23 days 6 hrs 6 min
Annual Conference 2027 — Registration now open — Early Bird pricing ends November 2— Register today to save

The Envelope and the Letter: Anonymous AI Chat and the Practice of Law

By Alexander Paykin

October 9, 2026

The Envelope and the Letter: Anonymous AI Chat and the Practice of Law

10.9.2026

By Alexander Paykin

A chat interface showing an exchange between a robot avatar and a person, with the robot asking how to assist and the person asking for help.Every lawyer I know has developed the same nervous habit. We type a question into an AI chatbot, pause with the cursor hovering over the enter key, and ask ourselves questions the terms of service do not always answer clearly: Where does this go? Who keeps it?  For how long?

For a while, that anxiety was easy to dismiss as paranoia. Then, in the summer of 2025, OpenAI’s chief executive said the quiet part out loud during – of all things – a comedy podcast. Sam Altman observed that people tell ChatGPT the most personal things in their lives, young people in particular use it as a therapist and life coach; and unlike conversations with an actual therapist, doctor or lawyer, those exchanges carry no legal privilege. If there is a lawsuit, he explained, OpenAI could be required to produce them, a state of affairs he described with admirable candor as “very screwed up.”[1]

Banner for the New York State Bar Association Annual Conference. Registration is open for January 19-22, 2022, at New York Hilton Midtown. Includes a Register Today button and a 150 years anniversary logo.Two months earlier, a federal magistrate judge in the Southern District of New York had directed OpenAI to preserve and segregate, going forward, output log data that otherwise would have been deleted, whether at a user’s request or under a privacy law, as part of discovery in The New York Times copyright litigation.[2] The general prospective preservation duty ended as of Sept. 26, 2025, but portions of the data retained between April and September remained preserved, and narrower preservation continued for specified domains.[3] OpenAI also stated that ChatGPT Enterprise was excluded after a court clarification and that zero data retention API endpoints were not affected because prompts and responses were not retained in the first place.[4]

Those distinctions matter: Product architecture, retention settings and contract terms determine what exists to preserve and produce, and tell lawyers which questions to ask.

Against this backdrop, a category of AI service has emerged promising something the mainstream products do not: anonymity. The most prominent example is Duck.ai, offered by DuckDuckGo, the search company whose brand is built on not tracking users. This article examines that service as a case study in the anonymous AI architecture, not as an endorsement of it, because the same engineering choices that make the design interesting for consumers create a series of distinct problems for legal practice, several of which have nothing to do with confidentiality at all.

How the Architecture Works

Duck.ai is, at bottom, a privacy-preserving middleman. Its free version requires no account or login and provides access to third-party models from companies including OpenAI, Anthropic and Mistral, as well as open models. Paid subscriptions add more advanced models. The exact lineup changes, so any description is necessarily time-stamped.[5]

When a user submits a prompt, DuckDuckGo removes metadata containing personal information, including the user’s IP address, before forwarding the request from its own servers. The model provider therefore sees a request from DuckDuckGo rather than a direct request from the individual user. By default, DuckDuckGo says it does not record or store chats, and neither DuckDuckGo nor the model providers use them for model training. Recent chat history is ordinarily stored locally on the user’s device. If the user enables sync & backup, the history is stored on DuckDuckGo’s servers in end-to-end encrypted form that DuckDuckGo says it cannot decrypt.[6]

The retention language requires care. The governing privacy policy says provider agreements require deletion once information is no longer needed to provide an output, with a ceiling of 30 days and limited safety and legal-compliance exceptions. Current help documentation goes further: Providers must delete prompts and responses immediately after each reply, an arrangement DuckDuckGo calls zero data retention, subject to documented exceptions including screening of uploaded images and files for child sexual abuse material by a third-party moderation provider and, in some cases, the model provider.[7]

For the especially cautious, certain models run inside a trusted execution environment. DuckDuckGo says that this design prevents the hosting company from seeing, retaining, sharing or training on the prompts and responses, and labels these “zero provider visibility” models.[8]

All these claims are DuckDuckGo’s own descriptions of its system, and every company’s description of itself is, in part, marketing. But the design choices are documented, and they frame the analysis that follows.

What Anonymity Addresses, and What It Does Not

Think of the architecture as mailing a letter without a return address through a forwarding service. The recipient still reads the letter and answers it but ordinarily cannot connect it to the sender’s address or account, and the forwarding service says it keeps no copy. For a consumer, that reduces identity-linked collection: less of a dossier to monetize, breach or subpoena. But the metaphor has limits even on its own terms. The letter itself may name the sender or another person, a local history may remain on the device, an encrypted copy may exist through the optional sync, subscription records may exist for a paid user and provider-side processing and the disclosed exceptions still occur. Reduced collection is not the disappearance of every record, and it does not prevent the contents of a prompt from identifying the people discussed in it.

