Published August 28, 2026
This article is general information, not legal advice. It describes laws, court decisions and official guidance as they stood on the publication date; several of them are moving. For your own situation, consult a qualified lawyer. Your use of Secret Chat is governed by our Terms of Service and Disclaimers.
For most of the short history of chatbots, using one without being identified has been filed under personal taste — something for the privacy-conscious, like a VPN or an ad blocker, that the rest of us could take or leave. That framing is quietly collapsing. In little more than a year, the CEO of the largest AI company has publicly asked for a legal privilege covering conversations with AI; a US state legislature has passed a bill creating one through one chamber; the Supreme Court has held that data you hand to a company can still carry a reasonable expectation of privacy against the government; a New York court has quashed a subpoena served on OpenAI for a litigant's prompts; Europe's regulators have finished writing the test that decides whether "anonymous" means anything; and a German statute already obliges digital services to let you use them anonymously where that is technically feasible. None of that adds up to a right to anonymous AI that you can point to in a statute book today — we will be precise about that. But the direction is clear enough: anonymity in AI use is being argued about in the language of rights and duties, not the language of settings and preferences. This article sets out what has already been decided, what has been demanded and by whom, what is still missing, and why the gap between "right" and "preference" matters to anyone typing a real question into a chatbot this week.
Why the "Preference" Framing Failed
A preference is something you can reasonably be expected to manage yourself. If anonymity is a preference, then the person who did not turn on Temporary Chat, did not opt out of training and did not read the retention policy has simply chosen convenience, and whatever happens to their conversations is on them. That was a comfortable story while chatbots were toys. It stopped being comfortable once people started using them for the things they used to reserve for a doctor, a lawyer or a therapist — and the evidence that they do is not anecdotal: it comes from the company that reads the logs.
In July 2025, Sam Altman said on a podcast that people bring the most personal things in their lives to ChatGPT, and drew the contrast himself: "If you talk to a therapist or a lawyer or a doctor about those problems, there's legal privilege for it." (Those protections are real but not uniform — attorney-client privilege, psychotherapist-patient privilege and physician-patient privilege differ in source, scope and exceptions by jurisdiction; his point was that ChatGPT has none of them.) For ChatGPT, he said, "we haven't figured that out yet," and added that if there were a lawsuit, "OpenAI would be legally required to produce those conversations today. I think that's very screwed up." He was not speaking hypothetically. Two months earlier, on May 13, 2025, a court in the New York Times copyright case had ordered OpenAI to preserve and segregate consumer chat logs that would otherwise have been deleted — including chats their authors had deleted on purpose. That order stopped applying to new data after September 26, 2025, but everything captured while it ran stays preserved. Separately, in January 2026 the court affirmed production of a de-identified sample of 20 million consumer conversations — a random sample from December 2022 to November 2024, drawn from what OpenAI had retained — to the plaintiffs' legal team. The people whose chats were in that sample were not parties to the case, were never individually notified, and had no opportunity to object in the proceedings. Their inclusion turned on nothing about them — only on the conversation having been retained and falling inside the sampled dataset and date range. And the record is still moving: in July 2026 the publishers moved for sanctions, alleging that outputs were deleted despite the order — allegations OpenAI disputes.
That is the moment the "preference" story broke. The people behind twenty million conversations did not make a privacy choice that went wrong. They used a product in the ordinary way, and the record their use created was reached by a process none of them could have opted out of. When the consequence of a design falls on people who had no meaningful way to avoid it, the question stops being "what did the user prefer?" and becomes "what was the provider obliged to build?" — which is the question a right answers and a preference does not.
Anonymity Was Already a Rights Question — Before Chatbots Existed
It is worth noticing that the human-rights system settled the status of anonymity more than seven years before ChatGPT existed. In May 2015, the UN Special Rapporteur on freedom of expression, David Kaye, delivered a report to the Human Rights Council (A/HRC/29/32) on encryption and anonymity. Its conclusion was not hedged: encryption and anonymity "enable individuals to exercise their rights to freedom of opinion and expression in the digital age and, as such, deserve strong protection." The report describes anonymity as creating "a zone of privacy to protect opinion and belief," and observes that the ability "to search the web, develop ideas and communicate securely may be the only way in which many can explore basic aspects of identity, such as one's gender, religion, ethnicity, national origin or sexuality."
