---
title: "Privacy and data controls in ChatGPT | Optimize All Academy"
description: "How data handling differs by plan As a general pattern (always confirm in OpenAI's current privacy policy, terms and help centre, plus your…"
url: https://optimizeall.com/learn/mastering-chatgpt/chatgpt-privacy-and-data-controls
updated: 2026-10-05
---

Mastering ChatGPT (OpenAI) · Privacy, data controls and team usage · lesson 18 of 19 · 15 min

# Privacy and data controls in ChatGPT

## How data handling differs by plan

As a general pattern (always confirm in OpenAI's current privacy policy, terms and help centre, plus your organisation's agreement):

- **Free, Go, Plus and Pro (consumer):** you control whether your conversations may be used to improve OpenAI's models through the **"Improve the model for everyone"** setting in Data Controls. You can delete chats, export your data, and use **Temporary Chat**, which does not appear in history, does not use or create memories, and is not used to train models (OpenAI may keep it for a limited period for safety).
- **Business, Enterprise and Edu:** covered by business terms; OpenAI states it does not train on business data by default. Admins get controls such as SSO, user management, app and GPT permissions, retention settings (Enterprise), and compliance tooling.
- **API:** data sent via the API is not used for training by default; retention and zero-data-retention options depend on eligibility and endpoint.

## Your 10-minute privacy check-up

1. **Data Controls:** decide the "Improve the model for everyone" setting deliberately.
2. **Memory:** review saved memories and chat-history reference; delete anything outdated or sensitive.
3. **Temporary Chat:** know how to start one.
4. **Shared links:** review and delete shared conversation links you no longer need; anyone with a link can view that conversation.
5. **Apps and plugins:** check which apps are connected and their permissions; disconnect unused ones.
6. **Custom instructions and GPTs:** remove anything confidential.
7. **Security:** enable multi-factor authentication; review logged-in devices.
8. **Export or delete:** export your data if you want a copy; delete chats you no longer need.

## Classify before you paste

| Class | Examples | Rule |
|---|---|---|
| Public | Published content, public web pages | Any approved tool |
| Internal | Plans, drafts, non-sensitive metrics | Approved work workspace |
| Confidential | Client contracts, unreleased campaigns, pricing | Business/Enterprise workspace only, minimised |
| Restricted | Passwords, API keys, card data, national IDs, health data, special-category data | Never in ChatGPT |

## Minimise and anonymise

- Share the clause, not the contract; the columns you need, not the whole export.
- Replace names and emails with IDs; aggregate where possible.
- Remove metadata and screenshots' visible personal data.
- Keep a note of what you shared and why for sensitive projects.

## Legal context

Personal data processing with AI is subject to data protection law: for example UK GDPR and the Data Protection Act 2018, the EU GDPR (and the EU AI Act's obligations as they phase in), the UAE's federal Personal Data Protection Law (with separate DIFC and ADGM regimes), Saudi Arabia's Personal Data Protection Law, and Pakistan's evolving framework. Client contracts may restrict AI use outright. Involve your data protection lead before processing customer or employee personal data.

## Shared links and GPTs: the overlooked leaks

- A shared conversation link exposes that conversation to anyone who has the link, including any files' content quoted in it.
- A public or widely shared GPT's knowledge files may be coaxed out by users.
- Connected apps inherit your permissions, so overshared folders become searchable.

## Worked example: customer survey analysis

A marketing assistant at a UK subscription box company needs themes from 2,000 open-text survey responses. She exports only the response text and plan type, removes names, emails and order numbers, and uses the company's ChatGPT Business workspace. She asks for themes with representative (identifier-free) quotes and counts, documents her method, and deletes the working file afterwards. Her manager can explain exactly what data was used if a customer asks.

## Hands-on

Complete the 10-minute check-up and schedule a quarterly reminder. Then write a one-paragraph personal data policy using the four classes and share it with your manager.

