Mentor dos Nerds Home ChatGPT Already Knows a Lot About You. Before You Trust It, Make It Show Its Work
Post

Article Artificial Intelligence

ChatGPT Already Knows a Lot About You. Before You Trust It, Make It Show Its Work

Conversation fragments pass through evidence, questions, and a rejected hypothesis before forming a confirmed contract surrounded by memory, security, and validation controls
Conversation fragments pass through evidence, questions, and a rejected hypothesis before forming a confirmed contract surrounded by memory, security, and validation controls

When I began building my personal harness—the context, memory, tools, permissions, and validations surrounding the model—I made a request that sounds stranger when told without the rest of the story:

I asked ChatGPT to answer a few questions as if it were me.

Imitating the way I speak was not enough.

For every answer, it had to show where the conclusion came from.

Then I gave that provisional inventory to the agent building the system—a system capable of choosing next steps and using tools within a bounded objective—and asked it to interview me. The questions had to reveal how I make decisions, what kind of evidence persuades me, when I change tone, how I write, where I accept autonomy, and where I want the decision returned to me.

I was not trying to create a copy of myself.

I was trying to stop reintroducing myself to the machine every time I started a conversation.

TL;DR

Depending on account settings, ChatGPT can use saved memories, past conversations, custom instructions, files, and connected apps to adapt its responses. That does not mean it “knows you” the way one person knows another, or that every inference is correct. I used this material as a starting point: I asked ChatGPT to formulate hypotheses about me while exposing evidence and uncertainty; then I used strategic questions to confirm, correct, or reject each hypothesis. Only confirmed conclusions became contracts in my harness. The conversation history supplied raw material. The direction remained mine.

“Knowing about you” is not knowing you

The title of this article is deliberately provocative.

ChatGPT may have received a great deal of information about you. It can retrieve relevant pieces of that material and produce a surprisingly coherent synthesis. Still, there is no person there observing your path, forming affection, or understanding your experience from the inside.

There is a system processing context.

The current ChatGPT memory documentation explains that, when the feature is enabled, it can use context from conversations, files, memories, and connected apps. The documentation also warns that the memory summary does not necessarily show everything that may be considered and that memories can become outdated or contradictory.

That supports a more modest claim than the title:

ChatGPT may have enough material to formulate useful hypotheses about how you think and work.

A hypothesis is not an identity.

Personalization is not consciousness.

Narrative coherence is not proof.

I began by asking for an imitation that showed its work

My first move was not to write a profile of myself from scratch.

I had already spent hours talking to ChatGPT. Those conversations contained decisions, corrections, writing preferences, objections, changes of course, examples, and moments when I said, “this represents me” or “this is not me.”

Instead of ignoring that archive, I turned it into an initial interview.

The request was roughly this:

1
2
3
4
5
6
7
8
9
10
11
Answer the questions below as if you were me, using only what you can
support from our conversations.

For every answer:
1. label it confirmed, inferred, or unknown;
2. present the evidence that led to the conclusion;
3. state your confidence level;
4. show contradictions or signs that the information may be outdated;
5. do not fill gaps merely to produce a pleasant or coherent answer.

If there is not enough evidence, say that you do not know.

That changes the quality of the result considerably.

“Felipe prefers direct answers” is a plausible guess.

“Felipe corrected answers that hid the current state three times and explicitly asked for the text to begin with state, risk, and next step” is an auditable hypothesis.

It may still be incomplete.

But now I know where to disagree.

The conversation archive became raw material, not a constitution

You can also export your conversation history and other eligible account data. OpenAI’s guidance warns that the package may contain sensitive information and should be protected.

That matters because “throwing my entire history into an agent” is not a memory strategy.

It is a data-leak strategy with hope attached.

The raw archive may contain:

  • old decisions that have already been superseded;
  • examples provided only to test an idea;
  • personal data that does not need to enter the system;
  • client or third-party information;
  • temporary reactions treated as permanent preferences;
  • answers produced by AI that I never confirmed.

That is why I separate three layers:

Layer What it is for What it must not do
Raw source Preserve the conversation and its origin Become a rule automatically
Hypothesis about the author Organize patterns worth confirming Pretend an inference is a fact
Confirmed contract Guide decisions, writing, and operations Freeze the person forever

The history says what happened.

