This post was originally written in January 2026 and updated in February. I updated it again on September 7, 2026, to reflect the changes in ChatGPT’s privacy policy and related terms.
I am often asked some version of this question: “Is ChatGPT private?”
The answer is a lawyer’s favorite two words, “it depends.” There is privacy, of a sort. There are also real limitations. The first thing to understand, as you read through this post, is that as with other consumer AI tools, paying for a higher-tier account does not automatically mean confidentiality. This post explains what actually changes across ChatGPT account levels, what does not, and how to think about privacy in a way that is realistic rather than alarmist.
Changes Since February 2026
Since I first wrote this post, a federal court ordered OpenAI to preserve chats users thought they had deleted, and then to hand twenty million of them to opposing counsel as part of a lawsuit. I mention that lawsuit here because it addresses what “delete” really means. Whether something is truly deleted is an issue we have dealt with as long as computers have existed. OpenAI has also revised its privacy policy twice since February, and ads have gone from a U.S. test to a product available to advertisers in the United States, Europe, and beyond. I cover those changes as well. Read on for details.
Privacy Is Not Binary
The biggest mistake people make when thinking about AI tools is treating privacy as an on/off switch. It is not. Privacy with ChatGPT is contextual, because what you enter matters. It is contractual, because the terms that apply to your specific account are the terms you get. And it is purpose-driven, because training, day-to-day operation, ethical compliance, and malpractice exposure are all distinct concepts. A setting that might address one of these issues may do nothing about the others.
So, we need to rephrase the question people ask. The correct question is not “Is ChatGPT private?” The correct question is “Is ChatGPT private enough for what purpose, under which account terms?”
Free and Go Accounts
Let’s start with the accounts most individuals use; free and Go. Free and Go are consumer accounts that carry the highest privacy risk, relatively speaking. Your conversations may be used to improve, or train, OpenAI’s models unless you opt out in settings. Your data is stored and logged. Some conversations may be reviewed by humans for safety, quality, or abuse detection. There are no individualized contractual assurances beyond the public privacy policy. And these accounts now carry ads, which I discuss below.
None of this means your content is publicly visible or reused verbatim elsewhere. It does mean that you should not treat a free or Go account as confidential. For lawyers, that alone should tell you that you would be better off not using these types of accounts and that you should never enter confidential client information in them.
Paid Consumer Accounts: Plus and Pro
This is where many people assume privacy appears. It does not. Paying for a consumer account buys you access to more capable models, faster responses, larger context windows, priority availability, and no ads. It does not buy you attorney-client confidentiality, a guarantee of non-retention, a promise that your data will never be reviewed, a bespoke privacy contract, or an exemption from OpenAI’s own marketing.
ChatGPT Consumer Accounts and Training
It is important to understand that on every consumer tier, including Plus and Pro, training on your conversations is on by default. Paying does not change the default. Only the setting does.
Turning off Training in ChatGPT
In order to turn off training, go to Settings, then Data Controls, then a toggle called “Improve the model for everyone.” If that toggle is on, your conversations may be used to train OpenAI’s models. If you turn it off, they are not used for training going forward. It is critical to appreciate what that opt-out does and does not do. Opting out limits model training. It does not guarantee deletion, and it does not eliminate retention for operational, safety, or legal reasons. Also, you cannot go back in time. Anything that was entered while training was on cannot be removed from training after you change the setting. There is no putting the horse back in the barn.
Do Not Rate Your Chats
There is also a trap hiding in plain sight, and it is the same one I flagged in my Claude post. Rating a response with a thumbs up or thumbs down submits that conversation as feedback, and OpenAI states that “the entire conversation associated with that feedback may be used to train our models,” whether or not you have opted out. If a chat contains anything sensitive, or you simply do not want your chats to be trained on, do not use the rating system.
What it comes down to is that while a paid consumer account is more powerful and ad-free, it is not meaningfully more confidential.
OpenAI Advertises Itself Too
The May 18, 2026, update to OpenAI’s U.S. privacy policy added something separate from the ads inside ChatGPT. OpenAI now shares what it calls limited information with select marketing partners so it can promote its own products on other websites and apps, and measure how well the advertising works. These partners are not OpenAI’s service providers, and some of them receive the information through cookies. The policy says that under several state privacy laws this counts as “targeted advertising” or sharing for “cross-context behavioral advertising,” while maintaining that OpenAI does not “sell” personal data. This is not your chat content. It is data about you as a user, going to third parties, and the policy does not limit it to free accounts.
