Publications

Are Your AI Conversations Really Private? When AI Chats Become Evidence

In August 2026, The Washington Post identified 12 U.S. court cases involving chatbot logs over two years.

An Elon University study published on Sep 2, 2026 helps explain why those records matter. It found that 27% of U.S. adult internet users had used AI for personal, emotional, or social interactions. Among the study’s AI companion users, 39% said they occasionally told AI things they would not tell other people. The survey was fielded in May 2026.

The interface invites a personal conversation. The resulting record may contain intimate disclosures, business decisions, or questions about legal trouble. Whether that record can later be obtained and used in a U.S. proceeding depends on several separate questions: what exists, who controls it, which protections apply, and what the conversation actually proves.

TL;DR

  • A personal AI conversation does not automatically receive legal privilege. Some litigation-preparation materials may qualify for separate work-product protection.
  • Training, retention, and disclosure are different issues. Privacy settings matter, but no single setting answers all three questions.
  • Chats may be obtained from users, devices, or providers. Preservation keeps records available; it does not itself authorize access or admission in court.
  • Deleting a chat may not remove saved memories, other copies, or data already sent to third-party services.
  • An AI transcript is not automatically a confession. Authorship, context, authenticity, and the purpose for which it is offered still matter.

Private, Confidential, and Privileged Are Different Questions

A chat can be private without being privileged. Privacy concerns access to and use of personal information; confidentiality concerns obligations to keep information secret. Evidentiary privilege can protect particular communications from compelled disclosure. Work product is a separate protection for qualifying litigation-preparation materials, not a label that attaches to every legal question typed into a chatbot.

A provider’s promise not to train on a conversation addresses one use of data. It does not, by itself, make the record unavailable in litigation. Equally, the fact that a provider retains a record does not mean anyone who asks is entitled to receive it.

Stored does not mean obtainable. Obtainable does not mean admissible. Admissible does not mean conclusive.

Federal Rule of Civil Procedure 26 expressly distinguishes discoverability from admissibility. A preservation request is another separate step: for example, 18 U.S.C. § 2703(f) requires covered providers to preserve records while the government obtains appropriate legal process. Keeping a record and disclosing it are not the same act.

What Do ChatGPT, Claude, and Gemini Actually Retain?

The comparison below concerns personal consumer accounts and ordinary text conversations. Business products, API deployments, feedback submissions, and legal or safety holds can follow different rules. This comparison reflects the providers’ policies as of Sep 7, 2026.

Consumer Products at a Glance

The relevant sources are OpenAI’s deletion guidance, Data Controls FAQ, and Temporary Chat FAQ; Anthropic’s consumer-retention policy and Incognito guidance; and Google’s Gemini Apps Privacy Hub. These periods describe different copies and purposes, not a guarantee that every retained copy remains recoverable by the user or obtainable in litigation.

The controls have real effects. Anthropic says disabling model improvement excludes previous and new chats from future training; deleting a chat also excludes it from future models. Neither action reverses training already completed or in progress. With Gemini, turning Keep Activity off prevents future chats from being used for model training unless the user submits feedback. In ChatGPT, disabling training does not delete ordinary chat history.

Longer retention also needs context. Anthropic may keep de-identified training data for up to five years when model improvement is enabled; flagged inputs and outputs can be retained for two years, and safety-classification scores for seven. Google retains reviewed conversations separately from accounts for up to three years. These are different categories, not evidence that every conversation receives the longest retention period.

Deleting a Chat Is Not Always Deleting Every Copy

Chat history is only one place information can persist. OpenAI’s Memory FAQ explains that memory can draw on chats, files, and connected apps; removing information may require addressing each source. In its saved-memory system, memories are stored separately from chat history, so deleting the original conversation does not necessarily delete a saved memory derived from it.

Third-party tools create another boundary. OpenAI’s Temporary Chat FAQ says information sent through GPT actions is governed by the recipient’s own privacy policy and may be retained for longer than 30 days. A temporary conversation with one service therefore does not impose that service’s deletion rules on another recipient.

Exports, screenshots, and copies shared with colleagues are another reason to distinguish deleting the original from deleting every record of the exchange. The practical question is not just whether the chat still appears in a sidebar, but where its contents have gone.

When Litigation Changes the Deletion Rules

The copyright litigation involving The New York Times and OpenAI illustrates how legal obligations can interrupt routine deletion. A May 13, 2025 preservation order directed OpenAI to preserve and segregate output logs that would otherwise be deleted. It did not, by itself, give the plaintiffs unrestricted access to those logs.

In an October 2025 update, OpenAI reported that the broad obligation to retain new user data indefinitely had ended on Sep 26, 2025, while a limited historical April–September dataset remained subject to preservation. That update describes the company’s position at that point in the litigation, not a permanent exemption from later lawful requests or orders.

For users and companies, routine data minimization is different from deleting relevant records after a duty to preserve arises. Federal Rule 37(e) addresses electronically stored information that should have been preserved, was lost because reasonable steps were not taken, and cannot be restored or replaced. Consequences depend on the rule’s conditions, including prejudice or, for the most severe measures, intent to deprive another party of the information. A lost chat does not automatically trigger sanctions.

