NEWS
Chatbots Hear Secrets That Doctors and Families Never Get
A DuckDuckGo survey finds 32% of AI users tell chatbots what they hide from doctors, while those logs can train models and be pulled into court.
32% of AI users have told a chatbot something they hid from a close friend, a parent or a doctor. DuckDuckGo put that figure on a survey of 1,944 U.S. adults fielded June 17 to 27, 2026, and published it on August 25.
Those chats do not stay in a vault. Most consumer bots can train on them unless a user opts out, staff can review flagged threads, and a court can demand the log. The doctor, parent or friend who never heard the secret still has not heard it.
DuckDuckGo Asked 1,944 Adults About Chatbot Secrets
The sample was U.S. adults 18 and older, balanced to census quotas for age, gender and region through the PureSpectrum panel, and reported unweighted. The margin of error is about ±2.2 percentage points at 95% confidence, and larger in subgroups.
Among people who already use AI, 32% said they had shared something they kept from a close friend, parent, colleague, doctor or therapist. Among self-described enthusiasts, the share was 56%.
DuckDuckGo’s own write-up put the finding in one line: people are sharing secrets that AI companies do not keep. A web search is a few words. A chat is a longer dump of how someone thinks, and the company storing it can keep the file.
WHO CONFIDES IN CHATBOTS
| Group | Share who told a chatbot something they kept from trusted people |
|---|---|
| AI users overall | 32% |
| Self-described AI enthusiasts | 56% |
| Parents or guardians who use AI | 43% |
| AI users with no children at home | 25% |
DuckDuckGo did not ask what the secrets were. Separate health polling, and the way chatbot makers pitch “life coach” and parenting help, fill in the likely topics: symptoms, money, marriage, kids.
Parents Open Up at Nearly Twice the Rate
Among parents or guardians with children at home who use AI, 43% said they had told a chatbot something they never told a doctor, therapist, close friend, parent or child. Among AI users with no kids at home, that share was 25%.
Forty-three divided by 25 is 1.72, which is the “nearly twice” gap DuckDuckGo flagged. Parenting is messy, and a bot answers at 1 a.m. without a look on its face. The company’s post noted that even AI chief executives talk about leaning on chat tools for parenting questions.
The people shut out of those chats include the other parent, the pediatrician and, in some households, the child. None of them has a copy. The vendor does, on a consumer account, unless the user has turned training off and later deletes the thread, and even then a legal hold can freeze what the delete button was supposed to erase.
The Doctor Never Gets That Confession
A chatbot is a cheap listener. It is not a clinic, and consumer ChatGPT is not covered by a HIPAA business associate agreement on Free, Plus or Business plans.
KFF’s Tracking Poll on Health Information and Trust, fielded February 24 to March 2, 2026, found that 32% of all adults had used AI for physical or mental health advice in the past year. That 32% is a different base from DuckDuckGo’s 32% of AI users who hide secrets; it is the share of the whole public going to a bot with health questions. Twenty-nine percent had used it for physical health, and 16% for mental health.
HEALTH USE THAT NEVER REACHES A CLINICIAN
- Privacy fear: 77% of adults said they were very or somewhat concerned about the privacy of personal medical details given to AI tools, per the KFF poll on AI health advice.
- They upload anyway: 41% of those health users, 13% of all adults, said they had uploaded personal medical information such as test results or a doctor’s notes.
- Speed first: 65% of health users called a wish for quick, immediate advice a major reason; 36% said they felt more comfortable looking up health questions privately.
- No follow-up: 58% of people who used AI for physical health later saw a doctor, so 42% did not; 42% of mental-health users later saw a mental health clinician, so 58% did not.
Uninsured adults were more likely than insured adults to use AI for mental health advice, 30% against 14%. The bot is doing the intake the office never sees, and the office cannot correct a bad answer it never received.
Fear of being judged is part of that split, and so is a wait list. The cost is that a symptom, a plan to self-harm, or a side effect can live in a chat history that has no duty to call a human, and no privilege when someone else later asks for the file.
Can Police Read Your ChatGPT History?
Yes, through more than one door. A phone search can already hold the app. A warrant or a subpoena can go to the vendor. The company can also call the police on its own if reviewers decide a thread shows an imminent, credible risk of harm.
OpenAI CEO Sam Altman said the quiet part on Theo Von’s podcast This Past Weekend in July 2025, after watching people treat ChatGPT like a therapist and a life coach.
