For 136 days in 2025, the delete button in ChatGPT removed a conversation from your screen and from nothing else. On 13 May 2025 Magistrate Judge Ona T. Wang ordered OpenAI to “preserve and segregate all output log data that would otherwise be deleted on a going-forward basis until further order of the Court”. The obligation ended on 26 September. In between, every deleted chat from a Free, Plus, Pro or Team account, and every non-ZDR API call, was kept.

NYT v OpenAI and the deleted ChatGPT chats order is usually told as a privacy story. For lawyers it is more useful than that: a live case study in what a third-party litigation hold does to a vendor’s retention promise, and therefore to yours. Every question a firm should ask an AI vendor was answered, in public, by this one order.

What happened: the 13 May 2025 order

In discovery the New York Times wanted to know how often ChatGPT reproduced its articles, which meant output logs, including the ones users had deleted. Judge Wang granted a preservation order in the terms quoted above (terms.law).

OpenAI’s response, posted on 5 June 2025 under the name of COO Brad Lightcap, did not hide its irritation: the demand “abandons long-standing privacy norms and weakens privacy protections”. The Times “is demanding that we retain even deleted ChatGPT chats and API content that would typically be automatically removed from our systems within 30 days” (OpenAI). One practitioner blog, relying on user reports rather than an OpenAI statement, added that OpenAI told European users it was suspending erasure requests for the duration under the legal-claims exception in Article 17(3)(b) GDPR; OpenAI’s own October update confirms only that EEA, Swiss and UK conversations were later carved out.

Which ChatGPT tiers were covered, and why Enterprise was not

OpenAI’s FAQ answered “Is my data impacted?” without hedging: “Yes, if you have a ChatGPT Free, Plus, Pro, and Team subscription or if you use the OpenAI API (without a Zero Data Retention agreement). This does not impact ChatGPT Enterprise or ChatGPT Edu customers. This does not impact API customers who are using Zero Data Retention endpoints under our ZDR amendment.” The court had clarified on 27 May 2025 that Enterprise was excluded.

Tier Covered? Why
ChatGPT Free, Plus, Pro Yes consumer logs held under OpenAI’s standard retention
ChatGPT Team (renamed Business on 29 August 2025) Yes not carved out; OpenAI’s FAQ lists it with the consumer tiers
API without a ZDR amendment Yes inputs and outputs kept up to 30 days for abuse monitoring, so there was something to preserve
ChatGPT Enterprise, Edu No excluded by the 27 May clarification; contractual, admin-controlled retention
API with a ZDR amendment No “Because it is not stored, this court order doesn’t affect that data” (Lightcap)

The logic generalises. A preservation order attaches to data the vendor holds. ZDR customers were untouched not because they had better lawyers but because there was nothing to preserve: “If you are a business customer that uses our Zero Data Retention (ZDR) API, we never retain the prompts you send or the answers we return.” Enterprise was untouched because its retention is a contractual control set by the customer’s admins, which the court respected. Everyone else was in.

The lift on 26 September 2025 and the 20 million logs

Preservation ended on 26 September 2025; OpenAI announced it on 22 October. Under an order reported for 9 October, OpenAI was freed from the going-forward duty with two exceptions: logs already saved stayed saved, and data for accounts the Times had flagged had to be retained. OpenAI’s October update confirmed that deleted conversations and Temporary Chats “will be automatically deleted from our systems within 30 days” once more, but that it “will securely store limited historical April–September 2025 user data … accessible only to a small, audited OpenAI legal and security team”. Conversations originating from the EEA, Switzerland and the UK were carved out of the continuing retention.

Then the second shoe. On 7 November 2025 Judge Wang ordered OpenAI to produce 20 million de-identified chat logs to the plaintiffs. OpenAI moved for reconsideration, calling the order a “privacy disaster” and a “fishing expedition” and arguing that 99.99% of the logs were irrelevant. For scale: 20 million was 0.5% of the preserved logs, and the plaintiffs had asked for 120 million (Jones Walker).

Judge Stein’s 5 January 2026 ruling

District Judge Sidney Stein affirmed in full: “Judge Wang’s rulings were neither clearly erroneous nor contrary to law. She adequately balanced ChatGPT users’ privacy interests against the relevance of the documents in light of the privacy protections already in place.” Those protections were de-identification and a protective order. Stein distinguished the wiretap cases OpenAI relied on because ChatGPT users had “voluntarily submitted their communications” to OpenAI. The consolidated proceeding, In re: OpenAI, Inc. Copyright Infringement Litigation, gathers 16 lawsuits.

OpenAI’s retention page reads, today: “When you delete a chat (or your account), the chat is removed from your account immediately and scheduled for permanent deletion from OpenAI systems within 30 days, unless: the chat has already been de-identified and disassociated from you, or OpenAI must retain it longer for security or legal obligations” (OpenAI Help). The business tiers carry the same clause, “unless longer retention is required by law”; the API, “unless we are legally required to retain them”.

