Published August 17, 2026 · Facts last verified August 17, 2026
This article is general information, not legal advice. Immigration law is unforgiving of guesswork — for your own situation, talk to a licensed immigration lawyer or a DOJ-accredited representative, not a chatbot. Your use of Secret Chat is governed by our Terms of Service and Disclaimers, which make clear that you are responsible for your own input and for using the service lawfully.
The question is nearly always typed at night, and it is nearly always some version of the same three sentences. "I overstayed my J-1 by six weeks in 2019. I'm applying for a green card through my husband next year. Do I have to bring it up — and what happens if I don't?"
There is no colleague you can ask that. Your husband is the one person you least want to worry. The lawyer costs money you are saving for the filing fees. And the chat window is right there — patient, fluent in immigration law, open at 2am. So you type it, into an account that carries your name, your email address, and a payment card with your billing address on it.
Here is the thing worth stopping on before you press Enter. Of all the people who confide in AI chatbots — the sick, the indebted, the divorcing — the visa applicant is the only one whose questioner is also, in a real sense, the audience. The government you are about to petition has spent the last several years building a program whose explicit purpose is to read applicants' online lives. Your AI account is not on its reading list today. The trajectory of that list is the subject of this article.
Five Years of Handles: How Visa Vetting Learned to Read
None of what follows is speculative. Every step below is announced policy, published by the agency that adopted it.
- Since May 2019, the DS-160 visa application form has required nearly all applicants to list every social media handle they have used in the previous five years — including accounts that are inactive, deactivated or deleted.
- In June 2025, the State Department resumed student visa interviews with a new instruction attached: F, M and J applicants — students and exchange visitors — must set their social media profiles to public so consular officers can review them. "Comprehensive and thorough vetting" is the department's own phrase.
- In December 2025, the same online-presence review was extended to H-1B workers and their H-4 dependents — the backbone of skilled employment immigration.
- On March 30, 2026, it was extended again, to fourteen more categories — the third and largest expansion so far, counted by categories added: fiancés, fiancées and certain spouses of US citizens, religious workers, trainees, cultural exchange visitors — and, notably, T and U visa applicants, who are by definition victims of trafficking and of serious crime.
- USCIS, which handles applications filed from inside the country, published a Federal Register notice on March 5, 2025 proposing to collect social media identifiers on nine of its forms — naturalization, adjustment of status, asylum among them — with an estimated 3.5 million respondents a year. It went through a public comment period rather than taking effect immediately, and the Office of Management and Budget approved the collection in February 2026. In April 2025 USCIS announced social media screening for antisemitic activity; in August 2025 it said it would weigh "anti-American" activity as a negative factor in the benefit decisions where it has discretion.
- In March 2025, according to reporting by Axios rather than any announcement of its own, the State Department began an AI-assisted review of visa holders' social media and other public information — known internally as "Catch and Revoke" and aimed first at students. Its precise scope has never been published, which is itself part of the problem: several thousand student visas have been revoked since, and applicants cannot see the standard being applied to them.
Set aside what anyone thinks of the policies. Read them purely as a description of capability and appetite, and they say something simple: the United States government now considers an applicant's online writing to be evidence about the applicant, has built automated tooling to read it at scale, and has widened the net repeatedly — three times in the ten months to March 2026 alone. No form asks for your ChatGPT handle. In 2018, no form asked for your Instagram either.
The Phone at the Border Is the Short Way In
Vetting reads what is public. At the border, the reach is longer, and it is worth being precise about it, because this is the one place where the contents of a private account meet a government officer directly.
In fiscal year 2025, Customs and Border Protection searched a record 55,318 travelers' electronic devices — up 17.6 percent on the year before, and up by a third on 2023. Kept in proportion: that is around 0.01 percent of all travelers processed, so the odds for any given person remain small. But three-quarters of those searched were not US citizens, and the rules are not symmetrical. A US citizen cannot be denied entry for refusing to unlock a phone, though the device itself can be detained. A visa holder or visitor refusing the same request runs a risk a citizen does not: admission is discretionary, an incomplete inspection counts against them, and they can be refused entry. Most searches are "basic" — an officer scrolling through the device by hand, which under CBP's own rules requires no suspicion at all; the forensic kind, where equipment is attached to copy and analyse the contents, requires reasonable suspicion and a senior manager's approval. CBP's directive confines the search to data resident on the device and tells officers to disable network connectivity where practicable, so material that lives only in a cloud account is out of reach — but whatever a chat app has cached locally is, at that moment, data on the device. An officer holding your unlocked phone reads those conversations the way they read your texts: by opening the app.
