Your AI Chats Can Be Subpoenaed
What Court Cases Have Already Shown

Published July 14, 2026 · Updated August 17, 2026

This article is general information, not legal advice. Laws differ by country and are changing quickly. For your own situation, consult a qualified lawyer. Your use of Secret Chat is governed by our Terms of Service and Disclaimers, which explain that you are responsible for your own input and for using the service lawfully.

Most people treat a chatbot like a private diary — somewhere to think out loud, ask embarrassing questions, or work through something personal. The uncomfortable reality, now confirmed by real court cases, is that a conversation stored on a provider's servers is a business record. And business records can be preserved, subpoenaed, and handed to a court — sometimes by the millions, and sometimes without the users ever being told.

Here is what has actually happened in court, what it means for anyone who uses AI, and how to reduce your exposure.

The Case That Changed Everything: 20 Million ChatGPT Logs

The clearest example comes from the copyright lawsuit brought by The New York Times and other publishers against OpenAI.

  • May 13, 2025 — a preservation order. A magistrate judge ordered OpenAI to preserve and segregate all output log data that would otherwise be deleted, over concerns that evidence could be lost. In plain terms: even chats users tried to delete were placed under a legal hold.
  • The scope. Reporting on the order indicated it reached ordinary consumer accounts (Free, Plus, Pro, Team) and standard API usage — while not applying to ChatGPT Enterprise, Education, or API customers with Zero Data Retention contracts.
  • Then, production — and this is a different set of data. On January 5, 2026, District Judge Sidney Stein affirmed an order requiring OpenAI to hand over roughly 20 million ChatGPT conversation logs in de-identified form. It is worth being exact about what that sample was, because the two things are routinely merged: it was a random sample of consumer ChatGPT conversations from December 2022 to November 2024 — not the material swept up by the 2025 preservation hold, and not Business, Enterprise, Edu or API traffic. What put a conversation in it was that it had been retained and fell inside that window; nothing about the user, the subject matter or the account decided it.
  • And the hold has since ended. The going-forward preservation obligation stopped applying to data generated after September 26, 2025, and OpenAI returned to its ordinary deletion practices for new data. What was captured while the order ran stays preserved; conversations originating in the EEA, Switzerland and the UK were carved out of it.

The individual users whose conversations landed in that sample were not personally notified and had no opportunity to object on their own behalf — OpenAI argued their privacy interests, and the court relied on sample reduction, de-identification and a protective order instead. That is the part worth sitting with: the safeguards were real, and no one asked you.

The lesson is not "OpenAI did something unusual." It is that in these orders courts approached AI prompts and outputs much as they approach email, Slack messages and server logs: as records that can be reached by ordinary civil process, subject to the usual arguments about relevance, proportionality and protective orders. If the data exists on a company's servers, a court can order it preserved and produced.

"Deleted" Does Not Mean Gone Under a Legal Hold

The most jarring part of that case is what it revealed about the delete button. When a preservation duty attaches, a legal hold can override a provider's normal deletion. Your "delete conversation" click removes a chat from your view, but while the company is under a court order to preserve data, copies can be retained regardless — held, in OpenAI's description, by a small, audited legal-and-security team rather than made freely available. That is not the permanent condition of every chatbot; it is what happens when a hold lands, and the OpenAI hold ran from May 2025 until it stopped applying to new data on September 26, 2025. The point survives its own expiry: deletion is a user-facing convenience, and a court order outranks it.

AI Chats Have No Privilege — With One Narrow Exception

When you talk to a lawyer, a doctor, or a therapist, the law protects that conversation with privilege. Talking to a chatbot creates no equivalent: there is no attorney-client privilege, no medical or psychotherapy privilege, and no "AI privilege" in its own right. Sam Altman said as much publicly in July 2025, contrasting ChatGPT with therapists and lawyers, noting OpenAI could be compelled to produce sensitive chats, and arguing that an equivalent protection ought to exist.

There is one real exception, and it has grown teeth since. Four courts have protected a litigant's AI chats as work product — the doctrine covering material prepared in anticipation of litigation:

  • Warner v. Gilbarco (E.D. Mich., February 10, 2026) — a self-represented plaintiff's ChatGPT queries were mental impressions; generative AI is a tool, not a person, so using it was not disclosure to a third party.
  • Morgan v. V2X (D. Colo., March 30, 2026) — protected in part, but conditioned on disclosing which AI platforms were used.
  • Tate Group Automotive v. Legacy Automotive Capital (Business Court of Texas, June 3, 2026) — protected for a party represented by counsel, expressly declining to follow the criminal ruling in United States v. Heppner.
  • Assini v. Hayward (Sup. Ct. Nassau County, June 4, 2026) — quashed subpoenas served on OpenAI itself for a self-represented defendant's prompts, uploads and outputs.

Read that exception precisely, because it is narrower than it sounds. It covers chats you created for your own case, and it is fact-specific — no appellate court has ruled, and every one of those decisions distinguished Heppner rather than overruling it. The ordinary conversation you had months before any dispute existed has nothing standing behind it. Practically, such a transcript can be used in civil litigation, a regulatory investigation or a criminal case like any other document, and confiding in it carries none of the confidentiality people assume.

