ChatGPT Data Privacy: What Happens to What You Type

Photo: Mateusz Dach / Pexels
Key takeaways
- ChatGPT Free and Plus train on your chats by default; Team, Enterprise and the API don't.
- Deleted consumer chats are typically purged from OpenAI's systems roughly 30 days later, not instantly.
- Only Team, Enterprise and API accounts come with a GDPR Data Processing Agreement.
- Switching tiers protects data going forward only; it doesn't retroactively remove what a personal account already sent.
- The safest rule for a small team: use the company workspace, never a personal account, for anything work-related.
ChatGPT data privacy comes down to one question with a tier-dependent answer: what does OpenAI actually do with what you type? A personal free account and a business workspace sit on opposite sides of the same product, and the gap between them is the whole privacy story. Get the tier right and most of the risk disappears; get it wrong and a marketing brief or a client's phone number can end up shaping a model nobody at your company controls. This guide sets out what happens to your data on each ChatGPT tier, how long it sits on OpenAI's servers, and the one rule that keeps a small team safe without banning the tool outright. It also covers the SOC 2 and vendor-review angle that increasingly forces the question, because 'which AI tools do you use, and how' has become a standard line in security questionnaires.
Free and Plus: training is on by default
On the consumer tiers, Free and Plus, OpenAI may use your conversations to improve its models unless you switch off 'Improve the model for everyone' in data controls. Most people never find that toggle, let alone flip it. That means a sales rep drafting a pitch on a personal Plus subscription, or an intern summarising a contract on the free tier, can hand a slice of company information straight into a training pipeline. This is the classic shadow-AI trap: nobody decided to share the data, it just happened by default, and there is no easy way to claw it back afterwards. Shared conversation links and custom GPTs built on a personal account carry the same exposure: anything fed into them sits under the same consumer terms, which is easy to forget once a GPT feels like 'your own' tool rather than someone else's product.
Team, Enterprise and the API: not used for training by default
OpenAI states that it does not train its models on inputs or outputs from ChatGPT Team, ChatGPT Enterprise, or the API platform by default. These tiers also add admin controls, a Data Processing Agreement for GDPR, and, on Enterprise, single sign-on. For any work touching client data, personal data or unreleased plans, Team is the realistic floor, and Enterprise adds the access controls a larger or regulated team will eventually need. OpenAI also lists SOC 2 Type II compliance for these tiers, which is usually the first thing a customer's security team checks before signing off on a new vendor. See OpenAI's enterprise privacy commitments for the current detail.
How long does ChatGPT keep your conversations?
Retention is a separate question from training, and it's worth treating it as one. Consumer chats stay on OpenAI's servers until you delete them, and deleted conversations are typically purged roughly 30 days later, not instantly. The API defaults to around 30 days of logging, with Zero Data Retention available on a subset of eligible endpoints. Business tiers let admins configure retention directly, so a company can set its own policy rather than rely on OpenAI's defaults; see OpenAI's business data commitments for the current terms. If retention length genuinely matters for your work, say because of a client confidentiality clause, check it rather than assume it.
Does ChatGPT meet GDPR requirements?
For a UK or EU business, GDPR is usually the sharper question than training. OpenAI offers a Data Processing Agreement on Team, Enterprise and API accounts, which is the contractual document that makes OpenAI a processor acting on your instructions rather than an uncontrolled third party. The ICO's guidance on AI and data protection is clear that a lawful basis and a data processing agreement are baseline expectations before personal data goes anywhere near an AI tool. No DPA is on offer for personal free or Plus accounts, which is itself a reason to keep them off company business.
Does switching tiers protect chats you already sent?
No, and this trips people up. Moving from a personal account to a company Team workspace protects everything from that point forward; it doesn't reach back and un-train a model on conversations already sent under the old account. If sensitive information went into a free or Plus account before the switch, treat that as done rather than fixable, and put the effort into making sure nothing new follows the same path. This is usually the more persuasive argument for moving early, rather than waiting for 'once we're bigger'. It's also worth remembering that training and retention are two different clocks: even where OpenAI doesn't use a conversation for training, the conversation itself can still exist in storage until it's deleted, so 'not used for training' is not the same promise as 'not kept'.
A small business, one bad habit
A 12-person recruitment agency ran entirely on personal ChatGPT Plus accounts for eighteen months, drafting candidate summaries, client emails, even redlining contracts. Nobody had decided to do it that way; it was just how the founder started, and everyone copied her. When a client asked, during a routine security questionnaire, whether AI tools touched candidate data and on what terms, the honest answer was 'we don't actually know'. Moving the team onto a shared ChatGPT Team workspace took an afternoon. The harder part was writing down, for the first time, what had already been typed into personal accounts over a year and a half, and accepting that some of it couldn't be un-shared. The agency now flags the decision in its own onboarding for new hires: one line in the day-one checklist, sign into the shared workspace, not a personal account.
Turning the tier decision into a rule
Knowing the facts about ChatGPT tiers doesn't help much if the rule only lives in someone's head. The practical fix is short: everyone uses the company ChatGPT Team or Enterprise workspace for anything work-related, nobody uses a personal account for company or client information, and the approved tier is written down rather than assumed. Our guide to setting a ChatGPT policy for work covers the exact wording teams use for this, because a rule that only lives in one person's head doesn't survive them going on holiday, let alone leaving the company. On Team and Enterprise, an admin can also see which members haven't yet signed in through the workspace, which turns 'we told everyone' into something you can actually check rather than hope.
Check before you assume
The honest way to answer whether ChatGPT is safe for your team is to check which tier they're actually on, not the tier you assume. Our guide to whether ChatGPT is safe for work goes deeper into that comparison, and ChatGPT's full data-handling profile, training, retention, SOC 2 status and DPA, sits in the AI Tool Risk Directory, sourced from OpenAI's own policies. If the tier decision isn't written down anywhere yet, the free policy generator turns it into a short, attestation-ready policy in a few minutes.
| Tier | Trains on your data? | Retention | GDPR DPA available? |
|---|---|---|---|
| Free | Yes, by default (opt-out setting exists) | Until deleted, purged roughly 30 days later | No |
| Plus | Yes, by default (opt-out setting exists) | Until deleted, purged roughly 30 days later | No |
| Team | No, not by default | Admin-configurable | Yes |
| Enterprise | No, not by default | Admin-configurable, plus SSO-based access control | Yes |
| API | No, not by default | ~30 days logging; Zero Data Retention on eligible endpoints | Yes |
“The tier is the privacy policy. Everything else is detail.”