If you go talk to ChatGPT about your most sensitive stuff and then there’s a lawsuit or whatever, we could be required to produce that. And I think that’s very screwed up.
Sam Altman, CEO, OpenAI, on This Past Weekend with Theo Von
He argued for the same privacy concept that covers a therapist, and said the industry had not built it. There is still no “AI privilege” in U.S. law. A chat with a licensed clinician can be shielded. A chat with a product is a business record.
OpenAI’s own OpenAI report on government requests for July through December 2025 is the dry version of that warning.
OPENAI GOVERNMENT REQUESTS, JULY TO DECEMBER 2025
| Request type | Received | Where data was disclosed | Accounts disclosed |
|---|---|---|---|
| Non-content (subpoenas for name, email, payment, history) | 224 | 146 | 307 |
| Content (warrants for prompts and outputs) | 75 | 62 | 84 |
| Emergency | 10 | 1 | 1 |
National-security process sat in a separate legal bucket of 0-249 requests and 0-249 accounts. Eighty-four content accounts in six months is not a mass roundup. It is proof the pipe works, and that only 25% of DuckDuckGo’s respondents knew a chat could be subpoenaed.
Civil court is the wider channel. OpenAI has said it fought a demand in the New York Times copyright case to turn over 20 million ChatGPT conversations, then complied with a magistrate’s order while it appealed. In Fortis Advisors v. Krafton, decided March 16, 2026, the Delaware Court of Chancery treated a CEO’s ChatGPT prompts about how to avoid an earnout of up to $250 million as evidence that a firing was a pretext.
Criminal files have started to cite the same logs. A Palm Beach County police affidavit says OpenAI contacted the FBI after a user described plans to harm an ex-girlfriend; local police used the chats, and the user later pleaded guilty to stalking and electronic threats and was sentenced to eight years of probation. In United States v. Kim, prosecutors told a New York federal court they had served Stored Communications Act warrants on May 21, 2026, on OpenAI and Anthropic for seven accounts in a wire and securities-fraud case.
Police often never need the vendor. If they are already inside the phone, the thread is sitting there.
Six Privacy Facts Most Adults Could Not Name
DuckDuckGo tested six basic points about how ordinary AI chats are stored, reviewed and handed over. Across users and non-users, 43% did not know any of them, a different 43% from the parent-confide figure. That group included about a third of self-described active AI users. Fifty-three percent did not know, or were not sure, that most chatbots train on conversations by default.
SIX FACTS DUCKDUCKGO TESTED
- Court process: AI chats can be subpoenaed by courts and law enforcement.
- Public docket: AI chats can be made public in a lawsuit.
- The boss: Employers can access work and enterprise AI accounts.
- The settings maze: Delete and stop-storage controls differ by vendor.
- Free vs paid: Free accounts often have weaker privacy than paid ones.
- Human eyes: Staff and contractors can review chats.
OpenAI’s consumer policy matches the training item in plain language. ChatGPT, it says, improves by further training on the conversations people have with it, unless they opt out of training on ChatGPT in Data Controls or the privacy portal. Business, Enterprise, Edu and Healthcare workspaces are off that default. On a personal Free, Plus or Pro plan, data sharing for training starts on.
Once people in the DuckDuckGo sample heard how chats are used, 58% were uneasy, and 30% were very uneasy. Trust was already thin. Only 14% mostly or completely trusted large AI companies with their data, and 39% had no trust at all. The U.S. government scored worse: 48% had no trust at all.
That is the odd part of the habit, and it does not require a sermon. People who say they do not trust the custodian still type the thing they would not tell a doctor, because the cursor does not raise an eyebrow.
DuckDuckGo Built a Product Around the Blind Spot
The same blog post that published the survey ends with Duck.ai, the company’s own chat layer. That is not a hidden motive so much as the business model: measure the leak, then sell a tap that claims to shut it off.
1 in 3 AI users have told a chatbot something they kept from trusted people in their lives like a doctor or close friend.
We surveyed nearly 2,000 U.S. adults about AI privacy. The results suggest that people are sharing secrets with AI that Big Tech doesn’t keep. pic.twitter.com/g2pL3SWyFk
— DuckDuckGo (@DuckDuckGo) August 25, 2026
Fieldwork closed June 27. Two days later, on June 29, 2026, DuckDuckGo launched Prying Eyes, its first national Duck.ai campaign, with spots still booked across TV, connected TV and YouTube into early fourth quarter. A privacy firm that just stood up a chatbot has a direct interest in proving that rival chats are leaky. The 1,944-person sample can still be read as a sample; it also lives on a product blog.
