Published August 12, 2026
This article is general information, not legal advice. For advice about your own situation, consult a qualified lawyer.
It happens at about four in the afternoon. You have decided to leave, the decision feels enormous, and you want help finding the wording that is firm without burning the bridge. The AI tab is already open, already signed in, already the thing you use forty times a day. You type: "Help me write a resignation letter. I've been here three years, my manager has been undermining me since the reorg, and I have an offer from a competitor starting in March."
In four seconds you have produced something you would never have written down anywhere else: a dated, timestamped, first-person statement of your intention to leave, your grievance, your destination and your timeline — inside an account your employer pays for, administers and can be compelled to search.
Most workplace-AI advice is about leaks: don't paste the client list, don't upload the unreleased roadmap. Job-hunting is the opposite problem, and that is why it deserves its own article. Nothing confidential leaves the company. The exposure runs the other way — the record is about you, it is held by the party whose interests are opposed to yours, and it is read later, at a moment you do not choose.
The One Category Where There Is No Innocent Reading
Almost every awkward prompt has a harmless explanation. "How do I tell someone their work isn't good enough" could be about a contractor. "What are the redundancy rules here" could be idle curiosity after a news story. Job-search prompts have no such cover. "Rewrite my CV for a senior role at a fintech" means one thing. So does a request to compare two offer letters.
Three properties make this category unusually sharp:
- The prompt is self-contained evidence. It needs no context to be understood and no interpretation to be damaging. One line, read alone, months later, still says exactly what it said.
- You do not have to announce it. Even without the word "resign", the cluster gives it away: salary benchmarking, "how do I answer why I'm leaving", a cover-letter rewrite, three questions about notice periods, all in one week. Nobody reviewing that workspace needs a confession.
- The reader is not neutral. Everywhere else in your working life being observed is boring — nobody cares that you asked an AI to reformat a spreadsheet. Here the observer is the counterparty to the decision.
There is a quieter version of the same trap: assistants that remember. A tool with personalization enabled can carry "the user is looking for a new job" forward into unrelated answers — including one you generate on a shared screen in a meeting room. The disclosure does not have to be a document. It can be a sentence the model volunteers while you are demonstrating something else.
Who Can Actually Read It — the Honest Version
The scaremongering answer is "your boss reads everything". The truthful answer depends on which plan your employer bought, and it is worth knowing precisely, because the accurate picture is quite bad enough.
ChatGPT Enterprise and Edu: built to be exported
OpenAI's Compliance Platform is, in OpenAI's own words, "available to Enterprise and Edu customers" and "provides access to logs and metadata from your ChatGPT workspace that you can connect with your eDiscovery, DLP, or SIEM tools". Conversation message logs are explicitly among the supported feeds, and the documentation names the integration partners — among them Microsoft Purview, Relativity, Smarsh, Global Relay, Varonis, Netskope, Palo Alto Networks and Zscaler. Those are not analytics products. Relativity and Smarsh are litigation and archiving tools; that is what the plumbing is for.
One line on that page matters more than the rest, and it is the one nobody quotes. The compliance log platform "retains data for 30 days", and then: "If longer retention is desired then consumers should implement a system to continuously download all logs and retain them according to their policies." The thirty days is OpenAI's window, not your employer's. Once an organisation has wired the feed into its own archive, the retention period that governs your resignation draft is the one written in your company's records-management policy — frequently measured in years.
ChatGPT Business: less than the rumour, more than comfort
Here OpenAI is genuinely more protective than people assume, and it deserves to be quoted accurately. Its Business documentation states that "each user has their own chat history", that members "cannot automatically view other members' private chat history", and answers the direct question — does usage analytics let admins read all user chats? — with a flat "No". The Compliance Platform is not part of the Business plan.
Two things stop that being reassurance. The first is the word automatically, which is carrying real weight in every one of those sentences: they describe what the product does not expose by default in its own interface, not a promise about every legal or contractual route to the data. The second is what happens when you actually go. OpenAI's removal policy is explicit: in a Business workspace, when a member is removed, "chats, files, and canvas documents are retained indefinitely", and if the person is re-added, "their content is restored". Your last month of prompts does not leave with you. It stays in the workspace, indefinitely, behind a door you no longer have a key to.
