Your AI Conversations Were Never Private – Now We Have Proof

Your AI Conversations Were Never Private – Now We Have Proof

Ondřej Barták
Ondřej Barták
Entrepreneur and Programmer
11. 6. 2025
8 minutes reading
Your AI Conversations Were Never Private – Now We Have Proof

Your AI conversations were never private – now we have proof

Remember when you thought your deleted ChatGPT conversations were actually gone? Well, about that...

The court order that changes everything

A U.S. federal judge has just ordered OpenAI to preserve ALL user conversations indefinitely. This includes those you deleted, those "temporary" chats that were supposed to disappear, trade secrets shared through the OpenAI API—everything. The order is part of an ongoing lawsuit by The New York Times and affects hundreds of millions of users worldwide.

Magistrate Judge Wang issued a sweeping order requiring OpenAI to preserve all records of ChatGPT user chats indefinitely. This order arose from a request by The New York Times, which speculates that such data may contain evidence relevant to its lawsuit. The New York Times filed a lawsuit against OpenAI and Microsoft, alleging that its copyrighted articles were used without permission to train large language models such as ChatGPT.

Does the court order also apply to Czech users?

Yes, this U.S. court order applies to all ChatGPT users globally, including users from the Czech Republic and throughout the European Union. This means that your conversations with ChatGPT in Czech are now also being stored indefinitely, regardless of whether you deleted them or requested their deletion.

This situation creates a legal conflict with the European GDPR (General Data Protection Regulation), which guarantees the right to data erasure (also known as the "right to be forgotten"). The GDPR imposes strict requirements on data retention and processing, and the indefinite retention of user conversations without user consent directly conflicts with these rules.

For Czech users, this means that their data is now being retained in violation of the European privacy standards to which they are accustomed. OpenAI must comply with the U.S. court order, even though doing so violates its obligations to European users under the GDPR.

OpenAI is not giving up without a fight

OpenAI is not taking this order lightly. In its blog post, it called the demand a "sweeping and unnecessary" overreach that "fundamentally conflicts with the privacy commitments we have made to our users." The company emphasizes that it allows users to opt out and request the permanent removal of deleted conversations from its systems within 30 days.

On June 3, 2025, OpenAI asked U.S. District Judge Sidney Stein to overturn the May data preservation order. The company is actively filing legal objections in an effort to have the order revoked, arguing that the indefinite retention of user conversations is an overly broad demand that conflicts with its long-standing commitments to protecting user privacy.

In its official statement, OpenAI said that the technical and legal implementation of this order would take months and create significant technical and legal challenges, particularly given the conflicting requirements of EU privacy laws.

Sam Altman and the concept of "AI privilege"

Sam Altman, CEO of OpenAI, went even further and proposed the concept of "AI privilege." This idea suggests that conversations with AI should be protected in a manner similar to communications with lawyers or doctors. This would mean that user chats with AI systems would be confidential and protected from sweeping legal disclosure in order to safeguard privacy.

On the social network X, Altman expressed his concerns about the court order and publicly advocated for the need for "AI privilege" to ensure that users' conversations with AI remain confidential, much like conversations with doctors or lawyers. It is not a bad idea, especially considering that many people actually use ChatGPT as their doctor, therapist, and lawyer.

Who is affected by the court order

According to OpenAI, the order applies to users of the ChatGPT Free, Plus, Pro, and Team versions, along with standard API customers. If you are a ChatGPT Enterprise or Edu user, or an API customer with a Zero Data Retention (ZDR) agreement, your data is not covered by the order. This distinction shows that some users paying for premium services have better privacy protection than ordinary users. The data preservation order affects users with ChatGPT Free, Plus, Pro, and Team subscriptions, as well as API users without a ZDR agreement. Enterprise, EDU, and API users with ZDR are not affected by this order. This creates unequal privacy protection among different types of users, with those who pay for the most expensive services receiving better protection.

For Czech users, this specifically means that if you use the standard versions of ChatGPT (Free, Plus, Pro, or Team), your data is included in the preservation order. Only companies and institutions with the most expensive Enterprise or Edu licenses are exempt from this order.

Security safeguards and data access

OpenAI assures users that the preserved data will not automatically be shared with The New York Times or third parties. Access to this data is strictly controlled under legal protocols. The company has also explored the possibility of anonymizing the retained data as a compromise to address privacy concerns, but the preservation order remains in effect while the appeal proceedings continue.

Data collected by AI companies

This decision raises the question: what data are we actually talking about? While the court order is new, data collection certainly is not. A chart recently appeared on Reddit providing a snapshot of how much data AI chatbots may collect (based on their own App Store privacy disclosures).

Chart of potential data collection

Meta AI takes the crown, collecting a staggering 32 out of 35 possible data types, including financial information, health data, and even "sensitive information" such as your political views. Google Gemini came in second with 22 data types, including your precise location and contacts. No surprise—Google will be Google. ChatGPT and Microsoft Copilot are surprisingly restrained, collecting only 10 data types each. And Elon's Grok is one of the lightest data collectors on the list.

