ChatGPT
Is ChatGPT safe?
- Made by
- OpenAI
- Company based in
- United States
- Trains on your chats
- Yes, unless you opt out
- People can read chats
- Yes
- Temporary chat mode
- Yes
- Chats used for ads
- Yes
- Minimum age
- 13
- Regulator actions listed
- 7
- Checked on
OpenAI encrypts chats and publishes security certifications, but on personal plans your chats are used to train its models unless you turn off “Improve the model for everyone”, and authorized staff and contractors can read conversations for safety, support and (unless you opt out) model improvement. Chats stay until you delete them; deleted chats are removed within 30 days. Free and Go plans can show ads chosen from your conversation.
Business, Enterprise and API data is not used for training by default. Temporary Chat is never used for training and is deleted within 30 days.
OpenAI has disclosed two incidents affecting users: a March 2023 bug that showed some users other people’s chat titles and exposed limited payment details of 1.2% of Plus subscribers, and a November 2025 breach at the analytics vendor Mixpanel that exposed profile data of some API users, which OpenAI says did not include chats. Italy’s data protection authority blocked ChatGPT for a month in 2023 and fined OpenAI €15 million in December 2024; the authority’s own page now says that decision was annulled by a Rome court in March 2026.
- Company responsible for your data
- OpenAI OpCo, LLC; OpenAI Ireland Limited for the EEA and Switzerland
- What is used for training
- For individual services such as ChatGPT and Codex, OpenAI "may use your content to train our models" (prompts, responses, images, files) unless you turn off "Improve the model for everyone"; opting out applies to new conversations. Even after opting out, thumbs-up/down feedback can put "the entire conversation associated with that feedback" into training, and Temporary Chats are never used for training.
- How to turn training off
- Web: profile icon > Settings > Data Controls > turn off "Improve the model for everyone". Mobile: side-bar menu > profile icon > Data Controls > turn off "Improve the model for everyone". Alternatively, choose "do not train on my content" in the privacy portal (privacy.openai.com). Codex's full-environment training has a separate setting.
- Business and API plans
- "By default, we do not train on any inputs or outputs from our products for business users, including ChatGPT Business, ChatGPT Enterprise, and the API"; API organizations can opt in to data sharing.
- How long chats are kept
- Chats are kept until you delete them ("Information we retain until you delete it"); longer retention is possible for safety, legal (e.g. subpoena), fraud/abuse or financial record-keeping reasons.
- After you delete a chat or account
- Deleted chats or accounts are removed from OpenAI's systems "within 30 days" unless they must be kept for security or legal reasons, or were "previously de-identified and disassociated from your account". After full account deletion, you can reuse the email for a new account after 30 days.
- Human review
- Yes. "A limited number of authorized OpenAI personnel, as well as trusted service providers" may access content for abuse or security investigations, support, legal matters, or "to improve model performance (unless you have opted out)". Selected portions may go to service providers "for data annotation and safety purposes". Temporary Chats "may be reviewed only to monitor for abuse".
- Temporary chat
- Temporary Chat: not saved to history, creates no memories and is not used for training. It is deleted within 30 days ("OpenAI may retain a copy for up to 30 days for safety purposes"). Saving a temporary chat turns it into a regular chat.
- Where data is stored
- "Content is stored on OpenAI systems and our trusted service providers' systems in the US and around the world." The EU policy says data is processed "on servers located outside of the EEA, Switzerland and the UK", including in the US, under adequacy decisions and SCCs. Business plans offer data residency.
- Age rules
- 13 (or the minimum age required in your country to consent); users under 18 need a parent's or legal guardian's permission.
- Ads
- Free and Go plans can show ads. They can be chosen from the current chat and, with "Personalize ads" on, from past chats and memory. Plus, Pro, Business, Enterprise and Edu have no ads. OpenAI says advertisers do not get access to chats and receive only aggregate data. Controls: Settings > Ad Controls.