Opting Out of Targeted Marketing
If you are logged in, you can opt out with the marketing privacy control in your account settings. If you are not logged in, you can opt out under Settings, then Data Controls in ChatGPT, or through the Your Privacy Choices link on OpenAI’s website. You can also opt out with a legally recognized signal such as Global Privacy Control.
What Deleting a Chat Actually Does
When you delete a chat, it disappears from your ChatGPT account immediately and is scheduled for permanent deletion from OpenAI’s systems within 30 days. Scheduled is the operative word. OpenAI’s own policy states that it keeps deleted content longer for security, fraud, and abuse investigations, for financial record-keeping, and under legal holds, meaning a court or regulator has required OpenAI to keep it. It also carves out content that has already been de-identified for model training, which deletion does not pull back. As I noted previously, this means that if a conversation was used to train a model before you deleted it, deleting the chat does not remove anything from the model.
Temporary Chat is the closest thing consumer ChatGPT has to an incognito mode. A temporary chat does not appear in your history, does not create memories, and is not used to train models. It is still retained for up to 30 days, and it may still be reviewed for abuse. Temporary Chat is a good habit for one-off sensitive questions. It is not a confidentiality guarantee, and temporary chats were not beyond the reach of a court order either.
Memory Does Not Go Away with a Deleted Chat
ChatGPT’s memory feature stores details about you across conversations, both memories you ask it to save and information it draws from your chat history. Two things of note: Turning memory off does not delete what has already been remembered; you have to delete stored memories separately. And deleting a chat does not delete the memories that came from it.
For a lawyer, the risk is accumulation. A client name here, a matter fact there, and the account has quietly built a profile that survives every individual conversation, even deleted ones. If you use a consumer account for anything involving client work, turn memory off and review what is already stored. Go to Settings, then Personalization.
The New York Times Case: When “Deleted” Chats Became Evidence
Users deleted chats. On May 13, 2025, Magistrate Judge Ona T. Wang of the Southern District of New York ordered OpenAI to preserve them anyway. The order covered ChatGPT Free, Plus, Pro, and Team accounts, along with standard API traffic. It did not cover ChatGPT Enterprise, ChatGPT Edu, or API customers on Zero Data Retention endpoints. The going-forward preservation obligation ended September 26, 2025, and was formally terminated by order on October 9, 2025, but the data preserved during those months from U.S. users is still held. On November 7, 2025, the court ordered OpenAI to produce a de-identified sample of 20 million consumer chat logs under a protective order, and on January 5, 2026, District Judge Sidney H. Stein affirmed that order over OpenAI’s objections. For more details see OpenAI’s statement, “How we’re responding to the New York Times’ data demands in order to protect user privacy,” and the docket in The New York Times Co. v. Microsoft Corp., where the preservation order is ECF 551, entered May 13, 2025.
Ads in ChatGPT
OpenAI announced in January 2026 that ads would be coming to ChatGPT. It began showing ads to U.S. users on the Free and Go plans in February. The program was expanded in August to include 31 European countries. Advertisers now buy placements through a self-serve Ads Manager. What began as a test is now a business, and it changed the privacy picture for the free tiers.
Currently, ads appear on Free and Go accounts. They do not appear on Plus, Pro, Business, Enterprise, or Education accounts, and they are not shown to users OpenAI identifies as under 18. OpenAI says the ads are clearly labeled as sponsored, visually separated from ChatGPT’s answers, and do not influence what ChatGPT tells you. They are always shaped by the context of your current conversation. If ad personalization is on, targeting also draws on your past chats and your stored memories. Your personal details and conversations are not shared with advertisers, who receive only aggregate performance data.
It is key to remember that with personalization on, the same memory feature discussed above becomes an input that impacts which ads you see. The data stays inside OpenAI, but the substance of what you have discussed with ChatGPT is being used to pick advertisements. Data can also go the other way. OpenAI’s privacy policy now states that it may receive information from advertisers and data partners, including information about purchases you make from those advertisers, to measure how well its ads work on Free and Go accounts. The advertiser does not need your chats to close the loop. Your purchase from them can come back to OpenAI on its own.
