Can ChatGPT Report You to the FBI? What the Goldman Sachs Case Means for AI Privacy
A former Goldman Sachs analyst recently learned a very uncomfortable fact about talking to an AI chatbot: the conversation may not stay entirely between you and the machine. OpenAI reported his ChatGPT conversations to the FBI after he used the service to describe detailed plans to harm his former girlfriend. The case is extreme, but the privacy lesson is not. If you use ChatGPT or any other large language model regularly, you should know what information you are putting into it, what controls you actually have, and what you are doing about the personal information that is already exposed elsewhere online.
What happened with the Goldman Sachs analyst?
According to court records reported by The Palm Beach Post, Darren Zhou, a 25-year-old financial analyst who was later fired by Goldman Sachs, began using ChatGPT after a breakup and gradually moved from talking about the relationship to describing threats against his former girlfriend. OpenAI's systems detected the risk, the conversation was reviewed, and the company reported the matter to the FBI. Zhou was later arrested, pleaded guilty to three charges, and received eight years of probation. The Palm Beach Post reported the original case.
There is an important distinction here. This was not a case of OpenAI reading an ordinary private conversation and deciding to call the police because it disliked what someone said. OpenAI has publicly said that when its systems detect users who are planning to seriously harm other people, those conversations can be routed to a specialized human review team. If reviewers determine there is an imminent threat of serious physical harm, the company may refer the matter to law enforcement. That is the policy context behind this case.
Does ChatGPT keep your conversations?
Yes, in the ordinary sense that your conversations are stored and associated with your account unless you delete them. OpenAI's current privacy documentation says it collects the content you provide to its services, including prompts, files, images, audio, video, and other material you submit. That does not mean every conversation is used to train an AI model, but it does mean that a normal ChatGPT conversation should not be treated like an anonymous notebook that exists nowhere outside your screen.
OpenAI gives users controls over how some of that information is handled. On individual ChatGPT accounts, you can turn off Improve the model for everyone in Data Controls. With that setting off, new conversations can remain in your chat history but are not used to improve OpenAI's models. That is useful, but it is not the same thing as making the conversation disappear.
What does Temporary Chat actually do?
Temporary Chat is a better privacy option for conversations you do not want sitting in your normal history. OpenAI says Temporary Chats do not appear in your chat history, do not create memories, and are not used to improve its models. They can still be kept for up to 30 days for safety purposes, and OpenAI says limited safety-related review may still occur. In other words, Temporary Chat reduces retention and personalization, but it is not the same as having a completely private, unrecorded conversation.
That distinction matters because people often think the privacy setting means, "Nobody can ever see this." It does not. Privacy controls can change how information is stored or used, while separate safety, security, or legal processes can still apply.
What should you never paste into an AI chatbot?
The easiest privacy rule is also the one people ignore: do not give an AI service more personal information than the task requires. A chatbot does not need your entire identity to help rewrite an email or explain a spreadsheet. Strip out details first when you can.
- Passwords and login codes. Never paste account passwords, one-time codes, recovery codes, or security questions into a chatbot.
- Financial account information. Remove bank account numbers, debit and credit card numbers, tax identifiers, and other information that can be used to access money or financial records.
- Government identifiers. Social Security numbers, driver's license numbers, passport numbers, and similar identifiers are rarely necessary for an ordinary AI request.
- Private documents. Employment records, legal paperwork, confidential contracts, medical documents, and private correspondence can contain far more identifying information than you realize.
- Other people's information. Your coworker, client, child, customer, or family member did not necessarily agree to have their personal information pasted into an AI service just because you can upload it.
Can you use ChatGPT without giving away your identity?
You can reduce the amount of identifying information you hand over, but there is a difference between sharing less and being anonymous. Your account, device, network, settings, and the content you submit can all form part of the overall data picture. OpenAI's privacy policy says it collects account information and user content, along with log and usage information related to the service.