No lawyer should be surprised. It is a litigation hold in vendor language. A retention schedule is a policy; a preservation duty is a legal obligation that overrides it, and any company that receives a hold letter or a court order stops deleting. A vendor cannot promise otherwise, and one that did would be promising to breach a court order. Sam Altman said the quiet part in July 2025: “If you talk to a therapist or a lawyer or a doctor about those problems, there’s legal privilege for it … We haven’t figured that out yet for when you talk to ChatGPT” (TechCrunch).

The same clause in Anthropic’s, Google’s and Perplexity’s terms

Vendor and tier Deletion promise What survives it
OpenAI, consumer deleted chats gone within 30 days “security or legal obligations”; data already de-identified
Anthropic, API and commercial inputs and outputs deleted within 30 days Files API, ZDR arrangements, Usage Policy enforcement, legal compliance
Anthropic, flagged content on any tier none inputs and outputs up to 2 years; trust-and-safety classifier scores up to 7 years
Anthropic, consumer opted in to training deleted chats not used for training de-identified data in training pipelines for up to 5 years
Anthropic, “Covered Models” from 9 June 2026 none 30-day retention “on every platform where these models are offered”, ZDR customers included
Google Gemini, consumer 72 hours if “Keep Activity” is off human-reviewed chats kept up to 3 years, disconnected from your account
Perplexity Free, Pro, Max opt-out available “Previously collected training data cannot be deleted or removed”

Sources: Anthropic’s retention page, Google’s Gemini privacy hub and Perplexity’s help centre, as of September 2026. Two rows deserve a second look. Anthropic’s safety-flag retention keeps a conversation the classifier does not like for two years and its scores for seven, whatever the user’s settings, and the current privacy policy adds that flagged conversations may be used for model improvement even after an opt-out. And Perplexity’s sentence is the most honest in any of these documents: what has been collected for training cannot be un-collected.

What this means for a firm’s data map and client disclosures

The bar opinions had already told you what to do; the order showed why. ABA Formal Opinion 512 expects lawyers to evaluate the risk that client information “will be disclosed to or accessed by others outside the firm” before inputting it, and to “read and understand the Terms of Use, privacy policy, and related contractual terms”. DC Bar Ethics Opinion 388 (April 2024) covers the same ground and quotes NPR’s description of a chatbot as “an omniscient, eager-to-please intern who sometimes lies to you”. New York City Bar Formal Opinion 2024-5 adds the point this order makes sharpest: terms “can change frequently and a lawyer’s obligation to understand the system’s use of inputs is continuing”. The ABA 512 explainer goes through the duties.

In practice a firm needs a data map: which lawyers use which tool on which tier, what each tier retains, and whether a deleted chat is deleted. If the answer for any tool is “consumer plan”, then for four and a half months in 2025 that firm’s deleted prompts sat on a litigation hold it did not know about. United States v. Heppner (S.D.N.Y., February 2026) adds the privilege point: Judge Rakoff found a defendant’s exchanges with consumer Claude protected by neither privilege nor work product, in part because the platform’s privacy policy allowed third-party access. Whether a vendor can preserve and produce your client’s material is now a fact about the tier, and clients are entitled to know it; the privilege guide covers the cases.

Build the firm's AI data map
Here is a list of the AI tools and plans in use at our firm, one per line, with who uses them:
[paste]

For each entry, produce a table row with: Tool | Tier (consumer / business / enterprise / API / legal platform / local) | Trains on inputs by default? | Retention of deleted chats per the vendor's current documentation | The legal-hold or "legal obligations" exception, quoted verbatim | Admin controls available | Gaps to check. Where you do not know the vendor's current terms, write "CHECK CURRENT TERMS" rather than guessing; do not invent retention periods. Finish with the three entries I should fix first and why.

How commercial tiers and ZDR change the analysis

The order drew a line the vendors had already drawn. ChatGPT Business, Enterprise and the API do not train on inputs by default; Enterprise admins set retention and have a compliance API for audit. Claude Team and Enterprise do not train by default; Enterprise retention is configurable to a 30-day minimum, and admins can disable “Rate chats” so that thumbs-up feedback does not go to Anthropic for five years. The Business versus Enterprise comparison goes through the settings.

Zero data retention is the strongest position and narrower than lawyers assume. OpenAI’s ZDR is “subject to prior approval”, covers only eligible endpoints, and images flagged by the CSAM classifier are retained even under ZDR. Anthropic’s ZDR applies to the API and Claude Code for Enterprise, not to the claude.ai chat products; it still keeps classifier results; and its newest Covered Models require 30-day retention regardless. Even the tier untouched by this order comes with footnotes, and the footnotes are what a court would preserve next time.

Courts are now writing the requirement into protective orders. Morgan v. V2X (D. Colo., 30 March 2026) barred AI platforms for confidential information unless the provider is contractually prohibited from “(1) storing or using inputs to train or improve its model; and (2) disclosing inputs to third parties except where essential” (Akin). That clause is a vendor test you can copy.

