Private AI for Journalists:
Protecting Sources and Notes

Published June 21, 2026 · Updated September 18, 2026

For a reporter, AI is tempting in exactly the moments when it's most dangerous. You have forty pages of interview transcript, a leaked report to make sense of before deadline, and a half-formed idea you want a sounding board for. An AI assistant could help with all of it in minutes. The problem is that the same material — a source's name, a location, an offhand detail that could identify someone — is precisely what you're professionally and ethically bound to protect.

The Main Reason for Reporters: an AI Council That Cross-Checks the Answer You Rely On

Source protection is what sends a reporter looking for a private AI tool. The AI Council is what makes one worth opening: you ask once, several top models answer in parallel, and a referee model then compares them claim by claim and marks where they contradict each other. The full panel is ChatGPT, Claude, Gemini and Grok: one from each company, each running its own live web search; a lighter two-model panel runs within the daily free quota and answers without search. A fabricated date, a misattributed quote or an invented study normally reads just like a real one when a single chatbot writes it; fluency authenticates nothing. Two models that both searched and still disagree have either found different evidence or read the same evidence differently — either way, that's a flag on the specific line that needs a primary source before it gets near a draft. Paste in an answer you were handed somewhere else and ask the panel to check it, and you get the same treatment of text you didn't commission.

Two limits, up front. Agreement is evidence, not proof (models share training data and can be wrong together), so a council tells you what to verify and never counts as having verified it. And it sends your question to every model on the panel, which widens where your text travels: everything below about keeping source-identifying detail out of a prompt applies with more force, not less.

So the honest starting point is this: pasting source material into any cloud AI tool carries risk, and no product on the market (this one included) can promise it away. What a privacy-conscious setup can do is shift the odds in your favor. It can make the work safer than dropping sensitive notes into a default consumer chatbot. The judgment about what is safe enough to share, and the duty to shield your sources, remain yours. This piece walks through where the danger actually lives, what "safer" buys you, and the working habits that protect people who trusted you with information.

This is general guidance, not security or legal advice. Follow your outlet's editorial and security policies, and lean on a digital-security trainer or your newsroom's security desk for high-risk reporting.

Why a Reporter's Notes Are a Special Kind of Risk

Most people who worry about AI privacy are protecting their own information. Journalists are usually protecting someone else's — often someone with far more to lose than the reporter does. A whistleblower can face dismissal, prosecution, or worse if their identity surfaces. That changes the calculation entirely.

When text goes into a typical consumer chatbot, a few things tend to follow, and each one matters more when a source is involved:

  • It is stored. Conversations are frequently retained and tied to an account, which means a record of what you asked can outlive the story.
  • It may be read or reused. Many free tools can use conversations to train future models unless you opt out, and some permit human reviewers to see samples.
  • It is linked to you. An ordinary account ties sensitive prompts to a verified identity, and, through metadata, to a time, a device, and a network.

There's a second, quieter trap that hits journalists specifically: files carry hidden data. A photo from a source can embed the exact GPS coordinates and timestamp of where it was taken. A PDF can carry author names and revision history. Uploading the raw file can betray a source even when the visible content looks harmless.

What the Law Actually Protects, and What It Does Not

Reporters often assume source protection is a settled legal shield that travels with the material. It's neither settled nor portable, and the gap between the ethical duty and the legal privilege is where sources get exposed.

  • There is no federal shield statute. Forty states and the District of Columbia have shield laws; the rest offer partial or judge-made protection, and two (Hawaii and Wyoming) have neither statute nor recognised non-statutory privilege. At the federal level, Branzburg v. Hayes (1972) rejected a First Amendment privilege against a good-faith grand jury subpoena, and lower federal courts have gone different ways ever since. The PRESS Act, which would have created a federal shield, passed the House in the 118th Congress and died without a Senate vote. It isn't law.
  • No court has held that a shield law follows your notes into an AI provider. That question is untested. It's also the wrong question to rely on: a shield law generally protects you from being compelled to testify. It doesn't stop anyone from serving a subpoena on a company that holds a copy.
  • The third-party doctrine is narrower than it was — and moving. The old rule from United States v. Miller (1976) was that information voluntarily handed to a company loses Fourth Amendment protection. Carpenter (2018) declined to apply that mechanically to cell-site location records, and on 29 June 2026 the Supreme Court went further in Chatrie v. United States, holding that police conducted a Fourth Amendment search when they obtained a user's Google Location History through a geofence warrant. Justice Kagan's opinion for the Court reasoned that the data was information "a user reasonably understands as his own, even though stored on Google's servers — much like his emails, photos, and calendar entries," and was "not truly shared" in the sense of wanting a company to see or use it. So, the Court concluded, "just as the third-party doctrine didn't apply in Carpenter, it doesn't apply here."

