The word confidential is doing two different jobs in this question, and that is why the answers you find online contradict each other. Legally confidential means protected from disclosure, the way a conversation with your lawyer is. Contractually confidential means a company has promised in writing not to use or share your data. ChatGPT is not the first. Whether it is the second depends entirely on which plan you are paying for.
Both halves matter, and most people only check one. Here is what OpenAI actually keeps, who inside the company can read it, what the plan tiers change, and where the line sits for anything regulated.
Legally confidential: no, and this is settled
Privilege is a narrow legal protection that attaches to specific relationships, mainly attorney and client, with limited forms for doctors and clergy. Typing something into a chatbot creates none of them. What you create instead is a record held by a third party company, and third party records are discoverable.
This is not a theoretical risk. We went through twelve cases in which chatbot transcripts were pulled into evidence, spanning divorce proceedings, employment disputes and criminal matters. OpenAI’s chief executive has said publicly that conversations people treat as therapy carry no legal protection, which is an unusually direct admission from a vendor.
The retention side has been tested too. A court order in the New York Times copyright case forced OpenAI to preserve output logs that would otherwise have been deleted, which meant deleted chats stopped disappearing for several months. That blanket obligation was lifted on October 9, 2025, effective back to September 26, 2025, but what had already been captured stays captured and specifically flagged accounts remain under retention. OpenAI published its own account of the dispute.
Contractually confidential: depends entirely on your plan
This is the part that actually varies, and the gap between the tiers is much wider than the price difference suggests.
| Free and Plus | Business, Enterprise, Edu | API | |
|---|---|---|---|
| Used to train models | Yes, unless you turn it off in Data Controls | No, not by default | No, not by default |
| Retention after you delete | Purged within 30 days, subject to legal holds | Removed within 30 days | Up to 30 days, or zero if ZDR is granted |
| Zero data retention available | No | No | On eligible endpoints, with a qualifying use case |
| Signed data processing agreement | No | Yes | Yes |
| SOC 2 Type 2 audited | Not applicable | Yes | Yes |
| Admin can be granted your message text | No admin exists | On Enterprise and Edu, if a workspace owner grants it | Your own organization holds the logs |
Read the last row carefully if you use a work account. OpenAI runs a compliance logs platform for Enterprise and Edu workspaces, and while most of it is audit and authentication metadata, conversation text is a separate higher permission that only a workspace owner can grant. Confidential from OpenAI is not the same as confidential from your employer, and we covered that distinction in detail in what IT actually logs when you use ChatGPT at work.
Who at OpenAI can actually read a conversation
OpenAI states that access to conversations is limited to two groups: authorized employees who need it for engineering support, investigating potential platform abuse and legal compliance, and specialized third party contractors bound by confidentiality obligations. Data is encrypted with AES-256 at rest and TLS 1.2 or higher in transit.
That is a normal and reasonably tight arrangement for a cloud service, and it is also not zero. Human review exists, the conditions under which it happens are defined by OpenAI rather than by you, and a contractor under an agreement is still a person reading text. If your mental model was that nobody ever sees any of it, adjust that model rather than the behavior you would have had anyway.
What actually gets kept, and for how long
The short version, with the caveats that matter.
Consumer (Free, Plus) Chats stored until you delete them Deleted chats purged within 30 days Training ON by default, off via Settings > Data Controls Temporary Chat not used for training, kept briefly for abuse review Exception: any legal hold overrides all of the above Business, Enterprise, Edu No training on your data by default Deleted conversations removed within 30 days Enterprise and Edu: conversation text reachable via compliance logs only if a workspace owner grants that permission API Inputs and outputs retained up to 30 days for abuse monitoring Zero data retention available on eligible endpoints No training on your data by default
Where the line sits for regulated data
If you handle health records, client legal matters, financial account data or anything covered by a confidentiality obligation you signed, the plan tier stops being a preference and becomes the whole question.
A consumer account has no data processing agreement behind it, which means you have no contractual basis to put someone else’s regulated data into it, regardless of what the privacy settings say. A business plan with a signed agreement and a SOC 2 report is the minimum starting point, and for the strictest cases the API with zero data retention is the only configuration where the text is not stored at all.
Common misconceptions
“Turning off training makes it private”
It stops your conversations being used to improve models. It does not delete history, does not prevent retention, does not block a legal hold and does not create any confidentiality obligation. It is one useful toggle, not a privacy mode.
“Deleting the chat removes it”
Deletion removes it from your view and starts a purge that completes within 30 days. It does nothing about copies already made under a legal hold, logs captured by your employer’s tooling, or anything an attacker already exfiltrated.
“Paying for Plus gives me business protections”
It does not. Plus is a consumer plan with consumer terms. The training default, the absence of a data processing agreement and the lack of an audited compliance posture are the same as Free. The tier that changes your legal position is Business, not Plus.
“Incognito or a VPN helps”
Neither touches this. Your conversations are stored server side against your account. A private browsing window changes what your own browser remembers and a VPN changes the IP address in the log, and both leave the transcript exactly where it was.
Frequently asked questions
Is ChatGPT confidential for business use?
On Business, Enterprise and Edu plans, yes in the contractual sense: no training on your data by default, a signed agreement, deletion within 30 days and a SOC 2 Type 2 audit. It is still not legally privileged, so a court can still reach it.
Can OpenAI employees read my chats?
A limited set can, under defined conditions: authorized staff handling engineering support, abuse investigations and legal compliance, plus contractors bound by confidentiality. It is not routine browsing, and it is not never.
Are ChatGPT conversations covered by attorney client privilege?
No. Privilege attaches to the lawyer and client relationship, not to the tool used. Pasting a privileged document into a chatbot can in some circumstances be argued to weaken the privilege rather than extend it, which is the opposite of what people assume.
Does the free plan train on my conversations?
By default yes, and you can turn it off under Settings, then Data Controls. The setting applies going forward and does not retroactively remove anything already used.
What is the most private way to use ChatGPT?
API access with zero data retention on an eligible endpoint, where nothing is stored. Below that, a business plan with training off. On a consumer account, Temporary Chat with training disabled is as far as the controls go.
Should I put client or patient data into it?
Not on a consumer plan, and on a business plan only after checking what your own contracts and regulator require. The vendor’s compliance documentation is a prerequisite, not permission.
The bottom line
ChatGPT is confidential in the way a cloud document editor is confidential. The company has promised, in writing on business plans, not to train on your content and to delete it when you ask. It has not promised, and cannot promise, that a court will not reach it, because no vendor can.
Practically, that means two rules. Match the plan to the sensitivity of what you are typing, because the gap between Plus and Business is legal rather than cosmetic. And remember that the realistic threat to your transcripts is not OpenAI at all: it is the laptop with the compromised session token, and no privacy policy covers that. If you are still working out how to get useful output in the first place, our beginner guide to ChatGPT is the better starting point.

