Your client's AI chats are not private
In February, a federal court in the Southern District of New York ruled in United States v. Heppner that chat logs between an alleged fraud defendant and a consumer AI chatbot were neither privileged nor work product. The defendant had used the free version of the tool in the weeks before his hearing; the court held that use of a "publicly available" AI tool meant the material had been shared with a third party, and privilege had dissolved. It is the first US federal opinion on attorney–client privilege and generative AI, and it will probably be the leading American case on the subject for some years.
The Indian legal press has covered the facts of Heppner well enough. What's mostly been missing is the software side of the argument, which is actually where the whole thing turns.
The legal side — section 132 of the Bharatiya Sakshya Adhiniyam, the October 2025 Summoning Advocates reference ((2025) INSC 1275), the ABA's Formal Opinion 512 — is an afternoon's reading for any advocate. The software side is harder to pick up from the outside, and that's what I want to unpack here.
We build an AI research tool for the Indian bar, and I'll come back to it at the end.
On Rakoff's use of the word "public"
The word the ruling hangs on is "public", and most readers would take it the wrong way.
When a lawyer hears "public", she thinks of something posted, indexed, put out in the open. That's not what Judge Rakoff was saying. He was using "public" in an operational sense — a tool you sign up for under a standard consumer terms-of-service, where the operator reads what you type, uses it to improve the service, and hands it over if the government asks. Heppner's chats were never on the open web. What made them "public" was the contract he clicked through to use the tool.
Here's the part that tends to get missed. The same AI model can be reached under two completely different contracts. A person typing into claude.ai (what you and I see when we go to claude.ai on the web) is on one; a business calling the Anthropic commercial API under an enterprise agreement is on another. Consumer terms let Anthropic train its models on what you type, keep your data around for a range of operational purposes, and make no promise of confidentiality. Enterprise terms do the opposite — no training, short retention just for abuse monitoring, and contractual commitments that flow down to the business customer.
Heppner was on the consumer tier, with no lawyer in the loop and no commercial contract behind him. So Rakoff wasn't ruling on commercial-API use by a law firm, and he wasn't ruling on the Kovel scenario either — the old US rule that lets a lawyer bring in a third-party professional under her own direction and the client's consent. Those doors were left open, and the serious American commentary has picked it up. Most of the Indian headlines haven't.
The "public" in this ruling is a contractual word, not a visibility word — and that single point is going to do more work in the privilege-and-AI cases of the next few years than anything else in the opinion.
The same underlying AI model can be reached under two entirely different contracts. Which one governs a client's use is what the Heppner ruling actually turned on.
The vendor question isn't new
When you use Microsoft Word to type out a memo or an opinion, your computer sends telemetry data back to Microsoft — version, usage time, features, and if you save to OneDrive, a snapshot of the file itself. And it doesn't stop there. The ISP and the email provider are getting their own snapshots of the content, the addresses on both ends, and everything in between. Each of those companies is operating under terms you accepted at some point, each with its own rules about what it keeps and for how long.
Privilege survives all of this because section 132 BSA is what governs privilege, not whatever the operating system is doing in the background. Indian advocates have been practising with privilege intact while their software, their email, their cloud storage, and their operating systems have been shipping information to various vendors for close to twenty years. What AI changes is that the vendor is now visibly reading the content, where before it was just passively moving it around.
So, from a strictly legal point of view, if you as an advocate have been using software for your work, the software makers can see what you are doing, if they want to. But you do not lose the attorney-client privilege. Similarly with AI tools — the enterprise version preserves the client's privacy while the free-to-use or web version does not.
Software is assembled from components
The other thing that gets in the way of clear thinking about AI is the idea that an AI tool is one thing made by one company. It isn't, and it hasn't been for years. Modern software is put together the same way a modern car is put together, and the analogy holds up better than you'd expect.
Think about what goes into a Tata Nexon. The engine is designed in one country, sometimes under licence from another. The steel comes from somewhere else, and so do the tyres, the electronics, and the interior fittings — all from wherever the latest tenders landed, to be put together in an Indian factory in Pune or Chennai or Sanand and shipped under Tata's name.
The Nexon is an Indian car, and nobody thinks about it any other way. When you buy one, the question that matters isn't where every bolt came from. It's who the manufacturer is, what warranty you have, who regulates them, and who you call when something goes wrong.
Software works the same way. Miss Lucy — the example I can actually describe in any detail, because we've spent two years on it — uses Anthropic's Claude Sonnet as its main research agent, Anthropic's Claude Haiku for document intake, Moonshot's Kimi (a Chinese-built model) for sorting work into matters, OpenAI's embedding model for semantic search, and Google's Gemini for reading scanned documents. Five models, four providers, two countries, each one picked because it's the best part for its specific job.
But the tool itself — the orchestration, the prompts, the contracts with each provider, the privacy policy, the grievance machinery, the DPDP work, the accountability posture — all of that is Miss Lucy, built in Bangalore and operated by an Indian LLP.
So when an advocate is sizing up an AI tool, the right questions to ask aren't "does this use Claude?" or "does this touch OpenAI?". Those are questions about components, and the answer doesn't tell you who you can hold responsible. Instead check what contract you signed with the company that gave you the custom-built tool.