## Questions to ask before approving any AI tool

- Is our content used to train models, and can we contractually prevent it?
- How long is data retained, and can we control retention?
- Where is data processed and stored, and which sub-processors are involved?
- What admin controls, audit logs, SSO and MFA options exist?
- Can we sign a data processing agreement?

Record the answers in a simple AI tools register so you can answer client security questionnaires quickly and consistently.

## Pitfalls

- Personal accounts for client work.
- Forgetting old shared links.
- Treating Temporary Chat as a legal compliance tool.
- Quoting old privacy terms to clients.

## How to measure success

You can state which data classes go into which tools, your shared links and connected apps are reviewed quarterly, and no restricted data has entered ChatGPT.

## Video lecture: Privacy and data controls in ChatGPT

Lecture coming soon · 16 chapters · about 8 minutes. Read the full transcript below.

1. Privacy in ChatGPT
2. Why privacy is mostly habits
3. Consumer plans
4. Business plans and the API
5. The 10-minute check-up
6. Four data classes
7. Minimise and anonymise
8. Legal context
9. Overlooked leaks
10. Simple example
11. Worked example: 2,000 survey responses
12. Try this now
13. Common mistakes
14. Watch me do it, part 1
15. Watch me do it, part 2
16. Recap and next step

## Lecture transcript

### Privacy in ChatGPT

Privacy in ChatGPT is mostly decided by three things, which plan you are on, how your settings are configured, and what you choose to paste. Get those right and you can use ChatGPT confidently with real work. In this lecture you will learn how data handling differs by plan, run a ten minute privacy check up, and learn the classification rules that make safe choices automatic.

### Why privacy is mostly habits

Why focus on privacy habits? Because settings only set the defaults. What really decides your risk is what you paste. A full customer export, a client contract in a personal account, a screenshot with someone's email visible. Think of it like home security. The alarm matters, but so does remembering to lock the door. This lecture gives you both the settings and the habits.

### Consumer plans

On consumer plans, Free, Go, Plus and Pro, you decide whether your conversations may be used to improve OpenAI's models, using the improve the model for everyone setting in Data Controls. You can delete chats and export your data. And Temporary Chat does not appear in history, does not use or create memories, and is not used for training, though OpenAI may keep it for a limited time for safety.

### Business plans and the API

Business, Enterprise and Edu plans are covered by business terms, and OpenAI states it does not train on business data by default. Admins get single sign on, user management, permissions for apps and GPTs, retention settings on Enterprise, and compliance tooling. Data sent through the API is also not used for training by default, with retention options depending on eligibility. Always confirm the current terms before advising a client.

### The 10-minute check-up

Now the check up. Decide your data controls setting. Review memory. Learn how to start a Temporary Chat. Review and delete old shared links, because anyone with a link can view that conversation. Check connected apps and their permissions. Remove anything confidential from custom instructions and your GPTs. Turn on multi factor authentication. And export or delete what you no longer need. Put a quarterly reminder in your calendar.

### Four data classes

Classify before you paste. Public data can go into any approved tool. Internal data goes into your approved work workspace. Confidential data, like client contracts, unreleased campaigns and pricing, goes only into a Business or Enterprise workspace, minimised. Restricted data, passwords, API keys, card data, national IDs, health data and other special categories, never goes into ChatGPT at all.

### Minimise and anonymise

Then minimise and anonymise. Share the clause, not the whole contract, and the columns you need, not the full export. Replace names and emails with IDs, and aggregate wherever you can. Remove visible personal data from screenshots. For sensitive projects, keep a short note of what you shared and why.

### Legal context

Data protection law applies when you process personal data with AI. UK GDPR and the Data Protection Act. The EU GDPR, plus the EU AI Act's obligations as they phase in. The UAE's federal personal data law, with separate rules in the DIFC and ADGM. Saudi Arabia's Personal Data Protection Law. And Pakistan's evolving framework. Client contracts may restrict AI use entirely. Involve your data protection lead before processing customer or employee data.