How Can AI Conversations Be Obtained?

Four recurring routes help explain how a conversation moves from a private account into a dispute or investigation. Each has its own requirements; none makes every conversation fair game.

1. Discovery from the User or Company

Under Federal Rule of Civil Procedure 34, a party can request documents and electronically stored information within another party’s possession, custody, or control. Relevant AI histories can fall within that framework. The target may therefore be the person or business controlling the account, rather than the chatbot provider.

Access and export capabilities can matter to the control analysis, but do not eliminate relevance, proportionality, privilege, or other objections. Nor does an employer necessarily control everything in an employee’s personal AI account. OpenAI’s civil-request policy says it may object when someone seeks a counterparty’s data without first exhausting ordinary party discovery.

2. Access to a Phone or Computer

A provider need not be involved when investigators can lawfully examine a device. In the Ryan Schaefer investigation, a Missouri police probable-cause statement records that Schaefer signed a consent-to-search form and supplied his phone’s PIN. Investigators downloaded the phone’s contents and found a ChatGPT exchange about damaged vehicles and whether he might be identified. The source was the phone, not a demand that OpenAI produce the conversation.

The example illustrates an independent source of evidence: data available on a device or through an accessible account. It does not establish that every consent authorizes an unlimited search, or that every chatbot stores a complete local archive.

3. Legal Requests to the Provider

Providers also receive direct requests. OpenAI’s July–December 2025 transparency report lists 75 requests for user content. Data was disclosed in response to 62 of them, affecting 84 accounts. The report separately lists 224 non-content requests and 10 emergency requests. These categories concern government requests, not the number of occasions on which OpenAI independently alerted authorities.

The required process depends on the requester and the information sought. OpenAI’s Government User Data Request Policy requires a warrant or equivalent process for U.S. requests for user content, while some non-content records can be obtained through other valid process. Retention alone does not establish that a particular request is legally sufficient.

In reporting on the Drew Hoehner investigation, Forbes described a warrant seeking account information associated with two known ChatGPT prompts. This illustrates a reverse-prompt request, but not proven identification through OpenAI data: Forbes reported that investigators identified the suspect through other information, and that the contents of OpenAI’s response were unclear.

Civil requests raise different issues. Where the Stored Communications Act applies to the service and records, § 2702 restricts disclosure of communication content, subject to statutory exceptions. An ordinary civil subpoena is not a universal entitlement to that content. Those provider restrictions should not be confused with the rules for seeking records from a litigant who controls them.

4. Emergency Disclosure

A covered provider may disclose content to a governmental entity under 18 U.S.C. § 2702(b)(8) when it has a good-faith belief that an emergency involving danger of death or serious physical injury requires disclosure without delay. OpenAI’s government-request policy also describes emergency handling. This is a limited legal exception, not a general permission to report every troubling or embarrassing conversation.

The distinction is important: an emergency request from authorities and a provider-initiated report are not the same event. Neither supports an assumption that human reviewers read every conversation or that all sensitive disclosures are automatically sent to police.

When Can Privilege or Work-Product Protection Apply?

Merely treating a chatbot as a lawyer does not create an attorney-client relationship. Existing protections instead depend on how the material was created, why it was created, who received it, and the applicable legal rules.

Heppner: Independent AI Use and Previously Privileged Information

In United States v. Heppner, the Southern District of New York rejected attorney-client privilege and work-product protection for 31 Claude-related documents. The Feb 17, 2026 opinion concerned materials found on seized devices. Heppner had used Claude independently, not at counsel’s direction; the materials did not reflect his lawyers’ mental impressions.

The court also considered Anthropic’s policy as of Feb 19, 2025, including its provisions on collecting and using content. Those historical terms matter; a current enterprise agreement cannot simply be substituted for the service conditions the court examined. Explaining why Claude was not a lawyer in a privileged relationship, the court wrote: “No such relationship exists, or could exist.”

Footnote 3 identifies a further risk: to the extent Heppner uploaded already privileged information received from counsel, the court found that disclosure waived the protection. The concern was therefore not only whether a new AI exchange was protected, but what happened to protected advice copied into it. This was a fact-specific privilege ruling, not a holding that all AI use defeats every legal protection.

Warner and Tremblay: Protection Depends on the Material and the Request

In Warner v. Gilbarco, Inc., a Michigan federal court rejected a request for a self-represented litigant’s ChatGPT materials. Its Feb 10, 2026 order addressed untimeliness, relevance and proportionality, as well as work-product protection. The court treated litigation-related mental impressions as protected and rejected speculative arguments that using an AI tool necessarily made them available to the opponent.

Both Warner and Heppner discuss work product. The cases cannot be reduced to one being “about privilege” and the other “about work product,” nor do they establish a nationwide rule. Their facts, procedural settings, and reasoning differ.

Tremblay v. OpenAI provides a narrower illustration: the court protected counsel’s negative ChatGPT testing and testing process as opinion work product, while requiring disclosure associated with positive results already used in the complaint. It did not protect all prompts simply because lawyers wrote them.

