Does ChatGPT save your data? What OpenAI keeps and deletes
· Updated · Written and maintained by Joaquín Trapero, Nonimo
Yes. ChatGPT saves what you type, for a period that depends on which account you signed into and which settings someone has touched. For an Australian practice, though, how long you let ChatGPT save your data is not the interesting part of the question.
The interesting part is that there are two different questions hiding inside one, and almost every page you will read about this answers only the first. One is whether OpenAI learns from your text. The other is whether your text left your office. They have different answers, different controls and, under the Privacy Act 1988, very different consequences.
This page answers both from OpenAI’s own documents, with the dates they carry, and then says what an Australian regulator asks that none of those documents mention. If what you actually want to know is whether a paste is a reportable breach, that is a separate question with its own rules, and it is the subject of our guide to client data and AI breach reporting.
Does ChatGPT save your data?
It does, and OpenAI says so plainly. Its privacy policy, updated 6 February 2026, lists what it calls User Content among the personal data it collects.
We collect Personal Data that you provide in the input to our Services (“Content”), including your prompts and other content you upload, such as files, images, audio and video.
That is one category among several, and the others matter more than people expect. So when a colleague asks “does ChatGPT save my data?”, the useful answer covers what is saved, how long, who can reach it, and which of those things a setting can change.
Our guides to Claude, Gemini and Microsoft Copilot answer the same questions, because the answers are not the same and the differences are the point.
Is ChatGPT confidential?
Not in the sense a client means by the word, and on a personal account not by default. Whether ChatGPT is confidential depends on which account the text goes into, and OpenAI’s own pages, as of 25 September 2026, describe three positions.
OpenAI may train on your conversations unless you turn off "Improve the model for everyone". Turning it off deletes nothing, and the conversations stay in your history.
It stays out of your history and is not used for training while it remains temporary, but OpenAI may keep a copy for up to 30 days for safety purposes.
No training by default, though content may pass through automated classifiers. On Business, OpenAI limits its own access to authorised employees for support, abuse and legal compliance, and to "specialized third-party contractors who are bound by confidentiality and security obligations, solely to review for abuse and misuse". Your workspace admins can view, export and delete conversations.
None of those positions takes over your duty of confidentiality to a client, which stays with you whatever a provider’s policy says. The practical steps are short: use the practice’s business account, turn training off wherever it is on, and keep names, client numbers and file references out of the prompt. Nonimo, a Mac and Windows app, replaces names and identifiers with labels before the text reaches the chat, so the originals stay on your computer.
What OpenAI collects besides the prompt
A conversation is not the only record a session leaves, and the policy is itemised enough to be useful rather than defensive. Read as a list, it tells you what a subpoena could reach.
- Account information, including name, contact details, date of birth, payment details and transaction history.
- User Content, meaning your prompts, uploaded files, images, audio and video, and data from connected services.
- Log data, including your IP address, browser type and settings, and the date and time of each request.
- Usage data, including which features you use, what you engage with, your time zone and your country.
- Device information, including the device name, operating system and device identifiers.
- Location information, derived from the IP address, and more precise location where a feature asks for it and you agree.
None of that is unusual for a cloud service, and it is only fair to say so. What makes it worth listing for a professional practice is that the metadata alone is often enough to establish who was working on what and when, before anyone opens a single conversation.
Memory and connected services widen the surface
Two features change what a single prompt reaches. Saved Memories carry details between conversations, and connected services let ChatGPT read from tools you authorise. The policy treats the content that arrives through connections as Content like any other.
The practical consequence is that a prompt that looks innocuous can pull in a document nobody meant to send. If your practice has enabled connections to a document store or a mailbox, that decision deserves the same scrutiny as the decision to use the tool at all, and it is a conversation for whoever runs your systems.
Content is monitored, and the policy says why
One purpose in the policy is easy to skim past and worth reading slowly: OpenAI uses personal data to prevent fraud, illegal activity and misuse, “including by monitoring any Content submitted or exchanged on our platforms”.
That is a statement that content can be inspected for safety purposes. It is the ordinary position across this category, and Anthropic has a version of it for Claude as well. It is not a claim that staff routinely read conversations, and it is not a promise that nobody ever will.
How long OpenAI keeps it, and the 30 days that are not what they sound like
The policy gives retention in three buckets rather than one number, which is more honest than a single figure and harder to plan around.
Deleting a chat, and the clause that survives it
Deletion is described as a removal within 30 days, and then the sentence carries a tail that matters more than the number.
Once you choose to delete Personal Data, we will remove it from our systems within 30 days unless we need to retain it for longer as described below, or it has already been de-identified and disassociated from your account when you allow us to use your Content to improve our models.
