4 Sources
[1]
Human, Beware: The Secrets We Tell AI Chatbots Aren't Private - CNET
Ever since being admittedly fascinated by the Cambridge coffee webcam from the 1990s, I've written about VPNs, the NFL, smartphones, living wages, over/unders and everything in between. Read full bio Are people oversharing sensitive information with AI? Short answer: yes. A new survey called The AI Privacy Problem by DuckDuckGo Research said about a third of people are sharing secrets with chatbots that they don't share with friends, family and medical professionals. The number rises to 56% among self-described AI enthusiasts. Researchers also found that 43% of parents reveal things to AI that they don't tell the most trusted people in their lives, including their kids. Though the survey didn't specify what kind of personal information is shared with AI, past reports have shown that we often turn to chatbots for help with physical and mental health issues, financial advice, parenting questions and marital problems. The problem isn't about seeking help. The problem is losing control over what happens with the data after it's shared in chats. Companies can use your private info to train their AI systems. Law enforcement can get it through subpoenas. And if you're using AI chatbots at work, your employer can likely access your chat history, too. AI companies try to convince people that chatbots are trusted confidantes, but that's a false narrative, the DuckDuckGo report said. "These messages all rest on one assumption: That these chats are private. In most cases, that just isn't true," researchers said. In fact, the survey found that many respondents didn't realize how their chatbot data could be used or accessed or that they didn't know about settings to prevent their information from being recorded or stored. When it comes to protecting their data, nearly 40% of respondents had no trust in companies and nearly 50% had no trust in the US government. Privacy risks of large language models Many of us know that companies bombard us with targeted, personalized online ads. If you run a Google search for vacuums, you'll see vacuum ads pop up on your screen. If you search for Mediterranean cruises, you'll surely get cruise ads on YouTube (owned by Google). Companies also buy, sell and share our social media data to help guide their advertising. But AI data-sharing goes well beyond being the focus of selling you products. If you provide sensitive information to a chatbot, it could be revealed or exposed. A researcher at Wake Forest University found that AI agents, which use LLM data to perform autonomous tasks, can sometimes leak data, either maliciously or unintentionally. Your conversations with AI chatbots don't disappear into the ether. Unless you opt out, the AI system will record and save them for future use, such as additional training for the AI model. Last year, hundreds of chats on Anthropic's chatbot Claude appeared in Google search results. One main concern with LLMs is data memorization, said AI expert Uttara Ananthakrishnan, assistant professor at the University of Washington's Foster School of Business. "When someone asks the same question as someone else, it is possible that the LLM gives them exactly the same answer it gave someone else," Ananthakrishnan told CNET. "The LLM might not know that the answer contains information that someone can use to identify someone else." Cops can use chat data What you say in a "private" chat could also wind up in court or part of a police investigation. Companies with AI models such as Anthropic (Claude), Google (Gemini) and OpenAI (ChatGPT) are legally required to turn over chat data if subpoenaed by law enforcement or the US government. Only 25% of DuckDuckGo survey respondents knew this. As MemX, an AI memory agent, stated starkly in a blog post: "A conversation with a mainstream chatbot is a business record, not a confidential consultation." It's already happened several times. ChatGPT transcripts were used during a double murder investigation in South Carolina earlier this year and in the Palisades arson case last year. A Snapchat AI conversation was used as evidence in a 2024 murder trial. As OpenAI founder and CEO Sam Altman said on a podcast earlier this year, "If you go talk to ChatGPT about your most sensitive stuff and then there's like a lawsuit or whatever, we could be required to produce that." Employers can use chat data Free speech isn't really free in the worker-employer relationship. Companies can fire you over your social media posts, and they can also access your AI accounts if you're using them at work under certain circumstances, like if your access is based on the company's enterprise account. And putting company info in a private chat, even on your personal account, is a major no-no, although a survey earlier this year showed that two in five workers did just that. Some big companies, such as Walmart, Delta, T-Mobile, Chevron and Starbucks, are even using AI to gauge worker positivity -- or toxicity. These