Published October 6, 2026 · Facts last verified October 6, 2026
This article is general information, not legal advice. For advice about your own situation, consult a qualified lawyer in your jurisdiction.
On September 26, 2026, a 30-year-old woman from Bonita Springs, Florida, allegedly wrote in a Claude conversation that she was going to “shoot up” the Lee County Sheriff’s Office. According to the arrest report, as described by WINK News, she wrote the next day that she had obtained a new gun.
According to investigators, as reported by WINK News, Anthropic’s automated safety systems flagged the conversation. It was escalated to a human review team, a reviewer judged the threat credible, and Anthropic alerted law enforcement. She was arrested and, on September 30, charged under Florida Statute 836.10 with making a written or electronic threat to kill, do bodily injury, or conduct a mass shooting or act of terrorism. The charge is a second-degree felony. Her arraignment is set for November 2, 2026, according to The Next Web.
The case is pending. She has been charged, not convicted, and is presumed innocent.
According to WINK News, the woman reportedly told deputies she uses AI “like a diary.” That detail matters. A diary does not run automated classifiers over each entry, send selected pages to a review team, or decide that the police should see them. A hosted AI service can do all three.
Lee County Sheriff Carmine Marceno put the law-enforcement view plainly: “Artificial intelligence is a powerful tool, and like any technology, it can be misused. When someone uses AI to make or facilitate a threat, we have to take that seriously.” On the facts alleged here, Anthropic’s decision was very likely the right one. The question is what must exist for that decision to be possible, and what the same machinery means when someone uses a chatbot to write about illness, debt, divorce, grief, or anything else they would once have put in a notebook.
WINK News also reports Marceno saying users are “never truly anonymous” in AI chatrooms. He is right in the sense that matters for this case: the words themselves reach the provider. An anonymous account does not make the content anonymous; someone who writes their own name, town, or target into a message has identified themselves in the message. An anonymizer is not a content protector.
A Chat Window Is Not a Diary
This was not a data leak. The reported sequence—automated screening, escalation, human review, and disclosure—was the safety system working as designed.
Anthropic’s Privacy Policy, effective September 10, 2026, says: “We may share personal data with government authorities, law enforcement, or other third parties where, based on the information available to us, we have a good-faith belief that disclosure is reasonably necessary to (i) comply with applicable law, regulation or legal process … (ii) prevent serious harm to any person or to property …”.
For this route, Anthropic’s own good-faith judgment can be enough. The clause does not say that a subpoena or warrant must arrive first. That is different from an ordinary government demand for user data. Anthropic’s government-requests article, last updated March 16, 2026, says it discloses user information to governments only under valid legal process, such as a subpoena or warrant, except in an emergency that may result in imminent physical harm or death.
The Privacy Policy covers Claude.ai and Anthropic’s consumer products. It also says it does not apply to content Anthropic processes on behalf of customers using its business offerings; customer agreements govern that content. The distinction changes which document applies. It does not mean that sending a prompt through an API switches off automated safety screening.
In fact, Anthropic’s retention article for commercial products, including the API, updated July 1, 2026, says inputs and outputs are automatically deleted within 30 days by default. It then gives a large exception: “We retain inputs and outputs for up to 2 years and trust and safety classification scores for up to 7 years if your chat is flagged by our automated trust and safety systems as violating our Usage Policy”.
So the useful mental model is correspondence handled by a service, not writing locked in a desk. The provider can screen the text. A flag can put it before a person. Under the provider’s policy, a person can decide that preventing serious harm justifies disclosure.
This Is a Pattern Across Providers
Tom’s Hardware counts the Florida matter as at least the third such conversation to reach police since August 2026. One earlier case came from San Antonio. According to News 4 San Antonio, a 22-year-old allegedly told an Anthropic chatbot on August 11: “I’m getting a gun as soon as I can, and when Serna Elementary starts, I’m just gonna walk in there and start shooting up kids”.
On August 28, the FBI’s National Threat Operations Section alerted the Southwest Texas Fusion Center. San Antonio police arrested the man on a third-degree felony terroristic-threat charge. The reports do not explain how the FBI first learned about the conversation, so they do not support saying Anthropic reported him to the FBI. The charge is an allegation, not a conviction.
