Glossary · Privacy

Chatbot Wiretapping: CIPA Claims Over Website Live-Chat & AI Chatbot Conversations

By Steve Levine · Updated July 2, 2026 · 7 min read

Quick Answer

Chatbot wiretapping is the shorthand for a wave of privacy class actions alleging that the conversations visitors have with a website's live-chat box or AI chatbot are intercepted, recorded, or shared with a third-party chat vendor without the visitor's consent. The core claim is California Invasion of Privacy Act (CIPA) § 631 — California requires all-party consent, and plaintiffs cast the chat vendor as an eavesdropper on a private conversation. Companies respond that they are a party to their own chats and that the vendor is just their tool. Newer complaints add an AI angle, alleging transcripts were used to train artificial-intelligence models. CIPA claims carry statutory damages of $5,000 per violation under § 637.2.

What “Chatbot Wiretapping” Means

Nearly every consumer-facing website now offers a chat window — sometimes staffed by human agents, increasingly powered by an AI chatbot. What most visitors do not know is that the chat feature is rarely built by the website itself. It is typically embedded software supplied by a third-party chat vendor, and the messages a visitor types may travel through, and be stored on, that vendor's servers.

“Chatbot wiretapping” lawsuits allege that this architecture is an illegal wiretap: the visitor believes they are having a two-way conversation with the brand, while — according to the complaints — an undisclosed outside company is reading, recording, or exploiting the exchange in real time. Hundreds of these cases have been filed, most in California, as one branch of the broader website-wiretapping wave that also includes session replay recording and Meta Pixel tracking claims. As with the rest of that wave, these are allegations — being named in a complaint is not a finding of wrongdoing, and defendants dispute both the facts and the legal theory.

The § 631 Theory — the Chat Vendor as Eavesdropper

The workhorse claim is CIPA § 631(a), California's wiretapping statute. It reaches anyone who reads or learns the contents of a communication while it is in transit without the consent of all parties — and anyone who aids or abets that conduct. Because California is an all-party-consent state, plaintiffs argue a website chat cannot lawfully be opened up to an outsider unless every participant agrees.

A typical complaint therefore runs on two tracks:

  1. The vendor intercepts. The chat provider allegedly captures each message as it is transmitted, stores transcripts on its own servers, and — in many complaints — analyzes or monetizes them for its own benefit, making it a third-party eavesdropper rather than a passive tool.
  2. The website aids and abets. The brand that embedded the chat widget allegedly enabled and profited from the interception, exposing it to liability under § 631(a)'s aiding-and-abetting prong even though it was a party to the chat itself.
Timing matters too: under Ninth Circuit case law on prospective consent, a disclosure the visitor only encounters after the recording has begun may not establish the consent CIPA requires — one reason chat windows increasingly lead with a recording notice before the first message.

The “Party to the Conversation” Defense

The defense that decides most of these cases is the party exemption. A participant in a conversation cannot “eavesdrop” on it — and the website is obviously a participant in its own customer chats. So the dispositive question becomes: what is the vendor?

Defendants argue the chat provider is an extension of the website — the modern equivalent of a tape recorder or an outsourced switchboard — that merely transmits and stores messages on the brand's behalf. On that view there is no third party at all, and § 631 never comes into play. Plaintiffs counter that the vendor is an independent business with its own access to the transcripts and its own uses for them: product improvement, analytics, marketing, or AI development. Courts have split, often along a familiar line — some ask whether the vendor merely has the capability to use the data for itself, while others require allegations that it actually did. A complaint that plausibly alleges the vendor exploited chat data for its own purposes has a far better chance of surviving dismissal. Defendants also raise consent (chat disclosures and privacy policies), the absence of “contents,” and standing challenges familiar from the rest of the CIPA wave.

§ 632 and Confidential Communications

Many complaints also plead CIPA § 632, which prohibits using an electronic device to record or eavesdrop on a confidential communication without all-party consent. Unlike § 631, which focuses on interception in transit, § 632 turns on whether the conversation was “confidential” — whether a party had an objectively reasonable expectation that the exchange was not being overheard or recorded.

That element is a real hurdle in chat cases. Defendants argue that no one reasonably expects an online customer-service chat — often prefaced by a recording notice — to be private in the § 632 sense. Plaintiffs respond that chats frequently involve exactly the kinds of information people treat as private: order and account details, financial questions, and in cases involving health-related websites, medical information typed into a chat box. The more sensitive the site, the stronger the confidentiality argument tends to be, which is why chat claims involving healthcare, insurance, and financial-services websites are litigated especially hard.

