
Is ChatGPT Safe? A Technical Founder's Honest Assessment
If you're asking "is ChatGPT safe," the short answer is: safe enough for casual use, not safe enough for anything you'd rather keep private. The longer answer involves deleted chats that aren't actually deleted, a DNS exfiltration bug that allowed silent data leakage, court orders that override your privacy settings, and an expanding attack surface as the product evolves from chatbot to autonomous agent. I've spent the better part of two years building a privacy-first AI assistant, so I have opinions here. They're grounded in specifics.
Key Takeaways
- ChatGPT is generally safe for everyday, non-sensitive queries. It is not safe for confidential information: conversations are retained by default, not end-to-end encrypted, and accessible to staff and third-party vendors.
- The "delete" button is a UI element, not a privacy guarantee. Deleted chats persist for up to 30 days, longer under legal holds, and a federal court has already ordered indefinite retention of chat logs in active litigation.
- A patched-but-real vulnerability in early 2026 demonstrated that conversation data could be exfiltrated via a hidden DNS side channel, bypassing safety guardrails entirely. The attack surface is growing as agentic features (browsing, screenshots, code execution) ship faster than trust models mature.
- Enterprise and Team tiers offer meaningfully better privacy postures than consumer tiers, but most employees default to personal accounts, creating a "shadow AI" governance gap that the EU AI Act (enforceable August 2, 2026) will penalize heavily.
- Policy-based privacy (opt-outs, toggles, terms of service) is structurally fragile. Architectural privacy, where sensitive data never reaches a server in a retainable form, is the more durable answer.
What Data Does ChatGPT Actually Collect?
More than most users expect. By default, OpenAI retains conversation history and uses inputs to train future models. That includes the full text of your prompts and the model's responses. It also includes metadata: timestamps, device information, IP addresses, usage patterns. You can toggle off "Chat History & Training" in settings, which stops your conversations from being used for training, but OpenAI still retains them for up to 30 days for abuse monitoring.
This matters because people paste things into ChatGPT that they wouldn't email to a stranger. Research from Q4 2025 found that 34.8% of employee inputs to ChatGPT contained sensitive data, up from 11% in 2023. Source code, financial projections, internal strategy documents, customer PII. The input field feels private. It is not.
Is ChatGPT Encrypted?
Not in the way that would matter most to you. Data is encrypted in transit (TLS) and at rest on OpenAI's servers. But OpenAI does not use end-to-end encryption, which means conversations can be accessed by OpenAI staff and third-party vendors during processing. The encryption protects your data from outside attackers. It does not protect your data from OpenAI itself.
This is a design choice, not a technical limitation. End-to-end encryption for an AI chat product is hard, because the model needs to read your plaintext to generate a response. But "hard" is not "impossible," and the absence of it means you're trusting organizational policy, not cryptographic guarantees, to keep your conversations private.
What Happens When You Delete a Chat?
Less than you think. Deleting chat history removes conversations from your visible interface immediately, but not from OpenAI's systems. Deleted chats are typically retained for up to 30 days before permanent deletion. That window extends if OpenAI determines retention is necessary for legal, security, or operational reasons. And it extends indefinitely under a legal hold.
This is not hypothetical. In the New York Times copyright lawsuit against OpenAI, a federal preservation order issued on May 13 directed OpenAI to retain all output log data that would otherwise be deleted, regardless of user deletion requests or privacy regulation requirements. District Judge Sidney Stein affirmed the order on June 26 after OpenAI appealed, rejecting arguments that user privacy should override preservation needs. The order was later narrowed on October 9, releasing OpenAI from the obligation to preserve all output logs going forward, though retention requirements persisted for accounts specifically flagged by the Times.
The precedent is set. A court can order your "deleted" conversations preserved indefinitely. The delete button is a UX element. It is not a privacy guarantee.
Has ChatGPT Ever Had a Security Breach?
Yes. In early 2026, security researchers disclosed a vulnerability that allowed sensitive conversation data to be silently exfiltrated via a hidden DNS-based side channel, bypassing OpenAI's guardrails against direct outbound network requests. Check Point's research team noted the same flaw could enable remote command execution inside the ChatGPT runtime, effectively letting an attacker establish a hidden shell via DNS queries, outside the model's safety checks entirely.
OpenAI patched the vulnerability on February 20, 2026, with no evidence of malicious exploitation. Credit to them for the fast response. But the bug is instructive. It wasn't a brute-force attack on the encryption layer. It was a side-channel exploit that treated the AI runtime itself as a proxy. As ChatGPT gains more capabilities (browsing, code execution, agentic task completion), the number of these side channels grows.
