Update 8/17/2026
I am often asked some version of this question:
“Is ChatGPT private?”
The honest answer is it depends. It depends in ways that most people do not intuitively understand. There is privacy, of a sort. There are also real limitations. And paying for a higher-tier account does not automatically mean confidentiality.
This post explains what actually changes across ChatGPT account levels, what does not, and how to think about privacy in a way that is realistic rather than alarmist. Since I last updated this post, a federal court ordered OpenAI to preserve chats users thought they had deleted, and then to hand twenty million of them to opposing counsel as part of a lawsuit. That story is now part of this post, because it addresses what “delete” really mean, that is, just because you deleted something, it may not be gone. This is not a new concept, it is an issue we have dealt with as long as computers have existed, in one way or another.
Privacy Is Not Binary
The biggest mistake people make when thinking about AI tools is treating privacy as an on/off switch. It is not.
Privacy with ChatGPT is:
- Contextual (what you enter matters)
- Contractual (which terms apply to your account)
- Purpose-driven (training, operation, and legal compliance are distinct concepts)
The correct question is not “Is ChatGPT private?” The correct question, in my opinion should be asked this way:
“Private enough for what purpose, under which account terms?”
Consumer Accounts: Free, Go, Plus, and Pro
Let’s start with the accounts most individuals use.
Free and Go Accounts
Free and Go consumer accounts carry the highest privacy risk, relatively speaking.
Key points:
- Conversations may be used to improve models, unless the user opts out in settings
- Data is stored and logged
- Some conversations may be reviewed by humans for safety, quality, or abuse detection
- There are no individualized contractual assurances beyond the public privacy policy
- Ads appear in these accounts (see below)
This does not mean your content is publicly visible or reused verbatim elsewhere. It does mean that you should not treat a free or Go account as confidential. For lawyers, that alone should be dispositive.
Paid Consumer Accounts (Plus / Pro)
This is where many people assume privacy magically appears. It does not. What paying for a consumer account actually buys you:
- Access to more capable models
- Faster responses
- Larger context windows
- Priority availability
- No ads
What it does not automatically buy you:
- Attorney-client confidentiality
- Guaranteed non-retention
- A promise that data will never be reviewed
- A bespoke privacy contract
And one point that deserves emphasis: on every consumer tier, including Plus and Pro, training on your conversations is on by default. Paying does not change the default. Only the setting does.
Checking Whether Training Is On
The control lives at Settings, then Data Controls, then a toggle called “Improve the model for everyone.” If that toggle is on, your conversations may be used to train OpenAI’s models. If you turn it off, they are not used for training going forward.
Users can opt out of training in their account settings, which is meaningful. However, that opt-out:
- Limits model training use
- Does not guarantee deletion
- Does not eliminate retention for operational, safety, or legal reasons
There is also a trap hiding in plain sight, and it is the same one I flagged in my Claude post. Rating a response with a thumbs up or thumbs down submits that conversation as feedback, and OpenAI’s data controls documentation states that feedback can be used for training regardless of your opt-out. If a chat contains anything sensitive, do not rate it.
A paid consumer account is more powerful, and ad-free. It is not meaningfully more confidential.
Retention: What Deleting a Chat Actually Does
When you delete a chat, it disappears from your account immediately and is scheduled for permanent deletion from OpenAI’s systems within 30 days. Scheduled is the operative word. OpenAI’s own policy carves out several situations in which deleted content is kept longer:
- Security, fraud, and abuse investigations
- Financial record-keeping
- Legal holds, meaning a court or regulator has required OpenAI to keep it
- Content that has already been de-identified for model training, which deletion does not pull back
That last carve-out is easy to miss. If a conversation was used to train a model before you deleted it, deleting the chat does not remove anything from the model.
Temporary Chats
Temporary Chat is the closest thing consumer ChatGPT has to an incognito mode. A temporary chat does not appear in your history, does not create memories, and is not used to train models. It is still retained for up to 30 days, and it may still be reviewed for abuse. Temporary Chat is a good habit for one-off sensitive questions. It is not a confidentiality guarantee, and as you will see below, temporary chats were not beyond the reach of a court order either.
