Chat · guide

Is ChatGPT safe? It depends which question you mean

By Alberto Gulotta · Updated · 8 min read

Is chatgpt safe is asked thousands of times a month, and it gets answered mostly by people guessing. It does not need guessing: OpenAI publishes its data settings, what each one does and how long things are kept. This guide quotes those pages and is honest about the parts they do not cover.

“Safe” is four different questions

And they have four different answers, only two of which anybody can look up.

Safe for my data?Documented. OpenAI publishes the settings, what each one does and how long things are kept. Quoted below, read on 21 August 2026.
Safe for work secrets?Partly documented, mostly not your decision. The controls are real; whether your employer permits it is a separate question with a different answer.
Safe to rely on?A different subject entirely — accuracy, not privacy. A confident wrong answer is a risk no privacy setting touches.
Safe as an account?The ordinary question you would ask of any service holding years of your writing: password, second factor, who else can get in.

The setting this question is really about

OpenAI’s own instructions, from its Data Controls FAQ.

Profile icon›Settings›Data Controls› turn off “Improve the model for everyone”

What that does, in OpenAI’s words: “Your conversations will still appear in your chat history but won’t be used to train ChatGPT.” It applies account-wide — “Once you turn off model training, the setting applies to your entire account. It doesn’t matter which device you’re using” — and it is not a one-way door: “you can change this setting anytime. There are no restrictions.”

Two details worth knowing. The control exists even if you never signed in — signed out, it is behind the question-mark icon in the corner. And turning training off is not the same as turning everything off: OpenAI notes that disabling memory and personalisation “does not disable safety features that may use limited, safety-relevant context in rare, high-risk situations”.

Three different questions that all get called is ChatGPT safe, and which of them a setting answers
Only two of the three have a switch. Figure drawn by AI Tools Primer.

It helps to know what that menu is called and what actually lives in it, because the name promises more than the contents. OpenAI describes Data Controls as the place that lets you “decide how ChatGPT uses your conversations and interactions”, and says they “specifically allow you to choose whether your conversations help improve our models”. That is the scope of the menu: it is about training, not about who can reach your account.

The same switch, three different places

OpenAI lists a separate route for each surface. They are not the same menu.

Web, signed in›profile icon› Settings›Data Controls› turn it off
Web, signed out›the ? icon, bottom right› Settings›turn it off
Mobile›side-bar menu› profile icon›Data Controls› turn it off

The routes differ because the options do. Signed out, OpenAI says, “you can choose if your chats are used to help train ChatGPT”; signed in, “you have additional options like exporting your data or deleting your account”. Exporting and deleting are account features, so they only exist once there is an account.

And the stronger option, which fewer people know about

That is a different setting from the training toggle and a stronger one for a single sensitive conversation. Note the third line rather than skipping it: not used for training is not the same as never seen by anyone. OpenAI says these chats may still be reviewed for abuse monitoring, and a page that quoted only the first two lines would be telling you half of what the company published.

The two settings interact, in a way the FAQ states in one line and most summaries drop. Turning training off leaves your conversations in your history — but if the conversation is a Temporary Chat, OpenAI says it “will be deleted after 30 days” anyway. The history you keep and the training you refuse are two separate decisions, and the temporary option overrides the first of them.

One more line is worth quoting for anyone who dealt with this the hard way, before the setting existed. OpenAI: “If you opted out by contacting support or using our privacy form, your account will represent that request.” An opt-out obtained by email is not quietly dropped when the interface catches up with it.

Which brings us to the question in this cluster that matters most and is answered worst: is chatgpt safe for confidential information. The honest answer has two halves. The first is that the controls above are real and documented. The second is that a setting you can verify says nothing about whether you are allowed to paste that material anywhere — and for work documents, client files, medical details or anything covered by an agreement, permission is the binding constraint, not the toggle. No page on the internet can tell you your employer’s policy, and any page that implies otherwise is guessing on your behalf about something you would be answerable for.

There is also a category difference worth naming. On a business plan the arrangement is not the same as on a personal account — OpenAI states that “our Team, Enterprise, and Edu plans offer additional data controls”. If your organisation has one, the answer to “is this safe for work” may already have been decided for you, in your favour, by somebody who read the contract.

The part no product setting covers, from a security agency. The NCSC frames the risk as the query itself rather than the account: an LLM provider “(or its partners/contractors) are able to read queries, and may incorporate them in some way into future versions”, so the terms and the privacy policy “need to be thoroughly understood before asking sensitive questions”. It adds two things a settings screen cannot: a question can be sensitive because of who is asking it rather than what is in it, and separate questions can be aggregated across one login.

The related searches show how specific the worry has become. Is chatgpt safe to use is the general version. Are chatgpt chats private and chatgpt security risk come from people thinking about the conversation history rather than the answers. And the newer ones — is chatgpt agent mode safe, is chatgpt atlas safe — are about features that do more than answer questions, which is a genuinely different risk and has guides of its own below.

Where to start

Four ways in.

“I want my chats out of training.”
It is above. Then the settings
“Is my account secure?”
Go to the account

The settings

Every control OpenAI documents, what it changes and what it does not. Quoted rather than summarised, because the difference between the two is where people get misled.

The account

Years of your writing behind one password. The ordinary security questions apply here as they would to email.

Not covered here. It will not tell you ChatGPT is safe or unsafe as a verdict. That word covers four questions and they have different answers.

It will not paraphrase a setting when the company has written it down. Where OpenAI publishes the wording, the wording is quoted with the date it was read — because these pages change, and this one was updated days before we read it.

And it will not decide your confidentiality question for you. That one belongs to your employer, your client or your regulator, and a page that answers it on your behalf is putting you at risk to sound helpful. What holds instead is simple: every setting quoted here comes from OpenAI’s own published help pages.

Living with ChatGPT: the plan, the history and the data

What you are paying for, what it keeps, and how to stop both.

The same job, in the other places it comes up
ChatGPT Go vs Plus: what each one actually buys
How to delete ChatGPT history, and what deleting means
How to cancel a subscription on iPhone, and when you cannot

Sources

  1. OpenAI Help Center — Data Controls FAQ, on the training setting, Temporary Chats, retention and business plans — help.openai.com, read 21 August 2026.
  2. National Cyber Security Centre — ChatGPT and large language models, what’s the risk: the query as the exposure, and the aggregation across one login — www.ncsc.gov.uk, read 4 September 2026.

Written by Alberto Gulotta

Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.

Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.

Written on 21 August 2026 · last checked 4 September 2026.

Independence and limits

No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.

This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.