Your AI conversations were never private – now we have proof
Remember when you thought your deleted ChatGPT conversations were actually gone? Well, about that...
The court order that changes everything
A U.S. federal judge has just ordered OpenAI to preserve ALL user conversations indefinitely. This includes those you deleted, those "temporary" chats that were supposed to disappear, trade secrets shared through the OpenAI API—everything. The order is part of an ongoing lawsuit by The New York Times and affects hundreds of millions of users worldwide.
Magistrate Judge Wang issued a sweeping order requiring OpenAI to preserve all records of ChatGPT user chats indefinitely. This order arose from a request by The New York Times, which speculates that such data may contain evidence relevant to its lawsuit. The New York Times filed a lawsuit against OpenAI and Microsoft, alleging that its copyrighted articles were used without permission to train large language models such as ChatGPT.
Does the court order also apply to Czech users?
Yes, this U.S. court order applies to all ChatGPT users globally, including users from the Czech Republic and throughout the European Union. This means that your conversations with ChatGPT in Czech are now also being stored indefinitely, regardless of whether you deleted them or requested their deletion.
This situation creates a legal conflict with the European GDPR (General Data Protection Regulation), which guarantees the right to data erasure (also known as the "right to be forgotten"). The GDPR imposes strict requirements on data retention and processing, and the indefinite retention of user conversations without user consent directly conflicts with these rules.
For Czech users, this means that their data is now being retained in violation of the European privacy standards to which they are accustomed. OpenAI must comply with the U.S. court order, even though doing so violates its obligations to European users under the GDPR.
OpenAI is not giving up without a fight
OpenAI is not taking this order lightly. In its blog post, it called the demand a "sweeping and unnecessary" overreach that "fundamentally conflicts with the privacy commitments we have made to our users." The company emphasizes that it allows users to opt out and request the permanent removal of deleted conversations from its systems within 30 days.
On June 3, 2025, OpenAI asked U.S. District Judge Sidney Stein to overturn the May data preservation order. The company is actively filing legal objections in an effort to have the order revoked, arguing that the indefinite retention of user conversations is an overly broad demand that conflicts with its long-standing commitments to protecting user privacy.
In its official statement, OpenAI said that the technical and legal implementation of this order would take months and create significant technical and legal challenges, particularly given the conflicting requirements of EU privacy laws.
Sam Altman and the concept of "AI privilege"
Sam Altman, CEO of OpenAI, went even further and proposed the concept of "AI privilege." This idea suggests that conversations with AI should be protected in a manner similar to communications with lawyers or doctors. This would mean that user chats with AI systems would be confidential and protected from sweeping legal disclosure in order to safeguard privacy.
we have been thinking recently about the need for something like "AI privilege"; this really accelerates the need to have the conversation.
— Sam Altman (@sama) June 6, 2025
imo talking to an AI should be like talking to a lawyer or a doctor.
i hope society will figure this out soon.
On the social network X, Altman expressed his concerns about the court order and publicly advocated for the need for "AI privilege" to ensure that users' conversations with AI remain confidential, much like conversations with doctors or lawyers. It is not a bad idea, especially considering that many people actually use ChatGPT as their doctor, therapist, and lawyer.
Who is affected by the court order
According to OpenAI, the order applies to users of the ChatGPT Free, Plus, Pro, and Team versions, along with standard API customers. If you are a ChatGPT Enterprise or Edu user, or an API customer with a Zero Data Retention (ZDR) agreement, your data is not covered by the order. This distinction shows that some users paying for premium services have better privacy protection than ordinary users. The data preservation order affects users with ChatGPT Free, Plus, Pro, and Team subscriptions, as well as API users without a ZDR agreement. Enterprise, EDU, and API users with ZDR are not affected by this order. This creates unequal privacy protection among different types of users, with those who pay for the most expensive services receiving better protection.
For Czech users, this specifically means that if you use the standard versions of ChatGPT (Free, Plus, Pro, or Team), your data is included in the preservation order. Only companies and institutions with the most expensive Enterprise or Edu licenses are exempt from this order.