Memory Does Not Die With the Chat
ChatGPT’s memory feature stores details about you across conversations, both memories you ask it to save and information it draws from your chat history. Two things about memory surprise people. Turning memory off does not delete what has already been remembered; you have to delete stored memories separately. And deleting a chat does not delete the memories that came from it.
For a lawyer, the risk is accumulation. A client name here, a matter fact there, and the account has quietly built a profile that outlives every individual conversation. If you use a consumer account for anything near client work, turn memory off and review what is already stored. Settings, then Personalization.
The New York Times Case: When “Deleted” Chats Became Evidence
I want to spend real time here, because this is no longer hypothetical. Everything above about retention and deletion was stress-tested in an actual courtroom, and users lost.
The New York Times and other publishers are suing OpenAI over the use of their content to train models. In discovery, the plaintiffs wanted ChatGPT conversation logs. On May 13, 2025, Magistrate Judge Ona T. Wang of the Southern District of New York ordered OpenAI to preserve all output log data that would otherwise be deleted. That included chats users had deleted. It included temporary chats. The normal 30-day deletion cycle stopped, and everything was held.
The order covered ChatGPT Free, Plus, Pro, and Team accounts, along with standard API traffic. It did not cover ChatGPT Enterprise, ChatGPT Edu, or API customers on Zero Data Retention endpoints. Sit with that list for a moment. The dividing line between whose deleted chats were frozen and whose were not was the account type, the same dividing line this post has always been about.
The preservation order did not last forever. The court ended the going-forward obligation as of September 26, 2025, and formally terminated it by order on October 9, 2025. New deletions now purge on the normal schedule. But the data preserved during those months was not released. It remains held, and accounts specifically flagged by the plaintiffs remain subject to continued preservation.
Then came the part that should change how every lawyer thinks about these tools. The plaintiffs asked for a sample of the preserved logs, and the court said yes. On November 7, 2025, Judge Wang ordered OpenAI to produce 20 million de-identified consumer chat logs, and on January 5, 2026, District Judge Sidney Stein affirmed that order over OpenAI’s objections. The logs are de-identified and covered by a protective order, and the reasoning included the observation that users had voluntarily submitted their conversations to ChatGPT.
So the sequence, in plain terms: users deleted chats, a court ordered the chats kept anyway, and then a court ordered millions of them produced to an adversary in litigation. De-identification and a protective order are real protections. They are not the same as your conversations never leaving OpenAI.
Sam Altman himself has said the quiet part out loud. In a podcast interview in July 2025, he acknowledged that conversations with ChatGPT carry no legal privilege, unlike conversations with a lawyer, doctor, or therapist, and that OpenAI could be required to produce them in litigation. I wrote about privilege and AI more fully in my post on U.S. v. Heppner. The short version has not changed. It is privacy, not privilege.
Ads in ChatGPT
OpenAI announced its advertising approach on January 16, 2026, and began showing ads to U.S. users in February 2026. This changed the privacy picture for the free tiers.
Which accounts see ads:
- Free accounts: Yes
- Go accounts: Yes
- Plus, Pro, Business, Enterprise, and Education accounts: No
- Users identified as under 18: No
How ads work:
- Ads are clearly labeled as sponsored and visually separated from ChatGPT’s answers
- Ads do not influence the answers ChatGPT gives you
- Ads are always shaped by the context of your current conversation
- If ad personalization is on, targeting also draws on your past chats and your stored memories
- Your personal details and conversations are not shared with advertisers
- Advertisers only receive aggregate performance data, not your chats, history, memories, or personal details
That fourth bullet deserves a second read. With personalization on, the same memory feature discussed above becomes an input into which ads you see. The data stays inside OpenAI, but the substance of what you have discussed with ChatGPT is being used to pick advertisements.
You have two distinct controls. You can turn off ad personalization under Settings, then Ad Controls, which limits targeting to your current conversation. Separately, free-tier users can opt out of ads entirely in exchange for a lower daily message limit.
For lawyers: even with these protections in place, the introduction of advertising in free tiers reinforces existing advice. Free accounts are not appropriate for sensitive client matters. The ad infrastructure introduces additional data-processing flows, even if OpenAI represents that conversation content is not shared with advertisers.
