
ChatGPT Privacy: What Actually Happens to Your Data, and What You Can Do About It
Most people using ChatGPT have never opened a privacy setting. That is the core problem with ChatGPT privacy in 2026: the defaults are not on your side, the protections differ wildly depending on what you pay, and a federal court once overrode the delete button entirely. This piece breaks down the current state of things with specifics, not vibes.
Key Takeaways
- Free-tier ChatGPT users have their conversations used for model training by default, and most never change this. Paid business tiers get contractual protections that consumer accounts do not.
- Privacy in ChatGPT is now a two-tier system: free users get marketing cookies turned on by default and ads in the interface, while paying subscribers are exempt.
- A 2025 federal court order forced retention of deleted chats for months, proving that "delete" in a cloud AI product is only as permanent as the legal environment allows.
- Agent-mode browsing retains data, including browser screenshots, for 90 days, a significant expansion of the data surface compared to standard chat.
- The only reliable privacy control is minimizing what data reaches a cloud provider in the first place. Settings toggles are a second line of defense, not a first one.
What Does ChatGPT Do With Your Conversations by Default?
It trains on them. On Free, Plus, and Pro plans, data sharing and model training on conversations are enabled by default, and the vast majority of users never toggle this off. Your prompts, the content you paste in, the questions you ask: all of it feeds future model iterations unless you explicitly opt out in settings.
Enterprise and Team plans are structurally different. Those accounts operate under contractual data-processing agreements that bar training on organizational data. The distinction matters. A toggle in your personal account settings is a preference. A contractual DPA is a legal obligation. If you are on a consumer plan, you have the former. No amount of toggling gives you the latter.
Business-tier plans also provide encryption at rest and admin-controlled retention windows, which are absent from consumer accounts. So the privacy posture of "ChatGPT" depends entirely on which ChatGPT you are using.
How Did Privacy Become a Paid Feature?
It happened gradually, then all at once. The pattern crystallized in early 2026 when OpenAI rolled out an advertising pilot alongside a privacy policy update effective February 9, 2026. Free and lower-tier users started seeing ads. Paid subscribers did not.
Then on April 30, 2026, OpenAI updated its US privacy policy to turn marketing cookies on by default for free-tier users, opt-out only. Plus and Enterprise subscribers were exempt. This created a formal two-tier privacy system: if you pay, your browsing behavior inside ChatGPT is not tracked for ad targeting. If you do not pay, it is, unless you find and flip the switch.
The economics are straightforward. With 800 million weekly users (most non-paying) and roughly $9 billion a year in operating costs, the company needed a revenue source beyond subscriptions. Ads were that source. And ads require data. The privacy policy update disclosed that OpenAI receives purchase data from advertisers and shares cookie and device identifiers with marketing partners, though advertisers do not get access to conversation content, chat history, or memories.
An April 2026 policy revision went further, loosening ad placement restrictions so that medical, legal, and financial advice contexts were no longer categorically blocked from ads. If you ask a free-tier ChatGPT about a medication interaction, an ad can now appear alongside the answer.
None of this is hidden. It is all in the privacy policy. But the defaults do the heavy lifting, and most users run on defaults.
What Happened With the Court-Ordered Data Retention?
This is the part most "ChatGPT privacy" guides skip, and it is arguably the most important.
In the New York Times v. OpenAI copyright lawsuit, a federal court issued a preservation order requiring OpenAI to retain "output log data," including deleted and temporary chats, that would otherwise have been erased. The order was in effect from roughly April through September 2025. During that window, if you deleted a conversation, OpenAI was legally required to keep it anyway.
The order was lifted in late September 2025 and normal deletion resumed, but logs from that five-month period remain in secure storage pending the litigation. Enterprise, Edu, and zero-data-retention business customers were excluded from the preservation requirement, and the order did not change the default policy of not training on business data.
The practical lesson here is not about one lawsuit. It is structural. Any cloud AI vendor can be subject to a discovery order in litigation they are party to, and that order can override whatever deletion policy they advertise. Your "delete" button is a software feature. A court order is a legal instrument. The legal instrument wins.
This makes "who can be legally compelled to retain your data" a due-diligence question for any organization evaluating an AI vendor. If the vendor holds your data in a centralized store, litigation involving that vendor (not involving you at all) can freeze your data in place. The only architectural defense is to minimize what the vendor holds.
Does ChatGPT's Agent Mode Change the Privacy Picture?
Yes, significantly. The agent browsing mode retains data, including browser screenshots, for 90 days, which is far longer than standard chat retention. When the model is browsing the web on your behalf, it is capturing visual snapshots of pages it visits, and those snapshots persist for three months.
This is a qualitatively different data surface than a text conversation. A screenshot can contain login states, personal dashboards, email previews, financial data visible on a banking page. The agent is acting with your context, visiting pages you directed it to, and the artifacts of that browsing stick around.
Most users do not know this. The 90-day retention is documented, but it is not surfaced at the moment you invoke agent mode. You would need to have read the data privacy documentation to know your browsing screenshots are retained.
