Quick Answer
ChatGPT is safe for everyday tasks, but ChatGPT is not a private space. OpenAI saves regular chats until you delete them and can use personal-plan conversations for model training unless you switch it off. Turn off training in Data controls, use Temporary Chat for sensitive questions, enable multi-factor authentication, and never paste passwords, ID numbers or financial details.
Key Takeaways
- OpenAI can use conversations from personal plans (Free, Go, Plus and Pro) to train its models until you turn off Improve the model for everyone under Settings > Data controls.
- Deleted chats disappear from your account at once and are scheduled for permanent deletion from OpenAI’s systems within 30 days, with exceptions for security or legal obligations.
- Temporary Chat keeps a conversation out of your history and out of training, but OpenAI may still keep a copy for up to 30 days for safety purposes.
- Rating a response with thumbs up or thumbs down can send the entire conversation for training, even after you opt out.
- A March 2023 bug in ChatGPT exposed limited payment details of 1.2% of Plus subscribers active during a nine-hour window; full card numbers were not exposed.
Is ChatGPT safe to use?
ChatGPT is safe for ordinary tasks such as drafting, summarizing and brainstorming, provided you treat every conversation as data that a company stores. The main risks are what you choose to type, who can reach your account, and whether you act on an answer without checking it.
OpenAI describes several built-in protections on its consumer privacy page, including encryption, security testing and monitoring for suspicious activity, and it states that it does not sell user data or share conversations with advertisers. Those commitments do not change the basic fact that regular chats are stored on OpenAI’s servers and can be exposed if your account is taken over or a link is shared.
Does ChatGPT save your data?
ChatGPT saves your regular and archived chats to your account until you delete them. According to OpenAI’s chat and file retention article, a deleted chat is removed from your account view immediately and scheduled for permanent deletion from OpenAI’s systems within 30 days. The same article lists 2 exceptions: chats that were already de-identified and disassociated from your account, and chats OpenAI must keep longer for security or legal obligations.
Archiving is not the same as deleting: OpenAI confirms that archiving does not change a chat’s retention period or whether it can be used for training. A file saved to Library also stays there after you delete the chat that used it.
The practical response is to delete, rather than archive, conversations you do not want kept, and to check Library for uploaded files you also want removed.
Does OpenAI train its models on your ChatGPT conversations?
OpenAI can train its models on conversations from its services for individuals, such as ChatGPT and Codex, unless you opt out. OpenAI’s article on how your data is used to improve model performance says you can opt out by turning off Improve the model for everyone or by selecting Do not train on my content in the OpenAI Privacy Portal, and that either option is enough. After you opt out, new conversations are not used to improve the models.
There are 2 important limits to the opt-out. First, feedback overrides it: if you select thumbs up or thumbs down on a response, OpenAI states that the entire conversation tied to that feedback may be used for training. Second, the opt-out covers new conversations only.
Business accounts work differently. OpenAI says that by default it does not use inputs or outputs from ChatGPT Business, Enterprise, Edu or the API to train its models.
Which ChatGPT privacy settings should you change?
To change ChatGPT privacy settings, open Settings and select Data controls, which is where OpenAI groups training, export, shared links and account deletion. The table below summarizes the 5 controls with the most effect on privacy, based on OpenAI’s data controls documentation as of September 2026.
| Control | Where to find it | What it does | Main limit |
|---|---|---|---|
| Improve the model for everyone | Settings > Data controls | Stops new conversations from being used for training | Does not delete chats; thumbs-up or thumbs-down feedback can still share a conversation |
| Temporary Chat | New chat > Temporary | Keeps the chat out of history, memory and training | A copy may be kept for up to 30 days for safety purposes |
| Shared links | Settings > Data controls > Shared links > Manage | Lists and deletes public links to your chats | Deleting a link does not remove copies other people already saved |
| Multi-factor authentication | Settings > Security and login | Adds a second sign-in step across ChatGPT and the API Platform | Cannot currently be enforced by workspace admins |
| Export data and delete account | Settings > Data controls | Downloads a copy of your data or permanently deletes the account | Self-service only on Free, Go, Plus and Pro; managed workspaces go through the owner |
Follow these steps on the web to turn off training:
- Open your account menu and select Settings.
- Select Data controls.
- Select Improve the model for everyone, turn it off, and select Done.
On iOS and Android, open the sidebar, tap your profile icon to open Settings, select Data controls, and turn off the same toggle. When you are signed in, the setting follows your account across devices; signed out, it is saved only in that browser.
How does Temporary Chat protect your privacy?
Temporary Chat protects your privacy by keeping a conversation out of your chat history, out of memory and out of model training while it stays temporary. OpenAI’s Temporary Chat article explains that you start one by opening a new chat, selecting Temporary, and choosing Personalized or Unpersonalized before you send the first message. An Unpersonalized temporary chat does not use your memories, custom instructions or plugins.
Temporary Chat is not the same as no record at all. OpenAI states that it may keep a copy for up to 30 days for safety purposes, and that saving the chat later turns it into a regular chat that follows your normal training and retention settings.
For most users, Temporary Chat combined with the training opt-out is the most private way to use a personal ChatGPT account, but it does not make it safe to paste information that should never leave your control.
What should you never share with ChatGPT?
You should never share information with ChatGPT that could unlock an account, identify you for fraud, or breach someone else’s confidentiality. There are 5 categories to keep out of any chatbot prompt:
- Login secrets: passwords, one-time codes, recovery keys and API keys.
