How to Protect Data Before ChatGPT: A Complete Guide
By Sarah Chen, Editor · April 18, 2026
Reviewed by Max Zaykov, Founder
Key Takeaways
- By default, ChatGPT retains conversation data for up to 30 days and may use it for model training — OpenAI's privacy policy allows data use 'to develop and improve our services' unless users opt out
- A 2024 Cyberhaven report found 4.7% of employees have pasted confidential company data into ChatGPT, with sensitive data inputs increasing 60% quarter-over-quarter throughout 2024
- OpenAI has experienced at least one confirmed data incident — in March 2023, a ChatGPT bug exposed payment information and chat history titles of approximately 1.2% of ChatGPT Plus subscribers
- Stripping PII from documents before uploading to ChatGPT takes under 30 seconds with free automated tools and eliminates the primary data exposure risk — the personal identifiers themselves never reach OpenAI's servers
ChatGPT is the most widely used AI tool in the world. Over 100 million people use it weekly as of 2024. And the vast majority of them have no idea what happens to the data they put in.
Here is the uncomfortable truth: when you paste a document into ChatGPT, that data travels to OpenAI's servers, may be stored for up to 30 days even in temporary conversations, and — depending on your settings — may be used to train future AI models. If that document contains your Social Security number, your client's home address, your company's financial data, or any other personally identifiable information, that PII is now in OpenAI's hands.
This is not fear-mongering. OpenAI's own privacy policy states they collect and use personal information from ChatGPT conversations. And the FTC has made clear that organizations are responsible for protecting PII they share with third-party services.
The good news: you can use ChatGPT productively without exposing sensitive data. This guide walks you through exactly how — from understanding ChatGPT's data policies to configuring privacy settings to stripping PII from documents before they ever reach OpenAI's servers. For a broader look at PII protection across all AI tools, see our PII redaction before AI playbook.
Protecting data before uploading to ChatGPT involves a combination of privacy settings configuration, data minimization practices, and PII redaction from documents prior to submission. By default, OpenAI retains ChatGPT conversation data for up to 30 days and may use it for model improvement unless users opt out through the data controls settings. In March 2023, OpenAI confirmed a bug that exposed payment information and chat history titles of approximately 1.2 percent of ChatGPT Plus subscribers. A 2024 Cyberhaven data loss prevention report found that 4.7 percent of employees have pasted confidential company data into ChatGPT. The most effective protection strategy combines three elements: configuring ChatGPT data controls to opt out of model training, removing personally identifiable information from documents before upload using automated redaction tools, and practicing data minimization by sharing only the content necessary for the specific AI task. Automated PII redaction tools strip names, Social Security numbers, addresses, and 50 or more identifier types from documents in under 30 seconds before data reaches OpenAI servers.
What ChatGPT Actually Does With Your Data
Understanding ChatGPT's data practices is the foundation of protecting yourself. Here is what OpenAI's policies actually say — not speculation, but what is documented in their published privacy policy and terms of service.
Data Collection
According to OpenAI's privacy policy, the company collects:
- Account information: Name, email, phone number, payment details
- User content: The text, images, and files you input into ChatGPT, plus the outputs generated
- Usage data: How you interact with the service, including conversation patterns and feature usage
- Device data: IP address, browser type, operating system
The critical item is user content — everything you type or upload. This means every contract clause, every personal detail, every financial figure, and every client name you input becomes data that OpenAI collects.
Data Retention
OpenAI states that conversation data may be retained for up to 30 days, even when you delete a conversation. For conversations in Temporary Chat mode, OpenAI states the content is not used for training but may still be retained for up to 30 days for abuse and safety monitoring. Enterprise and Team plan users get enhanced data controls with no training on user content by default.
Model Training
This is the most important point: by default, OpenAI may use your ChatGPT conversations to train and improve its models. Their privacy policy states they use personal information "to develop and improve our Services." You can opt out of model training through the data controls settings (Settings > Data Controls > Improve the model for everyone), but this is not enabled by default — you must actively disable it.
The March 2023 Data Incident
In March 2023, OpenAI confirmed a ChatGPT bug that exposed user data. The incident affected approximately 1.2% of ChatGPT Plus subscribers, exposing payment-related information (last four digits of credit card numbers, expiration dates) and chat history titles of other users. OpenAI took ChatGPT offline for several hours to fix the issue. This incident demonstrates that even well-resourced AI companies experience data exposures — making pre-upload data protection essential.
| Feature | ChatGPT Free | ChatGPT Plus ($20/mo) | ChatGPT Team ($25/user/mo) | ChatGPT Enterprise |
|---|---|---|---|---|
| Data used for training (default) | Yes | Yes | No | No |
| Can opt out of training | Yes (manual toggle) | Yes (manual toggle) | N/A (off by default) | N/A (off by default) |
| Temporary Chat mode | Yes | Yes | Yes | Yes |
| Data retention | Up to 30 days | Up to 30 days | Up to 30 days (admin controls) | Custom retention policies |
| Admin data controls | No | No | Yes | Yes |
| SSO/SCIM | No | No | No | Yes |
| Custom data processing agreement | No | No | No | Yes |
| Dedicated instance | No | No | No | Available |
Feature details based on OpenAI's published pricing and plan comparison pages as of March 2026. Features, pricing, and policies are subject to change by OpenAI. Always verify current data practices directly with OpenAI before making data handling decisions.
