On August 7, 2026, Mali Yahalomi and her daughter Liel vanished during a trip through Europe, last confirmed in Vienna. A week of national anguish and an international manhunt followed. They were found alive on a bus in Buenos Aires. According to Israeli media reports, investigators got there by recovering their deleted Google Gemini history: questions about leaving the country unnoticed, buying a phone without ID, and which countries have no extradition treaty with Israel. 
No crime was committed. But the case landed hard because it exposed a comforting illusion millions of people carry into every chatbot window: that a conversation with AI is a conversation with no one at all. It isn’t. It is a written record, sitting on a company server, that can be recovered, subpoenaed, or handed to a detective long after you typed it and moved on.
THIS IS NOT AN ISOLATED CASE
AI chat logs have become a recurring source of evidence across a variety of countries, courts, and proceedings, and none of the people involved expected it. In California, prosecutors in the 2025 Palisades Fire case pointed to the defendant’s ChatGPT history, including a message sent hours after the fire began asking whether he could be blamed if a cigarette had caused it, as evidence of a guilty conscience. In Missouri, a college student vandalized seventeen cars, then opened ChatGPT ten minutes later and described exactly what he had done; police found the transcript still on his phone. In Virginia, a teenager was convicted of murder partly on a Snapchat AI conversation from hours before the shooting, in which he asked what would happen if he used a gun on someone. In Connecticut, a man’s months of ChatGPT conversations, in which the chatbot repeatedly validated his paranoid delusions about his own mother, became the central exhibit in the wrongful death suit filed after he killed her and himself. Different countries, different legal systems, the same underlying lesson: once something is typed into a chatbot, it can resurface anywhere a court, regulator, or opposing lawyer has a reason to look.
THE MYTH OF THE PRIVATE CONVERSATION
A chatbot feels private for a simple reason: there is no other person on the line, no name at the top of an inbox, none of the social friction that makes most of us pause before writing something sensitive in an email or a text. That absence of an audience is exactly what makes the interface feel like private thought rather than written communication, and it is exactly why it is the wrong mental model to bring into the conversation.
The more accurate picture is this: a chatbot is a cloud service, tied to your account, your IP address, your browser, and a commercial company’s data retention policy. Every message you send is processed and, in most cases, stored, at least for some period, in a system built for that company’s own product, safety, and legal needs, not for your confidentiality. A closer analogy than “thinking out loud” is writing a letter and handing it to a company employee to file away. The letter might be shredded after thirty days. It might sit in a legal hold indefinitely because of a case that has nothing to do with you. Either way, once it leaves your hands, you no longer control what happens to it.
Deletion, in particular, is a promise rather than a fact. Most AI products advertise that a deleted or temporary chat is removed from their systems within a set window, often thirty days. That promise holds only until a legal process requires otherwise, and it does not matter whether you were ever a party to the case that triggered the requirement. For roughly four months in 2025, a US court order issued in an unrelated copyright lawsuit against a major AI provider required the company to stop deleting chat logs altogether, including conversations users had already deleted themselves, because the litigation needed the underlying data preserved as potential evidence. The order was eventually lifted, but for that entire period, every user of the product, hundreds of millions of people who had nothing to do with the lawsuit, had their deleted and temporary chats retained anyway, with no way to opt out.
THE LEGAL REALITY
Setting the psychology aside, it is worth understanding the legal mechanics in plain terms, because they are less mysterious, and less exotic, than most people assume.
A chat log is treated as just another form of stored electronic communication, obtained the same way emails and text messages are: through a subpoena in a civil matter, a warrant in a criminal one, or a company’s own decision to comply with a valid legal request under its terms of service. Every major AI provider’s terms include some version of a clause reserving the right to disclose user data to comply with law or legal process. That clause is standard across the industry. It simply means the privacy promises elsewhere in the policy carry a built-in exception.
More importantly, there is no special legal privilege protecting a conversation with a chatbot the way there is for a conversation with your lawyer, your doctor, or in many jurisdictions your spouse or clergy. This is genuinely new legal ground, and the first courts to address it have not agreed with each other. In February 2026, a federal court in New York held that a criminal defendant’s own exchanges with a consumer AI chatbot, in which he had worked through his defense strategy, were protected by neither attorney-client privilege nor work-product protection. The chatbot was not a lawyer, and he had not been directed by counsel to use it, so showing the output to his own attorney afterward did not retroactively wrap it in privilege. That same week, a federal court in Michigan reached the opposite result on different facts: a self-represented litigant’s own drafting sessions with a chatbot stayed protected as work product, because she never shared them with the opposing side, and work-product protection, unlike privilege, is lost only when material reaches an adversary, not merely a third party. Read together, the two rulings do not mean AI conversations are always exposed. They mean the outcome turns on variables an ordinary person has no reliable way to judge in the moment: which protection applies, whether a lawyer directed the AI use, whether the material ever reached the other side, and which court is asking. Until that settles, the safer assumption is that nothing typed into a public chatbot is protected, and that a conversation that genuinely needs to stay privileged belongs with your lawyer directly, not with a chatbot first.
Cross-border complexity adds a further layer that is easy to miss. A conversation typed in Tel Aviv or Milan may be processed on servers in the United States, subject to American discovery rules, or moved between jurisdictions in ways the user has no visibility into and no realistic way to challenge. Frameworks such as the GDPR and Israel’s Amendment 13 to the Privacy Protection Law give people real, meaningful rights over how organizations use their personal data, but those rights were built around a world of forms and databases. They were not built to answer what happens once your own words become evidence in someone else’s court case in a different country altogether.
THE RULE THAT COVERS EVERYTHING ELSE
Every AI conversation is a time-stamped record of your intentions, plans, fears, and half-formed thoughts. It can turn from a smart assistant into a witness against you, without any bad intent from anyone involved, the company included. None of this means AI tools should be avoided; used well, they remain genuinely useful for research, drafting, and problem-solving. It means treating the chat window the way you would already treat a work email or a text message you might one day have to explain: useful, ordinary, and never truly private. The simplest safeguard, and the one worth carrying into every conversation from here forward, is this: don’t type anything you would not be prepared to see read aloud in a courtroom or printed in tomorrow’s news.