Published August 15, 2026 · Updated August 18, 2026 · Facts last verified August 18, 2026
This article is general information, not legal advice. For advice about your own situation, consult a qualified lawyer in your jurisdiction.
In March 2026 a 25-year-old financial analyst in Palm Beach County opened ChatGPT to talk about a breakup. Six months of relationship had just ended. Over the following weeks, according to reporting by the Palm Beach Post and to court records, the conversation allegedly turned into something else: threats to rape and to kill his former partner, and then a murder-suicide plan.
"I'm gonna kill her by the end of this month," he allegedly wrote. "If I can't have her then nobody can." According to the messages preserved in court records, he described waiting in the parking lot of the woman's gym holding flowers, and said that if she refused them he would draw a gun, kill her, and then shoot himself. He is reported to have told ChatGPT he had bought an AR-15-style rifle, a Glock and a 12-gauge shotgun, and to have sent her photographs of the guns, along with zip ties and latex gloves.
He wasn't talking to a diary. OpenAI detected a pattern in the messages, reviewed them, and alerted the FBI in May 2026. Federal agents then handed two months of his chat logs to the Palm Beach County Sheriff's Office; by then the people he had named had reportedly grown to include the woman's family. He was arrested in May, spent two days in jail before posting $100,000 bail, and was charged in June with aggravated stalking, written threats to kill and unlawful use of a two-way communications device. On 13 August 2026 he pleaded guilty to all three under a deal that avoided a possible 25-year sentence, and it's worth being exact about the result, because it isn't a conviction: the judge withheld adjudication and imposed eight years of probation, an ankle monitor for the first two, a batterer intervention programme, a mental health evaluation, and no drugs, alcohol, guns or contact with her.
Almost every re-post of this story has carried the same one-line reaction, usually with a shrug emoji: ChatGPT saves lives — but aren't these chats supposed to be confidential?
They were never supposed to be. That's the part worth spending time on, because the mechanism that caught this man is running against everyone else's conversations too, and it's much less exotic than it sounds.
This Was Not a Leak. It Was the Documented Design.
Nothing here went wrong at OpenAI. No database was breached, no rogue employee went looking. The company did what its own published policy says it does, and it has said so in public since August 2025.
OpenAI's stated process, in its own words on Helping people when they need it most and Our commitment to community safety, works like this. Automated classifiers watch conversations. When they detect a user who appears to be planning to harm others, the conversation is routed into a specialised pipeline where it's read by a small team of human reviewers trained on the usage policies and authorised to act, including banning the account. Mental health and behavioural specialists help assess difficult cases. If those reviewers conclude there's an imminent threat of serious physical harm to another person, OpenAI may refer the matter to law enforcement.
The wording has firmed up over the year, which is worth noticing in a policy people are relying on. The August 2025 post said OpenAI may refer a case when reviewers find an imminent threat of serious physical harm; the April 2026 post states that where conversations indicate an imminent and credible risk to others, OpenAI notifies law enforcement. Same direction, less hedging.
One detail in that policy is more revealing than the rest, and it's easy to miss: OpenAI says it is "currently not referring self-harm cases to law enforcement" — note the word currently, which does the quiet work in a changeable policy — explicitly out of respect for the private nature of these conversations. So the company isn't claiming it can't see the conversations. It's telling you which of the things it sees it chooses to act on. That's a policy line, not an architectural one, and policy lines are revised.
Three plain facts follow, and they're true for everyone who uses a consumer chatbot, not just for people who type threats.
- The conversation is stored. There would be nothing to review, and nothing to hand over, if it weren't. Two months of logs existed to be handed to a sheriff's office.
- The conversation is machine-screened, and human-read conditionally. OpenAI describes automated detection systems that flag content and specialised pipelines where a small trained team reviews what is flagged. It doesn't publish how continuously that screening runs, but the structural point holds: a human reviewer is one flag away.
- The threshold is set by the provider and can move. Nobody outside the company votes on it, and the user isn't told when it changes.
Why Reasonable People Assumed Otherwise
The surprise in the comments is genuine, and it isn't stupidity. A chat window looks like a private surface. It has one participant on the other end, it answers instantly, it doesn't visibly involve anyone else, and it invites exactly the register people use in a diary or with a friend. Nothing in the interface signals an audience.
It's also true that most people never read the policy, and that the policy isn't written in the place where the disclosure would matter — in the box where you're typing. We have written before about what ChatGPT actually stores and about how AI chats get subpoenaed; the pattern is consistent. The confidentiality people feel comes from the shape of the interface, not from any promise anyone made.
And this case isn't the boundary of it. In the New York Times litigation against OpenAI, a court ordered production of a sample of 20 million consumer conversations — belonging to people with no involvement in the case, who were never notified. There, no one had typed a threat. The transcripts simply existed, which was enough.
The Uncomfortable Part: The Reporting Was Probably Right
It would be convenient for a privacy company to tell this story as a straightforward outrage. It isn't one, and pretending otherwise would be dishonest.