Has ChatGPT Had Actual Data Exposure Incidents?
Yes. In July 2025, a glitch caused thousands of shared ChatGPT conversation links to be indexed by Google, making private chats publicly searchable. The conversations were ones users had shared via link, but the indexing was unintentional, meaning content users expected to be semi-private (shared with a specific person via link, not published to the internet) ended up in search results.
This is a useful reminder that "shared via link" and "private" are not the same thing, and that the boundary between them can fail in ways the platform did not intend.
What Do the Privacy Settings Actually Control?
Less than you might expect. On consumer plans, you can toggle off data sharing for model training. This is worth doing. But several things remain true even with that toggle off:
- Your conversations still transit to and are processed on cloud infrastructure. The toggle controls training use, not data transmission.
- On consumer accounts, there is no contractual DPA regardless of your settings. The toggle is a policy choice by the provider, revocable via a privacy policy update.
- Agent-mode screenshot retention applies independently.
- If a court orders data preservation, the toggle does not override the order.
- Marketing cookies on free tier are a separate toggle from training-data opt-out. You need to find and disable both.
The settings are better than nothing. They are not a privacy architecture. They are a preference layer on top of someone else's architecture.
Why Is Pre-Prompt Data Minimization the Real Control Point?
Because no setting, toggle, or policy can un-transmit data that has already been sent to a cloud endpoint. Once your prompt hits the server, you are relying on the provider's policies, their legal environment, and their operational security to protect it. All three of those can change without your consent.
The court preservation order is the clearest illustration. Users who deleted chats during the April to September 2025 window believed their data was gone. It was not. The provider's deletion policy was overridden by external legal force.
The 90-day screenshot retention in agent mode is another illustration. Users who invoke agent browsing may not realize they are creating a 90-day visual record of their web activity stored on someone else's servers.
The advertising data-sharing policy is a third. Users who never changed their cookie settings are now having device identifiers shared with marketing partners.
In each case, the effective privacy boundary was determined after the data was transmitted, by someone other than the user. The only point where the user has unilateral control is before the prompt is sent. What you do not send cannot be retained, cannot be court-ordered, cannot be shared with ad partners.
This is why data minimization before the prompt matters more than any settings page. Strip identifying information, financial details, client names, internal project codes. If the data is not in the prompt, it is not in the system. OpenAI itself acknowledged this dynamic by releasing an open-weight on-device "Privacy Filter" model in April 2026 designed to let organizations strip personal data from text before it reaches their cloud service. The vendor is telling you: clean your data before you send it to us.
What Should Businesses Evaluate When Choosing an AI Provider?
Most vendor evaluations focus on capability benchmarks and pricing. Privacy due diligence should be equally rigorous, and it should go beyond reading the privacy policy. Concrete questions worth asking:
- Contractual vs. toggle-based protections. Is the no-training commitment in a binding DPA, or is it a user setting that can be changed via a policy update?
- Litigation exposure. If the vendor is party to a lawsuit, can a court compel retention of your organization's data? What architectural choices (data residency, retention minimization, encryption) reduce that exposure?
- Retention windows. What is retained, for how long, and does retention differ by feature (e.g., agent mode vs. standard chat)?
- Ad data flows. Does the vendor share device identifiers, cookies, or behavioral signals with advertising partners? Is this tier-dependent?
- Data minimization tooling. Does the vendor provide tools for PII stripping before data reaches their infrastructure? Is this on-device or cloud-based?
These are not hypothetical concerns. Every one of them has a concrete 2025 or 2026 precedent in the ChatGPT ecosystem.
How Does This Affect Individual Users?
If you use ChatGPT on a free or consumer-paid plan, here is the minimum set of actions worth taking:
- Go to Settings > Data Controls and turn off "Improve the model for everyone." This opts you out of training data contribution. It does not do anything else.
- Check your cookie preferences separately. Since April 2026, marketing cookies are on by default for free-tier users. You need to opt out explicitly.
- Audit your shared links. If you have ever shared a conversation via link, assume it could be indexed. Revoke links you no longer need active.
- Be deliberate about agent mode. If you use the browsing agent, know that screenshots of the pages it visits are retained for 90 days. Do not point it at pages containing sensitive information you would not want stored.
- Minimize what you put in prompts. Do not paste full contracts, employee records, medical information, or client-identifiable data into a consumer AI account. Redact before you send.
None of this is paranoid. It is just reading the policies and acting accordingly.
What Does a Privacy-First Architecture Actually Look Like?
The phrase gets thrown around loosely. Here is what we think it means concretely, because we built Selina around it.
Content is encrypted at rest. Files and transfers (via SelinaSEND) are zero-knowledge encrypted. Memory is encrypted at rest but is not end-to-end encrypted, because a slice of each request reaches a frontier provider at inference. Non-content operational metadata is kept for a short retention window, not indefinitely. The account is protected, not treated as a data asset. Delete means gone. Actually gone.
