Is AI therapy private?
The short answer is no — not in the way people mean when they ask. That is true of every AI product on the market, and it is true of this one. Here is what the answer actually means, what it does and doesn't put at risk, and how to check any tool for yourself.
Is AI therapy confidential?
AI therapy is not confidential. No consumer AI product carries the legal confidentiality a licensed therapist owes you, and conversations with an AI have no legal privilege — meaning they can be demanded by a valid subpoena, warrant, or court order. What a carefully built AI tool can offer instead is privacy: hard limits on who can read your words, how little is kept, and how quickly you can delete it. Those are real and worth having. They are not the same thing as confidentiality, and any product that lets you believe they are has told you something untrue by omission.
Private and confidential are two different words
This distinction is where most of the confusion lives, and almost nobody spells it out.
- Confidential is a legal duty owed to you. A licensed therapist can lose their licence for breaking it, and in most jurisdictions what you tell them is privileged — protected even from a court, with narrow exceptions like an imminent risk of serious harm.
- Private describes how a company handles data: who can read it, what is stored, how long it is kept, whether it trains a model. It is enforced by the company's own engineering and by consumer-privacy law — not by a licensing board, and not by privilege.
An app can only ever sell you the second one. When a product says "your conversations are confidential," read it as marketing language, not a legal statement, and go looking for the specifics.
Which legal protections actually apply?
Every explainer on this topic describes this in prose, which makes it hard to hold in your head. Laid out plainly, here is what does and does not attach to each kind of conversation:
| Where you talk | Legal privilege in court | HIPAA | Enforced by |
|---|---|---|---|
| A licensed therapist | Yes, with narrow exceptions | Yes | Licensing board + the courts |
| A therapist's AI notetaker | Follows the therapist's record | Yes — the vendor signs a BAA | Licensing board + contract |
| A general-purpose AI chatbot | No | No | Its own privacy policy |
| A consumer AI journaling app | No | No | Its own policy + consumer-privacy law |
| A paper diary | No — but discoverable only if known about | No | Nothing, and nobody holds a copy |
The bottom three rows are the important ones, and they are the rows people are surprised by. Consumer AI products — this one included — sit outside both protections that the word "confidential" implies. Consumer-privacy law still applies, and it is not nothing, but it governs how a company must handle data. It does not stop a court asking for it.
What "not confidential" actually puts at risk
The honest version is narrower than the headlines and broader than the marketing. Three things are genuinely true:
- Legal demands reach it. A company holding your conversations can be compelled to produce them. This is not a hypothetical about a hypothetical future — it is the ordinary operation of law, and it applies to every provider.
- Staff access is normal. Most products allow some employee access for support, abuse review, or debugging. That is not sinister; it is how software gets fixed. What varies is whether it is disclosed and how tightly it is scoped.
- Your words are processed by a third party. Every AI product sends your text to a model provider to generate the reply. That is not a leak, it is the mechanism. The question is whether the app tells you which company, under what agreement.
What is not generally true: that your conversations are public, that anyone can look you up, or that your therapist can see them. Those fears come up often and are, for any reputable product, unfounded.
How to check any AI tool yourself
This is the part nobody publishes, and it takes about five minutes. Open the product's privacy policy and answer six questions. If you cannot find an answer quickly, that absence is the answer — a company that has done this work is usually eager to show it.
If you would rather run these as a checklist than hold six answers in your head, we built a free tool that walks you through them and reads the result back to you. It stores nothing and sends nothing — the answers stay in your browser.
- 1. Does it name the AI provider? "Industry-leading AI" is not a name. You are looking for a specific company. If a product will not tell you whose infrastructure reads your words, every other privacy claim it makes is unverifiable.
- 2. Does it train on your conversations? Look for a plain yes or no, and check whether the default is opt-in or opt-out. Default-on training with a buried toggle is common.
- 3. What is actually stored on their servers — and can you turn that off? "Encrypted" tells you how something is stored, not whether it is stored. A tool that lets you stop server-side storage entirely is offering something stronger than one that only encrypts.
- 4. Who holds the encryption key? If the company derives or holds it, they can decrypt your data — that is encryption at rest, and it is a genuine protection against theft and unauthorised access, but not against the company itself or a court order. Only end-to-end encryption, where the key never leaves your device, protects against those. Very few products offer it, and the ones that do say so loudly.
- 5. Can you delete it — all of it, yourself, now? Deletion should be a button, not a support ticket. Check whether it covers exports, backups, and derived data like summaries, and how long anything is retained afterward.
- 6. What is the business model? If you are not paying, something else is being monetised. Ads and data brokerage create a permanent structural pull against your privacy that no policy page fully offsets.
The three tiers, honestly ranked
"AI apps" is not one category, and treating it as one is the main analytical mistake in the coverage of this topic. On privacy specifically, there are three tiers:
- Fully offline apps are the most private. A journaling app that runs a model on your own device and never sends anything anywhere cannot leak, cannot be subpoenaed at the company, and cannot train on you. If maximum privacy is your priority above everything else, this tier is the correct answer and you should stop reading here.
- Purpose-built cloud apps sit in the middle. They sync across your devices and can offer a much better product, but a server holds something. The good ones name their processor, encrypt what they store, strip identifiers, and let you delete everything. Haven is in this tier.
- General-purpose chatbots are the weakest for this use. They are built for everything, retain broadly by default, and are the most exposed to legal demands at scale. They are also, by a wide margin, what most people are actually using for this.
Where Haven lands on its own checklist
It would be dishonest to publish that checklist and dodge it, so here are our own answers — including the two we lose on.