Read that sentence again with a chatbot in mind. Searching, developing ideas and exploring questions of identity is a precise description of what people now do with AI — the report simply predates the tool. Its recommendations to states are the part that matters for our argument: restrictions on anonymity "must be strictly limited according to principles of legality, necessity, proportionality and legitimacy in objective"; "blanket prohibitions fail to be necessary and proportionate"; and states "should refrain from making the identification of users a condition for access to digital communications and online services." The report adds, in the same paragraph, that "corporate actors should likewise consider their own policies that restrict encryption and anonymity (including through the use of pseudonyms)."
A Special Rapporteur's report is not binding law. But it is the UN system's considered statement of how the existing right to privacy (Article 17 of the International Covenant on Civil and Political Rights) and the right to freedom of opinion and expression apply to anonymous use of online services — and it frames anonymity as something the right protects, not as a lifestyle choice the right tolerates. The United States reached a version of it earlier still, by a different route: in McIntyre v. Ohio Elections Commission (1995) the Supreme Court held that anonymous pamphleteering "is not a pernicious, fraudulent practice, but an honorable tradition of advocacy and of dissent" and that "anonymity is a shield from the tyranny of the majority" — a First Amendment protection for anonymous speaking, not for anonymous asking, but the nearest constitutional root the American conversation has. The chatbot industry arrived into a legal culture that had already reached these conclusions. What is happening now is that they are catching up with the new tool.
Europe: Not Identifying You Is Already a Legal Default
In the European Union, data protection is a fundamental right in its own name. Article 8 of the Charter of Fundamental Rights opens with "everyone has the right to the protection of personal data concerning him or her," and requires that such data be "processed fairly for specified purposes." The GDPR is the statute that gives that right teeth, and three of its provisions together come close to making non-identification the legal default whenever identification is not needed.
- Data minimisation (Article 5(1)(c)) — personal data must be "adequate, relevant and limited to what is necessary" for the purpose. An AI service that needs your prompt to answer you does not, for that purpose, need your prompt tied to your name.
- Data protection by design and by default (Article 25) — the controller must implement measures "such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation," and must ensure "that, by default, only personal data which are necessary for each specific purpose of the processing are processed." That obligation, the article says, "applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility." By default. Not on request, and not as a premium tier.
- Processing which does not require identification (Article 11) — where a controller's purposes "do not or do no longer require the identification of a data subject," the controller "shall not be obliged to maintain, acquire or process additional information in order to identify the data subject." The GDPR, in other words, explicitly contemplates services that answer you without knowing who you are, and tells them they need not build the identity link merely to satisfy the regulation.
None of these says "chatbots must be anonymous." They are qualified — Article 25 opens with "taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing," and a provider can argue that identification is necessary for billing, abuse prevention or safety. But the burden sits where a right puts it: on the provider, which must be able to demonstrate (Article 5(2)) that the link is necessary, not on the user to opt out of it. That is the structural difference between a right and a preference, written into the statute.
Germany goes one step further and says it in plain words. Section 19(2) of the TDDDG — Germany's privacy statute for telecommunications and digital services — provides that providers "haben die Nutzung von digitalen Diensten und ihre Bezahlung anonym oder unter Pseudonym zu ermöglichen, soweit dies technisch möglich und zumutbar ist": they must make it possible to use digital services, and to pay for them, anonymously or under a pseudonym, wherever that is technically feasible and reasonable — and must inform users of the option. The wording goes back to Germany's first teleservices data-protection law of 1997 and has survived every renaming of the statute since; it is a statutory duty on providers to offer anonymous use, and it is technology-neutral, so an AI chatbot within its scope is a digital service like any other — though we know of no published decision yet applying it to one. Germany also gave the wider idea its name: the Federal Constitutional Court's census judgment of December 15, 1983 recognised a right to "informational self-determination" — the individual's power, in principle, to decide for themselves on the disclosure and use of their personal data — which is the constitutional root from which the GDPR's design grew.
