AI assistants keep a record of what users type into them. This guide covers where those conversations are stored, how to export or delete your own copy, and what happens when a court asks the provider to hand them over.
Assemble what you need before you start
You need the login credentials for the account that produced the conversations, access to the email address attached to it, and a clear idea of which product tier you are on — consumer, team or enterprise — because retention rules differ between them. Set aside somewhere secure to put the export when it arrives.
The practical context for this is a legal one. Ars Technica reports that the province of British Columbia has sued OpenAI over a shooting in Tumbler Ridge in which ChatGPT was used, that the claim asks the company to fund a new school, and that it seeks the shooter’s ChatGPT logs. The merits of that claim are for a court, and nothing here is a prediction about it. What it illustrates is general: conversations with an AI assistant are records held by a third party, and third-party records can be demanded.
Confirm which account holds the conversations
Work out which account was actually signed in. People routinely mix a personal account with a work one, or use a single sign-on identity tied to an employer’s tenancy. This matters because it determines who controls the data. On a personal account, you usually hold the controls yourself. On a workplace or enterprise deployment, the administrator does: they can often see usage, set retention periods and export conversations without your involvement.
If you used the assistant while signed out, through an embedded feature in another product, or through a developer API key, the record may sit somewhere else entirely, under a different policy. Check each surface separately rather than assuming one export covers everything. Where you cannot determine which account was used, treat the conversations as potentially retained until you have confirmed otherwise.
Check the retention and training controls
Open the account settings and find the section dealing with data, privacy or data controls. Most major assistants expose three distinct things that are easy to confuse: whether your conversations appear in your visible history, whether they are used to improve the provider’s models, and how long the provider keeps them on its own systems. Turning off history or training does not necessarily mean immediate deletion; providers commonly keep copies for a defined period for abuse monitoring and security.
Read the provider’s published retention policy rather than inferring it from the interface. Note the stated period for deleted conversations, for temporary or incognito-style chats, and for API traffic, which is often governed separately. If the documentation does not state a period clearly, that is itself worth recording — it means you do not know how long the data persists.
Export the full history
Request a data export from the settings menu. On most services this is asynchronous: you ask for it, and a download link arrives by email within hours or days. The package typically contains your conversations in a machine-readable format such as JSON, sometimes with an HTML viewer, plus account metadata.
Download it promptly, because these links usually expire. Open the archive and check that it actually contains what you expect: the date range, the conversations you remember, and any uploaded files or images. Exports sometimes omit attachments, shared links, custom instructions or content from separate products under the same brand. If something is missing, submit a formal data access request under whichever privacy law applies to you — data protection regimes in the UK, the EU and Canada all give individuals a right of access to personal data held about them, with defined response deadlines.
Store and verify the export
Put the archive somewhere you control and can find again: encrypted local storage or a managed corporate repository, not an unsecured cloud folder. Record the date you made the request, the date you received the file, and its size. If the export may ever matter evidentially, compute a cryptographic hash of the file and note it alongside, so you can later show the copy has not been altered.
Remember what the export contains. Conversations with an assistant often include draft correspondence, credentials pasted in haste, client details, health information and internal business material. An export concentrates all of that into one file, which makes it convenient for you and valuable to anyone who obtains it. Treat it with the same care as a password vault backup.
Respond properly to a preservation notice
If you or your organisation receive a litigation hold, preservation letter or regulatory notice touching on AI tool use, stop routine deletion immediately. Disabling auto-deletion and telling staff not to clear histories is the first step; deleting material after a hold attaches can be a serious problem in itself, separate from the underlying dispute.
Tell your legal adviser which assistants are in use, on which accounts, and what the provider’s retention terms say. Bear in mind that a party to a case may be able to seek records directly from the provider rather than from you, and that the provider may hold data you no longer see. Whether any given provider still holds a particular conversation, and in what form, is not something outsiders can determine from the outside — only the provider can answer that.
Avoid the mistakes people actually make
The most common error is assuming that clearing a conversation from the interface erases it everywhere. Deletion from your view and deletion from the provider’s infrastructure are different operations on different timelines.
The second is treating an enterprise deployment as private from the employer. Administrative visibility is usually a contractual feature, not a bug.
The third is exporting once and considering the job done. An export is a snapshot; conversations created afterwards are not in it.
The fourth is deleting material in a hurry once a dispute appears on the horizon, which converts a manageable disclosure problem into an allegation of spoliation.
The fifth is confusing a provider’s public policy with the contract that actually governs your account. Negotiated enterprise agreements can differ substantially from the consumer terms published on a website.
Recognise when this approach is the wrong choice
Self-service export is the right tool for personal record-keeping, privacy hygiene and ordinary compliance. It is the wrong tool once a matter becomes contentious. If you are under investigation, party to litigation, or handling someone else’s regulated data, do not start clicking through settings on your own initiative: take legal advice first, because the act of exporting or deleting can itself become an issue.
It is also the wrong tool for verifying what another person did. You cannot retrieve someone else’s conversations by asking the provider politely; that requires legal process. And it will not tell you what a provider retains internally beyond what it chooses to disclose. For that, the only reliable sources are the provider’s own documentation and, where a court is involved, whatever it is ordered to produce.
Frequently asked questions
Does deleting a ChatGPT conversation remove it permanently?
Not immediately, and not necessarily everywhere. Deleting a conversation removes it from your visible history, but providers generally state that copies may persist on their systems for a defined period for security, abuse monitoring or legal reasons. The exact period varies by provider and by account type, and is set out in the published retention policy rather than in the interface. Backup and log systems can retain data on separate schedules.
Can a court order an AI company to hand over someone’s chat logs?
Courts can order third parties to produce relevant records they hold, and AI providers are third parties like any other service. Whether a particular order succeeds depends on jurisdiction, the legal basis of the claim, applicable privacy law and what the provider still holds. Ars Technica reports that the British Columbia lawsuit seeks such logs. Whether that request will be granted has not been determined.
How do I get a copy of everything an AI assistant knows about me?
Start with the in-product data export, usually found under settings labelled data controls or privacy. If the export is incomplete, submit a formal access request under the data protection law that applies to you, such as the UK or EU GDPR, or Canadian federal privacy legislation. These requests have statutory deadlines and generally cover more than the self-service tool returns.
Are my work conversations with an AI assistant private from my employer?
Usually not. In enterprise and team deployments, administrators typically have tools to set retention, audit usage and export conversations, and the employer rather than the individual controls the data. Some deployments also route traffic through corporate monitoring. Assume workplace AI conversations are visible to the organisation unless a written policy says otherwise, and check that policy rather than relying on the interface.
Sources and further reading
- Ars Technica — technology policy reporting on the British Columbia lawsuit against OpenAI, which is the immediate occasion for this guide.
- OpenAI’s published privacy policy and data controls documentation — the authoritative statement of what the company says it retains and for how long.
- The Office of the Privacy Commissioner of Canada — guidance on individual access rights to personal information held by organisations.
- Practitioner guides to electronic discovery and litigation holds, published by bar associations and law firms, for the mechanics of preservation obligations.
Surfaced from the rss:arstechnica signal “lawsuit over chatbot logs”. AI-assisted draft, editorially reviewed.

