Your ChatGPT and Claude conversations are not protected. A federal court ruled it.
Short answer
In February 2026, Judge Jed Rakoff of the Southern District of New York ruled that a defendant’s conversations with Anthropic’s Claude were not covered by attorney-client privilege. The defendant had to surrender thirty-one Claude-generated documents to the prosecution. The reasoning applies to ChatGPT and to every other public chatbot.
What the ruling actually says
Three findings drive the decision, and each one applies broadly enough to matter for any past conversation you may have had on a similar platform.
Privilege requires an attorney. Claude is a software platform, not a lawyer, and it disclaims that role explicitly when asked. The protection that exists between a client and a real lawyer cannot extend to a software interface, regardless of the quality of the answer or the sensitivity of the prompt. The court was clear: an AI chatbot is not a person, and the interaction with one cannot constitute the confidential professional relationship privilege requires.
Work-product protection requires direction. The work-product doctrine protects documents prepared at the direction of an attorney for the purpose of litigation. Heppner queried Claude on his own initiative. The output reflected his theories rather than his attorneys’ strategy. The court held that work-product protection therefore did not apply, even though the output was directly about the case. Self-directed work, no matter how careful, does not get the protection.
Terms of service waive what could have been preserved. By accepting Anthropic’s terms, the user consented to a disclosure framework that is fundamentally incompatible with privilege. Anthropic can retain conversations, can be compelled to produce them, and uses them in limited ways for safety review. None of those properties of the platform are negotiable from inside the chat window. The same logic applies to OpenAI and to Google.
What that means for your past conversations
If you have ever asked Claude or ChatGPT a question that touches a current or anticipated legal matter, that conversation can be subpoenaed. Retention varies by provider and by tier, but the floor is real. ChatGPT keeps conversations for thirty days at a minimum even if you have opted out of training, and is currently under a court-ordered legal hold for material from May to September 2025 that overrides user deletion. Anthropic retains conversations for up to thirty days for users who opted out of training, longer for those who did not. Google keeps Gemini conversations for eighteen months by default.
“Touches a legal matter” is broader than people think. A question about whether a particular asset transfer is reportable. A draft of a workplace complaint. A search for the strongest counter to a co-parent’s accusation. A summary of a contract clause you signed and now regret. A request to anonymize a story for HR. Each of those is a candidate for production if a subpoena hits the right party at the right time.
The harder question is whether the prosecution or opposing party knows the conversations exist. The honest answer is that they often do not, until you tell them. Forensic search of a phone or laptop will surface ChatGPT app history if installed. Discovery requests in civil cases now routinely ask about “AI tools used in connection with the matter.” In employment disputes, employer-managed devices reveal corporate Copilot use. In divorce proceedings, shared devices reveal whatever was on them.
What to do about it now
Three actions, in order of priority. None of them are reversible by anyone but you, and none of them require a lawyer to start.
1. Export and review your past conversations
Before deleting anything, you need to know what is there. ChatGPT exports go through Settings > Data Controls > Export Data and arrive by email within twenty-four hours. Anthropic exports go through Settings > Privacy > Export. Gemini exports go through takeout.google.com. The export is a JSON file. Open it. Search it for names, addresses, dollar amounts, employer names, the names of opposing parties or counsel.
If a current or imminent legal matter touches anything you find, stop. Speak to your lawyer before deleting anything once a matter is on the horizon. The line between routine data hygiene and evidence spoliation is drawn at the point where legal proceedings become reasonably foreseeable. Past that point, deletion can itself be a problem. We covered the distinction in detail in deleting evidence vs protecting yourself.
2. Stop using public chatbots for anything legally adjacent
Going forward, the rule is simple. If a topic could ever end up in a deposition, it does not go into ChatGPT, Claude, Gemini, Copilot, Perplexity, or any other public AI tool. That covers drafts intended for your lawyer, hypothetical reframings of your situation, and “I know someone who” framings, which fool nobody and convince no court.
If you genuinely need an AI tool for legal work, it has to be one your lawyer engaged on your behalf, billed through them, and covered by their engagement letter. Some firms now use Microsoft Copilot for Business or Anthropic enterprise contracts with explicit confidentiality terms. Those are different products from the consumer versions, and the difference is the contract, not the model.
3. Build the rest of your operational hygiene around the same rule
The Heppner decision is a specific application of a general principle: anything you tell a third party becomes their record, and their record becomes available to anyone with a subpoena and patience. That principle covers chatbots. It covers cloud notes. It covers Slack DMs at work. It covers messaging apps that keep server-side history. We laid out the general framework in our piece on how to build a threat model in 20 minutes, and the specific case for legal exposure in what law enforcement can actually access from your accounts.
For people specifically navigating a legal matter where the timing of a document creation will be examined, our piece on metadata vs content in court covers what shows up when a forensic team works through a device or an account export. Most people overestimate the protection of “deleted” and underestimate the trail of “created.”
If you are already mid-case
Two scenarios, and they are different.
If your matter is criminal or quasi-criminal and you have already used a public chatbot to think it through, your lawyer needs to know now., not at the next status conference. They need to know what conversations exist, what they contain, and whether the prosecution has any reason to look. Lying to your lawyer about this, or omitting it, makes their job impossible. The conversations may end up disclosed regardless. The variable that you can still control is whether the conversations surface on your timeline through your own counsel, or on the government’s timeline through theirs.
If your matter is civil (divorce, employment, contract dispute), the calculation depends on jurisdiction and on what discovery the other side is likely to request. Some firms have already updated their engagement letters to warn clients explicitly that AI tool conversations may be discoverable. Sher Tremonte was one of the first. More are following. If your firm has not updated theirs, ask. The conversation is awkward but materially worth initiating.
Frequently asked questions
Does deleting a chatbot conversation make it private?
No. Provider retention overrides user deletion in most cases. ChatGPT is currently under a court-ordered legal hold that preserves conversations from May to September 2025 even when users have deleted them. The fact that you cannot see a conversation in your interface does not mean the provider has destroyed it.
Does using the API instead of the consumer app change the analysis?
Slightly. API usage under business or enterprise terms with explicit confidentiality language gives some additional protection, but the underlying logic of the Heppner ruling still applies: an AI is not an attorney. The API may reduce retention exposure. It does not create privilege.
What about local models running on my own hardware?
That is a different question. A model running on your own machine, with no network connection, leaves no third-party record. The conversations exist only on your hardware. They are still discoverable if the device is seized, but they are not exposed by a subpoena to a third party. For people navigating sensitive matters, this is the only tier that approaches privacy.
If a chatbot tells me it cannot give legal advice, does that protect me?
It protects the provider, not the user. The Heppner court specifically cited Claude’s disclaimer as evidence that no attorney-client relationship existed. The disclaimer is the provider’s defense, not the user’s. Reading it does not retroactively turn a disclosed conversation into a confidential one.
There’s no perfect setup. Anyone selling you perfect is selling fear. The goal is simple: make yourself a harder target than the person next to you.
