aistatus.info

Privacy in the age of AI — checked against the actual policies.

← All providers

Does OpenAI train on your ChatGPT data?

Free, Plus and Pro train on your conversations by default; one toggle stops it. Business, Enterprise, Edu and the API never train unless you opt in. Last verified 2026-07-21.

Plan Trains by default Opt-out Retention (default) ZDR
OpenAI — all plans
ChatGPT Free Yes Yes Deleted chats purged in 30 days
ChatGPT Plus Yes Yes Deleted chats purged in 30 days
ChatGPT Pro Yes Yes Deleted chats purged in 30 days
ChatGPT Business No Admin-controlled · deleted in 30 days No
ChatGPT Enterprise No Admin-controlled · deleted in 30 days No
ChatGPT Edu No Admin-controlled · deleted in 30 days No
OpenAI API No 30-day abuse-monitoring window Yes
OpenAI API + ZDR No Zero at rest (eligible endpoints) Yes

Plan by plan

ChatGPT Free

Trains by default
Training default
Your content is used for training unless you opt out.
Opt-out
Settings → Data Controls → turn off 'Improve the model for everyone' (account-level, syncs web+mobile); or privacy.openai.com 'do not train on my content'; legacy support/form opt-outs still honored.
Retention
Chats kept until deleted; on deletion removed from account immediately and permanently deleted from OpenAI systems within 30 days (unless already de-identified for training, or legal/security retention applies). — Temporary Chats auto-delete within 30 days and aren't trained on. Saved Memories stored separately and persist until deleted (deleted-memory logs kept up to 30 days). Even with training off, content sits ~30 days for abuse monitoring. NYT indefinite-hold ended 26 Sep 2025; residual April–Sept 2025 preserved logs and flagged-account logs may remain. US Free/Go tiers show ads (adults, logged-in); advertisers get only aggregate metrics, not chats.
Human review
OpenAI staff and specialized contractors may review content to monitor/investigate abuse and safety; if training is on, sampled conversations may be reviewed by human trainers. Temporary Chats may be reviewed only for abuse.
Feedback carve-out
If you submit feedback (e.g., thumbs up/down), 'the entire conversation associated with that feedback may be used to train our models,' even if otherwise opted out.

Go ($8/mo) shares these consumer defaults. Codex has separate full-environment training controls in Codex Settings.

Sources (4)

ChatGPT Plus

Trains by default
Training default
Your content is used for training unless you opt out.
Opt-out
Same as Free: Settings → Data Controls → turn off 'Improve the model for everyone' (or privacy portal).
Retention
Same as Free: chats kept until deleted; deleted chats purged from systems within 30 days unless legal/security retention or already de-identified. — Identical consumer data policy to Free — Plus buys capability, not privacy. Temporary Chats auto-delete within 30 days. 30-day abuse-monitoring floor applies even with training off. Was in scope of the (now-ended) NYT preservation order.
Human review
Same as Free: abuse/safety review by staff/contractors; sampled human-trainer review when training is on.
Feedback carve-out
Same universal carve-out: submitting feedback licenses training on the entire associated conversation even after opt-out.

US Privacy Policy governs; 'Reference chat history' memory available. $20/mo, monthly only.

Sources (3)

ChatGPT Pro

Trains by default
Training default
Your content is used for training unless you opt out.
Opt-out
Same as Free/Plus: Settings → Data Controls → turn off 'Improve the model for everyone.'
Retention
Same as Free/Plus: deleted chats purged within 30 days unless legal/security retention or already de-identified. — Consumer defaults identical to Plus. Pro ($200/mo; a $100/mo Pro tier added April 9, 2026) buys usage/model access, not different data handling. Was in scope of the (now-ended) NYT preservation order.
Human review
Same as other consumer plans: abuse/safety review; sampled review when training on.
Feedback carve-out
Same universal feedback carve-out.

