

Participants were asked to locate and interact with specific privacy features including training data permissions, memory settings, temporary chat features, and default preferences. We also examined their understanding of ChatGPT's privacy policy—testing their prior knowledge, ability to locate the policy within the interface, and identifying surprising or concerning aspects after reading it.

Key Findings

Our interviews revealed significant gaps in privacy awareness and feature discoverability:

Critical Issues

  • Difficulty finding privacy policy
  • Unknown current settings - participants unaware of their privacy configurations
  • Feature awareness gaps - mixed knowledge of temporary chat

Positive Insights

  • Universal desire for choice - all participants wanted initial privacy setting options
  • Trust concerns - non-users expressed clear AI distrust
  • Privacy-first mindset - students value control over their data

Key Takeaway

"All participants thought that they should be initially presented with privacy setting choices" - highlighting a clear user need for transparent, upfront privacy controls.


Privacy-Focused Redesign

Based on our research findings, we developed comprehensive design recommendations to address the critical privacy and transparency gaps identified in user interviews and surveys.


Design Goal

Primary Objective

Design UI elements and user experiences that better inform users about where their data is going and how it's being used, creating actionable solutions through Figma prototypes.

Success Criteria

  • Transparency: Users understand data usage clearly
  • Control: Easy access to privacy settings
  • Education: Informed decision-making capabilities
Current ChatGPT interface showing the main chat area with message input and sidebar navigation

Existing ChatGPT interface analyzed for privacy design opportunities

Primary Needs Observed

Privacy Control

Users need more granular control over their data and privacy settings

Transparency

Clear information about data collection and usage practices

Intuitive Interface

Easy-to-find and understand privacy features and settings


UI Design Recommendations

We identified specific interface improvements to address immediate usability issues with existing privacy features.

UI design improvement: clickable memory update message

1. Clickable Memory Update Message

ChatGPT currently tells users that information was added to memory, but it's not immediately clear that this notification is clickable. We added visual cues to make it look like a button, with a pop-up that shows what information was added and allows users to manage their memories.

UI design improvement: privacy policy accessible in settings

2. Privacy Policy Accessible in Settings

Many interview participants immediately looked in settings for terms and policies. We added a direct link in the settings panel, in addition to the existing access point from the question mark icon in the main interface.


First-Time User Login Sequence

We completely redesigned the onboarding experience to prioritize privacy education and conscious decision-making from the very beginning of a user's ChatGPT journey.


Current Login Experience

ChatGPT's existing single-page login experience with email input and small-font privacy policy text

Current single-page login with implicit agreement

Problems Identified

ChatGPT's existing login experience consists of a single page where users enter their email and click "Agree" to continue. Most users implicitly agree to all terms without actually viewing them.

Critical Issues

  • Implicit agreement without reading terms
  • Privacy policy text in small font
  • No opportunity for conscious decision-making
  • Lack of transparency about data usage

Revised Login Sequence

We restructured this into a comprehensive 6-step sequence that promotes conscious agreement and user education:

First step of revised login sequence with cleaner interface and no immediate agreement required

Step 1: Clean login interface without pressure

Step 1: Simplified Login Page

Removes the immediate "Agree" button and presents a cleaner interface focused on user credentials, allowing users to proceed without feeling pressured to agree to terms they haven't read.

Privacy acknowledgment page with explicit agree/disagree options and improved typography

Step 2: Explicit privacy policy agreement

Step 2: Privacy Policy Agreement

Users must scroll through the full Privacy Policy with larger font sizes and bolded headings for better readability. They are then presented with explicit "Agree" or "Disagree" options, ensuring conscious decision-making.

Data Controls page explaining ChatGPT terminology and data usage in clear language

Step 3: Data terminology clarification

Step 3: Data Controls Education

After policy agreement, users learn about ChatGPT's technical terminology in plain language. This page clarifies how ChatGPT analyzes conversations, uses data to improve the model, and processes information.

Memory personalization page allowing users to choose whether ChatGPT tracks previous searches

Step 4: Memory storage personalization

Step 4: Memory Personalization

Users choose whether ChatGPT tracks their previous searches and conversations, providing granular privacy control from the start of their experience.

Multi-factor authentication setup page with options for SMS, authentication app, or opting out

Step 5: Multi-factor authentication setup

Step 5: Multi-Factor Authentication

Users can set up or opt out of multi-factor authentication. If they opt in, they can choose between SMS authentication, authentication app, or third-party authentication app for enhanced account security.

Review page showing overview of user's privacy and security selections before completing login

Step 6: Review and finalize selections

Step 6: Review Overview

Finally, users see an overview of their selections, which they can review and modify before continuing to ChatGPT. This ensures complete transparency and control over privacy preferences.

Design Rationale

It was important to make this sequence clear and straightforward to inform users about how ChatGPT works while presenting important options from the start without overwhelming users.

Key Design Decisions

  • One question per page to prevent cognitive overload
  • Progressive disclosure of complex privacy concepts
  • Clear visual hierarchy with improved typography
  • Explicit choice architecture requiring conscious decisions

While this creates a longer account creation process, our research showed the critical need for initial education before users begin using the application. Without this, users are forced to discover privacy features themselves—or never at all.


Privacy Walkthrough

We created an interactive Figma prototype to help existing users understand and navigate ChatGPT's privacy-related features after account creation.

Four Main Focus Areas

Controlling Privacy Settings

Navigate and modify data controls and privacy preferences

Locating the Privacy Policy

Find and access privacy documentation within the interface

Accessing Temporary Chats

Understand and use private conversation modes

Memory Management

Interact with and control ChatGPT's memory features

Walkthrough Structure

The walkthrough begins in the settings by describing privacy-related features in Security, Privacy, and Data Controls, highlighting the new location of the "Terms and Policies" link.

Privacy Walkthrough Examples

Settings introduction showing privacy-related settings locations

Settings introduction and navigation

Data controls settings explanation within the walkthrough

Data controls guidance

Memory update feature demonstration showing clickable memory notifications

Memory update interaction

Temporary chat access demonstration

Temporary chat feature


Reflections

Considerations + Limitations

  • Trade-off of privacy and free usage
  • Difficulty getting a diverse sampling for the survey (primarily Brown students, skewed towards CS majors)
  • Findings not representative of all college students
  • Interviewed 6 participants, limiting the broader applicability of the findings

Next Steps

  • Test how people would react to our changes through user testing and if they appreciate the changes or find them inconvenient
  • Going more broad and looking at UI designs across several GenAI models

Project Impact

This capstone project provided valuable insights into the intersection of AI technology and user privacy, highlighting critical gaps in current interface design that impact user awareness and control over their personal data.