[nonimo]
EN
Download

Does ChatGPT share or sell your data? What OpenAI says

· Updated · Written and maintained by Joaquín Trapero, Nonimo

OpenAI does not sell your ChatGPT conversations, and it says so in writing in both of its privacy policies. It does share defined categories of data with other parties. It does keep what you type until you delete it. And since September 10, 2026, the policy that governs you as an American says something the policy that governs Europeans does not.

That last sentence matters more than it looks. Almost everything written about ChatGPT data privacy works from one privacy policy, and there are two. They carry different dates, they answer the sharing question differently, and the American one is both the newer and the wider of the pair.

So here is what the documents say, in their own words, with the date each one carries. If you got here because you already pasted a client file and want to know whether that was a breach, that is a different question with its own guide.

QuestionShort answer, as of September 19, 2026
Does it sell your data?No. Stated in both policies
Does it share your data?Yes, in seven defined categories, and the first one changed in the US
Does it save what you type?Yes, until you delete it, then 30 days
Does it train on it?On consumer accounts, yes by default

Is ChatGPT confidential? Only in a narrow sense

Not in the way a lawyer or a doctor uses the word. What OpenAI offers are privacy commitments that change with the account, and as of September 25, 2026, its own pages set them out like this.

On Free, Go, Plus and Pro, your conversations may be used to train OpenAI’s models by default. Turning off Improve the model for everyone stops that for new conversations, but they still sit in your history, and if you give a response a thumbs up or thumbs down, the entire conversation may be used for training anyway. Temporary Chat keeps a conversation out of your history and out of training, and OpenAI may still keep a copy for up to 30 days for safety purposes.

On Business, Enterprise, Edu and the API, OpenAI does not train on your data by default. On Business and the API, its access is limited to authorized employees and to “specialized third-party contractors who are bound by confidentiality and security obligations,” reviewing for abuse. On Business, your own workspace admins can view and export every conversation. Telling a client which of these will hold its file is a job for an engagement letter’s AI paragraph.

None of those settings makes ChatGPT confidential in the professional sense. The duty to keep a client’s information confidential is yours, and a vendor’s privacy page does not discharge it. In practice, keep names, account numbers and matter numbers out of the prompt, work from a business account, and turn training off. Nonimo, a Mac and Windows app, replaces names and identifiers with labels before the text reaches the chat, so the originals stay on your computer.

ChatGPT data privacy: OpenAI has two policies, and yours is the newer one

OpenAI publishes one privacy policy for the rest of the world, updated February 6, 2026, and a separate US privacy policy, updated September 10, 2026. Each links to the other at the top. Most people never notice, because the site serves you one of them and both are titled the same way.

For a firm in the United States, the second one is the operative document, and the gap of seven months between them is where the interesting material sits. The cyber insurance questionnaire your broker sends asks which vendors handle your data, and this is one of the answers.

What the US policy added on September 10, 2026

The policy for the rest of the world says this, and it is unambiguous: OpenAI does not sell personal data, does not share it for cross-contextual behavioral advertising, and does not process it for targeted advertising purposes.

The US policy says something narrower. It says OpenAI does not sell personal data, and then adds that depending on your choices it may share limited data with select marketing partners to promote its own products on other companies’ properties. It then names what that is called: targeted advertising, or sharing for cross-context behavioral advertising under certain state privacy laws.

September 10, 2026
the date on the US privacy policy that first describes sharing for cross-context behavioral advertising. The policy for the rest of the world, dated February 6, 2026, still rules it out

Read the two columns next to each other and the difference is not a matter of tone.

Rest of the world, Feb 6, 2026United States, Sep 10, 2026
Sells personal dataNoNo
Shares for cross-context advertisingNoYes, you can opt out
Ads inside the productNot describedFree and Go users

Quoted from the two policy pages as published on openai.com, read September 19, 2026.

