When you type a question into ChatGPT. Then what? Is this private between you and the app? What if you type questionable content, ask how to hide money from the IRS, or how to fire your boss? Short answer: IRS is clean. Nothing gets reported.
Nothing goes to the police automatically. However, important internal controls can mean your chat is reported to someone.
This is important. The Chat App vendor has a privacy policy that controls what the vendor does by choice. It says nothing about what the vendor can be forced to do. OpenAI deletes your deleted chats in about 30 days. Anthropic keeps safety scores for up to seven years. Google keeps chats a human reviewed for three years, even after you delete them. None of those numbers matter once a court sends a request.
Every major AI company runs the same basic system. Software scans what you type. Most of what it catches goes nowhere. A small slice gets a human. A tiny slice leaves the building.
One category, and only one, is required by law. Child sexual abuse material. US companies must report it to the National Center for Missing and Exploited Children under 18 U.S.C. 2258A, and NCMEC passes cases to police.
This is not a gray area or a judgment call. Anthropic scans uploaded images against NCMEC’s known-image database automatically. A match gets reported with your account details. In the first half of 2026 it filed 15,079 reports. Most were automatic image matches. OpenAI reports all instances and bans the account.
Some things get a person to look, and that person may call someone. Credible threats against a real, named person. Weapons capable of mass casualties. Attacks on power grids or water systems. Coordinated scam or influence operations. And any account that keeps violating the rules.
OpenAI routes threats against other people to specialized human review, and says cases involving an imminent threat of serious physical harm may go to law enforcement.
Everything else. Malware. Exploit code. Drug synthesis. Weapons. Adult content. You get a refusal and a note on your file. Nobody calls anyone.
What moves something from tier 3 to tier 2 is usually not the request. It is doing it over and over.
You will not be told. No company says it notifies you when a human reads your chat. You find out only if you get a warning, a restriction, or a ban.
Self-harm is not reported to police. You have probably read that it is. OpenAI says plainly that it refers threats against other people, and does not refer self-harm cases, on privacy grounds. What you get instead is crisis resources in the chat.
The big US AI companies all offer private chat. None of them make your chat private.
OpenAI’s Temporary Chat stays out of your history and out of training. It is still kept for up to 30 days. Anthropic’s Incognito chats work the same way, also 30 days, longer if flagged. Grok’s Private Chat deletes within 30 days. Google’s Temporary Chat holds 72 hours.
On work accounts, private chats are not private from your employer. Anthropic includes incognito chats in organization data exports and its Compliance API. OpenAI makes temporary chats available to Enterprise admins for 30 days, and says so plainly: that applies “regardless if a custom retention period is defined.”
Microsoft goes further. Its Purview tools let a compliance reviewer see the prompt text you typed, in full. Google’s Vault rules apply to Gemini chats “even if users start temporary chats or delete their conversations.”
Most people find the training toggle and assume they are done. They are not. Anthropic says that if safety classifiers flag a conversation, it may still be reviewed and used – whatever your setting says. OpenAI keeps temporary chats up to 30 days “for safety purposes.” Microsoft is blunt about it: “an opt-out of human review is not available.”
Anthropic keeps flagged content for two years, and its trust and safety scores about you for seven. Google keeps chats a human reviewed for up to three years, and says they “are not deleted when you delete your activity.”
Delete removes it from your view. Sometimes that is all it does.
You already accept this next part. You know your Google searches can end up in court. People have been convicted on their search history.
That was never about Google. It was about the search leaving your machine. Once a query lands on someone else’s server, it becomes their record. And their records can be demanded.
A privacy policy tells you what a company chooses to do. It has nothing to say about what a company can be made to do. Those are separate questions, and only one of them is up to the company.
From least effort to most:
Nothing goes to the IRS on its own. There is no pipeline, no partnership, no automatic report. But the IRS can subpoena like anyone else. If you are already under investigation, your chats are reachable.
Talk to a lawyer and it is privileged. Talk to your accountant and there are protections. Talk to an AI and there is nothing. No confidentiality, no privilege, no professional shield.
If you are the professional, it cuts the other way. Under 26 U.S.C. 7216, a tax preparer who puts client-identifiable information into a public AI tool without consent faces civil and criminal penalties.
Run the model on your own machine. A local AI, or local image and video generation on your own GPU, has no vendor, no server, and no log for anyone to subpoena.
First, one distinction that clears up most confusion. There are two different things people mean by consent.
Subject consent is whether the real person in the image agreed. Depicted consent is whether the scene shows consent. Only the first one is a legal question. The second is a plot.
Apps that strip clothes off a photo. Many are marketed openly by overseas firms. That marketing tells you nothing about your own exposure.
The TAKE IT DOWN Act makes it a crime to publish an intimate image of a real, identifiable adult without their consent. AI-made images count. So does a disclaimer saying it is fake – that is not a defense.
Two things people get wrong. The crime is publishing, not generating. And consent to be photographed is not consent to be published. Those are separate permissions.
If the person is a minor, none of this analysis matters. It is child sexual abuse material, whatever app made it, and it is still illegal when no real child exists.