Nor is this limited to Claude. In a separate 2026 Palm Beach case, OpenAI reviewed ChatGPT conversations and alerted the FBI after a user allegedly described threats against a former partner. We covered that case in OpenAI Reported a ChatGPT User to the FBI. Different facts and policies are involved, but the broader pattern crosses providers: consumer chat systems can classify conversations, put flagged material before human reviewers, and disclose it.
The Reporting Was Probably Right. The Capability Still Matters.
A threat against a specific sheriff’s office, followed the next day by a statement about obtaining a gun, is not an ambiguous example. If the arrest report is accurate, treating it as credible was reasonable. A company does not need to ignore an apparent threat in order to respect the far more ordinary people who use its product.
But the safety judgment depends on infrastructure that sees more than the threat. Automated screening has to look at ordinary conversations in order to find the rare threat among them. The threshold for escalation belongs to the provider, and its policies, models, and review practices can change. Most flagged material will not resemble the allegation in this case so closely. Sarcasm, fiction, quotation, anger, and distressed speech can be harder to interpret. A classifier supplies a probability; a reviewer supplies a judgment.
That is the uncomfortable point. The same route that can help prevent violence begins with routine access to everyone’s text. A person writing about a diagnosis, debt, divorce, grief, or fear is using the same input box and the same provider systems. Calling that box a diary does not change what sits behind it.
Where Secret Chat AI Sits, and Where It Does Not
Secret Chat AI is an anonymizer. It removes you from a query; it does not remove the data you put into the message. Every prompt that passes our classifier goes verbatim from our servers to the provider of the model you chose. If you choose Claude, Anthropic’s API receives the text under our gateway’s credentials, without your name, Secret Chat AI account, or IP address. Whatever the provider holds under its own terms and configuration carries our gateway’s credentials rather than your identity.
That separation is useful, but it is not content protection. Anthropic’s published retention rule for flagged commercial inputs—up to two years for inputs and outputs and up to seven years for trust and safety classification scores—shows why using an API does not disable provider screening. We do not claim that our Anthropic account has a special retention arrangement, and you should not infer one.
A threat like this is refused before it reaches a model
Secret Chat AI screens every prompt with OpenAI’s automated moderation model before sending it to any chosen model. That check is itself a request to OpenAI: the text of every prompt is sent to its moderation endpoint before anything else happens. A short list is blocked on every model and at every setting: sexual content involving minors; threats of violence against a person or group; and instructions for violent wrongdoing such as terrorism or attacks.
A message like the one alleged in the Florida case is exactly what that block is meant to catch. If blocked, it never reaches Claude or any other model, receives no answer, and costs nothing. No classifier catches every possible phrasing, and we do not claim one does.
When the classifier refuses one of those categories, we record that the refusal happened: the category, model, timestamp, and account or session identifier. We never record the prompt text. That metadata is kept for 90 days, is not used for profiling, and is not displayed anywhere in the product.
Secret Chat AI does not automatically report anyone, and we do not report a user on the strength of a classifier score alone. A score is a probability, not a suspicion. Any escalation would be a human decision. Where a law that applies to us requires notifying an authority about a threat to life, we will comply. Our Law Enforcement Guidelines explain what records we hold and how requests are handled.
No chat archive on our side
Chats live in the user’s own browser. On our side, a prompt exists only while we fetch the answer and is deleted as soon as the browser collects it, within 24 hours in every case. We keep no chat archive and no backup containing conversations. Ordinary server logs, which can include an IP address, timestamp, and error code, are kept for no more than 30 days. Queries are never used for training.
This does not make anonymity a form of immunity. It creates no legal privilege, it is not a way to hide or destroy evidence, and it does not put anyone beyond the law. It means no profile and no chat associated with the person exists on our side, while the query reaches the selected model as a stranger’s. The provider still receives the words.
