News

Can AI Companies Report You to the Police? What the Claude Diary Case Means for Your Chats

Police say Anthropic reported a Florida woman's Claude diary. What AI companies can see and report, and why encryption and open models matter.

AI illustration of an open diary beside a chat window, with a doorway glowing coral behind them, labeled Maple News and AI / Privacy.

Yes, AI companies can report you to the police in specific cases. Automated screening flags a conversation, a human team reviews it, and the company decides whether to refer it, a right Anthropic's consumer terms reserve at its sole discretion.1 Governments can also compel chats through legal process, and civil courts can reach them in discovery. On September 30, a Florida woman was charged with a felony after, according to her arrest report, Anthropic flagged her Claude conversations and reported them to law enforcement.2

Reporting a specific, credible threat is defensible. The harder problem is structural: a few companies can read the place where many people now think out loud, hold the only copy of the models they use, and set and revise the rules for both. Encryption decides who can read a conversation, and open-weight models decide who controls the intelligence. At Maple we offer open models without running your own hardware and a private path for using them, and the argument holds whether or not you use us.

What happened in the Florida Claude diary case

The arrest report alleges that on September 26 a user identified as "Carli" wrote that she would "shoot up" the Lee County Sheriff's Office, and that a message the next day mentioned a new gun.2 It also says Anthropic monitors chats for threatening content and that, depending on severity, flagged chats can be elevated for human review. In this case, the review team decided to report its findings to law enforcement. Anthropic has not confirmed that account and had not commented publicly on the case as of October 10.

Court records show Carli Michelle Heller of Bonita Springs was charged on September 30 under Florida Statute 836.10, which covers written or electronic threats of a mass shooting or act of terrorism.3 She has been charged, not convicted. A public defender was appointed, and her arraignment is scheduled for November 2.

Florida law makes such a threat a second-degree felony, and the statute reaches writings sent "in any manner in which it may be viewed by another person."4 Whether a private AI chat meets that language is an open legal question.

Sheriff Carmine Marceno said Heller later told investigators she used AI like a "diary." That is her account as the sheriff relayed it, not a statement from her or her lawyer. He also said users are "never truly anonymous," and he described the case this way:

By Tom's Hardware's count, Heller's case is at least the third Claude conversation to reach police since August.3 In San Antonio, an arrest affidavit reported by News 4 San Antonio says the FBI alerted police to an August 11 Anthropic AI chat about a shooting at an elementary school.5 Reports do not say how the FBI learned of that chat.

The third case, in San Francisco, comes up below. The timeline shows how closely these cases and Anthropic's policy announcement fell together.

Timeline, 2026: Aug 11, alleged school threat in a Claude chat; Aug 14, reported threat against Anthropic staff, which Anthropic referred to police; Sept 26–30, Florida entries allegedly threatening the sheriff’s office, which the arrest report says Anthropic flagged and reported to police; felony charge Sept 30; Oct 8, usage policy update announced; Nov 2, arraignment scheduled; Nov 12, new policy takes effect.
Three Claude conversations reached police within seven weeks. Anthropic announced its usage policy update eight days after the Florida charge; nothing in it connects the rule to police referrals.

How ChatGPT, Claude and Gemini read, report and hand over chats

The contractual basis for a company's own report is plainest in Anthropic's consumer terms, shown below.1

Excerpt from Anthropic’s Consumer Terms of Service, effective October 8, 2025: “We reserve the right, at our sole discretion, to report information from or about you, including but not limited to Inputs, Outputs, or Actions to law enforcement.”
Anthropic’s consumer terms reserve the right to report inputs, outputs and actions to law enforcement, at the company’s sole discretion.

That clause does not mean a person reads every chat. Classifiers screen for policy violations, and referral is a narrower step. Anthropic's privacy policy says flagged conversations can be used for safety work even if you opt out of training.6 Deleted chats leave its back end within 30 days, but flagged content and legal holds are exceptions.