A man described a specific target, a specific location, a specific timeframe and specific weapons he had actually purchased, and had already sent that person photographs of the weapons together with restraints. Whatever one thinks about surveillance, the alternative outcome in that parking lot isn't an abstraction. Most people, on reading the facts, conclude that a warning was the right call.
Both things are true at once, and the tension between them is the entire subject:
- Reporting a credible, imminent threat to a named person is defensible — arguably obligatory.
- The capability that made it possible is a permanent transcript of everyone's conversations plus continuous classification plus discretionary human review. That capability doesn't switch itself off for the millions of people who are simply asking about a diagnosis, a debt, a divorce or a job.
The correct question is therefore not "should they have reported him". It is: what has to exist for that to be possible, and what else does the same thing make possible?
Where Secret Chat Sits: Including What It Does Not Do
Two things have to be said here, and the second one matters more than the first.
Such a prompt does not get through
Secret Chat screens every prompt with an automated classifier before it's sent to any model. How strictly depends on the model you chose: the permissive models are screened permissively, because refusing on their behalf things they would happily answer would make choosing them pointless. But a short list is refused on every model in the line-up, without exception: sexual content involving minors, and threats of violence against a person or a group.
The words quoted at the top of this article are, in classifier terms, an unusually clear example of the second category. Here, a message like that doesn't reach a model, doesn't produce an answer, and costs no credits. There's no permissive setting it can be sent under, because that particular rule isn't part of any setting; it applies underneath all of them.
Which means the conversation that generated two months of evidence in Florida is a conversation that doesn't accumulate here. It's stopped at the first message rather than answered, elaborated on across weeks, stored, and later reviewed.
We should be precise about the limits of that claim, because a classifier is a classifier. We can say exactly this: there's no model here on which threats of violence are permitted, a refusal isn't a judgement about the person, and no automated score causes us to report anyone to anyone. What we can't say is that any classifier catches every phrasing on earth — nobody who has built one would say that, and a company that does is selling you something.
And the part that is not a boast
Screening is the ordinary half. The structural half is what is missing on our side afterwards.
Your chats live in your own browser, not on our servers. A prompt exists on our side only for as long as it takes to fetch your answer, and is deleted as soon as your browser has it — within 24 hours in every case, including the ones nobody ever collects. There's no archive to search, no backup containing conversations, and no pipeline that routes a conversation to a human reader, because there's no conversation on our side to route.
So the specific event in this story, two months of chat logs handed over, has no counterpart here. Not because we would refuse; because two months of chat logs don't exist. We have written the whole list out, in the language of the people who send such requests, on our Law Enforcement Guidelines page: what we hold, what we don't, and why most requests to us come back empty.
What we do keep, and we would rather say it here than have you discover it: when a prompt is refused for one of those always-blocked categories, we record that it happened (the category, the model, the time, the account or session identifier) and never the text. Ninety days, no profiling, not shown anywhere in the product, and no automatic report to anybody. It exists so we can enforce our own Acceptable Use Policy and answer a lawful request truthfully. That's a deliberate, narrow trade, and it's the honest shape of it.
And one capability that follows from not being a single vendor
There's a smaller point in the same family, and it's about answers rather than about records. A consumer chatbot gives you one company's model, and that model's account of a subject is the only account you get. You can't tell from the surface whether a confident paragraph is well grounded or a fluent guess, and the vendor has no reason to show you a rival's version of it.
The AI Council sends one question to several models from different companies in parallel. Each answer appears the moment that model finishes, and a cheap referee model then extracts the factual claims and lays out a disagreement table — which model asserts each claim, which contradicts it, which never mentioned it — with a short synthesis of what at least two models agreed on and a "verify before acting" list. It runs in three sizes: a Duet (two models), a Trio (three), and a Quartet — ChatGPT, Claude, Gemini and Grok. The Duet and Trio let you pick which families sit at the table; the Quartet runs the whole bench. A Duet runs free within the daily free quota, on a lighter pair that answers from memory with no live web search; credits buy the branded panels and the larger sizes. Where a question turns on current or checkable facts, the whole panel answers with live web search attached — decided once for the panel rather than per model, so its members stay comparable. You can paste in an answer you already have and have the panel check it, or switch an existing chat to a council and let the panel read the whole conversation.
Two things about it we would rather say plainly than let a reader assume. Agreement between models is evidence, not proof; they're trained on overlapping data and are capable of being wrong together; the signal worth acting on is disagreement, because it names the exact claim to go and verify. And a council widens where your text travels: it reaches every model on the panel plus the referee. Each of those requests is anonymous (no profile, no account identity attached), but anonymization removes you from a query, not the contents of it, so the second bullet in the next section, about dropping the details that identify a person, applies with more force to a council rather than less. The finished check is stored only on your device, and the Session Privacy Report lists every model that took part.
And the standing limit, which no design changes: anonymity isn't privilege and not immunity. Using any tool, including this one, doesn't put you beyond the law, doesn't create a confidential relationship, and doesn't affect your own duty to preserve material relevant to a legal matter. What it changes is how much about you exists to be asked for.
