People tell chatbots things they would not tell a friend. That is not a criticism, it is the whole product. A tool that answers at three in the morning, never looks tired of you, and has no opinion it will repeat to anyone at dinner is genuinely useful, and tens of millions of people now use one that way.
The trouble is the last part of that sentence. It only holds if nobody else can read the transcript, and a new Washington Post review makes clear that plenty of people can.
The Post found chatbot conversations turning up in twelve public court cases over roughly two years. Most were not obtained through some exotic legal maneuver. They came off a phone during a search, or out of the ordinary evidence gathering phase of a civil lawsuit, where each side gets to demand the other’s documents.
The short version
- No privilege exists. Conversations with a lawyer, doctor or therapist are legally shielded. Conversations with a chatbot are not, in any jurisdiction, in any form
- Twelve cases and counting. The Washington Post counted that many public court cases in two years where chatbot transcripts were part of the record
- The device is the usual weak point. Most transcripts reached a courtroom because somebody searched a phone or requested files during discovery, not because a company handed them over
- At work, it is simpler than that. On a corporate Copilot or enterprise AI account, administrators can typically pull prompts and responses through standard audit and compliance tooling. No warrant, no subpoena, no notification to you
- Memory makes the archive worse. Chatbots are designed to retain context across sessions, which turns a set of isolated questions into a continuous record of your circumstances
- Even the CEO agrees. Sam Altman has publicly called the absence of confidentiality for these conversations “very screwed up” and argued that something like an AI privilege needs to exist. It does not yet
Privilege is a specific legal thing, and this is not it
Confidentiality in the everyday sense means a company promises to be careful with your data. Privilege is different. It is a rule that stops a court from compelling the disclosure of a conversation at all, and it exists for a small, deliberately narrow set of relationships: attorney and client, doctor and patient, therapist and patient, in many places clergy and penitent, and spouses.
Those categories were built over centuries on a specific argument, which is that society gets more out of people being able to speak with total candor to their lawyer or their doctor than it gets from occasionally using those words as evidence. No legislature has ever made that argument about a chatbot, so no court applies it.
Jen King, a privacy researcher at the Stanford Institute for Human-Centered Artificial Intelligence, put the practical version bluntly in the Post’s reporting. Hiding these conversations is essentially impossible “unless you are having a chat with a service that has a temporary chat or, basically, an incognito version,” and even then only if you are also “having it within a browser that’s not tracking you.”
Andrew Ferguson, a George Washington University law professor who studies digital surveillance, framed where this is heading: “The whole of your life will then be accessible to the police.”
At work, nobody even needs a court
The courtroom scenarios make the better headline, but the likelier version of this problem is duller and much closer to home.
If you are using a chatbot through an account your employer provides, whether that is Microsoft 365 Copilot, an enterprise ChatGPT deployment, or something built on a company API key, your prompts and the answers are generally treated as corporate records. In the Microsoft ecosystem they are captured for compliance and can be surfaced through audit logs, administrative export and eDiscovery tooling, in the same way an internal chat message or an email can be.
None of this is hidden. It is documented, it is sold as a compliance feature, and for a regulated business it is a legitimate requirement. The gap is that “private chat” in an enterprise product means other employees cannot see it. It has never meant the organization cannot.
Which matters, because of what people actually type into these things at work: that they are interviewing elsewhere, that they cannot cope with their manager, a rough draft of a grievance, a health situation they have not disclosed to HR. All of it lands in a system built to be searchable by the employer.
| How you are using it | Who can realistically read it | Practical exposure |
|---|---|---|
| Personal account Free or consumer subscription | You, the provider, anyone with your unlocked phone, and anyone who obtains it lawfully | History is stored by default. Memory links sessions together |
| Employer provided account Copilot, enterprise deployments | All of the above, plus your IT and compliance administrators | Highest. Retrieval is routine and requires no legal process |
| Temporary or incognito chat | Substantially fewer parties, though not nobody | Lower. Retention is shortened, and the exchange stays out of memory |
| Local model on your own hardware | You, and whoever can reach the machine | Lowest. Nothing leaves the device, but the device can still be searched |
Deleting the app does not delete the record
There is a second layer that trips people up. Even where a provider offers deletion, litigation can freeze it. OpenAI spent a good part of the past two years contesting a preservation order in the New York Times copyright case that required it to retain user conversation logs, with carve outs for certain enterprise and zero retention API arrangements. When a court orders preservation, a company’s own delete button stops being the end of the story.
Altman has been unusually direct about the underlying problem. Speaking publicly in 2025, he noted that someone discussing “your most sensitive stuff” with ChatGPT has none of the protection they would get from a therapist or a lawyer, said the industry has not figured that out, and called for something like an AI privilege to be established. That is a chief executive describing his own product’s legal position as broken. It has not been fixed since.
Meanwhile the transcripts are becoming more valuable to more people. Aggregated chat data is already being used to draw conclusions about entire professions, which is exactly what happened when researchers built a tool that scores how exposed your job is to automation using patterns pulled from chat logs. What is analytically useful in aggregate is evidentially useful one person at a time.
What is actually worth changing
Six adjustments that cost you nothing
- Keep work topics on the work account and everything else off it. The mixing is what creates the worst exposure, not the tool
- Use temporary chat for anything genuinely sensitive. Health, legal questions, relationships, money. It shortens retention and keeps the exchange out of memory
- Turn off memory, or prune it. Most services expose the stored facts about you and let you delete individual entries. Very few people have ever opened that screen
- Lock the phone properly. The single most common route into these transcripts is a device somebody could open, so a real passcode and biometrics matter more here than any setting inside the app
- Do not use a chatbot to rehearse a legal problem you actually have. Ask a lawyer, where the privilege is real. A transcript of you reasoning through your own liability is the worst possible document to create
- Read what your employer’s AI policy says about retention before assuming it says nothing
None of this argues for abandoning the tools. The comparison people reach for, which is a therapist or a confessional, is simply the wrong one. The right comparison is a text message thread: useful, personal, stored, and fully available to anyone who ends up with a legal reason to look at it.
The honest read
The uncomfortable part of this story is not that companies are behaving badly. Mostly they are behaving normally, and the enterprise logging in particular is a feature businesses specifically pay for. The problem is that the product is designed to feel like an intimate conversation while being built like a document store, and nobody has closed the gap between those two things.
That gap is now a pattern rather than an incident. It showed up when an AI assistant kept reading users’ email after its access was supposedly revoked, and it shows up every time a tool that behaves like a private space turns out to be an ordinary account with ordinary logs behind it. The interface promises discretion. The infrastructure has never made that promise.
Legislatures may eventually build an AI privilege. Until one exists, the safe assumption is the one the courts are already making: what you typed is a record, it belongs to the case, and the fact that it felt private when you wrote it carries no legal weight at all.