What the EU has not done deserves equal precision, because the AI Act is often assumed to cover this and does not. Since August 2, 2026, Article 50 of the AI Act requires that people be told they are interacting with an AI system unless that is obvious to a reasonably well-informed person. That is a right to know you are talking to a machine — not a right for the machine not to know you. The Act imposes no anonymity requirement, no restriction on tying prompts to accounts, no retention limit and no bar on training on conversations; those questions belong to the GDPR, with the GDPR's conditions and exceptions attached. Our plain-English AI Act guide goes through that gap in detail.
The Regulator Has Now Defined What "Anonymous" Has to Mean
A right is only as good as the definition of the thing it protects, and "anonymous" has been the loosest word in the privacy industry for years — applied to everything from a stripped account ID to a hashed email. In July 2026 the European Data Protection Board adopted draft Guidelines 02/2026 on anonymisation, intended to replace guidance that has stood since 2014, with public consultation open until October 30, 2026. Following the Court of Justice's EDPS v SRB judgment of September 4, 2025, the guidelines treat anonymity as relative and contextual: the test is whether anyone with realistic means could isolate a record, link it to other data, or infer something about an identifiable person — the draft's three criteria are no record isolation, no linkage and no inference — and the same data can be anonymous in one party's hands and personal data in another's. Separately, EDPB Opinion 28/2024 had already established that an AI model trained on personal data cannot be assumed anonymous merely because it is a model.
This cuts in two directions, and both matter. It raises the bar for marketing: a service cannot call a prompt "anonymous" because it removed the account name if the prompt itself says who you are. And it makes the word usable: once "anonymous" has a test, the question "did this service actually sever the link?" becomes something a regulator can ask and answer, which is the precondition for any right to it being enforceable. We say more below about how we use the word ourselves, because the honest answer to the new test is precision.
The United States: Courts Move, Legislatures Try
The American story has no GDPR in it, so it is being written case by case — and 2026 produced more movement than the previous five years combined.
The Supreme Court. On June 29, 2026, in Chatrie v. United States, the Court held that police conducted a Fourth Amendment search when they acquired a person's location history from Google. The old "third-party doctrine" — that you have no constitutional interest in information you voluntarily hand to a company — did not apply, the Court said, to information "a user reasonably understands as his own, even though stored on Google's servers — much like his emails, photos, and calendar entries," which is "not truly shared, in the normal sense of wanting a third party to see or use it." Chatrie decided nothing about AI prompts, constrains the government rather than private litigants, and expressly left the good-faith exception open. But its stated reason describes a typed question to a chatbot at least as well as it describes a location ping, and, for government searches at least, it takes away the easiest argument against treating AI conversations as constitutionally protected: that by sending them to a company you gave up any interest in them. That is direction of travel, not protection — and it is the direction a right travels in.
The trial courts. Whether your AI chats can be demanded by the other side in a lawsuit has now been decided, in different ways, by eight trial courts, and the results turn mainly on whether a lawyer directed the AI use — the full survey is in our privilege article. Two rulings belong here. In United States v. Heppner (S.D.N.Y., February 10, 2026), Judge Rakoff held that a represented criminal defendant's self-directed Claude sessions were protected by neither privilege nor work product — the protection never attached, in part because Anthropic's consumer terms, permitting collection and disclosure of inputs, defeated any reasonable expectation of confidentiality. In other words, the identity-linked, provider-retained record was itself part of the reason the court found no confidentiality. And in Assini v. Hayward (Sup. Ct. Nassau County, June 4, 2026), a New York court quashed a subpoena served on OpenAI for a pro se litigant's prompts and outputs used to prepare his filings, finding the reasoning of earlier work-product decisions persuasive. A court refusing to let one side reach into a chatbot provider's records for the other side's thinking is, in practice, what a right to confidential AI use looks like on the day it is enforced.
