Mahmoud Fasfos
العربية

AI9 min read

Is ChatGPT Safe With Your Data? What Happens to Your Chats

Does ChatGPT store and train on your chats? A traffic-light rule for what to paste, five settings to change today, and real incidents with dates.

Key takeaways

  • Deleting hides a chat instantly, but permanent removal from servers takes up to 30 days.
  • Switch off 'Improve the model for everyone' in Data controls to stop new chats being used for training.
  • Use the traffic light: green freely, amber after masking, red never (IDs, salaries, contracts, passwords).
  • Your personal account is not a company account; business products don't train on your data by default.
  • Documented incidents mostly come from rushed staff, technical bugs or legal orders, not from snooping.

You open ChatGPT, paste a long email from your manager, and type: "Summarise this." A few seconds later you have your answer. But have you ever asked where that email went the moment you hit send?

"Is ChatGPT safe?" doesn't have a yes-or-no answer. The honest one is that it depends on what you type, what kind of account you use, and a handful of settings most people never open. I have worked on information security and data classification inside organisations in Saudi Arabia, Canada and Jordan, and this is roughly what I tell staff there. Everything below is current as of October 2026, and every fact has a source at the end.

Where does your message go after you press send?

Your message is not processed on your device. It travels to the provider's servers, the model reads it, and the answer comes back. A copy of your words now sits outside your control, which raises three questions: how long is it kept, who can see it, and is it used to train the model?

According to the chat retention page in OpenAI's help centre, when you delete a chat it disappears from your account straight away and is scheduled for permanent deletion from OpenAI's systems within 30 days. There are two exceptions: the chat was already de-identified and disconnected from you, or OpenAI has to keep it for security or legal reasons. Deleted chats cannot be restored.

Note the gap. "Gone from my screen" is not the same as "gone from the servers". Most privacy surprises live in that gap.

Is your chat used to train the model, and how to stop it

On personal accounts there is a setting called "Improve the model for everyone". When it is on, your new conversations can be used to improve OpenAI's models. When you switch it off, new conversations are not used for training, and they can still appear in your chat history. That is how OpenAI's Data controls page describes it.

On the web the path is Settings, then Data controls, then switch it off. The setting is tied to your account, so it applies on all your devices. I can't tell what yours is set to right now, so open it and check.

The second option is Temporary Chat. According to its help page, a temporary chat stays out of your history and is not used to improve the models while it remains temporary. But OpenAI may keep a copy for up to 30 days for safety purposes. It is lower risk, not a vault.

A setting that blocks training does not block storage. Storage is one thing, training is another.

The traffic-light rule: what to type freely, carefully, or never

Settings alone are not enough. The rule I give the teams I work with is simple enough to remember when you're in a hurry: three colours.

Green: type freely

General questions, explaining a concept, drafting a message with no real names or figures, translating text that is already public, ideas for a presentation. If you could read the text aloud in a meeting with everyone present, it is green.

Amber: type it after masking

A contract draft, internal meeting minutes, a message from a client, a sales spreadsheet. Don't deny yourself the benefit, but strip everything that identifies the owners: the client's name, your company's name, exact amounts, phone numbers. Write "Client A" and "Project X". The AI doesn't need the real name to tighten your wording or summarise the points.

Red: never type it

  • National ID, residency or passport numbers, yours or anyone else's.
  • Salary sheets and employees' personal data.
  • Full client contracts with names and pricing clauses.
  • Passwords, access keys and verification codes.
  • Your company's source code and internal network details.
  • Medical reports and sensitive financial details, yours or anyone else's.

The reason is not that the provider is "out to get you". It is that any data leaving your device becomes exposed to a technical error, a legal process or internal misuse, and you no longer control it. The safest rule isn't "trust or don't trust". It is "don't send what you couldn't bear to see read".

A free account is not a company account: the privacy difference

This is where many people slip. Your personal account, free or paid, is not your employer's account. According to OpenAI's Business data privacy page, its business products (ChatGPT Enterprise, ChatGPT Business, ChatGPT Edu and the API) do not use your inputs and outputs to train models by default. If an organisation wants to help improve the models, it has to opt in explicitly.

That is a real difference: on a personal account the configuration is your job, while on a business account the default is no training. But don't read "company account" as "anything goes". The public page is an overview, and the binding terms come from the contract you sign. If you are responsible for a company that handles client data, ask for the data processing agreement (DPA) and read it instead of relying on a marketing page.

The practical verdict: if your employer hasn't given you an approved account, using your personal one for work tasks isn't saving time. It is moving company data into a channel the security team doesn't know about. That is a management decision before it is a technical one. For more on decisions left to chance, see my book The Blind Manager (Arabic).

