AI Chatbots & Assistants

ChatGPT

High risk

OpenAI's conversational AI assistant for writing, research, coding, and file analysis, available in consumer and enterprise tiers.

Verified 2026-08-31OpenAIchatgpt.com

Is ChatGPT safe for confidential data?

ChatGPT's consumer tiers (Free, Plus, Pro) may use what employees type to train OpenAI's models unless each user opts out individually, and chat history is retained by default. ChatGPT Business (formerly Team) and Enterprise do not train on customer data and add admin controls, but most unmanaged workplace use happens on consumer accounts — which is where confidential data leaks. Treat consumer ChatGPT as an untrusted destination for client or company data.

Risk by plan

The same product often carries very different terms depending on the tier — consumer plans are where the exposure concentrates.

Free / Plus / Pro (consumer)
Trains on inputs

Training on by default; per-user opt-out. No admin visibility or controls.

Business (formerly Team)
No training

No training on business data by default; workspace admin controls.

Enterprise
No training

Contractual no-training default, SSO, SCIM, audit logs, DPA, SOC 2 Type II scope.

Data handling

Training on inputs

Consumer tiers (Free, Plus, Pro) use conversations to improve models by default; users can opt out in settings. Business (formerly Team), Enterprise, Edu, and the API do not train on customer data by default.

Retention

Consumer chat history is retained until the user deletes it, with a deletion grace window, and may be preserved longer under legal hold. Enterprise admins can configure retention.

Residency

Data is processed in OpenAI-managed cloud infrastructure, primarily in the United States; Enterprise and API offer regional data-residency options in select regions.

Compliance

  • SOC 2Yes
  • GDPR / DPAYes
  • HIPAA BAAConditional

Certifications typically apply to specific tiers and contracts — confirm scope in writing before relying on them.

New to these frameworks? See our plain-language guides to SOC 2 and the other AI compliance standards.

Enterprise controls

  • SSO / SAML (Enterprise)
  • Admin console and usage insights
  • Data Processing Addendum
  • Configurable retention (Enterprise)
  • No-training contractual default (Business/Enterprise)

Frequently asked questions

Does ChatGPT train on my data?

On consumer tiers (Free, Plus, Pro), OpenAI may use your conversations to improve its models unless you opt out in your data-control settings. ChatGPT Business (formerly Team), Enterprise, and the API do not train on customer inputs by default.

Is ChatGPT safe for confidential client data?

Not on consumer accounts. Anything pasted into a personal ChatGPT account leaves your organization's control, may be retained indefinitely, and may be used for model training. Enterprise tiers reduce this risk contractually, but sensitive identifiers should still be redacted before they reach the prompt.

Is ChatGPT HIPAA compliant?

Consumer and standard business tiers are not covered by a BAA. OpenAI has offered BAAs only for qualifying API/enterprise healthcare arrangements — confirm coverage in writing before any PHI touches the product.

How do I stop employees pasting sensitive data into ChatGPT?

Blocking the site usually fails — employees switch to personal devices. The workable pattern is visibility plus automated redaction: detect AI destinations, strip PII and client identifiers from prompts before they leave the browser, and keep an audit trail. That is what Sanitized AI does.

Policy changelog

  • Initial entry published from OpenAI's published policies.

Sources

This profile summarizes the vendor's published policies as of the verification date. It is not legal advice.

ChatGPT is probably already in your organization.

Sanitized AI shows you who is using it and redacts sensitive data from prompts before it leaves your control.

Get a demo

More AI tool profiles