The legislatures. The clearest sign that this has become a rights conversation is that someone tried to write the right down. In January 2026, Arizona Representative Alexander Kolodin introduced HB 2410, "Artificial intelligence; privileged communications." Its operative text is one sentence: "A person's communication with an artificial intelligence is privileged if the person would have been entitled to privileged communication had the person sought the advice from a human professional." It passed the Arizona House on a 53-4 vote on that wording, then was held without a vote in the Senate Judiciary Committee on March 11, 2026, and died with the session. A bill that passes one chamber and dies in the next is not a right. It is the first draft of one, and first drafts are how rights usually start.
The industry. The demand is not coming only from users and civil-liberties groups. On June 5, 2025, responding to the New York Times preservation order, Altman wrote that OpenAI had "been thinking recently about the need for something like 'AI privilege'" and that "talking to an AI should be like talking to a lawyer or a doctor." It is fair to read that with some scepticism — a privilege would also shield the company from expensive discovery — but the fact stands: the provider whose logs are most often demanded is on record asking for a legal right of confidentiality in AI conversations. When the people who hold the archive say the archive should be legally out of reach, the "preference" framing has lost its last defender.
What Is Still Missing — Stated Plainly
An article arguing that something is becoming a right owes the reader a clear account of how far it has not yet become one. As of August 2026:
- No statute anywhere names AI chatbots and grants a right to use them anonymously. Germany's provider duty is the closest thing — technology-neutral, so it reaches a chatbot as it reaches any digital service in its scope — but it is qualified by technical feasibility and reasonableness, and no published decision we know of has yet applied it to one. The GDPR makes non-identification a default where identification is unnecessary; it does not stop a provider from concluding that identification is necessary for a purpose it can defend — necessity is scrutinised, not self-declared, but the argument is left open.
- No court has created an "AI privilege." No published ruling we know of has held that a standalone user–chatbot conversation is covered by attorney-client privilege merely because it concerns legal problems. The protective decisions are work-product rulings — a narrower doctrine that turns on anticipated litigation and who prepared the material — and Heppner shows how easily protection fails to attach at all. Arizona's bill died. Privilege still comes from a lawyer, not from software.
- Chatrie is a Fourth Amendment case about the government. It says nothing about the civil subpoena, the discovery request or the provider's own retention policy — the three mechanisms through which nearly all real-world exposure of AI chats actually happens.
- The EDPB guidelines are a draft, in consultation until October 30, 2026, and they define anonymity strictly enough that most services calling themselves "anonymous" today would have to explain precisely which link they severed.
- Nothing on the horizon un-does what has already happened. A right, when it arrives, will mostly govern future conduct. Stored account data can already be reached by existing erasure rights, with their conditions; but the 20 million conversations already produced, the archives already built and the training runs already completed are not reversed by a new right.
So the honest summary is this: the right exists in the general form — privacy, data protection, freedom of opinion, the Fourth Amendment's reasonable expectations — and is being applied to AI one decision at a time; the specific right to anonymous AI is being demanded, drafted and litigated, and has not yet been granted in terms. "Becoming" is the accurate word. "Is" would be a lie, and "merely a preference" is now an outdated one.
Why the Distinction Changes What You Should Expect
Whether anonymity is a right or a preference decides who carries the burden, and that has three practical consequences for anyone using AI today.
First, defaults are the battleground. A preference is honoured when the user finds the toggle; a right is honoured when the product ships that way. Article 25's "by default" is the legal expression of that difference, and it is why the fights of the next two years will be about what a chatbot does when you do nothing — whether training is on, whether memory is on, whether the account is the key to the archive — rather than about whether a setting exists somewhere in a menu. Our guides to opting out of training and the settings that matter are, in this framing, instructions for living in a world where anonymity is still a preference.
Second, the link is what a right can protect; the words are not. Every legal development above — minimisation, design-by-default, Article 11, Chatrie's "not truly shared," the EDPB's isolation-and-linkage test, Arizona's privilege bill — operates on the association between a person and a record. None of them, and no future right, can make a message containing your name, your diagnosis or your case number anonymous, because the identification is inside the content. A right to anonymous AI, when it matures, will be a right not to be linked; it will not be a right to be careless.
