By default, the previous conversation turns do. Just because it's easier to corrupt than a human brain doesn't make it not-state.
If ownership of the prompt is the issue, what about the model's own output reasoning? What about notes/"memories" it may write for itself?