Lawyer-directed AI use remains a separate, fact-sensitive question. Heppner left open whether an AI tool used at counsel’s direction could be treated differently, drawing on cases about specialists assisting lawyers. Direction alone is not a guaranteed shield: purpose, confidentiality, vendor terms, and the relevant doctrine still matter. Buzko Legal’s AI in Legal Disputes examines the wider litigation-workflow issues.

An AI Transcript Is Not Automatically a Confession

AI conversations can be unusually revealing because users explain context and explore options across multiple messages. But an interactive transcript is not a direct recording of a person’s thoughts, and its apparent candor does not settle what it proves.

Consider a hypothetical employer asking a chatbot to model arguments an employee might use to challenge a dismissal. The model proposes discrimination, retaliation, and document concealment. That output is not, without more, the employer admitting any of those acts. The exchange might be relevant to some issue, but the user’s request, the model’s suggestions, and any later adoption or action must be distinguished.

Federal Rule of Evidence 901 requires sufficient evidence that an item is what its proponent claims it is. Rule 801(d)(2) separately addresses statements made or adopted by an opposing party. A model-generated sentence is not automatically that party’s statement. Hypothetical, fictional, quoted, or adversarial prompts also require context rather than an assumption of literal intent.

A useful record therefore preserves the relevant exchange, speaker roles, timing, and surrounding circumstances, rather than relying only on a cropped screenshot. The court must still evaluate relevance, applicable hearsay rules, and other admissibility requirements. Even an authentic, admissible chat may be ambiguous or carry little weight; it must be assessed alongside the rest of the evidence.

What This Means for Companies, Lawyers, and Users

Enterprise Controls Reduce Exposure, Not Automatically Legal Discoverability

Business products can materially change who can access data, whether it is used for training, and how long it is retained. OpenAI’s enterprise commitments include no model training by default and retention controls for specified products. Anthropic’s commercial-retention policy generally provides for deletion of API inputs and outputs within 30 days, with contractual, safety, and legal exceptions.

Zero Data Retention can reduce what a provider holds, but its scope must be checked for the actual service, endpoint, and model. Anthropic’s covered-model policy, for example, requires 30-day retention for certain models and configurations even where other use benefits from ZDR. A product label is not a legal privilege, and a provider’s limited retention does not remove a user’s export or a company’s copy.

The implementation question is practical: which accounts are approved, what information may be entered, who administers access, and how can relevant records be preserved when a dispute is anticipated? Personal accounts used for company work deserve particular attention because they can create business records outside normal email and collaboration systems.

A Corporate Example: Fortis Advisors v. Krafton

The Delaware Court of Chancery’s Mar 16, 2026 opinion in Fortis Advisors LLC v. Krafton, Inc. shows why this is not just an issue for criminal investigations. In a dispute involving Unknown Worlds and earnout obligations, the court described a Krafton executive’s use of ChatGPT to develop strategy and his sharing of that advice with a colleague. It considered the exchanges alongside the company’s subsequent conduct.

The opinion also records an admission that certain relevant ChatGPT logs had been deleted. That does not establish that deleted logs were recovered from OpenAI. The useful point is narrower: AI-assisted planning can become part of the factual record in an ordinary business dispute, and its handling can matter alongside email and other documents.

Lack of Privilege Does Not Mean Lack of Protection

A request for an entire AI history is not justified merely because that history exists. Rule 26(b)(1) limits federal civil discovery by relevance and proportionality. Under Rule 26(c), a party or affected person can seek a protective order, including restrictions on disclosure or use of confidential material. The available relief depends on the request and the case; it is not automatic secrecy.

For lawyers, this means assessing confidentiality and legal protection before uploading client material, not assuming that a vendor’s security commitments answer both questions. ABA Formal Opinion 512 likewise calls for evaluating generative-AI risks to client information and the safeguards required in the particular circumstances.

For users, privacy settings are worth using, but they should match the goal: limiting training is different from removing memory or preventing third-party sharing. Once a legal dispute is reasonably anticipated, consult counsel about preserving relevant conversations before deleting them or changing automatic-deletion settings. Reducing routine collection is not a substitute for complying with an existing preservation duty.

Conclusion: Treat the Chat as a Record, Not a Verdict

Important questions remain unsettled, including how older communications statutes map onto particular AI services, when lawyer-directed tools fit within existing protections, and the constitutional limits of reverse-prompt requests. Neither a broad claim that AI chats are protected nor a broad claim that they are unprotected captures those differences.

The practical starting point is to treat an AI conversation as a record that may exist in several places. Then ask separately whether it can be obtained, whether a legal protection applies, and what its contents genuinely establish. Stronger privacy controls can reduce exposure. Legal protections can restrict disclosure. Context can change the meaning of the evidence.

The interface may feel like a private conversation. The law asks where the record is, who may obtain it, and what it actually proves.

FAQ

 

Contacts

Thank you — we'll get back to you within two business days.

Oops! Something went wrong while submitting the form.