[nonimo]
EN
Download

Does ChatGPT share your data, and how long does it keep it?

· Updated · Written and maintained by Joaquín Trapero, Nonimo

No, OpenAI does not sell it, and its policy says so in plain terms. It does disclose it, to five kinds of recipient, and that is a different matter. The text your colleague typed this morning reaches vendors and service providers, affiliates, government authorities where OpenAI believes the law requires it, whoever buys the company if it is ever sold, and, on a business plan, your own workspace administrator.

For a firm holding client files, though, who ChatGPT shares your data with matters less than how long the text lives, what the training switch actually switches off, who may read it, and which company is legally answerable to you.

This guide answers those four from OpenAI’s own pages, all checked on 19 September 2026. It takes them in that order, and the last one is the one that surprises British readers: the company answerable to a UK user is not the Irish one.

Does ChatGPT share your data?

Three claims get muddled here, and firms talk themselves into the wrong decision by merging them. Selling data, disclosing it and losing control of it are separate things, and only the first is untrue.

OpenAI’s Europe privacy policy, updated on 24 August 2026, lists disclosure under six headings. Read as a business rather than as a consumer, they collapse into the table below, and nothing in it is unusual for a cloud service.

That is rather the point. A firm that would not upload the same letter to an unvetted site for sharing files will put it in a chat box without the same pause. If your office has no written rule about which documents may go in, the AI policy template is the cheapest thing you can do this week.

Route outWhat OpenAI says
Vendors and service providersHosting, cloud, support, safety, analytics, payments; they process only on OpenAI’s instructions
AffiliatesCompanies under common control, using it consistently with the policy
Government authoritiesWhere OpenAI believes in good faith that the law requires it, or to protect rights, safety or property
Business transfersDiligence counterparties, then the successor, if OpenAI is sold or restructured
Workspace administratorsOn a business or Enterprise account, they may access and control your account, including your content

The heading that matters least to a consumer matters most to a partner in a firm. If your staff signed in with an email address at your own domain, OpenAI may tell your organisation that the account exists. If you run a business workspace, the administrator can reach the conversations. That is a feature, not a leak, and it is worth knowing before someone assumes a work chat is private from the boss.

Is ChatGPT confidential?

Not in the sense your clients mean by the word. Confidentiality is a duty your firm owes, and no provider’s privacy page discharges it for you. What OpenAI offers instead is a set of promises that change with the plan, and as of 25 September 2026 its own pages put them like this.

On Free, Go, Plus and Pro, OpenAI may train on your conversations by default. Switching off “Improve the model for everyone” stops that for new chats, but they stay in your history, and a thumbs up or down can still put the whole conversation back into training. Temporary Chat keeps a conversation out of history and out of training, yet OpenAI may keep a copy for up to 30 days for safety purposes.

On Business, Enterprise, Edu and the API there is no training by default, though content may still pass through automated classifiers. On Business and the API, OpenAI’s access is limited to authorised staff and to outside contractors, bound by confidentiality, who review for abuse and misuse. On Business, your own admins can also view, export and delete conversations.

So is ChatGPT confidential enough for client work? Only as far as the plan and the habits around it go. Use a business account for work, switch training off anywhere else, and keep names, file references and NHS or National Insurance numbers out of the box. Nonimo, a Mac and Windows app, replaces names and identifiers with labels before the text reaches the chat, so the originals stay on your computer.

What OpenAI collects when someone in your office types

The policy separates what you hand over from what the service takes. You hand over account information, and what OpenAI calls Content: the prompts, the uploaded files, the images, the audio and video, and data from any connected service. The service takes log data, usage data, device information and a general location derived from your IP address.

For a law firm or an accountancy practice, only one line of that list is a professional problem, and it is Content. A letter is denser than it feels. A single page of correspondence routinely carries a name, a date of birth, an address, a National Insurance or NHS number, a file reference at a previous adviser, and a second person who never consented to anything.

Whether that upload is a reportable breach is a separate question with its own tests, answered in our guide on client data and a data breach.

Uploaded files count as Content in full. There is no partial mode in which the model reads a document without OpenAI receiving it. For a clinic letter that means the header goes too, which is why the patient details should come out before anything is uploaded.

How long ChatGPT stores your data, and the exceptions

The headline figure is 30 days, and it is accurate as far as it goes. OpenAI states that once you delete personal data, it removes it from its systems within 30 days. Temporary chats are deleted automatically within the same window.

