On 4 November 2025 FBI agents searched the home of a man charged with a securities fraud of more than $150 million. Among what they took were roughly thirty-one documents that were not contracts, bank records or emails. They were his conversations with Claude. Three months later Judge Jed Rakoff ruled that none of them was protected: “Because Claude is not an attorney, that alone disposes of Heppner’s claim of privilege” (United States v. Heppner, S.D.N.Y., memorandum of 17 February 2026).
So: is ChatGPT confidential for lawyers? The question is slightly wrong, because the vendor matters far less than the plan. ChatGPT Free, Plus and Pro, Claude Free, Pro and Max, consumer Gemini, Copilot on a personal account and Perplexity Free, Pro and Max all train on your conversations by default. ChatGPT Business, Enterprise and the API, Claude Team, Enterprise and the API, Gemini in Workspace, Copilot with enterprise data protection and Perplexity Enterprise do not. Most lawyers get this wrong because they assume $20 a month buys privacy. It does not.
What follows draws on the vendors’ own privacy pages as of September 2026, the 2026 privilege cases and the bar opinions; the rest of the confidentiality cluster goes deeper.
The one distinction that matters: consumer tier versus commercial tier
Every vendor sells two products under one brand. The consumer product is free or cheap, sits behind a personal login and is paid for partly with your data. The commercial product sits behind an administered workspace, comes with a data processing agreement and carries a written promise not to train on what you send.
OpenAI: “By default, we do not use your business data for training our models”, covering ChatGPT Business, Enterprise, Edu and the API (OpenAI, enterprise privacy). Anthropic’s commercial terms say the same for Team, Enterprise and the API. Google Workspace: content “is not human reviewed or otherwise used for Generative AI model training outside your domain without permission”. Microsoft and Perplexity Enterprise make the same promise.
On the consumer side every one of those sentences reverses. The CCBE’s technical guide for lawyers put it in one line: “Whether a prompt is later used for model training depends not on the model architecture itself, but on the provider’s contractual terms.” Same model, different contract, different duty. And a personal account is a consumer account, even when a partner holds it.
The comparison table: five tools, seven columns
The table condenses the vendors’ privacy pages as they stood on 12 and 13 September 2026; terms change often, and the New York City Bar notes that the duty to understand a system’s use of inputs “is continuing”. “Not stated” means the page did not address the point; treat it as a question, not a yes.
| Tool and tier | Trains by default? | Retention of deleted or temporary chats | Who can read it | EU residency | HIPAA BAA | Where the switch is |
|---|---|---|---|---|---|---|
| ChatGPT Free, Go, Plus, Pro | Yes, until “Improve the model for everyone” is off | Deleted and Temporary Chats gone within 30 days unless kept for security or legal reasons | Abuse monitoring; ads on Free and Go | No | No | Settings > Data Controls |
| ChatGPT Business, Enterprise, API | No | 30 days; Enterprise admins set retention; API ZDR on approval | Abuse reviewers, including third-party contractors | New Enterprise and Edu workspaces; EU API projects; in-region inference since 16 Jan 2026 | ChatGPT for Healthcare and API healthcare customers | Admin console |
| Claude Free, Pro, Max | Yes since 28 Aug 2025, until “Help improve Claude” is off | Five years if opted in; 30 days if not; flagged chats two years, classifier scores seven | Safety reviewers for flagged chats | No | No | Settings > Privacy, or Incognito |
| Claude Team, Enterprise, API | No | API 30 days; Enterprise custom (minimum 30 days); feedback five years unless “Rate chats” is off | Classifier results kept even under ZDR; “covered models” 30 days everywhere | Only via AWS Bedrock or Google Vertex | HIPAA Type 1 reports; BAA excludes web search | Organisation settings |
| Gemini, personal account | Yes while “Keep Activity” is on | 72 hours if off; reviewed chats up to three years | Human reviewers | Not stated | No | Gemini Apps Activity |
| Gemini for Workspace, Gemini Notebook | No | Notebook prompts not retained after the session | Not outside your domain | Workspace commitments | Workspace yes; Gemini Notebook no | Workspace admin |
| Copilot, personal account | Yes until “Training on conversation activity” is off | Not stated | Not stated | No | No | Settings > Privacy |
| Copilot, work tenant with enterprise data protection | No | Your tenant’s retention and labels | Everyone your permissions already allow | EU Data Boundary, except web queries and Anthropic models | Yes, except web queries | Microsoft 365 admin centre |
| Perplexity Free, Pro, Max | Yes; earlier training data cannot be deleted | Not stated | Not stated | Not stated | No | Account > Preferences |
| Perplexity Enterprise | No | Uploads seven days; custom retention for 50+ seats | ZDR and zero-training agreements with OpenAI and Anthropic | Not stated | Not stated | Enterprise admin |
OpenAI: Data Controls, Temporary Chat, Business, Enterprise and the NYT hold
The consumer tiers turn on one toggle. OpenAI’s Data Controls FAQ: “Settings → Data Controls → Turn off ‘Improve the model for everyone’.” Temporary Chats “are deleted from our systems after 30 days” and “may be reviewed only to monitor for abuse”; a deleted chat is “scheduled for permanent deletion from OpenAI systems within 30 days, unless… OpenAI must retain it longer for security or legal obligations”. Free and Go have carried ads since February 2026, first in the US and then in other markets; a tier with ads is not a tier for client work.