Read the second half twice. If training was on when the conversation happened, deleting the conversation does not reach the copy that has already gone into a training set. It has been de-identified and cut loose from your account, which is a real protection and is not the same as gone. The Privacy Act asks more of that word than a provider does, as the difference between de-identified and pseudonymised data shows.
The exceptions are the ones that bite in a dispute
The first half of that sentence points at a list, and the list is short and specific. Litigators have a list running the other way: the NSW Supreme Court keeps subpoenaed and suppressed material out of AI tools unless the platform meets its conditions.
- Content or accounts banned for policy violations, retained to protect the service from fraud and abuse.
- Data held under a legal obligation, for example where OpenAI receives a lawful subpoena, for the duration of that obligation.
- Payment and transaction records, kept for accounting, dispute resolution and regulatory purposes.
- The audit record of your erasure request, kept so OpenAI can demonstrate it complied.
An AI use policy that promises staff their chats disappear on request is written on the wrong premise. The accurate version is that deletion is a request that OpenAI commits to complete within 30 days, with named exceptions, which is still a great deal better than nothing.
Temporary Chat, and the thing it does not do
Temporary Chat is the control people reach for when they are about to paste something they should not. While a chat stays temporary, OpenAI says it does not appear in history, does not create or update memories and is not used to improve its models. A personalised temporary chat can still draw on memories and custom instructions you already have, and OpenAI may keep a copy for up to 30 days for safety purposes.
Every one of those is a claim about OpenAI’s own handling. None of them is a claim that the text did not leave your office, which is the first question the Privacy Act asks.
Does ChatGPT train on what you write?
This is where the account you signed in with does all the work. OpenAI’s help centre article on how content is used to improve model performance splits the world in two, and the split is clean.
| Account | Trained on by default | Where the control sits |
|---|---|---|
| ChatGPT for individuals | Yes, unless you opt out | Settings, then Data Controls |
| ChatGPT Business | No | Nothing to turn off |
| ChatGPT Enterprise and Edu | No | Nothing to turn off |
| API platform | No, only if you opt in | You opt in, for example through Playground feedback |
OpenAI, “How your data is used to improve model performance”, read 19 September 2026.
For services for individuals, OpenAI writes that it “may use your content to train our models”, and that ChatGPT “improves by further training on the conversations people have with it, unless you opt out”. For business products the same article reverses it: “By default, we do not train on any inputs or outputs from our products for business users, including ChatGPT Business, ChatGPT Enterprise, and the API.”
That is a genuinely large difference, and it is available on a plan a small practice can buy. It is also the single change most firms have not made, because signing in with a personal account works perfectly well and nothing on the screen tells you which one you are using. Checking it across the practice costs nothing, and for the wider picture there is our approach for organisations.
The thumbs up that reopens the door
There is one sentence in that article worth putting in front of anyone in your practice who has ever rated a reply.
Even if you have opted out of training, you can still choose to provide feedback to us about your interactions with our products (for instance, by selecting thumbs up or thumbs down on a model response). If you choose to provide feedback, the entire conversation associated with that feedback may be used to train our models.
Not the rating. The entire conversation. A person who turned training off in March and clicked a thumbs down in September has, on OpenAI’s own account of it, handed over that conversation. It is documented in plain sight, and almost nobody reads it.
Where the switch actually lives
OpenAI accepts the choice in two places and says either is enough: the setting called “Improve the model for everyone”, under Settings and then Data Controls, or the option in its privacy portal. It also notes that support conversations may be used to improve its services, including its models, if training is enabled.
The setting is per account, which is the detail that undoes a good policy. A firm that turned it off on the office account has done nothing about the four people who signed in with their own.
Training and transit are two different questions
This is the point most advice gets wrong, and it is the reason our approach for organisations treats these as two separate lines rather than one.
“We do not train on your data” is a statement about one downstream use of the text. It is a promise not to fold your words into the weights of a future model. It is worth having, and OpenAI keeps it for business plans.
Here is what that same sentence does not say. It does not say the text stayed inside your office. It does not say nobody at the provider can reach it. It does not say it was not stored, logged, replicated or held under a legal order. It does not say it was not sent to a vendor. And it does not say the model ran on a machine in this country.
When the Privacy Act says the disclosure happens
Under the Privacy Act the operative event is earlier than all of that. The Office of the Australian Information Commissioner, in its Guidance on privacy and the use of commercially available AI products of 21 October 2024, updated 17 January 2025, describes what happens at the moment of the paste, in a worked example about an insurance company.
By entering the personal information into the AI chatbot, the insurance company is disclosing the information to the owners of the chatbot.