Anonymity Is Not Confidentiality

In light of this, should lawyers move their practices over to Duck.ai and sleep soundly? No. The first and most fundamental problem is that this architecture anonymizes the envelope, not the letter.

Suppose I type the following into an anonymous chatbot: My client John Smith, the commercial tenant at 123 Main Street, is being sued by his landlord, and here is his lease. DuckDuckGo may conceal the fact that Alexander Paykin submitted the prompt. It does nothing to remove John Smith’s name, address, legal problem or lease from the prompt itself. Those words must still be processed by a model, and the provider’s disclosed retention exceptions may still apply. Metadata scrubbing does not reach inside the sentences. Our professional obligations attach to the information itself, not merely to whether the disclosure can be traced back to the lawyer.

There is also a threshold contractual problem that the privacy pages do not answer in the lawyer’s favor. Duck.ai’s terms of service, updated June 16, prohibit use “[i]n a regulated area, including providing legal, financial, or medical advice or services.” The same terms warn that outputs may be unreliable and should be verified, especially when used for professional advice.[9] Whatever line ethics rules might otherwise permit, these terms present a contractual obstacle to ordinary law practice use unless DuckDuckGo changes or authoritatively clarifies the restriction.

Rule 1.6(a) of the New York Rules of Professional Conduct prohibits a lawyer from knowingly revealing confidential information unless the client gives informed consent, the disclosure is impliedly authorized to advance the client’s interests and is reasonable or customary, or an enumerated exception applies. Rule 1.6(c) separately requires reasonable efforts to prevent unauthorized disclosure, use or access.[10] Comment 8 to Rule 1.1, although guidance rather than a disciplinary rule itself, reminds lawyers to keep abreast of the benefits and risks associated with technology used to provide services or store or transmit confidential information.[11]

ABA Formal Opinion 512 applies a fact-specific inquiry. Before entering information relating to a representation, a lawyer should evaluate the sensitivity of the information, the tool’s terms and privacy policies, the risk of disclosure and whether client consent is required. It does not impose a categorical rule that every use requires consent and recognizes that idea generation without client information ordinarily does not.[12] NYSBA’s 2024 Task Force on Artificial Intelligence report likewise counsels caution, including obtaining assurances about protection and segregation of client information and monitoring changes in provider policies.[13] None of this guidance contains an exception merely because the provider does not know which lawyer submitted the information. A client secret disclosed anonymously is still a client secret disclosed.

Privilege: An Early Answer From the Courts

There is also the separate question of privilege. New York generally treats voluntary disclosure of a privileged communication to a third party as inconsistent with confidentiality, subject to exceptions for agents or others whose participation is necessary to the attorney-client relationship.[14] The analysis is already moving beyond the hypothetical. In United States v. Heppner, a Southern District Court of New York court held in February that a criminal defendant’s consumer Claude exchanges were not attorney-client privileged or protected work product. The court further concluded that, to the extent the prompts incorporated privileged attorney communications, the defendant waived privilege by sharing them with Anthropic under the applicable consumer terms.[15]

Heppner does not decide every lawyer-operated system. The defendant independently used a consumer chatbot, counsel had not directed the use, and the governing terms permitted provider access and use. A court could analyze differently a tool acting as counsel’s confidential agent under appropriately restrictive technical and contractual safeguards. But anonymity alone did not preserve privilege in Heppner, and lawyers should not assume it will do so elsewhere.

The Recordkeeping Problem: Ephemerality Cuts Both Ways

Now consider a set of drawbacks that has nothing to do with disclosure and everything to do with the records a lawyer is required to keep. Our obligations run in two directions. Rule 1.6 restricts what leaves the office; a separate body of duties governs what must remain in it. Lawyers must maintain the client’s file and surrender it on request. They must preserve documents and work product when litigation is pending or reasonably anticipated and must be able to reconstruct what was done on a matter when a client, a court, an adversary serving discovery or a grievance committee asks. Contemporaneous records are also the lawyer’s own first line of defense when work is later questioned.