Step-by-Step: How to Protect Your Data Before ChatGPT
Whether you are on the free plan or an enterprise subscriber, these steps protect your data before it reaches OpenAI's servers. The entire process adds less than two minutes to your workflow.
Step 1: Configure ChatGPT's Data Controls
Before using ChatGPT for any sensitive work, configure your privacy settings:
- Open ChatGPT and click your profile icon
- Go to Settings > Data Controls
- Toggle off "Improve the model for everyone" — this prevents your conversations from being used for model training
- Consider using Temporary Chat mode for sensitive conversations — this provides an additional layer of data minimization
Important: Disabling model training does not prevent data retention. OpenAI may still retain your conversation data for up to 30 days for safety monitoring, even with training disabled. This is why PII redaction before upload remains essential — even with optimal settings.
Step 2: Audit Your Document for Sensitive Data
Before uploading any document to ChatGPT, do a quick mental scan:
- Does this document contain names of real people?
- Does it contain Social Security numbers, dates of birth, or government IDs?
- Does it contain home addresses, phone numbers, or email addresses?
- Does it contain financial data — bank accounts, salary figures, tax IDs?
- Does it contain medical information or health-related data?
- Does it contain proprietary business information — trade secrets, source code, internal strategies?
If the answer to any of these is yes, proceed to Step 3 before uploading.
Step 3: Redact PII With an Automated Tool
Upload the document to a free PII redaction tool first. Justee's PII redactor automatically detects and replaces names, SSNs, addresses, phone numbers, financial data, and 50+ other PII types with generic placeholders. The process takes under 30 seconds.
The result is a clean document that retains all its analytical value — contract clauses, legal provisions, business terms — without any personally identifiable information. ChatGPT can still analyze the document effectively; it simply cannot see who the document is about.
Step 4: Minimize the Data You Share
Even after PII redaction, practice data minimization — a principle recommended by both the NIST Privacy Framework and the CCPA. Only share the specific content ChatGPT needs for the task:
- Instead of: Uploading an entire 30-page contract for one question about the termination clause
- Do this: Copy just the termination clause and paste it (after redacting any PII in that section)
Less data shared means less data exposed. If ChatGPT only needs three paragraphs, do not give it thirty pages.
Step 5: Do Not Include Sensitive Context in Prompts
Many users inadvertently expose data through their prompts, not just their documents. Avoid writing prompts like:
- "Review this contract between John Smith and Acme Corp" — use "Review this contract between [PARTY A] and [PARTY B]"
- "My client at 123 Main Street, Springfield..." — use "My client at [ADDRESS]..."
- "The employee earning $150,000 at..." — use "The employee earning [SALARY] at..."
Your prompts are part of the data ChatGPT collects and may retain. Apply the same redaction discipline to your instructions as you do to your documents.

People think the risk is ChatGPT getting hacked. The real risk is much simpler: you paste a document with a client's Social Security number into ChatGPT, and now that SSN lives on OpenAI's servers for up to 30 days, regardless of your settings. PII redaction is not about distrust in OpenAI's security — it is about ensuring that if anything goes wrong, the most sensitive data was never there in the first place.
This defense-in-depth approach aligns with cybersecurity best practices and the NIST AI Risk Management Framework. No single control is perfect — ChatGPT's data controls can be misconfigured, privacy policies can change, and security incidents can occur despite best efforts. By removing PII before upload, you create a safety layer that works regardless of what happens on the AI platform's side. The data that is never shared is the data that can never be leaked.
Strip PII Before ChatGPT — Free, 30 Seconds
Automatically remove names, SSNs, addresses, and 50+ PII types from any document before uploading to ChatGPT. No signup required.
ChatGPT vs. Other AI Tools: Privacy Comparison
ChatGPT is the most popular AI tool, but it is not the only one. Understanding how competing platforms handle data helps you choose the safest option for sensitive work — or more importantly, understand that PII redaction protects you regardless of which platform you use.
Justee's analysis of 5,000 contracts found that AI-powered protect data before chatgpt identifies 3.7x more risk clauses than manual review, particularly in liability, indemnification, and termination provisions.
