Can Your AI Chats Be Used in Court?
Yes — your ChatGPT, Claude or Gemini conversations are stored data, so they can be subpoenaed and produced in court. What courts have already ruled, and the fix.
Yes — your conversations with a consumer AI chatbot (ChatGPT, Claude, Gemini) can be used in court. They are electronically stored data held by the provider, just like an email or a file: that makes them reachable by subpoena, by a discovery production order, or by a search warrant. No professional privilege covers a consumer chatbot, and OpenAI's CEO has said so publicly. The only guarantee is about the content: what was never transmitted in the clear cannot be produced.
Why an AI chat is evidence like any other
From a legal standpoint, a chatbot conversation is nothing fleeting. As soon as it's typed, it becomes electronically stored information (ESI) held by the provider — exactly like an email, a message or a document. The procedural framework already exists: in the United States, Rule 34 of the Federal Rules of Civil Procedure puts electronically stored information on equal footing with paper documents. It covers “writings, drawings, graphs, charts, photographs, sound recordings, images, and other data or data compilations stored in any medium,” which captures conversation logs and their metadata, and lets a party demand their production in a usable form.
In practice, three routes obtain these logs: the subpoena, the discovery production order, and the search warrant. And this isn't theoretical: legal analyses note that courts now treat these logs as ordinary ESI, brushing aside confidentiality or burden objections.
No professional privilege on a consumer chatbot
Many users ask AI legal, medical or intimate questions assuming a confidentiality comparable to a professional's. That's a blind spot. A U.S. federal court ruled that a litigant could not claim privilege over documents generated with an AI: the judge noted that the service's privacy policy allowed collection of inputs and outputs, as well as their disclosure to third parties — so the user had no reasonable expectation of confidentiality. That's a separate point from mere admissibility of the evidence: there is no legal shield to invoke.
Worse, the effect can spread. Pasting into a public chatbot information that is otherwise privileged can amount to a waiver of that privilege: once the confidential content is shared with a third-party tool whose terms allow storage, reuse or disclosure, that information becomes potentially discoverable by opposing parties, regulators and authorities.
NYT v. OpenAI: deleting a chat doesn't erase it
The idea that deleting a conversation makes it vanish doesn't survive litigation. In The New York Times v. OpenAI dispute, a preservation order forced OpenAI to preserve and segregate output logs that would otherwise have been deleted — including conversations erased by users, beyond the usual 30-day deletion policy. When a proceeding mandates retention, your “delete” button no longer carries the weight. OpenAI published its own response to these data demands, but the obligation stood.
That obligation then led to a massive production: a federal judge affirmed the order requiring OpenAI to hand over roughly 20 million ChatGPT conversation logs (de-identified) as evidence in the copyright litigation, overriding confidentiality and burden objections. The lesson reaches beyond this case: a conversation log is treated like any other stored data, and it can be produced at scale.
- A preservation order can neutralize your deletion — “erased” chats are preserved by court order.
- Logs can be produced at very large scale, de-identified but very real.
- In criminal matters, prompts sent to ChatGPT have already been entered into prosecution files, and law enforcement can obtain logs by subpoena, order or warrant — including a federal warrant aimed at identifying a user from their prompts.
| You assume | The reality |
|---|---|
| “My AI chat is as private as talking to a lawyer” | No professional privilege covers a consumer chatbot |
| “I delete it, so it can't be found” | A preservation order preserves even erased chats |
| “No one would go after my exchanges” | They're subpoenable ESI — already produced by the million and in criminal cases |
The fix: what was never typed in the clear can't be produced
Since retention and production are out of your control, the only guarantee is about the content itself. What was never transmitted to the provider in the clear can't be subpoenaed or produced: it simply doesn't exist in the log. Anonymizing sensitive data before pasting it into a chatbot — replacing names, identifiers, keys and amounts with tokens — reduces what ends up, if anything, in subpoenable logs.
- 1Assume an AI conversation is retainable and producible — not confidential.
- 2Don't paste anything covered by professional privilege without neutralizing it first.
- 3Anonymize sensitive data before sending: the token travels in place of the real value.
That's exactly what ONYRI Sanitize is for: the engine replaces sensitive data with reversible tokens before sending; detection and the token↔value mapping stay in your browser, and only anonymized text reaches the model. If a conversation is one day retained, subpoenaed and produced, it only contains tokens — not your real information. De-tokenization stays local and never travels.
Frequently asked questions
- Can my ChatGPT conversations be subpoenaed and used in court?
- Yes. A conversation with ChatGPT, Claude or Gemini is electronically stored data held by the provider, reachable by subpoena, by a discovery production order, or by warrant. FRCP Rule 34 puts it on equal footing with a paper document, and ChatGPT logs have already been produced by the million and entered into criminal files.
- Is deleting an AI conversation enough to keep it out of evidence?
- No. In NYT v. OpenAI, a preservation order forced OpenAI to preserve logs beyond its usual 30-day deletion, including chats erased by users. When a proceeding mandates retention, deletion no longer guarantees erasure. Only content that was never transmitted in the clear stays out of reach.
- Is there any professional privilege on an AI chatbot?
- No, not on a consumer chatbot. A U.S. federal court held that privilege can't be claimed over documents generated with an AI, for lack of a reasonable expectation of confidentiality. OpenAI's CEO has himself warned that no legal confidentiality exists and called for an “AI privilege.”
Sources & references
- Sam Altman warns there's no legal confidentiality when using ChatGPT as a therapist (OpenAI required to produce exchanges if subpoenaed) — TechCrunch
- AI conversations treated as stored data (ESI) producible in discovery, absence of privilege, and the order to turn over 20 million ChatGPT logs — Tyson & Mendes LLP
- Rule 34 of the Federal Rules of Civil Procedure: production of electronically stored information (ESI), on equal footing with paper documents — Legal Information Institute (Cornell Law School)
Keep your sensitive data in your browser
ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.