Two things keep this in proportion. The first is that marketing data is not your conversations: nothing in either policy says prompts go to advertisers. The second is that you can opt out, through the marketing privacy control in account settings, and OpenAI states you can also do it with a legally recognized opt-out mechanism, naming Global Privacy Control.

This is where the search box and the statute stop agreeing. When you type does ChatGPT share your data, you mean does anyone else get to see this. When a California privacy policy uses the word, it means one specific thing.

Section 1798.140 of the California Civil Code defines sharing as disclosing a consumer’s personal information to a third party for cross-context behavioral advertising, and for nothing else, whether or not money changes hands. Disclosure to a hosting provider is not sharing. Disclosure under a subpoena is not sharing. Only the advertising kind counts.

So a page that tells you OpenAI does not share your data may be quoting a policy correctly and still leaving you with the wrong picture, because it answered the statutory question and you asked the plain English one. The plain English answer is the list two sections down, and it is longer.

What ChatGPT collects, on top of what you type

The prompts are the part everyone thinks about. Section 1 of the US privacy policy names ten more kinds of data alongside them, and for a professional firm two of those matter more than the prompts do.

CategoryWhat it is
Account informationName, contact details, credentials, date of birth, payment details
User contentPrompts, files, images, audio, video, data from connected services
Log dataIP address, browser type and settings, timestamps, interactions
Usage dataFeatures used, actions taken, time zone, country, device
Ads historyFor Free and Go users, ad content viewed or engaged with
LocationGeneral area from IP, or precise location if you provide it

OpenAI, US privacy policy, section 1, read September 19, 2026.

The parts of the record you did not write

Connected services is the first of the two. If you link a drive, a mailbox or an app from another company, the policy treats what comes back as content you provided, which means it lands in the same bucket as a prompt. You did not type it, and it is collected all the same.

Contact data is the second. If you let the mobile app read your address book, OpenAI uploads it and checks which of your contacts already use the service. For a firm whose address book is a client list, that is a disclosure of the client list, separate from anything anyone ever pasted into a chat.

Neither of those is hidden. Both are in section 1 of the policy, in plain sentences. They are simply not what people picture when they picture a chatbot, which is the general shape of this whole subject and the reason a written AI policy beats a conversation about it.

Does ChatGPT save what you write, and for how long?

Yes. Conversations sit in your history until you remove them, and the policy is explicit that retention is what makes history work. There is no setting that keeps a chat and stores nothing.

That is worth stating because whether it saves, stores, keeps or retains your chats is one question with one answer, and the answer is governed by your own deletions rather than by any timer. A chat you never touch stays available. The clock people ask about does not start until you act, which is the opposite of how the record retention schedules most firms already run on behave.

The thirty days start when you press delete

Once you delete a conversation, a memory or your whole account, OpenAI states it removes the data from its systems within 30 days. The same 30 days apply to a Temporary Chat you never delete: OpenAI’s help page says it may keep a copy for up to 30 days for safety purposes, and the US policy adds that it can hold one longer when it has to for safety or legal reasons. They also cover API inputs and outputs on endpoints without zero data retention.

30 daysto remove a conversation you deleted
30 daysthat OpenAI may keep a copy of a Temporary Chat
30 daysfor API inputs and outputs, absent zero data retention
OpenAI privacy policy of September 10, 2026, Temporary chat help page read September 25, 2026, and Enterprise privacy page of January 8, 2026

Thirty days is short, and thirty days is not zero. It is also a ceiling with named exceptions: a legal hold, banned content, financial records, and the audit record of your own erasure request, which OpenAI keeps in order to prove it honored the request.

There is one more exception, and it is the one that catches people. If you allowed your content to be used to improve the models, the policy says deletion does not reach data that has already been deidentified and disassociated from your account. You can delete the conversation. You cannot untrain a model.

