If you are trying to work out whether your AI conversations could surface in a lawsuit, the useful question is not what a company promises. It is a plainer one. Where are the conversations stored, and who can be ordered to hand them over?
This page answers that in three parts: what has already happened in a real court case, how Claudia is built, and the places where Claudia's design does not help you. The third part is the one most companies leave out, so it is written here in full.
Last updated: August 12, 2026
1. The plain-language reality
Most AI assistants keep your conversations on the company's servers. That is an ordinary product decision, and it is how history, sync, and search across devices work. It also means those conversations are records held by a company. Records held by a company can be reached through the legal system, whether or not you are a party to the case.
This is not a thought experiment. It has already happened, in public, on the record.
1.1. A court ordered chat logs preserved, including chats users had deleted
In the copyright case brought by The New York Times against OpenAI in the U.S. District Court for the Southern District of New York, OpenAI was placed under an order to hold on to consumer chat data instead of letting it age out on the normal schedule.
Writing publicly on June 5, 2025, OpenAI described the demand as an order to "retain consumer ChatGPT and API customer data indefinitely," covering "even deleted ChatGPT chats and API content that would typically be automatically removed from our systems within 30 days." The company said the order reached ChatGPT Free, Plus, Pro, and Team accounts, plus API use without a zero-retention agreement.
In an update posted October 22, 2025 on the same page, OpenAI said those preservation obligations ended on September 26, 2025, and that it had returned to its standard 30-day deletion practice, while still holding a limited set of April to September 2025 user data that the plaintiffs continued to demand.
The point worth taking from that sequence is not that one company behaved badly. It is that a user's ability to delete their own chat history was suspended by a court, in a case those users had nothing to do with, and they found out about it afterward.
1.2. A court then ordered 20 million conversations produced to opposing counsel
On November 12, 2025, OpenAI published a post that opened with this sentence: "The New York Times is demanding that we turn over 20 million of your private ChatGPT conversations." The company said the 20 million were randomly sampled from consumer conversations between December 2022 and November 2024, and that an earlier version of the same demand had covered 1.4 billion conversations.
The court did not accept OpenAI's privacy objection. A magistrate judge ordered the full de-identified 20 million log sample produced on November 7, 2025, and on January 5, 2026 the district court affirmed that ruling on review.
The reasoning is the part worth reading twice. The court held that logs having nothing to do with the plaintiffs' articles were still discoverable, because they could bear on OpenAI's fair use defense. It distinguished an earlier privacy ruling on the ground that ChatGPT users had voluntarily given their data to the company in ordinary use. The same analysis records that OpenAI keeps tens of billions of such logs in the ordinary course of business. De-identification, a reduced sample size, and a protective order were treated as adequate safeguards rather than as reasons to refuse production.
Where it stands now. The dispute is still live. OpenAI produced the sample in December 2025. Reporting on July 9, 2026 says the plaintiffs told the court that the production carried so many redactions that the court called it "unusable," and that they have moved for sanctions. OpenAI denies the allegations. Nothing on this page depends on who wins that motion.
1.3. The company's own chief executive said the conversations carry no privilege
On July 25, 2025, TechCrunch reported comments OpenAI's chief executive made on a podcast. Asked how AI fits the current legal system, he said that if you talk to a therapist, a lawyer, or a doctor, "there's legal privilege for it," and "we haven't figured that out yet for when you talk to ChatGPT." He added that in a lawsuit the company would be legally required to produce those conversations today, and called the situation "very screwed up."
That is the chief executive of the company at the center of the case above, saying in his own words that these conversations are not privileged and can be produced. It is not an accusation. It is a description of how the law currently works.
1.4. Sources
Every claim above is drawn from these documents. Two are OpenAI's own public statements. The others are dated reporting and legal analysis. Read them rather than taking our word for it.
| Date | What it establishes | Source |
|---|---|---|
| June 5, 2025 (updated Oct 22, 2025) | The preservation order over consumer ChatGPT and API content, including deleted chats. Which account types it reached. The October update stating the obligation ended September 26, 2025 | OpenAI, "How we're responding to The New York Times' data demands in order to protect user privacy" https://openai.com/index/response-to-nyt-data-demands/ |
| July 25, 2025 | OpenAI's chief executive stating there is no legal privilege for ChatGPT conversations and that the company would be required to produce them | TechCrunch https://techcrunch.com/2025/07/25/sam-altman-warns-theres-no-legal-confidentiality-when-using-chatgpt-as-a-therapist/ |
| November 12, 2025 | The demand for 20 million private conversations, the December 2022 to November 2024 sampling window, and the earlier 1.4 billion figure | OpenAI, "Fighting the New York Times' invasion of user privacy" https://openai.com/index/fighting-nyt-user-privacy-invasion/ |
| January 15, 2026 (analyzing the Jan 5, 2026 order) | The November 7, 2025 production order, the January 5, 2026 district court affirmance, the court's relevance and privacy reasoning, and the "tens of billions" of logs retained in the ordinary course of business | Robinson & Cole, "When Chats Become Evidence," The National Law Review https://natlawreview.com/article/when-chats-become-evidence-court-affirms-order-requiring-openai-produce-20-million |
| July 9, 2026 | Current status: the sample was produced in December 2025, the court called the redacted production "unusable," and the plaintiffs have moved for sanctions, which OpenAI denies | TechCrunch https://techcrunch.com/2026/07/09/new-york-times-says-openai-hid-evidence-in-chatgpt-copyright-trial/ |
2. How Claudia is built
Claudia is a local-first app. Conversations and memory are written to the app's own database on your iPhone. They stay there.
