ChatGPT Data Privacy for Business
ChatGPT Privacy, in Plain English: What Really Happens to What You Paste
ChatGPT privacy, in one paragraph: on free and personal plans, what you type may be used to improve the service unless you turn that setting off; on business plans and the API, your content is not used for training by default. Either way, treat anything you paste as shared with an outside vendor—because it is.
1-on-1 with Pete Enestrom, on your actual work

Written by Pete Enestrom
Yale & Columbia, ex-Microsoft & Intel — 1-on-1 AI coaching for executives

Your coach’s background
Most of what you will find online about ChatGPT privacy is written for consumers—people worried about their personal messages and their search history. This page is for a different reader: the owner of a company whose employees are pasting real business material into ChatGPT every day. ChatGPT data privacy for a business is a different question with different stakes: client confidentiality, employee accounts you do not control, and settings most people never open.
Everything below is plain English, and deliberately generic about the legal side—I am a coach, not a lawyer, and OpenAI's terms change often enough that any exact clause I quoted would be stale within months. What does not change is the logic: who can see what you paste, which settings control it, and what rules make the risk manageable. That is what this page gives you, ending with a short checklist you can act on today.
What actually happens to what you paste into ChatGPT?
On ChatGPT's free and personal paid plans, the default arrangement is simple: what you type may be used to improve the service. In practice, that means your conversations are processed by automated systems, may be reviewed by people in limited cases such as safety checks, and may be used to train future versions of the model unless you change the setting. OpenAI's help article on how your data is used confirms this default. OpenAI provides controls for this: a data-controls setting that turns training off, temporary chats that are not saved to your history or used for training, and the ability to delete old conversations. Deleting a conversation removes it from your view and schedules it for removal from OpenAI's systems, typically within about thirty days. Two things are worth holding onto. Turning training off applies going forward; it does not reach back into conversations already used. And no setting turns a consumer product into a vault.
ChatGPT's business plans—the team and enterprise tiers—and OpenAI's API work under a different default: customer content is not used to train the models (see OpenAI's enterprise privacy page). Conversations live inside a workspace that belongs to the company, so an employee who leaves can be removed and the company's chats stay with the company. The same consumer-versus-business split exists at Anthropic and Google: consumer tools are allowed to learn from the data they receive, while business tools charge money instead. Two cautions keep this honest. Terms change, so verify the current data-use policy before you rely on it. And “not used for training” is not the same as “nothing to think about”—a business plan changes the vendor's rights, not your employees' habits. In my experience coaching owners, the privacy incidents that actually happen are not the vendor misusing data; they are an employee pasting the wrong thing in the first place.
What are the real ChatGPT privacy concerns for a business?
When owners ask me about ChatGPT privacy concerns, they usually picture a hacker or a headline about a leak. The actual exposure is more ordinary and more controllable. These are the four risks I walk through with every client, in the order they tend to matter.
Confidential client data
- An employee pastes a client contract, a customer's details, or unpublished financials into a personal ChatGPT account to save an hour.
- The vendor's terms now govern that material, and your client never agreed to that.
- This is the risk that ends client relationships, and it happens with good intentions.
Employee shadow use
- Team members use ChatGPT on personal phones and personal accounts, outside any rule, because nobody has given them one.
- The company has no visibility into what is pasted and no way to turn access off when someone leaves.
- Banning drives the behavior further underground; a clear rule brings it into the open.
Training-data settings
- On consumer plans, pasted content may be used to improve the model unless someone changes the setting.
- Most employees have never opened the settings menu, so the default decides for them.
- A business-tier workspace removes this question by default.
Retention
- Deleted chats are scheduled for removal—often about thirty days—but retention terms change and legal obligations can extend them.
- Deleting history is tidying up, not a compliance strategy.
- The only reliable control is deciding what may be pasted before anything is pasted.
Which ChatGPT privacy settings should you check today?