The current representation reflects current policy. Policies change. What advertisers cannot access today may not be the same as what they cannot access in a future terms update. Read the policy. Check it again.
Automated Monitoring and Human Review: What Actually Happens
One additional privacy limitation is worth mentioning, because it is often missed and frequently misunderstood. OpenAI’s policy focuses primarily on automated monitoring, not routine human review. But that does not mean human eyes never see your conversations.
Automated Monitoring Is the Default
The primary layer of content oversight is automated on ChatGPT. Modern AI platforms use automated moderation tools that scan for risk patterns. These systems run continuously, operate at scale, and do not interpret professional context. They do not know you are a lawyer. They do not know your inquiry is legitimate.
What triggers automated flagging:
- Certain categories of content, regardless of intent
- Keywords or patterns associated with high-risk subject matter
- Combinations of content that match safety thresholds
For example, a criminal defense attorney researching a child exploitation statute, a journalist investigating online abuse, or a professor preparing course materials may all need to discuss highly sensitive subject matter. The automated system sees the content. It does not see the professional purpose. When a conversation is flagged by automated systems:
- Responses may be restricted or redirected
- The interaction is logged
- The conversation may be queued for further review
Human Review Is Not Routine: But It Can Happen
Human review is not a standard part of every conversation. OpenAI does not have staff reading your chats as a matter of course. However, human review can occur. OpenAI’s policy contemplates it in specific circumstances:
- When automated systems flag content for high-risk categories
- For safety investigations
- For abuse detection
- To train and improve moderation systems
The threshold for human review is higher than the threshold for automated flagging. But if your conversation is flagged, human review becomes a real possibility, not a theoretical one. Flagging is procedural, not punitive. It is not a judgment about legality, ethics, or professional necessity. But it is a reminder that legitimacy does not guarantee privacy.
What This Means for Lawyers
The practical takeaway is the same regardless of whether review is automated or human. Your content has been seen by something. And in some cases, by someone. For lawyers, this reinforces a broader principle:
Even lawful, ethical, and professionally necessary inquiries should not be assumed to be private simply because they are legitimate.
AI tools are best treated as research assistants and drafting aids, not confidential sounding boards, especially when dealing with sensitive facts or regulated subject matter.
Sharing Chats: The Google Indexing Episode
ChatGPT lets you share a conversation by generating a link. In 2025, OpenAI briefly offered an option to make shared chats “discoverable,” and thousands of shared conversations ended up indexed by Google, searchable by anyone. The exposed chats included names, resumes, and deeply personal material. OpenAI removed the option on July 31, 2025 and worked with search engines to de-index the links.
Two things are true at once here. This was not a hack; every exposed chat had been shared by its user, who checked a box. And most of those users plainly did not understand what the box did. If you have ever shared a ChatGPT conversation, the Shared Links section of your settings shows every link you have created, and you can delete them there. If a chat touches anything sensitive, do not share it at all. A share link is a publication, not a handoff.
Features That Change the Privacy Picture
ChatGPT is no longer just a chat box, and several features move more of your data into it. A few deserve specific attention from lawyers.
Connectors
Connectors link ChatGPT to your Gmail, Google Drive, SharePoint, GitHub, and similar accounts so it can answer questions using your own files and mail. That means your files and mail flow to OpenAI. On business tiers, connectors are off by default until an administrator enables them, and the content is not used for training. On consumer accounts, a connector routes whatever it can see through an account with consumer-grade terms. Think hard before connecting any account that contains client communications. A connector does not know which folders are privileged.
Record Mode
ChatGPT can record and transcribe meetings on the desktop app. The audio is deleted after transcription, and the transcript is stored in the conversation under normal retention rules. The privacy problem here is not primarily OpenAI. It is wiretap law. Pennsylvania is a two-party consent state, and so are California, Florida, and others. Recording a call or meeting without everyone’s consent is a crime in those states, and a transcript of a privileged conversation sitting in a third party’s systems is its own problem. If you use record mode at all, get consent on the record and keep client matters out of it.
