ChatGPT data privacy in 2026: the short answer
If you only read one section, read this one. All of it is explained in more detail below.
- Does ChatGPT save your data? Yes. Conversations stay in your account until you delete them. Deleted chats and Temporary Chats leave OpenAI systems within 30 days, unless a legal or security obligation applies.
- Does it train on your data? On Free, Go, Plus and Pro, yes, by default. You can switch this off. On Business, Enterprise, Edu and the API, no, not by default.
- Is ChatGPT encrypted? In transit (TLS 1.2 or higher) and at rest (AES-256), yes. End-to-end, no. OpenAI can technically read your conversations.
- Does OpenAI sell your data? No. It does share data with service providers and it must hand over data under a valid legal order, which has already happened at scale.
- Can you use it under the GDPR? Yes, with a data processing agreement, which OpenAI offers for Business, Enterprise and the API, but not for consumer accounts.
- The biggest practical risk is not OpenAI. It is employees pasting client data, patient records or credentials into a personal account.
Last verified: September 2026. Policies in this area change often, so check OpenAI’s own documentation before you rely on a specific number in a compliance document.
What data does ChatGPT collect?
OpenAI collects three broad categories when you use ChatGPT:
- Content you submit: prompts, conversation history, uploaded files and images, and the answers the model produces.
- Account and technical data: email address, IP address, approximate location, device and browser details, and usage patterns.
- Derived data: memories that ChatGPT extracts from your conversations, and metadata about which connected files or apps were accessed and when.
Memory is worth calling out separately, because it is a retention surface of its own. Deleting a conversation does not delete the memories ChatGPT built from it. You clear those under Settings, Personalization, Memory.
Does ChatGPT save your data?
Yes. ChatGPT stores your conversations in your account for as long as you leave them there. When you delete a chat it disappears from your history immediately and is scheduled for removal from OpenAI systems within 30 days. The exception is data OpenAI has to keep longer for security reasons or a legal obligation.
Retention differs per surface, which is where most confusion comes from:
| Surface | Retention after deletion | What is captured |
|---|---|---|
| Standard chat | 30 days | Prompts, answers, uploaded files |
| Temporary Chat | 30 days, no manual deletion needed | Prompts and answers, no history, no memories |
| Agentic browsing (cloud browser) | 90 days | Text, screenshots, browsing session data |
| Memory | Until you delete it separately | Facts extracted from conversations |
| API with Zero Data Retention | Not stored at all | Nothing written to disk |
Two things this table does not tell you. First, opting out of training does not shorten the 30-day window, because that window exists for abuse monitoring, not for training. Second, a Temporary Chat is not an incognito mode: the content still travels to OpenAI and is still held for 30 days.
Is ChatGPT encrypted?
Partly, and the distinction matters more than most summaries admit.
- In transit: yes. Traffic between you and OpenAI, and between OpenAI and its service providers, uses TLS 1.2 or higher.
- At rest: yes. Stored content is encrypted with AES-256.
- End-to-end: no. ChatGPT is not end-to-end encrypted, and no mainstream AI assistant is.
The reason is structural rather than a shortcoming in OpenAI’s security. The model has to process your prompt in readable form to answer it, so the content is decrypted on OpenAI’s infrastructure. That means OpenAI holds the keys, authorised staff can access content under strict controls, and a court can compel production. Signal-style guarantees are not available here.
Enterprise customers can narrow this gap with Enterprise Key Management, which lets the organisation hold its own encryption keys through AWS, Google Cloud or Azure. Revoke the key and the stored content becomes unreadable, including to OpenAI. It is available to Enterprise and Edu workspaces, and OpenAI does not recommend routine key revocation as an operational habit.
Does ChatGPT train on your data?
It depends entirely on your plan.
| Plan | Used for training by default | How to change it |
|---|---|---|
| Free, Go, Plus, Pro | Yes | Settings, Data Controls, switch off “Improve the model for everyone” |
| Business, Enterprise, Edu | No | Nothing to do, it is off by default |
| API platform | No | Nothing to do, it is off by default |
Two limits on the opt-out are worth knowing. It only applies going forward, so anything already absorbed into a completed training run cannot be pulled back out. And it does not change retention: your conversations are still stored and still kept for 30 days after deletion.
Temporary Chat is the cleaner option for a one-off sensitive question. It creates no history, creates no memories, is never used for training, and is deleted within 30 days.
Does ChatGPT share your data with third parties?
OpenAI does not sell your conversations. It does share data in three situations you should plan for.
- Service providers: infrastructure, analytics and support vendors process data on OpenAI’s behalf. In November 2025 a breach at analytics provider Mixpanel exposed limited account information for some API users. No conversations, passwords, API keys or payment details were involved, and OpenAI removed Mixpanel from production, but the incident is a reminder that your vendor’s vendors are part of your risk surface.
- Legal orders: OpenAI must comply with valid legal process. The New York Times litigation, covered below, is the clearest example of what that looks like in practice.