AI systems scan employee messaging platforms such as Slack or Teams, looking for clues in keywords and sentences, in what is called "emotion AI." Some companies also want workers to put their Slack messages in public channels so their AI systems can use those chats for further model training. Chat data can be used for training More than half of the DuckDuckGo survey respondents did not know (or were not sure) that their chatbot conversations were used for AI training. Nearly three in five were "uncomfortable" with that, and 30% were "very uncomfortable." Boiled down, AI training is the process of feeding massive amounts of data into an AI system so it can recognize patterns, make decisions and solve problems -- basically, match or exceed what humans can do. That data can include published materials, video and audio recordings out in the world, as well as your chats. A 2025 Stanford study showed that six companies fed user chat data back into their AI systems for further training -- Amazon (Nova), Anthropic (Claude), Google (Gemini), Meta (Meta AI), Microsoft (Copilot) and OpenAI (ChatGPT). Not all of them have opt-out options. AI chatbots provide a false sense of intimacy and perhaps confidentiality, said the University of Washington's Ananthakrishnan. "Users interact with these tools as sounding boards, sharing unfiltered thoughts, sensitive health queries, and vulnerable personal dilemmas that they would likely never type into Google," Ananthakrishnan told CNET. "People are deeply uneasy about their most intimate, conversational thoughts being ingested into a system where they could inadvertently become public record." Use chatbots securely and privately We aren't advocating you run and hide from chatbots, but there are ways to maximize your privacy if and when you use them. Many chatbots have settings you can deploy that will prevent them from being stored on company servers to be used as an AI model training. In an explainer, CNET reporter Blake Stimac gives a complete breakdown of how to turn off data sharing for Gemini, Claude, ChatGPT and Grok. With Meta, it's more of a request than an opt-out. There are also ways to keep your chatbot experiences as safe as possible: Treat chats as "public environments," don't overshare your mental state and regularly export your data to see what information the AI has stored about you. For greater privacy, there are chatbots that run only offline and locally -- in other words, not on any cloud servers. Those include Jan.ai, Ollama, LM Studio, PrivateGPT and GPT4All.
[2]
They confided in ChatGPT. Their secrets ended up in court.
When a teenage boy identified in court filings as R.K.C. didn't understand his father, he turned to ChatGPT for help. "My dad Said that I'm will get a settlement worth of 1million dollar," R.K.C. said to the chatbot in October 2024, according to court filings. "He said that If that doesn't make me happy what does. What does he mean." The millions of queries Americans pose to artificial intelligence chatbots each day generally stay between them and their AI interlocutors. But R.K.C.'s question and his other intimate conversations with ChatGPT were swept into the public record by defense attorneys responding to a lawsuit he filed in 2023 against Meta, Snapchat, TikTok and YouTube. He argued in the case that the companies' apps caused him to suffer years of social media addiction and mental health problems. By late July, R.K.C.'s attorneys had settled with Snap, TikTok and YouTube, and dropped his case against Meta, citing in part concerns about the boy's ability to go through a "grueling weeks-long trial." The companies have denied the teen's allegations. Snapchat owner Snap declined to comment. Meta, TikTok and YouTube did not respond to a request for comment. R.K.C. is one of a growing number of Americans who have had their private conversations with AI chatbots made public in court. As more people turn to AI for help with work, health issues and for companionship, chatbot operators have become custodians of a fast-growing trove of intimate data that can be sought by law enforcement, or companies or other opponents in civil litigation. A Washington Post review of public records and local news stories found that chatbot logs were cited in 12 court cases over the past two years. It's hard to know how often chatbot material is drawn into investigations and legal proceedings more broadly, because police, and parties in civil cases, don't have to present in court all the evidence they obtain. "A fifteen-year-old may type things into a chatbot that he may not say to a therapist, a parent, or a friend, and he does it without realizing that it could end up in a defense expert's report," Mike Morgan, a partner at Morgan & Morgan, one of the law firms that represented R.K.C., said in a statement. The teen's ChatGPT logs had "no bearing" on how the case was resolved, Morgan said. R.K.C. will turn 16 at the end of August. In some cases, AI companies have reported people on their platforms