The most useless expensive thing I own is a paper shredder.
I bought it six years ago in a fit of diligence — a cross-cut machine heavy enough that I carried it upstairs in two trips — and I have fed it faithfully ever since: bank statements, the envelope with the account number showing through the little window, the letter from the clinic. Confetti every time. Unreadable. Excellent.
What I did not notice until this January is that across those same six years, I typed into a chat box precisely the material the shredder was meant to protect me from. Not the envelope — the contents. A salary number and what I actually thought about it. A message to a family member I could not bring myself to send for two weeks, rewritten eleven times. Symptoms, before an appointment, phrased the way you only phrase them when you are certain nobody is listening.
That is the purchase I regret, and the regret is not about money. What I bought was the feeling of being careful, and I spent it on the wrong century's problem: shredding paper about my life while typing my life into a box that keeps things.
Which brings us to a Monday in January, and a courthouse in Manhattan.
What a judge actually ordered on January 5
On January 5, 2026, Judge Sidney H. Stein denied OpenAI's objections and affirmed two discovery orders from Magistrate Judge Ona Wang, requiring the company to produce 20 million de-identified ChatGPT conversation logs to the news organizations suing it: the Times, the New York Daily News and other news plaintiffs in the consolidated copyright litigation in Manhattan. Stein found, as Bloomberg Law reported, that "no case law requires the court to order the least burdensome discovery possible."
What is in the pile matters more than the number. Those logs are a random sampling of complete user conversations from December 2022 to November 2024 — whole exchanges, not snippets — which is why the sample could potentially expose up to 80 million individual prompt-and-response interactions. Nobody in it was asked. Nobody was notified. The selection criterion was randomness.
And here is the sentence at the center of it. Weighing these logs against wiretapped phone calls in an older case, the court found the privacy interest weaker here — because these are, in its own words, conversations users voluntarily disclosed to OpenAI and which OpenAI retains in the normal course of its business.
Read it twice. The reasoning is not that what you typed is trivial or unprotected. It is that you handed it over yourself, and the company kept it, because keeping it is what the business does. The same order records tens of billions of such logs retained in the ordinary course of business, and notes that conversations containing nothing belonging to the plaintiffs may still be relevant to OpenAI's fair-use defense — which is how an ordinary chat about a recipe becomes evidence in a copyright fight.
To be fair to the court, privacy was not waved away. Wang had called users' interests "sincere," one factor in the proportionality analysis, satisfied by three safeguards — reducing the volume from tens of billions of logs to 20 million, de-identification, and a standing protective order — and Stein concluded she had adequately balanced those interests against the relevance of the documents. The 20 million figure came from OpenAI itself, offered as "surely more than enough" after the newspapers asked for 120 million.
The word that got flattened in the headlines
Now the correction, because much of the summary since has upgraded this ruling into something it is not. No court has ruled that your conversations with a chatbot are unprivileged; that question was not before Judge Stein. What was decided is narrower and, in daily life, more consequential: those conversations are discoverable. Privilege is a shield you raise after somebody asks. Discoverability is whether they get to ask at all — and that was answered inside a fight about newspaper copyright that has nothing to do with you.
The second flattening is the word "public." These logs were not published, posted or released. They go to the other side's lawyers under what the court stressed are multiple layers of protection — de-identification, a protective order, and an "attorneys' eyes only" designation, meaning cleared professionals, not the internet. OpenAI says it will de-identify the chat logs and scrub personally identifying information, with the Times' technical experts the only people permitted to examine them.
But notice what the qualification concedes: the material needs three locks. OpenAI's own brief told the court the conversations include a massive amount of "inherently private, sensitive, confidential, proprietary, and even privileged information" belonging to users with no stake in the case — the company's characterization, not a court's ruling, but it is the party that has looked. And the practical rule, from a privacy lawyer with the hedge intact, is that your expectations are relevant but do not necessarily prevent disclosure in civil discovery.
The fight that is still going on — and nobody has ruled
Then it got sharper. On July 9, 2026 the news plaintiffs moved for sanctions, alleging a two-year effort to hide OpenAI's ability to search its training data and output logs for their copyrighted work — a "deliberate and systemic effort to obstruct discovery," in the motion's words. The Times, the Daily News, the Chicago Tribune and other outlets are asking for "serious sanctions", saying the company destroyed evidence and hid that capability until an OpenAI expert, in an April deposition, "finally revealed" it — their words, not a finding.