Microsoft 365 Copilot: it is email, structurally
If your work assistant is Copilot, the architecture is the plainest of the three. Microsoft's eDiscovery documentation states that "all user prompts and responses from AI applications are stored in a user's mailbox", held as individual message-class items an eDiscovery manager can search with the same tooling used for email. The source table on that page also lists ChatGPT Enterprise as a collectable source — both "local machine interactions" and "browser-based interactions" — so an organisation can pull a third-party AI tool into the same review pipeline as its own.
Gemini in Google Workspace: searchable before it was retainable
Google Vault administrators have been able to search Gemini app conversations and export the results for some time. Since 11 June 2026 they can also set retention rules by organisational unit and place litigation holds on Gemini data. Note the scope: this covers the standalone Gemini app on web and mobile, and not the Gemini features embedded in other Workspace apps such as "Help me write" in Gmail or Docs.
Deleting It Is Not the Undo Button You Think
The instinct, once this lands, is to go and delete the conversation. On a personal account that mostly works — OpenAI's retention policy schedules a deleted chat for permanent removal within 30 days, and Temporary Chats are removed within 30 days without you doing anything. In a corporate workspace, three mechanisms sit on top of that, and each one outranks you.
A hold beats the delete button, silently. Google states the consequence without euphemism: if a user deletes a conversation or turns off their activity setting while an active Vault hold requires retention, "the data is hidden from the user but remains fully retained". You see an empty history. The administrator sees the conversation. Nothing tells you which of those two views you are looking at.
Deletion in the corporate stack is an administrative project, not a click. Microsoft's own procedure for removing AI data requires an eDiscovery case, a search, and — before anything can actually be purged — removing every hold and retention policy from the affected mailboxes, then reapplying them afterwards. That is not a workflow you have access to, and not one anyone runs on your behalf.
Derived data survives its source. The same Microsoft documentation notes that Copilot memories are stored as a separate item class and that "deleting a conversation or message from Microsoft Purview or eDiscovery doesn't delete the associated Copilot memory". The transcript can be gone while the inference drawn from it remains — the general shape of the problem we cover in AI memory as a privacy time bomb: the summary outlives the sentence.
There is a legal corollary worth internalising. On business and enterprise tiers the AI vendor is normally acting as a processor for your employer, who is the controller. In practical terms your erasure request belongs to your employer, not to the AI company — in that arrangement, you are not the customer. The familiar objection does not work either: the Article 29 Working Party's Opinion 2/2017 on data processing at work concluded that consent is almost never a valid basis in employment, because an employee cannot freely refuse. Employers rely on other grounds instead, which means "I never agreed to this" is rarely the argument it sounds like. We walk through that whole landscape, including the US state notice laws, in what your IT department can see on a work computer.
The Delay Is the Danger
Almost nobody reads these records on the day they are written. They get read when something goes wrong — and the situations that send an employer looking are exactly the ones a job search creates.
A redundancy consultation where the selection is challenged. A bonus or vesting decision that turns on whether you had already resolved to leave. A garden-leave or restrictive-covenant dispute after you join a competitor. A constructive-dismissal claim in which your own account of when the relationship broke down is the central fact. A trade-secret allegation, where the company's first move is to pull everything you touched in your final weeks. In each of those, a months-old draft resignation letter naming your grievance, your destination and your date is not a side detail. It is the timeline, in your own words, written before you had any reason to be careful.
Do not expect the law to lift it back out. On the question people hope for — privilege — no published ruling holds that a standalone conversation between a user and a chatbot is covered by attorney–client privilege simply because it concerns a legal problem. In United States v. Heppner (S.D.N.Y., Judge Jed Rakoff, 10 February 2026), an executive who used a consumer chatbot to prepare defence material found that protection had never attached — not that it was waived, but that it was never there. The court's reasoning included the points that a chatbot is not an attorney and that the consumer terms defeated any reasonable expectation of confidentiality.
