Is ChatGPT Private? What OpenAI Does With Your Data
Is ChatGPT private? What OpenAI states about training, retention and deletion for consumer, business and API use.
It depends on the plan. OpenAI states that business customer content in ChatGPT Business and ChatGPT Enterprise is not used to train its models by default, and that data sent to the API is not used for training unless you opt in. For consumer ChatGPT, this post could not read OpenAI's own pages, so it does not state the defaults as verified. By default your prompts are also stored on OpenAI's systems for some period (the API documentation describes up to 30 days for abuse monitoring logs), which is why "private" needs a definition before you can answer it. Last verified 2026-10-07.
What could be verified, and what could not?
Be clear about the evidence first. On 2026-10-07 the pages on openai.com and help.openai.com, including the privacy policy, the business data page, the enterprise privacy page and the help-centre articles on data controls and Temporary Chat, returned HTTP 403 to automated requests. This post therefore does not quote them.
What could be opened, and is used below:
- OpenAI's developer documentation page "Data controls in the OpenAI platform", which covers the API.
- An OpenAI Academy resource on data governance for ChatGPT Enterprise and Business, shown as last updated on 17 September 2026.
- OpenAI's Private Safety Processing documentation.
- A court filing hosted by OpenAI, dated 10 December 2025.
Where a statement belongs to a page that could not be opened, this post says "not verified". Read the current OpenAI privacy policy and your own contract before you rely on any retention period, including the ones below.
What does OpenAI state for each plan?
| Plan | Training on your content by default | Retention as stated | Status |
|---|---|---|---|
| Consumer ChatGPT (free and paid individual plans) | Not verified: the help-centre pages could not be opened | Not verified | Read the Data controls and Temporary Chat articles in the OpenAI help centre |
| ChatGPT Business and ChatGPT Enterprise | "By default, OpenAI does not use business customer content from ChatGPT Enterprise and ChatGPT Business to train its models." | "By default, chats are saved indefinitely to the user's account until they delete them." Enterprise Owners can set a custom retention policy for the workspace, with a minimum of 90 days | Read on the OpenAI Academy page, updated 17 September 2026 |
| ChatGPT Edu | Not verified: not covered by the pages that could be opened | Not verified | Ask OpenAI, or read the Edu terms |
| API platform | "data sent to the OpenAI API is not used to train or improve OpenAI models (unless you explicitly opt in to share data with us)" | Abuse monitoring logs "retained for up to 30 days"; stored application state described below | Read on the developer documentation page |
Two further statements from the API page matter. Eligible customers can have their content excluded from abuse monitoring logs through Zero Data Retention or Modified Abuse Monitoring, which need approval and do not cover every endpoint. And the Responses API "has a 30 day Application State retention period by default, or when the store parameter is set to true". The same page says retention may be longer where "longer retention is required by law, or is reasonably necessary to protect our services".
The Academy page also says that business plans offer encryption of data at rest and in transit.
Does a human read my chats?
Not verified for consumer ChatGPT: the pages that would say so could not be opened. For the API, the developer documentation describes abuse monitoring logs, which exist so that misuse can be detected, but the page excerpt read here does not say who reviews them. OpenAI's Private Safety Processing documentation describes a different option for approved Zero Data Retention customers: offline, automated safety review "without OpenAI retaining customer prompts or responses", in "a hardware-attested computing environment that disables human access". That is an opt-in control, not the default.
If human review matters to you, ask the vendor in writing which categories of content can be seen by staff or contractors, under what conditions, and for how long.
Can a court make OpenAI hand over chats?
Stored conversations can be the subject of court orders. A filing hosted by OpenAI, dated 10 December 2025, in the US copyright litigation against it in the Southern District of New York, describes orders directing OpenAI to produce 20 million de-identified consumer ChatGPT logs to the news plaintiffs and then to the class plaintiffs. It gives 10 November 2025 as the date the initial order was entered and 3 December 2025 as the date reconsideration was denied. OpenAI objected on privacy grounds. The filing also says OpenAI compresses conversation logs into long-term offline storage.
This post could not confirm from OpenAI's own pages whether any preservation order is in force today, or how the case has moved since December 2025. Treat that as not verified. The practical point does not depend on the outcome: if a provider stores your content, that content can be reached by legal process in the provider's jurisdiction. For the jurisdiction question in general, see sovereign AI versus private cloud.
What would "private" actually mean?
Five questions turn the word into something you can test.
- Storage. Where is the content stored, for how long, and who controls deletion? OpenAI's API page lists data residency regions: United States, Europe (EEA and Switzerland), Australia, Canada, Japan, India, Singapore, South Korea, United Kingdom and United Arab Emirates. That list is for the API platform; residency terms for ChatGPT plans are not verified here.
- Access. Who can read it: your staff, the vendor's staff, subcontractors?
- Training. Can it be used to improve models, and is the default opt-in or opt-out?
- Jurisdiction. Which courts and agencies can compel the provider?
- Audit. Can you show who sent what, to which model, when, and what was removed first?
A plan can be strong on one and silent on another. A business tier that does not train on your content still stores it, and the storage is still reachable by the provider's legal process.
