ChatGPT Business Data Privacy: Where Your Firm's Files Actually Go
Last updated: September 16, 2026
You'll usually judge ChatGPT business data privacy on one promise: OpenAI says it doesn't train on Business data by default. The promise is true. Still, a copy of your client files sits on OpenAI servers, Library keeps its own, and in 2025 a court order stopped OpenAI deleting ChatGPT logs for over four months.
The real privacy concern is who holds your client file, what they may do with it, and how long.
Below, we follow your file through storage, admin access, retention, Business Associate Agreement (BAA) status and offline use.
Quick answer
- Business, Enterprise and API inputs and outputs aren't used for training by default.
- Your data is stored on OpenAI servers, and a Library copy survives deleting the chat.
- OpenAI's own pages disagree on what a Business admin can read and export.
- There's no BAA for the Business plan, and no ChatGPT mode runs fully offline.
- Elephas is a private AI knowledge assistant for Mac that redacts 28 types of sensitive data on-device before any cloud model sees them.
Where Does Your Business Data Go When You Hit Send?
Once you use ChatGPT in a Business workspace, a prompt leaves your Mac on send. It travels encrypted to OpenAI, which handles data processing and pulls text from any file. Prompt and file follow separate deletion rules.
Encryption stops outsiders reading a file in transit or on disk. People inside the workspace can still read it. Customer data is encrypted in storage with Advanced Encryption Standard (AES-256) and in transit with Transport Layer Security (TLS) 1.2 or higher, per OpenAI's business data page. See our business guide and plan costs.
Harmonic Security's 2025 study found that 26.38% of files uploaded to AI tools held sensitive information, and 57.25% of that material was business or legal data (Harmonic Security).
- Library keeps uploaded files after you delete the chat that held them (Library page).
- Data residency covers storage only. Abuse-monitoring logs stay in the United States whatever region you pick, and a copy of prompts and responses is held there for a "limited time" (storage page).
- Removing a member keeps their user data indefinitely by default (member removal).
| Plan | Trains by default | Retention | Admin reach | BAA |
|---|---|---|---|---|
| Free, Plus | Yes, unless opted out | 30 days after deletion | None | No |
| Business | No | Admin-set | Disputed in vendor docs | No |
| Enterprise | No | Admin-set | Owner-granted Compliance Platform | Sales-managed only |
Temporary Chats are deleted after 30 days, per the OpenAI FAQ, while chats with training turned off still show up in your history. ChatGPT Team became Business in August 2025.
Is Your Firm's Data Used to Train OpenAI's Models?
The Business plan doesn't train on your data by default, and neither does Enterprise, per OpenAI's business data page. Storage, admin access and a court's reach sit outside that default.
OpenAI Terms of Use cover consumer plans. Business customers sign the Services Agreement, which says customer content isn't used to improve services unless the customer agrees.
Cyberhaven's 2025 report found that 34.8% of company data employees put into AI tools was sensitive (Cyberhaven Labs).
- Wrong account: Samsung employees pasted source code and a meeting recording into consumer ChatGPT in 2023, prompting a temporary ban on company devices (CIO Dive; TechCrunch).
- Personal logins: a client file typed into an employee's own Plus account can become training data until someone opts out (OpenAI).
- Regulators: Italy's Garante briefly banned consumer ChatGPT in 2023 (TechCrunch), though a Rome court scrapped its later 15 million euro fine (Reuters).
- Privilege: see our AI privilege waiver guide, and consumer ChatGPT risks.
Consent is its own duty. NYC Bar Association Formal Opinion 2024-5 says lawyers "may wish to obtain advance client consent" before sharing client information with generative AI.
Which Data Controls Let an Admin Read Employee Chats?
Whether a workspace owner can read what associates typed depends on which OpenAI page you trust. Its enterprise privacy page, dated 8 January 2026, says admins can view and export member chats. Its Help Center, updated in September 2026, says they cannot see all private chats or export.