Real incidents and what they teach

I don't like scare stories without evidence. These are documented, and each one teaches something different. For a broader look at AI and security, see AI vs. AI: Cybersecurity in the Age of Deepfakes and Autonomous Defense.

Samsung, 2023. Bloomberg reported on 2 May 2023 that Samsung had sent an internal memo banning staff at one of its largest divisions from using generative AI tools, after an accidental leak of source code. The memo warned that violations could lead to dismissal. Samsung did not confirm what leaked, and reports in the Korean press were never officially verified. The lesson: the risk came from an employee trying to get work done fast, not from a hacker.

The 20 March 2023 bug. OpenAI disclosed that a bug in an open-source library let some users see titles from another active user's chat history, and possibly the first message of a new conversation. After investigating, it said payment details of 1.2% of ChatGPT Plus subscribers active during a nine-hour window may have been visible to others: name, email, billing address, the last four digits of the card and its expiry date. Full card numbers were not exposed. The lesson: any cloud service can fail, so don't put in it what you couldn't bear to see exposed.

Shared links in Google, 2025. At the end of July 2025 OpenAI removed an option that let people make a shared chat discoverable by search engines, after a Fast Company investigation found more than 4,500 shared links indexed on Google. The company's security chief said the feature created too many chances for people to share things they hadn't meant to. The lesson: "Share" is not innocent, and a chat link can leave your circle.

The New York Times court order. In May 2025 a court order in the newspaper's copyright case required OpenAI to preserve output logs that would normally be deleted. On 9 October 2025 Magistrate Judge Ona Wang ended that blanket requirement, with exceptions: data already preserved stays accessible, and data tied to accounts the Times flagged must still be kept. What I found stops at October 2025, so check for newer developments if it matters to you. The lesson: "I'll delete the chat" is a promise you can't keep alone, because a legal process can intervene.

Italy's fine. In December 2024 Italy's data protection authority fined OpenAI 15 million euros, saying it lacked an adequate legal basis for using personal data in training and had not reported the March 2023 incident. But a Rome court annulled the decision on 18 March 2026 on jurisdiction, finding that Ireland's regulator had become the competent lead authority. The court did not rule on the underlying alleged violations. So don't read the annulment as an acquittal, or the original fine as a final conviction.

Five settings to change today, in five minutes

Menu names change between updates, so if you can't find an option word for word, look for a close match in Settings. These details come from OpenAI's help pages as I saw them in October 2026, so re-check them before building an official policy on them.

The bottom line: safety is a decision you make before you type

ChatGPT is neither enemy nor friend. It is a powerful tool, and what you put into it sets the risk. Most problems I have seen in organisations did not come from a breach. They came from a rushed employee pasting something that should never have left the company.

And if what worries you goes beyond data, to your own habits and how you act under pressure and quick decisions, the book Resign From Yourself (Arabic) helps you notice what you do when you're in a hurry, before it hardens into habit.

Frequently asked questions

Is ChatGPT safe for my personal data?

It depends on what you type, your account type and your settings. It suits general questions; never paste IDs, salaries, contracts or passwords.

Does ChatGPT save my conversations?

Yes, they stay in your history until you delete them. After deletion OpenAI schedules permanent removal within 30 days, with security and legal exceptions.

How do I stop my chats being used for training?

Go to Settings, then Data controls, and switch off 'Improve the model for everyone'. It applies to your account on all devices.

Is Temporary Chat fully private?

No. It stays out of your history and isn't used for improvement while temporary, but a copy may be kept up to 30 days for safety.

Are company accounts safer?

By default OpenAI says business products don't use your inputs for training, but binding terms live in the contract, so ask for the data processing agreement.

Sources

  1. Chat and file retention policies in ChatGPTOpenAI Help Center, 2026
  2. Data controls in ChatGPTOpenAI Help Center, 2026
  3. Temporary chat in ChatGPTOpenAI Help Center, 2026
  4. Business data privacy, security, and complianceOpenAI, 2026
  5. March 20 ChatGPT outage: Here's what happenedOpenAI, 2023
  6. Samsung Bans Staff's AI Use After Spotting ChatGPT Data LeakBloomberg, 2023
  7. Samsung bans use of generative AI tools after source code leakThe Register, 2023
  8. OpenAI no longer has to preserve all of its ChatGPT data, with some exceptionsEngadget, 2025
  9. OpenAI faces 15 million fine as the Italian Garante strikes againLewis Silkin, 2025
  10. Italian court kills OpenAI's EUR15M finePPC Land, 2026
  11. OpenAI is pulling shared ChatGPT chats from Google searchSearch Engine Journal, 2025
Mahmoud Fasfos

Mahmoud Fasfos

CTO & COO · Author

Technology leader with 15+ years across Saudi Arabia, Canada and Jordan, working on AI, cybersecurity and project delivery. Author of «The Blind Manager» and «Resigning from Yourself».