Write for the Answer You Need, Not for the Feeling of a Diary
Treat an AI chat as correspondence with a service. Keep the details that shape the answer—dates, jurisdiction, amounts, sequence, relevant symptoms—and remove names, addresses, employers, account numbers, and other details that merely identify a person. That does not make the text invisible. It reduces the harm if a record exists somewhere you did not expect.
For the most sensitive material, ask whether the model needs it at all. A useful answer often needs “my manager at a small company” rather than the manager’s name and company. A health question may need age range and symptoms, but not a full name and date of birth. An AI cannot forget a detail before receiving it.
If you are in crisis, an AI chat is not where help comes from. Talk to a person who can respond to what is happening now. In the United States, you can call or text 988 to reach the Suicide & Crisis Lifeline.
Frequently Asked Questions
- Does Anthropic report Claude users to the police?
It can. In the Florida case reported by WINK News, Anthropic’s automated systems flagged a Claude conversation, a human reviewer judged the alleged threat credible, and Anthropic alerted law enforcement. Anthropic’s Privacy Policy says it may share personal data when it has a good-faith belief that disclosure is reasonably necessary to prevent serious harm. That does not mean every flag or policy violation is reported.
- Can Anthropic employees read my Claude chats?
Flagged conversations can reach human reviewers, as the reported Florida case demonstrates. Anthropic’s documents also distinguish its consumer products from content processed for business customers, which is governed by customer agreements. The applicable product and terms matter, but an API request is still subject to automated trust and safety screening.
- Can Anthropic share data without a warrant?
Anthropic’s published policy says ordinary government requests require valid legal process, such as a subpoena or warrant, except in an emergency that may result in imminent physical harm or death. Its Privacy Policy separately permits sharing based on Anthropic’s good-faith belief that disclosure is reasonably necessary to prevent serious harm. That describes Anthropic’s policy, not a legal ruling about every possible disclosure.
- Would that message be blocked on Secret Chat AI?
It is meant to be. A threat of violence like the one alleged here is exactly what the always-on block is intended to refuse. Secret Chat AI screens every prompt before it reaches a chosen model. Threats against a person or group and instructions for violent wrongdoing are blocked on every model and setting. A blocked prompt gets no answer, costs nothing, and its text is not recorded. No classifier catches every phrasing, and we do not claim one does.
- Could Secret Chat AI hand over my conversations?
Secret Chat AI keeps no chat archive or backup containing conversations. Prompts are deleted from our side as soon as the browser collects the answer, within 24 hours in every case. We can still hold ordinary server logs for up to 30 days and, for an always-blocked refusal, category, model, timestamp, and account or session identifier for 90 days—never the refused text. Every prompt is sent to OpenAI’s moderation endpoint for screening. The selected model provider also receives allowed prompts verbatim under our gateway’s credentials and may hold them under its own terms and configuration.
- Does a privacy-focused service put me beyond the law?
No. Anonymity is not immunity or legal privilege, and it is not a way to avoid detection, hide conduct, or destroy evidence. Secret Chat AI blocks threats rather than helping them reach a model. Its anonymity promise is narrower: no profile or chat is associated with the person on our side, and allowed queries reach the provider under our gateway’s credentials rather than the user’s identity.
Related reading: OpenAI reported a ChatGPT user to the FBI · does Claude store your conversations · how AI chats can be subpoenaed · a realistic threat model for AI secrets
Sources
- WINK News — Woman arrested after AI threat against Lee County Sheriff's Office: Investigators
- Tom’s Hardware — Anthropic reports Florida woman’s Claude ‘diary’ threat to shoot up sheriff’s office, felony charge follows
- Decrypt — A Florida Woman Used Claude as a Diary. An Anthropic Employee Read It and Reported It to Police (October 5, 2026)
- The Next Web — Florida woman arrested after Anthropic reported her Claude chat to police (October 5, 2026)
- News 4 San Antonio — Man arrested after using AI to threaten elementary school, affidavit says (August 31, 2026)
- Anthropic — Privacy Policy (effective September 10, 2026)
- Anthropic — Policy for handling governmental requests for user information (updated March 16, 2026)
- Anthropic — How long commercial product data is stored (updated July 1, 2026)