The product claim is specific. By default, Duck.ai does not store chats, and DuckDuckGo says neither it nor the underlying model makers use those chats for training. Prompts are stripped of personal metadata such as IP address before they go to OpenAI, Anthropic, Mistral, Azure or Tinfoil, so the request looks like it came from DuckDuckGo.
WHAT DUCK.AI SAYS PROVIDERS MUST DO
- Zero Data Retention: Delete prompts and replies right after a response is generated, with listed exceptions.
- No training: Never use Duck.ai chats to train their models.
- No extra sharing: Never give the data to third parties for their own commercial use, other than subprocessors.
- Caches and law: OpenAI may hold a prompt in short-term memory up to 1 hour and never write it to disk; Anthropic may keep chats where the law requires it or to fight abuse.
Tinfoil models are labelled “zero provider visibility” and run in a trusted execution environment, which DuckDuckGo says keeps even the host from reading the prompt. Optional Sync & Backup stores chats with a key that lives on the user’s devices. Feedback chats that a user chooses to share are stored and reviewed.
None of that creates a legal privilege. A user who pastes a medical record into any consumer bot, including a “private” one, still does not get doctor-patient confidentiality. What changes is how long a named file sits on a server waiting for the next warrant, the next reviewer, or the next training run.
The June survey put a number on a habit that is already in evidence folders and training sets. The doctor, the parent and the friend still have not been told.
Frequently Asked Questions
Are ChatGPT chats covered by doctor-patient privilege?
No. Privilege attaches to a licensed clinician, lawyer or clergy member, not to a software vendor, and Sam Altman’s 2025 call for an “AI privilege” has not become U.S. law. Consumer ChatGPT Free, Plus and Business plans also have no HIPAA business associate agreement, so pasting a patient’s chart into those products is not a protected medical record.
Does turning off ChatGPT training remove old chats from the model?
No. OpenAI says that once you opt out, new conversations are not used to train, but the control does not pull data already used in training back out of a model. Temporary Chat is a separate mode: those threads stay out of history and training while they remain temporary, then are deleted from OpenAI’s systems after 30 days, with abuse review still possible in that window.
Can a boss read chats on a work AI account?
Usually yes. DuckDuckGo listed employer access to work and enterprise accounts as one of its six basic facts, and company-managed ChatGPT, Copilot or Gemini seats are business systems. Personal chats typed on a work device can also show up in a device image or a later discovery request even if the vendor never hears from the employer.
Do Duck.ai chats still go to OpenAI or Anthropic with your name on them?
DuckDuckGo says it strips personal metadata such as IP address before the prompt reaches those firms, so the call is attributed to DuckDuckGo, and providers agree not to train on the text. OpenAI may still cache a prompt in memory for up to 1 hour, and Anthropic may retain chats when required by law or to stop abuse, so “anonymous” is not the same as “never stored anywhere for any reason.”
Disclaimer: This article is news reporting on a published survey and on public legal and product records. It is informational only and is not medical, legal or privacy-compliance advice. It does not tell anyone what to type into a chatbot, what to tell a clinician, or how to respond to a subpoena, warrant or employer request. Readers who have a health concern should speak with a licensed clinician, and readers who have a legal exposure should speak with a qualified attorney in their jurisdiction, before acting on anything described here. Figures and product rules reflect the cited survey, poll, company pages and court records as of the dates on those documents and can change when companies update settings or when courts issue new orders.
-
NEWS4 months agoThe Orchard Bug Forced Zcash to Open an Empty Pool
-
GAMING4 months agoThe $5.99 Game That Won Steam’s 2026 Summer Sale
-
ENTERTAINMENT6 months agoDon Lee Joins Hemsworth as Extraction 3 Starts Shooting
-
NEWS4 months agoYouTube Shorts Retires Dislikes and Swaps Likes for Hearts
-
NEWS4 months agoNEURA Robotics Is Spending Its $1.4B on a Machine Stack
-
AUTO6 months agoKawasaki Bets the New Z1100 Against Its Own Supercharger
-
BUSINESS5 months agoNorway’s Export Bank Backs Nscale’s $790 Million Narvik Loan
-
GAMING4 months agoGame of Thrones Dragonfire Follows Boston’s Conquest Playbook
