08/05/2025
Think your AI chatbot conversations are private? Think again.
It is possible for chats with AI tools like Gemini, ChatGPT, Claude, and Perplexity AI to be found and obtained through a legal discovery process. The idea that these conversations are private or ephemeral is largely a misconception. Here's a breakdown of why this is the case:
1. Cloud Storage and Data Retention:
- Server-Side Storage:** When you interact with these AI chatbots, your conversations are not stored locally on your device. They are sent to and stored on the company's servers in the cloud. This is how the chatbot "remembers" previous parts of a conversation to maintain context.
- Data Retention Policies: Each company has its own data retention policy. While some may offer a way to delete your chat history, the underlying data may still be retained on their servers for a certain period, sometimes for months or even longer, to comply with legal obligations or for product improvement. For example, some sources indicate that even if you delete a chat, the data might be retained on OpenAI's servers for a period.
2. Lack of Legal Privilege:
No Attorney-Client Privilege: A key point to understand is that conversations with an AI chatbot are not protected by legal privileges like the attorney-client privilege. An AI is not a lawyer, a doctor, or a therapist, and therefore, the same confidentiality rules do not apply. This is a critical distinction, especially for legal professionals who might be tempted to use these tools for sensitive matters.
3. Legal Discovery and Subpoenas:
- Discoverable Records: The legal system generally takes a broad view of what constitutes a "discoverable record." This includes digital communications, and courts have previously established that things like emails, text messages, and chat logs are subject to discovery. AI chatbot conversations fall into this category.
- Subpoenas and Court Orders: In the event of litigation, a party can issue a subpoena or obtain a court order compelling the AI company to produce records of a user's conversations. The companies' privacy policies and terms of service typically include a clause stating that they will comply with such legal requirements.
- Relevance: The discoverability of these conversations depends on their relevance to the case. For example, if a lawsuit involves an employee's actions, and they used an AI tool to assist in those actions, those conversations would likely be considered relevant and could be used as evidence.
4. Public Exposure:
Sharing Features: Some platforms have had features that allow users to share conversations via a public URL. While this has been addressed by some companies to prevent search engine indexing, older shared chats may still be publicly available or discoverable. The act of sharing a conversation can make it publicly accessible, further removing any expectation of privacy.
Conclusion:
Given that AI chatbot conversations are stored on cloud servers and are not protected by legal privileges, they are absolutely vulnerable to being found and obtained through a legal discovery process. It is a significant risk to use these tools for any confidential, sensitive, or legally relevant information.