Dr Prerna Kohli

You Think You’re Writing in a Diary. You’re Writing on Someone Else’s Server.

AI & Mental Health · 5 of 9

You Think You're Writing in a Diary. You're Writing on Someone Else's Server.

What actually happens to the things you type into a chatbot, how that differs from clinical confidentiality, and what India's data law does and doesn't give you.

Is ChatGPT confidential? No, not in the way a therapy session is. Conversations with general chatbots are stored on company servers, may be reviewed by staff, and depending on your settings may train future models. Clinical confidentiality is a professional duty with legal weight. A privacy policy is a company's own terms, changeable at will.

"People tell a chatbot things they have never told their husband. They do it because the screen feels private. Privacy and confidentiality are not the same thing, and the difference matters most to the people least likely to check."
PK

From a clinical-psychology lens. Confidentiality is the foundation everything else in my work sits on. When someone assumes they have it and don't, that isn't a technical footnote. It's a misunderstanding about the nature of the relationship they think they're in.

A woman asked me last year whether her sessions could be subpoenaed. Reasonable question, and I answered it properly, because clinical confidentiality has limits and people deserve to know them before they speak rather than after.

She'd never asked the same question about the app she'd been using nightly for a year.

What confidentiality actually means in therapy

It's a professional obligation, not a preference. What you say in a session stays there, and the limits on that are narrow, well-defined, and explained to you at the outset rather than buried in a document you scrolled past.

Those limits exist. They generally involve serious risk to you or someone else, or a court order. A clinician who tells you confidentiality is absolute is being careless. What matters is that the boundaries are known in advance, they're enforced by a professional body, and I can't change them because it suits me commercially.

What happens to what you type into a chatbot

Something structurally different. You're a user of a service, and the terms are set by the company providing it.

  • It's stored. Conversations are retained, typically for a period the company decides. Deleting a chat from your view isn't the same as deletion from their systems.
  • Humans may read it. Most providers reserve the right to have staff or contractors review conversations for safety and quality.
  • It may train the model. Depending on the product and your settings, what you write can be used to improve future systems. Consumer accounts often default to this.
  • The terms can change. A privacy policy is a document a company writes and can rewrite. My professional duty isn't.
  • It can be produced in litigation. Data held by a company is discoverable in the ordinary way, and there's no equivalent of a clinical privilege attached to it.

The confidentiality gap

41%
of surveyed users named privacy and anonymity as one of the most appealing aspects of using AI chatbots for mental health
1 in 3
roughly the proportion of Indian young users in one study who understood that a general chatbot is not a mental-health tool
₹250 cr
maximum penalty under India's Digital Personal Data Protection Act, with full enforcement scheduled for May 2027

Sources: Statista survey of US users, May 2024; Indian research on young users' chatbot use, reported 2025; Digital Personal Data Protection Act 2023 and DPDP Rules notified November 2025, Ministry of Electronics and Information Technology.

The first two figures together describe the problem. People choose these tools partly because they feel private, and most haven't checked whether they are.

Where India's data law leaves you

Better protected than before, and not yet protected in practice. The Digital Personal Data Protection Act was passed in 2023, its rules were notified in November 2025, and enforcement is phased across 2026 and 2027.

What it gives you on paper is real: the right to know what's collected and why, to access and correct it, to ask for deletion, and a Data Protection Board to complain to. Penalties reach ₹250 crore. It applies to any company offering services to people in India regardless of where the company sits.

What it doesn't give you is clinical privilege. Data-protection law governs how your information is handled. It doesn't make a conversation confidential in the sense a consulting room is, and it doesn't make a chatbot a clinician. Those are different categories of protection and the second one isn't available from a software product.

Be especially careful about writing about other people. Your account of a marriage, a parent or a colleague names someone who never agreed to be written about. They have no settings to adjust and no notice that it happened.

Who this matters most for

Not everyone equally. If you're describing an ordinary difficult fortnight, the exposure is modest.

It's different if what you're writing could cost you something. Anyone working through their sexuality in a family that doesn't know. Anyone describing violence at home. Anyone in a custody dispute, or a workplace matter, or a family property fight, where a written record of what you thought in March could matter later. People in marital difficulty often type things they'd never put in a message, without registering that they've created a document.

It's also different for anyone in a household where a shared device, a shared account or a family member with your password makes the conversation local rather than corporate. That's a common situation in Indian homes and it's the exposure people most often overlook.

Using it more carefully

You don't have to stop. Be deliberate about a few things.

