
Opting out of training doesn't hide your chat from a reviewer. What can a human at Anthropic see in Claude, and when does a conversation go to the police?
Does Anthropic read your Claude chats? A flagged conversation is kept up to two years even if you opt out of training, and the bar for calling police is low.
In this article6
Anthropic can read your Claude chat and hand it to the police, and its privacy policy dated September 10, 2026 says so directly: disclosure is allowed when the company believes in good faith that it is reasonably necessary to prevent serious harm to a person or to property. The path looks like this: automated systems flag a conversation, serious cases go to a team of human reviewers, and a reviewer decides whether to call the police. That is what happened on September 26 with a Florida woman who wrote that she would "shoot up" the sheriff's office: on September 30 she was charged under statute 836.10. A flagged chat is kept for up to 2 years and classifier scores for up to 7, and opting out of training doesn't change that. Deleting a normal chat removes it from the servers within 30 days; a flagged one stays. How often Anthropic has called the police on its own is not public: the company's report only counts incoming government requests.
Opting out of training in Claude switches off one thing, not everything. It stops Anthropic from training models on your conversations. It does not stop automated systems from scanning a conversation, a human from reading it, or the company from keeping it for two years if it gets flagged. All of this is written in Anthropic's privacy policy and its data retention help article.
The reason to open those documents came from Florida. A woman who, by her own account, used Claude as a diary wrote a threat in it, and an Anthropic employee read that entry. Below we go through the primary sources: what happens to a message you send to Claude, which settings affect what, and what the public documents leave out.
What happened in Florida and how we know
There are no details from Anthropic: the company has not commented on the case. Everything known comes from the arrest report as summarized by the local station WINK News and from the county court records that Tom's Hardware checked.
On September 26 a user the report calls "Carli" wrote to Claude that she planned to "shoot up" the Lee County Sheriff's Office. The next day the same account said she had a new gun. According to the report, Anthropic's platform monitors key phrases and threatening content, and because of how serious the messages were, they went to a human review team. That team contacted the police.
Deputies identified Carli Michelle Heller of Bonita Springs and arrested her at home without incident. She told Sheriff Carmine Marceno that she uses AI "like a diary". On September 30 a charge under Florida statute 836.10 was filed in court: a written or electronic threat to conduct a mass shooting or act of terrorism, a second-degree felony. Arraignment is set for November 2.
One line here is interesting for lawyers. Statute 836.10 requires the threat to be sent or posted in a way that another person can see it. Tom's Hardware suggests that a conversation with a model that a reviewer reads fits that definition. A court will decide.
Never truly anonymous.
This is not the first case. Tom's Hardware counts at least three chatbot conversations that have reached the police since August. In San Antonio on August 11 someone asked an "Anthropic AI chat" about a shooting at a nearby elementary school, the FBI alerted police, and a 22-year-old man was arrested. On August 14 in San Francisco a user told Claude he had bought an AR-15 and threatened Dario Amodei. Anthropic notified police, but there was no arrest and no charge.
How a flagged chat reaches a human at Anthropic
From Anthropic's documents and the arrest report, the path comes down to four steps. The company does not publish thresholds or criteria, so below is only what is written down.
- 1
Classifiers
Automated trust and safety systems check conversations for Usage Policy violations. According to the arrest report, they look for key phrases and threatening content.
- 2
Flag
A flagged chat is kept for up to 2 years, classifier scores for up to 7 years. It is used to train safety models even if you opted out of training.
- 3
Human
Serious cases go to a human review team. This comes from the arrest report; Anthropic's documents do not describe it separately.
- 4
Disclosure decision
If a reviewer considers the threat real, the company may share data with authorities under the policy clause on preventing serious harm.