Read that last one carefully, because it is easy to over-read. Chatrie is about location data, not prompts, and the Court decided nothing about AI. The judgment was vacated and remanded, with the good-faith exception left for the Fourth Circuit. What it does is remove the easy argument, that handing something to a company automatically ends your constitutional interest in it, and it does so with reasoning that fits typed content stored on a provider's servers rather well. That's a direction of travel, not a protection you can rely on today.

"Safer" Is the Honest Word: Here Is the Line

It's worth being precise about what a privacy-focused tool changes and what it can't. Putting the limits first is the responsible order.

What it changes: less of your material sitting in a cloud account, weaker links between your prompts and your real identity, and clearer handling of what happens to a conversation after you close it. Compared with a stock chatbot, that's a genuine reduction in exposure.

What it doesn't change: to produce an answer, the AI model has to read what you send. With a multi-model cloud service like this one, your text is passed to the model provider you select (the company behind GPT, Claude, Gemini, Grok, or Perplexity), so it can generate the reply, and to each provider on the panel when you run an AI Council. The content is processed off your machine by an outside company. This is cloud AI, not on-device AI, and it isn't encrypted in a way the model provider can't read. Privacy features lower specific risks; they don't turn a cloud assistant into a sealed vault, and they don't transfer your duty to protect a source onto the software.

What improves vs. a default chatbotWhat stays your responsibility
Chat history and files kept on your own deviceDeciding what is safe enough to share at all
Sign-up that asks for little about youRemoving names, locations, and identifying detail
Your IP hidden from the model providerStripping hidden data from photos and files
Deletion requested where the provider supports itVerifying every fact the AI gives back

When the Story Demands Maximum Protection

For the most dangerous reporting (where a single leaked detail could expose a source to real harm) the strongest answer is to keep the material off third-party servers altogether. That can mean a newsroom running AI on infrastructure it controls, or a reporter running an open-weight model locally on a laptop with no network connection. Nothing leaves the building over the network, but treat that phrase as a description of the network, not of the machine. A local model still sits on a disk that can be seized, imaged, backed up or stolen, on an operating system that updates and may phone home, and inside a building someone can enter. Air-gapping is a practice, not a product: it means full-disk encryption, strong authentication, controlled backups, a patching plan, physical security and verified deletion, and an ordinary laptop with the Wi-Fi switched off has none of those by default. Handled that way, though, there's no outside provider to subpoena, breach, or persuade.

The honest trade-off is capability. The open-weight models you can self-host today are, as a rule, noticeably weaker than the flagship models that the major labs offer only through their paid APIs. You give up some quality of reasoning, summarizing, and drafting in exchange for the highest level of control. Many newsrooms land on a split: a local model for the truly sensitive material, and a privacy-focused gateway to the strongest commercial models for lower-risk work, with careful redaction applied no matter which path a task takes. If a newsroom is weighing hardware for the local half, our measured comparison of local LLMs and a private gateway shows what a modest machine actually delivers and what frontier-level quality would really require.

What Secret Chat Does to Lower the Risk

Secret Chat AI is a private AI assistant and multi-model gateway designed with privacy-first defaults. At its core it's an anonymizer: it builds no profile of you and never associates your prompts with your identity (the email you sign up with is used only for account access and payment), so even where a provider retains data, it isn't linked to you. It won't make cloud AI confidential, but it strips away several of the habits that make mainstream chatbots a bad place for source material.