Temporary Chat, and the one thing it does not undo

Temporary Chat is the best consumer control OpenAI offers, and it is worth knowing exactly what it buys. While a chat stays temporary, it does not appear in your history, does not create or update memories, and is not used to improve OpenAI’s models. A personalized temporary chat can still draw on the memories and custom instructions you already have. And OpenAI may keep a copy for up to 30 days for safety purposes.

What it does not do is unsend. The text still traveled to OpenAI, was still processed there, and was still held for up to a month. If the concern is that client information left the office, Temporary Chat does not address the concern. It addresses what happens afterward.

Does ChatGPT train on your data? That depends on the account

On the consumer services, the default is yes. OpenAI’s help center puts it plainly: when you use services for individuals such as ChatGPT, it may use your content to train its models, and you opt out by turning off Improve the model for everyone under Settings then Data Controls.

On the business side, the default reverses. OpenAI states that by default it does not train on any inputs or outputs from ChatGPT Business, ChatGPT Enterprise, the API and the rest of the commercial line, unless the customer explicitly opts in.

AccountTrains by default
Free, Go, Plus, ProYes, you can opt out
ChatGPT BusinessNo
ChatGPT Enterprise, Edu, Healthcare, TeachersNo
API Platform, after March 1, 2023No

OpenAI, How your data is used to improve model performance, and Enterprise privacy page of January 8, 2026.

For a small firm, that table is the single largest lever available, and it costs nothing to pull. Which account your people sign in with decides which contract governs their text, which is why the deployment usually runs through whoever manages your Microsoft or Google tenant.

The thumbs up that reopens the door

One sentence in the help center applies whichever account you are on. OpenAI states that even if you have opted out of training, you can still choose to give feedback, and if you do, the entire conversation associated with that feedback may be used to train its models.

Not the rating. The conversation. One person clicking a thumbs up on a useful answer hands over the exchange that produced it, including whatever was pasted above it. The same help center page adds that support conversations may be used to improve OpenAI services, including its models, if training is enabled in settings.

Nobody hid it: it is written on the page that explains how to opt out, one paragraph below the switch. People just tend to stop at the first paragraph.

Training is one use of your text, not the only one

Everything above circles one confusion, and it is worth naming directly, because it is the confusion that gets client data pasted into chatbots by people who believed they had checked.

We do not train on your data is a promise about one use. It says the text will not be folded into a future model. It does not say nobody reads it, it does not say it is not kept, and it does not say it never left your office. Those are four separate questions and the answer to one of them tells you nothing about the other three.

The confusion is easy to fall into because training is the only one of the four that sounds permanent. A model you helped train is out there forever; a log that deletes in thirty days feels like nothing happened. But the thing that actually costs a firm money is almost never the model. It is the copy that existed, somewhere else, on a date when someone had a right to ask for it.

Four things that still happen with training off

What still happensWhere OpenAI says so
The text is stored and retainedRetention section, both policies
It runs through automated classifiersEnterprise privacy, business data review
Staff or contractors may access itEnterprise privacy, per service
It is disclosed under valid legal processDisclosure section, both policies

OpenAI US privacy policy of September 10, 2026, and Enterprise privacy page of January 8, 2026.

For a US firm the second column is the one to read twice, because the last row is not theoretical here. A court in a copyright case with nothing to do with your clients once ordered OpenAI to preserve output logs that would otherwise have been deleted at users’ request, and that order ran for five months before it was lifted. No product setting had any say in that decision.

So the test that matters is who can be made to produce it, not did they train on it, and the answer to that question is set the moment the text arrives, not afterward. A federal judge read a provider’s terms that way when ruling on a defendant’s own exchanges with Claude.

Who can read a conversation: OpenAI, a contractor, your own admin

Three different sets of eyes, three different rules, and the differences are per product rather than per plan tier.