The disclosure is complete when the text arrives. Whether a model is later trained on it is a second question about a second use. A training switch cannot reach backwards through the first one, and a server in Sydney cannot either.
Does the text reach a system outside your organisation, such as the developer's?
YesThe paste is a disclosure to the owners of the chatbot, complete when the text arrives.
NoWith protections that keep it inside, the OAIC treats it as a use rather than a disclosure.
Is training switched off?
YesOne later use is ruled out. The disclosure, if there was one, has already happened.
NoThe conversation may also be used to train future models.
The first question is the one the Privacy Act asks. The training switch only answers the second.
The test that decides which side you are on
For the regulator, what separates a use from a disclosure is who controls the information, not which brand of tool it is.
If your organisation is using a proprietary AI system rather than a publicly available chatbot, for example, and has protections in place to ensure that information entered into the system will not be disclosed outside the organisation (such as to the system developer), this will constitute a use rather than a disclosure of personal information.
That is a contractual and architectural test. It turns on your agreement and your configuration, which is a conversation for the provider who owns your rollout, not for whoever is nearest the keyboard.
A business or Enterprise workspace, with a business agreement and training off by default, is a far stronger position on that test than a personal account. It is still a position you have to be able to evidence, in writing, on the day somebody asks.
Does OpenAI share it, sell it, or hand it over?
The policy answers the question about selling data in precise legal terms, and the terms matter.
We don’t “sell” Personal Data or “share” Personal Data for cross-contextual behavioral advertising, and we do not process Personal Data for “targeted advertising” purposes (as those terms are defined under state privacy laws).
Those are defined terms from United States state privacy statutes. The sentence is true and it is narrower than “we never give your data to anyone”, which the same document does not claim.
The disclosure list, read as a list
Disclosure has its own section, and the categories are the ordinary ones for a cloud service. Reading them together is more useful than reading them one at a time.
- Vendors and service providers, including hosting, cloud, support, safety and payment services.
- Government authorities, where OpenAI believes disclosure is necessary to comply with a legal obligation, to protect its rights, or to detect fraud, among other stated grounds.
- Business transfers, meaning a sale, reorganisation or bankruptcy carries the data with the rest of the assets.
- Affiliates, which may use the data consistently with the same policy.
- Business account administrators, who on an Enterprise or business account “may access and control your OpenAI account, including being able to access your Content”.
The one that surprises people in the wrong direction
That last item cuts both ways, and it is worth saying out loud to staff before they find out. On a work account your firm’s administrator can read what people typed.
For a practice worried about a partner’s confidential matter sitting unnoticed in a junior’s chat history, that is a feature and a control. For the junior it is a fact about their employer’s systems, and it belongs in the policy you hand out rather than in a discovery six months later.
Where the servers are: Australia is on one list and not on the other
OpenAI publishes two separate residency commitments, and the difference between them is the whole Australian story.
| Commitment | What it controls | Is Australia offered |
|---|---|---|
| Data residency | Where covered content is stored at rest | Yes |
| Inference residency | Where the model actually runs on that content | No |
OpenAI, “Data residency and inference residency for ChatGPT”, read 19 September 2026.
Data residency covers storage at rest and is available in ten regions including Australia. Inference residency, which OpenAI defines as keeping GPU execution within the region, is offered in three: Europe, the United States and the United Arab Emirates. Australia appears on the first list and not on the second, and it takes ten seconds to check.
There is a second gate before that one. Residency is offered to eligible API customers and to new ChatGPT Enterprise and Edu workspaces. ChatGPT Business, which is the plan a practice of this size actually buys, is not on that list.
What residency does not cover, in OpenAI’s words
Even where it applies, the commitment has documented limits. OpenAI lists categories that may sit outside the chosen region: data handled through external integrations such as apps, connectors and web search, transient processing steps, workspace metadata, the workspace name, billing information and user logins.
And it answers the obvious next question in its own FAQ, in one word. Asked whether inference residency guarantees that all processing stays within the region, OpenAI says no: activities such as authentication, routing and analytics may still occur outside the selected region.
What that means under Australian Privacy Principle 8
Australian Privacy Principle 8 does not turn on where the disk is. It turns on who receives the information: a person who is not in Australia. Under section 16C, if that overseas recipient then does something that would have breached the principles, the breach is yours. Storage in Sydney does not change who received the prompt.
The identity of that recipient is published. OpenAI’s policy names OpenAI Ireland Limited as controller for the European Economic Area and Switzerland, and for everyone else, which includes Australia, it names OpenAI OpCo, LLC, at an address in San Francisco.