Third, architecture is how a right gets delivered before the law requires it. Rights in the digital world have repeatedly been realised by engineering first and statute second — encryption was a "preference" of the technically literate for two decades before Kaye's report described it as a condition of free expression. A service that never builds the identity link is not waiting for a court to order the link severed. It has simply built the thing the right will one day require, and the structural fact that follows is the same fact that made the 20 million-conversation sample possible in reverse: what is never stored and never linked cannot be preserved, sampled, subpoenaed or trained on.
How Secret Chat AI Fits — and Its Honest Limits
Secret Chat AI is built on the position this article argues for: that not identifying you is the default a service should ship, not a setting you should have to find. It creates no profile of you, associates no chat with your identity, and passes your queries to the top models — GPT, Claude, Gemini, Grok, Perplexity and DeepSeek — anonymously; your queries are never used for training. Your email is used only for account access and payment and is never linked to your prompts. Chats live only in your own browser, and a prompt exists on our side only for as long as it takes to fetch your answer — there is no stored chat archive on our servers, which means there is nothing on our side for a preservation order to freeze or a sample to be drawn from. Whatever a model provider holds under its own terms and configuration, the record on that side carries our gateway's credentials and server address — not your name, your account or your IP. You use the model as a stranger. We keep ordinary infrastructure telemetry — IP addresses, request timestamps and error codes — for at most 30 days; that is not a record of what you asked.
The same precision the EDPB now demands of the word applies to us. "Anonymously" describes the link, not the words: no account identifier travels with your prompt. It is not a claim that the text stops being identifying — write your own name or your case number into a message and it is all still sitting there in the message, and under the GDPR's contextual test that content is not anonymous however it was routed. Secret Chat AI removes you from your queries — it does not remove the data from your messages. Redacting identifying details before sending is your responsibility, and pasting someone else's personal data makes you responsible for that disclosure. Anonymity is not privilege, not a legal exemption and not a licence to hide anything a court is entitled to: no AI service, ours included, creates attorney-client privilege, and a party's own duty to preserve relevant material is unaffected by the tool they used. GDPR roles follow what a service actually does, not what it calls itself — saying we are not sold as an enterprise processor arrangement describes what we offer, not a legal spell preventing a regulator from characterising the processing otherwise.
What we offer against the gap this article describes is narrower than a right and real: a service that never builds the linked archive has structurally less to hand over, lose or train on — today, whatever the law eventually says.
Frequently Asked Questions
- Is there a legal right to use AI anonymously?
Not as a specific, named right in any statute we know of. What exists is the general architecture: privacy and data protection are fundamental rights in the EU, the GDPR makes non-identification the default where identification is not necessary (Articles 5(1)(c), 11 and 25), Germany obliges digital-service providers to enable anonymous or pseudonymous use where technically feasible (§ 19(2) TDDDG), and the UN Special Rapporteur's 2015 report treats anonymity as protected by the rights to privacy and free expression. A specific right to anonymous AI is being argued for, drafted and litigated — it has not yet been granted in terms.
- Did Sam Altman really say AI conversations should be privileged?
Yes, twice in public. On June 5, 2025, responding to the court order preserving ChatGPT logs in the New York Times case, he wrote that OpenAI had been "thinking recently about the need for something like 'AI privilege'" and that "talking to an AI should be like talking to a lawyer or a doctor." In July 2025 he said on a podcast that there is legal privilege for a therapist, lawyer or doctor, that "we haven't figured that out yet for when you talk to ChatGPT," and that OpenAI "would be legally required to produce those conversations today" in a lawsuit — a situation he called "very screwed up." Neither statement created any legal protection; both are the provider itself asking for one.
- Has any US state passed an AI privilege law?