ChatGPT Team became ChatGPT Business on 29 August 2025, a name change only. On Business, Enterprise, Edu and the API, OpenAI does not train by default, admins control retention, and deleted conversations go within 30 days “unless longer retention is required by law”. Staff access is limited to authorised employees and “specialized third-party contractors… solely to review for abuse and misuse”. Enterprise adds an audit log, single sign-on and EU data residency. Zero data retention exists only on the API, for eligible endpoints, “subject to prior approval by OpenAI”.
Anthropic: the August 2025 default switch and five-year retention
On 28 August 2025 Anthropic stopped being the vendor that did not train on consumer chats. Free, Pro and Max users now choose whether chats train the model; the toggle defaults to on; and if you allow training Anthropic is “extending data retention to five years”, against 30 days if you do not (Anthropic, updates to consumer terms). Incognito chats are excluded.
The carve-out that matters is safety review. Anthropic’s privacy policy, effective 10 September 2026: “Even if you opt-out, we will use Inputs and Outputs for model improvement when: (i) your conversations are flagged for safety review… or (ii) you’ve explicitly reported the materials to us.” Flagged chats are kept up to two years and classifier scores up to seven, and the policy does not define what triggers a flag. A consumer plan is never a clean environment for client material.
The commercial side is different. Team, Enterprise, the API, Bedrock and Vertex were excluded from the change. API inputs and outputs are deleted within 30 days; Enterprise admins set retention at 30 days or more. Zero data retention is available only to eligible API customers and Claude Code for Enterprise, “subject to Anthropic’s approval”, and Anthropic “still retains User Safety classifier results”. From 9 June 2026 prompts to its “covered models” are “retained for 30 days to support our safety work, on every platform where these models are offered”, ZDR or not.
Gemini, Copilot and Perplexity: the three tools lawyers forget to check
Google Gemini: the warning in Google’s own words
Google is the most candid of the five. Its Gemini Apps Privacy Hub for personal accounts says: “Please don’t enter confidential information that you wouldn’t want a reviewer to see or Google to use to improve our services.” Reviewed chats are “Retained for up to 3 years, disconnected from your account”; with activity off, chats are kept 72 hours.
Gemini for Google Workspace is a commercial product under the Cloud Data Processing Addendum: no training without the customer’s permission, no human review outside your domain. Gemini Notebook (NotebookLM until 16 July 2026), the tool lawyers like for closed-universe document work, is not human-reviewed on a Workspace account even if you press thumbs-up. One caveat from Google’s own compliance table: Gemini Notebook “does not support ISO, SOC, or FedRAMP compliance and is not covered by the Google Business Associate Agreement”.
Microsoft Copilot: three tiers and the EU Data Boundary carve-out
Copilot is where “we use Microsoft, so we are fine” goes wrong. Copilot on a personal Microsoft account trains on conversations unless “Training on conversation activity” is off, and the opt-out does not cover “advertising, digital safety, security, and compliance purposes”. Copilot Chat on a work account and the paid Microsoft Copilot add-on carry enterprise data protection: covered by the Microsoft DPA, not used to train foundation models, and subject to your tenant’s sensitivity labels and retention (Microsoft Learn, enterprise data protection).