"Workspace admins have control over workspaces and can view, access, export, and delete end user conversations in the workspace."
OpenAI enterprise privacy page, Business FAQ, "Updated: January 8, 2026"
"By default, admins and owners cannot see all private member chats."
"Self-service data export is not available in ChatGPT Business workspaces."
ChatGPT Business General FAQ, Help Center
We checked both pages on 16 September 2026. OpenAI hasn't said which one governs.
The Business privacy article says members can share single chats by link, and spend dashboards show usage figures. Prompts sent through Elephas's automatic redaction reach a cloud model as sanitized text, with names stripped on the Mac.
- Enterprise and Edu have a documented admin route, the Compliance Platform, where only a workspace owner can grant the "Conversation messages permission."
- A third page, on managed accounts, says an administrator "may be able to access, export, audit, retain, delete" account data.
- Work run through Elephas's built-in local LLM models stays on the Mac, outside any vendor admin console.
BigID's 2025 survey of 233 security, compliance and data leaders found 47.2% have no AI-specific security controls (BigID report).
How Long Does Data Retention Last After the NYT Court Order?
A deleted ChatGPT chat is normally scheduled for permanent removal within 30 days under OpenAI's retention policy. In 2025 a Southern District of New York court paused that schedule for over four months.
"OpenAI is NOW DIRECTED to preserve and segregate all output log data that would otherwise be deleted on a going forward basis until further order of the Court."
Magistrate Judge Ona T. Wang, preservation order, 13 May 2025, in the New York Times copyright suit (NYT v. OpenAI + Microsoft, Case 1:23-cv-11195)
The preservation order ended on 26 September 2025, as a 9 October 2025 order records. OpenAI says normal deletion resumed, while consumer logs from April to September 2025 stay on legal hold, seen only by a small audited team, with no published end date.
- Federal Rule of Civil Procedure 37(e) penalizes a firm in a lawsuit that fails to keep evidence, AI chats included.
- Deleting a Library file is a separate step with its own 30-day window.
- Cancelling the subscription doesn't delete the workspace or its files (retention policy).
- Files handled by Elephas with built-in local LLM models never enter a vendor retention schedule.
On 5 January 2026, Judge Sidney H. Stein upheld an order making OpenAI hand over 20 million de-identified ChatGPT logs, the ABA Journal reported.
Can You Get a BAA for ChatGPT Business or ChatGPT Enterprise?
The Business plan cannot take protected health information (PHI) under the Health Insurance Portability and Accountability Act (HIPAA) without a BAA, which that plan doesn't offer.
OpenAI offers no Business customer a BAA, says its help page. Its HIPAA-eligible list names ChatGPT Enterprise with Regulated Workspace and ChatGPT for Healthcare, not every Enterprise workspace.
A cloud provider that handles ePHI for a practice is a business associate "even if the CSP processes or stores only encrypted ePHI and lacks an encryption key for the data."
HHS cloud computing guidance, 45 C.F.R. §§ 164.308(b)(1) and 164.502(e)
Signing a business associate agreement won't make your practice HIPAA compliant by itself. Your own duties stay with you, such as the HIPAA "minimum necessary" rule in 45 CFR §164.502(b), so send an excerpt instead of a whole chart.
- No PHI, unless you hold a signed BAA on an eligible plan.
- No client material under a non-disclosure agreement, without documented consent.
- Tax return information, which IRC § 7216 rules generally bar sharing without written consent.
- EU personal data, where EDPB Opinion 28/2024 sets a General Data Protection Regulation (GDPR) test.
- Elephas's built-in local LLM models keep such work on the Mac, which reduces exposure but never replaces a BAA.
Is There Any ChatGPT Mode Where No One Else Handles Your Data?
Offline web search answers questions from OpenAI's stored copy of the web, per its offline web search page. No documented version of ChatGPT runs on-device without sending anything out, even for sensitive matters.
Check Point Research showed on 8 September 2026 how "a hidden channel" let one ChatGPT account reach another user's Gmail. OpenAI has since shut it.