- Government and financial identifiers: Social Security numbers, passport numbers, bank account numbers and full card numbers.
- Health records: test results, diagnoses and insurance details tied to your name.
- Other people’s private data: client files, patient information, and contact details of friends or colleagues.
- Confidential work material: unreleased financials, source code under a nondisclosure agreement and legal documents.
OpenAI’s own sharing guidance tells users not to include health information, financial details, passwords or account numbers in shared content, because anyone who has a personal-account link can view it. The same logic applies to every prompt, because data you never enter cannot be retained or leaked. Replace names and numbers with placeholders before you paste a sensitive document. For health questions specifically, TechJournal’s guide on whether ChatGPT Health is safe covers the separate health features.
How do you secure your ChatGPT account?
To secure your ChatGPT account, turn on multi-factor authentication (MFA), which adds a second verification step at sign-in. OpenAI’s MFA help article lists 4 verification methods: an authenticator app, push notifications, a text message code by SMS or WhatsApp, and a passkey. OpenAI states that MFA applies across its services, including ChatGPT and the API Platform. An attacker who steals your password still needs the second factor to read your chat history.
Safety first: if you believe someone you know has accessed your account, such as a partner or family member, plan your next steps from a device that person cannot reach, because changing the password or signing out other sessions can alert them.
- Open ChatGPT Settings and select Security and login.
- Choose a method under Multi-factor authentication (MFA) and follow the setup prompts, such as scanning a QR code with an authenticator app.
- Select Log out of all devices on the same page if you suspect another session is active. OpenAI notes this can take up to 30 minutes to complete.
- Review Settings > Data controls > Shared links and delete links you no longer need.
Stop and contact OpenAI Support through its official help center if you are locked out, if MFA settings changed without your action, or if you see charges you did not make. For a wider view of how passkeys protect accounts, see TechJournal’s explainer on passwords versus passkeys.
How do you spot fake ChatGPT apps and phishing?
Fake ChatGPT apps and phishing messages are a larger practical risk for many users than OpenAI’s own servers. The safe rule is to install ChatGPT only from the links on OpenAI’s official download page, which points to the Windows app, the Chrome extension, and the iOS and Android store listings. Look-alike apps can charge subscriptions for a service the real app offers for free, flood the phone with ads or hide malware, as TechJournal describes in its report on fake ChatGPT app scams.
Phishing follows the same pattern. After a November 2025 incident at the analytics vendor Mixpanel, OpenAI’s incident notice reminded users that it does not request passwords, API keys or verification codes through email, text or chat, and that messages claiming to be from OpenAI should come from an official OpenAI domain. Genuine shared conversation links begin with https://chatgpt.com/share/, according to OpenAI.
Has ChatGPT ever had a data breach?
OpenAI has disclosed 2 notable incidents that exposed limited user information: 1 bug in its own systems and 1 breach at a vendor. In its March 24, 2023 post, OpenAI said a bug in the open-source redis-py library let some users see titles from another active user’s chat history. OpenAI said the same bug may have exposed payment-related information of 1.2% of ChatGPT Plus subscribers active during a nine-hour window on March 20, 2023, including name, email, payment address, card type, the last 4 digits of the card and its expiration date. OpenAI stated that full card numbers were not exposed.
The second incident took place in Mixpanel’s systems rather than OpenAI’s. OpenAI said an attacker exported a dataset on November 9, 2025, containing names, email addresses, approximate location and browser details for some API users and a limited number of ChatGPT users. OpenAI stated that no chats, passwords, API keys, payment details or government IDs were exposed. Both incidents show that exposure can come from bugs and vendors, not only attackers.
Can you trust ChatGPT’s answers?
ChatGPT’s answers are useful but not reliable enough to act on without checking. OpenAI’s Terms of Use state that output may not always be accurate and should not be relied on as a sole source of truth or as a substitute for professional advice.
The practical response is to use ChatGPT to understand a topic or prepare questions, then confirm important facts with a primary source or a qualified professional. The same Terms also set a minimum age of 13 and require parental permission for users under 18. Parents can review the controls in TechJournal’s guide to ChatGPT parental controls. For a comparison with another popular chatbot, see whether DeepSeek is safe.
Frequently Asked Questions
Is ChatGPT safe to use for free?
Yes, the free version of ChatGPT is safe for everyday tasks when you download it from OpenAI’s official site or app store listing. Free accounts can have conversations used for training by default, so turn off Improve the model for everyone under Settings > Data controls if you want to opt out.
Does ChatGPT keep your chats after you delete them?
No, ChatGPT removes a deleted chat from your account immediately, and OpenAI schedules it for permanent deletion within 30 days. OpenAI can keep a chat longer if it was already de-identified or if security or legal obligations require it.
Can other people see my ChatGPT conversations?
No, other ChatGPT users cannot see your conversations unless you create a shared link or someone gains access to your account. Anyone with a personal-account shared link can view that conversation, so manage links under Settings > Data controls > Shared links.
Is Temporary Chat in ChatGPT completely private?
No, Temporary Chat in ChatGPT is not completely private, although it stays out of your history, memory and model training. OpenAI may keep a copy for up to 30 days for safety purposes.
Should I turn off ChatGPT model training?
Yes, turn off ChatGPT model training if you do not want new conversations used to improve OpenAI’s models. The setting does not delete existing chats, and rating a response with thumbs up or thumbs down can still share that conversation for training.