Security safeguards and data access
OpenAI assures users that the preserved data will not automatically be shared with The New York Times or third parties. Access to this data is strictly controlled under legal protocols. The company has also explored the possibility of anonymizing the retained data as a compromise to address privacy concerns, but the preservation order remains in effect while the appeal proceedings continue.
Data collected by AI companies
This decision raises the question: what data are we actually talking about? While the court order is new, data collection certainly is not. A chart recently appeared on Reddit providing a snapshot of how much data AI chatbots may collect (based on their own App Store privacy disclosures).

Meta AI takes the crown, collecting a staggering 32 out of 35 possible data types, including financial information, health data, and even "sensitive information" such as your political views. Google Gemini came in second with 22 data types, including your precise location and contacts. No surprise—Google will be Google. ChatGPT and Microsoft Copilot are surprisingly restrained, collecting only 10 data types each. And Elon's Grok is one of the lightest data collectors on the list.
The misleading nature of data collection disclosures
The catch is that this is based on what companies claim they collect. As some have pointed out, these labels can be problematic. ChatGPT discloses location tracking on Android, but not on iOS. Meta probably checked every box simply to cover itself legally. And Apple's reviews cannot detect server-side tracking that occurs after you press send. These figures, based on companies' own claims, may be misleading. Actual data collection may differ significantly from what companies officially report. Server-side tracking that takes place after a message is sent often escapes scrutiny and may be far more extensive than officially disclosed practices.
GDPR versus the U.S. court order
For Czech and European users, this case creates an unprecedented situation in which U.S. law comes into conflict with European privacy standards. The GDPR requires companies to respect users' right to have their personal data erased and to minimize data retention to the shortest possible period.
The indefinite retention of all ChatGPT conversations, including those deleted by users, directly conflicts with these principles. This creates a legal paradox in which OpenAI must violate European privacy laws in order to comply with a U.S. court order.
The Czech Office for Personal Data Protection and other European regulatory authorities could intervene in the future if this situation continues. This could result in fines for OpenAI under the GDPR, which may amount to up to 4% of the company's global annual revenue.
The significance of the dispute for the future
The OpenAI court order proves that no matter what these companies claim about deleting data, it is essentially meaningless when a judge says, "preserve everything." Your late-night anxiety spirals, your business strategy sessions, your secret project prompts—all of it will be retained for potential legal review.
This creates a dangerous precedent. Every other AI company is watching how this unfolds, and you can bet their lawyers are thinking, "Maybe we should preserve everything too." Unless we achieve Sam's vision of user-AI privilege to protect us, we may be entering an era in which every conversation with your AI could become part of a permanent record.
The outcome of this legal battle could set significant precedents for privacy and data retention in the AI industry. If the court rules in favor of The New York Times, it could lead other AI companies to begin proactively retaining all user data to avoid future legal problems.
Recommendations for Czech users
It is important for Czech users to realize that their conversations with ChatGPT are no longer as private as they may have thought. The following is recommended:
- Limit the sharing of sensitive information - do not enter personal data, financial information, or trade secrets into ChatGPT.
- Consider upgrading to the Enterprise version - if you are a business user, the Enterprise version offers better privacy protection.
- Monitor developments in the case - the situation may change depending on the outcome of OpenAI's appeal.
- Learn about alternatives - there are AI tools with better privacy standards.
The new reality of AI privacy
This case reveals a fundamental problem with how we perceive privacy in the new age of artificial intelligence. What we considered private conversations with AI assistants may now become the subject of court proceedings and legal disputes. OpenAI is actively fighting this order, but the outcome will have far-reaching consequences for the entire AI industry.
For Czech users, the situation is particularly complicated because they find themselves in a legal vacuum between U.S. courts and European privacy standards. Consumers should be aware that their "deleted" conversations with AI may not actually be deleted and may be retained indefinitely, in violation of their rights under the GDPR.
This precedent may change how we think about privacy in the digital age and highlights the urgent need for international coordination of legal frameworks protecting privacy in AI technologies. Until clear regulations are established, users should be cautious about what information they share with AI systems, regardless of where they live.