When a Chatbot Becomes the Central Evidence

Chat logs are not just swept up in unrelated cases — sometimes they are the heart of the matter. In Garcia v. Character Technologies (M.D. Fla., No. 6:24-cv-01903), Megan Garcia filed a wrongful-death lawsuit after the death of her 14-year-old son, which she attributed to his interactions with a Character.AI companion bot. On May 21, 2025, Senior Judge Anne Conway allowed most claims to proceed, declining at that stage to treat the chatbot's output as protected speech. The boy's chat logs were central evidence, reviewed by lawyers and referenced in court filings; the case, which also named Google, settled and was dismissed on January 7, 2026, on undisclosed terms. Whatever one thinks of the underlying claims, the case shows starkly that intimate chatbot conversations can end up dissected in a courtroom.

How AI Chats Enter a Case

There is no single door. A stored AI conversation can reach a court through any of the usual routes:

  • A subpoena in civil litigation, demanding records from the provider. This is not hypothetical — in Assini the plaintiffs served exactly such a subpoena on OpenAI, and it took a court ruling to quash it. Note the distinction the headlines blur: the 20-million-log production came from discovery orders against a party, not from a subpoena.
  • Civil discovery, where your own chats are requested by the opposing party.
  • A court order or preservation order, as in the OpenAI case.
  • A search warrant or law-enforcement request in a criminal matter.

And, as the 20-million-log order showed, you can be affected even when you are not a party to the case — your data can be preserved or produced as part of someone else's lawsuit, without notice.

How to Reduce Your Exposure

You cannot control every lawsuit, but you can control how much of a paper trail you leave:

  • Assume it could be read aloud in court. The simplest rule: do not type anything into a consumer chatbot that you would not want a stranger, an opposing lawyer, or a jury to see.
  • Prefer tools that keep no server-side archive. A conversation that is never stored on a company's servers is not sitting there waiting to be preserved or subpoenaed from that company.
  • Use business/API/enterprise tiers for serious work. These generally carry stricter data terms, no-training defaults and configurable retention — and, as the OpenAI order showed, Enterprise, Edu and qualifying Zero Data Retention endpoints fell outside that preservation order's scope. It is a better contract, not immunity: ZDR is approval- and endpoint-dependent, administrators choose retention, some features keep state anyway, and whatever data does exist remains reachable by legal process.
  • Delete — but understand the limit. Deleting still helps in the ordinary course; just do not treat it as erasure once litigation or a hold is involved.
  • Keep the truly sensitive off cloud AI entirely. For anything you genuinely cannot risk surfacing, a chatbot is the wrong place.

How Secret Chat AI Fits — and Its Honest Limits

Secret Chat AI is built around exactly this problem, and it is important to describe both what it does and what it cannot do.

What it does. Secret Chat keeps no server-side archive of your conversations. Your chats and files live only in your own browser's local storage (IndexedDB and OPFS) — as our Terms put it, "we do not have access to this data, and we do not store it on our servers." So there is no chat history on our side to be preserved, subpoenaed, or handed over. On top of that, Secret Chat is an anonymizer: it builds no profile of you, your email is used only for account access and payment (never associated with your prompts), and requests reach the model providers with no name, account, or IP attached — so a log held by a provider is much harder to tie back to a specific person.

What it does not do. Secret Chat is an anonymizer, not a shield against the law and not a content filter. To answer you, the model provider still has to read your prompt, and it may briefly retain it under its own terms — so nothing you send becomes immune to legal process, and this is emphatically not a licence to use AI unlawfully. You are responsible for your own input and for using the service lawfully; Secret Chat is a conduit to third-party models and does not monitor or endorse what you type. Those responsibilities are spelled out in our Disclaimers and Terms of Service. The honest value here is narrow and real: for the ordinary, lawful privacy of ordinary people, keeping no archive and removing your identity means far less of your life is sitting in a database that a court could one day open.

Frequently Asked Questions

  1. Can my AI chats really be subpoenaed?

    Yes — a subpoena was served on OpenAI in Assini v. Hayward, though that one was quashed. Stored conversations can also be preserved and produced through ordinary discovery: a federal court affirmed an order requiring OpenAI to produce a de-identified sample of roughly 20 million consumer ChatGPT conversations from December 2022 to November 2024.

  2. If I delete a conversation, is it safe?

    Not necessarily. Deleting removes a chat from your view, but a legal hold or preservation order can require a provider to keep copies regardless — as OpenAI's did between May and September 2025. Deletion is a convenience, and a court order outranks it.

  3. Are my chatbot conversations privileged like talking to a lawyer?

    No. There is no attorney-client, medical or "AI" privilege in a chatbot conversation. The one exception is narrow: four courts in 2026 protected chats a litigant created for their own case as work product. Ordinary conversations, created before any dispute, have nothing standing behind them.

  4. Does Secret Chat store my chats where they could be subpoenaed from you?

    No. Your conversations and files are stored only in your own browser, not on our servers, so we have no conversation archive to preserve or hand over. The model provider that answers your prompt still processes it under its own terms, and you remain responsible for using the service lawfully — see our Terms and Disclaimers.

  5. Does using an anonymizer let me hide illegal activity?

    No, and you should not try. Secret Chat protects the lawful privacy of ordinary users; it is not a tool to evade the law, it does not make prompts immune to legal process, and you are responsible for your own conduct and content.

Conclusion

The court record is now reasonably clear: AI chats are not private in the legal sense. They can be preserved despite deletion, produced by the millions, and used as evidence — with no privilege to protect them beyond the narrow work-product exception for material you prepared for your own case, and, sometimes, no notice to the people involved. The practical takeaway is simple and slightly old-fashioned: be mindful of what you commit to a machine that keeps records. And where privacy genuinely matters, prefer tools that keep no server-side archive and do not tie your conversations to your name — while remembering that responsibility for lawful use always stays with you.

Sources