Every word of that is an allegation. As of today, August 16, 2026, there has been no ruling, and the relief sought is narrower than the rhetoric traveling with it: unspecified monetary sanctions, special jury instructions and other measures. OpenAI's answer belongs in the same breath — it says it followed the preservation orders "to the letter", has "gone to herculean efforts" to turn over all of its training data and tens of millions of ChatGPT outputs, and calls the motion an attempt "to rewrite history." That is also the only account I can find of how much has actually changed hands, so treat it as the company's position rather than established fact. And because "destroyed evidence" travels fast: the deletion genuinely undisputed here is that OpenAI deleted the Books1 and Books2 datasets in 2022, about a year before any of these suits began. That is training data, not your chat history.
So is nothing private? Not quite
Here is where I argue against my own headline, because the fatalist reading is tidy and partly wrong.
Stanford's Riana Pfefferkorn worked through the federal communications-privacy statute and concluded that AI prompts and responses are "contents of electronic communications" under the Stored Communications Act, with AI companies counting as covered providers — so statutory protection does attach to what you type. She also notes OpenAI's stated policy of disclosing user content to law enforcement only in response to a valid warrant. Keep those two doors separate, though. A police demand for content runs through criminal process: warrants, probable cause, a statute. January was civil discovery — two private parties, a proportionality analysis, no notice to you. The warrant standard was never what stood between your chat history and a stranger's expert witness.
The second counter punctures a premise I hear constantly, including from myself. Economists analyzing ChatGPT messages report that by July 2025 the tool had reached around 10% of the world's adult population, with non-work messages growing from 53% to more than 70% of all usage — but the emotional share is fairly small: 1.9% of messages fell under Relationships and Personal Reflection, 0.4% under Games and Role Play. Scope that precisely — shares of messages, not users, in a sample running May 2024 to July 2025 — and note the authors flag the contradiction with an earlier estimate putting therapy and companionship at the top. Mostly, people ask for help with work and errands.
The caveat cuts both ways, and the paper says so: the sample deliberately excludes conversations users deleted, users who opted out of sharing messages for training, and users who self-report as under 18. The cleanest picture we have of what people type has the deleted tail cut off — and that tail is where the material I opened with would live. There is a quieter problem than confession, too: researchers who read real conversations with commercial models found personally identifiable information appears in unexpected contexts such as translation or code editing. You do not have to be baring your soul; you just have to paste in the contract, the email, the lab result.
Brazil ran the same question through an entirely different machine
Now change countries, and watch the machinery change with it.
The American answer to "who gets the conversations people had with an AI" came out of a private litigant's discovery request inside a copyright suit. No regulator, no data-protection statute, and nobody asking whether keeping the material was necessary — only whether handing it over was proportional to another party's case.
Brazil starts from the other end. Its data protection law limits processing to the minimum required for the accomplishment of its purposes, "relevant, proportional and non-excessive" — the necessity principle, binding on anyone processing personal data — inside an Article 6 that also imposes purpose limitation, transparency, prevention and accountability. Duties owed to the person whose data it is, before any dispute exists.
And it gets used. When Meta changed its privacy policy to train generative models on Brazilians' posts, the national data protection authority, ANPD, opened a file, and the technical note behind its decision invokes the necessity principle by name — "o princípio da necessidade (Art. 6º, III, da LGPD)" — as the test the company had to meet. On July 2, 2024 the regulator issued a preventive measure requiring Meta to suspend the new policy, with a daily fine of 50,000 reais, on the stated ground of an imminent risk of serious and irreparable or difficult-to-repair damage to fundamental rights.
The structural difference is in one clause: that investigation was initiated ex officio by the Authority, without any third-party provocation. Nobody sued. Nobody complained. And the remedy ran opposite to a discovery order — not "hand the data to the other side" but "stop doing this." It had teeth: Meta suspended the use of its AI assistant in Brazil in response.
It was not permanent, which is the honest half of the comparison. The preventive measure of July 2, 2024 was lifted at the end of August, after a compliance plan the agency judged adequate — though processing data from people under 18 stayed barred. Nor was it a one-off: on December 18, 2024 the same regulator ordered X Corp. to suspend processing of under-18 users' data for generative-AI training.
The agency has kept going in public since: its analysis holds that scraping personal data for AI must rest on a lawful basis and comply with the principles of good faith, purpose limitation, adequacy, and necessity, it named artificial intelligence one of four enforcement axes in a Priority Themes Map for 2026–2027 last December, and it released on Tuesday, July 21, 2026 the English version of its "Technology Radar – Generative Artificial Intelligence." Brazil's comprehensive AI bill, Bill No. 2.338/2023, approved by the Senate in December 2024 and still before the Chamber of Deputies, would make that agency responsible for imposing fines — a bill, not yet a law.
I am not holding Brazil up as paradise. But the comparison is about which question the system is built to ask. In Brasília it was whether this data should have been collected this way at all. In New York it was who gets a copy, given that it exists.