If that sounds theoretical, consider what happened to Alistair Kitchen, an Australian writer who flew from Melbourne on June 12, 2025 and was pulled aside during his Los Angeles layover. By his account, an officer told him exactly why: "It's because of what you wrote online about the protests at Columbia University" — reporting he had published on his own blog and deleted before the flight. The rest of the sequence is his account too, reported by the Committee to Protect Journalists and the U.S. Press Freedom Tracker rather than independently established: held for twelve hours, laptop seized, and told that refusing to hand over his phone passcode meant deportation. He complied. Officers searched the phone, said they had found references to drug use but never showed him what they had, and questioned him until he acknowledged prior marijuana use. He was refused entry and flown home. The government's official position is that he was denied entry not for his writing but because he had answered the drug question on his travel authorization falsely — that is, the stated ground for refusing him was the gap between a government form and what his phone was said to contain.
Notice the two lessons that case actually teaches, because they are not the ones usually drawn from it. First, deleting before you fly did not help him: the posts were gone, and the vetting had already read them. Second, whatever the true motive, the phone supplied the material. The record that ends a trip is rarely created at the border. It is created months earlier, at home, in an app that felt private, and then it travels with you into the one jurisdiction where you have the fewest rights of anyone in the room.
The Long Way In: The Account Itself
The border only reaches what you carry. A named cloud AI account is reachable without you, and three facts about it do all the work.
It is stored. A consumer AI account is a running transcript attached to your identity — name, email, phone number, payment method. We have covered what ChatGPT retains and what the temporary modes really promise; the short version is that the transcript exists, and deletion is a policy the provider applies, not a law of nature. In the New York Times litigation, a court first ordered OpenAI to preserve conversations that would otherwise have been deleted, then ordered production of a de-identified sample of 20 million consumer conversations — belonging to people with no connection to the case, who were not notified and had no chance to object. The sample was de-identified and covered by a protective order, so this is not a story about reporters browsing your chats at leisure. It is a story about the fact that whether your conversation was in that set turned on nothing you did, knew about, or could have prevented.
It is not privileged. In United States v. Heppner (S.D.N.Y., February 10, 2026), a federal judge held that a defendant's chatbot-drafted defense documents were protected by neither attorney-client privilege nor work product. The distinction matters: the protection never attached in the first place, rather than being lost along the way. Privilege failed because a chatbot is not a lawyer and the consumer terms defeated any reasonable expectation of confidentiality; work product failed for a separate reason — the defendant had gone to the tool on his own initiative rather than at his counsel's direction, so the output reflected no lawyer's strategy. The judge allowed that counsel-directed use might have looked different, which is a hint for lawyers, not a safe harbour for anyone else. A few civil courts have protected AI-assisted litigation preparation under the narrower work-product doctrine — one New York court even quashed a subpoena served on OpenAI for a litigant's whole account — but that doctrine turns on a lawsuit being anticipated and says nothing about the question you asked years before you had a case. The full picture is in our article on AI and privilege and on subpoenas.
It is read by the provider. Consumer AI conversations are continuously machine-classified, and flagged ones are read by human reviewers — that is how safety systems work, and it is documented policy, not a leak. In one 2026 case, OpenAI referred a user's conversations to the FBI, and two months of his chat logs ended up with a county sheriff's office. The referral was, on those facts, probably right — we wrote about the case at length — but the capability it demonstrates does not switch off for anyone else. A transcript that can be reviewed and referred is a transcript that exists, is linked to you, and is one policy decision away from an audience you did not choose.