The assessment clock that starts when someone suspects a problem is set out in the breach guide. The narrow point for now is that residency is a storage commitment, and OpenAI is careful to say so.
Free, Go, Plus, Pro, Business, Enterprise: what actually changes
Plans differ on four things, and price is not the useful axis. Whichever one you land on, the written rule that goes with it belongs in your AI policy.
| Free, Go, Plus and Pro | Business | Enterprise and Edu | |
|---|---|---|---|
| Trained on by default | Yes, unless you opt out | No | No |
| An administrator controls the workspace | No | Yes | Yes |
| Residency available | No | No | Storage only, for new workspaces |
| Contract that governs the text | Consumer terms and the privacy policy | Business agreement | Business agreement |
Training is on by default for individual plans and off for business plans. An administrator changes who can read what and who can enforce a setting. Residency is open to Enterprise, Edu and the API only, and covers storage rather than processing.
The contract is the largest free lever a small practice has, and OpenAI states it in the opening lines of the policy itself: the privacy policy “does not apply to content that we process on behalf of customers of our business offerings”. Deciding which account people sign in with changes the legal position of every prompt after it, and costs nothing beyond the licence you may already hold.
Three things people believe that OpenAI’s documents do not say
All three come up in practice and are answered in the same documents quoted above, and each has a close relative among the beliefs about Claude, Gemini and Copilot.
It removes one use. The retention section still applies, and so do its exceptions.
Deletion means removal within 30 days, with exceptions, and it does not reach a de-identified training copy made while training was on.
Enterprise can mean stored in Australia. OpenAI does not offer inference residency here, and says regional storage does not imply regional processing.
None of those is a criticism of OpenAI, whose documentation is clearer on all three points than most of the commentary written about it. They are places where a summary written by somebody else has quietly widened a commitment, which is the failure mode worth watching for in this whole subject.
How to turn training off and delete what is there
None of this needs a purchase, and all of it needs about fifteen minutes.
- Turn off “Improve the model for everyone”, in Settings, then Data Controls. OpenAI also accepts the same choice through its privacy portal and says either one is sufficient for ChatGPT and Codex tasks.
- Tell people to stop rating replies, or to accept that rating one sends the whole conversation.
- Delete the chats that should not exist, and expect removal within 30 days rather than immediately.
- Export the history before you delete an account, from the same data controls screen.
- Write down which account each person uses, because the setting is per account and staff sign in with whatever is open.
If your practice is answering an insurer’s questions about any of this, the wording an underwriter will accept is a separate skill, covered in our guide to the AI questions on a cyber questionnaire.
Is ChatGPT safe for privacy? What the Privacy Act asks
The OAIC has not banned anything. Its position is a recommendation on best practice, and quoting it accurately is the difference between advice and folklore.
As a matter of best practice, the OAIC recommends that organisations do not enter personal information, and particularly sensitive information, into publicly available AI chatbots and other publicly available generative AI tools, due to the significant and complex privacy risks involved.
The binding obligation sits elsewhere, in APP 6, which governs use and disclosure and asks whether the person would reasonably expect it. A client who instructed you on a conveyance did not expect their file to be read by a model, and if your engagement letter says nothing about AI, that is an argument you do not have. At a council, APP 6 is not the rule at all, and which one is depends on your state.
A practice that wants the expectation argument on its side can write it into the AI clause of its engagement letter, before the first file goes in.
The regulator has already written your scenario
In December 2025 the regulator returned to the subject in a post on generative AI in the workplace, naming ChatGPT, Grammarly, Claude, Copilot and Gemini.
Its case study is an employee uploading a customer’s hardship application, with health and family details, against the employer’s own written policy. That is the scenario we build for, described by the regulator rather than by a vendor, and it is a better training document than anything a software company could write.
Whichever tool you use, your cyber insurer will ask about it, so it pays to know what a cyber policy covers in Australia.
What none of this fixes
Every control above is a control over what OpenAI does after the text arrives. Not one of them is a control over whether the text arrives.
That gap is where our own software sits, and it is worth being exact about what it does. Nonimo runs on the machine, replaces identifiers in the text before it goes anywhere, and shows what it changed so a person can overrule it. On an Australian file that means a TFN, an ABN or a Medicare number traded for a placeholder of its own.
It pseudonymises, which means the mapping can be reversed and is kept encrypted on the user’s own computer. That is a smaller claim than the word anonymisation makes, and the difference is legal rather than cosmetic. What it keeps is set out on Nonimo’s security page, and the licence terms on the licence page.
The most useful steps cost nothing. Decide which accounts your people sign in with. Write one page saying what may never be pasted. Name the person to call when it happens anyway. A practice that does those three is in better shape than one that bought a tool and did none of them. Comparing tools comes afterwards, which is the right order.