The second step has a catch. The policy says flagged content is de-linked from your user ID and used to train internal classifiers. That sounds like anonymization. The next sentence of the same policy: Anthropic may re-identify those inputs and outputs to enforce its Terms of Service or Usage Policy against the responsible user. De-identification here serves training, not protection from consequences.
how long Anthropic keeps trust and safety classifier scores for a flagged chat. The inputs and outputs themselves are kept for up to 2 years
What opting out, deleting and incognito actually change
The rules below cover the consumer plans Free, Pro and Max, including Claude Code on those accounts: Anthropic's retention article is written for exactly these. On the API and enterprise plans the periods differ, except for one rule we cover after the table.
| Normal chat | Flagged chat | |
|---|---|---|
| Training opt-out | Not used to train models | Still used to train safety models |
| Deletion | Gone from history immediately, from servers within 30 days | Kept up to 2 years, scores up to 7 |
| Incognito | Not in history or memory, not used for training, kept 30 days | The help article doesn't say |
| Training enabled | De-identified, up to 5 years in training pipelines | Up to 2 years plus scores up to 7 |
We worded the incognito row carefully. The help article promises that incognito chats stay out of history, memory and training, and that they are kept for 30 days. It says nothing about classifier checks, neither yes nor no. We would not treat incognito as protection from review: 30 days on the servers is exactly the window in which the automation runs.
The rule that applies to every plan is in the API documentation. Even with Zero Data Retention or HIPAA, a flagged chat or session is kept for up to 2 years. If your product runs on the API and your customers type whatever they want into it, this applies to you too: ZDR does not switch off trust and safety.
For people working in Claude Code, the takeaway is mundane. The agent reads your files, your logs and any conversation you paste into it, and all of that is part of the session. Anthropic's rules don't cover what never leaves your machine, such as claude-mem memory in a local SQLite database. Everything that goes to the cloud model lives by the rules in the table.
When Anthropic can hand a conversation to the police
This is where the retellings and the primary source part ways, and it is the main thing we found.
TechSpot writes that Anthropic shares user data in limited emergency cases when it believes disclosure is necessary to prevent death or serious physical injury. The wording is real, but it comes from the government requests report. There it describes "emergency requests": the police come to Anthropic themselves and ask for data without a warrant.
For disclosure on its own initiative, Anthropic has one public basis: the privacy policy. And the bar there is lower. Disclosure is allowed if the company has a good-faith belief that it is reasonably necessary to "prevent serious harm to any person or to property". Serious harm to a person or property. Not death, not severe injury. Property too. The same clause lists two more grounds: detecting or preventing fraud and other illegal activity, and protecting the rights, property and safety of Anthropic itself, its users and others.
Two standards in two documents
Government requests report: disclosure on an emergency request from police, to prevent a threat of death or serious physical injury. Privacy policy dated September 10, 2026: disclosure on Anthropic's own initiative, to prevent serious harm to a person or property, as well as fraud and other illegal activity. In the Florida case the police asked for nothing: Anthropic reached out first.
For comparison, OpenAI described its own process publicly in August 2025. Conversations where a user is planning to harm others go to a small team trained on its usage policies. If that team sees an imminent threat of serious physical harm to others, OpenAI may refer the case to law enforcement. OpenAI does not refer self-harm cases to police and explains this by the private nature of the conversations. We found no comparable public text from Anthropic, including on self-harm.
What nobody but Anthropic knows
The government requests report for July–December 2025 looks reassuring. 2 requests for conversation content covering 8 accounts, data provided for both. 20 requests for account data such as name and email covering 55 accounts, data provided for 7. Zero emergency requests.
The Florida case will not show up in such a table, not even in the 2026 report. By definition the report counts requests that came to Anthropic. Cases where Anthropic itself calls the police are not counted at all. Tom's Hardware pointed this out, and we checked the PDF: there is no such row. How many conversations a year the classifiers send to humans, and how many of those reach the police, is not public.
One more thing missing from the documents is a promise to notify. Anthropic says it tells users about government requests, except where the law forbids it and in emergencies involving an imminent threat of serious harm. There is no promise to notify users about its own referrals to police.