- Connected apps: when you link Google Drive, Microsoft OneDrive, Slack or another system, data moves in both directions under the permissions you granted. Apply least privilege and review those connections periodically.
Is ChatGPT safe and secure to use?
For everyday work, yes. OpenAI holds SOC 2 Type 2 certification, runs a bug bounty programme, and applies the encryption and access controls described above. For confidential or regulated data on a personal account, no.
The gap between those two answers is user behaviour, not platform security. Recent incidents show both sides of it:
- February 2026: Check Point disclosed a side channel in ChatGPT’s code execution runtime that could have leaked conversation content to an attacker. OpenAI had identified the underlying issue internally and deployed a fix on 20 February 2026. There is no evidence it was exploited.
- October 2025: the municipality of Eindhoven reported a data breach after large numbers of files containing personal data were sent to public AI sites, including ChatGPT.
The Dutch Data Protection Authority has been explicit on this point since 2024: entering personal data into an AI chatbot against your organisation’s own rules is a data breach, with a reporting duty to the regulator and, in some cases, to the people affected. That makes ChatGPT governance an AVG obligation, not an IT preference.
The New York Times lawsuit and your deleted chats
The copyright litigation against OpenAI showed that a company policy on deletion can be overridden by a court. The sequence matters:
- May 2025: a US magistrate judge ordered OpenAI to preserve all consumer ChatGPT and API output logs, including conversations users had already deleted. Enterprise, Edu and Zero Data Retention API customers were excluded, as were conversations from the EEA, Switzerland and the UK.
- September 2025: the going-forward preservation obligation ended on 26 September and OpenAI returned to its standard 30-day deletion schedule.
- January 2026: District Judge Sidney Stein affirmed an order compelling OpenAI to produce 20 million de-identified consumer logs to the news plaintiffs, under de-identification, a protective order and an attorneys-eyes-only designation.
- September 2026: the case reached summary judgment, and the US Department of Justice filed a brief supporting OpenAI’s fair use position. A ruling is expected in the months ahead.
What this means for you: standard deletion works again for new conversations, but data captured between April and September 2025 sits in a separate legal hold and a sample of it is being analysed by outside parties. Your right to erasure is only as durable as the litigation your provider is exposed to. For anything you could not defend in a courtroom, the control is not deleting afterwards, it is not sending it in the first place.
Agentic ChatGPT: Work, the cloud browser and connectors
The privacy picture changed again when ChatGPT stopped being a chat window. ChatGPT Work, introduced in July 2026, runs multi-step tasks on a separate machine in the cloud, and its cloud browser can read pages, fill in forms and operate websites you are signed in to. It replaces the earlier standalone agent mode. Three characteristics matter for data protection:
- Screenshots and browsing data are retained longer. Agentic sessions and the screenshots taken during them are kept until you delete them, and removed within 90 days after deletion, three times the standard chat window.
- The cloud browser is walled off from your own. It keeps its own cookies and sessions and does not use your local browser’s tabs, history, saved passwords or extensions. Credentials entered through the secure sign-in form go to the remote browser rather than through the conversation, so the model does not see them.
- Sessions persist until you clear them. Cookies and signed-in sessions stay in the cloud browser until they expire or you remove them under Settings, Cloud browser, Browser data. Convenient for repeat tasks, and a standing access path that belongs in your offboarding checklist.
Practical rule: an agent that can see a screen can record what is on that screen. Do not point it at banking portals, HR systems or dashboards with personal data unless you have deliberately accepted that.
Is ChatGPT GDPR compliant?
ChatGPT can be used in a GDPR-compliant way, but compliance is a property of your deployment rather than of the product. OpenAI supplies the building blocks:
- Data processing agreement: available for ChatGPT Business, ChatGPT Enterprise and the API platform. Not available for consumer accounts, which is the single clearest reason not to run company data through a personal Plus subscription.
- Data residency: eligible Enterprise, Edu, Healthcare and API customers can store content at rest in Europe and a number of other regions, with in-region processing available on supported endpoints.
- Retention controls: qualifying organisations can configure retention periods, and API customers can request Zero Data Retention.
What you still own: a lawful basis, a record of processing, a DPIA where the risk warrants one, transparency towards the people whose data you process, and a workable answer to erasure and rectification requests. That last one is hard, because a model cannot surgically forget a single fact without retraining.
The EU AI Act and the Dutch position
Two dates matter for anyone deploying ChatGPT in the EU:
- 2 August 2025: obligations for general purpose AI models took effect, covering technical documentation, a public summary of training content and compliance with EU copyright rules.
- 2 August 2026: the transparency duties under Article 50 took effect and the AI Office gained enforcement powers over general purpose AI providers, with fines up to 3% of global turnover or 15 million euro.
The Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026, deferred the high-risk obligations to 2 December 2027 for stand-alone systems and 2 August 2028 for AI embedded in regulated products. It did not move the general purpose AI dates. Our EU AI Act compliance checklist works through what this means step by step.
