Is ChatGPT safe for your business? What happens to your data

Jack 17 JULY 2026 11 min read

ChatGPT is safe to use. Whether it’s safe for your business comes down to two things: which account you’re on, and what you paste into it.

The usual answer, “safe as long as you don’t share sensitive information”, is true and close to useless, because sharing information is the whole point of the tool. Samsung found the sharp end of that in 2023: within 20 days of letting staff use ChatGPT, engineers had pasted semiconductor source code into it to debug and fed it recordings of internal meetings, three leaks in under three weeks, and the company banned the tool outright. So here’s the specific version: what OpenAI stores, for how long, who can see it, what a court has already pulled out of it, and the one change that turns a personal ChatGPT into something you can run a business on.

Start with the split that decides everything. Free, Plus and Pro are consumer accounts. By default they train OpenAI’s models on what you type, and, as you’ll see below, a court has already reached into them. ChatGPT Business and Enterprise are a different animal, with a contract behind them. Most owners are on a personal account doing company work, and that mismatch is the actual problem, not ChatGPT itself.

What ChatGPT does with your data

Yes, ChatGPT saves your chats, and it keeps them until you delete them, not for a tidy 30 days. That 30-day figure gets repeated everywhere and it’s the wrong end of the stick. Every conversation sits in your account indefinitely until you remove it. When you delete a chat it disappears from your account immediately and is scheduled to be wiped from OpenAI’s systems within 30 days, per OpenAI’s retention policy, unless they’re legally required to hold it. Thirty days is the deletion window, not a storage limit. Anything you don’t delete, they keep.

Three things are worth writing down. Temporary Chat, the incognito-style mode, isn’t saved to your history, is deleted within 30 days, and is never used for training, so it’s the right mode for a sensitive one-off. Memory now runs at two levels, and both outlive a deleted chat: the list of facts it explicitly saves about you, and, since April 2025, a setting that lets ChatGPT draw on your entire past chat history by default, on Free, Plus, Pro and Business alike (Enterprise ships with it off unless an admin turns it on). Deleting a conversation clears neither; you clear memory yourself under Settings, and until you do, the model can carry something you told it months ago into a chat you thought was fresh. And files you upload live in a Library managed apart from your chats, so deleting the chat doesn’t delete the document you fed it.

It trains on your chats, unless you turn that off

On a personal account, ChatGPT uses your conversations to train OpenAI’s models by default. Free, Plus and Pro all do it unless you opt out: Settings → Data Controls → switch off “Improve the model for everyone”. Two things that toggle doesn’t do. It doesn’t reach backwards, so anything already used for training stays in the model. And it doesn’t shorten retention, your chats still sit on the servers for the 30-day window after you delete them.

The toggle is a setting you’re granted, not a contract you hold, and that gap is the whole of the AI sovereignty question. On the business tiers further down, no-training is the default and it’s backed by an agreement rather than a checkbox that OpenAI could reword tomorrow.

The delete button doesn’t bind a judge

Deleting a chat clears it from your account, but it can’t clear it from a court, and that stopped being hypothetical in 2025. In May of that year, a federal judge in the New York Times’ copyright case against OpenAI ordered the company to preserve every consumer ChatGPT log that would normally be deleted, including chats users had already deleted and Temporary Chats. For about four months, “I deleted it” was not true.

The order covered Free, Plus, Pro, Team and the API without a zero-retention agreement. It did not cover ChatGPT Enterprise, Edu, or API customers on zero data retention, the tiers with the strongest contracts. OpenAI’s obligation to retain everything ended on 26 September 2025 and normal 30-day deletion resumed, but the company still holds a locked snapshot of April-to-September 2025 conversations, and in January 2026 a judge affirmed an order to hand 20 million de-identified logs from it to the plaintiffs under a protective order.

OpenAI’s own CEO says the quiet part out loud. In July 2025 Sam Altman warned that a conversation with ChatGPT carries none of the legal privilege a talk with a doctor or lawyer does, so if it came to a lawsuit “we could be required to produce that.” He called the situation “very screwed up,” which it is, but the takeaway isn’t a policy debate. When the company selling you the tool tells you your chats aren’t privileged and could be handed to a court, take it at face value.

