This year, more people than ever are being invited to share their health records with apps. AI assistants now answer hundreds of millions of health questions every week, and the newest ones ask you to connect your actual medical records so their answers fit you.
Some of these tools are impressive. This post isn't a warning against them. It's about one distinction worth understanding before you hand your health information to any service, including mine: the difference between a company that promises not to look at your data, and a company that has built things so it can't.
The promise most apps make
Nearly every health app protects your privacy the same way: with a policy. "We won't look at your data." "We don't sell it." "We don't train on it." Often these promises are sincere, made by people who mean them.
But a policy is a decision. And decisions made by a company can be changed by the company — or overridden by someone with more authority than the company.
What two courts showed this year
In January, a federal judge in New York ordered OpenAI to hand over twenty million ChatGPT conversations to lawyers in a copyright lawsuit. OpenAI objected, arguing its users' privacy should be protected. The court disagreed, reasoning that users had voluntarily given their conversations to the company. The conversations existed on OpenAI's servers in readable form — so they could be ordered produced, and they were.
A few weeks later, in a separate criminal case, a defendant argued his conversations with an AI assistant should be private, the way conversations with a lawyer are. The court said no. Talking to an AI is not like talking to your lawyer or your doctor. No special protection applies.
Neither company did anything wrong here. Both defended their users, and both lost — because the question was never about their intentions. When a court orders a company to produce data, "we won't look" becomes "we have to hand it over." A promise is only as strong as the company's legal power to keep it, and against a court order, that power is limited.
Why this matters more for health records
You might read those cases and think: that's copyright lawsuits and criminal trials, not me. But health records are among the most frequently demanded documents in ordinary legal disputes — insurance disagreements, workplace injury claims, family court. Regular people's medical histories get pulled into other people's disputes all the time.
There's a second wrinkle: the privacy rules that bind your doctor's office generally don't bind a consumer app. When your records leave the health system and enter an app, they usually leave those protections behind. What's left is the app's policy — and you now know what a policy is worth against a court order.
So for any app holding your health records in readable form, the honest summary is: your privacy is protected until someone with a court order wants it not to be.
The other kind of promise
There's a different way to build these services — where the promise isn't needed, because the design does the work.
WellKey works this way. Your documents are locked before they ever leave your control, with a key that only you hold. What reaches us — what sits on our servers — is an unreadable copy. We can't open it. Not to look, not to sell, not to train on, not to comply.
That last one is the point of this post. If a court ordered us to produce your records, we could comply completely, hand over every byte we hold — and every byte would be unreadable. Even if we were legally required to hand over your files, all anyone would receive is an unreadable copy. Nobody at WellKey has to be brave on your behalf. The protection doesn't depend on our courage or our lawyers. It's just how the thing is built.
Two honest caveats, because a protective promise should come with its fine print. First, this design has a cost: if you forget your passphrase, we can't reset it or recover your documents — the same lock that keeps everyone else out keeps us out too. Second, this protects what we hold. The copies on your own devices and in your own drawer are yours to look after, and a court can always ask you for your own records. What this design guarantees is narrower and stronger: the service you trusted can never be the leak.
The question to ask
You don't need to understand cryptography to protect yourself. You need one question, and any health app should be able to answer it plainly:
"If a court ordered you to hand over my records tomorrow, what exactly would they receive?"
If the answer is "your records," the app is protecting you with a promise. If the answer is "an unreadable copy," it's protecting you by design. There are legitimate services built both ways — but you deserve to know which one you're using before you upload a single page.
That's the standard I'd hold any app to, including this one.
This post describes court decisions in general terms and isn't legal advice. WellKey is built and operated in New Brunswick, Canada.
Sources
- Judge affirms order requiring OpenAI to produce 20 million chat logs — Bloomberg Law, January 2026 (see also ABA Journal)
- Court rules AI chat logs are not protected by attorney–client privilege — US v. Heppner, S.D.N.Y. 2026
- ChatGPT Health opens to all US users; AI health questions at ~300M/week — TechCrunch, July 2026