Hoovered up as a data point: Exploring Privacy Behaviours, Awareness, and Concerns Among UK Users of LLM-based Conversational Agents

Large Language Models (LLMs) are widely used in conversational agents (CAs) due to their ability to generate coherent and human-like text. However, their deployment raises significant privacy concerns, as users often share sensitive data in prompts. This data can be used to train the underlying LLM, introducing memorisation risks and challenging users' right to be forgotten. While these issues have been explored from a technical standpoint, little is known about how users perceive and navigate privacy issues in their day-to-day use of LLM-based CAs. To address this research gap, we conducted a survey of UK-based CA users (n=211) that focused on their privacy behaviours, self-disclosure boundaries, concerns, and awareness of LLM-specific privacy issues. We found that engagement with protective behaviours was low overall, and that many participants held inaccurate beliefs about the effects of deleting data and opting out of model training. Although participants were generally reluctant to share sensitive information during interactions, we identified several challenges to limiting self-disclosure in practice, such as balancing privacy with app utility. Lastly, we observed a nuanced relationship between privacy awareness and concern, and identified significant demographic effects. We propose design avenues for privacy-supportive tools, and discuss the implications of our work for regulation and governance.

Paper

Full text

PDF

Hoovered up as a data point: Exploring Privacy Behaviours, Awareness, and Concerns Among UK Users of LLM-based Conversational Agents

OpenAlex · Privacy, Security, and Data Protection · 2025

Abstract

Large Language Models (LLMs) are widely used in conversational agents (CAs) due to their ability to generate coherent and human-like text. However, their deployment raises significant privacy concerns, as users often share sensitive data in prompts. This data can be used to train the underlying LLM, introducing memorisation risks and challenging users' right to be forgotten. While these issues have been explored from a technical standpoint, little is known about how users perceive and navigate privacy issues in their day-to-day use of LLM-based CAs. To address this research gap, we conducted a survey of UK-based CA users (n=211) that focused on their privacy behaviours, self-disclosure boundaries, concerns, and awareness of LLM-specific privacy issues. We found that engagement with protective behaviours was low overall, and that many participants held inaccurate beliefs about the effects of deleting data and opting out of model training. Although participants were generally reluctant to share sensitive information during interactions, we identified several challenges to limiting self-disclosure in practice, such as balancing privacy with app utility. Lastly, we observed a nuanced relationship between privacy awareness and concern, and identified significant demographic effects. We propose design avenues for privacy-supportive tools, and discuss the implications of our work for regulation and governance.

Similar papers

© 2026 NYSGPT2525 LLC