Fifteen minutes, no IT department required. Menus get renamed from time to time, so hunt a little if a label has moved—the settings below all exist in some form. This is general information, not legal advice; if your company operates in a regulated industry, have counsel confirm your setup.
- Know which plan you are actually on. A personal Plus account and a business workspace look identical in the chat window but carry different data terms. Check the plan name in your account settings before anything else.
- On a personal plan, open Settings, then Data Controls, and turn off “Improve the model for everyone”—the training toggle. The change applies to future conversations; it does not unwind past ones.
- Use Temporary Chat for anything borderline. Temporary chats are not saved to your history and are not used for training; they are kept briefly for safety and then removed.
- Review the Memory setting. ChatGPT can remember details across conversations; decide whether that convenience is worth it for work use, and clear stored memories you do not want kept.
- Delete old conversations that contain sensitive material—while remembering that deletion schedules the data for removal rather than erasing it instantly.
- Check Shared Links. A shared chat link is a public page: anyone with the link can read the conversation. Review your existing shared links and delete any you would not hand to a stranger.
- Move company work to company accounts. If your employees are on personal accounts, that move is the real fix—not another setting.
What rules of thumb can you hand your team this week?
Settings are the backstop; habits are the front line. The owners I coach get more protection from five plain sentences, repeated until they are boring, than from any configuration screen. Here are the rules of thumb I suggest handing to your team this week. They require no technical knowledge, they survive every terms-of-service update OpenAI will ever ship, and they work identically for Claude, Gemini, and whatever arrives next year.
- Treat everything you paste as shared with an outside vendor—because contractually, it is.
- If you would not email it to a contractor, do not paste it into a personal AI account.
- Keep the names and numbers out; ask the structural question instead. “A client in logistics with a mid-seven-figure contract” gets you the same advice as the real name.
- Company work goes through the company account. Personal accounts are for personal questions, full stop.
- AI output is a draft that a person checks. Your name is on whatever leaves the building.
- Unsure? Ask before you paste. The question costs a minute; the mistake does not.
When do you need a written AI policy?
Rules of thumb are a start; a written policy is the moment the rules become official. Your company has crossed the line into needing one when any of these are true: client contracts or NDAs restrict how you handle client information; your business touches regulated data—health records, financial data, personal data at scale; more than a handful of employees use AI tools every week; or you have already had the small scare, the paste you wish someone had not made, and you caught it only by luck. A written AI policy does not need to be long. The version I give owners is one page: an approved-tools list, a never-paste list, a disclosure rule, and a named owner with a review date.
That one-page policy is published on this site as a template you can copy clause by clause: my AI usage policy template walks through what each clause does and how to roll it out in one thirty-minute meeting. And when the policy raises the harder question—how does our team get genuinely good at these tools, inside the guardrails, on our real workload—that is the work I do with owners in 1-on-1 coaching: a human teacher, not an AI coach bot. Clear rules keep your information where it belongs; training turns the tools into hours back.
1-on-1 coaching
Get the guardrails—and the training—right.
A policy nobody understands protects no one. We'll set the rules and teach your people to work well inside them.

Your coach
Coached by Pete Enestrom
Yale and Columbia grad, former Microsoft and Intel, and a venture-backed exited founder. Pete has spent the last four and a half years going deep on every major AI tool, and he teaches the way operators learn: on your real work, at your pace, with nothing assumed.

Common questions
Straight answers, the way I'd give them across a table.
Keep reading
Resource
AI Use Policy: A Practical Template Your Team Will Actually Follow
A plain-English AI usage policy template for business owners: what a policy should cover, ten copy-ready clauses, and how to roll it out in one team meeting.
ReadGuide
How to Use Claude: A Practical Guide for Busy Executives
A plain-English guide to Claude for founders and executives: what it is, how to start in ten minutes, and five real workflows with copy-paste prompts.
ReadGuide
ChatGPT for Work: A Practical Guide for Non-Technical Executives
How non-technical executives use ChatGPT at work: drafting, summarizing, brainstorming, notes into action lists, and meeting prep—with six copy-paste prompts.
ReadBeyond coaching
When the workflow needs to be encoded, not just learned — that's what our team at Zaigo builds.