Is ChatGPT safe for confidential information?
Three things decide the answer: which account the paste went into, what the written terms say, and where the file sits afterwards. A drawing in a free account is governed by a setting that whoever holds the account can change. The same drawing sent through an eligible endpoint under a retention amendment is never logged. Neither of those keeps the file in your own building, which is the third thing to settle.
The short answer, by account
OpenAI publishes different treatment for each account tier, and the tier decides most of what happens to a paste. Find your own row first. The rows come from OpenAI's published retention statement, read again on September 22, 2026.
| Account | Trained on by default | Who controls retention | What deletion means |
|---|---|---|---|
| ChatGPT Free, Plus, Pro | The user decides in settings | The user | Removed from the account immediately, and scheduled for permanent deletion within 30 days, unless legally required |
| ChatGPT Team | No, by default | Each end user | Deleted or unsaved conversations go within 30 days, unless legally required |
| ChatGPT Enterprise and Edu | No, by default | Workspace administrators | Deleted conversations go within 30 days, unless legally required |
| API, default | Not used for training since March 1, 2023 unless the customer opts in | The customer, through the endpoints it uses | Removed from OpenAI logs after 30 days, unless legally required |
| API, zero retention endpoints | No | The signed amendment | Inputs and outputs are never logged and are not retained for application state |
The API training default and the endpoint lists come from OpenAI's developer documentation on your data. Four of those five rows end on the same clause: "unless we are legally required to retain them". A preservation order in 2025 invoked that clause, and the next section says which tiers it reached.
What deleted means here
Deletion removes the chat from the account immediately and schedules removal from OpenAI systems within 30 days. The exception attached to that sentence is the one to read, because an obligation from outside the company suspends it.
What a court order did to those settings in 2025
A preservation order in the New York Times litigation required OpenAI to retain consumer ChatGPT and API content that would otherwise have been deleted. OpenAI published which customers it reached: ChatGPT Free, Plus, Pro and Team, and API customers without a zero data retention agreement. It did not reach ChatGPT Enterprise, ChatGPT Edu, or API customers using zero retention endpoints under the retention amendment.
Obligations under that order ended on September 26, 2025, and standard 30 day deletion resumed. A limited set of April to September 2025 user data is still stored under legal hold. Only a small audited legal and security team can reach it.
For a plant it comes down to one sentence. A retention setting is a company policy, and an order from outside the company can suspend it. The tiers that came through untouched were the ones holding a written term.
What is actually in the paste
Five objects carry the exposure, and every one of them crosses a shop on a normal day.
- A customer drawing. A customer drawing carries tolerances, the revision, the customer's part number, and often the customer's name in the title block. Under most supply agreements the drawing is the customer's property, so disclosing it is the shop's exposure and the customer's loss.
- A supplier quote or a purchase price. A supplier quote states landed cost, which is margin read backwards.
- A costing sheet or a routing. A costing sheet lists cycle times, setup times and the shop rate. Anyone holding those can price against the shop.
- An email thread from the RFQ. An RFQ thread carries the customer contact, the commercial terms and the delivery promise.
- An ERP export. An ERP export hands over part numbers, customers and prices for the whole book in one paste.
Most of these arrive as an attachment. A prompt and an uploaded file take different paths through a provider's systems. A retention term written for one does not automatically cover the other. The next section names the difference.
Not sure what has already been pasted
Send the question you are trying to answer, whether that is a customer questionnaire or an estimator pasting drawings.
Start a conversationZero data retention, and the two things it does not cover
A zero data retention arrangement is a contract amendment. OpenAI grants it on prior approval and on acceptance of further terms. Under it, inputs and outputs are never logged and are not retained for application state.
The first thing it does not cover is every endpoint. Chat completions, responses, embeddings, image generation and audio transcription sit on the eligible list. Files, vector stores, conversations, assistants and threads, batches and fine tuning jobs sit on the ineligible one. Those are the endpoints an application uses to keep a document. Read that in shop terms: the answer can run under zero retention while the uploaded drawing sits in storage the amendment never covered. Abuse monitoring logs are generated for all API feature usage and kept up to 30 days.
The second thing it does not cover is every model. Anthropic publishes the same shape with a sharper edge. Commercial inputs and outputs are deleted on the backend within 30 days of receipt or generation. A conversation flagged by trust and safety systems is kept up to 2 years, and its classification scores up to 7 years. Prompts and outputs for models Anthropic designates as covered are retained for 30 days on every platform where those models are offered. That designation overrides a prior zero retention arrangement, and organizations holding one have to enable retention to use those models. The published list changes, so read it on the day you sign.
This is why our own contracts name the model tier. Zero retention is not available for every tier, so a contract that says zero retention without naming the tier has not said anything yet.
The three controls that change the answer
Act on them in this order.
- The account. Who signs for it, and whether an administrator rather than an end user controls retention. Most shops have turned this one on and nothing else, and it is the weakest of the three.
- The written terms. A retention amendment names the endpoints it covers and the model tier it applies to. Changing it takes a renegotiation.
- Where the file sits at rest. The control the first two do not touch. A retention term governs the inference call, and the document stays wherever the application put it.
The ThriveAI workspace is designed to run on a dedicated server in Canada, one per client. The drawing, the ERP export and the costing sheet stay at rest on that server. Inference runs two ways, and the client picks. One is an open weight model on that same server. The other is a frontier model under a written zero data retention control, with the model tier named. A named person approves every quote, message and write back.
The third control is the one a buyer settles on paper. It decides what a Canadian manufacturer can control about where its data sits.
Four rules worth writing down
Whether a chat tool is safe at work turns on which account is open and what is in the paste. These four rules settle both, and a shop can write them down in an afternoon.
What may be pasted where
Customer drawings, costing sheets, supplier prices, ERP exports and anything carrying a customer name go into an approved account only. General questions, public standards, code the shop wrote and material the shop owns outright can go anywhere. One line carries it: if the file came from a customer, it does not leave the approved account.
If it has already been pasted
Start with the account that holds the history. Turn off the setting that lets chats improve the model, delete the conversations that carried customer files, and write down which files those were. A deleted conversation goes within 30 days unless retention is legally required, so the record of what went out is the part that lasts. Tell the customer which of its files went through, before it asks.
Which accounts are approved
An approved account passes four tests. The company contracts for it. An administrator controls retention. Training on business content is off by default. The written terms name the endpoints they cover and the model tier they apply to. A personal account fails the first test and therefore all four.
What gets logged
Keep a record of which account each person uses and which files left the building through it. The reason is operational. When a customer asks where its drawing went, the shop answers from a record instead of from memory.
Who signs off
One named person approves a new account, a new connector, and any first upload of a customer's file. That is the same rule that governs the quoting work: a named person approves every action, and nothing goes out on its own.
What this looks like when it is built in
The paste happens because the answer lives in systems the estimator cannot query: the ERP, the mailbox and the drawing vault. Copy those into one data warehouse on the shop's own server, and the estimator asks the warehouse instead of pasting the export. Every value keeps a line back to the record it came from, and the system refuses when the warehouse has no answer. The same mechanism lets an estimator ask the ERP directly instead of pasting the export. It sits under the other modules described in AI for manufacturing.
Costing work can run against a plant's own cost and time records on a dedicated server, so no drawing or price is pasted into a consumer chat account.
This page is also en français.