Since May 2026 platforms also have 48 hours to remove this content once someone reports it. Penalties run past $53,000 per violation.
The May law only covers intimate images. A political deepfake is not intimate, so that law does not touch it.
Other rules do. Many states now require a disclosure label on synthetic political content near an election. Defamation still applies. So does the right to control commercial use of your own face. Parody has real protection.
The line is simple. Non-intimate satire is mostly protected speech.
All adults, invented characters, unusual scenarios, non-human or creature subjects. No real person exists, so nobody’s consent is missing. Nothing here is reportable.
What is left is obscenity law, which is decided by a local jury after the fact, not by a checklist you can follow in advance. Platform rules are far stricter and will stop you long before the law does.
One real trap. Youthful-appearing characters. Species, setting, and art style do not matter. If a character reads as a child, you are in the one category with mandatory reporting.
Most people think the rule is about whether something is public. It is not. The rule is about whether the file moved.
Obscenity law is written around verbs like ship, transport, sell, and distribute. Possession is not on that list. The Supreme Court held in 1969 that what you keep privately at home is protected.
So the ladder looks like this.
Private possession is protected. But the minute you share to one other person, you have opened the door as a publisher.
Cloud backup counts as moving it. Google Drive and Dropbox scan what you upload. Syncing a folder is transmission, even though it feels like storage.
Payment processors outrank the law. Visa and Mastercard rules end more creator accounts than any prosecutor ever has.
Your model has a license too. Plenty of checkpoints and LoRAs forbid adult output even where the law allows it.
A LoRA trained on a real person turns your “generic” AI face into an identifiable individual. You built the evidence into the model.
Age records. Federal recordkeeping rules cover human performers. Synthetic content has none. However, may you need to retain a record that your content is AI created.
Outside the US this all changes. The UK and EU have their own rules.
They refuse things. They keep a log. They send a narrow slice to a human. They report one category to authorities because the law requires it. That is the whole job.
They are not watching for you. They are not calling the police about your prompts.
The odds of an AI company reporting you for anything other than child abuse material are close to zero.
The exposure was never the company’s intentions. It was the transmission. Your prompt left your computer, landed on a server, and became a business record belonging to someone else. Everything after that is out of your hands and out of theirs.
Anything you share – even with one person – can break laws you never read, in places you have never been. And anything you keep to yourself, on your own machine, is protected private possession.
No. Every prompt goes to a company server and becomes their record. Private from other users, yes. Private from the company, a court, or your employer, no.
For child abuse material, yes, and it is required to. For a credible threat against a real person, possibly, after a human reviews it. For anything else, no. You get a refusal or a ban.
Not really. Incognito chats stay out of your history and out of training. Anthropic still keeps them 30 days, longer if flagged, and includes them in organization exports and its Compliance API. So your employer can see them.
Yes. They are stored records with no legal privilege. Prosecutors, opposing lawyers, and divorce attorneys can all reach them.
No. This one is widely misreported. OpenAI refers threats against other people and says it does not refer self-harm cases, on privacy grounds. You get crisis resources in the chat instead.
Yes, and it takes less than you think. Account records need only a subpoena. The actual text needs a warrant. Freezing your data for 90 days needs no judge at all.
Usually within about 30 days. But flagged content sticks around for two years at Anthropic, safety scores for seven, and Google keeps human-reviewed chats three years even after you delete your activity.
No. It stops your words from teaching the model. It does not stop safety review. Anthropic reviews flagged chats regardless of your setting, and Microsoft states that opting out of human review is not available.
On a work account, yes. Admins can export conversations at OpenAI and Anthropic, including private chats. Microsoft compliance tools show your prompt text in full. Google Vault rules survive both temporary chats and deletion.
No. There is no confidentiality and no privilege. And if you are a tax professional, putting client information into a public AI tool without consent carries civil and criminal penalties.
Different question entirely. The issue is not what they report, it is where your data sits and what rights you have over it. Several store data inside China, and none of the eight we checked document a private chat mode. Germany’s regulator went furthest: Berlin’s data protection commissioner reported DeepSeek to Apple and Google for removal, on the finding that “Chinese authorities have extensive access rights to personal data within the sphere of influence of Chinese companies.” Details below.
These are published policies as of September 2026. They describe what each company says it does, not what it does in practice. Policies change, so check the date on the page when you read it.
Two patterns across all eight Chinese vendors. None documents a private or incognito chat mode. And the domestic versions require real-name registration tied to government ID, so nothing there is anonymous by design.
In the realm of Medical Research, Alternative Medicine, the success of clinical trials often hinges…
An Amazon agency should report TACoS (total advertising cost of sales), ACoS, conversion rate, organic…
But for creators who want more freedom to test ideas and build visuals that would…
Key takeaways The strongest case for staff augmentation isn't any single benefit on this list.…
For a car accident lawyer in Tampa, a slip and fall attorney, or a motorcycle…
Modern endpoint threat detection depends on continuous monitoring, behavioral analysis, event correlation, and well-planned response…