- Security and certifications
- For individuals, content is "encrypted at rest and in transit between you and OpenAI, and between OpenAI and its service providers"; Advanced Account Security is optional. Enterprise pages state AES-256 at rest and TLS 1.2+ in transit. Certifications: SOC 2 Type 2 (API and ChatGPT business products); ISO/IEC 27001:2022 and 27701:2019 (API, ChatGPT Enterprise, Edu); ISO/IEC 42001:2023 covering consumer and business products; PCI-DSS for delegated payment components; CSA STAR Level 1. Trust portal: https://trust.openai.com
- Regulator actions
Date Authority Action Source 2023-03-30 Garante per la protezione dei dati personali (Italy) Ordered an urgent temporary limitation on the processing of Italian users' data by OpenAI, citing no information notice, no legal basis for training and no age verification. ChatGPT was effectively blocked in Italy. https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9870832 2023-04-12 Garante per la protezione dei dati personali (Italy) Announced its 11 April 2023 order: the limitation would be lifted if OpenAI met measures by 30 April (transparency notice, legal basis for training, right to object, age gating and an age-verification plan). https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9874751 2023-04-28 Garante per la protezione dei dati personali (Italy) Confirmed that OpenAI had brought ChatGPT back in Italy after adopting the required transparency and rights measures, and said its investigation would continue. https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9881490/ 2023-07-27 Personal Information Protection Commission (South Korea) Fined OpenAI KRW 3.6 million for not reporting the March 2023 data breach (687 Korean users affected) and issued improvement recommendations. https://www.pipc.go.kr/eng/user/ltn/new/noticeDetail.do?bbsId=BBSMSTR_000000000001&nttId=2271 2024-05-23 European Data Protection Board (ChatGPT Taskforce) Published the ChatGPT Taskforce report on the coordinated national investigations into OpenAI's processing. It notes that the one-stop-shop mechanism has applied since 15 February 2024. http://edpb.europa.eu/system/files/2024-05/edpb_20240523_report_chatgpt_taskforce_en.pdf 2024-12-20 Garante per la protezione dei dati personali (Italy) Fined OpenAI EUR 15 million and ordered a 6-month information campaign; the Garante's page now says the decision was removed after the Tribunale di Roma upheld OpenAI's appeal (judgment 4153/2026, published March 18, 2026). https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10085432 2025-09-11 US Federal Trade Commission Issued 6(b) orders to seven companies, including OpenAI OpCo, LLC, for a study of AI chatbots acting as companions and their effects on children and teens. This is a study, not an enforcement action. https://www.ftc.gov/news-events/news/press-releases/2025/09/ftc-launches-inquiry-ai-chatbots-acting-companions - Data incidents disclosed by the company
Date What happened Source 2023-03-24 A bug let some users see other users' chat titles; payment details of 1.2% of active ChatGPT Plus subscribers could be exposed during a nine-hour window on March 20, 2023. https://openai.com/index/march-20-chatgpt-outage/ 2025-11-26 A breach at analytics vendor Mixpanel exposed limited profile data of API users and some ChatGPT users; OpenAI says no chats, passwords, API keys or payment data were exposed. https://openai.com/index/mixpanel-incident/ - Privacy policy
- openai.com
- Terms
- openai.com
- Data controls help page
- help.openai.com
- Sources
Page URL OpenAI Privacy Policy (rest of world), updated Feb 6, 2026 https://openai.com/policies/row-privacy-policy/ OpenAI Europe Privacy Policy, updated Aug 24, 2026 https://openai.com/policies/eu-privacy-policy/ OpenAI US Privacy Policy, updated May 18, 2026 https://openai.com/policies/us-privacy-policy/ OpenAI Terms of Use, effective Jan 1, 2026 https://openai.com/policies/row-terms-of-use/ Help: How your data is used to improve model performance https://help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance Help: Data Controls FAQ https://help.openai.com/en/articles/7730893-data-controls-faq Help: How OpenAI handles data in consumer services https://help.openai.com/en/articles/7039943-how-openai-handles-data-in-consumer-services Help: Ads in ChatGPT https://help.openai.com/en/articles/20001047-ads-in-chatgpt Enterprise privacy at OpenAI https://openai.com/enterprise-privacy/ Security and privacy at OpenAI https://openai.com/security-and-privacy/ March 20 ChatGPT outage https://openai.com/index/march-20-chatgpt-outage/ Mixpanel security incident https://openai.com/index/mixpanel-incident/ Garante decision, March 30, 2023 https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9870832 Garante press release, April 12, 2023 https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9874751 Garante press release, April 28, 2023 https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9881490/ Garante press release, December 20, 2024 (with note on annulment) https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10085432 PIPC press release, July 27, 2023 https://www.pipc.go.kr/eng/user/ltn/new/noticeDetail.do?bbsId=BBSMSTR_000000000001&nttId=2271 EDPB ChatGPT Taskforce report http://edpb.europa.eu/system/files/2024-05/edpb_20240523_report_chatgpt_taskforce_en.pdf FTC 6(b) AI companion chatbots press release https://www.ftc.gov/news-events/news/press-releases/2025/09/ftc-launches-inquiry-ai-chatbots-acting-companions