What This Means If You Are Not Threatening Anyone
Which is to say: for essentially everyone reading this.
The value of the Palm Beach case isn't that it might happen to you. It's that it settles an empirical question people were still arguing about. Consumer chatbot conversations are stored, are scanned, can be read by employees, and can leave the company, and now there's a named case with a docket number rather than a hypothetical.
Three practical conclusions follow.
- Treat the chat box as correspondence, not as a thought. The useful test before typing something sensitive isn't "is this legal"; it's "would I be comfortable with this sentence being read aloud, with my name attached, by someone unsympathetic, in two years' time". Most of what people worry about typing passes that test easily. Some of it doesn't, and the ones that don't are worth ten seconds of thought.
- Keep the specifics that shape the answer and drop the ones that identify a person. Jurisdiction, dates, amounts, sequence and exact wording are what make an answer good. Names, employers, addresses and account numbers almost never are. This costs nothing and works against every item on the list.
- Know which of the two problems a tool solves. Deleting a conversation and using temporary mode address the sidebar on your own screen. They don't address storage, classification, review or legal process. Only an architecture that never accumulates the transcript does that, and you should ask any service that claims it to show you exactly what it keeps instead.
The man in Palm Beach was caught because a company held his conversations and read them. That was the right outcome in his case. It's worth being clear-eyed that the same sentence describes what happens to everybody else's.
Frequently Asked Questions
- Does OpenAI really report ChatGPT users to the police?
Yes, in defined circumstances it has stated publicly since August 2025. Automated classifiers flag conversations that appear to involve planning to harm others; those are routed to a small team of trained human reviewers authorised to act, including banning accounts; and if the reviewers conclude there's an imminent threat of serious physical harm to another person, OpenAI may refer the case to law enforcement. OpenAI says it doesn't refer self-harm cases to law enforcement. In the Palm Beach case reported in August 2026, the referral went to the FBI, which passed two months of chat logs to the county sheriff's office.
- Are ChatGPT conversations confidential?
No, and they have never been presented as such. Conversations are stored on the provider's systems, scanned by safety classifiers, readable by a small number of employees under the conditions above, and reachable by legal process, a court in the New York Times litigation ordered production of a 20 million-conversation sample belonging to users who were never notified. Talking to a chatbot also creates no legal privilege; only a lawyer can do that.
- Would a message like that be blocked on Secret Chat?
A prompt of that kind is refused on every model in our line-up. Threats of violence against a person or a group, and sexual content involving minors, are blocked underneath the per-model settings rather than by them, so there's no permissive model on which they're allowed through. A blocked prompt never reaches a model and costs no credits. No classifier catches every possible phrasing, and we don't claim one does.
- If someone did type a threat, could Secret Chat hand over their conversations?
There are no conversations to hand over. Chats are stored in your own browser; a prompt exists on our side only for as long as it takes to return the answer and is deleted within 24 hours in every case, so no archive, backup or searchable history exists. When a prompt is refused for one of the always-blocked categories we record the fact — category, model, timestamp, account or session identifier, kept 90 days — and never the text of the prompt. We don't report anyone on the strength of a classifier score. Our Law Enforcement Guidelines set out the full list.
- Do I have to take one company's model at its word for an answer?
Not here. The AI Council sends one question to several models from different companies at once, reveals each answer as that model finishes, and then has a referee build a table of which model asserts each claim, which contradicts it, and which never mentioned it, plus a synthesis of what at least two models agreed on and a list of things to verify before acting. A two-model Duet is free within the daily quota, on a lighter pair with no live web search; credits buy the ChatGPT/Claude/Gemini/Grok panels and the larger Trio and Quartet. Agreement between models is evidence, not proof (they share training data and can be wrong together), and a council widens where your text goes, since every model on the panel and the referee receive it, anonymously but verbatim.
- Does using a privacy-focused AI service put me beyond the law?
No, and no honest service will tell you otherwise. Anonymity isn't privilege and not immunity: it doesn't create a confidential relationship, it isn't a way to hide or destroy evidence, and it doesn't change your own duty to preserve material relevant to a legal matter. What it changes is how much information about you exists in the first place for anyone to request.
Related reading: does ChatGPT store your conversations · how AI chats get subpoenaed · a realistic threat model · how to use ChatGPT anonymously
Sources
- Palm Beach Post (via AOL) — ChatGPT reported South Palm Beach man's rape and murder threats to FBI (August 2026)
- Detroit News / USA Today Network — OpenAI alerted FBI after man told ChatGPT he planned to kill his ex (14 August 2026)
- Futurism — OpenAI Reports Goldman Sachs Analyst to FBI for Horrifying ChatGPT Conversations (14 August 2026)
- OpenAI — Helping people when they need it most
- OpenAI — Our commitment to community safety
- Bloomberg Law — OpenAI Must Turn Over 20 Million ChatGPT Logs, Judge Affirms (January 2026)