Are AI therapy chats private? Usually not in the way people assume. Talking to a consumer AI "therapy" or companion chatbot is not the same as talking to a licensed therapist: there is generally no legal confidentiality and no therapist-patient privilege, and many popular chatbot terms let the company store your messages, use them to improve its models, and hand them over in a legal process. Is Character.AI confidential? Its own privacy practices allow it to save your chats, let staff and systems use them to train models, and disclose data to law enforcement or through legal process. This is not medical or legal advice, and if you are in crisis you should reach a licensed professional or a crisis line, not a chatbot.
Why an AI therapy chat is usually not legally confidential
A conversation with a consumer chatbot carries no legal privilege. Privilege is a specific legal protection that attaches to a relationship with a licensed professional, such as a therapist, a doctor, or a lawyer. It can keep what you say out of court and off the record. A chat window inside a phone app does not create that relationship, no matter how caring the responses feel.
The head of the company behind ChatGPT said this plainly. In July 2025, Sam Altman warned that "there's no legal confidentiality for users' conversations" when people use ChatGPT as a therapist, and contrasted that with a real therapist, lawyer, or doctor, where "there's legal privilege for it." He added that in litigation, "OpenAI would be legally required to produce those conversations today." The point is not that one company is careless. The point is that the legal protection you expect from a clinic does not exist for a consumer AI chat.
Confidential to a friend is not the same as legally confidential. A chatbot can promise privacy in soft language while its terms still allow storage, model training, and disclosure through legal process.
What no therapist-patient privilege means for you
No privilege means your words can be requested and used. Lawyers who follow this area describe it directly: there is no attorney-client privilege, no therapist-patient privilege, and no fiduciary duty attached to a chatbot conversation. Because the data sits with a third-party company, prosecutors can often reach it with a subpoena rather than the higher bar of a warrant, and companies can receive national security demands they cannot even tell you about. The risk here is what the same lawyers call the illusion of the advisor: people treat a friendly bot like a trusted professional and share things they would never post publicly, assuming a confidentiality that was never there. The legal protection you get for information shared with an AI is not matched to how sensitive that information is or to how private it feels in the moment.
There is a second trap that catches careful people. If you paste genuinely sensitive material, such as details tied to a divorce, a custody fight, or a workplace dispute, into a public AI tool, you may weaken the very protections you would otherwise have. Content you typed into a chatbot can become evidence that surfaces in related litigation. The safe assumption is simple: treat anything you type into a consumer AI app as something that could one day be read by a stranger.
What popular companion and therapy chatbot terms usually allow
Read the fine print and the pattern repeats: store, train, share. Character.AI, one of the most used companion apps, states that it collects your chat communications, posted images, and shared characters, and that this data is used to help train and improve its models. It also describes sharing information with affiliates and vendors, with law enforcement or through legal process, with a buyer in a business transfer, and with other users when a character is public or a chat is shared. Deleting your account does not guarantee immediate deletion of everything you sent.
This is common across the category, not unique to one app. When Mozilla reviewed 11 romantic and companion AI chatbots for its Privacy Not Included guide, every single one earned a privacy warning label, and 10 of the 11 failed basic security standards such as requiring a strong password. One app fired more than 24,000 data trackers within a single minute of use, sending information to advertising and marketing companies. Mozilla's takeaway was that users have little to no control over their data and often cannot opt out of having their conversations used to train the AI.
Regulators have noticed. On September 11, 2025, the US Federal Trade Commission issued Section 6(b) orders to seven companies that run consumer-facing AI companion chatbots, including Alphabet, Character Technologies, Meta, OpenAI, Snap, and xAI. The inquiry is examining how these products are monetized, how they test for harm, how they handle age verification, and what they disclose to users and parents about data collection and risks, with a focus on children and teens.
The 2025 and 2026 wave of state action against AI therapy
Several US states have now moved to keep AI out of the therapist's chair. Illinois went first. On August 1, 2025, Governor JB Pritzker signed the Wellness and Oversight for Psychological Resources Act (HB 1806, Public Act 104-0054), which took effect on signing. It bars anyone from using AI to provide mental health therapy or to make independent therapeutic decisions, and it stops AI from directly interacting with clients in therapeutic communication without a licensed professional. Violations can bring civil penalties of up to 10,000 dollars each, enforced by the state regulator.
Nevada and Utah acted in 2025 as well, with different tools. Nevada's AB 406 forbids AI systems from delivering professional mental or behavioral health care and from claiming they can, and it also keeps AI out of the counseling work done in schools. Utah took a lighter route with HB 452: it lets mental-health chatbots operate but requires them to disclose clearly that they are not human, restricts how they can advertise, and bars them from selling user health data. The direction of travel is consistent: an AI chatbot is not a licensed clinician, and states are increasingly saying so in law.
