Artificial Intelligence (AI) > ChatGPT privacy policy
ChatGPT privacy policy explained: What happens to your data?
ChatGPT is the world’s most popular AI chatbot, with a billion monthly app users. But it collects vast amounts of personal data and processes it in ways you may not feel comfortable with. Here’s what ChatGPT’s privacy policy allows OpenAI to do with your information.

ChatGPT privacy policy at a glance
This analysis is based on official sources including ChatGPT’s privacy policy, enterprise privacy commitments, help center documentation, and publicly disclosed security standards.
- What does it collect?
- How is data encrypted?
- How long is data kept?
- Does it comply with GDPR and CCPA?
- Does it read your chats?
- Can you choose where your data is stored?
- Is your data used to train AI?
- Is your data subject to US surveillance?
- What privacy controls does it offer?
- Who else sees your data?
- Does it show ads or sell your data?
How ChatGPT handles your data
ChatGPT keeps your data to help generate responses, but that creates an AI paper trail on OpenAI's servers. Here’s what you should know about it:
Data collected by ChatGPT
Account information: Name, email, login credentials, plus payment details and transaction history for paid tiers.
User content: Everything you enter or upload, including prompts, text, files, images, audio, and media, plus responses generated during your conversations.
Device and usage logs: IP address, approximate location, browser and operating system settings, timestamps, features used, and interaction histories.
Contacts: Names, contact details, and address book information from your synced contacts.
Cookies and tracking tokens: Identifiers used to maintain active sessions, remember your preferences, and support platform analytics.
Communication data: Name, contact details, and message contents if you contact OpenAI support or interact with OpenAI on social media.
How long ChatGPT stores your data
Why ChatGPT monitors and reviews chats
How ChatGPT uses your data
AI training
By default, OpenAI may use conversations from Free, Go, Plus, and Pro users to train and improve its models. This includes prompts, uploads, responses, and feedback.
Temporary Chats are excluded from training. ChatGPT Business, Enterprise, Edu, and API data is also excluded by default, unless the organization chooses to opt in.
If you delete your data to limit future AI training, OpenAI says it will remove it from its systems within 30 days. However, this comes with two major caveats. First, OpenAI can hold onto your data longer if it needs to for legal, regulatory, or safety reasons. Second, once your content is stripped of your account details and used to train OpenAI’s models, it becomes a permanent part of the software and cannot be undone.
Human reviewing
OpenAI uses automated systems to scan chats, but human reviews can be used to monitor abuse, enforce safety rules, investigate reports, improve reliability, or meet legal obligations.
OpenAI says that even if you have opted out of training, the full conversation linked to thumbs-up or thumbs-down feedback may still be used to improve its models. For voice chats, OpenAI also says a human may review recordings linked to thumbs-down feedback.
Temporary Chat reduces some data use, but it does not make a conversation invisible to OpenAI. Though not used for training and will not appear in your history, Temporary Chats may still be reviewed for abuse monitoring.
Sharing with third parties
ChatGPT shares data with service providers including cloud hosting, analytics, customer support, payments, communications, security, fraud prevention, and other operational tools.
Data can also be shared with affiliates, business partners, legal authorities, industry peers, or other third parties when needed for corporate changes, legal compliance, policy enforcement, fraud prevention, safety, rights protection, or liability management.
Dependence on outside vendors creates a permanent weak link in user privacy. A data breach at a third-party partner can easily expose your information, leaving records vulnerable even when OpenAI's primary infrastructure remains secure.
Advertising and selling data
OpenAI claims not to sell your personal data for advertising or share personal data for targeted advertising across other websites and apps. Paid tiers like Plus, Pro, Business, and Enterprise currently remain completely ad-free.
Advertisements will show on Free and Go plans. OpenAI states that these ads will not influence assistant responses and that conversations will not be shared directly with advertisers.
However, what exactly is shared with advertisers is vague, and ChatGPT can still use in-app activity to determine which ads to show. Depending on your settings, those signals may include the current chat, past chats, memory, ad interactions, general location, and language.
Content ownership and user rights
You retain ownership of the data you provide to ChatGPT. OpenAI also assigns you its rights, title, and interest in the data it generates, subject to applicable law.
