Privacy 101: what ChatGPT remembers, sees, and shares
New to AI7 min readAI Safety & Data Privacy

Privacy 101: what ChatGPT remembers, sees, and shares

Separate training, memory, storage, and third-party sharing. Check the controls that affect your account without treating Temporary Chat or a paid plan as permission to share sensitive data.

What you should be able to do

Not used for training does not mean not stored. Turning off memory does not erase its sources. Check the exact account, data, and recipient before sharing anything sensitive.

Saved only in this browser.
In this article

A private-looking chat window does not tell you who processes its contents, how long copies remain, or whether a connected service receives them. Those are different questions. You can make a useful privacy decision without assuming either that everything becomes public or that one setting makes every upload safe.

This guide covers ChatGPT, with consumer and business-account differences called out. Do not transfer its settings or retention promises to Claude, Gemini, or Copilot.

Documentation checked on 5 September 2026 in an AI-assisted update. This is not a new named-human review, hands-on product test, or legal review. Controls can vary by account, workspace, platform, and rollout.

What gets stored

Start with four separate questions:

QuestionWhat to check
Can my content be used for model training?Account data controls and any separate sharing choice
Can it personalize later answers?Memory, instructions, and sources available to the account
Where do copies remain?Chats, archives, Library files, projects, and retention terms
Does another organization receive it?The specific app or action and its recipient’s terms

Ordinary chats stay in your account until you delete them. Archiving hides a chat without deleting it. Deletion removes it from the account and normally schedules system deletion within 30 days, with exceptions for already de-identified data and security or legal obligations. It is not an instant erase-everywhere operation.

Where Library is available, uploaded files saved there are separate from their chats: deleting the chat does not delete the Library file. Files attached to projects or custom GPTs have their own lifecycle too. Check the relevant storage location instead of assuming the sidebar represents every copy.

Training, personalization, storage, and sharing are separate controls. Turning one off does not prove the others are off or erase information already sent.

What gets used for training

For individual services, OpenAI may use content for model training; opting out applies to new conversations. Open Settings → Data Controls and turn off “Improve the model for everyone” if that is your preference. The Data Controls FAQ says this account-wide choice leaves chat history available. Do not interpret it as undoing earlier training.

There is a separate feedback exception: even after opting out, submitting feedback can allow the associated conversation to be used for training. Avoid sending feedback on a conversation containing information you must not share for that purpose.

Business, Enterprise, and API products are not used for training by default unless an organization explicitly opts in. That training rule does not establish zero storage, no provider access, or your employer’s approval. Workspace controls and API retention need their own assessment.

A paid personal subscription is not the same as an organization-approved account. Check the exact service and terms; other providers’ defaults differ.

What memory does

Memory can personalize answers using context from chats, files, and connected apps. Its summary is not a complete inventory of everything the system may use. Review Settings → Personalization → Memory and any available source indicators.

To remove information, check every place it occurs: memory, past and archived chats, files, and connected apps. Clearing memory does not delete the chats that supplied it. If you later re-enable personalization, retained sources may become relevant again. Older memory controls can look different; follow the documentation for your account.

Keep reusable preferences low risk, such as language or units. Do not put credentials, customer records, or confidential work context into personal instructions or memory. The custom instructions and memory guide explains the difference.

What “chat history” does

The sidebar is a way to revisit saved conversations, not a complete retention report.

Temporary Chat starts without personalization; you can choose personalization when starting it. It creates no memories and is not used for training while temporary, but OpenAI may retain a safety copy for up to 30 days. Saving it converts it to a regular chat governed by your account settings. Limited safety context can still apply.

Treat Temporary Chat as a specific control, not permission to enter secrets or a guarantee that nothing leaves the service. Inspect personalization and any external capabilities before using them.

Eligible accounts can request an export through settings or the privacy-request process. Do not assume it contains every artifact the provider holds. Inspect and protect the archive. Business and Enterprise users should ask their workspace owner about available processes rather than expect the consumer export option.

The three checks worth making today

Repeat these checks when the account, task, or data changes.

  1. Training and feedback: confirm your preference and remember that feedback is a separate sharing choice. This does not approve work data for a personal account.
  2. Reusable context: review memory, custom instructions, and their sources. Use a harmless preference to explore personalization; do not repeat a secret to test whether it was deleted.
  3. Copies and recipients: check chats, files, and external services. If you accidentally shared work data, follow your organization’s incident process before deleting potential evidence. Removing a chat does not undo transmission.
A closed document folder sits beside a phone and a small note sheet.
AI-generated illustration accompanying “The three checks worth making today”.

Personal account vs work account

The exact tool, tenant, account, workflow, and data category need approval. A work email address, training opt-out, or enterprise label is not sufficient by itself.

DataA cautious starting point
Public text or wholly invented practice dataUse within the tool’s terms and your organization’s policy
Internal documents or customer informationOnly through a process approved for that data
Credentials, keys, or security incidentsStop and use the responsible security team’s process
Health, legal, financial, or family detailsMinimize disclosure and seek the appropriate qualified help

Replacing names does not necessarily make a document anonymous. Dates, roles, locations, or unusual events may still identify someone. For learning, invent an example rather than lightly disguising a real person’s record.

Use the work-data checklist and work-secrets guide to prepare questions. Neither can grant permission on your employer’s behalf.

What still falls through the cracks

Provider access: OpenAI’s consumer data-usage FAQ describes controlled access by authorized personnel and service providers for support, security, legal matters, and permitted model improvement. Opting out of training does not mean nobody can access stored content.

External recipients: data sent through a GPT action follows the recipient’s policy, which can permit retention beyond Temporary Chat’s 30-day window. Check the recipient and whether that transfer is approved.

Account access: protect your account and recovery methods. Someone with access may be able to read retained content. Avoid sharing a personal account.

Changing terms: recheck when you enable a feature, switch accounts, or receive a policy change. A setting checked today is not a permanent guarantee.

A simple mental model

Before submitting a prompt, complete this sentence:

“I am sending this data to this recipient through this approved account for this specific purpose.”

If you cannot identify the data, recipient, or authority to share it, stop. Use public or invented material, ask the responsible person, or leave it out.

Try this with a fictional support ticket containing no real identifiers. Decide which details the task needs, choose an account, and answer the four questions in the first table. The useful result is a decision you can explain, not the assistant’s assurance that it is safe.

A specific note for European users

Where GDPR applies, rights can include access, correction, erasure, and restrictions on processing, subject to conditions.

The European Data Protection Board explains that erasure is not unconditional. Legal obligations or legal claims can be grounds for retaining data. Use the provider’s privacy-request route and contact the relevant data-protection authority if you need help.

A request is not proof that every copy has immediately disappeared. This is general educational guidance, not a determination of your legal entitlement in a particular case.

In short

Check training, reusable context, copies, and recipients separately. Use approved processes for work data. Temporary Chat changes specific behavior; it does not remove your responsibility to decide what you may share.

Read next

Continue through the same learning path with the next practical articles.