Controlling Ad Personalization
You have two distinct controls. You can turn off ad personalization under Settings, then Ad Controls. It does not stop ads, and it does not stop them from matching what you are talking about. Ads still use basic context such as your general location and language. What it stops is OpenAI using your other chats, your saved memories, your ad history, and the topics it has stored about you to decide what to show you.
Separately, free-tier users can opt out of ads entirely, in exchange for lower usage limits and reduced feature access, including fewer messages and no image generation or deep research. That option is limited to the Free plan, so a Go subscriber who wants no ads has to drop back to Free or move up to Plus or Pro.
What Ads Mean for Lawyers
For lawyers, the introduction of advertising in free tiers reinforces existing advice. Free accounts are not appropriate for sensitive client matters. The ad infrastructure introduces additional data-processing flows, even if OpenAI represents that conversation content is not shared with advertisers. And the current representation reflects current policy. I will point out that just because this is how the advertising works now does not mean it will not change in the future. Recent history is filled with businesses that make one promise about how data will be handled only to do a one-eighty later on, once they have profitability issues or realize how much money your data is worth. I am not claiming that OpenAI has or will make this change. I am simply noting that it is a possibility that further change will come. As a result, it is critical that attorneys track and stay on top of any changes in the policies of any AI tools they and their clients might be using.
Automated Monitoring and Human Review
I will never forget the first time I told a room full of attorneys that cloud-based and other online tools are scanning everyone’s accounts for child sexual abuse materials. The shock was palpable. This is an obligation for myriad types of accounts. But many AI tools go much further with their monitoring, including OpenAI.
OpenAI’s policy focuses primarily on automated monitoring, not routine human review. But that does not mean human eyes never see your conversations. Modern AI platforms use automated moderation tools that scan for risk patterns. These systems run continuously, operate at scale, and do not interpret professional context. They do not know you are a lawyer. They do not know your inquiry is legitimate. They flag certain categories of content regardless of intent: keywords or patterns associated with high-risk subject matter, and combinations of content that cross safety thresholds. A criminal defense attorney researching a child exploitation statute, a journalist investigating online abuse, or a professor preparing course materials may all use AI to address highly sensitive issues. The automated system sees the content. It does not see the professional purpose. When a conversation is flagged, responses may be restricted or redirected, the interaction is logged, and the conversation may be queued for further review.
Human review is not a standard part of every conversation. OpenAI does not have staff reading your chats as a matter of course. But human review can occur, and OpenAI’s policy contemplates it when automated systems flag content in high-risk categories, in safety investigations, in abuse detection, and to train and improve the moderation systems themselves. The threshold for human review is higher than the threshold for automated flagging. If your conversation is flagged, though, human review becomes a real possibility. Flagging is procedural, not punitive. It is not a judgment about legality, ethics, or professional necessity. It is a reminder that legitimacy does not guarantee privacy.
The practical takeaway is the same whether the review is automated or human. Your content has been seen by something, and in some cases by someone. Even lawful, ethical, and professionally necessary inquiries should not be assumed to be private simply because they are legitimate. AI tools are best treated as research assistants and drafting aids, not confidential sounding boards, especially when dealing with sensitive facts or regulated subject matter.
Sharing Chats: The Google Indexing Episode
ChatGPT lets you share a conversation by generating a link. In 2025, OpenAI briefly offered an option to make shared chats “discoverable,” and thousands of shared conversations ended up indexed by Google, searchable by anyone. The exposed chats included names, resumes, and deeply personal material. OpenAI removed the discoverability option on July 31, 2025, and worked with search engines to de-index the links.
This was not a hack; every exposed chat had been shared by its user, who checked a box. It is likely that most of those users did not understand what the box did. If you have ever shared a ChatGPT conversation, the Shared Links section of your settings shows every link you have created, and you can delete them there. If a chat touches anything sensitive, do not share it at all.
Features That Change the Risk
ChatGPT is no longer just a chat box. There are now different ways to share your data with ChatGPT, some of which deserve specific attention from lawyers and anyone concerned about confidentiality.
Apps, Formerly Connectors
Apps, which OpenAI called connectors until recently, link ChatGPT to Microsoft 365, Gmail, Google Drive, SharePoint, GitHub, and similar accounts so it can answer questions using your own files, calendar, and mail. That means your files and mail flow to OpenAI. The defaults differ by tier. On Business, apps are enabled by default, and administrators change availability for the workspace. On Enterprise and Edu, a new workspace starts with a selected set of apps already enabled, and beyond that set new plugins and apps are disabled by default until an administrator reviews them. On all three, workspace content accessed through an app is not used for training by default.