### Overlooked leaks

Three leaks people overlook. Old shared links, which expose that conversation to anyone who has them. Knowledge files in widely shared GPTs, which determined users can sometimes coax out. And connected apps, which inherit your permissions, so an overshared folder becomes easy to search. Review all three every quarter.

### Simple example

A simple example. You want ChatGPT's help rewording a reply to a customer complaint, and your screenshot shows the customer's name and email in the header. Crop the header out, or paste only the complaint text, before you share it. Ask the same question. You get exactly the same help, because the useful part was the complaint, not the identity. Ten seconds of cropping, and no personal data ever left your screen.

### Worked example: 2,000 survey responses

A marketing assistant at a UK subscription box company needs themes from two thousand survey responses. She exports only the response text and plan type, strips names, emails and order numbers, and uses the company's ChatGPT Business workspace. She asks for themes with counts and identifier free quotes, documents her method, and deletes the working file afterwards. If a customer ever asks, her manager can explain exactly what was used. Months later, a customer asked whether their survey answer had been shared with an AI tool. Because the method note existed, her manager could answer precisely. Only the anonymous response text was used, in the company's business workspace, and no names or emails were included. A two minute note turned a potentially awkward question into a reassuring answer.

### Try this now

Try this now. Work through the ten minute check up. Decide your data controls setting, review memory, find Temporary Chat, delete old shared links, check connected apps, clean your custom instructions and GPTs, turn on multi factor authentication, and export or delete what you no longer need. Then write a one paragraph personal data policy, which data classes go into which tools, and share it with your manager. Set a quarterly reminder to repeat it.

### Common mistakes

Four common mistakes. Using a personal account for client work, just this once. Forgetting shared links that are still live months later. Treating Temporary Chat as if it satisfies legal or contractual obligations, when it only controls history and memory. And quoting old privacy terms to a client instead of checking the current policy. Avoid those, and you are ahead of most organisations.

### Watch me do it, part 1

Let me run the privacy check up. Data controls first, where I decide the improve the model setting deliberately. Memory, where I delete an entry about a client's launch date. Shared links, where I find two conversation links I shared last year with a freelancer, and delete both, because anyone with the link could still read them. Apps, where I disconnect a calendar app I no longer use. Custom instructions, where I remove a client's name I had added months ago. And security, where multi factor authentication is already on. Six screens, under ten minutes.

### Watch me do it, part 2

Now the subscription box survey. I open the export and delete the name, email and order number columns, keeping only the response text and plan type. I switch to the company's ChatGPT Business workspace using the workspace switcher, and I can see the business badge. I upload the trimmed file and ask for the top themes, with counts and two short quotes each that contain no personal details. I check three quotes against the file. Then I write a short method note, which columns I used, which workspace, and the date, and delete the working file from my laptop.

### Recap and next step

Recap. Know your plan's data terms and confirm the current policy. Run the privacy check up quarterly. Classify, minimise and anonymise. Watch shared links, GPT knowledge and connected apps. And check law and contracts first. Your next step: complete the check up today and write a one paragraph personal data policy for your own AI use.

## Key takeaways

- Consumer plans let you control model-improvement use; Business, Enterprise, Edu and the API do not train on your data by default. Confirm current terms.
- Run a quarterly check-up: data controls, memory, Temporary Chat, shared links, apps, instructions/GPTs, MFA, export/delete.
- Classify data as public, internal, confidential or restricted; never paste restricted data; minimise and anonymise the rest.
- Data protection law and client contracts apply; involve your data protection lead before processing personal data.

## Try it

Complete the 10-minute privacy check-up and schedule a quarterly reminder to repeat it.

- [Previous: Integrations: function calling, MCP and the Agents SDK with your business tools](https://optimizeall.com/learn/mastering-chatgpt/openai-api-business-integrations)
- [Next: ChatGPT Business and Enterprise: admin, governance and rollout](https://optimizeall.com/learn/mastering-chatgpt/chatgpt-for-teams-and-enterprise)
- [All lessons of Mastering ChatGPT (OpenAI)](https://optimizeall.com/learn/mastering-chatgpt)