Then the footnotes: “The EU Data Boundary doesn’t apply to web search queries. In addition, Anthropic models are currently excluded from the EU Data Boundary.” A German or Austrian firm that bought Copilot for the data boundary and then let users pick an Anthropic model has quietly left it.
The larger Copilot risk is not Microsoft. Copilot surfaces everything a user already has permission to see across SharePoint, Teams, OneDrive and mail; as the ABA’s Law Technology Today put it in 2026, “Permissions set years ago and never revisited now define what an AI tool will surface on demand.” Run the oversharing reports and label the privileged folders first.
Perplexity: training on by default, and it cannot be undone
Perplexity’s data-collection page is blunt: “For Free, Perplexity Pro and Perplexity Max users, AI Data Retention is enabled by default.” Opting out covers only future data: “Previously collected training data cannot be deleted or removed.” Downgrade from Enterprise to Free and the default switches back on. Enterprise Pro and Max are the commercial tier: never used for training, uploads kept seven days, and zero-retention, zero-training agreements with OpenAI and Anthropic, which matters because Perplexity routes to other companies’ models.
Privilege: Heppner, Warner v. Gilbarco and the Kovel-style dicta
Confidentiality and privilege are different questions, and 2026 produced case law on the second. In Heppner the defendant had run his Claude sessions after receiving a grand jury subpoena, on his own initiative. Judge Rakoff held there was no attorney-client privilege, because Claude “could not” be his attorney and because the communications “were not confidential”: Anthropic’s consumer privacy policy, as it stood on 19 February 2025, said inputs and outputs could be used to train the model and disclosed to third parties. There was no work product because nothing was prepared at the behest of counsel.
The dicta is the useful part: “Had counsel directed Heppner to use Claude, Claude might arguably be said to have functioned in a manner akin to a highly trained professional who may act as a lawyer’s agent within the protection of the attorney-client privilege.” That is Kovel-style agent logic. Counsel-directed use on a tool whose terms keep the content confidential has a credible claim to protection; a client’s solo session on a consumer app does not.
Three civil decisions complete the picture:
- Warner v. Gilbarco, Inc. (E.D. Mich., 10 February 2026): a pro se plaintiff’s ChatGPT use did not waive work product; “the work-product waiver has to be a waiver to an adversary”, and AI programs are “tools, not persons”.
- Morgan v. V2X, Inc. (D. Colo., 30 March 2026): the protective order now bars inputting confidential information into AI platforms unless the provider is contractually prohibited from “(1) storing or using inputs to train or improve its model; and (2) disclosing inputs to third parties except where essential”, which “practically bars the use of most ‘low-to-no-cost’ AI tools”.
- Jeffries v. Harcros Chemicals Inc. (D. Kan., 25 March 2026): public AI tools banned for all discovery material.
The UK reached the same place through professional conduct. In [2026] UKUT 81 (IAC) a solicitor had put client letters and Home Office decision letters into ChatGPT to “improve” them; the Upper Tribunal held that doing so “is to place this information on the internet in the public domain, and thus to breach client confidentiality and waive legal privilege”. The SRA quoted that sentence in its warning notice of 17 August 2026 and added: “legal professional privilege may be permanently waived and unable to be recovered” (SRA, Misuse of AI warning notice). The privilege guide has the decision tree and the protective-order language.
What the bar opinions require: reasonable efforts, consent, no boilerplate
ABA Formal Opinion 512 (29 July 2024) applies a three-question test.
- Have you evaluated the disclosure risk? “Before lawyers input information relating to the representation of a client into a GAI tool, they must evaluate the risks that the information will be disclosed to or accessed by others outside the firm.” That means reading “the Terms of Use, privacy policy, and related contractual terms”, or having IT do it.
- Is the tool self-learning? If so, “a client’s informed consent is required prior to inputting information relating to the representation into such a GAI tool”, even where the tool is used only by lawyers at the same firm.
- Is the consent real? “Merely adding general, boiler-plate provisions to engagement letters purporting to authorize the lawyer to use GAI is not sufficient.” The client needs to know why the tool is used, the specific risks, and how others might use the information against them.
The Opinion 512 explainer covers fees and supervision.
Other regulators say the same in their own register. The SRA: “Both paid for and free-to-use AI tools may not provide the contractual, and technical safeguards needed to maintain client confidentiality.” Germany’s BRAK asks for only “abstract” prompts on ChatGPT-type tools and reads § 203 StGB so that the provider’s mere possibility of access counts as disclosure; Austria’s ÖRAK calls entering mandate-related information into public or unsecured AI systems “standesrechtlich unzulässig”.