30 days
to remove deleted content from OpenAI's systems, subject to four named exceptions. OpenAI Europe privacy policy, 24 August 2026

The four exceptions, which are the interesting part

The same section then names four situations where the clock does not apply, and any of them can outlive your matter.

  1. A banned account or banned content. If content or an account is banned for breaching the usage policies, OpenAI may retain that data to protect its services from fraud, abuse or further violations.
  2. A legal requirement. If OpenAI is legally required to retain your data (the policy’s own example is a subpoena), it may keep it for as long as that obligation lasts.
  3. Payment and transaction records. Where OpenAI is a party to a financial transaction, such as your monthly subscription, it keeps the associated records for accounting and regulatory purposes.
  4. The audit record of your erasure request. When you ask for deletion, OpenAI retains proof that it complied.

There is a fifth case that is easy to miss, because it is written as a clause rather than a heading: content is not deleted within the 30 days if it has already been de-identified and disassociated from your account through model training. Once the text is in that pipeline, deleting the chat does not reach back into it.

A court can also override all of this, as one did to OpenAI’s retention for five months, and that story is told in full in the breach guide rather than repeated here.

Does ChatGPT train on your data?

It depends entirely on which account the text went into, and that single choice is the largest free lever a small firm has.

On consumer services, OpenAI’s help page is direct: when you use services for individuals such as ChatGPT and Codex, it may use your content to train its models. You turn that off under Settings, then Data Controls, with the switch labelled “Improve the model for everyone”.

On business services the default is the other way round. OpenAI states that by default it does not train on any inputs or outputs from ChatGPT Business, ChatGPT Enterprise or the API, and that organisations are opted out of data sharing unless they explicitly opt in.

The feedback button that hands over the whole conversation

Now for the proviso that decides whether the switch is worth anything in an office. OpenAI’s own wording is that even if you have opted out of training, you can still choose to give feedback, and if you do, “the entire conversation associated with that feedback may be used to train our models”.

Nobody thinks of a thumbs up as a disclosure. It takes one click, and staff make it dozens of times a day because the interface invites it. On a consumer account with training switched off, it is the one action that puts a whole conversation, client letter and all, back into the training set.

So it belongs in your written rule, next to the list of what never goes in, and it is worth a line in the answers you give an insurer about AI use in your renewal questionnaire.

Training is not the same as passing through OpenAI’s servers

This is the distinction almost every page asking whether ChatGPT shares your data gets wrong, and it is worth stating flatly. “We do not train on your data” is an answer to one question out of four. It says nothing about whether the text arrived, nothing about how long it stays, nothing about who may read it, and nothing about what a court can compel.

Take the strongest business position OpenAI offers. On its enterprise privacy page, updated 8 January 2026, it states that it does not train on your business data by default, that you own your inputs and outputs, and that data is encrypted at rest with AES-256 and in transit with TLS 1.2 or later. All of that is true and none of it means the letter stayed in your office.

Who can read a ChatGPT Business conversation

The same page answers that, and the answer differs by plan. It is the clearest evidence that not training and not reading are separate promises.

PlanWho OpenAI says can reach the conversation
ChatGPT BusinessYour workspace admins can view, access, export and delete users’ conversations
ChatGPT BusinessAuthorised OpenAI staff, plus “specialized third-party contractors” reviewing for abuse and misuse
ChatGPT EnterpriseAdmins via an audit log through the Compliance API
ChatGPT EnterpriseAuthorised OpenAI staff, for incidents, recovery with your permission, or where the law requires

Read the second row again. On ChatGPT Business, the plan a firm of fifteen people is most likely to buy, OpenAI describes outside contractors, bound by confidentiality and security obligations, who may review content for abuse and misuse. They are not training a model. They are people, outside both your firm and OpenAI, who can be shown a conversation. If the answer you gave a client was “it does not train on our data”, that answer was true and incomplete.

The same test applied to Claude, Gemini and Copilot produces three more answers, and not one of them is that the document stayed in your office.

Who your data controller is, if your firm is in the UK

Here is the finding that matters most to a British reader, and it comes from reading the four big providers’ policies on the same afternoon with the same question.

OpenAI publishes two privacy policies. The Europe one covers, in its own words, the European Economic Area, the United Kingdom and Switzerland. Then its final substantive clause allocates responsibility, and the allocation does not match the coverage. The Irish entity is named for “the European Economic Area (EEA) or Switzerland”. Everyone else falls under the next sentence, which names OpenAI OpCo, LLC of 1455 Third Street, San Francisco.