You don’t need to follow the litigation. The lesson is the single line that outlives it: once your words are on someone else’s server, your delete button is a preference, not a guarantee.

Delete clears your view, not the record. On a consumer account, a chat you erased can still be reached by a court, reviewed by staff, or caught in a bug. None of that makes ChatGPT unusable. It makes a personal account the wrong place for anything you would genuinely never want preserved.

Who can actually see your conversations

Your chats don’t leak to other users when the model answers them, which is the fear most people carry and the one least worth carrying. The model isn’t reciting your data to strangers; that isn’t how it works. For a plain walkthrough of what does and doesn’t happen to a prompt after you hit send, this explainer covers it well: AI & Privacy: What Happens to Your Data After You Paste It Into ChatGPT.

The real exposures have come from features and bugs, not the model. In March 2023 a bug in a software library let some active users see other people’s chat titles, and briefly exposed the name, billing address and last four card digits of roughly 1.2% of Plus subscribers. In August 2025, an experimental “make this chat discoverable” option on shared links let Google index thousands of shared conversations, some carrying names, emails and resumes; OpenAI killed the feature within days. Both were fixable, and fixed. But they tell you where the risk sits: in the sharing button and the occasional bug, not in the chat box.

That pattern has a 2026 edge worth knowing if you connect ChatGPT to your other tools. In September 2025 researchers at Radware demonstrated an attack they named ShadowLeak: a booby-trapped email, with instructions hidden in white-on-white text, that told ChatGPT’s research agent to quietly pull data out of a connected Gmail inbox and send it to the attacker, with no click from the user. OpenAI patched it and it was never used in the wild, but it’s the shape of the risk now: the danger isn’t the chat box, it’s what you wire into it. Every connector you switch on, Gmail, Drive, your calendar, is another door, and prompt injection, hiding commands inside content the AI reads, is an unsolved problem across every AI vendor rather than a single bug that stays fixed. If you turn connectors on for a business account, turn them on deliberately, not by default.

One thing is always the case: OpenAI staff can review conversations when they need to, for abuse, safety or legal reasons. It isn’t a free-for-all, but “nobody at OpenAI can ever see this” was never the deal.

The biggest breach wasn’t OpenAI’s fault

The largest haul of ChatGPT logins ever found on the dark web had nothing to do with an OpenAI hack. In 2023, security firm Group-IB found credentials for 101,134 ChatGPT accounts for sale in the logs of information-stealing malware. The passwords weren’t taken from OpenAI. They were lifted from people’s own infected computers, scraped straight out of the browser where they’d been saved.

That reframes account security as your job, not OpenAI’s. Your ChatGPT account is only as safe as the device you log in from and the password guarding it. A strong, unique password and two-factor authentication in Settings close the door that actually gets used.

Lock down a personal account in ten minutes

If you’re staying on Free or Plus, a handful of settings get it as private as a consumer plan goes:

  1. Turn off training: Settings → Data Controls → switch off “Improve the model for everyone”.
  2. Use Temporary Chat for anything sensitive you only need once. Nothing is saved, nothing trains the model.
  3. Clear your Memory and check what it’s holding, under Settings, and turn off “reference chat history” if you don’t want ChatGPT drawing on old chats. Deleting chats doesn’t clear either.
  4. Turn on two-factor authentication, so a stolen password alone can’t get in.
  5. Review the apps and custom GPTs you’ve connected, and revoke anything you don’t use.
  6. Never use a share link for anything you wouldn’t post publicly, and delete old shared links you’ve made.
  7. Delete chats you no longer need, remembering the 30-day window before they leave the servers.

That’s the ceiling for a personal account. It’s real, and it’s still a setting away from being undone.

The real fix for a business: get off the personal account

The single change that beats every setting above is moving company work off a personal account and onto ChatGPT Business. This is the move most owners skip, and it’s the one that matters.

ChatGPT Business, renamed from ChatGPT Team in August 2025, runs about $20 per person a month on annual billing or $25 month to month, with a two-seat minimum (prices move, so check the live page). For that you cross from consumer defaults to a business footing: OpenAI doesn’t train on your data by default, you can sign a data processing agreement you’d be happy to show a client, and the account is covered by a SOC 2 Type 2 audit with AES-256 encryption at rest and TLS in transit. Enterprise stacks admin controls, single sign-on and your own encryption keys on top, and was one of the tiers, with Edu and zero-retention API, that sat outside the court’s preservation order.