Extract retention and legal-hold terms from a vendor's policy
Below are a vendor's privacy policy and data-retention pages. Extract, quoting verbatim with the section heading: (1) the default retention period for prompts and outputs; (2) what happens when a user deletes a conversation; (3) every exception to deletion (legal obligations, safety review, abuse monitoring, feedback, de-identified data, special or "covered" models); (4) whether inputs are used for training by default and how to opt out; (5) who inside or outside the vendor may read content; (6) whether a zero-data-retention option exists and its stated limits. Then list the questions these documents do not answer. Do not paraphrase where a quotation is available.

<policy>
[paste]
</policy>

Lessons for your own vendor contracts

The order is a checklist. Ask each AI vendor, in writing:

  1. What do you retain by default, for how long, and what is the exception list? Get the “legal obligations” sentence in front of you.
  2. If you receive a preservation order or subpoena covering our data, will you notify us? ÖRAK’s checklist for Austrian firms already requires providers to undertake to inform the firm of a search; ask for the same for holds.
  3. Is ZDR available to us, on which endpoints, and what survives it? Classifier scores, CSAM scans, covered-model carve-outs.
  4. Can we set retention ourselves, export an audit log, and delete at matter end? Usually Enterprise-only.
  5. Can a safety flag override our training opt-out? On Anthropic’s consumer plans the policy says it can.
  6. Where is the data stored, and whose orders reach it? Conversations originating in the EEA, Switzerland and the UK were carved out of OpenAI’s continuing retention; everyone else’s April to September 2025 data stayed. The EU data residency guide has the current options.
Draft the vendor questionnaire
Draft a one-page questionnaire to send to an AI vendor before our firm signs. Group the questions under: training on inputs; retention and deletion (including every exception, and how we would learn of a preservation order or subpoena covering our data); human access and abuse monitoring; sub-processors and regions; admin controls (retention settings, audit export, disabling feedback); certifications (SOC 2 Type II, ISO 27001, ISO 42001, a signed DPA); and deletion at matter end. Each question must be answerable yes/no with a reference to the contractual clause. End by asking the vendor which of its answers would have changed under a court preservation order like the one in the New York Times litigation in 2025.

The full list, with the CCBE’s questions, is in the vendor due-diligence checklist; the answers belong in the firm AI policy, and the prompts above are in the prompt library.

Where to go next: does ChatGPT train on your data walks through the settings tier by tier, is ChatGPT confidential for lawyers is the overview, and the confidentiality hub has the rest. In AI Lab for Lawyers this order is the reason the first session ends with each participant writing a one-page tier policy for their own firm; it takes about an hour, and it is the document you will want when the next preservation order lands.

Frequently asked questions

Did a court force OpenAI to keep deleted chats?

Yes. On 13 May 2025 Magistrate Judge Ona T. Wang ordered OpenAI to preserve and segregate all output log data that would otherwise be deleted, on a going-forward basis, in the New York Times copyright litigation. The obligation ran until 26 September 2025. During that window, deleted and temporary chats from Free, Plus, Pro and Team users, and non-ZDR API data, were preserved instead of being removed within OpenAI's usual 30 days.

Were ChatGPT Enterprise users affected by the NYT order?

No. The court clarified on 27 May 2025 that ChatGPT Enterprise was excluded, and OpenAI's FAQ confirms Enterprise, Edu and API customers with a Zero Data Retention amendment were not affected. ChatGPT Team, since renamed Business, was covered. Enterprise's carve-out reflects contractual, admin-controlled retention; the ZDR carve-out reflects the simpler fact that nothing is stored, so there was nothing to preserve.

Are deleted ChatGPT conversations really gone?

Normally yes, within 30 days, according to OpenAI's retention page. But that page carries an exception: unless the chat has already been de-identified, or OpenAI must retain it longer for security or legal obligations. The 2025 order shows the exception is real. A preservation order overrides a retention schedule for any vendor, so read deleted as deleted absent a legal hold, and treat the tier you use as the real control.

Can OpenAI be forced to hand over my chats?

It can be ordered to produce logs it holds. In the NYT case Judge Wang ordered production of 20 million de-identified logs, and Judge Stein affirmed on 5 January 2026, finding that privacy interests were adequately balanced by de-identification and a protective order and that users had voluntarily submitted their communications to OpenAI. Sam Altman himself said in July 2025 that there is no legal privilege for conversations with ChatGPT.

What should law firms learn from NYT v. OpenAI?

Three things. Know which tier every lawyer uses, because the tier decided who was covered. Read the retention exception in every vendor's terms, since Anthropic, Google and Perplexity carry equivalents. And put client data only into commercial tiers with contractual no-training terms, admin-set retention and, where available, zero data retention. Then write a one-page tier policy and be able to tell clients what it says.

Written by

Dr. Niklas Schmidt, Partner at Wolf Theiss

Partner at Wolf Theiss Attorneys-at-Law, where he heads the firm-wide tax team; lawyer, author, TEDx speaker and technologist. He has spent well over 1,000 hours testing practical AI applications for legal work, runs a toolkit of roughly 80 AI tools in daily practice, founded the WT Crypto Academy (1,000+ participating lawyers) and has given around 450 talks over 20 years. He teaches the live course AI Lab for Lawyers on Maven.