We route requests through a stack of frontier models, selected per task. We are not running a local-only model, and we are not claiming to be. The point is that the architecture is designed so that what reaches the provider is minimized, what is stored is encrypted, and what is deleted is not recoverable. The user controls the data lifecycle, not us, and not a court order in a lawsuit we are party to.
This is not a solved problem. It is a set of architectural choices that shift the default from "retain everything, let the user opt out" to "retain the minimum, encrypt the rest." The difference shows up when defaults are tested by legal orders, policy changes, or ad revenue pressure.
Where Is This Headed?
The EU AI Act is now imposing strict transparency obligations on general-purpose AI, adding regulatory pressure on top of GDPR and CCPA. As AI products shift from passive chatbots to active agents that browse, execute code, and interact with external services, the data surface expands. Every new capability is a new retention question, a new legal exposure, a new potential ad signal.
The trajectory is clear. AI products will collect more data as they become more capable, and the business model for free tiers will increasingly rely on monetizing that data through advertising. Privacy will continue to stratify by price tier unless architectural alternatives exist.
The question for users and organizations is not "is ChatGPT private?" in the abstract. It is: what are the defaults, what are the contractual commitments, what survives a court order, and what data never needed to be sent in the first place? Those four questions, asked of any AI vendor, will tell you more than any privacy policy summary.
If the architecture interests you: start a free 7-day trial, no card required.
Frequently Asked Questions
Does ChatGPT use my conversations to train its models?
Yes, on Free, Plus, and Pro plans, data sharing and model training are enabled by default, and most users never opt out. Enterprise and Team plans are excluded from training under contractual data-processing agreements.
Why do free ChatGPT users see ads while paid subscribers don't?
OpenAI rolled out an advertising pilot and privacy policy update in early 2026, and as of April 30, 2026, it turned on marketing cookies by default for free-tier users while exempting Plus and Enterprise subscribers. This created a two-tier system where paying users avoid ad tracking but free users must manually opt out.
Can OpenAI really keep my data even after I delete it?
Yes, this happened during the New York Times v. OpenAI lawsuit, when a federal court ordered OpenAI to retain deleted and temporary chat data from roughly April to September 2025 for litigation purposes. The order was lifted in late September 2025, but logs from that period remain in secure storage pending the case, showing that legal orders can override deletion policies.
Is ChatGPT's agent mode more risky for privacy than regular chat?
Yes, agent mode retains data including browser screenshots for 90 days, far longer than standard chat retention. These screenshots can capture sensitive visual information like login states or financial data visible on pages the agent browses, and this retention isn't disclosed at the moment you use the feature.
What can I actually do to protect my privacy on ChatGPT?
You can toggle off data sharing for model training and disable marketing cookies in settings, though these are separate toggles you need to find individually. However, since settings don't stop data transmission to cloud servers, prevent court-ordered retention, or apply to agent-mode screenshots, the most reliable control is minimizing what data you send to the platform in the first place.
Sources & References
- ChatGPT and Privacy: Everything You Need to Know in 2026
- Is ChatGPT private? A 2026 guide to your data privacy and security
- ChatGPT Data Privacy - DataNorth AI
- Is ChatGPT safe? The complete 2026 security & privacy guide
- OpenAI's Privacy Policy Update and ChatGPT Ads Expansion: The Complete 2026 Guide for Users, Marketers, and Businesses | ALM Corp
- I Asked ChatGPT About Data Privacy in 2026 — Here’s What It Revealed
- ChatGPT Privacy Settings: The Complete 2026 Guide | Predact Blog
- In ChatGPT Case, Order to Retain All Chats Threatens User Privacy - Center for Democracy and Technology
- OpenAI Court Order Forces Indefinite ChatGPT Data Retention
- ChatGPT promised to forget user conversations. A federal court ended that.
- How we’re responding to The New York Times’ data demands in order to protect user privacy | OpenAI
- ChatGPT Data Retention Policy Including the Court Order
- Court-Ordered Data Retention: OpenAI’s ChatGPT Chat Log Preservation And The Privacy Dilemma | Richt Law Firm
- ChatGPT Logs Retained Indefinitely: An Ethical Firestorm
- crazy overreach openais sam altman blasts nyts request to store chatgpt records says privacy is really important
- techpolicylab.uw.edu
- chatgpt plugin sdk keywords search volume
- ai keyword traffic volume
- online searches ai artificial intelligence united states
- pride month keyword traffic volume
- developers.google.com
- developers.google.com
- ahrefs.com
- anzahl der keywords pro suchanfrage
- The conference for marketers ready to win in 2026
- OpenAI Updates Privacy Policy to Formalize Ad Data Sharing in ChatGPT
- Ad policies | OpenAI
- Ads in ChatGPT | OpenAI Help Center
- US privacy policy | OpenAI
- OpenAI updates privacy policy as ads expand in ChatGPT
- OpenAI’s ChatGPT Privacy Policy Update: What It Means for Users, Ads,
- ChatGPT Is Showing Ads Now: What Every Free User Needs to Know | TechSifted
- ChatGPT to show ads for free and Go users in the US