That is why a sensible approach is to minimize the identifying details inside the prompt itself. Instead of writing, "My name is John Smith, I live at 123 Main Street, my phone number is..." you can often say, "I'm dealing with a billing dispute and need help writing a complaint." The AI usually needs the problem, not your full identity.
What about all the information already exposed about you?
This is where the AI conversation and the rest of your digital footprint become two separate privacy problems. You can be careful about what you type into ChatGPT and still have your home address, phone number, age, relatives, property records, or old contact information sitting on a people-search site.
Those sites are a different part of the data ecosystem. They collect information from public records, commercial sources, and other databases, then turn it into searchable profiles. Removing yourself from one site does not automatically remove you from the next, and a profile that disappears today can return later when a fresh record feeds into the system. This is why online privacy is not just about what you share; it is also about what other companies have already collected about you.
AI privacy and online privacy are connected, but they are not the same problem
You control what you put into an AI service. You do not control every data broker, people-search site, public-record database, or background-check service that may already have a profile about you. Privoria helps with that second problem by finding exposed personal information and having our team work through the removal process across the sites where your information is published.
Run my free scan Start free trialWhat can I do right now to protect my privacy when using AI?
The goal is not to stop using AI. ChatGPT and other LLMs can be incredibly useful. The better goal is to treat them like any other online service that receives information from you.
- Turn off model improvement if you do not want new chats used for that purpose. Check Settings > Data Controls and review the current options on your account.
- Use Temporary Chat for conversations you do not want in your normal history. Remember that Temporary Chat still has limited safety retention.
- Remove names, addresses, account numbers, and other identifiers before sending a prompt. Most tasks can be completed with the sensitive parts replaced or generalized.
- Delete old conversations you no longer need. Deleting is different from archiving, and OpenAI says deleted chats are scheduled for permanent deletion within 30 days subject to legal or security exceptions.
- Check what is already publicly exposed about you. AI privacy controls cannot remove a people-search profile that is already online.
Should I stop using ChatGPT because of this case?
No. The lesson is not that every ChatGPT conversation is being watched by the FBI. The more useful lesson is that an AI service is still a service operated by a company, with data controls, safety systems, retention policies, and legal obligations. In this case, the reported conversation involved detailed threats of serious physical harm, which is precisely the type of situation OpenAI says can trigger human review and possible law-enforcement referral.
The broader privacy habit is simple: do not put sensitive information into a service unless you understand why it needs the information and what controls you have over it. The same principle applies to AI, social media, online forms, shopping sites, and the hundreds of companies that collect information about you behind the scenes.
Frequently asked questions
Can ChatGPT report you to the police?
OpenAI says that if its systems detect someone planning to seriously harm another person, the conversation may be reviewed by a specialized team and may be referred to law enforcement when reviewers determine there is an imminent threat of serious physical harm. That is what happened in the reported Goldman Sachs analyst case.
Does turning off model training make ChatGPT private?
No. Turning off "Improve the model for everyone" means new conversations are not used to improve OpenAI's models, but the conversations can still remain in your chat history unless you delete them. Other privacy, safety, security, and legal processes can still apply.
Is Temporary Chat completely private?
No. Temporary Chats do not appear in history, do not create memories, and are not used to improve OpenAI's models, but OpenAI says they may be retained for up to 30 days for safety purposes.
Should I give an AI chatbot my real name and address?
Usually not unless the task genuinely requires it. For many writing, research, brainstorming, and troubleshooting questions, you can remove names, addresses, account numbers, and other identifiers first. The less unnecessary personal information you provide, the less you have to worry about later.
Can Privoria remove information from ChatGPT?
No. Privoria's service is designed for a different part of the privacy problem: finding and removing personal information published by data brokers and people-search websites. We cannot delete your ChatGPT account data or control another company's retention policies. What we can do is help reduce the public personal information that makes it easier for someone to find you in the first place.
Can I ever remove everything about myself from the internet?
No service can honestly promise that. Public records, copies, screenshots, archived material, and sites outside a removal service's reach can continue to exist. The realistic goal is to reduce unnecessary exposure and make your personal information substantially harder to find.