The United Kingdom has not been in the European Economic Area since 2020. On the face of the document, the company that answers to a British user reading OpenAI’s Europe privacy policy is a Californian one.

ProviderController named for a UK userWhere
ChatGPTOpenAI OpCo, LLCSan Francisco
ClaudeAnthropic Ireland, LimitedDublin
GeminiGoogle LLCMountain View
Microsoft CopilotMicrosoft Ireland Operations LimitedDublin

Two of the four route a British user to a US entity and two keep them in Dublin. That is no ranking, just a fact about drafting that a firm should know before it decides which tool its staff sign into, and each row is read off the provider’s own page. The same comparison from the other three sides is in the guides on Claude, Gemini and Copilot.

The ICO is still where you complain

None of this removes your regulator. The same policy states that if you reside in the UK you can contact the Information Commissioner’s Office, and that where transfers leave the UK it relies on the UK Secretary of State’s adequacy regulations, the Standard Contractual Clauses, and the UK International Data Transfer Addendum to those clauses.

So the route to complain is British and the counterparty is American. That is an ordinary arrangement, and simply worth writing down in your record of processing. If you work in a council, the same record can also be requested under freedom of information, and that runs on its own clock.

Where the servers are, and what UK residency buys

OpenAI does offer data residency in the United Kingdom, and it is easy to read that as the end of the argument. It is not, for two reasons its own help page gives.

The first is scope. Data residency is available to eligible API customers and to new ChatGPT Enterprise or Edu workspaces. It is not offered on Free, Go, Plus, Pro or Business. If your staff are on a personal Plus account, UK residency is not a setting you have.

Storage in Britain, inference somewhere else

The second reason is sharper. OpenAI separates two things: data residency, which fixes where content is stored at rest, and inference residency, which fixes where the GPU actually runs. Residency for storage is offered in ten regions including the United Kingdom. Inference residency is offered in three: Europe covering the EEA and Switzerland, the United States, and the United Arab Emirates.

Not on the list
The UK is offered storage residency but not inference residency, which OpenAI lists for Europe, the US and the UAE. Data residency and inference residency for ChatGPT, OpenAI help centre

Even with inference residency enabled, OpenAI names what still happens elsewhere: processing on the CPU, such as extracting the text from an uploaded PDF or Word file, request routing, authentication and analytics. Far from a trivial edge case, extracting text from a document is the step that reads your client’s letter.

So a British firm on the highest tier can hold its chat history on British soil and still have the document processed abroad. Residency describes where a copy sleeps. It does not describe where the work happens, and it never undoes the moment the text left the building. If your cover depends on where data sits, that assumption is worth testing against your policy wording, which our comparison of UK cyber insurance sets out.

Advertising, and the context of your current chat

This is the newest part of the answer, and most pages on the subject predate it.

OpenAI’s Europe privacy policy now sets out advertising as a purpose with its own legal basis. Where ads personalisation is available and switched on, it uses past chats to make ads more relevant, and it states plainly that “our ads system uses the context of your current chat as well as other available information to select the most relevant ads for a given query”.

The legal basis given is consent, for Free and Go users. Plus and Pro accounts are named as outside the personalised advertising route. There is also a generic ads experience that uses the context of the current chat, location, time of day and device type.

AccountWhat the policy says feeds the ads
Free and Go, personalisation onPast chats, with consent, plus the context of the current chat
Free and Go, generic adsContext of the current chat, location, time of day, device type
Plus and ProNamed as outside the personalised advertising route
Business and EnterpriseAdvertising does not appear in the business terms at all

Nothing here is a sale of data, and OpenAI says elsewhere that it does not sell personal data or share it for cross-contextual behavioural advertising. But “the context of your current chat” is a phrase a firm should read twice.

If the current chat is a redundancy consultation or a probate matter, the context of that chat is now an input to something other than the answer on the screen. On a paid business plan this does not arise. On the free account your junior uses at home, it does, which is a reason to settle the account question in a written rule rather than leave it to habit.

What changes between Free, Go, Plus, Pro, Business and Enterprise

The account is the contract, and the contract decides almost everything above. There are six plans a UK firm might be on, four of them train by default unless someone changes a setting, and one of them can hold data in the UK.