Draft an engagement-letter clause on our use of AI tools for a [law firm] in [jurisdiction] that would satisfy the informed-consent standard in ABA Formal Opinion 512 rather than a boilerplate authorisation. Cover: the tools we use (commercial tiers with contractual no-training and retention terms; no consumer tools for client information); what client information may be processed and whether it is anonymised first; the specific risks (error, confidentiality, retention, disclosure to providers, legal holds); our human-review commitment; the client's right to object; and billing (actual time only). Plain English, under 300 words. Then draft a one-paragraph warning to clients about pasting our advice into public AI tools. Tag any rule or opinion you cite [VERIFY].The wrapper paradox: a legal platform adds a subprocessor
Harvey’s security page says it “never trains on customer data”, “contractually prohibits model providers from training on customer data” and “requires Zero Data Retention (ZDR) by model providers”. Thomson Reuters says CoCounsel requests are “processed under the identity ‘Thomson Reuters,’ never identifying the Thomson Reuters customer”. These are real commitments and better than a consumer chatbot’s.
They are not magic. A practitioner on r/legaltech put Anthropic’s Commercial Terms and DPA next to Harvey’s Platform Agreement, DPA and Security Addendum and found they “read about the same”: both prohibit training, both commit to 48-hour breach notice, both offer SOC 2 reports and audit rights. Then the line every procurement committee should pin up: “Going direct removes a party from the chain instead of adding one.” A wrapper sits on a foundation model and lists that model’s provider as a subprocessor; what you buy is negotiated carve-outs (abuse monitoring off, matter-level isolation, a higher liability cap for a breach), not the absence of the model company.
The vendor due diligence questions ask for the no-training clause in writing, what survives ZDR, who can read flagged content, the subprocessor list and regions, and deletion at matter end.
Here are a vendor's terms of service, privacy policy, DPA and security page: <terms>[paste]</terms>. Extract, quoting the exact words and section number for each: (1) whether inputs, outputs, uploaded files and embeddings are used to train or improve any model, and any exceptions; (2) default retention for prompts, files and deleted items, and whether zero data retention is available and for which products; (3) what is retained regardless (safety classifier results, abuse monitoring, legal holds); (4) who may read customer content and under what conditions; (5) subprocessors, including model providers, and processing regions; (6) breach-notification period; (7) deletion and export at termination. Where a document is silent, write NOT ADDRESSED. Do not summarise or soften; quote.Which tier for which data: a practical protocol
Bar guidance, the Casemark traffic-light system the NC Bar cites, the CCBE and BRAK converge on three tiers. Write them into the firm policy with the approved tool names next to each.
| Tier | What goes in | Which tools | Conditions |
|---|---|---|---|
| Green | Public information, general legal concepts, marketing drafts, “abstract” questions that reveal no matter | Any tool, including consumer plans with training off | Nothing that identifies a client, even by context |
| Amber | Research starting points, summaries, first drafts, contract review with placeholders | Commercial tier only: ChatGPT Business or Enterprise, Claude Team or Enterprise, Gemini in Workspace, Copilot with enterprise data protection, legal platforms | Anonymise with a local key table; strip metadata; feedback off; log what went where and who reviewed |
| Red | Privileged strategy, witness statements, protective-order material, health records, anything to be filed | Enterprise with ZDR or configured retention, a legal platform with counsel-directed use documented, or a local model | Never a consumer tool, even anonymised; informed consent on file; verification logged |
Brooke Loesby’s example in the ABA Journal shows what Green looks like: not “My client Sarah is suing her business partner for embezzling $400,000” but “I am working on a partnership dispute involving allegations of financial misconduct”.
The protocol has to beat the alternative, because shadow use is the normal state: 34% of professionals use unsanctioned AI tools (Thomson Reuters, 2026), and when Hill Dickinson blocked ChatGPT after logging 32,000 hits in a week, the ICO replied that “the answer cannot be for organisations to outlaw the use of AI and drive staff to use it under the radar”. A workspace plus a two-line rule beats a ban.
