Is ChatGPT Confidential?
It depends which ChatGPT, and the honest answer for every tier is the same: confidentiality there is a contractual promise, not an architectural guarantee. A 2025 court order proved the difference in the most concrete way available.
In short
Consumer ChatGPT trains on your conversations by default and you have to switch that off yourself. ChatGPT Team, Enterprise, Edu and the API do not train on your content by default, which is a real difference and not the same as not retaining it. In 2025 a court in the New York Times litigation ordered OpenAI to preserve output logs, overriding its own deletion schedule for consumer, Team and non-ZDR API users; OpenAI says that going-forward obligation ended on 26 September 2025 and the case continues. No setting a user can toggle would have changed that.
The question gets asked as though it has one answer, and it has at least four. Free, Plus and Pro behave one way. Team, Enterprise and Edu behave another. The API behaves a third. And underneath all of them sits the same structural fact, which is the part worth understanding: confidentiality in a hosted AI product is a promise made by a company, governed by terms that company can change and by courts that can override them. That is not the same kind of thing as a guarantee, and in 2025 the difference stopped being theoretical.
What the consumer tier does by default
Start with the tier most people mean. On consumer ChatGPT, which is Free, Plus and Pro, the default is that your conversations can be used to improve the models. It is a setting, it is on unless you turn it off, and turning it off is a thing you have to know to go and do. Most people using a chatbot to summarize a document have not been through the data controls screen. The default is the policy, for almost everyone.
Turning it off does less than people assume, too. Opting out stops your content being used for training. It does not make the conversation vanish. Deleted chats normally leave the system on roughly a thirty day schedule, and that schedule is OpenAI's operational choice rather than a property of the system. Retention and training are two different questions, and a product can answer one of them well while answering the other very differently.
Team, Enterprise and the API are different
The business tiers genuinely are different, and it is worth being fair about that rather than lumping everything together. ChatGPT Team, Enterprise and Edu do not use business customer content to train models by default. The API does not either, and API retention is limited to roughly thirty days for abuse monitoring unless you hold a Zero Data Retention agreement, in which case it is not retained at all. If you are choosing between tiers for work, that difference is real and you should take it.
But notice what kind of difference it is. Every one of those protections is a term in a contract. It is a commitment by a vendor about what they will do with data that is, by then, sitting on their infrastructure. It is worth having. It is not the same as the data not being there, and the distinction only matters on the day something forces the question.
The court order that proved the point
In 2025 something did. In the New York Times copyright litigation against OpenAI, a court issued a preservation order requiring OpenAI to retain output log data going forward, overriding the deletion schedule it would otherwise have applied. It reached consumer ChatGPT and Team, and it reached API customers who did not hold a Zero Data Retention agreement. ChatGPT Enterprise, Edu, and ZDR API customers were outside it. OpenAI contested the order and has said the obligation to retain that going-forward content ended on 26 September 2025. The underlying case continues.
Read that sequence again with an eye on who decided what. A user picked a tier. A user possibly went into settings and switched training off. A user deleted their chats and reasonably believed they were gone. And then a dispute those users were not party to, about a matter that had nothing to do with them, changed what happened to their data. There was no setting that would have prevented it, because the mechanism operates above the settings layer entirely.
Structural, not a complaint about one vendor
That is the whole point, and it is not a criticism of OpenAI specifically. Any company holding your data can be compelled to keep it. Any terms of service can be revised. Any retention schedule is a policy rather than a physical constraint. This is true of every hosted AI product, including the ones with the strongest privacy commitments, and it will keep being true no matter how good those commitments get. It is a property of the arrangement, not of the vendor.
For most people that is an acceptable risk, honestly assessed. For some it is not, and the line is usually drawn by an obligation someone else wrote. A lawyer owes a client confidentiality that does not have a "unless the tool was convenient" exception, and ABA Formal Opinion 512 now says that in as many words. A clinician handles material where the covered entity, not the chatbot, is accountable. If you are inside one of those, the question is not whether you trust the vendor. It is whether you are permitted to make that trust the control.
The only guarantee that is not a promise
There is exactly one thing in this picture that no term of service and no court order can reach, and it is unglamorous: the data that never arrived. A value that was replaced before it left the machine is not in a log to preserve, not in a training set to opt out of, and not in a backup to schedule for deletion. It is the only part of the chain that is settled by architecture instead of by promise.
Which is why we built Protect, and why it is free for everyone permanently. It watches the clipboard, detects personal information in what you are about to paste, and replaces it with numbered placeholders before it leaves the device. The chatbot still gets your question and still helps you with it. The client name, the patient identifier and the account number do not travel. Protect itself runs entirely offline, which matters, because a privacy tool that phones home is just a second copy of the problem.
None of that requires you to distrust anyone. Use the best tier you can, read the terms, switch training off, and prefer the API with Zero Data Retention where you can get it. Then strip the identifiers anyway, because every one of those measures is somebody's promise, and the only thing that survives a promise being overridden is the data you never sent.