What Heppner actually gives us
If you read the ruling carefully — looking at what Rakoff said was missing rather than what was there — you end up with a short checklist of six things a legal AI tool needs if privilege is going to hold up.
One. The tool has to be on a commercial contract, so the agreement runs vendor-to-business and not vendor-to-individual.
Two. That contract has to promise, in writing, that the vendor won't train on your content — a contractual commitment, not a best-effort aspiration.
Three. There has to be a proper data-processing agreement between the tool's operator and each AI provider behind it.
Four. The operator has to sit in a legal system you can actually hold accountable, so that "who do I go after if this goes wrong" has a local answer.
Five. Each advocate's material has to be walled off from every other advocate's.
Six. There has to be a defined process for deletion, for grievances, and for responding to regulators.
Six conditions a legal AI tool has to meet before an advocate can rely on it for protected work — read out of what Rakoff said was missing from the consumer-tier use in Heppner.
None of this will be news to anyone who read the ABA's Formal Opinion 512 from July 2024. What's new is a court ruling that takes all of it and turns it from professional guidance into judicial reasoning. For advocates using tools built against that list, Heppner is clarifying rather than threatening — it just formalises the question their tool was already answering.
Before Heppner, nobody really knew where AI and privilege stood, so some advocates pasted client material into free chatbots because no court had told them not to, while others stayed away from AI altogether on the basis that "there are no rules yet" is a perfectly good reason to sit something out. Heppner changes that by laying out what careful AI use actually looks like — which tier, which contract, which jurisdiction, which accountability, which walls, which deletion — and an advocate can check all of it without needing a computer-science degree.
Advocates who were already staying away from AI will now point at Heppner as their reason, but most of them weren't staying away on privilege grounds to begin with — they were staying away because they've never really used a computer beyond email, where typing is still what the clerk does and annotating a PDF feels like a stretch in 2026. Every decade brings a new technology and a real concern about it, and there is always a group of advocates who take that concern as a reason to stay where they are: fax did it in the 1990s, email did it in the early 2000s, cloud storage did it through most of the last decade, and Heppner will get used the same way.
The vocabulary you need to think about AI and privilege isn't specialist. "Public" in this context means used under consumer terms that let the vendor train on it and hand it over when asked, and it does not mean visible to the world. The same underlying AI model can be reached under a consumer contract or a commercial one, and the legal posture is completely different between the two. And every piece of software on a modern lawyer's desk has been sending information to some vendor or other for close to twenty years now; AI just makes it harder to ignore.
Miss Lucy was built against the list Heppner has now formalised. Every AI provider we work with is on a business contract rather than the consumer version of the same service, and each of those contracts — negotiated with the provider individually — commits them not to use what you type to improve their AI and to hold it only for as long as they need to catch misuse, which is usually a few days before they delete their copy. One advocate's work is walled off from another's, so one matter never bleeds into another, and the private memory Miss Lucy builds up for you — the things she notices about how you like your drafts structured, the cases you have worked on, the phrases you reach for — doesn't show up on anybody else's screen.
Within your own account, your work is organised by matter in the same way you already organise your practice, so a session you run on an arbitration sits under that arbitration and nothing from it touches the family-law consultation you ran the same afternoon. This isn't just a technical convenience — it is what lets you answer, months later, exactly what Miss Lucy did on a given file for a given client on a given day. Every step of the reasoning behind a response is shown to you before you decide to use any of it, and the full record of each session sits in your account as a retrievable log of what was asked, what was consulted, and what was produced, under your control and available only to you. Nothing leaves without your say-so, and when you ask for a session or a matter to be deleted, it is deleted — the working copy first, then the backups, then whatever the providers still have on their end — all within a window the policy commits to in writing.
All of this sits with Banyan Tree Teaching Solutions LLP, the Indian LLP that operates Miss Lucy, which is the operator itself rather than a local reseller for somebody else's product. If you have a grievance, it goes to a named officer at the LLP whose name and contact details are published on the website along with the window in which you can expect a response, so you don't get routed to a support queue in another country.
The LLP is already answerable under Indian law for everything it holds on your behalf, and from around November 2026, when the Digital Personal Data Protection Act, 2023 comes into full effect, that answerability will run specifically as a data fiduciary under the new Act. We have already built the machinery the Act asks for — the consent records it requires us to maintain, a procedure for responding to rights-requests from the advocates whose data we hold, a defined path for notifying the regulator and affected advocates in the event of a breach, and published retention schedules that tell us when data has to be discarded. So when the Act commences, it will formalise what Miss Lucy is already doing rather than force us into a last-minute change.
Whether that is a reason to use Miss Lucy is your call, and the point of this post isn't that you should land on one answer or another. What has changed is that you now have a list to check against.
If you're an advocate in India thinking about whether AI belongs in your practice, and about how to choose a tool that respects the professional responsibilities you already carry, I'd like to meet you. Request access at miss-lucy.in.
Ready to lead the Generation Leap?
Join the charter partners using Miss Lucy to transform Indian legal research.
Request Early Access