Anonymisation, local models and other fallbacks
Anonymisation is the most useful habit on this page, and it is not redaction. Redaction removes text and leaves the model nothing to reason over; anonymisation swaps “Acme Corp” for [PARTY_A] and “$5M” for [AMOUNT_1], keeps the structure, and lets you re-hydrate the output from a key table that never leaves the firm. Strip tracked changes, comments and document properties first. BRAK’s warning applies: removing names and addresses is often not enough “wenn sich Mandatsinformationen aus dem Kontext ergeben können”.
Before I work with this document, replace every personal name, company name, address, account number, date of birth, case number and unique identifier with consistent placeholders ([PERSON_1], [COMPANY_A], [ACCOUNT_1], [DATE_1]) so the document stays internally coherent. Also generalise contextual identifiers that would allow re-identification (unusual job titles, unique events, small towns, distinctive amounts) into a neutral description. Output the anonymised text and a separate key table. Do not summarise, shorten or alter any other content.Do not run that prompt on a consumer tool; the information is uploaded before it answers. The anonymisation guide covers the tooling, including Microsoft’s open-source Presidio.
Local models are the last fallback and a real one for the most sensitive matters. Llama 3.1 8B runs on a 16 GB laptop and nothing leaves the machine. The price is capability: the guide that champions Ollama admits that on a research question “Three of the five cases it gave me either didn’t exist or had holdings that said the opposite”. Local is for confidentiality, not research; the local LLM guide covers the set-up.
Where to go next: the settings walkthrough shows every toggle, the Business versus Enterprise comparison tells a firm which plan to buy, and the EU residency guide is the page for German, Austrian and UK firms. Knowing which tier you are on is a five-minute settings exercise; in AI Lab for Lawyers we do it live for every tool, then practise anonymising a real document before prompting with it.
Frequently asked questions
Is ChatGPT confidential for lawyers?
It depends on the plan. On ChatGPT Free, Go, Plus and Pro your conversations train the model by default, deleted chats can take up to 30 days to purge and Temporary Chats may be reviewed for abuse, so none is confidential enough for client information. On Business, Enterprise and the API, OpenAI does not train on your data by default and offers a DPA. No tier gives you privilege, and a court order can still reach stored chats.
Can I put client information into ChatGPT?
Only into a commercial tier (Business, Enterprise or the API), only with the client's informed consent where the tool is self-learning, and ideally anonymised first. ABA Formal Opinion 512 requires you to evaluate disclosure risk before inputting information relating to a representation, and the SRA warns that both paid and free tools may lack the safeguards needed. Never put client information into a consumer plan: the UK Upper Tribunal treated that as placing it in the public domain.
Does ChatGPT keep my conversations?
Yes, unless you delete them, and even then for a while. Deleted chats are scheduled for permanent deletion within 30 days unless OpenAI must retain them for security or legal reasons. Temporary Chats are deleted after 30 days and may be reviewed for abuse. From 13 May to 26 September 2025 a court order in the New York Times case forced OpenAI to keep every deleted chat of Free, Plus, Pro and Team users; 20 million were later ordered produced.
Is Claude more private than ChatGPT?
Not on the consumer tier. Since 28 August 2025 Claude Free, Pro and Max train on your chats unless you switch off Help improve Claude, and opted-in data is retained for up to five years; conversations flagged for safety review can be used for training even if you opted out. Claude Team, Enterprise and the API do not train by default and delete API data within 30 days. On commercial plans the two vendors' terms are broadly comparable.
Does using ChatGPT waive attorney-client privilege?
It can. In United States v. Heppner (S.D.N.Y., February 2026) Judge Rakoff held that a defendant's own conversations with Claude were protected by neither attorney-client privilege nor work product: the tool is not a lawyer and its consumer privacy policy allowed third-party access. The court suggested counsel-directed use on suitable terms might be different. Warner v. Gilbarco (E.D. Mich. 2026) went the other way for a pro se litigant's work product. Assume consumer-tier chats are discoverable.
Which AI tools are safe for law firms?
Tools with a written no-training clause, a data processing agreement, a defined retention period, admin controls and, where needed, EU residency or a BAA: ChatGPT Business or Enterprise, Claude Team or Enterprise, Gemini in Google Workspace, Microsoft Copilot with enterprise data protection, Perplexity Enterprise, and legal platforms such as Harvey, CoCounsel and Lexis+ Protégé. Even then, anonymise where you can, switch off feedback buttons, and keep privileged strategy on the most restricted tier or a local model.