
Short answer: not in the way a conversation with a doctor or lawyer is. As of October 2026, OpenAI's own documents say that chats on personal plans may be used to train models by default unless a setting is switched off; that a limited number of authorised staff and service providers can access content for four stated purposes; that deleted chats and Temporary Chats are removed within 30 days unless they must be kept for security or legal reasons; and that personal data can be shared with government authorities to comply with a legal obligation. A court order did force the company to keep deleted consumer chats from April to September 2025. OpenAI states that it does not sell personal data. Business plans carry different, stricter terms.
Everything below is taken from documents opened in the first week of October 2026. These policies change, and at least one of the help pages showed an edit from the previous day.
Four meanings of "private"
The question gets muddled because the word covers four unrelated things. A product can be good on one and poor on another.
| Meaning of "private" | The question | What OpenAI's documents say for personal plans |
|---|---|---|
| Access | Who at the company can read a chat? | A limited number of authorised personnel and service providers, for abuse and security investigations, support, legal matters, and model improvement if not opted out |
| Training | Does the chat become training data? | It may, by default. A setting turns this off |
| Retention | How long is it kept, including after deletion? | Saved chats stay in the account; deleted chats are scheduled for removal within 30 days, with exceptions |
| Legal privilege | Can it be demanded in a legal case? | The privacy policy allows disclosure to government authorities to comply with a legal obligation. No privilege is claimed |
The rest of this article takes the four in order.
Who can see my ChatGPT conversations
OpenAI's consumer data FAQ gives a direct answer. A limited number of authorised OpenAI personnel, along with trusted service providers, may access user content "only as needed" for four purposes:
- Investigating abuse or a security incident
- Providing support and troubleshooting
- Handling legal matters
- Improving model performance, unless the user has opted out
The same page says that access is subject to technical access controls, is limited to authorised personnel on a need-to-know basis, that staff must complete security and privacy training before accessing user content, and that all access is monitored and logged.
That is a description of controlled access, not of no access. The enterprise page describes encryption at rest (AES-256) and in transit (TLS 1.2 or higher), which protects data from outsiders and does not prevent the company itself from reading it. The documents do not say how often access happens or how many people are authorised. No number is published in the pages checked, so none is given here.
Beyond staff, the privacy policy lists other recipients of personal data: vendors and service providers, affiliates, and government authorities where required to comply with a legal obligation.
Does ChatGPT use your data for training
On personal plans, yes, by default. OpenAI's help page on model improvement says that when someone uses its services for individuals, the company "may use your content to train our models".
The opt-out is a single switch: Settings > Data controls > Improve the model for everyone. Two details from the help pages are worth knowing:
- Turning the switch off does not delete or hide saved chats.
- Feedback overrides the opt-out. If a user clicks thumbs up or thumbs down on a response, the entire conversation attached to that feedback may be used for model improvement, even with the setting off.
For business products the default is reversed. The enterprise privacy page and the help centre both say that inputs and outputs from ChatGPT Business, ChatGPT Enterprise, ChatGPT Edu and the API are not used to train models by default.
Does ChatGPT save your data, and are deleted chats really deleted
Chats are saved to the account history unless Temporary Chat is used. The pages checked describe no automatic expiry for saved or archived chats on personal plans; archiving only moves a chat out of the sidebar and does not delete it.
Deletion is described consistently in OpenAI's privacy policy and consumer FAQ. A deleted chat disappears from the account view immediately and is scheduled for permanent deletion from OpenAI's systems within 30 days, with two exceptions:
- it had already been de-identified and disassociated from the account, or
- OpenAI must keep it longer for security or legal obligations.
The second exception is not hypothetical. OpenAI's own account of its litigation with The New York Times says that a court order required it to retain consumer ChatGPT and API content indefinitely, including deleted chats that would normally have been removed. According to that page:
| Detail | What OpenAI's page states |
|---|---|
| Who was covered | ChatGPT Free, Plus, Pro and Team; API users without Zero Data Retention |
| Who was not | ChatGPT Enterprise and Edu; API customers on Zero Data Retention endpoints |
| When the obligation ended | 26 September 2025 |
| What is still held | "Limited historical April–September 2025 user data" |
| Who can reach it | A small, audited legal and security team, for legal obligations only |
This is the company's description of the order, not the order itself, which was not opened for this article. The practical lesson does not depend on the fine print: a deletion promise is always subject to legal process, and for about five months in 2025 pressing delete on a consumer account did not remove the chat from OpenAI's systems.
Is Temporary Chat private
Temporary Chat is the closest thing ChatGPT has to a private mode, and it is narrower than the name suggests. According to the Temporary Chat FAQ:
- The chat stays out of history and is not used to improve models "while it remains temporary". A temporary chat can be saved, at which point ordinary rules apply.
- OpenAI "may keep a copy of a temporary chat for up to 30 days for safety purposes". The privacy policy adds "unless we have to retain them for safety or legal reasons".
- A temporary chat can be started in a personalised mode that still uses existing memories and custom instructions.
- If a custom GPT sends data to a third party through an action, that data is governed by the recipient's privacy policy, and the recipient may keep it for longer than 30 days.