Anthropic, OpenAI and Google describe their processes differently, and the public record on each is uneven:

CompanyHuman review of flagged chatsReporting on its own or in an emergencyGovernment requestsUser notice
Anthropic (Claude)1, 7Yes, according to the Florida arrest reportAt its "sole discretion" under its terms; emergency exception for imminent physical harm or deathValid legal process, such as a subpoena or warrantYes, unless legally prohibited or a rare exception applies
OpenAI (ChatGPT)8, 9Yes: chats about harming others go to a small trained teamMay refer an imminent threat of serious physical harm to others; emergency exception for danger of death or serious injuryWarrant for content; subpoena or court order for other data (US)Yes, unless prohibited by law; may be withheld in emergencies
Google (Gemini)10, 11Yes: some chats, after they are disconnected from the accountMay share information with a government agency to prevent death or serious physical harmSearch warrant for content in US criminal casesEmail before disclosure, unless legally prohibited

Three routes, three decision-makers

Company referral is one of three routes from your chat to someone else. The diagram shows all three and who decides on each.

Diagram of three paths from your chat. Company referral: automated flag, human review, referral to police, decided by the company. Government request: request with legal process or emergency exception, decided by a court, or the company in an emergency. Lawsuit: civil discovery, decided by a judge.
Each path has a different decision-maker: the company itself, a court (or the company in an emergency), or a judge in a civil case.

For government access, the Stored Communications Act sets out how a warrant or court order reaches content a provider holds.12 Civil litigants can reach logs too: in the New York Times case against OpenAI, a federal judge affirmed an order to produce 20 million de-identified ChatGPT logs.13

Sam Altman has said that the confidentiality people get with a therapist or lawyer is something "we haven't figured that out yet for when you talk to ChatGPT."14

The thresholds differ from company to company, but all three routes share one condition. The transcript exists in readable form somewhere other than your device, and someone other than you decides what happens to it.

What about real threats?

The Florida case is the hard case. As alleged, it involved a named target, a stated method and a next-day mention of a new gun. The arrest report says a human review team made the call, not a keyword alone. Most people would want someone to act on a message like that, and this piece does not argue otherwise.

The San Francisco case suggests a threshold at work. The San Francisco Standard reported that Anthropic banned and referred a user who allegedly threatened to kill people at the company, and that the user was not arrested or charged.15 The Anthropic employee who spoke with police said he was not immediately concerned about safety and declined to show them the messages. A company spokesperson described the decision this way:

Companies also face pressure from both directions. The report that counted those Claude cases described AI companies as:

The answer to the objection is that private spaces have never needed a built-in reader for dangerous people to be found. A paper notebook, a phone call and an end-to-end encrypted message have no reader by default. Investigators still find threats through conduct, tips from other people and legal process.

Reporting a credible threat once you know about it is defensible. Designing every private space so that someone is always in a position to know is a separate choice, with costs that one alarming case can hide. Most people who use a chat this way are not threatening anyone. They are thinking, and under the current design they do it in a space with a reader they never see.

AI chat rules change by announcement

On October 8, eight days after Heller was charged, Anthropic announced a usage policy update that takes effect November 12.16 The image below shows the new rule and the exclusions announced with it; the announcement also says Claude's ability to end such conversations will remain the primary enforcement mechanism.

Anthropic’s new usage rule and its exclusions. New rule, Usage Policy effective November 12, 2026: “Engage in sustained and needless abusive or cruel behavior toward our models.” Announced exclusions, October 8, 2026: “It does not apply to common versions of user frustration, pushback, dark creative themes, or model testing and research.”
The new rule takes effect November 12, 2026. Anthropic says it does not cover ordinary frustration, pushback, dark creative themes or model testing.

This is not a ban on swearing at a chatbot. The policy's general clause still lets Anthropic warn users or throttle, limit, suspend or terminate access, but the company has disclosed no penalty specific to this rule.17 Nothing in either document connects the rule to police referrals.

The same update added surveillance rules, including that Claude "cannot be used to decide or recommend who to investigate, arrest, or charge."16 Those rules cover what customers may do with Claude. They do not say when Anthropic itself reports a user.

The rule is narrow. Its history says more about how these rules come to exist. In August 2025, Anthropic gave Claude the ability to end some conversations, a feature it said was developed "primarily as part of our exploratory work on potential AI welfare."18

The 2026 announcement does not repeat that rationale.16 It says only that the new prohibition "aligns with a step we've already taken," so a product behavior became a written usage rule. Enforcing any usage rule depends on detection, and the policy itself says Anthropic's Safeguards Team "implements detection and monitoring to enforce our Usage Policy."17

Thresholds already vary across a single company's documents. The privacy policy allows disclosure to prevent serious harm to a person "or to property."6 The transparency report defines an emergency disclosure as one involving "danger of death or serious physical injury to a person."19

Platform rules have followed a familiar path before. Social networks began with rules nearly everyone accepted and widened them over the years under legal, political, advertiser and public pressure, with each step looking reasonable at the time. AI chats raise the stakes. A post is something you chose to publish, while a chat is often where you work out what you think before you say it to anyone.