  • Your conversations live on your device. Chat history is kept in your browser's local storage rather than in a cloud account on Secret Chat's servers, and uploaded files are stored locally too. The lasting record of your reporting sits with you.
  • Sign-up reveals little. An email address is all that's required (no name, no phone number), so there's less tying your questions back to you.
  • Your network is shielded from the provider. Requests pass through Secret Chat's infrastructure, so the model provider doesn't see your IP address directly.
  • Deletion is requested, and reported honestly. Where a provider allows it, Secret Chat asks for the processed content to be deleted or not stored, and each message can generate a Session Privacy Report (PDF) that shows what happened, including when a deletion step failed, rather than pretending it always works.
  • One place, several models. You can choose the right assistant for a task and compare outputs without spreading your work across multiple provider accounts.

On documents: uploads support images and PDFs, and since September 2026 also Word files, spreadsheets, PowerPoint decks, CSV, text and code files, and zip archives of them. Images and PDFs go to the model as files; every other document is converted to text in your browser and only that text is sent, so the file itself never leaves your machine. The contents still reach the provider either way, so drop anything that shouldn't travel before you attach — the app shows you the exact text it is about to send.

It also makes those files, not only reads them. The Generators group in the model selector holds eight of them, each answering with the finished piece instead of prose to rework. Table pulls the timeline out of a 200-page filing as a sortable .xlsx (or a CSV); Chart turns those rows — payments by year, donations by donor — into a JPG or a PDF for the graphics desk; Presentation makes the .pptx for the editorial meeting; Document writes the FOI request or the right-of-reply letter as a .docx. Translator renders a foreign-language document or a quoted statement into any language on its list, Email drafts the request for comment in the tone you set, Article gives you a first draft of an explainer to rewrite in your own voice, and Social Post writes the post that promotes the piece, within the network's limit. Hand it your own material and it structures that; a leaked spreadsheet attached to the Table generator is tabulated from what's in it, and the model doesn't go to the web for more unless you flip the web switch yourself. Editing is the same move as creating — attach the file, say what to change — and the result is a new file, not tracked changes. The file you download is assembled in your browser from the model's reply, never built or stored on a server, and everything the generators make is kept in the app's Library on your device, each entry with an Edit button that reopens it on its generator. None of that changes where the text goes: the rows you attached reached the model provider, exactly as a pasted question would, so the redaction comes first here too. The generators run on the paid models — ChatGPT, Claude, Gemini and Grok.

Source-Protection Habits That Beat Any Tool

The most reliable safeguard isn't a setting; it's discipline about what you put in. Every identifying detail you leave out is one that can't leak downstream, but don't mistake that for anonymity. People are routinely re-identified from writing style, an unusual fact, a chronology, or a combination of details that are individually harmless, and none of that's fixed by swapping the names out. Redaction lowers the risk; it doesn't zero it.

  • Anonymize before you paste. Replace real names, places, employers, and dates with neutral stand-ins ("the source," "City A," "the agency"), and keep the key that maps them back somewhere offline.
  • Separate the sensitive from the useful. Often the analytical question can be asked without any identifying facts at all. Send the question, not the dossier.
  • Scrub files before upload. Remove location data and camera details from photos, and clear author names, comments, and revision history from documents before they leave your device.
  • Share the fragment, not the file. Upload the single page or paste the single passage you actually need help with, not the whole leak.
  • Treat output as a lead, not a fact. Confirm every name, date, quote, and claim against primary sources; AI can invent details that sound authoritative.
  • Match the tool to the risk. For the highest-stakes material, fall back to offline or in-house options rather than any cloud service.

A safe way to put a tool to work without handing over your source:

Act as an editor. I have removed all names, locations, and identifying details from these notes and replaced the source with "the source." Organize them into a clear chronological outline and flag any gaps or contradictions I should follow up on. Here are the notes:

One more thing worth saying plainly, because this article is about one tool and source protection isn't: an AI gateway isn't a channel for talking to sources. For that, the established tooling exists and is better — SecureDrop for anonymous submissions and Signal for direct contact, with full-disk encryption on whatever machine the material lands on. Even those leave metadata: who contacted whom, and when. Use AI on the material after it reaches you safely, not to receive it.