So Temporary Chat answers the training question and shortens retention. It does not change who can access content during those 30 days, and it does nothing about legal process.
Plan by plan: training, retention, human access
| Plan or setting | Trained on by default | Retention | Human access, as documented |
|---|---|---|---|
| Free, Plus, Pro, default settings | Yes, may be used | Saved until deleted; deleted chats removed within 30 days, with exceptions | Authorised personnel and service providers, four purposes |
| Same, with "Improve the model for everyone" off | No, except conversations with thumbs feedback | Unchanged | Same, minus model improvement |
| Temporary Chat | No, while it remains temporary | Up to 30 days, longer if required for safety or legal reasons | Not separately described; safety purposes are cited |
| ChatGPT Business | No | Workspace admins control retention | Incidents, recovering conversations with explicit permission, or where required by law |
| ChatGPT Enterprise, Edu | No | Customer controls retention | Same as Business |
| API | No | Zero Data Retention available for eligible endpoints on request | Same as Business |
The human-access wording for business products comes from the enterprise privacy page. On a workplace account there is a second audience that the table does not show: the employer, whose administrators set retention and manage the workspace.
Does ChatGPT sell your data
The US privacy policy says: "We don't “sell” Personal Data." The consumer FAQ says OpenAI "does not sell your data or share your ChatGPT conversations with advertisers".
The same US policy, in the version updated on 10 September 2026, also says that personal data is disclosed to "vendors, service providers, and marketing partners", and that, depending on the user's choices, "we may share limited data with select marketing partners for purposes of promoting our products and services to you on third-party properties". The policy's US state disclosures note that this kind of sharing counts as targeted advertising under certain state privacy laws, and that users can opt out with a marketing privacy control in account settings. Read together, the stated position is that conversations are not sold or given to advertisers, while some limited account-level data may be shared with marketing partners to promote OpenAI's own products. The policy does not list which data fields that covers.
Is ChatGPT confidential? Can chats be used in court?
This is the meaning of "private" that the settings menu cannot touch.
Confidentiality in the professional sense is a legal status, not a product feature. In general terms, the protection around a conversation with a lawyer, doctor or therapist comes from a professional relationship and the duties attached to it, not from the tool used to hold the conversation. Nothing in OpenAI's documents claims that a chat carries any such protection.
What the documents do say points the other way. The privacy policy allows sharing with government authorities where required to comply with a legal obligation, "handling legal matters" is one of the four listed purposes for staff access, and OpenAI's own account of the 2025 preservation order shows that chat logs can be swept into litigation the user has nothing to do with.
So the cautious working assumption for any chat is that it is a written record held by a third party, which may be sought through legal process. This is general information, not legal advice. Whether a particular chat is protected or can be used in a particular case is a legal question that varies by jurisdiction and circumstances, and it belongs with a lawyer. No statute or court ruling is cited here because none could be opened from an official source for this article.
Is ChatGPT HIPAA compliant
A personal ChatGPT account is not, and the question is slightly malformed. The Department of Health and Human Services explains that HIPAA applies to covered entities (health plans, health care clearinghouses, and health care providers that transmit information electronically in connection with certain standard transactions) and to their business associates. When a covered entity uses an outside service to handle health information, it must have a written business associate contract with that service.
Two consequences:
- For individuals: HIPAA does not apply at all when a person types their own symptoms or lab results into a consumer chatbot. The company is not that person's health care provider. The only protections are the privacy policy and general consumer law.
- For clinicians and health organisations: OpenAI's enterprise page says it is "able to sign Business Associate Agreements (BAA) in support of customers' compliance" with HIPAA, and lists a ChatGPT for Healthcare product among its business offerings. Without a signed BAA, putting patient information into a personal plan is a compliance problem for the clinician, whatever the product's security.
What the regulator has said
Privacy policies are written by the company, so the fair question is what holds a company to them. In the US the main answer is the Federal Trade Commission. In January 2024 staff in its Office of Technology published guidance titled AI Companies: Uphold Your Privacy and Confidentiality Commitments. Its points, in summary:
- Companies that fail to abide by privacy commitments to users and customers "may be liable under the laws enforced by the FTC".
- That includes promises not to use customer data for undisclosed purposes such as training or updating models.
- Past remedies have included requiring businesses to delete models and algorithms developed from unlawfully obtained data.
This is staff guidance, not a rule, and it names no company. Its relevance is that a statement such as "we do not train on business data by default" is an enforceable promise. It creates no right to confidentiality beyond what a company has promised.
What is not worth doing
Treating Temporary Chat as an incognito window. It stops history and training. A copy can still exist for up to 30 days, and longer under a legal hold.
Deleting chats after the fact and assuming they are gone. Deletion starts a 30-day clock that a court order can stop, as happened in 2025.
Switching assistants and assuming the problem is solved. Other consumer assistants publish their own training, retention and review terms, and the same four questions apply to each. Read the current policy before trusting a different product with sensitive material.
Abandoning the tools out of general unease. For most uses, such as rewriting an email or planning a trip, none of the four meanings of private is in play. The risk is concentrated in a small number of pastes.