None of this predicts a particular future rule. The point is about structure. The company that can read the space writes its rules, revises them by announcement and answers to outside pressure. That pressure mostly argues for reading more, and little in the design pushes the other way.

Why this is a freedom-of-thought problem

A chat with an AI often works as a drafting space, not a publication. People use it to work through a diagnosis, rehearse a hard conversation, test a political idea they're unsure of, or put an ugly feeling into words to see what it looks like. If you handle that kind of material professionally, our guide to using AI safely in a therapy practice covers where AI fits and where it doesn't.

Thinking in drafts depends on the draft having no audience. We grant that to diaries and to encrypted messages. We accept that someone could write something alarming there and no one would know, because the alternative is a reader attached to every private thought.

The people who write AI usage policies may be careful and well-intentioned, and nothing here questions their motives. The concern is concentration: when private thinking runs through a few services that can read it, their terms start to act as rules for thought, written by a small number of companies and revised on their schedule.

Open-weight models: the second safeguard

Encryption settles who can read a conversation, but it does not settle who controls the model. With a closed model, one company holds the weights, sets the model's behavior for every user, decides the terms of access and can end your account. No one else can offer you that same model.

Open-weight models change that. Once the trained weights are published, no single company can withdraw a released model or rewrite it for everyone. The model is portable, which gives you sovereignty over the intelligence you rely on: you can run it yourself, choose among hosts, and leave a host whose rules you reject. We made a related case for businesses in The End of Rented Intelligence.

The comparison below sets the two arrangements side by side.

Comparison of a closed AI service with an open-weight model, end-to-end encrypted. Who can read your conversation? The company; no one but you. Who sets and changes the rules? The company; fixed in the released weights, you choose the host (the model’s trained-in behavior still comes from its maker). Can you take the model elsewhere? No; yes.
Encryption decides who can read a conversation; open weights decide who controls the model. Its trained-in behavior still comes from its maker.

Open weights have real limits. A model keeps the refusals and values its maker trained into it. Anyone hosting an open model can add filters of their own, or read your chats unless the service is built to prevent that.

Running a large model yourself also takes serious, expensive hardware, so most people end up with hosted access. That brings the privacy question straight back, which is why open weights need encryption alongside them.

Where Maple fits: open models and a private path

We offer both safeguards, and neither one is the whole point on its own. On the model side, we offer open-weight families including GLM (Z.ai), Kimi (Moonshot AI), DeepSeek, gpt-oss (OpenAI), Gemma (Google) and Llama (Meta). That lets you use capable open models without building a GPU server. Capability varies by model and task, and the current lineup is in our model library.

Our code is open source with reproducible builds. The live attestation on our proof page lets anyone check that the running code matches the published build. We don't use your data for model training, advertising or tracking. Our one-year retrospective explains how this came together.

We do have rules. Our terms prohibit illegal or harmful use and allow us to suspend accounts that violate them. We also hold account basics such as your email and payment details, as our privacy policy describes.

We have no information about your conversations. None. There is nothing for us to review, flag or hand over.

A three-question test before you use AI as a diary

Before you treat any AI chat as a diary, ask the three questions the comparison above turns on:

  1. Who can read this conversation?
  2. Who decides what happens if they do?
  3. Can I take this model somewhere else if the rules change?

If the answers are "the company," "the company" and "no," treat the chat as a space with a reader and write accordingly. That service may still be the right tool for a lot of work, for reasons of capability, convenience, price or an existing workflow. It is not a diary.

