Is ChatGPT safe for confidential information?

It depends entirely on which ChatGPT. The free one and the one your employer pays for are governed by different rules, and most people asking this are using the wrong one.

Analysis by Inzonex · published 2026-09-25 · counted from published open data · how we work

Key figures

Business, Enterprise, Edu, Healthcare, Teachers and the API are not used to train models by default.

Data from the consumer versions is used in training.

On the business tiers your workspace administrator can read your conversations.

The split that answers the question

OpenAI's published enterprise privacy position, updated in January 2026, draws one line that settles most of this question. For ChatGPT Business, Enterprise, Edu, Healthcare, Teachers and the API Platform, it states: we do not train our models on your data by default.

On the same page, describing what training data comes from, it lists public sources, licensed third-party data, material created by human reviewers, and data from versions of ChatGPT and other services for individuals.

That is the whole answer in two sentences. The business products carve your data out of training. The personal ones are named as a source of it.

What each tier actually commits to

TierUsed for training by defaultRetentionWho can read it
Personal ChatGPTNamed as a training data sourceAccount settingsYou, plus abuse review
ChatGPT BusinessNoAdmin-controlled; deleted conversations removed within 30 daysYou, your workspace admins, abuse reviewers
Enterprise, Edu, HealthcareNoAdmin-controlled; deleted conversations removed within 30 daysYou, admins via a compliance audit log, abuse reviewers
API PlatformNo, for data submitted after 1 March 2023Up to 30 days for abuse detection; zero retention available for eligible endpointsLimited authorised staff and contractors

The compliance scaffolding behind those claims is real and checkable: a SOC 2 Type 2 audit, a data processing addendum for GDPR, a business associate agreement for HIPAA, AES-256 at rest and TLS 1.2 or better in transit.

The part people do not expect

Two details in the published policy surprise people, and both cut against the assumption that a paid tier means privacy.

Your administrator can see your conversations. On ChatGPT Business, workspace admins can view, access, export and delete end user conversations. On Enterprise and Edu they can access an audit log of conversations through a compliance API. Not training on your data is not the same as nobody reading it.

Specialised third-party contractors may review content for abuse and misuse, bound by confidentiality obligations.

So the honest framing for an employee is: your employer can read what you typed. That is normal for a corporate tool, and it is the opposite of what most people picture when they are told the enterprise version is private.

A workable rule

Three questions settle nearly every real case.

Which product is this? If you cannot name the tier, assume personal, and assume training.

Whose confidence is it? Your own drafts are yours to risk. A client's data, patient data or anything under an NDA is not, and the applicable rule is the contract you signed, not the vendor's privacy page.

Would you mind your employer reading it? On a business tier that is not a hypothetical.

Three pieces of context outside the vendor’s own page are worth holding. In May 2023 Samsung prohibited generative AI internally after engineers pasted source code into a public chatbot. In December 2024 Italy’s data protection authority fined OpenAI €15m over legal basis, transparency and age verification, a decision the Court of Rome then annulled in March 2026. And the UK National Cyber Security Centre has warned that prompt injection is a structural weakness rather than a bug to be patched, because a model cannot reliably tell instructions from data.

And the practical note that outlives any policy: a commitment not to train on your data is a commitment about one use. It is not a guarantee against breach, subpoena or a future change of policy. Pasting a trade secret into any third-party service is a decision about all three.

Sources and method

  • Enterprise privacy at OpenAI, OpenAI, page updated 8 January 2026. Source of every commitment quoted here, including the default training position, the retention periods, administrator access and the compliance certifications.
  • Samsung bans ChatGPT and other chatbots for employees after sensitive code leak, Forbes, May 2023. The case that set the template for corporate bans: engineers pasted source code into a public chatbot and the company prohibited generative AI internally.
  • OpenAI faces €15 million fine as the Italian Garante strikes again, Lewis Silkin, January 2025. The Court of Rome annulled the fine on 18 March 2026. Regulatory action over legal basis, transparency and age verification, and the subsequent annulment, which together show how unsettled this area still is.
  • ChatGPT and large language models: what’s the risk?, UK National Cyber Security Centre. National guidance on what a query to a hosted model actually exposes, and why prompt injection is a structural rather than a patchable problem.
  • This page describes OpenAI's published policy at the date it was read. Policies change, and other providers differ.
  • This is a summary of a vendor's published position, not legal advice, and it does not override your own organisation's rules.
  • Every source here was opened and checked on 25 September 2026. Where nothing has been measured, this page uses a table and says so rather than drawing a chart of an opinion.