For honesty's sake, the boundary of the argument: the immigration cases documented so far run on phones and public posts, not on subpoenas to AI providers, and we know of no visa decision that has turned on a chat log. The point is not a precedent. The point is that the transcript, the identity link and the legal reachability all exist today, while the vetting net has widened every year since 2019 — and records, unlike policies, are retroactive. What is written into a named account now is available to whatever the rules become later.
Why Immigration Questions Are Radioactive in Particular
Every sensitive topic produces regrettable records. Immigration produces a specific kind, and it is worth seeing why this category is worse than almost any other.
- Intent is the legal substance. Much of immigration law adjudicates state of mind: whether you secretly intend to stay, whether a marriage is genuine, whether a misstatement was willful, whether your character is "good" within the meaning of the statute. Ordinary people research their options in exactly the words that read worst later — "can I stay if I marry my girlfriend", "what happens if I overstay", "will they find out about my job". Asked out of anxiety, recorded as planning. A question about intent, written down, is evidence of intent — and unlike most evidence, you manufactured it yourself, timestamped, in the first person.
- The question gives away what the question is about. "Do I have to disclose the arrest" concedes that there is an arrest. "Does the ESTA drug question cover something I did years ago" concedes the something — the very subject that, checked against a phone, ended Alistair Kitchen's trip. To be precise, a chat message is not an "admission" in the technical immigration sense: that is a term of art with real procedural requirements, and a stray sentence to a chatbot does not qualify. It does not need to. Under US law a validly made admission of certain conduct can carry consequences with no conviction at all — and well short of that, a written question is a lead: a documented reason to ask you the same thing somewhere it does count.
- The person whose status is at stake usually has the weakest position in the room. Not always the one typing — US citizens research this constantly, as petitioners for a spouse or a parent, and they carry their own exposure. But where the applicant is the one asking, they are a non-citizen at the border and in front of the caseworker: discretion runs against ambiguity, declining to unlock a phone costs them something it would not cost a citizen, and much of what is decided about them is decided without a hearing.
- The timeline is measured in years. An immigration life is long: a status question today, a petition in two years, naturalization in seven. A chat transcript with no expiry date sits across that entire span, waiting to be inconsistent with something you will one day sign under penalty of perjury.
The Line This Article Will Not Cross
Before the practical part, the part that has to be said plainly, because "keep it off the record" can be read two ways and only one of them is ours.
This article is about not generating gratuitous, permanent, identity-linked records of lawful private thinking — the anxious 2am research of a person trying to understand their own situation. That is ordinary privacy, and a visa applicant is entitled to it like everyone else.
It is not about defeating vetting, and nothing here does. Answer every government form truthfully, including the social media questions and the drug questions — the surest way to turn a survivable problem into a far worse one is to lie about it, because a material misrepresentation is its own ground of inadmissibility, it carries no time limit of its own, and the waivers that exist for it are narrow and discretionary. Do not delete or withhold anything you have a legal duty to preserve or disclose. And if you already know your history contains a real problem — an overstay, an arrest, a prior refusal — the answer is not a cleverer search engine. It is a licensed immigration lawyer, who has seen your problem a hundred times, knows which waivers exist, and is the one adviser the law actually lets you speak to in confidence. Secret Chat does not clean your social media, does not launder your history, and is not a way to say things to a consulate's face that are false. It is a way to ask your questions without filing them under your name.
Keeping the Question From Becoming a Record: What Actually Works
1. Never ask from an account that knows who you are
The single decision that matters most. An immigration question in a named cloud account is a signed, timestamped statement about your status, stored by a third party, linked to your email, your payment card and — even without an account — your device. That includes the university Google or ChatGPT account your school administers (foreign students: your school is also your visa sponsor), and it doubly includes anything your employer runs if your status depends on that employer. Ask somewhere that builds no profile and keeps no archive — or at minimum, somewhere that is yours alone.