Sources

  1. Anthropic, Consumer Terms of Service, October 8, 2025. Effective date; the reporting clause at the company's sole discretion.
  2. WINK News, Woman arrested after AI threat against Lee County Sheriff's Office investigators, September 30, 2026. The arrest report's allegations and review process, and the sheriff's statements.
  3. Tom's Hardware, Anthropic reports Florida woman's Claude diary threat to shoot up sheriff's office; felony charge follows, October 5, 2026. Docket check, arraignment date and the count of at least three cases.
  4. Florida Legislature, Florida Statutes § 836.10: Written or electronic threats, 2026. Statute text and felony degree.
  5. News 4 San Antonio, Man arrested after using AI to threaten elementary school, arrest affidavit says, August 2026. The FBI alert to police described in the affidavit.
  6. Anthropic, Privacy Policy, September 10, 2026. Effective date; disclosure to prevent harm, flagged chats after a training opt-out, and 30-day deletion.
  7. Anthropic, What is Anthropic's policy for handling governmental requests for user information?, March 16, 2026. Legal process, the emergency exception and user notice.
  8. Futurism, OpenAI says it's scanning users' conversations and reporting content to police, August 27, 2025. Quotes OpenAI's August 2025 description of review and referral.
  9. OpenAI, Law Enforcement Policy, v2025.12, December 2025. Legal process by data type, the emergency exception and user notice.
  10. Google, Gemini Apps Privacy Hub, June 29, 2026. Human review, account disconnection, three-year retention and the confidentiality warning.
  11. Google, How Google handles government requests for user information, accessed October 9, 2026. Warrants for content, emergency disclosure and user notice.
  12. United States Code, 18 U.S.C. § 2703: Required disclosure of customer communications or records, current text. How legal process reaches content held by providers.
  13. Bloomberg Law, OpenAI must turn over 20 million ChatGPT logs, judge affirms, January 2026. The affirmed production order in the New York Times case.
  14. TechCrunch, Sam Altman warns there's no legal confidentiality when using ChatGPT as a therapist, July 25, 2025. Altman's statement on confidentiality.
  15. San Francisco Standard, Anthropic called SFPD over threat against CEO. Claude user says it was a misunderstanding, September 4, 2026. The referral, the spokesperson's statement and the outcome.
  16. Anthropic, 2026 usage policy update, October 8, 2026. The new rule's scope, exclusions and primary enforcement.
  17. Anthropic, Usage Policy, November 12, 2026. Effective date; rule text, general enforcement clause, and detection and monitoring.
  18. Anthropic, Claude Opus 4 and 4.1 can now end a rare subset of conversations, August 15, 2025. The original AI-welfare framing of conversation-ending.
  19. Anthropic, Transparency report, July–December 2025, covering July–December 2025. The definition of an emergency disclosure.

Frequently Asked Questions

Can ChatGPT report you to the police?

Yes, in limited cases. In August 2025, OpenAI said conversations about planning to harm others go to a small trained review team, and that it may refer a case to law enforcement if reviewers find an imminent threat of serious physical harm to others. It also said it was not referring self-harm cases at that time. Separately, ChatGPT logs can be reached through legal process, as the New York Times copyright case showed.

Can your AI chats be used against you in court?

Chats that a provider holds can be reached through legal process. Governments can seek chat content from a provider with a warrant or other valid process, and civil litigants can seek logs in discovery. In January 2026, a federal judge affirmed an order requiring OpenAI to produce 20 million de-identified ChatGPT logs in the New York Times case, under a protective order. Sam Altman has said the confidentiality people have with a therapist or lawyer has not been worked out for ChatGPT.

Does Claude share your data with the government?

Anthropic says it discloses user information in response to government requests only with valid legal process, such as a subpoena or warrant. The exception is an emergency that may result in imminent physical harm or death. It says users get notice unless it is legally prohibited or a rare exception applies. Separately, its consumer terms let it report information to law enforcement on its own initiative, at its sole discretion.

What happens if Claude flags your chat?

The Florida arrest report says Anthropic monitors chats for threatening content and that, depending on severity, flagged chats can be elevated for human review. Anthropic has not confirmed that description. Its privacy policy says flagged conversations can be used for safety work even if you opted out of training, and flagged content is an exception to the 30-day removal of deleted chats. Under a separate rule taking effect November 12, 2026, Claude ending the conversation is the primary enforcement for sustained, needless abuse of the model.

Which AI has the most privacy?

No single answer fits everyone, and capability, price and convenience matter too. Ask three questions: who can read your conversations, who decides what happens if they do, and whether you can move the model elsewhere. A service built so the provider has no access to your conversations, with a way to check the code it runs, and that offers open-weight models answers all three better than most. Maple is built that way, though we still hold account basics such as email and payment details and enforce our terms.