Where AI Earns Its Place in the Newsroom

With those habits in place, AI is genuinely useful for the parts of reporting that don't require exposing anyone:

  • Making sense of a long, redacted document — a quick summary of a PDF before you read it line by line.
  • Shaping raw, anonymized notes into an outline, a timeline, or a list of open questions.
  • Pressure-testing an angle by asking different models to argue for and against your framing.
  • Drafting and tightening headlines, standfirsts, and explanatory passages you then edit.
  • Translating dense or technical language into plain English for your own understanding or for readers.
  • Getting the file, not the text — the timeline as a spreadsheet, the figures as a chart, the pitch as a .pptx, the FOI request as a .docx, the post that promotes the story — through the Generators described above, from redacted material.

The division of labor is constant: AI speeds up the mechanical parts; you supply the verification, the ethics, and the protection of the people behind the story.

Pressure-testing an angle is the one on that list most often abandoned on deadline, because doing it by hand is four tabs, the same question pasted four times, four waits taken one after another and then a long side-by-side read. The AI Council is the same exercise without either delay. Every model is asked at the same moment, so the run lasts about as long as its slowest member rather than the sum of the panel, and each answer appears as it lands, so you're reading while the rest are still being written. Then the referee reads them so you don't have to: the factual claims are pulled out, lined up model by model, and returned as a short synthesis of what at least two models arrived at independently, with whatever stayed contested set out separately, which is, in practice, your list of what to put a second source behind. Four long answers that largely repeat each other come back as one short passage and a handful of named disputes, so the panel leaves you less to read than a single model would, not more. It remains a list of what to check rather than a check, and it sends the question to every model on the panel, as the note at the top of this article says.

The Bottom Line

Journalists should be able to use modern tools without gambling with a source's safety. The truthful framing is the careful one: a privacy-focused tool like Secret Chat makes AI use with sensitive notes safer — through on-device chat and file storage, low-information sign-up, IP shielding, and transparent deletion handling, but never risk-free. The model provider still reads your prompt, and protecting sources and personal data stays in your hands.

Keep the sensitive details out, verify what comes back, and reserve the most dangerous material for offline or in-house tools. Want a more private place to do the lower-risk work? Try Secret Chat AI, and bring your own redaction discipline with you.

Frequently Asked Questions

  1. Is it safe to put source material or sensitive notes into AI?

    No cloud AI tool is fully "safe" for source material, because the model provider has to read your prompt to answer it. A privacy-focused tool can be safer by reducing how much is stored and how easily it links back to you, but the duty to protect sources stays with you. Keep identifying details out and share only what a task truly needs.

  2. Can AI protect my confidential sources?

    No software can guarantee that. Protection comes mainly from what you choose not to share — anonymizing names and places, scrubbing files, and reserving the most dangerous material for offline tools. A privacy-focused gateway lowers some risks around storage and identity, but it's a support for good practice, not a replacement for it.

  3. What file types can I upload, and what about photos from a source?

    Images, PDFs, Word files, spreadsheets, PowerPoint decks, CSV, text and code files, and zip archives of them; documents other than PDFs are converted to text in your browser before being sent. Be especially careful with photos: they can carry GPS coordinates and timestamps. Remove that hidden data yourself before uploading, since you should never assume a tool will do it for you.

  4. Can it turn a document into a spreadsheet, a chart or a deck?

    Yes. Pick Table, Chart, Presentation or Document from the Generators group (Email, Translator, Article and Social Post sit beside them), attach the file or paste the material and say what you want; the answer is a new .xlsx, chart, .pptx or .docx assembled in your browser, and it works from what you gave it rather than searching the web unless you turn the web on. Attach a file with changes in mind and you get a fresh file back, not a redline. Results stay in the app's Library on your device. The material still reaches the model provider, so redact before you attach. The generators run on the paid models.

  5. Does the tool automatically remove names or identifying details from my text?

    No. Assume nothing is stripped for you. If you don't want a name, location, or other identifier processed, take it out before sending. Handling personal and sensitive data remains your responsibility.

  6. What should I use for the highest-risk reporting?

    For material where no outside party can ever be allowed to see it, keep it off third-party servers, a newsroom-controlled deployment or an open-source model running locally and offline. The trade-off is that self-hosted open-weight models are generally less capable than the top-tier models available only through the providers' APIs, so many teams reserve local tools for the most sensitive work and use a privacy-focused gateway for the rest.

Sources