A chatbot marketed for "wellness" or "venting" instead of "therapy" is often designed to sidestep these rules. The label on the app does not change what happens to your words.
Where your sensitive words actually end up
The honest comparison is about custody of your text, not about which tool sounds kindest. A licensed therapist gives you privilege and a professional duty of care. A consumer AI chatbot gives you neither. A private notes app is a different thing again: it can keep your material out of training data and locked down, but it is a place to store thoughts, not a substitute for a clinician. The table below lays out the tradeoffs so you can decide what to type and where.
| What matters | Consumer AI therapy or companion chatbot | A private notes app like MemX |
|---|---|---|
| Legal privilege | None; it is not a licensed clinician | None either; it is a memory tool, not therapy |
| Who can read your text | Staff and systems may review chats; other users if shared or public | Private by architecture, per-user isolation; MemX does not train on your data |
| Used to improve AI models | Often yes, sometimes with a limited opt-out | No; your content is not used to train models |
| Exposure in legal process | Stored chats can be subpoenaed and produced | Encrypted at rest, but still not privileged; treat legal exposure as possible |
| Right call in a crisis | No; reach licensed care or a crisis line | No; it stores notes; reach licensed care or a crisis line |
What to do before you type anything sensitive
Assume the chat is not private, then act accordingly. You do not have to quit these tools to use them more safely. A few habits sharply reduce your exposure.
- Do not share identifying details. Skip full names, addresses, employers, account numbers, and anything that ties a story to a real person, including you.
- Read the privacy policy and terms before you open up. Look for whether your chats are used to train models, whether there is an opt-out, how long data is kept, and when it is shared with third parties or law enforcement.
- Turn off model-training settings where the app offers them, and delete conversations you no longer need, understanding that deletion is not always immediate or complete.
- Keep the sensitive stuff out of the cloud chat. If you want to journal a hard week, write it somewhere private that does not feed a model, then bring only general themes to the chatbot if you use one at all.
- For a real problem, choose real care. For depression, self-harm, abuse, or any crisis, a licensed professional or a crisis line is the appropriate and safer channel, and in a growing number of states an AI chatbot is legally barred from acting as your therapist anyway.
A private place to keep your own notes
If the issue is that your journaling and voice notes should not become training data or courtroom exhibits, the fix is to keep them somewhere built for privacy rather than for engagement. MemX is a personal memory app: it stores your documents, photos, voice notes, and messages, and lets you ask questions and get answers with the source. It is private by architecture, with per-user isolation, customer-managed keys, encryption at rest, and on-device processing where possible, and it does not train on your data. To be clear, MemX is a memory tool, not a therapist and not a legal shield, so it carries no privilege and cannot replace licensed care. What it can do is give your private reflections a home that is not designed to mine them.
The larger lesson holds no matter what you use. A comforting interface is not a confidentiality agreement. Before you tell an AI app your secrets, read the fine print, keep the identifying details to yourself, and save the hard conversations for the professionals who are actually bound to keep them.
01Are AI therapy chats private and legally confidential?
Generally no. A consumer AI therapy or companion chatbot does not create a therapist-patient relationship, so there is no legal privilege. The company's terms typically allow it to store your messages, use them to improve its models, and disclose them through legal process, so treat the chat as something that could later be read by others.
02Is Character.AI confidential?
No. Character.AI's own privacy practices state that it collects your chats, images, and shared characters and uses that data to help train and improve its models. It also describes sharing information with vendors, with law enforcement or through legal process, and with a buyer in a business transfer. Deleting your account does not guarantee everything is erased.
03Can my AI chatbot conversations be used in court?
Yes, they can. Because your chats sit with a third-party company and carry no privilege, they can be requested by subpoena and produced in litigation. Sensitive details you type into a public AI tool can become evidence, and pasting confidential material into a chatbot may even weaken protections you would otherwise have had.
04Did any US states ban AI therapy?
Yes. Illinois signed the WOPR Act in August 2025 barring AI from providing therapy or making independent therapeutic decisions, with fines up to 10,000 dollars per violation. Nevada's AB 406 prohibits AI from delivering professional mental health care, and Utah's HB 452 regulates mental-health chatbots with disclosure rules and a ban on selling health data.
05Is it safe to use an AI chatbot for mental health support?
A chatbot can help with light reflection, but it is not a safe channel for a real problem or a crisis, and it offers no confidentiality. This is not medical advice. For depression, self-harm, abuse, or any emergency, contact a licensed professional or a crisis line, and avoid sharing identifying details with any consumer AI app.
