ChatGPT Enterprise — privacy & data policy
Provider: OpenAI. PromptPrivacy score: 90/100. Last verified May 03, 2026.
What happens to your data?
Your business data remains your property and is not used to train OpenAI's models by default. OpenAI only accesses your data to provide services, ensure security, or comply with legal requirements.
Does it train on your data?
Data is not used for model training by default. Users must explicitly opt-in to share data for service improvement.
Can you opt out?
Yes, data is not used for training by default, so no opt-out is required to prevent training. If you have opted in, you can manage settings through your workspace or feedback mechanisms.
Data retention
Workspace admins control retention for Enterprise, Edu, and Healthcare; users control retention for Business and Teachers. Deleted data is removed within 30 days unless legal requirements apply.
Encryption & security
Data is encrypted at rest using AES-256 and in transit using TLS 1.2+.
Is it safe for work?
Yes, the service is designed for enterprise use with SOC 2 compliance, administrative controls, and data ownership protections.
Source policy: https://openai.com/enterprise-privacy