ChatGPT Health
OpenAI launched a health feature in 2026 that connects medical records and Apple Health data to ChatGPT. OpenAI says health conversations are not used for training or ads and are stored in an isolated space. Here is the piece that matters for lawyers: OpenAI states the feature is not intended for clinical use and offers no business associate agreement. When a person uploads medical records to a consumer app, that copy sits outside HIPAA. If your practice touches personal injury, health law, or employment, your clients may be doing this right now, and the copies they create are discoverable.
Group Chats
ChatGPT offered group conversations with multiple participants; OpenAI began retiring the feature in July 2026, and existing group chats are read-only. The lesson outlives the feature. Anything placed in a shared thread was visible to every participant, and sharing privileged material with an outside participant is a classic path to waiver. If you or your clients used group chats, the history is still there and can be exported or deleted.
Business, Team, and Enterprise Accounts
This is where the privacy posture genuinely changes.
Team / Business / Education Accounts
These accounts are designed for organizational use and generally include:
- No training on customer data by default
- Administrative and access controls
- Clearer representations about data handling
- No ads
This is a meaningful improvement for internal workflows and collaborative use. But it is still privacy, not privilege.
One caution from the litigation above: Team accounts were covered by the preservation order. Enterprise and Edu were not. If your firm chose Team as its middle path, the training default is off, but the account did not sit on the protected side of the line when a court came calling.
Enterprise and API Accounts
Enterprise and API access currently offer the strongest privacy protections available from OpenAI.
Typically:
- Customer data is not used for training
- Retention periods are shorter, and administrators control them
- Strong contractual assurances apply, including a data processing addendum
- Systems are designed with regulated industries in mind
API customers with a qualifying use can also request Zero Data Retention, under which eligible traffic is not stored at all. Data that is never stored cannot be preserved, produced, or breached, and the Zero Data Retention tier was exempt from the New York Times preservation order for exactly that reason.
Even here:
- Data still exists (outside Zero Data Retention)
- Data is still processed
- Lawful access (such as subpoenas or regulatory requests) remains possible
Enterprise-grade privacy is risk reduction, not immunity.
Security Incidents: What Has Actually Happened
It is worth separating confirmed incidents from headlines. Two real exposures are on the record from the past year. The shared-link indexing episode is described above. The other came through a vendor: in November 2025, a breach at Mixpanel, an analytics provider OpenAI used, exposed names, email addresses, and approximate locations for some API and ChatGPT users. Chats, passwords, and payment data were not involved, and OpenAI cut the vendor off and notified affected users.
The steadier risk is less dramatic. Credentials for ChatGPT accounts circulate on criminal markets by the millions, harvested by malware on users’ own devices, not from OpenAI. If someone logs into your account, they can read everything in it, including your chat history and memories. Use a strong unique password and multi-factor authentication on any account that has ever touched anything sensitive. Claims of large-scale breaches of OpenAI itself have circulated and have not been verified.
What No Account Level Provides
This part matters most, especially for lawyers. No ChatGPT account, free, paid, business, or enterprise, creates:
- Attorney-client privilege
- Absolute confidentiality
- Guaranteed deletion on demand
- A promise that no human will ever see data
- Protection from lawful process
The New York Times litigation is no longer a hypothetical illustration of that last bullet. It happened.
AI tools are services, not vaults.
A Practical Rule of Thumb
Here is the framework I use myself:
- If disclosure would violate professional duties → do not input it
- If the information is sensitive but non-confidential → minimize and abstract
- If the information is public, hypothetical, or generalized → reasonable use
- If the tool must handle real confidential data → use enterprise-grade solutions with contracts
This is not about fear. It is about competence and proportional risk management.
The Bottom Line
ChatGPT can be used responsibly and ethically, but it is important to understand the privacy limitations. Yes, privacy exists. Yes, limitations exist.
- Paying for Plus or Pro eliminates ads and improves the experience but does not transform the tool into a confidential advisor.
- Free and Go accounts include advertising, another reason they are not appropriate for sensitive matters.
- Deletion is a schedule, not a certainty, and a court order can stop the schedule entirely.
- Enterprise-level accounts offer the strongest protections, and the New York Times litigation showed that the account-type distinction has real teeth.
If you approach AI with clear eyes instead of magical thinking, it can be an extraordinarily useful assistant. Just don’t confuse convenience with confidentiality.