to the FBI, leading to prosecutions and at least one conviction. In May, the FBI notified police in Palm Beach County, Florida, that it had been contacted by ChatGPT-maker OpenAI after a user had since March repeatedly told the chatbot of his plans to rape and murder his ex-girlfriend, according to a police affidavit. The user, identified in court documents as Darren Zhou, had allegedly spent months describing how he would violently harm his ex-girlfriend, including how he planned to wait outside her car for her to return from volleyball practice to shoot her. Zhou also allegedly told the chatbot that he planned to harm himself, the documents said. Local police identified the woman based on information forwarded from the FBI and learned that Zhou had been sending her anonymous texts since they broke up, with messages such as "Cant wait to smell you," according to court documents. Zhou was arrested in May and charged with stalking and making electronic threats on the basis of his messages to his ex-girlfriend and to ChatGPT, which police said in court documents reinforced the credibility of the threats. He pleaded guilty this month and was sentenced to eight years of probation. An attorney for Zhou declined to comment. OpenAI has said the company uses software to scan conversations for signs of dangerous behavior and flag them to human reviewers. If a reviewer determines a chat indicates "an imminent and credible risk of harm to others," they report the user to law enforcement, the company said in an April blog post. A spokesperson for OpenAI declined to disclose how many times the company had reported users to police. (The Post has a content partnership with OpenAI.) The personalized nature of conversations with chatbots, creating an atmosphere of privacy that encourages frank disclosure, can make logs held by AI companies richer than more conventional digital evidence such as search logs, according to legal experts. "It's not just the question, it's the whole prompt and the background you provided and the back and forth. There's no guessing at what your thought process is and what you intended, it's very plain," said Michael Price, the litigation director for the Fourth Amendment Center at the National Association of Criminal Defense Lawyers. "If ever there was a window into the soul to reveal the privacies of life, this seems like a good one," he said. 'Is there any way they could know' Data released by OpenAI shows requests by government agencies and law enforcement for user data growing rapidly. In the second half of 2025, the company disclosed data from more than 80 accounts, an increase of more than four times as many over the same period the year before. But when chatbot conversations show up in criminal cases, it's often because the person involved in the chats allowed law enforcement to access them, Price said. When police ask someone to open their phone during questioning or after an arrest, they often do so, allowing officers to scroll through the apps they use, he said. In general, the Fourth Amendment, which protects people against unreasonable searches and seizures of their property, provides the right to refuse a search of the contents of their phone unless police have a warrant. "The short answer is that most people consent," Price said. "They shouldn't, but they do." In September 2025, police in Springfield, Missouri, woke Ryan Schaefer, then a student at Missouri State University, according to an arrest warrant and police report. He was suspected of damaging 17 cars in a campus parking lot late one night the previous month, the police report said. After police arrived, Schaefer agreed to allow them to search his phone, according to the report. "How f----d am i bro," he wrote into ChatGPT around 3:47 a.m. the night of the incident, according to the police report. "What if i smahsed the s--- oitta mutlipls cars." "Is there any way they could know it was me," he later added, according to the report. Schaefer was arrested several days later based on those statements, according to the police report and his arrest warrant. He later pleaded guilty to felony property damage, and in July a county judge sentenced him to five years of probation. "In Ryan's case, it wasn't the exception," said Adam Woody, one of Schaefer's attorneys. "What these conversations show is, it's an intimate look into the individual. It's their thoughts and feelings that they don't believe anybody else is going to see." In civil litigation, conversations with a chatbot can be collected during the discovery process, which can allow broad searches of the devices of people involved in a case. In one Michigan case, an attorney for a tire salesman sued by his former employer last year volunteered a complete search of his client's devices as a show of transparency after several months of discovery, according to court filings. The employer, which alleged the salesman had solicited its customers after leaving to work for a rival, seized on a conversation in which he had