Sources
Every page below was open in front of us on 19 September 2026.
- OpenAI privacy policy, updated 6 February 2026. The collection list, User Content, content monitoring, the deletion window of 30 days and its four exceptions, the de-identified training copy, the disclosure list including business account administrators, the “sell” and “share” sentence under United States state privacy laws, the exclusion of business offerings from the policy, and OpenAI OpCo, LLC as controller outside the European Economic Area and Switzerland.
- OpenAI, “How your data is used to improve model performance”. Training on individual accounts unless you opt out, the business default, where to opt out, support conversations, and the feedback sentence about the entire conversation.
- OpenAI, “Data residency and inference residency for ChatGPT”. The ten storage regions including Australia, the three inference regions that do not include it, eligibility limited to API, Enterprise and Edu customers, the categories that may sit outside the chosen region, and the FAQ answer that inference residency does not keep all processing within the region.
- OpenAI, “Enterprise privacy at OpenAI”, updated 8 January 2026, read 25 September 2026. No training on Business, Enterprise, Edu or API data by default, automated content classifiers, OpenAI’s access to Business conversations limited to authorised employees and contracted abuse reviewers, and workspace admins able to view, export and delete them.
- OpenAI, “Data controls in ChatGPT”, read 25 September 2026. Turning off “Improve the model for everyone” on Free, Go, Plus and Pro stops training on new conversations without deleting them from history.
- OpenAI, “Temporary chat in ChatGPT”, read 25 September 2026. Out of history, not used for training while temporary, and a copy kept for up to 30 days for safety purposes.
- OAIC, Guidance on privacy and the use of commercially available AI products, published 21 October 2024, updated 17 January 2025. The insurance company disclosure example, the proprietary system counterexample, and the recommendation on best practice, quoted in full.
- OAIC, GenAI tools in the workplace, 4 December 2025. The named products and the hardship application case study.
- OAIC, APP Guidelines chapter 8, version 1.3, updated 3 October 2025. Cross-border disclosure turning on the recipient rather than the server.
- Privacy Act 1988 (Cth). Australian Privacy Principle 6 and section 16C.
Common questions
Does ChatGPT save your data?
Yes. OpenAI's privacy policy of 6 February 2026 lists your prompts and uploaded files as personal data it collects. Chats you delete are removed from its systems within 30 days, unless it needs to keep them for legal, security or abuse reasons.
Is ChatGPT confidential?
It depends on the account, and the short answer to 'is ChatGPT safe for confidential information' is no on a personal plan. On Free, Go, Plus and Pro, OpenAI may train on your chats unless you turn that off. Business, Enterprise and the API are not trained on by default, though authorised OpenAI staff can reach them in limited cases. Either way, your duty of confidentiality to a client stays with you.
Does ChatGPT train on what I type?
On a personal account, yes, unless you turn it off. OpenAI says it may use content from services for individuals to train its models. For ChatGPT Business, Enterprise and the API, it says it does not train on inputs or outputs by default.
If I turn training off, is client data safe to paste?
No. Turning training off removes one use of the text. It does not undo the disclosure that happened when the text left your office, and it does not stop OpenAI storing the conversation or handing it over under legal process.
Can I keep my ChatGPT data in Australia?
Storage, yes, on some plans. OpenAI lists Australia among the regions where content covered by the commitment can be stored at rest for eligible Enterprise, Edu and API customers. Inference residency, meaning where the model actually runs, is not offered in Australia.
Does OpenAI sell my data?
Its privacy policy says it does not sell personal data or share it for cross-contextual behavioural advertising, as those terms are defined in United States state privacy laws. It does disclose data to vendors, affiliates and government authorities in stated circumstances.
Who is responsible for my data if I am in Australia?
OpenAI OpCo, LLC, in San Francisco. Its policy names OpenAI Ireland Limited as controller for the European Economic Area and Switzerland, and OpenAI OpCo, LLC for everyone else. That makes an Australian prompt an overseas disclosure to consider under APP 8.
How do I delete my ChatGPT history?
Delete individual chats or the whole account in settings, and OpenAI says deleted data leaves its systems within 30 days. Content already used to train a model when you allowed that use is de-identified and cannot be pulled back out.
Can my employer read my ChatGPT chats?
On a business or Enterprise workspace, yes. OpenAI states that administrators of that account may access and control your OpenAI account, including being able to access your Content. On a personal account your employer has no such access.
Does the OAIC ban staff from using ChatGPT?
No. Its October 2024 guidance recommends as best practice that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools. The binding obligation is Australian Privacy Principle 6.