You're typing into Meta AI in WhatsApp, asking whether you should really send that email to your boss. Or how to bring up a breakup. Until recently, that theoretically ended up somewhere in Meta's systems, permanently. Since mid-May 2026, there's an airbag for that: Incognito Chat.
What Incognito Chat actually is
Incognito Chat is a second mode for talking to Meta AI — the assistant built into WhatsApp, Instagram, and Facebook. Run a normal conversation, and it's treated like any regular chat. Switch on incognito mode, and Meta promises: no storage, no analysis, no reading — not even by Meta itself.
Under the hood sits something called a "Trusted Execution Environment" (TEE). Put simply: a sealed-off computing space that, in theory, not even Meta can peek into while it processes your request. Apple uses a similar principle for its "Private Cloud Compute." Once the conversation ends, nothing is supposed to remain.
One detail that's easy to miss: web searches the AI runs for you during an Incognito Chat go through a relay server in between. That masks your IP address from Meta — so the search request can't easily be traced back to you.
Haven't we had this already?
Half. Temporary chats are nothing new: ChatGPT has them, and Perplexity even calls its version incognito mode. The difference isn't the button — it's what sits behind it.
With ChatGPT and Perplexity, it's a promise by house rules. The chat doesn't show up in your history and isn't used for training. It still travels in plain text across the provider's servers and sits there for a while — currently up to 30 days at OpenAI for abuse monitoring, while Perplexity drops the thread from your library after 24 hours and keeps it in the backend considerably longer. The provider could read along. It just says it doesn't.
OpenAI accidentally demonstrated how much such a promise is worth. In May 2025, a US court ordered it to preserve all chat logs — explicitly including the ones that deletion or temporary chat should have wiped long ago. The order ran until the end of September 2025. For months, "temporary" simply meant: stored, just invisible.
Meta's approach is a different category. The claim isn't "we delete it afterwards" but "we can't read it in the first place." Hardware instead of house rules — and hardware doesn't change its mind for a court order.
Real guarantees still only come in one flavour: AI on your own machine, say with Ollama and OpenWebUI. Nothing leaves the device, and you don't have to trust anyone because nobody else is involved. The price is setup effort and a reasonably capable computer — for a quick chat on the go, it's no substitute.
What doesn't work (yet)
Incognito Chat is text-only for now. No uploading images, no generating them, no voice messages. If you want the AI to edit a photo, you have to switch back to normal mode — and back to normal data handling.
The trust catch
Here's the honest framing: you can't independently verify that the TEE actually works the way Meta claims. It's a promise, backed by a documented architecture and, according to Meta, external audits — but at the end of the day it's still a matter of trust, like every "we don't store anything" statement from a big tech company. Some skepticism is warranted; blind panic isn't required either. The architecture is reasonably well documented and resembles what Apple has run for years with Private Cloud Compute, without major known leaks.
There's also a question that shadows every US provider: the CLOUD Act. The American law obliges US companies to hand data to US authorities — no matter which continent the servers sit on. Meta is squarely covered. The good news: you can only hand over what you have. If the sealed-off environment holds, the content of your Incognito Chat doesn't exist at Meta in readable form at all. The same logic already protects your regular WhatsApp messages.
The less good news: content isn't everything. That your account used incognito mode, when, and how often — Meta knows all of that, and it's disclosable. With sensitive topics, the "who" is often half the information already. And the masking of your IP only works as long as Meta and the relay provider don't put their puzzle pieces together. Both are based in the US.
The myth that isn't true
Worth clearing up, since it keeps circulating as chain-message panic: Meta AI does not automatically read your regular chats with friends or family. End-to-end encryption on your normal WhatsApp chats stays untouched — Meta AI only gets involved when you address it directly or add it to a group. German fact-checkers and consumer protection agencies have confirmed exactly that.
What you can actually do
- Try Incognito Chat: in the chat view with Meta AI, there's a toggle for incognito mode — good for anything a bit more sensitive.
- Advanced Chat Privacy (a separate, older feature, available since April 2025): lets you block Meta AI from being used at all in specific chats or groups, and stop media from auto-saving to your gallery.
- Object to the data use: under GDPR, EU users have the right to object to their data being used for AI training. Consumer protection groups and Germany's federal data protection authority publish step-by-step guides for exactly that.
Who's this actually for?
Basically anyone with WhatsApp — that's the point. No developer skills needed, no cost, no subscription. Just one more control toggle in an app most of us have open every day.
The bottom line: Incognito Chat is a genuine step up from "we just store everything by default." It doesn't make AI in messaging apps automatically safe — but it gives you an honest option before you hand something personal to the AI. Using it costs nothing. Ignoring it might cost you an extra explanation later for why you didn't.