Now run it forward five years
Here I stop reporting and start extrapolating, so weigh it accordingly. Nothing about the January order was exotic: ordinary discovery applied to an extraordinary archive. The question is not whether it happens again but who runs the play next — and the answer is whoever has a docket number and a theory.
Picture the divorce bar in 2031, where the standard first request is no longer text messages and bank records but the assistant history — because the assistant is where the plan was drafted and the budget actually worked out. Picture an employment case turning on what someone knew and when, with a work assistant provisioned by the employer holding the transcript; corporate counsel are already being told that AI systems create discovery obligations that traditional data governance frameworks did not anticipate. Then add memory, which turns disconnected sessions into one continuous record of a person, and agents, which turn conversations into actions — so the log stops recording what you said and starts recording what you did.
None of that needs new technology or a new statute. It needs what happened in January: someone with standing, a relevance argument, a judge weighing proportionality. The rule worked as designed, on material it was never designed for.
What the people who watch this for a living are saying
The alarm is not coming from one corner of the political map, which is the part I find persuasive.
The Electronic Frontier Foundation has been loud on this case since the preservation order, calling it a badly misguided court order and warning — conditional intact — that unless courts limit orders to information that is actually relevant and useful, they will needlessly violate the privacy rights of millions of users. Ask a chatbot a question, the group argues, and you have a reasonable expectation of privacy in that information. The ACLU's Jay Stanley adds the scale point about video, formerly near-impossible to search and now queryable in plain language: material becomes interesting to institutions the moment it becomes searchable.
From the other side of the aisle, the Foundation for American Innovation, a right-of-center tech policy shop, lands on the same worry: when a provider shares your data, you "may have no Fourth Amendment protection because the data was 'shared' with a third party." That is the third-party doctrine, summarized by Congress's own nonpartisan research service as the rule that a person has no legitimate expectation of privacy in information voluntarily turned over to third parties — built for bank records and dialed numbers, now sitting underneath the most intimate text most people have ever produced. Daniel Solove, who teaches privacy law at George Washington, offers the corrective to panic: these problems are "often not new", just longstanding ones AI remixes.
And then there is the man running the company at the center of it. Sam Altman says talking to a therapist, a lawyer or a doctor carries legal privilege, and that "we haven't figured that out yet" for conversations with ChatGPT — he wants the same concept of privacy for AI conversations that we have with a therapist. When the vendor and the civil-liberties groups agree the protection is missing, the argument is no longer about whether, but who writes it and when.
What does this mean for you?
Not paranoia. Calibration. Five things I have changed:
Treat retention as the default and deletion as a request. The January order describes tens of billions of retained logs, and when a new order on October 9, 2025 freed OpenAI from the blanket duty to preserve every future log, data tied to accounts the Times had flagged still had to be kept.
Learn which door your words leave by. A law-enforcement demand for content runs through warrants. Civil discovery does not — it runs through an argument between two parties, neither of them you. The second door is the one that opened in January.
Apply the attorneys'-eyes-only test. Before typing something sensitive, ask whether you would be comfortable with an opposing party's technical experts reading it under a protective order. That is not the worst case; that is the handling regime here.
Use the training opt-out, but know its size. It is real enough that the biggest usage study excluded opted-out users from its sample. It governs whether your text trains a model; nothing in this record suggests it defeats a discovery order.
Split the tool from the confessional. Use the assistant for the task, and take the part that needs confidentiality to a human who actually has privilege. If you run a team, ask your vendor in writing how long conversations are kept and who can be made to produce them; a marketing page instead of a retention schedule is itself an answer.
The lesson, as I see it
My shredder was a good answer to a 1998 question: what if someone goes through my trash. It has no answer to the 2026 question, which is what if someone goes through my archive — one I built voluntarily, a useful little query at a time, inside a system designed to keep things because keeping things is how the product improves.
What I cannot get over is how this was decided. Not by a privacy statute. Not by a legislature weighing what a conversation with a machine ought to be worth. It was settled as a scheduling matter inside somebody else's copyright case, and the reasoning turned on the plainest fact about me: I typed it in myself.
That fact will not change; the rule sitting on top of it can — a statute extending something like professional confidentiality to conversations with an AI, or at minimum a rule that reaching millions of uninvolved people takes more than proportionality arithmetic. Brazil got to that question by building an office whose job is to ask whether the collection was necessary at all. We have no such office, so it reaches us sideways, years late, inside somebody else's fight.
My vote? Type as though it is kept — because it is — and spend some of the discomfort that produces on the argument that would make the typing safe. The docket is not going to volunteer it.
If someone in your life talks to a chatbot the way people used to talk to a diary, forward this to them — not to frighten them, just so they know which of the two it actually is. The HAIA Foundation reads the filings so you don't have to, and this newsletter is where that reading ends up.




