Your AI Confidant May Not Keep Your Secrets Private

People are telling AI chatbots secrets they would never share with trusted people in their lives. At the same time, many users do not know that those conversations can help train AI systems, enter public court records, or even appear on the open web.
The privacy gap is growing as chatbots become places where people reveal their deepest thoughts. A full third of all AI users admit they have told a chatbot a secret they would not tell the “trusted people” in their lives, yet the protections around those conversations remain unclear to many regular users.
Users Are Sharing More Than They Realize
A DuckDuckGo survey found that 53 percent of regular users did not know AI chatbots are training on data obtained through their conversations. That means many people may treat a chatbot exchange as a private moment without understanding that the conversation can become part of the data used to train an AI system.
The issue reaches beyond training data. The survey found that 75 percent of users did not realize conversations with large language models, or LLMs, can easily be subpoenaed by police. A message written to an AI system can feel personal, but the legal status of that conversation creates a very different picture.
Jen King, a privacy researcher at Stanford Institute for Human-Centered Artificial Intelligence, offered a direct warning: “You can’t be sure that it’ll be totally private.”
That uncertainty matters because chatbot conversations often contain the kind of material people protect most closely. The fact that a full third of AI users have shared secrets with chatbots shows how quickly these systems have moved into personal spaces, even as users remain unsure about who may access their words.
Chatbot Conversations Are Reaching Public Records
There have been a dozen court cases where chatbot transcripts were cited in the public record over the last two years. Those cases show that AI conversations are not sealed away from legal proceedings simply because they took place inside a chatbot.
The number is small enough to miss at a glance, but it carries a clear message: transcripts can travel beyond the original conversation. Once a chatbot exchange enters a public record, words written in a private-looking interface can become part of a case that other people can see.
The exposure risk also extends beyond courtrooms. A whole trove of chats with Anthropic’s chatbot Claude had been exposed to the open web, creating a direct example of how conversations can escape the setting where users wrote them.
That incident gives the privacy concern a sharper edge. Users are not only facing questions about how OpenAI or Anthropic handle chatbot data; they are also facing the possibility that conversations can become visible outside the company’s intended experience.
The Trust Gap Is Now the Story
AI systems invite personal disclosure while users lack basic information about what happens next. The survey figures capture that mismatch: 53 percent of regular users did not know about training on conversation data, and 75 percent did not know police could subpoena LLM conversations.
Those numbers sit beside the finding that a full third of AI users have shared a secret with a chatbot. Together, they describe a trust gap built into everyday AI use. People are opening up to systems that feel available and responsive, but many do not understand the path their words can take.
The court cases and exposed Claude chats turn that gap into something concrete. A conversation can move from a chatbot window to a legal record, or from a private exchange to the open web. The boundary between personal disclosure and public exposure is not as firm as many users assume.
Joe Wilkins, an author and correspondent, is identified alongside this reporting on the issue, while DuckDuckGo conducted the survey that measured user awareness. The findings place privacy knowledge at the center of the AI conversation, not at its edges.
As of Sep 5, 2026, at 9:01 AM EDT, the message is hard to miss: an AI chatbot may feel like a confidant, but users cannot assume their words will remain confined to that exchange. The next phase of AI trust will depend on whether people understand what happens to their secrets before they share them.