6plans a UK firm might be on
4that train by default
1with UK storage residency
OpenAI enterprise privacy page, 8 January 2026, and the ChatGPT data residency help article
Trains by defaultAdmin can readUK storage residency
Free and GoYes, unless switched offNoNo
Plus and ProYes, unless switched offNoNo
BusinessNoYes, view, export, deleteNo
Enterprise and EduNoAudit log via Compliance APIYes, on new workspaces

Two lines of practical advice fall out of that table without any product being involved. First, the difference between the second and third rows is a purchasing decision rather than a technical one, and it changes which contract governs the text. If your terms of business name the tool and the plan, as an engagement letter AI clause can, that line has to match the row you are actually on.

Second, the fourth row is the only one where UK residency appears, so a firm that has told a client its data stays in Britain should check which row it is actually on. Firms of this size usually make both decisions through the provider who runs their systems.

How to turn training off and delete what is there

Four steps, none of which costs anything, in the order that recovers the most control per minute.

  1. Decide which account people sign in with, and verify it. This is the one that counts. Everything in the table above follows from it, and verification means looking, not asking.
  2. Turn off “Improve the model for everyone”. It lives under Settings, then Data Controls. OpenAI also offers “Do not train on my content” in its privacy portal, and says either one is sufficient; you do not need both.
  3. Tell people what the feedback buttons do. Opting out of training does not cover a conversation attached to a thumbs up or thumbs down. This is the single most useful sentence to put in a staff briefing.
  4. Export before you delete. The account’s own export carries the dates, which a screenshot does not. Then delete, knowing the 30 days and its exceptions.
ControlWhat it doesWhat it does not do
“Improve the model for everyone” (Settings, then Data Controls)Stops your content being used for trainingCover a conversation you rate with a thumbs up or down
“Do not train on my content” (privacy portal)The same; either one is sufficientThe same exception applies
Thumbs up or thumbs downSends feedback on a replyStay out of training: the entire conversation may be used
Temporary ChatNo history, no memories, not used for trainingStay off OpenAI’s servers: kept for up to 30 days

Temporary Chat is worth knowing too: OpenAI states that those conversations do not appear in history, do not create memories, and are not used to train its models. They are still sent to OpenAI, and still retained for up to 30 days. If an external provider runs your systems, these four steps are theirs to verify rather than yours to assume, and our other guides cover the rest.

Is ChatGPT safe under UK law?

No regulator has answered that question about a named product, and any page that tells you the ICO has approved or banned ChatGPT is wrong. What exists is the ordinary law, applied to an ordinary disclosure.

Your firm remains the controller for the client data it holds. You need a lawful basis for the disclosure, you owe the data minimisation duty, and you owe the security duty in Article 5(1)(f) and Article 32.

The regime is the UK GDPR together with the Data Protection Act 2018, supervised by the ICO. On top of it sits a professional layer that no data protection lawyer will mention: your regulator, your practising certificate, and your professional indemnity insurer. For a litigator, the court belongs in that layer too, with its own expectations of documents drafted with AI.

LayerMade up of
Data protectionUK GDPR and the Data Protection Act 2018, supervised by the ICO
ProfessionYour regulator, your practising certificate, your professional indemnity insurer
Court, for litigatorsIts expectations of documents drafted with AI

A contract does not decide who the controller is

When the ICO published its response to the generative AI consultation series, one line did more work than the rest. Controllership, it said, turns on the practical reality rather than the label, and “a contract does not necessarily determine whether an organisation is a controller”. It also flagged the risk that deployers of closed models “do not have meaningful control and influence over all the processing at deployment”.

That cuts both ways, against the comfortable reading on either side. Signing a data processing addendum does not by itself make the provider your processor and nothing more. Equally, being unable to see inside a model does not discharge you, because you chose to send the document.

What changed on 19 June 2026

The Data (Use and Access) Act 2025 is now fully commenced: the ICO states that all of its data protection provisions came into force on 19 June 2026. For a small firm the practical change is a duty, not a freedom. You must take steps to help people who want to complain about how you use their information, acknowledge a complaint within 30 days and respond without undue delay.

That duty and this topic meet in one place. If a client learns that their file went into a chat box and writes to you about it, that letter is now a complaint you have to handle on a clock.

Which is a good reason to have written down, before it happens, which tools your staff use and on which accounts. The wider picture is in our note on the EU AI Act timetable, which reaches UK firms through their customers rather than through the ICO.

