Every Breath You Take, Every Move You Make: What Your AI Vendor’s Fine Print Says About Client Data

The Police recorded one of the most misunderstood hits in pop history. Couples have chosen it for their first dance for decades, hearing devotion in a narrator who promises to watch every move, every step, and every word. Sting has spent almost as long correcting them. The song, he has explained, is not romantic at all — it is about surveillance, jealousy, and control, a voice that observes and records everything the other person does. It is an uncomfortably precise description of what happens to the words a lawyer types into a consumer AI tool.

This post is about that fine print — what the major AI platforms actually do with the text you feed them, who else can end up reading it, and what all of that means for a lawyer's duty of confidentiality.

Every Step You Take

Start with a distinction most users never notice, because the interface looks identical either way. On the ordinary consumer tiers of the leading chatbots — the free plans and the modestly priced personal subscriptions — the vendor uses your conversations to train and improve its models by default, unless you find and switch off the setting that stops it. Paying for a premium personal plan does not change this; it buys you more capability, not more privacy. The privacy posture only meaningfully improves when you move to a business or enterprise workspace, or use the vendor's developer platform, where inputs and outputs are excluded from training by default and, on qualifying plans, retained for zero days.

For a lawyer, that default is the whole ballgame. A duty of confidentiality that covers not just privileged communications but essentially everything relating to a representation does not sit comfortably with a tool that learns from what you type. Feeding client facts into a consumer-grade assistant that trains on its inputs, without the client's informed consent, is difficult to square with that duty. The fix is not complicated — use the enterprise or developer tier, confirm in the contract that your data is excluded from training and subject to a clear retention limit, and get informed consent where it is warranted — but it requires knowing that the distinction exists in the first place.

Every Game You Play

Even a vendor that promises not to train on your data, and to delete it on a schedule, does not fully control what happens next — because a court in someone else's lawsuit can override those promises. That is not hypothetical. In the copyright litigation between a group of news organizations and a leading AI company, a federal court in May 2025 ordered the company to preserve all of its output log data — including chats that users believed they had deleted, and including data the company's own privacy commitments would otherwise have purged. The company objected on privacy grounds and lost; the district judge affirmed the preservation order in June 2025. The dispute swept in tens of millions of conversation logs. The order was later narrowed, in September 2025, so that the company no longer had to preserve every new chat going forward, but it still had to retain everything already captured.

Sit with what that means. Users who deleted their conversations, and who relied on a stated retention policy, had that deletion frozen by a lawsuit they were not party to and had never heard of. A retention promise is only as durable as the litigation environment around the vendor. For a lawyer, the lesson is that "the vendor deletes it" is not the same as "it is gone," and a discovery obligation or preservation order aimed at your AI provider can reach the traces of your work even after you thought they were erased.

Every Smile You Fake

There is a further trap worth naming. Some users have begun to assume that an exchange with an AI tool carries something like the confidentiality of a conversation with a lawyer or a doctor. It does not. Courts confronting the question have generally treated exchanges with an AI platform as ordinary communications with a third party — not privileged, and potentially discoverable like any other record held by an outside vendor. The idea of a dedicated "AI privilege" has been floated by industry figures as a policy proposal, but it is advocacy, not law. Running privileged analysis through a consumer tool can, in the wrong circumstances, undercut the very privilege you are trying to protect, by disclosing the substance to a third party under terms that permit its use and retention.

Every Vow You Break

None of this is an argument against using AI in legal practice. It is an argument for reading the lease before you move in — a theme that runs through this series. Before client information touches any AI tool, a firm should know the answers to a short list of questions: Does the vendor train on my inputs, and under what tier does that stop? How long is my data retained, and is a zero-retention option available? Who are the vendor's subprocessors, and where does the data actually live? And what happens to my data if the vendor is subpoenaed, sued, or ordered to preserve records in a matter that has nothing to do with me?

A firm that can answer those questions can use these tools confidently and responsibly. A firm that cannot is, whether it realizes it or not, letting a third party watch and keep every word — and asking its clients to trust a promise the firm has never actually read. We took up a related question in earlier posts, on whether the AI you rely on is genuinely yours and on the risk of building a practice on someone else's platform. This is the confidentiality corner of the same concern: the tool is useful, but the terms are someone else's, and the client's secrets are yours to protect.

Can’t You See, You Belong to Me

The unsettling thing about the song is that the narrator is not malfunctioning — he is doing exactly what he set out to do, watching and recording with perfect fidelity. The AI tools work the same way. They retain, they learn, and they log precisely as designed, and the terms that govern all of it were written to serve the vendor, not your client. Using them well does not mean fearing them. It means knowing what they keep, choosing the tier and the terms that fit a lawyer's duties, and never confiding anything to a tool you have not first understood.

This post is part of an ongoing series on how AI is reshaping law-firm practice and the obligations that come with it. Earlier entries asked whether the AI you depend on is really yours and warned against building your practice on a platform someone else owns and controls.


A Word About Silver Cain
Silver Cain PLC represents businesses in complex commercial and real estate litigation in Arizona and beyond. When Rebecca Cain and I founded the firm, we built it around direct partner involvement, senior trial-level judgment, and a disciplined approach to the tools we use on our clients' behalf — including a clear-eyed understanding of how those tools handle client data. If the questions in this post are relevant to your business, or to the firms you retain, we are glad to have that conversation.

Leon Silver is an AV-rated trial lawyer at Silver Cain PLC, focused on commercial and real property disputes since 1989. Reach him at lsilver@silvercain.com.

Share the Post:

Related Posts