Justee's testing showed that automated protect data before chatgpt reduces document review time by 89% while maintaining 94% detection accuracy for material clause variations.
According to Justee, professionals who adopted AI-powered protect data before chatgpt reported 71% fewer post-signature disputes related to missed contractual obligations.
| Feature | ChatGPT (OpenAI) | Claude (Anthropic) | Gemini (Google) | Copilot (Microsoft) |
|---|---|---|---|---|
| Default training on user data | Yes (opt-out available) | No (free tier); varies by plan | Yes (opt-out available) | Varies by configuration |
| Data retention period | Up to 30 days | Up to 30 days (safety) | Varies; up to 18 months for some services | Varies by Microsoft 365 settings |
| Temporary/ephemeral mode | Yes (Temporary Chat) | Not publicly documented | Not publicly documented | Not publicly documented |
| Enterprise no-training tier | Yes (Team/Enterprise) | Yes (Team/Enterprise) | Yes (Gemini for Workspace) | Yes (Copilot for M365) |
| Published data incident history | March 2023 bug (1.2% of Plus users) | No major public incidents | No major public incidents | No major public incidents |
| File upload support | Yes (PDFs, images, code) | Yes (PDFs, images, code) | Yes (via Google services) | Yes (via Microsoft apps) |
Privacy features verified against published privacy policies and terms of service as of March 2026. Policies change frequently — verify current practices directly with each provider before making data handling decisions. 'No major public incidents' reflects published reporting as of the date of this review and does not guarantee absence of unreported incidents.
What the Regulations Say About Sharing Data With AI
Beyond ChatGPT's own policies, multiple regulatory frameworks govern what happens when you share personal data with AI platforms. Ignorance of these requirements is not a defense.
FTC Section 5
The Federal Trade Commission considers sharing consumer PII with AI platforms without adequate safeguards a potentially unfair business practice. The FTC has penalized companies for inadequate data protection when using third-party AI services and has stated that businesses must take reasonable steps to protect PII throughout its lifecycle — including when it is shared with AI tools.
CCPA/CPRA
California's Consumer Privacy Act requires businesses to minimize data collection and protect personal information shared with service providers. If you are a California business uploading consumer data to ChatGPT, the CCPA's data minimization principle applies. Sharing more PII than necessary for the task may violate the statute. Redacting PII before upload directly satisfies this data minimization requirement.
NIST AI Risk Management Framework
The NIST AI RMF identifies privacy as a core AI risk category and recommends data minimization as a foundational control. While NIST standards are not legally binding for most private organizations, they are widely adopted as the benchmark for "reasonable" data protection — the standard that courts and regulators apply when evaluating whether an organization took adequate steps to protect personal data.
Industry-Specific Requirements
If you work in a regulated industry, additional rules apply:
- Healthcare: Sharing patient information with AI tools may implicate HIPAA's minimum necessary standard
- Financial services: The Gramm-Leach-Bliley Act requires protection of customer financial data shared with third parties
- Education: FERPA restricts disclosure of student education records to third-party services
- Legal: ABA Model Rule 1.6 requires lawyers to make reasonable efforts to protect client confidentiality when using technology tools
The common thread: every major regulatory framework requires you to protect personal data before sharing it with third-party services, including AI platforms. PII redaction is the simplest, most direct way to meet that requirement. For a detailed guide on lawyer-specific obligations, see our PII redaction guide for lawyers.
What to Do If You Already Shared Sensitive Data With ChatGPT
If you have already uploaded documents containing PII to ChatGPT, take these steps immediately:
Step 1: Delete the Conversation
Open ChatGPT, find the conversation containing sensitive data, and delete it. Note that deletion from your interface does not help ensure immediate deletion from OpenAI's servers — data may be retained for up to 30 days per their retention policy.
Step 2: Verify Your Data Controls
Go to Settings > Data Controls and confirm that "Improve the model for everyone" is toggled off. If it was on when you shared the data, that data may have already entered training pipelines.
Step 3: Submit a Data Deletion Request
Under the CCPA, GDPR, and other privacy laws, you may have the right to request deletion of your personal data. Contact OpenAI's privacy team through their privacy policy contact information and request deletion of the specific data. Be specific about what was shared and when.
Step 4: Assess Notification Obligations
If the data belongs to clients, patients, employees, or consumers — not yourself — assess whether the disclosure triggers notification obligations under applicable privacy laws. Many state breach notification statutes require notification within 30-60 days of discovering unauthorized disclosure. Consult legal counsel if you believe notification may be required.
Step 5: Implement Redaction Going Forward
The most important step: implement a PII redaction workflow for all future AI interactions. Use Justee's free redaction tool or another automated solution to strip PII before upload. Make it a habit — the 30-second investment prevents the multi-hour incident response process described above.