On ChatGPT Business the admin can read everything

OpenAI’s enterprise page states that on ChatGPT Business, workspace admins can view, access, export and delete users’ conversations in the workspace. On ChatGPT Enterprise, Edu and Healthcare, admins instead reach an audit log of conversations through the Enterprise Compliance API. Neither arrangement settles whether ChatGPT is HIPAA compliant for a practice, because that turns on what the staff member sends, not on who can read it afterward.

ProductWho at OpenAIWho at your firm
ChatGPT BusinessStaff plus outside contractors, for abuse reviewAdmins, full read and export
Enterprise, Edu, HealthcareStaff, for incidents or where law requiresAdmins, via Compliance API log
API PlatformStaff plus outside contractors, for abuse reviewWhoever holds the key

OpenAI, Enterprise privacy at OpenAI, updated January 8, 2026.

The row that surprises people is the first one. The plan a firm of five people is most likely to buy is the plan where a colleague can open their chats. And if you handle protected health information, OpenAI’s enterprise privacy page mentions a business associate agreement only in its answer about the API Platform, so ask before assuming Business is covered.

The plans OpenAI will sign that agreement for, and the features each one still leaves outside it, are set out plan by plan for practices under HIPAA.

The work email address nobody thought about

There is a quieter version of the same clause. Both policies state that if you create an account using an email address belonging to your employer or another organization, OpenAI may share the fact that you have an account, and certain account information such as your email address, with that organization.

That runs in the direction people do not expect. A paralegal who signed up for a personal Plus account with the firm’s domain has a link back to the firm, before anyone deploys anything. In a city hall the same personal account carries a second surprise, because a prompt typed there can be a public record whoever pays for the plan.

Where the servers are, and why that is the wrong question here

OpenAI states it processes personal data on servers in various jurisdictions, including its own facilities in the United States. For an American firm that is usually the end of the inquiry rather than the start of one.

The question matters in Europe because a transfer out of the bloc needs a legal mechanism and a regulator can ask you to produce it. In the United States there is no federal data regulator to produce it to. Server location is a procurement talking point here, not an obligation, and treating it as the headline is a habit imported from a different legal system.

Free, Go, Plus, Pro, Business, Enterprise: what actually changes

Six names, and the differences that matter are not the ones the pricing page leads with. Ignore message limits for a moment and sort the plans by what happens to your text.

PlanTrains by defaultAdsRetention control
Free, GoYes, you can opt outYesUser only
Plus, ProYes, you can opt outNoUser only
BusinessNoNoWorkspace admin
Enterprise, Edu, HealthcareNoNoWorkspace admin

Compiled from OpenAI’s US privacy policy of September 10, 2026, and Enterprise privacy page of January 8, 2026.

Going from Free to Plus buys you speed and removes the ads. It does not change the training default, and it does not give anyone at your firm the ability to set a retention period or to see what was sent. The first plan that changes the contract is Business, and the guides on Claude, Gemini and Copilot make the same comparison for each.

How to turn training off, and how to delete what is there

This takes four steps and a few minutes, and costs nothing. Do them in this order and check them on a second device, because people assume the setting carried over, and it is worth confirming that it did.

  1. Turn off model training. Settings, then Data Controls, then switch off Improve the model for everyone. OpenAI states the setting applies to the whole account across devices, and that chats stay in your history but stop being used to train.
  2. Decide about memory. The same screen controls whether details carry between chats. Turning it off does not delete what is already saved, so clear saved memories separately.
  3. Delete what is already there. Delete individual chats, or delete the account. Either way the 30 days start running, with the named exceptions above.
  4. Tell people about the thumbs up button. This is the one that needs saying out loud, because no setting covers it and the button looks harmless.

Then write down who did it and when. An undocumented control is worth very little the day your insurer’s renewal form asks what you have in place.

What US law gives you, which is not a regulator

There is no federal comprehensive privacy statute and no federal data protection authority. What exists instead is a patchwork with three parts that carry the weight: the Federal Trade Commission on unfair or deceptive practices, the state attorneys general on their own residents, and HIPAA through HHS Office for Civil Rights where health data is involved. Health data in an employer’s HR file sits outside HIPAA, and there employment law and the state lists take over.