A service deliberately engineered so that no server-side record exists, and whose providers delete prompts and responses after each reply, is engineered against those duties. If substantive work is performed in such a tool, the only record is whatever the lawyer happens to capture manually from a local device before a browser or sync policy erases it. Nothing can be retrieved from the provider later because, if the system works as described, nothing is there. That is an attractive property when a third party comes looking; it is a serious defect when the lawyer is the one under the preservation obligation. A lawyer subject to a litigation hold cannot outsource forgetting. And as courts pay increasing attention to how lawyers use AI, a tool that retains nothing leaves counsel unable to demonstrate after the fact what was asked, what was generated and what was independently verified.

The Continuity Problem: A Practice Needs a File

Legal work is longitudinal. A matter unfolds over months or years, across devices and usually across people. The anonymous architecture is built for the opposite: Chat history lives locally on a single device by default. DuckDuckGo’s own policy notes that some browsers automatically delete locally saved chats after a period of inactivity, and chats stored through the optional encrypted sync are deleted if not accessed for 18 months.[16] There is no matter-based organization, no shared workspace, no way for an associate to hand a research thread to a partner and no way for a supervising attorney to review what was asked and answered. Even the model lineup changes over time, so the model that helped analyze a contract may not exist when the dispute over it ripens. None of this is a flaw in the engineering; it is the engineering. A system built to remember nothing about its users cannot double as the institutional memory of a law practice.

Governance, Supervision and the HIPAA Analogy

The underlying design tension is that consumer anonymity and professional accountability solve different problems. Consumer anonymity tries to prevent a provider from connecting content to a person. Professional practice also demands governance: defined responsibilities, technical controls, supervision, enforceable commitments and evidence of what safeguards applied.

HIPAA illustrates the accountability side, although the analogy must be stated carefully. When a covered entity allows a business associate to create, receive, maintain or transmit protected health information on its behalf, the covered entity generally must obtain required assurances documented in a written contract or other written arrangement satisfying the regulations. Not every physician is a covered entity, not every vendor is a business associate and not every disclosure requires an agreement.[17] The point is narrower: regulated professionals often need documented, role-specific commitments in addition to privacy-friendly engineering, and there is no way to sign a business associate agreement with a service that does not know who you are.

An anonymous service can still enter into enforceable online terms; Duck.ai itself relies on contracts with users and model providers. The problem is not structural impossibility. The problem is that a consumer-facing service does not give a law firm the negotiated commitments, administrative controls, audit information, breach obligations, retention options and organizational accountability the firm needs.

The problem compounds inside a firm. Rules 5.1 and 5.3 impose managerial and supervisory duties concerning lawyers and nonlawyers, with personal responsibility arising in the circumstances specified by those rules.[18] A managing lawyer therefore needs policies, training, approved systems and a practical way to enforce the line; an anonymous tool by design offers no usage logs to enforce it with.

Nor does the word “enterprise” end the analysis in the other direction. Enterprise does not automatically mean zero retention, no training, no human access or preservation of privilege; lawyers should examine the actual terms, configuration, security documentation, retention controls, subprocessors, incident-notification obligations, administrative features and the client’s instructions. The OpenAI preservation orders illustrate the practical point without proving an ethical one: Different products generated different bodies of retained data, and that affected the discovery result, but no category of tool was thereby declared safe for client information. Contracts and engineering are complements, not substitutes.

The Intern Without a File Cabinet

I have written before that lawyers should treat AI as a capable but unlicensed intern whose work the signing attorney always owns and reviews. The anonymous architecture requires two corollaries: an intern who never signed a confidentiality agreement, who works at a table in a crowded coffee shop and who shreds his notes at the end of every day. The coffee shop is the confidentiality problem. The shredder is the recordkeeping problem and it may be the more insidious of the two because it produces no dramatic disclosure, only an empty drawer where the file should be.

A general question about the elements of constructive eviction, a request to explain a CPLR provision or a paragraph of boilerplate containing no client information may present little or no Rule 1.6 risk. But the Duck.ai’s terms’ prohibition on legal advice or services presents a contractual obstacle to law practice use of this particular product, the absence of any durable record presents a practice-management obstacle, and no general-purpose chatbot should be treated as an authoritative legal research database in any event; its propositions and citations must be checked against primary sources.

In my own practice, the line is drawn accordingly. Tools that touch matter content operate under vetted business agreements and configurations with retention and use commitments I can identify and, just as important, with records I control. Anonymous tools are confined to anonymous personal questions, where neither confidentiality nor the file is implicated.