AI literacy under Article 4 has applied since February 2025 and is not deferred. In the Netherlands, the Autoriteit Persoonsgegevens set out its position on generative AI in February 2026 and published practical AVG guidance for developers and deploying organisations in July 2026. The consistent message across both: map which AI tools are already in use including the ones outside IT’s view, make agreements with suppliers, and involve your data protection officer at the start rather than afterwards.
How to make ChatGPT more privacy-friendly
1. Switch off model training on consumer accounts
On Free, Go, Plus and Pro, open Settings, then Data Controls, and switch off “Improve the model for everyone”. Takes under a minute and does not affect how well ChatGPT works for you.
2. Use Temporary Chat for sensitive one-offs
No history, no memories, no training, deleted within 30 days. The right default for anything you would not want surfacing in a future conversation.
3. Move the organisation to Business or Enterprise
This is the step that actually changes your legal position. Business and Enterprise give you no training on your data by default, a data processing agreement, SSO and centralised administration. Enterprise adds configurable retention, data residency, Enterprise Key Management and audit logging. Buying seats is cheaper than a reportable data breach.
4. Redact personal data before it leaves your network
In April 2026 OpenAI released Privacy Filter, an open-weight model under the Apache 2.0 licence that detects and masks personal data in text. It runs locally, so the raw text never has to leave your machine to be sanitised, and it labels eight categories including names, addresses, email addresses, phone numbers, dates, account numbers and secrets such as API keys. OpenAI reports an F1 score of 96% on the PII-Masking-300k benchmark.
It is useful as a preprocessing layer in front of support tickets, transcripts or logs. OpenAI is explicit that it is a data minimisation aid rather than an anonymisation or compliance guarantee, and it performs unevenly across languages, so keep human review in place for legal, medical and financial workflows.
5. Govern connectors and agents like you govern accounts
Connected apps and cloud browser sessions are standing access. Grant least privilege, review the list periodically, and revoke sessions when someone leaves.
6. Train the people, not just the settings
Most incidents are a person pasting something they should not have. Written rules on what may and may not go into which tool, plus a short training round, prevent more damage than any toggle. If you want support with this, see our ChatGPT Workshop.
ChatGPT data privacy checklist for organisations
| Level | Measure | What it gives you |
|---|---|---|
| Basic | Training opt-out and Temporary Chat | No training, minimal footprint |
| Standard | ChatGPT Business or Enterprise | No training by default, DPA, admin control |
| Advanced | Local PII redaction before sending | Less personal data leaves your network |
| Sovereign | EU data residency and Enterprise Key Management | In-region storage, revocable keys |
| Maximum | Zero Data Retention on the API | Nothing written to disk |
Need help navigating AI privacy in your organisation?
DataNorth helps organisations use ChatGPT and other AI tools without creating a compliance problem. Our ChatGPT Assessment maps what your people already use, where personal data flows, and what needs to change to meet the AVG and the EU AI Act.
Frequently asked questions (FAQ) about ChatGPT Data Privacy
Does ChatGPT store my data?
Yes. Conversations remain in your account until you delete them. Once deleted, they are removed from OpenAI systems within 30 days, unless a legal or security obligation requires longer retention. Temporary Chats are deleted within 30 days without any action from you.
Is ChatGPT end-to-end encrypted?
No. Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256, but not end to end. The model needs to read your prompt to answer it, so OpenAI holds the keys and can technically access the content. Enterprise Key Management lets Enterprise and Edu workspaces hold their own keys, which is the closest available equivalent.
Does ChatGPT use my data for training?
On Free, Go, Plus and Pro it does by default. Switch it off under Settings, Data Controls, “Improve the model for everyone”. On Business, Enterprise, Edu and the API, your data is not used for training by default. Opting out only applies to future conversations.
Is ChatGPT Plus more private than the free version?
No. Plus and Pro follow the same consumer privacy rules as Free and Go: training is on by default, there is no data processing agreement, and the same 30-day retention applies. Paying more buys capability, not a different privacy posture. Business and Enterprise are the plans that change it.
Is ChatGPT safe for confidential company information?
Not on a personal account. Without a data processing agreement you cannot lawfully process client or employee personal data, and the content is used for training unless someone remembered to switch it off. Use ChatGPT Business or Enterprise, and keep credentials, identification numbers and special category data out regardless of plan.
I deleted my ChatGPT history in mid-2025. Is it really gone?
Probably not. Conversations generated or deleted between April and September 2025 fell under a federal preservation order in the New York Times case and sit in a separate legal hold. A 20 million log sample from that set is being produced to the news plaintiffs for analysis under a protective order.
Can I ask ChatGPT to forget a specific fact about me?
Not from the model itself. A large language model cannot unlearn one fact without retraining, which conflicts with the right to rectification under the GDPR. What you can do is delete the conversation, clear the stored memory under Settings, Personalization, Memory, opt out of training, and submit a privacy request to OpenAI.
Does ChatGPT read my screen when I use agent features?
It sees the cloud browser it controls, not your desktop. Agentic sessions capture screenshots to work, and those screenshots are kept until you delete the chat and then removed within 90 days. Do not point the agent at screens showing banking details, credentials or personal data.