The hypothesis proposes what it might mean.

I decide what gets to govern the system.

Then I had the agent interview me

The second step was more valuable than the first synthesis.

Instead of asking “who is Felipe?”, the agent began asking questions that would change the system’s behavior.

For example:

  • When a source contradicts your initial thesis, do you preserve the thesis, suspend the conclusion, or rewrite the argument?
  • Which decisions may the agent execute on its own, and which ones must return to you?
  • What turns a suggestion into a current decision?
  • When does humor bring the reader closer, and when does it diminish the seriousness of the subject?
  • Which words make the text technically correct but sound as though someone else wrote it?
  • Do you prefer a fast answer with explicit uncertainty or to wait for a deeper verification?
  • Which information may become durable memory, and which should die with the conversation?
  • What is a reusable preference, and what depends on the client, the risk, or the current context?

When there was a strong hypothesis, the question could already offer possible answers:

Previous conversations suggest that you prefer private infrastructure, open-source components, and greater control over data. Is this a general rule, a context-dependent preference, or a wrong conclusion? Which exceptions do you accept?

That saves time without turning the agent’s guess into a decision.

I can still answer:

“It is the first option.”

“It is a mix of the first and second.”

“I did not understand the question.”

“That does not represent me.”

That is exactly how parts of this system became defined.

What is worth mapping in a personal harness

There is no universal questionnaire, because each harness has to serve a real person and a real operation.

Even so, a few dimensions tend to reveal a great deal:

Dimension Useful question Operational outcome
Decision-making What counts as sufficient evidence? Acceptance and escalation criteria
Writing When should the tone be direct, explanatory, ironic, or sober? A voice guide with examples and counterexamples
Uncertainty How should an unproven claim be presented? Separation of fact, hypothesis, and synthesis
Autonomy What may be executed, and what may only be recommended? Permissions and approval points
Risk What requires proportional confirmation before action? Limits for external or hard-to-reverse actions
Sources Which evidence supports each kind of claim? A research and reference hierarchy
Tools Which capabilities exist, and when should each be used? Execution routing
Continuity What needs to survive the conversation? Memory, contracts, and a source of truth
Privacy What must not be stored, repeated, or sent to third parties? Data minimization and access control
Business Which problem do I solve, and which promise do I refuse to make? Coherent positioning and communication

That is how apparently small preferences began to produce real effects.

“I do not want flattery” became a requirement for counterpoints and explicit uncertainty.

“The direction is mine” became an approval boundary.

“Explain the technical term without making the subject shallow” became an editorial rule.

“Evaluation before publication” became a process; the Pull Request remained only the technical way to materialize it on this blog.

A confirmed sentence stops being decoration when it changes how the system works.

Custom instructions help, but they cannot carry the entire operation

ChatGPT Custom Instructions let you state directly what you want the system to consider in its responses.

They are useful for broad preferences.

But an operational harness usually needs more:

  • different rules for different projects;
  • files with provenance, ownership, and validity;
  • reusable procedures;
  • tools and permissions;
  • reviewable memory;
  • automated validations;
  • specialized agents;
  • clear criteria for stopping and asking for a decision.

In this environment, AGENTS.md serves as the entry point. The agent reads it to understand the initial rules, learn how to navigate the files, locate tools and workflows, and know which checks must be completed before acting.

It does not contain everything.

It teaches the system how to find what matters.

That distinction matters: putting every piece of information in one prompt increases volume. Building navigation paths increases the ability to retrieve the right context.

The subtlest risk is receiving a flattering version of yourself

There is a particularly dangerous trap in this process.

You ask AI to describe how you think.

It produces a beautiful, coherent, admirable profile.

And you like what you read so much that you forget to check whether it is true.

It is the same excessive agreeableness I have discussed elsewhere on this blog, now applied to the user’s identity.

A system that knows I value autonomy can exaggerate it until I become a caricature incapable of collaboration.

A system that notices my interest in open source can treat an architectural preference as dogma, regardless of cost, risk, or context.

A system tuned to reproduce my tone can repeat my writing habits and call them authenticity.