A separate line of civil cases has protected AI chats, and it is important not to confuse the two doctrines. Warner v. Gilbarco (E.D. Mich., 10 February 2026), Morgan v. V2X (D. Colo., 30 March 2026), Tate Group Automotive v. Legacy Automotive Capital (Business Court of Texas, 3 June 2026) and Assini v. Hayward (Sup. Ct. Nassau County, 4 June 2026 — which quashed a subpoena served on OpenAI itself) are work-product decisions. Work product turns on material prepared in anticipation of litigation, and often on counsel's direction. A resignation letter drafted months before any dispute exists, with no lawyer within sight, is close to the definition of a document that qualifies for neither protection. Our overview of how AI chat logs surface in divorce and employment cases goes deeper into that split.
It Is Not Only Your Own Data
A job-search prompt is unusually crowded with other people. The recruiter who contacted you. The competitor who made the offer, and the number attached to it — frequently under an NDA you signed. The colleague you name as a witness to how you were treated. Another employee's salary, quoted to make your comparison land.
Two consequences follow. Legally, pasting someone else's personal data makes you responsible for that disclosure, whichever tool you used. Practically, it turns a document about your own feelings into a document about other people's confidential information — which is precisely what makes an ordinary HR matter escalate into something with a legal budget attached.
What to Do Instead
None of this means AI is the wrong tool for a career decision. It is a genuinely good one: it will pressure-test your reasoning, flatten an angry paragraph into a professional one, and rehearse the conversation you are dreading. The fix is not to stop. It is to move the whole thing off your employer's estate — and the move has to be complete, because doing four of these five things gets you nothing.
1. Change the device, not the setting. Your own phone or laptop, on cellular data or your home network, signed into your own account. That single change bypasses device management, the corporate certificate, endpoint agents and the company network at once. No toggle inside a work machine comes close, and private browsing solves none of it.
2. Never let it touch the work identity. Not the work SSO, not the work email as a recovery address, not the corporate browser profile, not the company Wi-Fi even from a personal phone. Sync is the quiet killer here: a personal account signed into a managed browser profile can land the history exactly where you were trying to keep it out of.
3. Strip it down before you type it. The advice does not need the names to be good advice. Not your manager's name, not the competitor's, not the recruiter's, not the salary figures of colleagues. Describe the situation, not the cast: "a manager who reassigned my main project after a reorg" gets you the same letter as the version with everyone identified.
4. Keep the artefacts off company storage. The CV in the work OneDrive or Google Drive, the offer PDF in the work mailbox, the draft in a work note-taking app — each is the same disclosure in a different container. And remember that files carry metadata of their own: a document created on a work machine may name its author and origin regardless of what the text says.
5. Assume the record is permanent, and write accordingly. The most durable protection is the oldest one: do not put in writing what you would not want read aloud in a meeting you were not invited to. Ask the AI for the letter; do not use it as the diary.
If you want a starting point that is useful without being self-incriminating, this one is deliberately free of names, employers and dates:
I am planning to resign from a role I have held for about three years, and I want a short, professional resignation letter that keeps the relationship intact. Do not include reasons for leaving or any criticism. Give me two versions — one warm, one neutral and formal — each under 150 words, with a placeholder for the notice period. Then list the three things I should be careful not to say in the conversation that follows.
Note what that prompt does not contain: no grievance, no destination, no start date, no manager. It still produces the letter. The detail you leave out is the detail nobody can read back to you later.
Where Secret Chat AI Fits — and Where It Does Not
We build a private AI gateway, so let us be exact about the boundary, because the honest limit is the important part of this article.
Secret Chat AI removes you from your queries — it does not remove the data from your messages. What it changes is your relationship with the model provider: we build no profile of you, no chat is ever associated with you, your queries reach the top models anonymously under our gateway's credentials rather than your name or IP address, and they are never used for training. Your conversations live in your own browser rather than in a server-side archive, and a prompt exists on our side only for as long as it takes to fetch your answer. Registration takes an email, but it is used only for account access and payment — never linked to what you ask. Retention may still apply at the provider; your query simply arrives there as a stranger's.