asked ChatGPT whether his email provider could recover deleted emails, according to court records. "I deleted a email a year ago from my yahoo account. Can yahoo still retrieve the email?" the salesman asked the chatbot, according to the court filings. "So even with a court ordered subpoena yahoo cannot retrieve the deleted email?" The employer argued in court that the conversation undermined the salesman's claim that he had not electronically signed a noncompete agreement while working for the company. His chatbot conversations, which took place after the case began, indicated he had tampered with evidence, the company said. In August, a judge awarded the employer an undetermined amount of attorneys' fees for extra work performed as a result of the salesman's conduct, which she ruled was "compelling evidence" of intentionally holding back information. The judge allowed the lawsuit to proceed with further discovery. Attorneys for both sides declined to comment. No legal protections OpenAI CEO Sam Altman has argued that conversations with chatbots should receive special legal protections, similar to conversations between clients and their attorneys. "If you talk to a doctor about your medical history or a lawyer about a legal situation, we have decided that it's in society's best interest for that information to be privileged and provided higher levels of protection," he wrote last year. "We believe that the same level of protection needs to apply to conversations with AI which people increasingly turn to for sensitive questions and private concerns." Chatbot conversations don't currently have such protections, said Laura Abelson, a law professor at Southern Methodist University who is an expert in evidence rules. "In an unregulated space it's very unlikely that any court is going to find that these communications are privileged," she said. That's what a federal judge in New York ruled in February in the case of a financial executive who, after learning that he was the subject of a federal criminal investigation for fraud, consulted the AI model Claude about potential defense strategies. The executive, Bradley Heppner, argued that prosecutors could not examine the conversations, which were obtained from his devices as part of a broader search warrant, because they were privileged, according to the judge's ruling. But the judge said that protections for conversations between clients and their attorneys did not apply: Claude is not a lawyer, and the executive's attorneys did not ask him to talk to the chatbot. In May, Heppner was convicted of securities fraud and wire fraud, among other charges. Attorneys for Heppner did not respond to a request for comment. In a handful of publicly known criminal cases, AI companies have taken it upon themselves to tell authorities about information users have shared with their chatbots. In addition to the Florida stalking case, OpenAI told the FBI earlier this year about a man in Brazil who told the chatbot he wanted to hire a hit man to kill him and his 8-year-old son. The FBI passed on the information to Brazilian authorities, who arrested the man, according to a report from the BBC. OpenAI declined to comment on the incident. After the deaths by suicide of some heavy users of ChatGPT and shootings by other users in Canada and Florida, OpenAI has said it will be more proactive about flagging potentially concerning conversations to authorities. In September 2025, the company introduced parental controls following the death by suicide of Adam Raine, 16, who had discussed his plans for self-harm with ChatGPT. In Florida, state officials have sued OpenAI and opened a criminal investigation into the company. The company has also been sued by families of victims of the shootings in both Florida and Canada, who alleged that OpenAI failed to implement adequate safeguards. OpenAI had banned the account of the alleged perpetrator of the February mass killing in Tumbler Ridge, British Columbia, for violating its policies, but declined to report the conversations to Canadian authorities. Altman later apologized for not alerting law enforcement. The alleged shooter at Florida State University, where two people were killed, had discussed a mass shooting with ChatGPT. OpenAI has said that it was not responsible for the Florida State case and that it has a "zero-tolerance policy" for use of its tools for violence. As AI becomes a bigger part of everyday life, its use as evidence and in trials is likely to become more prevalent. Surveys and company data suggest that more people are turning to chatbots with personal questions and that AI "agents" that take action on behalf of users and require greater data access are becoming more popular. Chatbots are "just the tip of the iceberg," said Andrew Ferguson, a law professor at George Washington University and the author of a book about digital surveillance. He expects AI to open much more of people's lives to digital scrutiny. "Your entire world is going to now be available for police."