Updated August 17, 2026, to add the New York Times preservation and production orders, retention and memory mechanics, the shared-link indexing episode, ad personalization details, connectors, record mode, ChatGPT Health, and the Mixpanel vendor incident.
I am often asked some version of this question:
“Is ChatGPT private?”
The honest answer is it depends. It depends in ways that most people do not intuitively understand. There is privacy. There are also real limitations. And paying for a higher-tier account does not automatically mean confidentiality.
This post explains what actually changes across ChatGPT account levels, what does not, and how to think about privacy in a way that is realistic rather than alarmist. It has been updated to reflect OpenAI’s latest privacy policy changes. (Updated February 14, 2026).
Privacy Is Not Binary
The biggest mistake people make when thinking about AI tools is treating privacy as an on/off switch. It is not.
Privacy with ChatGPT is:
- Contextual (what you enter matters)
- Contractual (which terms apply to your account)
- Purpose-driven (training, operation, and legal compliance are distinct concepts)
The correct question is not “Is ChatGPT private?” The correct question is:
“Private enough for what purpose, under which account terms?”
Consumer Accounts: Free, Go, Plus, and Pro
Let’s start with the accounts most individuals use.
Free and Go Accounts
Free and Go consumer accounts carry the highest privacy risk, relatively speaking.
Key points:
- Conversations may be used to improve models, unless the user opts out in settings
- Data is stored and logged
- Some conversations may be reviewed by humans for safety, quality, or abuse detection
There are no individualized contractual assurances beyond the public privacy policy
- Ads may appear in these accounts (see below)
This does not mean your content is publicly visible or reused verbatim elsewhere. It does mean that you should not treat a free or Go account as confidential. For lawyers, that alone should be dispositive.
Paid Consumer Accounts (Plus / Pro)
This is where many people assume privacy magically appears. It does not. What paying for a consumer account actually buys you:
- Access to more capable models
- Faster responses
- Larger context windows
- Priority availability
- No ads
What it does not automatically buy you:
- Attorney-client confidentiality
- Guaranteed non-retention
- A promise that data will never be reviewed
- A bespoke privacy contract
Users can opt out of training in their account settings, which is meaningful. However, that opt-out:
- Limits model training use
- Does not guarantee deletion
- Does not eliminate retention for operational, safety, or legal reasons
A paid consumer account is more powerful, and now ad-free. It is not meaningfully more confidential.
NEW: Ads in ChatGPT
OpenAI’s updated privacy policy introduces advertising to ChatGPT. This is a meaningful development. Here is what you need to know.
Which accounts see ads:
- Free accounts: Yes
- Go accounts: Yes
- Plus, Pro, Enterprise, Business, and Education accounts: No
How ads work:
- Ads are always clearly labeled as sponsored and visually separated from ChatGPT’s answers
- Ads do not influence the answers ChatGPT gives you
- Ad personalization uses information that stays within ChatGPT, such as ads you’ve interacted with or context from your chats
- Your personal details and conversations are not shared with advertisers
- Advertisers only receive aggregate performance data, not your chats, history, memories, or personal details
- You can manage ad personalization in settings at any time
For lawyers: even with these protections in place, the introduction of advertising in free tiers reinforces existing advice. Free accounts are not appropriate for sensitive client matters. The ad infrastructure introduces additional data-processing flows, even if OpenAI represents that conversation content is not shared with advertisers.
It is important to note that the current representation reflects current policy. Policies change. What advertisers cannot access today may not be the same as what they cannot access in a future terms update. Read the policy. Check it again
Automated Monitoring and Human Review: What Actually Happens
One additional privacy limitation is worth mentioning, because it is often missed and frequently misunderstood. OpenAI’s policy focuses primarily on automated monitoring, not routine human review. But that does not mean human eyes never see your conversations.
Automated Monitoring Is the Default
The primary layer of content oversight is automated on ChatGPT. Modern AI platforms use automated moderation tools that scan for risk patterns. These systems run continuously, operate at scale, and do not interpret professional context. They do not know you are a lawyer. They do not know your inquiry is legitimate.
