Quick Answer: Only on a managed plan: OpenAI says ChatGPT Enterprise, Business and the API don't train on business data by default, but personal accounts can. Even then, is ChatGPT safe for confidential information? Only with company rules on accounts, retention and what never gets pasted, plus a signed BAA for health data.
The realistic ChatGPT risk is an employee, not a breach: someone pastes a customer list into a personal Free or Plus login, where OpenAI may train on chats unless training is switched off.
This guide is for the IT or security lead who has to answer leadership's question: is ChatGPT safe for confidential information at our company, and on which plan? Every OpenAI fact below was checked on OpenAI's pages on 25 September 2026.
Is ChatGPT safe for confidential business information?
Yes on ChatGPT Enterprise, ChatGPT Business and the OpenAI API, with the right settings; no on unmanaged personal accounts. OpenAI's enterprise privacy commitments state that it doesn't train on business data by default and encrypts data at rest with AES-256 and in transit with TLS 1.2 or higher.
Personal plans work the other way round: OpenAI may use ChatGPT content to train its models unless the user opts out. So the account type, not the model, is what you control.
A safe setup has three parts:
- A managed workspace or an API integration for work data, never a personal login.
- Retention and access settings an admin chose on purpose.
- A written rule on which data may go in at all, because no setting stops someone pasting a password.
No OpenAI plan solves one case: a contract or regulator requiring data to stay inside your own infrastructure, since every plan processes prompts on OpenAI's systems. Keeping data in your own environment is private AI, and how sovereign AI differs from private AI covers when jurisdiction matters too.
What happens to the data you type into ChatGPT?
ChatGPT data privacy comes down to three things OpenAI documents per plan: whether content trains models, how long it's stored, and who can read it.
Personal plans: Free, Go, Plus and Pro
Chats stay in your history until you delete them. OpenAI's data controls article explains the Improve the model for everyone setting: when it's off, new conversations aren't used for training. ChatGPT Temporary Chat keeps a conversation out of history, memory and training, though OpenAI may keep a copy for up to 30 days for safety.
OpenAI's article on how it handles consumer data says cleared chats are deleted from its systems within 30 days, unless already de-identified or kept for security or legal reasons. Authorized staff and service providers may read content for abuse investigations, support, legal matters, and model improvement for users who haven't opted out.
Business and Enterprise workspaces
Content is excluded from training by default. Admins control retention, and deleted conversations are purged after up to 30 days unless the law requires longer. Enterprise admins can pull an audit log through the Compliance API, and OpenAI staff access is limited to incidents, recovery with your permission, or legal requirements.
The OpenAI API
OpenAI's platform data controls state that API data hasn't trained models since 1 March 2023 unless you opt in. Abuse-monitoring logs, which can hold prompts and responses, are kept for up to 30 days. Approved customers can get Zero Data Retention on eligible endpoints. Assistants threads and vector stores keep data until you delete it.
Each of OpenAI's retention promises allows longer retention where the law requires it.
How do ChatGPT business plans handle data differently from personal plans?
On personal plans the user decides whether chats train models; on business plans OpenAI switches training off and hands retention to an admin.
Data handling as documented by OpenAI on 25 September 2026; links in the text.
| Plan | Trains models by default? | How long data is kept | Who sets retention | Data residency | HIPAA BAA |
|---|---|---|---|---|---|
| Free, Go, Plus, Pro | Yes, unless the user opts out | Until deleted; cleared chats purged after up to 30 days | The user | Not documented | Not for standard personal plans |
| ChatGPT Business | No | Admin-set; deleted chats purged after up to 30 days | Workspace admins | Not listed | No |
| ChatGPT Enterprise | No | Admin-set; deleted chats purged after up to 30 days | Workspace admins | Yes, for eligible customers | Sales-managed accounts only |
| OpenAI API | No, since 1 March 2023 | Abuse logs up to 30 days; Zero Data Retention if approved | Customer, within approved controls | Yes, for eligible projects | Yes, on request |
OpenAI's BAA help article says it doesn't offer a BAA for ChatGPT Business, so that plan isn't for protected health information. Its residency list also omits Business. OpenAI's Enterprise Key Management lets customers control their own encryption keys.
