Is ChatGPT Safe for Confidential Information? An Honest Answer

Basics|11 min read|Updated 2026-07-19
Written byMoneli Automation
Technically reviewedMoneli Automation
Last verified2026-07-19
This guide is notlegal advice

Disclaimer: This content is for educational purposes only and does not constitute medical, legal, or financial advice. CPT descriptions are original summaries — not official AMA text. Always verify billing and credentialing details with your payer. Read full disclaimer

Short answer: for genuinely confidential material, treat the free and personal versions of ChatGPT as unsafe by default — not because the provider is malicious, but because you're handing confidential data to a third party under terms most offices have never read. The longer answer is more useful, because "safe" depends on which version, whose data, and what obligations you carry.

What Actually Happens When You Paste Text In

When someone in your office pastes a client file into ChatGPT, that text is sent to the provider's servers and processed there. From that moment, three separate questions decide your exposure:

  1. Is it used for training? For consumer tiers, the provider's own documentation states conversations may be used to improve models unless you opt out; business tiers exclude this by default (OpenAI's data-usage page and enterprise privacy commitments — check the current versions; policies change).
  2. Is it retained, and who can see it? Conversations are stored, at minimum temporarily, and may be reviewable under the provider's policies (for abuse monitoring, for example) and reachable by legal process.
  3. Did you have the right to share it at all? This is the one offices forget. If you owe a client confidentiality — as a lawyer, clinician, or accountant typically does — disclosing their information to any third party without a proper basis can breach that duty even if the provider never misuses it. The breach is the disclosure, not the outcome.

That third question is why "but the provider promises not to train on it" doesn't end the conversation. Privacy regulators have said as much: the Office of the Privacy Commissioner of Canada's principles for generative AI, for example, say organizations should "know and document their legal authority for collection, use, disclosure and deletion of personal information" in generative AI systems — in other words, putting personal information into an AI service is a use and disclosure you must be able to justify, not a neutral act.

A common workaround here is DIY anonymization — swap in mock names before pasting, find-and-replace them back afterwards. It helps, but less than it feels like it does: names are rarely the only identifying detail in a client file, and the confidential facts themselves (the transaction, the diagnosis, the dispute) can identify the client to anyone who knows the situation. Treat it as risk reduction for borderline material, not a licence to paste anything.

Does ChatGPT Train on My Data? Plan by Plan, From OpenAI's Own Documentation

The answer genuinely differs by plan, and most summaries you'll find online are out of date — including the plan names. OpenAI's lineup is now Free, Go, Plus, Pro, Business, and Enterprise (current pricing page); the plan formerly called Team is now ChatGPT Business. Here is what OpenAI's own current documentation says, cell by cell:

FreePlusBusiness (formerly Team)Enterprise
Price$0 (pricing)$20/month (pricing)$20/user/month billed annually (2+ users), $25 monthly (business pricing)Custom — contact sales (business pricing)
Trains on your chats by default?Yes, unless you opt out (data-usage page)Yes, unless you opt out (same source)No — "we do not train on any inputs or outputs from our products for business users" (same page; enterprise privacy)No — same default, opt-in only (enterprise privacy)
How you turn training off"Improve the model for everyone" toggle, Settings → Data Controls; applies account-wide (Data Controls FAQ)Same toggle, same placeAlready off; sharing data is an explicit opt-inAlready off; sharing data is an explicit opt-in
Deleted chatsRemoved from your account immediately; "scheduled for permanent deletion from OpenAI systems within 30 days," with de-identification and security/legal exceptions (retention policy)Same as FreeDeleted or unsaved conversations removed within 30 days unless required by law or needed to protect against harm (enterprise privacy)Same 30-day rule (enterprise privacy)
Who controls retention?You (per-chat deletion; Temporary Chats auto-delete within 30 days)You (same)Workspace admins — they "can control how long your data is retained" and can view, access, export, and delete end-user conversations (enterprise privacy)Workspace admins — retention controls, plus a Compliance API audit log of conversations (enterprise privacy)
Security & compliance commitmentsConsumer terms onlyConsumer terms onlySOC 2 Type 2 audited; AES-256 at rest, TLS 1.2+ in transit; DPA available (enterprise privacy)SOC 2 Type 2; SAML SSO; AES-256 / TLS 1.2+; DPA available (enterprise privacy)

The Go ($8/month) and Pro ($100/month) plans follow the same consumer rules as Free and Plus: training on by default, same opt-out toggle, same retention behavior.

Plain English for that last row: "SOC 2 Type 2" means an independent auditor has checked the company's security controls over time; "AES-256 at rest, TLS 1.2+ in transit" means your data is encrypted both while stored and while travelling over the internet; a "DPA" is a signable contract governing how the vendor processes your data; "SAML SSO" means staff log in through your company's own login system.

Three details from the fine print worth knowing before you rely on this table:

  • The opt-out has a leak. Even with "Improve the model for everyone" turned off, giving a thumbs-up or thumbs-down on a response can cause "the entire conversation associated with that feedback" to be used for training (OpenAI's data-usage page). If your office opts out, staff should also skip the feedback buttons on anything sensitive.
  • Temporary Chats are the strongest consumer setting. They're excluded from training, don't create memories, and are deleted from OpenAI's systems within 30 days — reviewed only for abuse monitoring (Data Controls FAQ; retention policy).
  • No BAA on the ordinary chat products. OpenAI offers HIPAA Business Associate Agreements for its API platform and — as of January 2026 — for its dedicated ChatGPT for Healthcare product, which it will sign with qualifying healthcare organizations. But not for ChatGPT Business or Enterprise as sold off the shelf (enterprise privacy page; HIPAA Journal's analysis) — a distinction that matters if you handle health information. (In plain English: a BAA is the signed contract HIPAA requires before a vendor may touch patient data.)