2. Ask the general question, not the identifying one
Nearly all of the value is in the general answer. How overstays are treated, how a waiver works, what a consular officer may consider, what "good moral character" means — none of it needs your name, your dates, your case number or your husband's employer. Round the numbers, drop the names, and the record that remains — anywhere — is a person who once asked how immigration law works, which is not evidence of anything. A prompt that makes this the default:
I want to understand a US immigration topic in general terms. I will describe a hypothetical situation with round numbers and no real names, dates or places, and I would like you to answer about how the law generally treats such cases rather than asking me for identifying details. If a specific detail genuinely changes the answer, tell me which one and why, so I can raise it with a licensed immigration lawyer. Here is the situation:
3. Do not upload the documents
A typed summary is a paraphrase; an uploaded file is the original. Passports, I-94s, visa stamps, RFEs, sponsor letters and old filings carry names, numbers, addresses and case identifiers on every page — and a scan or a photograph can carry metadata of its own. If you need a document explained, retype the sentence that confuses you. And remember that pasting in your sponsor's, your spouse's or your employer's details discloses their data, which is your responsibility, not the tool's.
4. Think about what crosses the border with you
A border search reads the device, so the device is what you curate. Know what your apps show when opened — chat histories, photo libraries, deleted-message folders. This cuts in every direction, including ours: Secret Chat keeps your chats in your own browser, on your own device, which means they too are readable by anyone holding that device unlocked — the difference is that deleting them locally is real, because there is no server copy behind them. Travel with a device you would be comfortable opening in front of a stranger, and treat that as ordinary hygiene done well in advance — not as something to be arranged in the security line, and never as a way to defeat a duty to preserve evidence you actually have.
5. Keep the real case with a human who owes you confidentiality
Use AI to learn the vocabulary, the process, the questions worth asking — it is genuinely good at that, and arriving informed makes the paid hour cheaper. Then take the actual case to a licensed immigration lawyer or a DOJ-accredited representative. That is the only place privilege exists — no AI tool creates it, ours included — and immigration is a field where the general answer is reliably wrong about the specific case in ways only someone who has read your file can catch.
6. Assume the record outlives the application
Whatever you write into any system, ask the one question that reliably helps: if this surfaced in five years, next to a date stamp, while an officer compared it with my sworn forms — what would it look like? Five years is not hypothetical. It is the lookback window printed on the form.
How Secret Chat AI Fits — and Its Honest Limits
Secret Chat AI exists for exactly the conversation this article opened with, and precision about what it does and does not do matters more here than anywhere.
What it does. It builds no profile of you. No chat is ever associated with you. Your conversations live only in your own browser, and a prompt exists on our side only for as long as it takes to fetch your answer — there is no stored chat archive on our servers, nothing to accumulate into a dossier about your status, and nothing here for anyone to demand from us later. Your queries reach the top LLMs anonymously, and they are never used for training. Registration takes an email, but it is used only for account access and payment — never stored against your prompts or associated with them. Whatever a model provider holds under its own terms and configuration, the record on that side carries our gateway's credentials and server address, not your name, your account or your IP. You use the model as a stranger — which, for a person whose next few years depend on a government file, is the entire point.
What it does not do. Secret Chat AI removes you from your queries — it does not remove the data from your messages. "Anonymously" describes the link, not the words: no account identifier travels with your prompt, but write your A-number, your full name or your case history into a message and it is all still sitting there in the message, reaching the provider verbatim. Redacting identifying details before you send is your responsibility — that is what step 2 is for. It does not make your public social media private, does not alter what vetting can lawfully read, does not help you answer a form falsely, and does not change what is stored on a device an officer is holding — the local history in your browser is yours to manage, and step 4 explains how to think about it. We keep ordinary infrastructure telemetry — IP addresses, request timestamps and error codes — for at most 30 days, as our privacy policy sets out; that is not a record of what you asked. And anonymity is not privilege, not a legal exemption, and not a licence to hide anything a court or an agency is lawfully entitled to: only a lawyer creates privilege, your duties of truthful disclosure stand whatever tool you use, and the honest, narrow value is exactly this — the lawful private research of people at the most scrutinized moment of their lives no longer accumulates in a database with their name on it.
Frequently Asked Questions
- Can US immigration officers read my ChatGPT conversations?
Not from the provider as a routine matter — visa vetting reviews public information like social media profiles, and no form collects AI account handles today. But at the border, officers can search the device you carry without a warrant, and a signed-in AI app or browser session shows whatever history it holds. In fiscal year 2025 CBP searched a record 55,318 devices, three-quarters of them belonging to non-citizens.