Separately, in July 2025, search engines were found indexing thousands of ChatGPT conversation links, exposing sensitive queries users had unintentionally shared via the "share conversation" feature. The specific leak was resolved, but it demonstrated how easily a convenience feature becomes an exposure vector.
How Does the Enterprise Tier Differ from Consumer Plans?
Substantially. On Enterprise, Team, and API tiers, OpenAI does not train on user data, and the platform is encrypted and SOC 2 compliant. Enterprise adds admin controls, SSO, domain verification, and data processing agreements suitable for regulated industries. If your organization is evaluating ChatGPT for business use, the tier you deploy is the single largest variable in your risk posture.
The problem is organizational, not technical. Most employees don't wait for IT to provision an Enterprise seat. They sign up with a personal email, upgrade to Plus with a personal credit card, and start pasting proprietary data into an account that explicitly permits training on their inputs. This "shadow AI" pattern is widespread and growing. The gap between what Enterprise offers and what employees actually use is where most real-world data leakage happens.
And even Enterprise depends on policy commitments, not architectural guarantees. OpenAI promises not to train on Enterprise data. They honor that promise today. Whether a future acquirer, a regulatory order, or a change in leadership would alter that commitment is a question of trust, not cryptography.
What Are the Privacy Implications of ChatGPT's Agent Mode?
They're significant and underexamined. The newer agentic features let ChatGPT browse the web, interact with sites, and execute tasks on your behalf. The agent mode retains data, including screenshots of your browser, for 90 days. That's three times the standard chat retention window and includes visual captures of whatever was on screen during the agent's operation.
This shifts the privacy question from "what happens to my text" to "what can this system access and do while acting as me online." An agent that can browse, click, and screenshot has access to session cookies, authenticated pages, and contextual information far beyond what a user would voluntarily type into a chat prompt. The trust boundary is no longer the input field. It's your entire browser session.
The attack surface implications are worth thinking about carefully. The DNS exfiltration bug mentioned above was discovered in a pre-agentic version of ChatGPT. An equivalent vulnerability in the agentic runtime, where the model is actively browsing authenticated sessions, would have a fundamentally different blast radius.
Does ChatGPT Use Your Data for Advertising?
OpenAI introduced ads in early 2026 and stated that its advertising model would not involve sharing personal data with advertisers. That's the current policy. Whether it remains the policy as ad revenue becomes a larger share of OpenAI's business model is an open question. If you've watched the trajectory of any ad-supported platform over the past two decades, you know how these trajectories tend to bend.
The structural issue is the same one that recurs throughout this analysis: policy-based privacy is only as durable as the incentives supporting it. When the business model shifts, the policy follows.
What About Kids and Teens?
ChatGPT's minimum age is 13. Since October 2025, OpenAI has offered Parental Controls that let parents monitor usage and apply content filters. These are meaningful steps. They're also reactive measures layered on top of a system that was not originally designed with adolescent users as a primary consideration.
The documented concerns about chatbots reinforcing delusional thinking or producing inappropriate responses for younger users are real enough that any parent should treat AI chat products the way they'd treat any other unsupervised internet access: with active oversight, not passive trust in a content filter.
How Does the EU AI Act Affect ChatGPT's Safety?
August 2, 2026 marks the full application of the EU AI Act for high-risk AI systems, with non-compliance penalties up to €35 million or 7% of worldwide annual turnover, whichever is higher. Those numbers are large enough to force behavioral change.
For organizations deploying ChatGPT in the EU, the regulatory stakes now compound the technical risks. Data processing agreements, audit trails, and demonstrable compliance become requirements, not nice-to-haves. The "shadow AI" problem described above, employees using personal-tier accounts for work, becomes not just a security risk but a regulatory liability.
This is one of the reasons OpenAI released its "Privacy Filter" in April 2026: an open-weight, on-device model designed to strip PII from text before it reaches a cloud AI service. It's a notable admission from the industry's largest player that on-device processing is becoming the credible answer to cloud-side exposure. When the vendor itself builds a tool to keep data away from its own servers, you should pay attention to what that implies about the default data flow.
Policy-Based Privacy vs. Architectural Privacy
Most of the "is ChatGPT safe" discourse treats safety as a feature checklist. Toggle off training. Delete your history. Use the Enterprise tier. These are all good hygiene practices. They are also all policy-based: they depend on a vendor honoring commitments, courts not intervening, and employees following procedures.
The NYT preservation order is the clearest illustration of why this is fragile. A user deleted their chats. OpenAI's policy said those chats would be purged within 30 days. A federal judge ordered otherwise, and the chats persisted. No toggle, no setting, and no terms-of-service clause could override a court order, because the data existed on a server that OpenAI controlled.