The misleading nature of data collection disclosures

The catch is that this is based on what companies claim they collect. As some have pointed out, these labels can be problematic. ChatGPT discloses location tracking on Android, but not on iOS. Meta probably checked every box simply to cover itself legally. And Apple's reviews cannot detect server-side tracking that occurs after you press send. These figures, based on companies' own claims, may be misleading. Actual data collection may differ significantly from what companies officially report. Server-side tracking that takes place after a message is sent often escapes scrutiny and may be far more extensive than officially disclosed practices.

GDPR versus the U.S. court order

For Czech and European users, this case creates an unprecedented situation in which U.S. law comes into conflict with European privacy standards. The GDPR requires companies to respect users' right to have their personal data erased and to minimize data retention to the shortest possible period.

The indefinite retention of all ChatGPT conversations, including those deleted by users, directly conflicts with these principles. This creates a legal paradox in which OpenAI must violate European privacy laws in order to comply with a U.S. court order.

The Czech Office for Personal Data Protection and other European regulatory authorities could intervene in the future if this situation continues. This could result in fines for OpenAI under the GDPR, which may amount to up to 4% of the company's global annual revenue.

The significance of the dispute for the future

The OpenAI court order proves that no matter what these companies claim about deleting data, it is essentially meaningless when a judge says, "preserve everything." Your late-night anxiety spirals, your business strategy sessions, your secret project prompts—all of it will be retained for potential legal review.

This creates a dangerous precedent. Every other AI company is watching how this unfolds, and you can bet their lawyers are thinking, "Maybe we should preserve everything too." Unless we achieve Sam's vision of user-AI privilege to protect us, we may be entering an era in which every conversation with your AI could become part of a permanent record.

The outcome of this legal battle could set significant precedents for privacy and data retention in the AI industry. If the court rules in favor of The New York Times, it could lead other AI companies to begin proactively retaining all user data to avoid future legal problems.

Recommendations for Czech users

It is important for Czech users to realize that their conversations with ChatGPT are no longer as private as they may have thought. The following is recommended:

  1. Limit the sharing of sensitive information - do not enter personal data, financial information, or trade secrets into ChatGPT.
  2. Consider upgrading to the Enterprise version - if you are a business user, the Enterprise version offers better privacy protection.
  3. Monitor developments in the case - the situation may change depending on the outcome of OpenAI's appeal.
  4. Learn about alternatives - there are AI tools with better privacy standards.

The new reality of AI privacy

This case reveals a fundamental problem with how we perceive privacy in the new age of artificial intelligence. What we considered private conversations with AI assistants may now become the subject of court proceedings and legal disputes. OpenAI is actively fighting this order, but the outcome will have far-reaching consequences for the entire AI industry.

For Czech users, the situation is particularly complicated because they find themselves in a legal vacuum between U.S. courts and European privacy standards. Consumers should be aware that their "deleted" conversations with AI may not actually be deleted and may be retained indefinitely, in violation of their rights under the GDPR.

This precedent may change how we think about privacy in the digital age and highlights the urgent need for international coordination of legal frameworks protecting privacy in AI technologies. Until clear regulations are established, users should be cautious about what information they share with AI systems, regardless of where they live.

Category:AI
Did you enjoy this article?
Discover more interesting posts on our blog
Back to blog

Related posts

Altman Announced the Singularity Days After His Models Escaped the Lab on Their OwnAltman Announced the Singularity Days After His Models Escaped the Lab on Their Own
OpenAI chief Sam Altman declared on the Relentless podcast that humanity has already entered the singularity. “We’re like, in the singularity now,” he said verbatim. For decades, the term belonged more to science-fiction literature
6 min read
28. 7. 2026
AI Remixed a Madonna Song—and Now It Tops the Charts in Australia. Musicians Are Furious.AI Remixed a Madonna Song—and Now It Tops the Charts in Australia. Musicians Are Furious.
Since April, Australian radio has been playing a dance remake of Madonna’s hit Like a Prayer on repeat. Released by Queensland DJ Josh Fawaz, it tops the radio airplay chart and has 35 million Spotify streams.
6 min read
28. 7. 2026
Claude Opus 5 Built a Shooter from Scratch. What Can Claude of Duty Do?Claude Opus 5 Built a Shooter from Scratch. What Can Claude of Duty Do?
A first-person shooter that runs directly in the browser, with its own physics and eleven separate code modules. Around 55,000 lines in total, split across eleven subsystems and built on Thr
4 min read
28. 7. 2026
Přihlaste se k odběru našeho newsletteru
Zůstaňte informováni o nejnovějších příspěvcích, exkluzivních nabídkách, a aktualizacích.
CodedTrip

Operated by CodedTrip LLC, USA.

YouTube
TikTok