What it cannot do is undo the device. If you type a resignation letter on a managed laptop, an endpoint agent reads the text before it reaches us, a corporate proxy sits on the path whatever we route to, and browser-side history lives on a disk your employer administers. Any AI vendor claiming otherwise is describing something that is not architecturally possible. A private gateway is the right answer to the second half of the question — who sees this at the model provider — but only once you have answered the first half by changing the machine.
Two further limits, stated plainly. "Anonymously" describes the link, not the words: no account identifier travels with your prompt, but write your own name or your employer's into a message and it is all still sitting there in the message. And anonymity is not privilege, not a legal exemption, and not a way to keep anything from a court entitled to it. Redacting identifying details before you send remains yours to do.
The Bottom Line
A job search is the one workplace topic where you and your employer sit on opposite sides of the same question, and it is the topic people most often research in the tool their employer controls. The record survives your intentions, outlasts your access, and gets read at the moment it hurts most — a redundancy pool, a bonus decision, a covenant dispute. On Enterprise and Edu plans the export machinery is a documented product feature with named litigation-tooling partners; on Business your chats stay in the workspace indefinitely after you leave; and a hold beats your delete button while showing you an empty history.
So keep the whole matter on hardware you own, on a network you chose, in an account nobody else administers — and if you would rather the model provider did not build a picture of you either, run it through Secret Chat AI, where the question reaches the model without you attached to it. Write the resignation letter. Just not on their laptop, in their account, on their Wi-Fi.
Frequently Asked Questions
- Can my employer read my ChatGPT conversations at work?
It depends on the plan and the tooling. On ChatGPT Enterprise and Edu, OpenAI's Compliance Platform gives the organisation access to workspace logs — including conversation message logs — and connects them to eDiscovery, DLP and SIEM tools, with partners such as Microsoft Purview, Relativity and Smarsh named in the documentation. On ChatGPT Business, OpenAI states that each user has their own chat history and that members cannot automatically view another member's private chats. Either way, the device and network layers are separate and can expose the text regardless of the plan.
- What happens to my work AI chats when I leave the company?
They generally stay. OpenAI's documentation says that in a Business workspace, chats, files and canvas documents are retained indefinitely after a member is removed, and are restored if the person is re-added. In Enterprise and Edu workspaces it follows the workspace's configured retention policy, which can itself be indefinite. Your access ends; the record does not.
- If I delete the conversation, is it gone?
Not necessarily. On a personal account a deleted chat is scheduled for permanent deletion within 30 days. In a corporate workspace a legal hold overrides you: Google states that if a user deletes a Gemini conversation while an active Vault hold requires retention, the data is hidden from the user but remains fully retained. Microsoft's procedure for actually purging AI data requires removing holds and retention policies first — an administrative task you cannot perform.
- Are AI chats about a job or a workplace dispute legally protected?
Do not assume so. No published ruling holds that a standalone user–chatbot exchange is covered by attorney–client privilege, and in United States v. Heppner (S.D.N.Y., 10 February 2026) the court found that protection had never attached to defence material prepared with a consumer chatbot. Several civil courts have protected AI chats as work product, but that is a different doctrine, turning on material prepared in anticipation of litigation and often at a lawyer's direction — which a resignation letter written months before any dispute is unlikely to satisfy. This is general information, not legal advice.
- Where should I draft a resignation letter or work on my CV instead?
On a device you own, on your own network or cellular data, in an account with no connection to your work identity — not the work SSO, not the corporate browser profile, not the company Wi-Fi. Leave out names, employers, salary figures and dates; the letter comes out just as well without them. If you also want the model provider kept at arm's length, use a gateway that unlinks the query from you, while remembering that it cannot protect anything typed on a managed machine.
Sources
- OpenAI Help Center — OpenAI Compliance Platform for Enterprise and Edu Customers
- OpenAI Help Center — Managing data, sharing, and privacy in ChatGPT Business
- OpenAI Help Center — Data retention when a member is removed from a workspace
- OpenAI Help Center — Chat and File Retention Policies in ChatGPT
- Microsoft Learn — Search for and delete AI application data in eDiscovery
- Google Workspace Updates — Google Vault now supports retention rules and litigation holds for Gemini app (11 June 2026)
- Article 29 Data Protection Working Party — Opinion 2/2017 on data processing at work (8 June 2017)