Is ChatGPT safe for confidential information?

Three things decide the answer: which account the paste went into, what the written terms say, and where the file sits afterwards. A drawing in a free account is governed by a setting that whoever holds the account can change. The same drawing sent through an eligible endpoint under a retention amendment is never logged. Neither of those keeps the file in your own building, which is the third thing to settle.

The short answer, by account

OpenAI publishes different treatment for each account tier, and the tier decides most of what happens to a paste. Find your own row first. The rows come from OpenAI's published retention statement, read again on September 22, 2026.

AccountTrained on by defaultWho controls retentionWhat deletion means
ChatGPT Free, Plus, ProThe user decides in settingsThe userRemoved from the account immediately, and scheduled for permanent deletion within 30 days, unless legally required
ChatGPT TeamNo, by defaultEach end userDeleted or unsaved conversations go within 30 days, unless legally required
ChatGPT Enterprise and EduNo, by defaultWorkspace administratorsDeleted conversations go within 30 days, unless legally required
API, defaultNot used for training since March 1, 2023 unless the customer opts inThe customer, through the endpoints it usesRemoved from OpenAI logs after 30 days, unless legally required
API, zero retention endpointsNoThe signed amendmentInputs and outputs are never logged and are not retained for application state

The API training default and the endpoint lists come from OpenAI's developer documentation on your data. Four of those five rows end on the same clause: "unless we are legally required to retain them". A preservation order in 2025 invoked that clause, and the next section says which tiers it reached.

What deleted means here

Deletion removes the chat from the account immediately and schedules removal from OpenAI systems within 30 days. The exception attached to that sentence is the one to read, because an obligation from outside the company suspends it.

A preservation order in the New York Times litigation required OpenAI to retain consumer ChatGPT and API content that would otherwise have been deleted. OpenAI published which customers it reached: ChatGPT Free, Plus, Pro and Team, and API customers without a zero data retention agreement. It did not reach ChatGPT Enterprise, ChatGPT Edu, or API customers using zero retention endpoints under the retention amendment.

Obligations under that order ended on September 26, 2025, and standard 30 day deletion resumed. A limited set of April to September 2025 user data is still stored under legal hold. Only a small audited legal and security team can reach it.

For a plant it comes down to one sentence. A retention setting is a company policy, and an order from outside the company can suspend it. The tiers that came through untouched were the ones holding a written term.

What is actually in the paste

Five objects carry the exposure, and every one of them crosses a shop on a normal day.

Most of these arrive as an attachment. A prompt and an uploaded file take different paths through a provider's systems. A retention term written for one does not automatically cover the other. The next section names the difference.

Not sure what has already been pasted

Send the question you are trying to answer, whether that is a customer questionnaire or an estimator pasting drawings.

Start a conversation

Zero data retention, and the two things it does not cover

A zero data retention arrangement is a contract amendment. OpenAI grants it on prior approval and on acceptance of further terms. Under it, inputs and outputs are never logged and are not retained for application state.

The first thing it does not cover is every endpoint. Chat completions, responses, embeddings, image generation and audio transcription sit on the eligible list. Files, vector stores, conversations, assistants and threads, batches and fine tuning jobs sit on the ineligible one. Those are the endpoints an application uses to keep a document. Read that in shop terms: the answer can run under zero retention while the uploaded drawing sits in storage the amendment never covered. Abuse monitoring logs are generated for all API feature usage and kept up to 30 days.

The second thing it does not cover is every model. Anthropic publishes the same shape with a sharper edge. Commercial inputs and outputs are deleted on the backend within 30 days of receipt or generation. A conversation flagged by trust and safety systems is kept up to 2 years, and its classification scores up to 7 years. Prompts and outputs for models Anthropic designates as covered are retained for 30 days on every platform where those models are offered. That designation overrides a prior zero retention arrangement, and organizations holding one have to enable retention to use those models. The published list changes, so read it on the day you sign.

This is why our own contracts name the model tier. Zero retention is not available for every tier, so a contract that says zero retention without naming the tier has not said anything yet.

The three controls that change the answer

Act on them in this order.

  1. The account. Who signs for it, and whether an administrator rather than an end user controls retention. Most shops have turned this one on and nothing else, and it is the weakest of the three.
  2. The written terms. A retention amendment names the endpoints it covers and the model tier it applies to. Changing it takes a renegotiation.
  3. Where the file sits at rest. The control the first two do not touch. A retention term governs the inference call, and the document stays wherever the application put it.