What to write in Claude and what not to
Our opinion, and you can argue with it: this story is not about surveillance, it's about many people not reading the terms. A model that answers like a conversation partner is easy to mistake for a diary. But a diary has no classifiers, no two-year retention and no employee deciding what in it is serious. We are wrong if Anthropic publishes its thresholds and statistics on reviews and police referrals: then it becomes a clear procedure rather than a black box.
In practice, not much follows from this:
- A Claude chat is not a private journal. Anything you wouldn't write in a work messenger where an admin can open the history, don't write here either. Threats, even as a joke or in anger, especially.
- Opting out of training is not privacy. It is about training models, not about retention or review. Check the setting anyway, but don't count on it as protection.
- Don't put other people's personal data into a cloud model. Customer databases, correspondence, documents. For agents this means not letting Claude Code read anything that doesn't belong on someone else's servers. How a vendor watches its own agents and where that monitoring fails is visible in our breakdown of an OpenAI agent escaping its sandbox.
- If you build a product on the API, say so in your own policy. Your users write to the model through you, and the rule about flagged requests and ZDR applies to them too.
Document versions as of October 6, 2026
Anthropic privacy policy dated September 10, 2026, retention help article dated July 1, 2026, government requests report for July–December 2025. Details of the Florida case come from the arrest report as summarized by WINK News and Tom's Hardware; Anthropic has not commented. Policies change, so check the current versions before you decide anything.
Sources11expand
- Anthropic, "Privacy Policy", effective September 10, 2026, checked October 6, 2026 — https://www.anthropic.com/legal/privacy
- Anthropic Privacy Center, "How long do you store my data?", July 1, 2026 — https://privacy.claude.com/en/articles/10023548-how-long-do-you-store-my-data
- Anthropic Privacy Center, "What is Anthropic's policy for handling governmental requests for user information?", March 16, 2026 — https://privacy.claude.com/en/articles/9519291-what-is-anthropic-s-policy-for-handling-governmental-requests-for-user-information
- Anthropic, "Government Requests Report", July–December 2025 — https://www-cdn.anthropic.com/5d453bc3285b8e0c101b7193b5765419920cee24.pdf
- Claude Docs, "API and data retention", checked October 6, 2026 — https://platform.claude.com/docs/en/manage-claude/api-and-data-retention
- Claude Help Center, "Use incognito chats", checked October 6, 2026 — https://support.claude.com/en/articles/12260368-use-incognito-chats
- Damien Alvarado, WINK News, "Woman arrested after AI threat against Lee County Sheriff's Office: Investigators", September 30, 2026 — https://www.winknews.com/news/woman-arrested-after-ai-threat-against-lee-county-sheriffs-office-investigators/article_3d4c5915-7015-43c0-b86a-d7fa5eadf958.html
- Shane Downing, Tom's Hardware, "Anthropic reports Florida woman's Claude diary threat to shoot up sheriff's office", October 5, 2026 — https://www.tomshardware.com/tech-industry/artificial-intelligence/anthropic-reports-florida-womans-claude-diary-threat-to-shoot-up-sheriffs-office-felony-charge-follows-its-at-least-the-third-such-conversation-to-reach-police-since-august
- Rob Thubron, TechSpot, "Florida woman used Claude as a diary, then Anthropic reported an entry to police", October 4, 2026 — https://www.techspot.com/news/114091-florida-woman-used-claude-diary-anthropic-reported-shoot.html
- Florida Statutes, § 836.10, checked October 6, 2026 — http://www.leg.state.fl.us/statutes/index.cfm?App_mode=Display_Statute&URL=0800-0899/0836/Sections/0836.10.html
- OpenAI, "Helping people when they need it most", August 2025, quoted via Futurism, August 27, 2025 — https://www.yahoo.com/news/articles/openai-says-scanning-users-conversations-210511235.html
Read next
The alarm went off after 12 minutes. The agent was stopped two and a half hours later. What actually broke in OpenAI's sandbox?September 27, 2026
OpenAI Dots works without being asked. What did OpenAI find when it gave one ten tasks in a row?September 30, 2026
claude-mem: so you stop explaining your project every morningAugust 27, 2026
Comments