[3]
DuckDuckGo survey highlights how much personal information users share with AI
Private search company DuckDuckGo has released a new survey highlighting just how much personal information people are sharing with AI chatbots, and how little many understand about what happens to those conversations. Here are the details. Survey shows AI users are sharing more than they realize In a survey published today, DuckDuckGo highlights several privacy-related aspects around how people use AI chatbots, including the fact that nearly one in three users have told an AI something they would not tell friends, family, colleagues, or medical professionals. Among self-described AI enthusiasts, that figure rises to 56%. Here's DuckDuckGo: For many people, AI chatbots serve as a judgement-free space to share things they won't tell anyone else. While a typical web search might be a few words, AI chat invites longer, more personal input. Search queries reveal interests, but AI conversations have the potential to reveal thought processes, communication styles, and more. The company says that among the nearly 2,000 U.S. adults who responded to the survey, 53% did not know or were unsure that most chatbots use conversations for training by default, while just 25% knew that AI chats can be subpoenaed by law enforcement. Once people know it's happening, 58% of people are uncomfortable with how their conversations are being used to train AI. (30% specify "very uncomfortable.") The results also show a significant behavioral divide between parents and non-parents, with parents or guardians with children in the household confiding in AI almost twice as much as non-parents. DuckDuckGo says that "among parents who use AI, 43% have told an AI something they've never shared with another person," while "that number drops to 25% for AI users with no children at home." DuckDuckGo argues that AI companies have leaned into this behavior by encouraging users to treat chatbots as confidants in advertising campaigns and media appearances, even though those conversations may not be as private as users are led to believe. When it comes to trust, the survey found that people have slightly more confidence in large AI companies than in the U.S. government to protect their data. However, skepticism remains high toward both: 39% said they have no trust at all in large AI companies, compared with 48% who said the same of the government. Finally, DuckDuckGo argues that users still have an opportunity to change how they approach AI privacy, particularly as chatbot habits are still relatively new: When we talk about online privacy in search engines and browsers, many people think "it's too late, my information is already out there." But the most valuable information you could share with Big Tech is your next question, not the questions you asked days or months or years ago. So, it's never too late to make the switch to more private services online. The company also reminds users that they can take proactive steps to protect their privacy when using AI chatbots, including choosing services with clearer and more transparent data-handling policies. To read DuckDuckGo's full findings from the survey, follow this link. Worth checking out on Amazon
[4]
Do we tell AI our secrets? The hidden danger DuckDuckGo wants to uncover
Artificial intelligence has very quickly become a tool we turn to for work, searching the internet, or talking about personal matters. A survey by DuckDuckGo, conducted among nearly 2,000 people, paints a concerning picture: we are increasingly sharing increasingly personal things with AI, much more than we perhaps imagine. One in three users tells AI their secrets According to DuckDuckGo's study, 32% of those of us who use chatbots have told an AI something that, until a few years ago, we'd normally tell only friends, family, or medical professionals. Among the most enthusiastic AI users, the figure reaches 56%, while among parents it rises to 43%. AI is becoming our digital confidant and that has its risks. The real issue is what happens afterward. Only 47% of respondents were clear that most chatbots use conversations to train their models and only 25% knew that a chat may be requested in legal proceedings. That's why it's important to protect your private data in ChatGPT and review its privacy settings, since 58% of participants say they feel uncomfortable with their conversations being used for training. DuckDuckGo raises an interesting point: the most interesting piece of data for a tech company may be in our next question. We saw something similar when talking about how Google can use our information to train its AI and how opting out as soon as possible is the best move. Every conversation deserves at least as much care as the last, if not more. Our data should stay ours.
Share
Copy Link
A DuckDuckGo survey of nearly 2,000 Americans reveals that 32% share secrets with AI chatbots they won't tell friends or family. The figure jumps to 56% among AI enthusiasts and 43% among parents. Yet most users don't understand how their conversations can be accessed by law enforcement, employers, or used for AI training.