The ThriveAI workspace is designed to run on a dedicated server in Canada, one per client. The drawing, the ERP export and the costing sheet stay at rest on that server. Inference runs two ways, and the client picks. One is an open weight model on that same server. The other is a frontier model under a written zero data retention control, with the model tier named. A named person approves every quote, message and write back.

The third control is the one a buyer settles on paper. It decides what a Canadian manufacturer can control about where its data sits.

Four rules worth writing down

Whether a chat tool is safe at work turns on which account is open and what is in the paste. These four rules settle both, and a shop can write them down in an afternoon.

What may be pasted where

Customer drawings, costing sheets, supplier prices, ERP exports and anything carrying a customer name go into an approved account only. General questions, public standards, code the shop wrote and material the shop owns outright can go anywhere. One line carries it: if the file came from a customer, it does not leave the approved account.

If it has already been pasted

Start with the account that holds the history. Turn off the setting that lets chats improve the model, delete the conversations that carried customer files, and write down which files those were. A deleted conversation goes within 30 days unless retention is legally required, so the record of what went out is the part that lasts. Tell the customer which of its files went through, before it asks.

Which accounts are approved

An approved account passes four tests. The company contracts for it. An administrator controls retention. Training on business content is off by default. The written terms name the endpoints they cover and the model tier they apply to. A personal account fails the first test and therefore all four.

What gets logged

Keep a record of which account each person uses and which files left the building through it. The reason is operational. When a customer asks where its drawing went, the shop answers from a record instead of from memory.

Who signs off

One named person approves a new account, a new connector, and any first upload of a customer's file. That is the same rule that governs the quoting work: a named person approves every action, and nothing goes out on its own.

What this looks like when it is built in

The paste happens because the answer lives in systems the estimator cannot query: the ERP, the mailbox and the drawing vault. Copy those into one data warehouse on the shop's own server, and the estimator asks the warehouse instead of pasting the export. Every value keeps a line back to the record it came from, and the system refuses when the warehouse has no answer. The same mechanism lets an estimator ask the ERP directly instead of pasting the export. It sits under the other modules described in AI for manufacturing.

In practice

Costing work can run against a plant's own cost and time records on a dedicated server, so no drawing or price is pasted into a consumer chat account.

This page is also en français.

Questions people ask

Does ChatGPT keep conversations confidential?
Treatment differs by account. On Free, Plus and Pro the user decides in settings whether chats help improve ChatGPT. On Team each end user controls whether conversations are retained, and on Enterprise and Edu a workspace administrator does. Every ChatGPT tier in the table carries the same exception: a deleted conversation goes within 30 days unless retention is legally required. The account table on this page sets out each row.
What should you not paste into ChatGPT at work?
Five objects carry the exposure in a shop. A customer drawing is the customer's property under most supply agreements. A supplier quote or a purchase price is margin stated backwards. A costing sheet or a routing gives away cycle times, setup times and the shop rate. An RFQ email thread carries the contact, the terms and the delivery promise. An ERP export hands over part numbers, customers and prices for the whole book in one paste.
Can I trust ChatGPT with personal or customer information?
Separate the written term from the setting. A business account gives a company something it can point at: an administrator who controls retention, and terms it can renegotiate. A personal account gives a setting that whoever holds the account can change, and no term. Customer information held under a supply agreement belongs in the first category, or in a system the shop runs itself.
Does ChatGPT leak information?
The best documented route is credential theft from the user's own machine. Group-IB found 101,100 compromised ChatGPT account credentials in information stealer logs between June 2022 and May 2023. Training on content is a setting the user controls on the consumer tiers, and it is off by default on the business tiers. A stolen personal login exposes the chat history behind it.
Does ChatGPT have zero data retention?
It is available on eligible API endpoints under an amendment that OpenAI grants on prior approval. Under it, inputs and outputs are never logged and are not retained for application state. It does not exist on the consumer tiers. It does not cover every endpoint either. Files, vector stores, conversations, assistants and threads, batches and fine tuning jobs sit on the ineligible list.
Is ChatGPT safe to use at work?
It depends on which account is open and what is in the paste. Decide both in writing. Name the accounts the company contracts for, and name the files that may go into them. Keep a record of which customer files went through, and name the person who approves a new account. The four rules on this page settle all four.

Contact

Use AI on drawings and prices without the risk

Tell Derik which documents your team pastes into AI tools today and which plans you pay for. He will tell you which of the three controls your setup is missing.

Prefer to talk? Book a meeting.

Your message goes to Derik Lawlis, the founder.