  • Check your settings once. Most providers let you turn off training on your conversations, and turn on shorter retention. It takes two minutes and almost nobody does it.
  • Write about feelings, not identities. "My manager" rather than a name. "My brother-in-law" rather than a place of work and a designation.
  • Keep the legally sensitive out. Anything touching a dispute, a case, or a matter that might be examined later belongs with a lawyer or a clinician, not a chatbot.
  • Assume permanence. Write as though it might be read. Not because it probably will be, but because that assumption produces sensible caution at no cost.
  • Watch the device. Log out on shared phones and computers. In a joint household this is often the bigger risk.

Some things belong in a room with a door

Sessions with Dr. Kohli directly, in Gurugram or online worldwide, in English or Hindi. Confidentiality and its limits explained clearly before you begin.

Book a session WhatsApp +91 9811862338

Common questions

Is ChatGPT confidential?

No, not in the clinical sense. Conversations are stored on company servers, may be reviewed by staff for safety or quality, and depending on your settings may be used to train future models. Confidentiality in therapy is a professional duty with defined limits. A privacy policy is a company's own terms, which it can change.

Can OpenAI or Google read my conversations?

Providers generally reserve the right to have staff or contractors review conversations for safety, abuse detection and quality purposes. Whether any specific conversation is read is a different question from whether it can be. The permission exists in the terms you accepted.

Does deleting a chat actually delete it?

Deleting removes it from your view. Retention on the provider's systems follows their own policy, which usually keeps data for some period afterwards, and backups may persist longer. Treat deletion as removing it from your screen rather than from existence.

Can my chatbot conversations be used in court?

Data held by a company can generally be sought through ordinary legal process. There's no equivalent of clinical privilege attached to a chatbot conversation. If you're involved in anything that might become a legal matter, that's a strong reason to keep it out of an app.

Does India's DPDP Act protect my chatbot conversations?

It gives you rights over your personal data: to be informed, to access and correct, to seek deletion, and to complain to the Data Protection Board. It applies to companies serving Indian users wherever they're based. What it doesn't create is clinical confidentiality, which is a different kind of protection entirely.

Is a mental health app safer than ChatGPT for privacy?

Sometimes, and don't assume it. Purpose-built tools may make clearer commitments, but they're still commercial products governed by their own terms. Read what the specific app says about retention, human review and training rather than trusting the category.

Can I turn off AI training on my conversations?

Most major providers offer a setting to exclude your conversations from model training, and some offer shorter retention. It's usually in privacy or data controls and takes a couple of minutes. Very few people ever look, which is the main reason the default matters.

What if I've already shared very personal things?

Most people have, and it isn't a catastrophe. Check your settings, delete what you'd rather not keep, and be more deliberate going forward. If something you wrote could genuinely be used against you in a dispute or at home, that's worth discussing with an appropriate professional.

Is it risky to write about my family?

It carries a risk they didn't agree to. Your account of a spouse, parent or child names a person who has no settings to change and no idea it happened. Writing about your own feelings is different from creating a record about someone else's behaviour.

What are the limits of confidentiality with a psychologist?

They're narrow and they're explained before you start. Broadly they involve serious risk of harm to you or another person, or a legal requirement such as a court order. Anyone who tells you confidentiality is absolute isn't being straight with you.

Is online therapy as confidential as in person?

Yes, in professional terms. The duty is the same regardless of the medium. What changes is the practical side: you need somewhere private to take the call and a device you control, which in a shared household is often the harder part to arrange.

Someone in my family knows my password. What should I do?

Log out after use, use a device-level lock, and consider whether the app is the right place for anything sensitive. In many Indian households this is a larger practical risk than anything a company does. It's also worth thinking about why the privacy matters so much, and whether that's a subject in itself.

Related reading: marriage counselling, anxiety, and NRI mental health.

PK

Dr. Prerna Kohli

Clinical Psychologist · Gurugram and online worldwide

PhD & M.Phil in Clinical Psychology from Aligarh Muslim University, where she was a four-time gold medallist. More than 30 years in private practice. Honoured among the "100 Women Achievers of India" by the President of India in 2016. TEDx speaker, published author, and an independently documented entity on Wikipedia and Wikidata. She sees individuals, couples and families in English and Hindi.

This article is general psychoeducation and not legal advice or a substitute for individual assessment. Data-protection provisions change, so check current terms with your provider. If you are in immediate danger or unable to keep yourself safe, contact your local emergency services or attend your nearest hospital without delay.