OpenAI's NYT page lists 'ChatGPT Free, Plus, Pro' together for retention practices, confirming Pro follows consumer defaults.

Sources (2)

ChatGPT Business (formerly ChatGPT Team)

No training by default
Training default
Your content is not used for training unless you explicitly opt in.
Opt-out
No opt-out needed — not trained on by default. It is opt-IN: training only occurs if the org/user explicitly opts in (e.g., feedback mechanisms). Admins control workspace data/privacy settings.
Retention
Workspace admins control retention; deleted or unsaved conversations removed within 30 days, unless longer retention is required by law or reasonably necessary to protect the services or a third party. — Renamed from 'ChatGPT Team' on Aug 29, 2025 (name change only; contracts/features/pricing/limits unchanged). $25/user/mo monthly or $20 annual (monthly cut $5 effective Apr 2, 2026), 2-seat minimum. Memories tied to individual accounts, not trained on by default, admin-controllable. Was listed in the (now-ended) NYT order scope for 'Team.'
Human review
Access limited to (1) authorized employees for engineering support, abuse investigation, and legal compliance, and (2) specialized third-party contractors bound by confidentiality, 'solely to review for abuse and misuse.' Workspace admins can view/export/delete end-user conversations.
Feedback carve-out
Opting in — e.g., submitting feedback — allows OpenAI to use that shared data to train models; otherwise no training.

ZDR is API-only; the ChatGPT chat product isn't ZDR because persistent chat history is intrinsic.

Sources (4)
  • help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance (Updated 2026)
    “By default, we do not train on any inputs or outputs from our products for business users, including ChatGPT Business, ChatGPT Enterprise, and the API.”
    accessed 2026-07-21
  • openai.com/enterprise-privacy/ (Updated January 8, 2026)
    “Your workspace admins can control how long your data is retained. Any deleted or unsaved conversations are removed from our systems within 30 days, unless longer retention is required by law, or is reasonably necessary to protect our services or any third party from harm.”
    accessed 2026-07-21
  • openai.com/enterprise-privacy/ (Updated January 8, 2026)
    “Our access to conversations stored on our systems is limited to (1) authorized employees … and (2) specialized third-party contractors who are bound by confidentiality and security obligations, solely to review for abuse and misuse.”
    accessed 2026-07-21
  • help.openai.com/en/articles/12111915-chatgpt-business-rename-faq (2025)
    “As of August 29th, 2025, the ChatGPT Team plan has been renamed to ChatGPT Business … This is a name change only. All features, pricing and limits remain the same … All existing contracts and terms remain in effect.”
    accessed 2026-07-21

ChatGPT Enterprise

No training by default
Training default
Your content is not used for training unless you explicitly opt in.
Opt-out
Not trained on by default; opt-IN only via explicit agreement (e.g., feedback mechanisms). Admin-controlled workspace settings.
Retention
Workspace admins control retention duration; deleted conversations removed from systems within 30 days unless legally required to retain. — Contractual guarantee in Services Agreement §4.2. SOC 2 Type 2 audited; SAML SSO, Enterprise Key Management, Compliance API. Never impacted by NYT preservation order.
Human review
Authorized OpenAI employees 'will only ever access your conversations for the purposes of resolving incidents, recovering end user conversations with your explicit permission, or where required by applicable law.' Business data may run through automated classifiers (metadata only).
Feedback carve-out
Only if the customer explicitly opts in (e.g., feedback mechanisms) does OpenAI use shared data to train; otherwise never.

The Enterprise chat product is not a ZDR product (persistent chat history is part of how it works); ZDR is API-only.