What are your options?
| Option | What it gives you | What it does not change |
|---|---|---|
| Vendor business tier or API with data controls | Contractual no-training default, admin controls, retention settings, in some cases residency | Content still sits with the vendor and is subject to its jurisdiction |
| Zero Data Retention, where approved | Content excluded from abuse monitoring logs on eligible endpoints | Eligibility and endpoint coverage are limited; approval is the vendor's decision |
| A gateway with redaction in front of the vendor | Secrets and personal data removed before the prompt leaves your control; one place to audit | The redacted prompt still reaches the vendor, and the gateway becomes another party in the path |
| Self-hosted or local models | Prompts stay on hardware you control | You carry the operations, the model quality gap and the security work |
Most organisations end up mixing these by data class: public and low-risk text to a vendor tier, regulated or confidential material to a controlled path. A first step is to find out what staff already paste into consumer tools. See shadow AI for how that discovery works.
Where does Swfte fit?
Swfte makes no claim to be more private than any vendor. It offers some of the control points above, with these statuses.
- Connect is one OpenAI-compatible API with bring-your-own-key access to model providers, a content-policy layer with built-in secret and personal-data detectors and a redact action, and an audit event stream. Status: Built. It adds Swfte to the path of the request, so read Trust and the subprocessor list before you route sensitive traffic through it. See Connect.
- Cortex is a desktop app that runs local models through Ollama and LM Studio and keeps knowledge bases and retrieval on the device. Status: Built. See how to run LLMs locally.
- Private deployment in your own environment is designed for, and offered on request through a dedicated deployment engagement. See dedicated cloud. It is not a self-serve product.
- Customer data on Swfte's hosted platform is stored in AWS eu-west-1 (Ireland), as set out on the Trust page. Swfte does not claim certification or compliance on this page.
You do not need Swfte for a vendor business tier, an API with Zero Data Retention or a local model run. If you want an open alternative to ChatGPT that you host yourself, read how to self-host a ChatGPT alternative.
Sources and last verified
Last verified 2026-10-07. Every dated or technical fact in this post was read from the pages below on that date. Anything that could not be confirmed is left out or marked as not verified.
- OpenAI: data controls in the OpenAI platform. API training default, 30-day abuse monitoring logs, Zero Data Retention and Modified Abuse Monitoring, Responses API application state, data residency regions.
- OpenAI Academy: data governance and compliance. ChatGPT Business and Enterprise: no training on business content by default, retention until deleted, custom retention minimum of 90 days, encryption. Page shown as updated 17 September 2026.
- OpenAI: Private Safety Processing. Offline automated safety review without retaining prompts or responses, for approved Zero Data Retention customers.
- OpenAI-hosted court filing, In re OpenAI Copyright Infringement Litigation, document 935, 10 December 2025. Orders to produce 20 million de-identified consumer ChatGPT logs, their dates, and the description of long-term compressed log storage. A party filing, not a policy page.
Frequently asked questions
Is ChatGPT private?
It depends on the plan and on what you mean by private. OpenAI states that business customer content in ChatGPT Business and Enterprise is not used for training by default, and that API data is not used for training unless you opt in. Content is still stored for a period, and a provider can be compelled by legal process. For consumer plans, this post could not verify the defaults.
Does OpenAI train on my ChatGPT conversations?
For consumer ChatGPT this is not verified here, because OpenAI help-centre pages returned HTTP 403 to automated requests on 2026-10-07. Read the Data controls article in the help centre for the current setting. For ChatGPT Business and Enterprise, an OpenAI Academy page updated on 17 September 2026 says OpenAI does not use business customer content to train its models by default.
How long does OpenAI keep ChatGPT Business and Enterprise chats?
By default, chats are saved indefinitely to the account until the user deletes them, according to an OpenAI Academy page updated on 17 September 2026. Enterprise Owners can set a custom data retention policy for the workspace, with a minimum of 90 days. That page does not give retention terms for the consumer plans or for ChatGPT Edu, so those are not verified here.
Does Zero Data Retention mean OpenAI stores nothing?
No. OpenAI states that Zero Data Retention excludes customer content from abuse monitoring logs in the same way as Modified Abuse Monitoring, and that eligible customers need approval. The same documentation says ineligible endpoints or capabilities may retain application state even when Zero Data Retention is enabled. Check the eligibility list for each endpoint you plan to use.
Can a court access my ChatGPT conversations?
Stored conversations can be the subject of court orders. A filing hosted by OpenAI and dated 10 December 2025 describes orders to produce 20 million de-identified consumer ChatGPT logs in US copyright litigation, which OpenAI objected to. Whether any preservation order is in force now is not verified here. The general point is that data held by a provider can be reached by legal process in its jurisdiction.
How can you reduce what a model vendor sees?
Combine controls by data class. Use a business tier or API with the no-training default for ordinary work, Zero Data Retention where approved, a gateway that redacts secrets and personal data before the prompt leaves your control, and local or self-hosted models for the most sensitive material. Each step reduces exposure but adds work, so decide the data classes first and match the route to each.
Does Swfte make AI use private?
Swfte does not claim to be more private than any vendor. Connect, which is Built, adds bring-your-own-key access, content-policy detectors for secrets and personal data with a redact action, and an audit stream, but it also puts Swfte in the request path. Cortex runs local models on the desktop. Private deployment is designed for and offered on request. See the Trust page for hosting and security statements.