- Do visa applications ask about AI chatbot accounts?
No. The DS-160 collects social media identifiers used in the past five years, and since 2025–2026 many applicant categories must also set those profiles public. AI chat accounts are not on the list — but the list has been expanded repeatedly (students in June 2025, H-1B in December 2025, fourteen more categories in March 2026), so the honest answer is "not yet", and records created now would be visible to whatever the rules become later.
- Can a border officer make me unlock my phone?
A US citizen cannot be denied entry for refusing, though the device itself can be detained. For a visa holder or visitor, admission is discretionary and refusing can cost them entry — that is the asymmetry that matters. Basic scrolling searches require no suspicion under CBP policy; forensic searches require reasonable suspicion plus a senior manager's approval. The directive limits searches to data resident on the device and tells officers to disable connectivity, so cloud-only material is out of reach — but content an app has cached locally is on the device.
- Are my immigration questions to an AI legally confidential?
No. In United States v. Heppner (S.D.N.Y., February 2026) a court held that neither attorney-client privilege nor work-product protection ever attached to a defendant's chatbot-generated documents — the protection never existed rather than being waived. Privilege failed because a chatbot is not a lawyer and the consumer terms defeated any expectation of confidentiality; work product failed because he had used the tool on his own initiative rather than at counsel's direction. Providers also state that flagged conversations are reviewed by human staff and may be referred to law enforcement, and courts have compelled production of millions of consumer chats in litigation. Only a lawyer creates privilege.
- Does Secret Chat let me hide things from immigration authorities?
No, and you should not try. Secret Chat is an anonymizer for lawful private research: it keeps no server-side chat archive and never associates your queries with your identity, so your research does not accumulate under your name. It does not make your social media private, does not create privilege, does not change your duty to answer every form truthfully, and does not affect what is stored on a device that crosses a border. For a real case, see a licensed immigration lawyer.
Conclusion
People in the immigration system are told, correctly, to be careful what they post. Almost nobody tells them to be careful what they ask — even though the questions are more revealing than the posts, the questioner is the government's own applicant, and the account holding them is built to remember.
The advice is not to stop asking. A person navigating this system needs more information than most, at exactly the moment mistakes cost the most, and a machine that explains waivers at 2am without judging is genuinely valuable. The advice is to separate the two things that should never have been joined: the question and your name. Ask everything — generally, anonymously, off the record. Put your real facts in exactly two places: the government's forms, truthfully, and your lawyer's file, in confidence. And keep the 2am version of yourself out of the file that decides your next five years.
Sources
- U.S. Department of State — Announcement of expanded screening and vetting for visa applicants (June 18, 2025)
- Seyfarth Shaw — Expanded digital vetting for H-1B and H-4 visa applicants (December 2025)
- Boundless — U.S. expands social media vetting to 14 more visa categories (March 30, 2026)
- Federal Register — USCIS notice proposing collection of social media identifiers on immigration forms (March 5, 2025)
- Yale OISS — USCIS plans to collect social media identifiers on nine immigration forms (March 2025)
- Boundless — USCIS social media monitoring rules, antisemitism and anti-Americanism screening (2025)
- Axios — State Department's AI-assisted "Catch and Revoke" visa program (March 2025)
- Brennan Center for Justice — The AI-driven "Catch and Revoke" initiative
- U.S. Customs and Border Protection — Border search of electronic media, FY2025 statistics
- U.S. Customs and Border Protection — Border search of electronic devices (basic vs advanced searches, traveler obligations)
- U.S. Press Freedom Tracker — Australian writer deported after interrogation over reporting, phone search (June 2025)
- Committee to Protect Journalists — Australian writer questioned, deported from US (June 2025)
- Gibson Dunn — S.D.N.Y. rules against privilege protection for consumer AI outputs (analysis of United States v. Heppner)
- Proskauer — S.D.N.Y. addresses privilege and work-product implications of using unsecured public AI tools
- Assini v Hayward, 2026 NY Slip Op 26086 — Supreme Court, Nassau County (subpoena to OpenAI quashed)
- OpenAI — Fighting The New York Times' invasion of user privacy (scope of the 20-million-conversation sample)