What triggers automated flagging:
- Certain categories of content, regardless of intent
- Keywords or patterns associated with high-risk subject matter
- Combinations of content that match safety thresholds
For example, a criminal defense attorney researching a child exploitation statute, a journalist investigating online abuse, or a professor preparing course materials may all need to discuss highly sensitive subject matter. The automated system sees the content. It does not see the professional purpose. When a conversation is flagged by automated systems:
- Responses may be restricted or redirected
- The interaction is logged
- The conversation may be queued for further review
Human Review Is Not Routine: But It Can Happen
Human review is not a standard part of every conversation. OpenAI does not have staff reading your chats as a matter of course. However, human review can occur. OpenAI’s policy contemplates it in specific circumstances:
- When automated systems flag content for high-risk categories
- For safety investigations
- For abuse detection
- To train and improve moderation systems
The threshold for human review is higher than the threshold for automated flagging. But if your conversation is flagged, human review becomes a real possibility, not a theoretical one. Flagging is procedural, not punitive. It is not a judgment about legality, ethics, or professional necessity. But it is a reminder that legitimacy does not guarantee privacy.
What This Means for Lawyers
The practical takeaway is the same regardless of whether review is automated or human. Your content has been seen by something. And in some cases, by someone. For lawyers, this reinforces a broader principle:
Even lawful, ethical, and professionally necessary inquiries should not be assumed to be private simply because they are legitimate.
AI tools are best treated as research assistants and drafting aids, not confidential sounding boards, especially when dealing with sensitive facts or regulated subject matter.
Business, Team, and Enterprise Accounts
This is where the privacy posture genuinely changes.
Team / Business / Education Accounts
These accounts are designed for organizational use and generally include:
- No training on customer data by default
- Administrative and access controls
- Clearer representations about data handling
- No ads
This is a meaningful improvement for internal workflows and collaborative use. But it is still privacy, not privilege.
Enterprise and API Accounts
Enterprise and API access currently offer the strongest privacy protections available from OpenAI.
Typically:
- Customer data is not used for training
- Retention periods are shorter
- Strong contractual assurances apply
- Systems are designed with regulated industries in mind
Even here:
- Data still exists
- Data is still processed
- Lawful access (such as subpoenas or regulatory requests) remains possible
Enterprise-grade privacy is risk reduction, not immunity.
NEW: Other Updates Worth Knowing
OpenAI’s updated policy also includes several other clarifications:
- Contact syncing: You can now optionally sync contacts to see who else uses OpenAI services. This is entirely optional and does not affect privacy defaults.
- Age prediction and teen safeguards: OpenAI now uses age-prediction technology to provide safer, more age-appropriate experiences for younger users.
- New features: The policy adds details about Atlas, Sora 2, parental controls for teen accounts, and other features.
- Data retention transparency: More detail about how long data is kept, what controls users have, and the legal bases relied on when processing personal data.
These are positive steps toward transparency. They do not change the fundamental privacy calculus for legal professionals.
What No Account Level Provides
This part matters most, especially for lawyers. No ChatGPT account, free, paid, business, or enterprise, creates:
- Attorney-client privilege
- Absolute confidentiality
- Guaranteed deletion on demand
- A promise that no human will ever see data
- Protection from lawful process
AI tools are services, not vaults.
A Practical Rule of Thumb
Here is the framework I use myself:
- If disclosure would violate professional duties → do not input it
- If the information is sensitive but non-confidential → minimize and abstract
- If the information is public, hypothetical, or generalized → reasonable use
- If the tool must handle real confidential data → use enterprise-grade solutions with contracts
This is not about fear. It is about competence and proportional risk management.
The Bottom Line
ChatGPT can be used responsibly and ethically, but it is important to understand the privacy limitations. Yes, privacy exists. Yes, limitations exist.
- Paying for Plus or Pro eliminates ads and improves the experience but does not transform the tool into a confidential advisor.
- Free and Go accounts now include advertising, another reason they are not appropriate for sensitive matters.
- Enterprise-level accounts offer the strongest protections but still carry inherent limits.
If you approach AI with clear eyes instead of magical thinking, it can be an extraordinarily useful assistant. Just don’t confuse convenience with confidentiality.
Updated February 14, 2026, to reflect OpenAI’s 2025 privacy policy changes, including the introduction of advertising on Free and Go plans, optional contact syncing, and additional transparency around data retention.