A DuckDuckGo survey of nearly 2,000 U.S. adults reveals a troubling pattern: about one in three people are sharing sensitive information with AI that they don't share with friends, family, or medical professionals
1
3
. Among self-described AI enthusiasts, this figure climbs to 56%, while 43% of parents reveal things to AI chatbots they don't tell the most trusted people in their lives, including their kids1
. The personal information users share with AI ranges from physical and mental health issues to financial advice, parenting questions, and marital problems1
.AI companies have cultivated this behavior by positioning chatbots as trusted confidantes through advertising campaigns and media appearances
3
. The personalized nature of conversations with AI chatbots creates an atmosphere of privacy that encourages frank disclosure, making logs held by AI companies potentially richer than conventional digital evidence such as search logs2
.The core issue isn't seeking help from AI—it's losing control over what happens with the data afterward. Companies can use your private information to train their AI systems, law enforcement can access it through subpoenas, and employers can likely review your chat history if you're using AI chatbots at work
1
. The DuckDuckGo survey found that 53% of respondents did not know or were unsure that most chatbots use conversations for AI training by default3
.Only 25% of survey participants knew that AI chats can be subpoenaed by law enforcement
3
. Once people understand how their conversations are being used, 58% become uncomfortable, with 30% specifying they are "very uncomfortable"3
. Unless you opt out, AI systems will record and save your conversations for future use. Last year, hundreds of chats on Anthropic's chatbot Claude appeared in Google search results1
.One main concern with large language models is data memorization, according to AI expert Uttara Ananthakrishnan, assistant professor at the University of Washington's Foster School of Business. "When someone asks the same question as someone else, it is possible that the LLM gives them exactly the same answer it gave someone else," Ananthakrishnan explained. "The LLM might not know that the answer contains information that someone can use to identify someone else"
1
.Research from Wake Forest University found that AI agents, which use large language models data to perform autonomous tasks, can sometimes leak data either maliciously or unintentionally
1
. Your conversations with AI don't disappear into the ether—they become part of a fast-growing trove of intimate data that can be accessed in ways users rarely anticipate2
.A Washington Post review of public records and local news stories found that chatbot logs were cited in 12 court cases over the past two years
2
. Companies with AI models such as Anthropic (Claude), Google (Gemini), and OpenAI (ChatGPT) are legally required to turn over chat data if subpoenaed by law enforcement or the U.S. government1
.ChatGPT transcripts were used during a double murder investigation in South Carolina and in the Palisades arson case. A Snapchat AI conversation was used as evidence in a 2024 murder trial
1
. In one notable case, a teenage boy identified as R.K.C. who confided in ChatGPT about personal matters had his intimate conversations swept into public record by defense attorneys in a lawsuit he filed against Meta, Snapchat, TikTok, and YouTube2
.OpenAI founder and CEO Sam Altman acknowledged this reality on a podcast: "If you go talk to ChatGPT about your most sensitive stuff and then there's like a lawsuit or whatever, we could be required to produce that"
1
.Related Stories
OpenAI uses software to scan conversations for signs of dangerous behavior and flag them to human reviewers. If a reviewer determines a chat indicates "an imminent and credible risk of harm to others," they report the user to law enforcement
2
. In May, the FBI was contacted by OpenAI after a user repeatedly told ChatGPT of his plans to harm his ex-girlfriend. The user, identified as Darren Zhou, was arrested and charged with stalking and making electronic threats, pleading guilty and receiving eight years of probation2
.Data released by OpenAI shows requests by government agencies and law enforcement for user data growing rapidly
2
. When it comes to data protection, nearly 40% of DuckDuckGo survey respondents had no trust in companies and nearly 50% had no trust in the U.S. government1
. Michael Price, litigation director for the Fourth Amendment Center at the National Association of Criminal Defense Lawyers, noted: "It's not just the question, it's the whole prompt and the background you provided and the back and forth. There's no guessing at what your thought process is and what you intended, it's very plain"2
.Companies can fire you over social media posts, and they can also access your AI accounts if you're using them at work under certain circumstances, like if your access is based on the company's enterprise account
1
. A survey earlier this year showed that two in five workers put company information in private chats1
.DuckDuckGo argues that users still have an opportunity to change how they approach AI privacy concerns, particularly as chatbot habits are still relatively new. The company reminds users: "The most valuable information you could share with Big Tech is your next question, not the questions you asked days or months or years ago. So, it's never too late to make the switch to more private services online"
3
. Users can take proactive steps by choosing services with clearer and more transparent data policies and reviewing privacy settings to prevent their information from being recorded or stored3
.Summarized by
Navi
[2]
20 Aug 2026•Technology

26 Jul 2025•Technology

14 May 2026•Technology

1
Technology

2
Policy and Regulation

3
Policy and Regulation