The practical consequence is a change of posture rather than a change of rules. In Europe a firm would worry about a letter from a data protection regulator. Here the first person to ask what you pasted is usually opposing counsel in discovery, or a client’s own security questionnaire, and neither of them is bound by what a privacy policy permits. That is why the breach analysis and the state notification clocks matter more here than the vendor’s compliance page does.

Who can askOn what basisWhat they look at
Federal Trade CommissionUnfair or deceptive practicesA policy change made without clear notice and consent
State attorney generalState law, for its own residentsWhat happened to residents’ personal information
HHS Office for Civil RightsHIPAA, where health data is involvedProtected health information sent to a vendor
Opposing counselDiscovery, not the privacy policyWhat you pasted, and any copy that still exists
A client’s security questionnaireThe client’s own questions, not the privacy policyWhat you pasted

Summarized from this guide as of September 19, 2026: the FTC post of January 9, 2024, HIPAA through HHS, and the preservation order in the copyright case.

The FTC, deception, and a policy that changed

The FTC’s Office of Technology published a post on January 9, 2024, aimed squarely at companies that host models for others. Its last line is the one to keep: there is no AI exemption from the laws on the books.

What it says in the middle is more useful still. Companies that retain or use consumer data for other purposes without clear and conspicuous notice and affirmative express consent, for example by surreptitiously changing terms of service or a privacy policy, or by burying a disclosure behind hyperlinks, in legalese or in fine print, risk running afoul of the law.

That is the standard against which a dated policy change gets read, and it is why the date on the document matters as much as the words. It also tells you what the FTC is not doing. Its only open study of consumer chatbots, 6(b) orders sent to 7 companies on September 11, 2025, is about children and teens, not about your client files.

7 companies
received the FTC's 6(b) orders on AI companion chatbots on September 11, 2025, on effects on children and teens. Nothing comparable is open on business confidentiality

If you are in California, or you have California clients, section 1798.135 of the Civil Code requires a business that sells or shares personal information to give consumers a clear and conspicuous way to stop it. OpenAI’s US policy points to the marketing privacy control in account settings, the Your Privacy Choices link on its site, and Global Privacy Control.

The practical version is short. Turn the control off once, and turn on Global Privacy Control in the browser your firm standardizes on, which covers every other site at the same time. Neither of those touches what happens to a prompt, which no state statute currently regulates.

What a tool can do here, and what no tool can do, including ours

Software of this kind can mask identifiers before the text is sent, because identifiers sit in predictable places and follow recognizable formats. It can show what it changed so a human can overrule it, and it can leave a record that the control was on.

It cannot decide that a document is too sensitive to send at all. It cannot notice that a paragraph identifies a client through facts rather than names. And it cannot make you compliant, because compliance is not a property software has.

What our engine does and does not do in the United States

An SSN next to its label, or written with its usual dashes, is masked before the text leaves, and so is an EIN behind the words employer identification number and a Medicare beneficiary identifier behind MBI. All three become a general REFERENCE tag, never the digits.

An email address and a valid payment card number are replaced without asking, because their format leaves no doubt.

Nonimo runs on the computer itself, on Mac and Windows, and IT sets the policy step for the whole firm rather than for each user. What it replaces, it replaces reversibly, keeping the mapping encrypted on the user’s own computer. That is pseudonymization rather than anonymization, and it is how our pages for organizations describe it too.

What the app keeps on your disk is on Nonimo’s security page.

If you buy nothing at all, do these five things

  1. Decide which account your people sign in with, and verify it. It changes the contract that governs their text and it costs nothing.
  2. Turn off training on every consumer account, then check it on a second device. The setting applies to the whole account, and people assume rather than confirm.
  3. Tell people what the thumbs up and thumbs down buttons send. No setting covers feedback, and the button does not look like a disclosure.
  4. Write the never list. Five lines naming the document types that may never be pasted. Yours will name things nobody else can guess.
  5. Note the date you checked. These policies changed on January 8, February 6 and September 10 of this year alone.