That is why the review also needs to look for:

  • evidence to the contrary;
  • exceptions;
  • changes over time;
  • differences between stated preference and observed decision;
  • attributes that sound suspiciously flattering;
  • sensitive inferences that should not be persisted.

The goal is not to build a mirror that agrees with me.

It is to build a system that understands my premises well enough to help me—even when it needs to point out that I am contradicting one of them.

Not everything ChatGPT remembers belongs in the harness

OpenAI’s documentation says sensitive information may appear in memory when it is shared. It also describes controls to review, correct, delete, or disable memory and to use Temporary Chat, whose behavior varies with the personalization option selected.

Before reusing any history, I would apply at least these rules:

  1. Minimize. Carry forward only information with a clear purpose and consumer.
  2. Classify. Separate declared fact, observed behavior, inference, and gap.
  3. Show the source. A rule without evidence is difficult to correct.
  4. Ask for confirmation. No relevant inference becomes a contract on its own.
  5. Set validity. Preferences change; some need a date or a review cycle.
  6. Protect third parties. Conversations may contain data that is not yours alone.
  7. Create a right to be forgotten. The system must allow information to be removed when it should no longer be used.

Useful memory is not infinite memory.

It is governed memory.

A practical way to begin

If I rebuilt this process today, I would do it this way:

  1. Review the account’s memory, personalization, and data settings.
  2. Ask ChatGPT for a provisional inventory of what it can support with evidence about how I decide, write, and work.
  3. Require evidence, confidence, contradictions, and an explicit “I don’t know” field.
  4. Remove sensitive, circumstantial, or operationally useless data.
  5. Give the hypotheses to an interviewing agent that asks strategic questions in small batches and offers possible answers when evidence supports them.
  6. Confirm, correct, or reject every conclusion.
  7. Turn only approved conclusions into contracts, examples, permissions, validations, and memory with provenance.
  8. Test the system in real situations, especially when the data contradicts my initial preference.
  9. Periodically review what has become obsolete.

The sixth step is the most important.

Without it, you have merely traded an empty profile for a probabilistic autobiography.

ChatGPT can interview you for the system you will build next

Today I can speak a few sentences into a microphone and start an entire operation because the system does not begin from zero.

It has access to contracts I confirmed.

It knows where to look for information.

It knows how to present uncertainty.

It recognizes that I want the best available answer, not the one that flatters my ego most.

And, as this same series of articles has shown, it can still lose an important priority. That is why the work never ends with “now the AI knows me.” It continues through validation, correction, and system improvement.

At i-9.ai, this is one of the differences between installing a tool and building an AI-assisted operation. A tool responds. An operation has to incorporate context, rules, sources, limits, decision paths, and verifiable learning without taking direction away from the person accountable for the result.

If you like this way of working, get in touch. We can begin with the decisions your team repeats, the information scattered across systems, and the context that should not have to be retaught every week.

ChatGPT may already know a lot about you.

But you decide what, once proven, deserves to govern your system.

To go deeper

References and limits of use

  • OpenAI, “Memory FAQ”: supports the description of how ChatGPT memory can use different sources when enabled and of the available controls. It does not prove that a specific account has every feature enabled or that an inference about the user is correct.
  • OpenAI, “ChatGPT Custom Instructions”: supports the use of explicit guidance for personalization. It does not show that custom instructions replace governance, tools, or external validation.
  • OpenAI, “Exporting your ChatGPT history and data”: supports export availability and basic handling guidance for eligible accounts. It does not guarantee that every piece of data a user expects is present in the package.
  • OpenAI, “Temporary Chat FAQ”: supports the description of current Temporary Chat options and limits. Behavior depends on the personalization choice and account settings.

The method of interviewing ChatGPT, requiring evidence, and turning only confirmed conclusions into contracts is an authorial account of how I built my harness. It is not an experiment or a guarantee that another system will faithfully reconstruct a person’s identity, writing, or decision-making.

This post is licensed under CC BY 4.0 by the author.

Open conversation

Continue the conversation

Disagree, spot a gap, or have an experience that adds to the subject? Comment with your GitHub account. Do not publish personal data, credentials, or sensitive information.