First, the thing that matters most and gets said least: Haven is not therapy, not a therapist, and not a crisis service. It is a private space to think out loud with a supportive AI guide. Nothing on this page should be read as a claim to be treatment.
- Provider named: yes — Google's Gemini API generates the replies, and it is named in our Privacy Policy rather than described vaguely.
- Trains on your conversations: no. We do not train any model of our own on what you write.
- Stored on our servers: yes, by default — your conversations sync so they follow you between your phone and your laptop, encrypted at rest with AES-256-GCM. Turning off Remember chats in Settings stops that: the server then holds no conversations for your account. Separately, the chat endpoint itself never writes your message text to our database — it records only the usage numbers needed for billing.
- Who holds the key: we do. Haven is not end-to-end encrypted. Your data is encrypted at rest on our servers and again in your browser's local storage, but the key is derived by our server, so we could decrypt it and a court could require us to. An app whose key never leaves your device beats us on this, and we would rather say so than let the word "encrypted" do misleading work.
- Deletion: yes, self-serve. You can delete individual conversations and memories, erase all saved conversations, export your data, and delete the account outright from Settings.
- Business model: a subscription. No ads, no ad trackers, no selling data. Optional usage analytics can be turned off in Settings, which also deletes the events already recorded.
- One extra: before your text reaches the model, identifying names are stripped out and substituted back into the reply afterwards — so the words that leave our server carry less about who you are than the words you typed.
What we cannot protect you from
Stated as plainly as the strengths above, because a privacy page that only lists wins is not worth reading.
- Lawful process. If served with a valid subpoena, warrant, or court order, we would have to comply, exactly as our Privacy Policy states. Turning off Remember chats is the strongest practical answer: what we do not hold, we cannot produce.
- Legal privilege. We cannot give you what only a licensed professional can. Nothing you tell Haven is privileged.
- HIPAA coverage. HIPAA does not cover consumer wellness apps, and it does not cover Haven. What protects you here is our Privacy Policy, consumer-privacy law, and a product built to collect little and delete on request — not a healthcare regulation that was never written for this. Our health-data notice covers this in more detail.
- Anyone you choose to share with. If you open a shared conversation or connect a professional, they see what you deliberately send them. That is under your control, and it is not undoable by us.
- Your own device. If someone has your unlocked phone or your account password, no server-side design helps. A device passcode and two-factor authentication do more for your privacy here than any feature we could ship.
Where to go from here
If you want the specifics for this product rather than the category, how private Haven is, in detail walks through what happens to a single message end to end. If you are weighing a general chatbot against a purpose-built tool, what court orders mean for ChatGPT conversations and a straight Haven-versus-ChatGPT comparison are the two most useful next reads. For journaling specifically, is your AI journal actually private? runs the same checks across that category. And if the underlying question is whether any of this is good for you rather than whether it is private, is talking to an AI healthy? is the more honest place to start.
Common questions
Is AI therapy confidential?
No — not in the legal sense the word carries with a licensed therapist. Confidentiality is a legal duty backed by licensing boards and, in court, by privilege. No consumer AI product has that, including this one. What a well-built AI tool can offer is privacy: limits on who can read your words, what is kept, and how fast you can delete it. Those are real protections, but they are the company’s policy and engineering, not a legal shield.
Does HIPAA cover AI therapy apps?
Almost never. HIPAA applies to healthcare providers, health plans, and their business associates — not to consumer wellness apps, which is what most AI therapy and AI journaling products are. An app can hold extremely sensitive information about your mental health and still sit entirely outside HIPAA. "HIPAA-compliant" on a consumer app’s marketing page is usually either about a separate clinician-facing product or is simply wrong.
Can my AI chats be subpoenaed or used in court?
Yes. Conversations with an AI carry no legal privilege, so a company holding them can be compelled to produce them by a valid subpoena, warrant, or court order. OpenAI’s own CEO said publicly in 2025 that this protection has not been worked out for ChatGPT. The practical defences are ordinary ones: pick a tool that stores less, and delete what you no longer need — a company cannot hand over what it does not have.
Does AI use my conversations to train its models?
It depends entirely on the product and the tier, and this is the single most important thing to check. Many consumer chatbots use conversations to improve models by default, with an opt-out buried in settings. Paid API tiers used by purpose-built apps generally do not. The answer should be stated plainly in the privacy policy; if you cannot find it in under a minute, treat that as the answer.
Can my therapist see my AI chats?
Not unless you show them. There is no channel by which a therapist can reach into a consumer AI app and read your history, and no reputable app offers one. The reverse question matters more and is asked less: if your therapist uses an AI notetaker to record sessions, that audio leaves the room and is processed by a third-party company. That is worth asking about directly.
Who can actually read what I type into an AI chatbot?
Usually more parties than people expect: the company itself (staff access is normal for support, abuse review, and debugging), the AI provider processing the text to generate a reply, and anyone the company is legally compelled to disclose to. A careful product narrows this list, encrypts what it stores, strips identifiers before the text reaches the model, and says so specifically. A vague "we take your privacy seriously" is not an answer to this question.
What is the difference between private and confidential?
Private describes how data is handled: who can read it, how it is stored, how long it is kept. Confidential describes a legal duty owed to you, enforceable through licensing boards and privilege in court. A therapist owes you confidentiality. An app can only offer you privacy. Products blur the two constantly, and the blur is the thing to watch for.
Is AI journaling confidential?
No, for the same reason AI therapy is not — there is no legal duty attached. But AI journaling tools vary enormously in how private they are in practice. A fully offline journaling app that never sends anything to a server is more private than any cloud product, including this one. A cloud app that names its processor, encrypts what it stores, and lets you delete everything is meaningfully more private than a general-purpose chatbot. Those are three different tiers, not one category.