However, owning your prompts and responses doesn’t make them private. OpenAI may still process this data to deliver services, maintain safety, meet legal obligations, or improve models unless you opt out.
The broader legal picture around AI content is unsettled. Authors, news outlets, and publishers have sued OpenAI, arguing that its models were trained on copyrighted work without permission or payment. So while OpenAI gives people rights over their own inputs and outputs, the ownership questions around AI training data and generated content are still being disputed in court.
ChatGPT’s encryption, compliance, and data residency
Data encryption
For Enterprise customers, OpenAI uses AES-256 encryption for data at rest and TLS 1.2 or higher for data in transit. These protections reduce risks like interception and unauthorized access, but they are not as strong as end-to-end or zero-access encryption — OpenAI still has the technical ability to access your chat data.
For individual plans, OpenAI mentions encryption for data in transit and at rest, but it's unclear how it differs from the Enterprise plans.
Regulatory compliance
OpenAI’s policies describe rights under privacy laws such as the GDPR and CCPA, including the right to access, correct, delete, restrict, transfer, or object to data processing.
For people in the EEA and Switzerland, OpenAI Ireland Limited is the data controller. For everyone else, OpenAI OpCo, LLC is generally the controller. Business customers may also get compliance support aligned with SOC 2, ISO, and CSA STAR standards.
ChatGPT data residency
OpenAI may process and store personal data in the United States and other countries where its affiliates, vendors, or service providers operate. Although the controversial FISA Section 702 technically expired in June 2026, active court orders keep the program running until at least March 2027, meaning US intelligence agencies can still compel American companies to provide foreign user data without a warrant.
Some business, enterprise, and API customers can use data residency or inference residency options. Individual Free, Go, Plus, and Pro users cannot choose a specific storage region, even if they are covered by the European privacy policy.
How to reduce ChatGPT data collection
These steps can reduce how much of your data is retained or used for model improvement, although they do not make ChatGPT zero-access encrypted.
Turn off model training
Go to Settings → Data Controls and switch off Improve the model for everyone. Once this setting is disabled, new conversations should no longer be used to train OpenAI’s models.
OpenAI may still process data to maintain security, prevent abuse, comply with legal obligations, or handle safety-related cases.
Use Temporary Chat
Open a Temporary Chat for conversations you don’t want to appear in your history, Memories, or be used for model training.
Temporary Chats are not completely invisible to OpenAI. They are retained for up to 30 days and may still be reviewed for abuse monitoring.
Delete chats and Memories
Open the chat options menu to delete individual conversations, or go to Settings → Data Controls to clear all chats. To remove saved Memories, go to Settings → Personalization → Memory.
Deleted chats and files are generally removed from OpenAI’s systems within 30 days, unless they are retained for legal or security reasons.
Export your ChatGPT data
Go to Settings → Data Controls → Export Data, then select Export and confirm the request. OpenAI sends a download link to the email address or phone number linked to your account.
Note: Exporting data does not delete it from OpenAI servers.
Delete your OpenAI account
On ChatGPT web, go to Profile → Settings → Account → Delete account, then follow the confirmation steps.
Account deletion removes access to OpenAI services, including ChatGPT, API, and DALL·E. Limited records may still be kept for security, legal, accounting, dispute resolution, or regulatory reasons.
Submit a privacy request
Go to OpenAI’s Privacy Portal, select Make a Privacy Request, then choose the type of request you want to submit.
Privacy rights vary by region, but users covered by laws such as the GDPR or CCPA may have additional data subject rights.
ChatGPT makes privacy optional, not the default
ChatGPT does have privacy controls, but they're opt-ins for individual accounts, with the defaults favoring data collection and model training. If the way OpenAI handles your data doesn't sit right with you, consider a ChatGPT alternative that makes privacy the default.
Switch to a private AI assistant
Lumo is designed for people who want an AI assistant that doesn’t treat the collection and reuse of their conversations as a necessary tradeoff just to get the benefits of AI.

Frequently asked questions about ChatGPT's privacy policy
- Can governments see my ChatGPT data?
- Can I completely delete my data from ChatGPT?
- Is Temporary Chat private?