The question owners always ask: on a business plan, can I read my team’s chats? On Business, no. Each person’s history stays private to them and there’s no admin export, which is the right answer for trust. Enterprise is where admins gain compliance tools that can reach conversation content for audits and legal holds, so if you actually need that oversight, that’s the tier that carries it, not Business.

That one move does more for your data than any checkbox, because it changes no-training from a setting you toggle into a term of your contract. Which of the big assistants to standardise on is a separate decision, covered in ChatGPT vs Claude vs Gemini; on data handling they all draw the same consumer-versus-business line.

What to keep out of it entirely

Even on a business tier, some things don’t belong in a general AI tool at all. A no-training contract stops your data becoming training material. It doesn’t make the tool the right home for your crown jewels, the pricing logic, the full client dataset, the methodology that makes your business worth more than the one down the road, or for data you’re legally bound to protect, like health records or matters under legal privilege.

The courts and the regulators are drawing that same line, and the sovereignty guide walks through where it sits and what your professional body has probably already said about client data in a public chatbot. When data genuinely can’t leave your walls, the answer isn’t a better subscription, it’s running a model on hardware you own: our private transcription build and the self-hosted AI piece show what that takes.

The verdict

ChatGPT is safe for your business when you match the account to the data. On a personal Free or Plus account it trains on your chats by default and a court has shown it can be reached, so keep those accounts to work you wouldn’t mind being seen. For anything with a client’s name on it, move to ChatGPT Business, get the data processing agreement on file, and turn training off from habit. Keep the few things that make your business yours out of any third-party tool. Do that, and the answer to “is ChatGPT safe” is straightforward: safe enough for most of what you do, on the right account, with your eyes open. It sits alongside the rest of the small-business AI shortlist, which covers the tool to reach for in every other job.

Questions people ask

Is ChatGPT safe to use for a business?
Yes to use, but the risk is the account you're on and what you paste. Free, Plus and Pro are consumer accounts that train on your chats by default, so on those, treat anything you type as if someone could read it one day. Move company work to ChatGPT Business or Enterprise, where OpenAI doesn't train on your data and you get a signed agreement, and it's safe enough for most of what a business does.
Does ChatGPT save your data?
Yes. Your chats are saved to your account and kept until you delete them, not for a fixed 30 days. When you delete one it leaves your account immediately and is scheduled to be wiped from OpenAI's systems within 30 days. Temporary Chat isn't saved to your history and auto-deletes within 30 days, and it's never used for training.
Does ChatGPT use my conversations to train its models?
On Free, Plus and Pro, yes, by default. You can turn it off in Settings, Data Controls, by switching off 'Improve the model for everyone'. The toggle only affects future chats and doesn't shorten how long data is stored. ChatGPT Business, Enterprise and the API don't train on your data by default, no toggle needed.
Can other people or OpenAI staff see my ChatGPT conversations?
The model doesn't recite your chats to other users, so that common fear is the least worth holding. OpenAI staff can review conversations for abuse, safety or legal reasons. The real exposures have come from features, not the model: a 2023 bug, an old share-link feature that let Google index chats people had shared, and, in 2025, a researcher demo that pulled data out of a connected Gmail inbox through ChatGPT's own agent. All were fixed, but they show the risk sits in what you plug in, not the chat box.
If I delete a ChatGPT conversation, is it really gone?
From your account, yes, immediately, and from OpenAI's systems within 30 days under normal conditions. But a court order in the New York Times case forced OpenAI to preserve a snapshot of April to September 2025 conversations, including ones users had deleted. Delete clears your view; it doesn't override a judge.
Is ChatGPT Business or Enterprise safe for company data?
For most business data, yes. Neither trains on your data by default, both come with a data processing agreement, and they're covered by a SOC 2 Type 2 audit with AES-256 encryption at rest and TLS in transit. Keep the exceptions out: regulated data like health records, and the crown-jewel material that makes your business worth more than a competitor's.

Rather have it built for you?