Architectural privacy works differently. If sensitive data never reaches a retainable server in plaintext, there's nothing to subpoena, nothing to retain under a legal hold, nothing to exfiltrate via a DNS side channel. The privacy guarantee comes from the system's design, not from a promise in a terms-of-service document.
This is the lens through which we built Selina. Content is encrypted at rest, files and transfers via SelinaSEND are zero-knowledge encrypted, and non-content operational metadata is kept only for a short retention window. Memory is not end-to-end encrypted (a slice of each request reaches a frontier provider at inference), so we don't claim otherwise. But the architecture is designed so that delete means gone, and we can't read your content by design.
That's a different structural posture than "we promise not to look."
So Is ChatGPT Safe to Use?
For asking about recipes, debugging code snippets you'd post on Stack Overflow anyway, drafting emails you wouldn't mind being public: yes, it's safe enough. The model itself is not going to steal your identity or hack your bank account.
For anything confidential, proprietary, personally sensitive, or legally privileged: no. Not because OpenAI is malicious, but because the architecture doesn't protect you from the full range of threats. Your data persists on servers you don't control. It's accessible to staff and vendors. It's subject to court orders you'll never know about. It's retained longer when new features like agent mode are involved. And the attack surface is expanding with every new capability.
The right question isn't really "is ChatGPT safe." It's "safe for what, and under what threat model." If your threat model includes litigation, regulatory scrutiny, competitive intelligence, or simple embarrassment, the answer is that policy-based privacy isn't enough. You need architecture that makes the question moot.
If that framing resonates, start a free 7-day trial of Selina, no card required.
Frequently Asked Questions
Is ChatGPT actually safe to use?
It's safe enough for everyday, non-sensitive queries, but not safe for confidential information. Conversations are retained by default, not end-to-end encrypted, and accessible to OpenAI staff and third-party vendors.
Does deleting a ChatGPT conversation actually remove it?
No, deleting a chat only removes it from your visible interface, not from OpenAI's systems. Deleted chats are typically kept for up to 30 days, longer under legal holds, and a federal court has already ordered indefinite retention of chat logs in the NYT copyright litigation.
Is ChatGPT end-to-end encrypted?
No. Data is encrypted in transit and at rest, but not end-to-end, meaning OpenAI staff and third-party vendors can access conversations during processing rather than only cryptographic guarantees protecting them.
Has ChatGPT had any security vulnerabilities?
Yes, in early 2026 researchers found a DNS-based side channel that could silently exfiltrate conversation data and potentially enable remote command execution, bypassing safety guardrails; OpenAI patched it in February 2026 with no evidence of exploitation. Separately, in July 2025 shared conversation links were found indexed by search engines, exposing sensitive queries.
Is ChatGPT's Enterprise tier more private than the free or Plus version?
Yes, Enterprise, Team, and API tiers don't train on user data and include SOC 2 compliance, admin controls, SSO, and data processing agreements. However, many employees still use personal consumer accounts that permit training on their inputs, creating a 'shadow AI' gap that drives most real-world data leakage.
Sources & References
- Is ChatGPT safe? A 2026 guide to security risks and user safety
- Is ChatGPT Safe for Business in 2026? The Real Risks ...
- Is ChatGPT safe? The complete 2026 security & privacy guide
- Is ChatGPT safe? The ultimate guide for privacy
- Is ChatGPT private? A 2026 guide to your data privacy and security
- Is ChatGPT safe? | NordPass
- Is ChatGPT Safe? Privacy Facts Every User Should Know (2026) | AI Tool Compare
- Is ChatGPT Safe? Enterprise Security Guide 2026
- ChatGPT Privacy: What Data It Collects & How to Stay Safe
- ChatGPT Data Leak (Fixed Feb 2026): Key Takeaways
- ChatGPT Data Privacy - DataNorth AI
- A 2026 Guide to ChatGPT Risks | Concentric AI
- I Asked ChatGPT About Data Privacy in 2026 — Here’s What It Revealed
- OpenAI Court Order Forces Indefinite ChatGPT Data Retention
- OpenAI Court Case: Can Your ChatGPT Logs Be Subpoenaed? 20M Chats Ordered | Terms.Law
- OpenAI vs. NYT Lawsuit: The Only Way to Escape OpenAI’s Permanent Chat Storage Order
- NYT v. OpenAI: Court Order Requires Everything You Ask ChatGPT Be Saved; Historic Copyright Case Moves Forward - Long Island Guide
- ChatGPT Logs Retained Indefinitely: An Ethical Firestorm
- Deleted ChatGPT Conversations Can Be Preserved by Court Order: What Users Need to Know — You're the Expert Now
- OpenAI will stop saving most ChatGPT users’ deleted chats
- New on Yahoo
- New on Yahoo