Sources (4)
  • openai.com/policies/business-terms/ (Updated December 1, 2025; effective January 1, 2026)
    “OpenAI will not use Customer Content to develop or improve the Services, unless Customer explicitly agrees to such use.”
    accessed 2026-07-21
  • openai.com/enterprise-privacy/ (Updated January 8, 2026)
    “Your workspace admins control how long your data is retained. Any deleted conversations are removed from our systems within 30 days, unless we are legally required to retain them.”
    accessed 2026-07-21
  • openai.com/enterprise-privacy/ (Updated January 8, 2026)
    “Authorized OpenAI employees will only ever access your conversations for the purposes of resolving incidents, recovering end user conversations with your explicit permission, or where required by applicable law.”
    accessed 2026-07-21
  • openai.com/index/response-to-nyt-data-demands/ (June 5, 2025; updated October 22, 2025)
    “This does not impact ChatGPT Enterprise or ChatGPT Edu customers.”
    accessed 2026-07-21

ChatGPT Edu

No training by default
Training default
Your content is not used for training unless you explicitly opt in.
Opt-out
Not trained on by default; opt-IN only. Admins have the same controls as ChatGPT Enterprise.
Retention
Workspace admins control retention; deleted conversations removed within 30 days unless legally required to retain. — Processed under OpenAI's Student Data Privacy Agreement (SDPA) rather than the standard DPA. Never impacted by the NYT preservation order (explicitly exempt). Data export off by default; admin-enabled.
Human review
Same Enterprise-grade conditions: employee access only for incidents, explicit-permission recovery, or where legally required; automated classifiers produce metadata only.
Feedback carve-out
Only via explicit opt-in (e.g., feedback mechanisms); otherwise never.

Chat product not ZDR (API-only). ChatGPT for Teachers/Healthcare follow the same no-training-by-default model but are out of scope.

Sources (4)
  • openai.com/business-data/ (2026)
    “By default, we do not use data from ChatGPT Enterprise, ChatGPT Business, ChatGPT Edu, ChatGPT for Healthcare, ChatGPT for Teachers, or our API platform—including inputs or outputs—for training or improving our models.”
    accessed 2026-07-21
  • openai.com/enterprise-privacy/ (Updated January 8, 2026)
    “You control how long your data is retained (ChatGPT Enterprise, ChatGPT for Healthcare, ChatGPT Edu) … Any deleted conversations are removed from our systems within 30 days, unless we are legally required to retain them.”
    accessed 2026-07-21
  • openai.com/index/response-to-nyt-data-demands/ (June 5, 2025; updated October 22, 2025)
    “This does not impact ChatGPT Enterprise or ChatGPT Edu customers.”
    accessed 2026-07-21
  • openai.com/enterprise-privacy/ (Updated January 8, 2026)
    “For ChatGPT Edu and for Teachers, we process your data pursuant to our Student Data Privacy Agreement.”
    accessed 2026-07-21

OpenAI API (Platform, standard terms)

No training by default
Training default
Your content is not used for training unless you explicitly opt in.
Opt-out
Not trained on by default; opt-IN only (e.g., sharing feedback/evals in the Playground). Unless explicitly opted in, organizations are opted out of data-sharing.
Retention
Abuse-monitoring logs retained up to 30 days for all API usage, then removed, unless longer retention is required by law or reasonably necessary to protect the services/third parties. — Stateful endpoints persist application state 'until deleted' (Conversations, Threads, Assistants, Vector Stores, Files, fine-tuning files). /v1/moderations and audio transcription/translation have no abuse-monitoring retention. Fine-tuned models are private to the customer. Was in scope of (now-ended) NYT order for non-ZDR API.
Human review
Authorized employees (engineering support, abuse investigation, legal compliance) plus specialized third-party contractors 'solely to review for abuse and misuse.'
Feedback carve-out
API customers can opt in to share data (e.g., Playground feedback/evals) which OpenAI then uses to improve models; no training without explicit opt-in.

Governed by the Services Agreement + DPA. Data residency available (per-project) for eligible regions; non-US regions require MAM/ZDR amendment.