On consumer accounts you connect apps yourself, and the terms are consumer terms. OpenAI says that for Free, Go, Plus, and Pro users it “may use information accessed from apps to train our models if your ‘Improve the model for everyone’ setting is on.” This is a good reason to immediately turn off training on consumer accounts. Apps you enable may also see basic information of the kind any website gets, such as your IP address, device or browser type, language and region settings, and approximate location, and they can reach conversation context and your memories if you allow it. These are third-party services, so that information is going to whoever runs the app, not only to OpenAI. By default an app can read your information without asking each time, but it has to check with you before it does anything, like sending a message or changing a file. You disconnect under Settings, then Apps. Disconnecting there does not necessarily revoke access on the other side, so check the permissions in the connected account as well.
Be careful before connecting any account that contains client communications. An app does not know which folders are privileged; that responsibility remains on you. An app also runs on your credentials, so it can reach anything your account can reach, including a client’s shared folder or an employer’s private repositories, not only files that are yours. OpenAI also warns that its safeguards “do not eliminate third-party or prompt-injection risk.” Think of a prompt injection as instructions hidden inside something the AI reads, a web page, a document, an email, that the AI then follows as though you had given them. That is worth knowing, since we have already seen one prompt injection case in Brazil and another in the US, and more are likely to occur.
Atlas Web Browser
As of this writing, OpenAI’s privacy policy still describes a web browser named Atlas, including how its incognito mode works. Atlas stopped working on August 9, 2026, and its capabilities were moved into the ChatGPT desktop app. The policy was last updated on May 18, 2026, so it predates the shutdown and has not caught up. Even a company’s own privacy policy can lag the reality, which is why it is worth staying on top of the tools your firm actually uses.
Transcription
Record mode lets ChatGPT record and transcribe meetings on the macOS desktop app. It is available on Plus, Pro, Business, Enterprise, and Edu, not on Free or Go. The audio is deleted after transcription, and the transcript is stored in the conversation under normal retention rules. On Plus and Pro, that transcript can be used for training if you have left the model-improvement setting on.
ChatGPT Health
ChatGPT Health connects medical records and Apple Health data to ChatGPT, and is available to Free, Go, Plus, and Pro users in the United States who are 18 or older. OpenAI says connected medical records and Apple Health information are not used to train its foundation models or target ads, that health information carries additional encryption protections, and it now publishes a separate Health Privacy Notice. OpenAI states that Health in ChatGPT “is not intended for clinical or covered-entity use and does not offer a Business Associate Agreement.” When a person uploads medical records to a consumer app there are concerns about what level of protection it can sustain. If your practice touches personal injury, health law, or employment, your clients may be sharing this kind of data right now, and the copies they create may well be discoverable.
OpenAI does sign Business Associate Agreements, but only for its regulated offerings, including ChatGPT for Healthcare, ChatGPT for Clinicians, Enterprise with a regulated workspace, and the API with modified retention. It does not offer one for ChatGPT Business, and it does not offer one for Health in ChatGPT.
Group Chats Is Retiring
Group chats let multiple people share one ChatGPT conversation. OpenAI is retiring the feature, but the histories remain, so anything a client shared with an outside participant is still there and still discoverable.
Business (Previously Team) and Education Accounts
Designed for organizational use, these accounts are quite different in terms of privacy. Some of the differences between these accounts and the consumer ones explored above include:
- Training is off by default.
- They have administrative and access controls.
- They carry clearer representations about data handling.
- There are no advertisements.
OpenAI states the first one plainly in its enterprise privacy commitments: “We do not train our models on your data by default,” unless you have explicitly opted in to share it. The controls include single sign on, audit logs, and control over how long your data is retained. The representations are contractual, since OpenAI will execute a data processing addendum for ChatGPT Business, and states that you own your inputs and outputs where the law allows. And ads do not appear on Business or Edu accounts. While this is a meaningful improvement for internal workflows and collaborative use, it is still privacy, not privilege.