The takeaway is not that anonymous AI services are badly engineered; the architecture appears to do what its designer says it does. The takeaway is also not that anonymity is irrelevant to Rule 1.6; reducing collection and attribution can form part of a reasonable-efforts analysis. The point is narrower and, for practitioners, more important. Anonymity, confidentiality, privilege, preservation and continuity are five different protections, and this architecture supplies only the first. It empties the envelope but does nothing for the letter, and it dissolves the file the letter belongs in. Before a lawyer hits enter, the right questions are whether the information may be sent at all, what terms govern it, what record will exist afterward and what the lawyer will be able to demonstrate about all of it later.


Alexander Paykin is the managing director of The Law Office of Alexander Paykin, P.C., a New York litigation and complex transactions firm, and serves as chair of the New York State Bar Association’s Committee on Technology and the Legal Profession.

Endnotes:

[1] This Past Weekend w/ Theo Von, Episode 599: Sam Altman at 32:34-33:18 (July 23, 2025), youtube.com/watch?reload=9&v=aYn8VKW6vXA).

[2] Order, The New York Times Co. v. Microsoft Corp., No. 1:23-cv-11195, Dkt. 551 (S.D.N.Y. May 13, 2025), https://cases.justia.com/federal/district-courts/new-york/nysdce/1%3A2023cv11195/612697/551/0.pdf.

[3] Order, The New York Times Co. v. Microsoft Corp., No. 1:23-cv-11195, Dkt. 922 (S.D.N.Y. Oct. 9, 2025), https://cdn.arstechnica.net/wp-content/uploads/2025/10/NYT-v-OPenAI-Order-to-Terminate-OpenAIs-Preservation-Order-10-9-25.pdf.

[4] How We’re Responding to The New York Times’ Data Demands in Order to Protect User Privacy, OpenAI, https://openai.com/index/response-to-nyt-data-demands/ (last visited July 24, 2026).

[5] What AI Chat Models Are Available?, DuckDuckGo, https://duckduckgo.com/duckduckgo-help-pages/duckai/chat-models (last visited July 24, 2026).

[6] Duck.ai Privacy Policy and Terms of Service, DuckDuckGo, https://duckduckgo.com/duckai/privacy-terms; How Does Duck.ai Protect My Privacy?, DuckDuckGo, https://duckduckgo.com/duckduckgo-help-pages/duckai/ai-chat-privacy (last visited July 24, 2026).

[7] Id.

[8] Id.

[9], Duck.ai Privacy Policy and Terms of Service, DuckDuckGo, https://duckduckgo.com/duckai/privacy-terms (last updated June 16, 2026).

[10] N.Y. Rules of Prof’l Conduct r. 1.6(a), (c), 22 N.Y.C.R.R. § 1200.0, https://www.nycourts.gov/ad3/agc/rules/22NYCRR-Part-1200.pdf.

[11] N.Y. Rules of Prof’l Conduct r. 1.1 cmt. 8, https://www.nycourts.gov/ad3/agc/rules/22NYCRR-Part-1200.pdf.

[12] ABA Comm. on Ethics & Prof’l Resp., Formal Op. 512, Generative Artificial Intelligence Tools 5-7 (July 29, 2024), https://www.americanbar.org/content/dam/aba/administrative/professional_responsibility/ethics-opinions/aba-formal-opinion-512.pdf.

[13] N.Y. State Bar Ass’n, Report and Recommendations of the New York State Bar Association Task Force on Artificial Intelligence, at 57-60 (Apr. 2024), https://nysba.org/wp-content/uploads/2022/03/2024-April-Report-and-Recommendations-of-the-Task-Force-on-Artificial-Intelligence.pdf.

[14] Ambac Assurance Corp. v. Countrywide Home Loans, Inc., 27 N.Y.3d 616, 624 (2016), https://nycourts.gov/reporter/3dseries/2016/2016_04439.htm.

[15] United States v. Heppner, 820 F. Supp. 3d. 292 (S.D.N.Y. 2026), https://www.mindingyourbusinesslitigation.com/wp-content/uploads/sites/53/2026/02/Bench_Ruling_on_AI_and_Privilege_1771361150.pdf.

[16] Duck.ai Privacy Policy and Terms of Service, DuckDuckGo, supra note 6.

[17] 45 C.F.R. §§ 164.502(e)(1)–(2), 164.504(e), https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.502; https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.504.

[18] N.Y. Rules of Prof’l Conduct rr. 5.1, 5.3, 22 N.Y.C.R.R. § 1200.0, https://www.nycourts.gov/ad3/agc/rules/22NYCRR-Part-1200.pdf.

Related Articles

Six diverse people sitting holding signs
gradient circle (purple) gradient circle (green)

Join NYSBA

My NYSBA Account

My NYSBA Account