Sources (4)
  • developers.openai.com/api/docs/guides/your-data (2026 (current docs))
    “As of March 1, 2023, data sent to the OpenAI API is not used to train or improve OpenAI models (unless you explicitly opt in to share data with us).”
    accessed 2026-07-21
  • developers.openai.com/api/docs/guides/your-data (2026 (current docs))
    “By default, abuse monitoring logs are generated for all API feature usage and retained for up to 30 days, unless longer retention is required by law, or is reasonably necessary to protect our services or any third party from harm.”
    accessed 2026-07-21
  • openai.com/enterprise-privacy/ (Updated January 8, 2026)
    “Our access to API business data stored on our systems is limited to (1) authorized employees … and (2) specialized third-party contractors who are bound by confidentiality and security obligations, solely to review for abuse and misuse.”
    accessed 2026-07-21
  • help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance (Updated 2026)
    “We offer API customers a way to opt-in to share data with us, such as by providing feedback in the Playground … Unless they explicitly opt-in, organizations are opted out of data-sharing by default.”
    accessed 2026-07-21

OpenAI API with Zero Data Retention

No training by default
Training default
Your content is not used for training unless you explicitly opt in.
Opt-out
ZDR is itself the strongest opt-out of retention; content is never trained on (same default as standard API) and is excluded from abuse-monitoring logs. Configured in Settings → Organization → Data controls → Data Retention after approval.
Retention
Inputs and outputs are never logged and not retained for application state on ZDR-eligible endpoints; store parameter forced to false for /v1/responses and /v1/chat/completions. — Eligibility is approval-gated: customers must apply via sales and provide qualifying use-case justification; not available on free/standard pay-as-you-go by default. ZDR-eligible (stateless): /v1/chat/completions, /v1/responses, /v1/embeddings, /v1/moderations, /v1/completions, /v1/audio/*, /v1/realtime, gpt-image generation. NOT eligible (stateful): /v1/conversations, /v1/threads, /v1/assistants, /v1/vector_stores, /v1/files, /v1/fine_tuning/jobs, /v1/evals, /v1/batches, /v1/videos. Image/file inputs flagged as potential CSAM are retained for manual review even under ZDR. Never affected by the NYT order.
Human review
None under ZDR ('not accessed by human reviewers'), except potential-CSAM image/file inputs retained for manual review. Related controls: Eyes Off (no human review even if retained) and Safety Retention (retain + review only classifier-flagged severe-risk content).
Feedback carve-out
No training regardless; ZDR content is excluded from logs and human review. Opting into feedback would be a separate, explicit choice.

Eligible only for API/business customers, granted per organization/project; the ChatGPT consumer/chat products are not ZDR. Extended prompt caching may store encrypted KV tensors in GPU-local storage (not retained after 24h).

Sources (4)
  • developers.openai.com/api/docs/guides/your-data (2026 (current docs))
    “Zero Data Retention excludes customer content from abuse monitoring logs … the store parameter for /v1/responses and v1/chat/completions will always be treated as false, even if the request attempts to set the value to true.”
    accessed 2026-07-21
  • developers.openai.com/api/docs/guides/your-data (2026 (current docs))
    “Currently, these controls are subject to prior approval by OpenAI and acceptance of additional requirements. Approved customers may select between Modified Abuse Monitoring or Zero Data Retention for their API Organization or project.”
    accessed 2026-07-21
  • developers.openai.com/api/docs/guides/your-data (2026 (current docs))
    “Image and file inputs are scanned for CSAM content upon submission. If the classifier detects potential CSAM content, the image will be retained for manual review, even if Zero Data Retention, Modified Abuse Monitoring, or Eyes Off is enabled.”
    accessed 2026-07-21
  • openai.com/index/response-to-nyt-data-demands/ (June 5, 2025; updated October 22, 2025)
    “If you are a business customer that uses our Zero Data Retention (ZDR) API, we never retain the prompts you send or the answers we return. Because it is not stored, this court order doesn't affect that data.”
    accessed 2026-07-21

Worth knowing