What to actually do
Change three settings on a personal account:
- Turn off Improve the model for everyone under Settings > Data controls. This stops training use, apart from thumbs feedback.
- Use Temporary Chat for sensitive one-offs: no history, no training, a copy kept for up to 30 days.
- Review memory and personalisation, which decide what carries over between chats.
Skip the thumbs buttons on sensitive chats. OpenAI says the entire conversation attached to feedback may be used for training even when the setting is off.
Keep a short list of things that never get pasted:
- Passwords, API keys, recovery codes
- Social Security, passport, bank and card numbers
- Other people's medical, legal or financial details, which were never the user's to share
- Client or patient information, unless the organisation has a business plan and, for health data, a signed BAA
- Employer confidential material on a personal account
- Anything connected to a current or likely legal dispute; that conversation belongs with a lawyer
Use the work account for work. Business plans are not trained on by default and have tighter staff-access terms. The trade-off is that the employer's administrators control the workspace.
Delete old chats anyway. Deletion is imperfect and still reduces what is on file when an account is breached or a device is borrowed. It fits naturally into the same sitting as a subscription audit, and into a broader habit of digital minimalism: fewer accounts holding less.
Re-check once or twice a year. The US policy was updated in September 2026.
Privacy is one cost of these tools and not the only one. The water and energy used by AI is a separate ledger, and so is the time they absorb, which the evidence on how much screen time is too much covers.
Questions people ask
Is ChatGPT private? Not fully. On personal plans, OpenAI's documents say chats may be used for training by default, can be accessed by authorised staff for four stated purposes, and are removed within 30 days of deletion unless security or legal obligations require otherwise. Business plans are not trained on by default.
Does ChatGPT save your data? Yes. Chats are saved to the account history until the user deletes them, unless Temporary Chat is used. Temporary chats may still be kept for up to 30 days for safety purposes.
Does ChatGPT sell your data? OpenAI's US privacy policy states that it does not sell personal data, and its consumer FAQ says conversations are not shared with advertisers. The same policy says limited data may be shared with select marketing partners to promote OpenAI's products, with an opt-out, and that data goes to vendors and affiliates.
Is ChatGPT confidential? Not in the professional sense. Confidentiality with a lawyer, doctor or therapist comes from a professional relationship. OpenAI's documents claim no such protection for chats, and its policy allows disclosure to government authorities where needed to comply with a legal obligation.
Who can see my ChatGPT conversations? According to OpenAI, a limited number of authorised personnel and trusted service providers, for abuse or security investigations, support, legal matters and model improvement unless opted out. Access is logged. On workplace accounts, administrators also control the workspace.
Does ChatGPT use your data for training? On Free, Plus and Pro, it may by default. Turning off "Improve the model for everyone" under Settings, Data controls stops this, except for conversations where thumbs up or down feedback is given. Business, Enterprise, Edu and API data is not used for training by default.
Are deleted ChatGPT chats really deleted? Usually, within 30 days, according to OpenAI. The exceptions are chats already de-identified and chats that must be kept for security or legal obligations. Under a court order, deleted consumer chats from April to September 2025 were retained; OpenAI says that obligation ended on 26 September 2025.
Is Temporary Chat private? More than a normal chat, less than the name implies. It stays out of history and is not used for training while temporary. OpenAI may keep a copy for up to 30 days for safety purposes, and longer if required for safety or legal reasons.
Is ChatGPT HIPAA compliant? A personal account is not a HIPAA arrangement. HIPAA binds health providers, plans and their business associates, and requires a written contract between them. OpenAI says it can sign Business Associate Agreements for eligible business customers. Individuals typing their own health details are not covered by HIPAA at all.
Can ChatGPT conversations be used in court? They may be sought. Chats are records held by a third party, and OpenAI's policy permits disclosure to comply with legal obligations. OpenAI says a court order in 2025 required it to preserve consumer chats, including deleted ones, during litigation. Whether a given chat can be used in a given case is a question for a lawyer.
This article summarises company privacy documents and US government guidance as they read in October 2026, for general information. It is not legal advice, policies change without notice, and anyone with a legal, medical or compliance question about a specific situation should consult a qualified professional and the current version of each policy.
References
- OpenAI. Privacy Policy (United States), updated 10 September 2026. openai.com
- OpenAI Help Center. Data Usage for Consumer Services FAQ. help.openai.com
- OpenAI. Enterprise privacy at OpenAI. openai.com
- OpenAI. How we’re responding to The New York Times’ data demands in order to protect user privacy, updated 22 October 2025. openai.com
- OpenAI Help Center. How your data is used to improve model performance. help.openai.com
- OpenAI Help Center. Temporary Chat FAQ. help.openai.com
- Federal Trade Commission, Office of Technology (2024). AI Companies: Uphold Your Privacy and Confidentiality Commitments. ftc.gov
- U.S. Department of Health & Human Services. HIPAA: Covered Entities and Business Associates. hhs.gov
The weekly readout
One email each Thursday: what we tested, which claim collapsed under a closer look, and the one number worth paying attention to.