Not as of August 2026. The closest attempt was Arizona's HB 2410, "Artificial intelligence; privileged communications," introduced in January 2026, which would have treated communications with an AI system as privileged where the same communication with a human professional would be. It passed the Arizona House 53-4 but was held without a vote in the Senate Judiciary Committee on March 11, 2026, and died with the session.
- What did the Supreme Court decide in Chatrie, and does it cover chatbot prompts?
In Chatrie v. United States (June 29, 2026) the Court held that police conducted a Fourth Amendment search when they obtained a person's location history from Google, because the third-party doctrine does not apply to information a user "reasonably understands as his own, even though stored on Google's servers." It decided nothing about AI prompts, binds the government rather than private litigants, and left the good-faith exception open. Its reasoning is favourable to treating typed prompts as protected — that is direction of travel, not protection.
- Does the EU AI Act require chatbots to be anonymous?
No. Article 50, applying since August 2, 2026, requires that you be told you are interacting with an AI system unless that is obvious. It imposes no anonymity requirement, no limit on tying prompts to accounts, no retention limit and no restriction on training on conversations. Those questions are governed by the GDPR, whose data-minimisation and by-default rules push toward non-identification but are qualified and do not forbid a provider from justifying the link.
- If anonymity becomes a right, will my old chats be protected?
A right, when it arrives, will mostly govern future conduct. It would not reverse the preservation orders already executed, the samples already produced, the archives already built or the training runs already completed. That is why sending less identifying detail now, and using services that never link chats to your identity, matters more than any ruling that may come later — the conversation hardest for any future process to reach is the one that never created a linked record.
Conclusion
Preferences are things you adjust; rights are things you are owed. For years the industry's answer to "can I use AI without being identified?" was a settings page, and the burden of finding it was yours. What 2025 and 2026 have changed is not the technology but the question's category. A UN rapporteur had already called anonymity a condition of free expression; the GDPR already made non-identification the default where identification is unnecessary; Germany already required providers to offer it. Now the largest AI company's CEO has asked for a privilege, a state legislature has passed a bill creating one through one chamber, the Supreme Court has said that data on a company's server can still be yours, a court has quashed a subpoena on OpenAI, and the regulator has written the test that decides whether "anonymous" is true. None of it is finished, and we have tried to say exactly where each piece stops. But one thing has changed for good: it is getting hard to describe anonymity in AI use as a hobby of the careful. It is being described as something people are entitled to — and, until the law catches up, something the architecture of the service you choose either delivers or does not.
Sources
- UN Human Rights Council — Report of the Special Rapporteur on freedom of opinion and expression, David Kaye, A/HRC/29/32 (May 22, 2015), on encryption and anonymity (PDF mirror)
- EU Agency for Fundamental Rights — Charter of Fundamental Rights, Article 8: Protection of personal data
- GDPR Article 25 — Data protection by design and by default
- GDPR Article 11 — Processing which does not require identification
- § 19 TDDDG — Technische und organisatorische Vorkehrungen (German statute text, incl. paragraph 2 on anonymous or pseudonymous use)
- Bundesverfassungsgericht — Judgment of December 15, 1983 (census judgment; right to informational self-determination)
- European Data Protection Board — Guidelines 02/2026 on anonymisation (public consultation until October 30, 2026)
- Cornell LII — McIntyre v. Ohio Elections Commission, 514 U.S. 334 (1995), opinion of the Court
- Norton Rose Fulbright — AI in litigation: NY State Court weighs in on GenAI privilege (Assini v Hayward, July 2026)
- Supreme Court of the United States — Chatrie v. United States, No. 25-112 (June 29, 2026), slip opinion
- TechCrunch — Sam Altman warns there's no legal confidentiality when using ChatGPT as a therapist (July 25, 2025)
- Sam Altman on X — the "AI privilege" post (June 5, 2025)
- Arizona Legislature — HB 2410 (2026), "Artificial intelligence; privileged communications", House-engrossed text
- Arizona House Majority Research Staff — HB 2410 House-engrossed summary (sponsor, committee and Third Read votes)
- BillTrack50 — Arizona HB 2410 (2026): action history incl. the Senate Judiciary hold of March 11, 2026