- PrentusAI operates no server that stores your conversations. There is no PrentusAI backend in the path between you and the AI model you selected. Your message goes from your phone straight to that provider.
- PrentusAI operates no server that relays your conversations. We do not proxy provider traffic. We never see the request, so we never hold a copy of it.
- We cannot search, export, or produce your chats, because we never receive them. There is nothing here to look through.
- The App Store privacy label reads "Data Not Collected," and that answer is accurate. Section 4 below explains what Apple is actually asking and why that is the honest answer rather than a convenient one.
- Claudia requires no account. There is no sign-up, no login, and no user record, so there is also no account list to be served with anything.
The practical consequence is narrow and worth stating precisely. If someone served PrentusAI with a demand for your conversation history, there would be nothing to attach it to. Not because we deleted an archive, and not because we hardened one. Because a conversation archive was never built here in the first place.
What this claim is, and what it is not. This is a statement about what PrentusAI holds. It is not a promise that your conversations cannot be reached by anyone, anywhere. It is a smaller claim than that, and a checkable one. They are not here. Section 3 sets out exactly where that stops helping you.
The full technical description of what is stored, where, and what leaves the device is in the Claudia Privacy Policy, and the complete list of third-party services Claudia can be configured to use is on the AI Services and Data Providers page.
3. The honest limits
Local-first design moves the risk. It does not delete it. Three limits apply, and none of them has a workaround we can offer you.
3.1. Your own device and its backups
The conversations are on your phone. A phone, and any backup of that phone, is your own property and your own records. Personal records can be subject to legal process the same way your other records can. A court that can reach your documents, your messages, or your device can reach these too.
We are not standing between you and that, and we could not if we wanted to, because we are not in that path at all. What local-first changes is that the demand has to come to you, in a proceeding you are part of, rather than arriving at a company you have never dealt with and being answered without you ever hearing about it.
3.2. Cloud models you connect with your own key
When you configure a cloud provider and send a message, that request goes directly from your phone to that provider, under your own account and your own key. From that moment the provider's retention policy governs what happens to it, not ours. We have no ability to shorten it, no ability to recall the message, and no visibility into how long it is kept.
Every case described in section 1 is about exactly this kind of data, sitting on a provider's servers. Using Claudia does not exempt a message you sent to a cloud model from that provider's retention and from that provider's legal obligations. If retention matters to you, read the policy of the provider you selected before you select it. Each one is linked on the AI Services and Data Providers page.
3.3. Scheduled briefs are the one background call
Nearly every network call Claudia makes is one you started. One feature is different, and it is disclosed in the privacy policy at section 3.1 rather than being covered by a broad word like "only."
If you create a scheduled brief, such as a morning summary, Claudia may prepare that answer shortly before it is due while the app is in the background. It does this by sending that brief's question to the AI service you selected. It is the same call your tap would have made, run a few minutes early, and like that call it carries the context Claudia normally uses to answer you, which can include your saved memory. It happens only for briefs you created, and it uses only tools that read. Delete the brief and the call stops.
We list this here rather than burying it, because a page about legal exposure that quietly omitted the one background call would not be worth reading.
This page is general information, not legal advice. It describes how Claudia is built and cites public court filings and public company statements. It is not advice about your situation, and it does not create any professional relationship. If you have a real legal question about your own records, consult a lawyer in your jurisdiction.
4. What "Data Not Collected" means on the App Store label
Apple's App Privacy questions ask what the developer and the developer's partners collect. They are not asking what a user chooses to send to a third party under the user's own account. Claudia answers "Data Not Collected" for three reasons:
- No PrentusAI server sits in any data path in the app. There is nothing for us to collect into.
- The app carries no analytics, advertising, crash-reporting, or tracking SDKs. No Sentry, Mixpanel, Amplitude, Segment, Datadog, PostHog, Firebase Analytics, or Crashlytics. No advertising identifier is collected, and Apple's App Tracking Transparency prompt is intentionally not shown, because nothing tracks.
- Your own provider calls are your data flow, not our collection. When you bring your own key and send a message, you are transacting with your provider under your account. We never see, hold, or have the ability to see any of it. This is the same reason a mail app does not declare the contents of the mail its user sends.
The label is only worth something if it is maintained honestly, so here is the standing rule that governs it. If PrentusAI ever proxies provider traffic, bundles a PrentusAI-funded key beyond an App Review build, adds any call that reports usage back to us, or ships a feature that puts a PrentusAI endpoint in a data path, the privacy label changes in the same App Store submission that ships the feature. Not afterward.
That rule has been tested once. An optional relay endpoint operated by PrentusAI was listed on the data providers page between July 20 and August 10, 2026. The feature was discontinued, the server was deleted along with any data it held, and the app no longer contains a pairing flow. The removal is recorded with its dates on the AI Services and Data Providers page. No PrentusAI-operated endpoint remains in the app.
5. Questions
If something on this page is unclear, or you think a claim here is wrong, write to team@prentusai.com. Corrections to factual claims are made in public, with the date, in the same way the removal note above was.