What none of this fixes

Everything above is about a service. The problem in your office is about a person, under time pressure, at four in the afternoon, with a letter that will not summarise itself.

Re: 14 Bruce Street, complaint reference NR-2291
Client: A. Okonjo, DOB 03/11/1974
NI number: AB 00 00 00 A
NHS number: 000 000 0000
Acting for: Ms Okonjo and her daughter (minor, initials S.O.)
Previous adviser: Harris and Poole, file ref HP/4471

Six lines, and what matters is that every field carries a label, because the labels are what a machine can find. A name, a date of birth, two national identifiers, an address, a file reference at a named previous adviser, and a child. A GP practice sees the same shape in every referral or discharge summary, which opens with the patient’s name, date of birth and NHS number: the details a practice can tag before anyone pastes.

Now delete every name from it. A specific street address, a minor in the household and a reference at a named prior adviser will still identify the matter to anyone who has seen the file, and often to anyone in the same town.

That last point is a real limit, and it applies to every tool in this category including ours. Identifiability is a property of the whole document, not of the words you removed. The ICO’s own advice is the useful framing: if an organisation can remove identifiable information from documents before sharing them, it should do so. That is a duty to reduce risk, not a way to leave the law behind.

What a masking tool does here, and what it does not

The facts first, so you can check them. Nonimo is a Mac and Windows app that finds identifiers in text before it is sent and hides them, working on the machine rather than in a cloud, with a policy set by IT rather than by each user.

For the United Kingdom it covers NHS numbers, UTRs and driving licence numbers written after their label, National Insurance numbers with or without one, and postcodes, plus a vehicle registration, masked as a number plate when a word such as “Registration:” comes before it, and a mobile number that follows a label such as “Mobile:”.

Each of them is masked in front of you, where you can undo it, so the person who knows the matter has the last word on every change. What it costs a firm is on the licence page.

What the app keeps on your computer is set out on Nonimo’s security page.

Sources

Checked 19 September 2026, when OpenAI’s own domains, which return 403 when fetched from the command line, were read in a browser; they are live. The OpenAI pages behind the section on confidentiality were read again on 25 September 2026.

Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.

Common questions

Does ChatGPT share your data with anyone?

Not by sale. OpenAI's policy of 24 August 2026 names five routes out: vendors and service providers, affiliates, government authorities where it believes the law requires it, parties to a corporate transaction, and your own workspace administrator on a business plan.

Is ChatGPT confidential?

No, not in the sense a client means: the answer to 'is ChatGPT safe for confidential information?' turns on the plan. As of 25 September 2026, Free, Go, Plus and Pro may train on your chats unless you switch it off. Business, Enterprise and the API do not train by default, but OpenAI can still reach the text, and on Business and the API that includes outside contractors reviewing for abuse.

Does ChatGPT store your data, and for how long?

Yes. Deleted content is removed within 30 days, and temporary chats within 30 days. Longer retention applies where OpenAI is legally required to keep it, where an account is banned, and for payment records.

Does turning off training stop OpenAI keeping my conversations?

No. The setting removes one use. OpenAI's help page also states that if you give feedback with a thumbs up or thumbs down, the entire conversation attached to that feedback may still be used to train its models.

Who is my data controller for ChatGPT if I am in the UK?

On the face of OpenAI's Europe privacy policy, OpenAI OpCo, LLC in San Francisco. The clause names the Irish entity for the European Economic Area and Switzerland only, and the UK is in neither.

Can I keep ChatGPT data in the UK?

Storage, yes, on new Enterprise or Edu workspaces and eligible API accounts. Inference residency, which fixes where the GPU runs, is offered for Europe, the United States and the United Arab Emirates, and not for the UK.

Can my employer read what I type into ChatGPT Business?

Yes. OpenAI states that workspace administrators can view, access, export and delete users' conversations in a ChatGPT Business workspace. Enterprise administrators get an audit log through the Compliance API.

Does ChatGPT use my chats for advertising?

On Free and Go accounts, with consent, yes. OpenAI's policy states that its ads system uses the context of your current chat and other available information to select ads, and that past chats can make ads more relevant.

Is putting client data into ChatGPT allowed under UK law?

There is no rule naming ChatGPT. Your firm stays the controller and needs a lawful basis, and the ICO advises removing identifiable information from documents before sharing them where you can.