If this were true, the attacker would need to send prompts to retrieve information, making it an easy attack for the user to spot. However, if the malicious actor has the power to delete prompts and chats, I would suspect they already have access to every other chat.
A 32GB iPad isn’t the best choice in 2025. Anyhow, have you deleted the photos in the trash?