A firm that does all five is in better shape than one that bought software and did none of them. If a technical control later looks worth it, the license terms say what ours is and is not.

Two things you will read elsewhere that are wrong today

We checked both claims below against the current documents on September 19, 2026.

The first is that OpenAI does not share your data for advertising. That was true of the policy Americans were served until this month, and it is still true of the policy for the rest of the world, dated February 6, 2026. It is no longer what the US policy of September 10, 2026, says, and pages that state it flatly are quoting the wrong document.

The second is that a paid plan stops the training. It does not. Plus and Pro carry the same consumer default as Free, and the same way to opt out; the change happens at ChatGPT Business, which is a different product with a different contract. The comparison pages that put a padlock next to the paid tier are describing ads and rate limits, not training.

Both errors have the same shape, and it is the shape to watch for whenever you read about ChatGPT data privacy. A true sentence gets copied forward past the date it stopped being true, and nobody checks, because the page it was copied from still reads perfectly well. Every claim in our own guides carries the date we read the source, for exactly that reason, and this one will need rereading too.

Sources

Checked September 19, 2026. OpenAI’s own domains return 403 to tools run from the command line and load normally in a browser, which is a measure against bots rather than a dead link; each page below was opened and read.

The same questions for the other three assistants: does Claude train on your data, what Gemini does with your data, and does Microsoft Copilot train on your data.

Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.

Common questions

Does ChatGPT sell your data?

No. OpenAI covers ChatGPT data privacy in two policies, and both say it does not sell your data. The US policy, updated September 10, 2026, adds that it may share limited data with select marketing partners for targeted advertising, which is a different thing, and you can opt out of it.

Is ChatGPT confidential?

No, not in the sense a lawyer or accountant means, and how private it is depends on the account. On Free, Go, Plus and Pro, OpenAI may train on your conversations by default unless you turn that off. On Business, Enterprise, Edu and the API it does not train by default, but it may still scan the text with automated classifiers, and on Business your workspace admins can read it. Your duty of confidentiality to a client stays yours.

Does ChatGPT share your data with anyone?

Yes, in defined categories: vendors and service providers, affiliates, government authorities under legal process, your workspace administrator if you have a business account, and marketing partners if you have not opted out.

Does ChatGPT save your conversations?

Yes, until you delete them. Once you delete a conversation or your account, OpenAI states it removes the data from its systems within 30 days, unless it is legally required to keep it or it has already been deidentified.

Does ChatGPT train on what I type?

On consumer accounts, yes by default, and you can turn it off under Settings then Data Controls. On ChatGPT Business, Enterprise, Edu, Healthcare, Teachers and the API, OpenAI states it does not train by default.

If I turn training off, is my data private?

It removes one use of your text. OpenAI still keeps the conversation in your history, still runs it through automated classifiers, and still discloses it under valid legal process. Turning training off does not undo a disclosure.

Can my employer read my ChatGPT conversations?

On ChatGPT Business, yes. OpenAI states that workspace admins can view, access, export and delete their users' conversations. On Enterprise and Edu, admins reach conversations through the Compliance API audit log instead.

Where does OpenAI store my data?

On servers in various jurisdictions, including its own facilities in the United States, according to its privacy policy. For a US firm this is rarely the question that decides anything, because there is no federal data regulator to complain to.

How do I delete my ChatGPT history?

Delete individual chats, or use Settings then Data Controls to delete your account. OpenAI states deleted data leaves its systems within 30 days, with exceptions for legal holds, banned content and financial records.

Is ChatGPT safe for confidential client information?

No chatbot setting makes a disclosure safe. Once client text reaches a provider it has left your control, which is a question for your own duty of confidentiality rather than for the provider's privacy policy.