What should employees never paste into ChatGPT?
Anything harmful in an outsider's hands, or that contracts and regulators say must stay in your systems. Even on a business plan, keep these out unless approved in writing:
- Credentials: passwords, API keys, tokens and connection strings.
- Customer personal data, such as Social Security or card numbers.
- Patient or employee health information, unless covered by a signed BAA.
- Unreleased financials, board papers and deal documents.
- Source code or designs received under an NDA.
- Privileged legal material that counsel hasn't cleared.
OpenAI's own consumer guidance asks users not to enter "sensitive information that you would not want reviewed or used."
When does a company need a private ChatGPT-style assistant instead?
When the obligation is about where data lives, not how a vendor handles it. OpenAI's business plans run on infrastructure OpenAI manages. A private assistant in your own data center or cloud account fits when:
- A contract or regulator requires data to stay on infrastructure you control.
- You want to host open-weight or fine-tuned models yourself.
- Security wants every prompt and model call in your own logs.
Firms that build OpenAI and ChatGPT integrations into enterprise software usually start from the API for this reason: no training by default, and Zero Data Retention for approved customers. Our roundup of companies that integrate ChatGPT into internal tools covers who does that work.
For more control, a custom ChatGPT runs on your own infrastructure, and the mode you pick, on-premise, private cloud or air-gapped, decides how far data travels. Choose ChatGPT Enterprise when your data can sit on OpenAI's infrastructure and the team wants the full product without running anything.
How do you set safe ChatGPT rules for your team?
Write rules an employee can follow after one read, then enforce them with settings.
- Approve the tools. Name the workspace or integration for work data; personal accounts are out.
- Classify the data. Public, internal and restricted is enough. Restricted data needs a named exception.
- Put identity in front. Use SAML single sign-on where your plan supports it.
- Set retention on purpose. Pick a period in the admin console and record why.
- Log and review. Check the audit exports your plan offers on a schedule.
- Train with examples. Show one prompt that was fine and one that wasn't.
A short AI acceptable use policy holds these rules; shadow AI, meaning tools used without approval, is what they catch.
What mistakes do companies make when rolling out ChatGPT?
- Banning it with no approved alternative. Staff move to personal accounts, the riskiest setup.
- Leaving personal accounts in use after the workspace launches.
- Skipping data loss prevention. A policy with no browser or network control relies on memory.
- Assuming "Enterprise" settles compliance. OpenAI's audits cover OpenAI's controls, not your duties under HIPAA or client NDAs.
- Forgetting connected apps. OpenAI says ChatGPT respects your existing permissions, so an over-shared folder stays over-shared.
How Origins AI Chat AI keeps assistant data inside your network
Origins AI (originshq.com) is an AI-augmented engineering partner for product teams that also builds its own enterprise AI products, deployed in the customer's environment. According to its product page, Origins AI Chat AI is a private ChatGPT-style assistant offered four ways: on-premise on your servers, private cloud in your own AWS, Azure or GCP VPC with no shared infrastructure, an embedded widget in your product, or API-first.
In on-premise deployments with self-hosted models, no data leaves your network. Route requests to a hosted model provider and, per the product page, that provider's data handling applies.
Controls a security reviewer will check, per the product page:
- Identity: SSO via SAML 2.0 or OIDC with Okta, Azure AD or Google Workspace, and access scoped by department and document.
- Audit: every message, model call and retrieval event logged with user ID, timestamp and session context.
- Data handling: PII redaction before storage, AES-256 at rest, TLS 1.3 in transit.
- Model choice: OpenAI, Anthropic, Meta Llama, Mistral or your own fine-tuned model.
One deployment can serve an internal assistant and a customer support widget or API, which is how Origins AI builds custom ChatGPT-style apps with embedded customer support. Its implementation team handles SSO, ingestion and rollout.
Talk to an engineer
Book a call with an Origins AI engineer to map deployment mode, identity and audit to your environment.
Written by Apoorva Kumar, Co-Founder & CEO, Origins AI.


