In May 2025, a federal judge ordered OpenAI to preserve every ChatGPT conversation, including the ones users had deleted, and the ones they had marked temporary specifically so they would not be kept. For weeks before anyone was told, the company was quietly retaining those “deleted” chats to comply. By November, the same lawsuit forced OpenAI to hand over twenty million user conversations to the plaintiffs. The users whose chats were in that pile were not parties to the case, were not asked, and were not able to stop it.
Sit with what that means. Your “deleted” AI conversations were never actually yours to delete. They lived on a server, tied to your account, your IP, and your timestamps, and a copyright lawsuit you had nothing to do with turned them into evidence you could not opt out of. The delete button was a light switch that only dimmed the room you were looking at.
This is the new surveillance surface almost nobody is accounting for, and it may be the most intimate one yet: the AI assistant.
Why AI is a different kind of exposure
A search engine sees your questions. An AI assistant sees your thinking.
People talk to chatbots the way they talk to no app and no search box, candidly, at length, about the things they are most careful with everywhere else. Health worries they have not told their doctor. Legal problems. Money trouble. Relationship dilemmas. Business plans and client details. Half-formed ideas they would never say out loud. It feels like a conversation, so people confess to it, and every word is logged on someone else’s computer, attached to their identity.
That is the shift. It is not that AI collects more of the same kind of data. It is that you volunteer a deeper kind of data, willingly, because the interface feels private and patient and non-judgmental. It is a confessional wired to a corporation, and the corporation keeps the transcript.
What actually happens to what you type
It is retained, and “deleted” may not mean deleted. As the OpenAI case showed in the harshest way, your control over your own chat history is provisional. A court order, a policy change, or a lawsuit can override your delete button, and you will likely be the last to know. Even in normal operation, “memory” features keep extracted notes about you separate from the chats, so clearing a conversation does not clear what the system learned from it. It is the same lesson as deleting anything digital: gone from your view is not gone from the server.
It can become discoverable. Logged conversations tied to your identity are exactly the kind of thing that gets subpoenaed, produced in litigation, or handed over by the tens of millions, as we just watched happen. Whatever you told it can, in the wrong circumstance, be read by someone you never imagined.
It can train the product. Depending on the service and your settings, your inputs can be used to train future models, folding your words into a system millions of other people query, with a real if small risk of the model regurgitating something it should not.
It can go somewhere you would not choose. Some popular assistants route your data through jurisdictions with their own ideas about access. Free AI, like most free things online, is paid for with your data. And leaks happen: one major assistant’s “discover” feed briefly exposed people’s private conversations to the public because they did not realize what they were sharing.
And increasingly, it watches your screen. The biggest change underway is AI being baked directly into the operating system, with deep, standing access. Features that screenshot everything you do so the assistant can “remember” it. Assistants wired into your messages, files, and apps. The assistant is quietly becoming an always-on eye with system-level privileges, and most of its intelligence runs in the cloud.
The fix is the same one we keep arriving at: keep it on the device
The privacy-preserving answer to all of this already exists, and it is not “trust the AI company more.” It is to run the AI on your own device.
Models now run locally on phones. When the AI lives on the device, your prompt never leaves it. There is no server-side log, because there is no server. Nothing to retain under a court order, nothing to train on, nothing to subpoena, nothing to breach, nothing to hand over by the millions in someone else’s lawsuit. The intelligence comes to your data instead of your data going to the intelligence. This is the exact same principle behind everything we build: on-device beats the cloud, and the strongest privacy is the kind where there is simply nothing for anyone else to hold.
We will be honest about the tradeoff, because there is one. On-device models are smaller and less capable than the giant frontier models running in data centers. For a lot of everyday tasks they are more than enough, and the gap is closing fast. But some jobs genuinely need the big cloud models, and when you reach for one, the right mental model is simple: treat it like a public conversation. Do not put anything in it you would not put on a postcard, turn off history and training where you can, and prefer providers with real retention policies rather than ones a single court order can rewrite. On-device for anything sensitive, cloud only for the things that are not, and never confuse the two.
How we think about it
We build for on-device intelligence, AI that runs on your hardware rather than reporting your inner monologue to a server, and for a device where you decide what any assistant is allowed to see rather than having a cloud assistant welded into the OS with a view of your whole life by default. Your AI should work for you, locally, the way a tool does. It should not be a microphone into your most candid moments that happens to answer questions.
The uncomfortable truth of the last two years is that people have started telling AI the things they trust least to everyone else, at exactly the moment it became clear those conversations are logged, retained, and discoverable on machines you do not control. The answer is not to stop using AI. It is to run the private parts of it where the transcript belongs to you, which is to say, nowhere but your own device.
If you want a phone built to keep your AI, and your data, on your side of the glass, that is what we make. Email hello@spicycorp.com, or book a call.
SovereignOS is a hardened, de-Googled phone, set up the way we would build one we had to rely on ourselves. One-time price, no subscription, no account required.
See SovereignOSRecent Posts
- Your Phone, Laptop, and TV Are One Profile. Here’s How They Got Linked.
- Your Advertising ID Is a Tracking Number. Here’s How to Actually Kill It.
- Surveillance Capitalism in Plain English (You’re Not the Product, Your Future Is)
- Does iPhone Lockdown Mode Actually Work? (Yes, and Here’s Where It Stops.)
- Your Data Just Leaked. Here’s the First 48 Hours.
Recent Comments
Post Widget
Why Your VPN Isn’t Hiding Your IMEI
Should You Trust Signal?
Social Media Widget
Customer service
Real people, ready to help. Reach our team anytime at hello@spicycorp.com.
Fast Free Shipping
Get free shipping on orders of $150 or more (within the US)
Returns & Exchanges
We offer free returns and exchanges within 30 days of purchase.