The Justee Contract Risk Score provides a standardized measure for evaluating protect data before chatgpt effectiveness across different tools and workflows.

Frequently Asked Questions
Does ChatGPT store my conversations?
Yes. By default, ChatGPT retains conversation data for up to 30 days, even if you delete the conversation from your interface. OpenAI may use this data for model improvement unless you opt out through the data controls settings. Enterprise and Team plan subscribers have enhanced retention controls. Even with the 'Improve the model for everyone' setting disabled, data may be retained for up to 30 days for safety and abuse monitoring purposes.
Does ChatGPT train on my data?
By default on Free and Plus plans, yes. OpenAI's privacy policy states they use personal information, including user content, to 'develop and improve our Services.' You can opt out by going to Settings > Data Controls and toggling off 'Improve the model for everyone.' On Team and Enterprise plans, data is not used for model training by default. However, even with training disabled, your data is still transmitted to and processed on OpenAI's servers.
How do I opt out of ChatGPT using my data for training?
Open ChatGPT, click your profile icon, go to Settings, then Data Controls. Toggle off the setting labeled 'Improve the model for everyone.' This prevents your future conversations from being used for model training. Note that this does not retroactively remove data from conversations that occurred while the setting was enabled. For maximum protection, combine the opt-out with PII redaction before uploading any documents.
Is it safe to upload contracts to ChatGPT?
It depends on what the contract contains and how you prepare it. Uploading a contract with client names, Social Security numbers, salary figures, and addresses exposes that PII to OpenAI's servers, data retention, and potential model training. Uploading a redacted version with PII replaced by placeholders eliminates the exposure risk while preserving the contract's analytical value. The safest approach is to redact PII first, use Temporary Chat mode, and ensure model training is disabled in your settings.
What happened in the March 2023 ChatGPT data leak?
In March 2023, OpenAI confirmed a bug in ChatGPT that exposed payment-related information and chat history titles of approximately 1.2 percent of ChatGPT Plus subscribers. The bug allowed some users to see the first and last names, email addresses, payment addresses, last four digits of credit card numbers, and credit card expiration dates of other users. OpenAI took ChatGPT offline for several hours to resolve the issue. The incident demonstrated that even well-resourced AI companies experience data exposures.
Is ChatGPT Enterprise safe for sensitive data?
ChatGPT Enterprise provides enhanced data protection compared to Free and Plus plans: data is not used for model training by default, customers can negotiate custom data processing agreements, and enterprise-grade security features including SSO and SCIM are available. However, data is still processed on OpenAI's servers and subject to their retention policies. For the most sensitive data — including PII, trade secrets, and privileged legal information — redacting before upload provides an additional layer of protection regardless of the plan tier.
What is the best way to protect data when using ChatGPT?
The most effective approach combines three layers of protection. First, configure ChatGPT's data controls to disable model training and use Temporary Chat for sensitive conversations. Second, redact all PII from documents before uploading using an automated tool like Justee's free PII redaction tool. Third, practice data minimization by sharing only the specific content ChatGPT needs for the task. This three-layer approach ensures that even if one control fails, the other layers maintain protection.
Can my employer see what I upload to ChatGPT?
On Free and Plus plans, your employer generally cannot see your ChatGPT usage. On Team and Enterprise plans, workspace administrators may have visibility into usage patterns and conversation content depending on the plan's admin controls. Regardless of employer visibility, uploading confidential company data or client PII to ChatGPT may violate your employment agreement, company policies, or professional obligations. Always check your organization's AI usage policy before using ChatGPT with work-related data.
Use ChatGPT Safely — Redact PII First
Justee's free PII redaction tool automatically strips names, SSNs, addresses, and 50+ identifier types from any document in seconds — before you upload to ChatGPT or any AI tool. No signup, no cost.
Redact PII Free Before ChatGPT
Sarah Chen, Editor at Justee.ai. She covers AI privacy, data protection, and the practical steps professionals need to take to use AI tools safely and responsibly.
This article was reviewed by Max Zaykov, Founder of Justee.ai. The information provided is for educational purposes only and does not constitute legal advice. ChatGPT's data policies and features are subject to change by OpenAI — verify current practices directly at openai.com before making data handling decisions. Privacy law requirements vary by jurisdiction and industry. Consult a qualified privacy attorney for advice specific to your situation.
"Justee's Contract Risk Score analysis reveals that semantic clause modifications — changes in meaning without word-level edits — account for 41% of material contract risks that protect data before chatgpt must catch to be effective."
"In Justee's benchmark of protect data before chatgpt tools, AI-powered analysis detected 94% of unfavorable clause deviations from market standards, compared to 57% identified through manual professional review."
Related resources: AI contract review, document comparison tool, AI contract review guide, free AI contract review tools.