Two cautions. First, the privacy policy states that “When you join a ChatGPT Enterprise or business account, the administrators of that account may access and control your OpenAI account, including being able to access your Content.” On a firm account, the firm can read your chats. That is usually the point, but the associate who uses the firm’s ChatGPT for a personal question should know it. Second, the accounts then called Team were covered by the preservation order in the New York Times litigation. Enterprise and Edu were not. If your firm chose that middle path, the training default is off, but the account did not sit on the protected side of the line when a court came calling. While I understand why many attorneys choose these accounts for their work, please note that they still require you to redact confidential client data.
Enterprise and API Accounts
Enterprise and API access currently offer the strongest privacy protections available from OpenAI.
- Customer data is not used for training.
- Retention is limited. Abuse monitoring logs are kept up to 30 days unless the law requires longer, and approved customers can configure retention at the organization and project level.
- Strong contractual assurances apply, including a data processing addendum, and the systems are designed with regulated industries in mind.
- API customers with a qualifying use can also request Zero Data Retention, under which eligible traffic is not stored at all. Eligible traffic that is never stored cannot be preserved or produced, and the Zero Data Retention tier was exempt from the New York Times preservation order for that reason. Not stored is not the same as not present, though. The data still moves through OpenAI’s systems while it is being processed, and that window is its own exposure. The Check Point vulnerability discussed below is exactly that kind of problem, and no retention setting would have prevented it.
Even here, outside Zero Data Retention, the data still exists. It is still processed. Lawful access, whether by subpoena or regulatory request, remains possible. Enterprise-grade privacy is risk reduction, not immunity, and not attorney-client privilege.
Security Incidents: What Has Happened
Everything prior to this section describes OpenAI’s policies. Now I want to take a moment to explore three incidents that have actually occurred that potentially impacted users’ privacy.
The first is the shared-link indexing episode described above. Note that a similar incident happened with Anthropic’s Claude.
The second came through a vendor. In November 2025, a breach at Mixpanel, an analytics provider OpenAI used, exposed names, email addresses, approximate locations, browser and operating system details, and user or organization IDs. OpenAI first said the incident affected API users, then clarified on December 19, 2025 that it “also affected a limited number of ChatGPT users who submitted help center tickets or were logged into platform.openai.com.” OpenAI states that no chat content, API requests, passwords, credentials, API keys, payment details, or government IDs were exposed. OpenAI cut the vendor off and notified affected users.
The third is perhaps the most serious, because it involved conversation content. Check Point Research disclosed on March 30, 2026 that a hidden outbound path from ChatGPT’s code execution runtime meant sensitive data shared in ChatGPT conversations could be silently exfiltrated without the user’s knowledge or approval. OpenAI had identified the problem internally, and the fix was fully deployed on February 20, 2026. It seems that the problem was found and closed the right way. It also shows that each new capability, here running code, is another route for data to leave.
What No Account Level Provides
Attorneys, please understand that as with other AI tools, no ChatGPT account, free, paid, business, or enterprise, creates attorney-client privilege. None provides absolute confidentiality, guaranteed deletion on demand, or a promise that no human will ever see your data. None protects you from lawful process, and the New York Times litigation proves that this is not a hypothetical risk. It happened. AI tools are services, not vaults.
A Practical Rule of Thumb
Here is the framework I suggest:
- If disclosure would violate professional duties → do not input it.
- If the information is sensitive but non-confidential → minimize and abstract.
- If the information is public, hypothetical, or generalized → reasonable use.
- If the tool must handle real confidential data → use enterprise-grade solutions with contracts that provide strong protection.
The Bottom Line: TL;DR
ChatGPT, like other AI tools, can be used responsibly and ethically, but it is important to understand the reality. Privacy exists, but there are limitations. Paying for Plus or Pro eliminates ads and improves the experience, but it does not transform the tool into a confidential advisor. Free and Go accounts include advertising, one reason among several that they are not appropriate for sensitive matters. The marketing-partner sharing is not limited to free accounts, so paying does not opt you out of it. Deletion is a schedule, not a certainty, and a court order can stop the schedule entirely. Enterprise-level accounts offer the strongest protections, and the account-type distinction makes a difference.
I, like many, have mixed feelings about AI. I am a fan for some reasons and concerned for others. The best thing I can recommend to other attorneys is that if you approach AI in a practical way with your eyes open, it can be an extraordinarily useful assistant. Just don’t confuse convenience with confidentiality.