- Tenable's November 2025 "HackedGPT" research found seven ChatGPT flaws that could leak private chat data (Tenable).
A 2025 Melbourne Business School and KPMG study of over 48,000 people found 57% of employees hide how they use AI (study summary).
Sending less is the one control that works on every risk above. A name that doesn't leave your Mac has no retention clock, no admin console and no legal hold. Elephas is a private AI knowledge assistant for Mac that sends less in two ways.
For researchers who still want a leading cloud model, Elephas adds a second layer through automatic PII redaction. Before a prompt is sent to ChatGPT, Claude, Gemini, Grok, Perplexity, or any other cloud model, Elephas strips sensitive names, emails, phone numbers, and identifiers on your Mac. The cloud model only ever sees the sanitized text. When the answer comes back, the redacted fields are reassembled locally on your machine, so identifiable information never leaves the device. Elephas pairs this with zero data retention: content never trains AI models, never sits on a vendor's server, and never passes through a third-party reviewer's screen.
- Personally identifiable information (PII) is removed before sending, so the cloud model never receives it.
- A 1,700-page PDF costs $0.40 to process.
- Built-in local LLM models process sensitive data on the Mac with no cloud call (AI privacy and security).
- Elephas has a free plan and starts at $19/month, with the live plan list on the Elephas pricing page. Try Elephas for free on one real matter.
The Safer Data Path for Confidential Client Work
ChatGPT Business data privacy comes down to six controls: training, storage, admin access, retention, legal holds and what you send. You control only what leaves your Mac.
ABA Formal Opinion 512, issued 29 July 2024, says lawyers must weigh a tool's data security and confidentiality before using it for client work.
Gallup's February 2026 survey of 23,717 US employees found privacy, security and compliance concerns among 43% of non-users (Gallup).
- No training by default; retention, admin access and legal holds need separate privacy controls.
- Deleting your chat doesn't delete its Library copy.
- OpenAI's pages disagree on Business admin access, so get your answer in writing.
- ChatGPT Business won't give you a BAA or fully offline mode.
- For client files that must stay private, Elephas is a privacy-friendly AI knowledge assistant with built-in local LLM models, so sensitive fields never leave the Mac.
Keep your AI chats private, on your own Mac
Elephas pairs with the AI model you already use, or runs fully offline with built-in local LLM models, and redacts sensitive data before it ever leaves your Mac.
Frequently Asked Questions
Does OpenAI train on ChatGPT Business data?
Not by default. OpenAI says inputs and outputs from Business, Enterprise and the API aren't used to train models unless the organization opts in (business data page). That default doesn't control retention, admin access, or legal holds, so your team manages those.
What happens to our files if we cancel ChatGPT Business?
Cancelling the subscription doesn't delete everything you already uploaded. Library files follow the workspace retention policy, and deleted items are scheduled for removal within 30 days (retention policy). Before cancelling, delete what you don't need and confirm deletion in writing.
Does putting a client NDA document into ChatGPT waive privilege?
Whether you have waived privilege depends on the facts, but the upload can put it at risk, because privilege depends on keeping information confidential. ABA Formal Opinion 512 calls for informed client consent where a tool could reveal client information. Our privilege waiver guide covers the details.
Does Temporary Chat keep an uploaded file out of Library?
Only if you never save it. OpenAI's Temporary Chat page says eligible uploaded files may be saved to Library once you save a temporary chat, and OpenAI may keep a copy for up to 30 days for safety. The upload itself still leaves your Mac.
Can OpenAI staff read ChatGPT Business conversations?
In limited cases, yes. The Business answer on OpenAI's privacy page limits access to authorized employees for engineering, abuse checks and legal compliance, plus confidentiality-bound abuse reviewers. The OpenAI Enterprise FAQ is narrower. Work run on Elephas's built-in local LLM models stays on the Mac and reaches none of them.