One honest caveat about this table: it is accurate as of the last verified date above, sourced entirely from OpenAI's own pages — and those pages change. If a decision hangs on a cell, click through and read the current version.

ChatGPT Data Retention: Are "Deleted" Chats Really Gone?

The retention policy is genuinely reasonable on paper: delete a chat and it's removed from your account immediately and "scheduled for permanent deletion from OpenAI systems within 30 days" — unless it's already been de-identified, or unless OpenAI must keep it "for security or legal obligations" (retention policy).

That last exception recently stopped being theoretical. During The New York Times' copyright lawsuit against OpenAI, a court order required OpenAI to preserve consumer ChatGPT content — including chats users had deleted — regardless of its published policy. By OpenAI's own account, that obligation ended on September 26, 2025, but a limited set of April–September 2025 user data remains preserved under legal hold at the newspaper's demand. The order covered Free, Plus, Pro, and the then-named Team plan; ChatGPT Enterprise was excluded.

The lesson for a small office isn't "OpenAI misbehaved" — it complied with a court, then pushed back publicly. The lesson is structural: when your data sits on someone else's servers, a legal fight you're not even a party to can override the delete button. That's not a risk any policy toggle removes; it's a property of where the data lives.

When It's Genuinely Fine

An honest guide says this part out loud: most ChatGPT use is fine. Drafting a marketing email, summarizing a public article, rewriting your own non-sensitive text, brainstorming — none of that involves confidential information, and banning it wholesale mostly produces quiet rule-breaking. The problem is never "staff use AI"; the problem is unsorted use, where the harmless and the harmful flow through the same chat window with nobody deciding which is which.

Where Offices Actually Get Burned

The realistic failure isn't cinematic. It's an assistant pasting a patient referral to "clean up the wording." A junior associate summarizing discovery documents. A bookkeeper asking the chatbot to explain a client's unusual transactions. Each one felt like using a spellchecker; each one was a disclosure of confidential material to a third party.

This isn't speculation — the pattern is documented:

  • In healthcare, researchers describe clinicians already using ChatGPT for the routine load — in one USC researcher's words, the "correspondence that everybody has to do, but nobody wants to do" — and put the legal frame bluntly: "Once you enter something into ChatGPT, it is on OpenAI servers and they are not HIPAA compliant… that is, technically, a data breach." HIPAA Journal's assessment of consumer tiers reaches the same conclusion.
  • In law, the North Carolina Bar Association's 2026 practice guidance warns that banning AI without an approved alternative backfires: lawyers "under pressure to be efficient, may turn to free, consumer-grade tools… on personal devices," and — their words — "prohibition drives usage underground; clear policies bring it into the open where it can be supervised."
  • Across workplaces generally, a 2026 survey of 1,250 office professionals found 66% had knowingly used AI in ways they believed violated company policy. And 88% had put work-related information into public AI tools; within that group, 43% had shared emails and other correspondence, 34% customer data, and 31% financial information or confidential company documents. (That survey sampled large enterprises; treat it as directional for small offices, where there's usually even less oversight.)

The shadow use problem, in short: if you haven't looked, the honest assumption is that it's happening in your office too — and the professional guidance above agrees that the fix is sorting and supervising, not banning.

Your Three Real Options

  1. Sort your usage. Allow public AI tools for public material, with a written rule staff can actually follow ("nothing you wouldn't email a stranger"). Cost: a policy conversation. This is the floor, and every office should do it this week.
  2. Buy the business tier and read the terms. Stronger contractual commitments, no-training defaults, admin controls — the middle two columns of the table above. The third party remains — for some obligations (health data rules, strict confidentiality duties, data-residency requirements) that can still be the sticking point — but the risk category shrinks meaningfully.
  3. Move the sensitive work to hardware you own. Local AI removes the third party from the loop entirely: the model runs on a machine in your office, and the custody chain is your staff → your network → your hardware, full stop. The trade is up-front cost and some peak capability. It's the option whose "is this safe?" analysis your existing policies already know how to do, because it's the same analysis as any other office system — and it's the only option where a preservation order in a vendor's lawsuit doesn't sweep in your data. (Legal process aimed at you still reaches your own hardware, as it always has.)

Which option fits depends on how sensitive your data is and how much of your daily work touches it — which is exactly what the readiness quiz estimates in two minutes, and what the cost worksheet prices honestly.

Worked Example

Illustration — a fictional office, showing the pattern.

A four-person accounting firm discovers, during a staff conversation (not an incident), that two employees regularly paste client spreadsheets into a free AI chatbot to draft explanation letters. The firm doesn't panic and doesn't ban: it sorts. Public-material drafting stays on the free tool; a written one-line rule covers what may never leave the office; and because client financials touch most of their daily work, they run the numbers on a local setup for the sensitive half. The exposure ended the day the rule was written — the deployment decision was made calmly, weeks later, on cost rather than fear.

Next step

Wondering if this fits your office?

The readiness assessment walks through your data sensitivity, current AI use, and what a local setup would actually involve — with an engineer, not a salesperson.

Assess your readiness →

Frequently Asked Questions

Ask about this article

Get a plain-language answer drawn from this article. Answers are AI-generated from the text on this page.

Please don’t paste confidential or client information.

500 left

External Resources

Authoritative references and tools related to this documentation type.