The AI-Training Angle

The newest generation of chat-privacy complaints adds an artificial-intelligence twist: allegations that conversations were not just stored but used to train AI models. The claims take two shapes. In one, a website's human-facing chat vendor allegedly feeds customer transcripts into its machine-learning systems to improve its products — a use plaintiffs say no visitor consented to. In the other, the chatbot is the AI company's product, and the complaint alleges the conversations themselves were intercepted or shared with advertising and analytics third parties.

OCA covers live examples of both: the Perplexity AI chat privacy class action, which alleges embedded Meta and Google trackers forwarded users' AI chat transcripts to those companies, and the OpenAI ChatGPT privacy suit, a proposed class action making similar tracking allegations that the plaintiff voluntarily dismissed days after filing. Both illustrate the same caution: these are complaint-stage allegations, not adjudicated facts, and courts are only beginning to work out whether training an AI model on chat data violates wiretap statutes written decades before large language models existed.

Damages, Disclosures, and What Consumers Should Know

CIPA's private right of action, Cal. Penal Code § 637.2, lets a plaintiff seek the greater of $5,000 per violation or three times actual damages, plus an injunction — and no dollar loss is required to sue. Multiplied across every chat on a busy website, the theoretical exposure is enormous, which is why even contested legal theories generate settlement pressure. Those figures are what a court may award if a violation is proven; they are not an automatic payout, and resolved web-tracking cases have typically paid class members modest per-person amounts.

For consumers, the practical takeaways are simple. A notice that “this chat may be recorded or monitored” is doing legal work — it is the consent the statutes contemplate, so read it before typing. Treat a website chat box like any customer-service channel: assume it is retained, and be deliberate about sharing sensitive personal, financial, or health information. And if a chat-privacy case settles as a class action, affected users are typically notified and can file a claim — current opportunities appear on our open settlements listing.

Frequently Asked Questions

What is chatbot wiretapping?

Chatbot wiretapping refers to class action claims that conversations visitors have with a website's live-chat box or AI chatbot are intercepted, recorded, or shared with a third-party chat vendor without the visitor's consent. Plaintiffs allege this violates wiretap laws — most often the California Invasion of Privacy Act (CIPA) § 631 — because California requires the consent of all parties before a communication can be recorded or read by an outsider.

How can a company wiretap its own website chat?

Legally, it generally cannot — a party to a conversation cannot eavesdrop on itself. That is why chatbot complaints target the third-party vendor that supplies the chat technology. Plaintiffs allege the vendor intercepts and stores the chats on its own servers and can use them for its own purposes, making it an eavesdropper rather than a mere tool of the website. The website is then accused of aiding and abetting the vendor. Whether a given vendor is a 'tool' or an 'eavesdropper' is the central disputed question, and courts have come out both ways.

What is the AI-training angle in chatbot lawsuits?

Newer complaints allege that chat vendors and AI companies use customers' chat transcripts to train artificial-intelligence models — a use the website visitor allegedly never consented to. These are allegations at the complaint stage, which the defendants generally dispute; courts are only beginning to address whether training an AI model on chat data violates wiretap or privacy statutes.

What damages are available in a chatbot wiretapping case?

CIPA's private right of action, Cal. Penal Code § 637.2, allows a person to seek the greater of $5,000 per violation or three times actual damages, plus injunctive relief, and does not require proof of a dollar loss. These are amounts a court may award if a violation is proven — not an automatic payout. How violations are counted, and whether a class is certified at all, dramatically affects any real-world recovery.

Is it legal for a website to record my chat conversation?

It depends on consent and on where you are. In all-party-consent states like California, plaintiffs argue a chat cannot be recorded or shared with a third party unless every participant agrees, which is why many chat windows now display a disclosure such as 'this chat may be recorded' before you start typing. Whether a particular disclosure was conspicuous enough, and whether it came before the recording began, are the facts these lawsuits typically turn on.


About This Page

General legal-information about chatbot and website-chat wiretapping claims, not legal advice. OpenClassActions.com is a consumer news site and is not a law firm or a settlement administrator. Chat-privacy lawsuits involve allegations that the defendants generally dispute, the underlying legal questions remain unsettled and vary by court, and settlements resolve claims without any admission of wrongdoing. How the law applies depends on the specific chat technology, disclosures, and facts of a given website. If you think your rights were affected, consult a qualified attorney in your jurisdiction.


More on Chat & Communications Privacy