Answers

Does ChatGPT store your data? Retention, training and deletion explained

Published 3 July 2026 · Updated 17 July 2026 · Occlira team

Short version: yes — everything you send reaches OpenAI’s servers, personal accounts use it for training by default, and “delete” is governed by policy and, as 2025 proved, by court orders you don’t control. Here’s exactly how retention, training and deletion work across ChatGPT, Claude and Gemini — and the one control you fully own.

Short answer. Your text is transmitted and stored; on Free/Plus/Pro it trains the model unless you opt out; deleting is a 30-day request, not a guarantee; and a court can override the provider’s deletion and training policies. The only control you fully own is not sending the sensitive data — anonymize it locally first.

What OpenAI does with your data

On Free, Plus and Pro accounts, your conversations are used to train OpenAI’s models by default. You opt out with “Improve the model for everyone” in Settings → Data Controls — but the opt-out is forward-looking only (it can’t remove data from a training run that already ran), and a thumbs-up/down on a reply can still send that conversation for training even with the toggle off. (Source: OpenAI Help Center, accessed July 2026.) Business, Enterprise and API tiers are not trained on by default.

How long does OpenAI keep it, and what does “delete” do?

Deleting a chat removes it from your view immediately, and OpenAI schedules permanent deletion from its systems within about 30 days — subject to de-identification, security and legal-hold exceptions. (Source: OpenAI Help Center, accessed July 2026.) The word “delete” is doing a lot of work there: it’s a scheduled request with exceptions, not an instant erase.

Temporary Chat and memory — the settings people misread

Temporary Chat isn’t saved to history, isn’t used for training, and doesn’t use or create memories — but OpenAI may keep a copy for up to ~30 days for safety. (Source: OpenAI, accessed July 2026.) Memory has a trap: turning off Saved Memories or deleting a chat does not erase memories already saved (manage those under Settings → Personalization). Turning off “Reference chat history” does delete what was remembered from past chats, within about 30 days. (Source: OpenAI, accessed July 2026.)

Consumer vs business vs API — the tier that decides everything

PlanTrained on by default?Retention / controlSwept into the 2025 order?
Free / Plus / ProYes — opt out in Data ControlsDeleted chats removed within ~30 daysYes
Team / BusinessNoNot trained on; DPA availableYes (standard API too)
Enterprise / EduNoConfigurable retention; DPANo — excluded
API (standard)NoAbuse logs up to 30 daysYes
API (Zero Data Retention)NoNot persistently storedNo — excluded

Business/Enterprise/API terms and Zero Data Retention per OpenAI Enterprise privacy (accessed July 2026).

2025: when “deleted” stopped meaning deleted

On 13 May 2025, in the New York Times copyright case, a federal court ordered OpenAI to “preserve and segregate all output log data that would otherwise be deleted” — overriding users’ own deletions and even Temporary Chats. It swept in Free, Plus, Pro and Team users plus standard API customers; Enterprise, Edu and Zero-Data-Retention API customers were excluded. The going-forward obligation was terminated around 26 September 2025, but everything already preserved must still be kept. (Source: OpenAI.)

Then it went further. On 5 January 2026, a judge affirmed an order requiring OpenAI to produce a sample of 20 million “anonymized” conversations — about 0.5% of the preserved logs — reasoning that users “voluntarily submitted their communications.” Legal analysts warn “anonymization won’t save you”: conversational logs routinely carry directly-identifying details like full names, addresses and ID numbers, so de-identifying them is unreliable. (Source: Jones Walker.) The lesson isn’t about one lawsuit — it’s that once your data is on a provider’s servers, its retention and disclosure are no longer your decision.

How Claude and Gemini compare

Every provider’s policy is a moving target. On 28 August 2025, Anthropic updated its consumer terms so chats from Claude Free, Pro and Max can be used to train Claude based on your choice, with a decision deadline of 8 October 2025. Allowing training extends retention from 30 days to five years; declining keeps the 30-day window. Deleted conversations leave your history immediately and back-end storage within 30 days, but flagged content can be kept up to two years and trust-and-safety scores up to seven. (Source: Anthropic, 28 Aug 2025.) Google’s consumer Gemini likewise retains activity and may use it to improve its products by default, with opt-outs, while its enterprise terms differ — so check the current settings for whichever tool you use.

The only control you fully own

Notice the pattern: opt out of training and your data is still stored; use Temporary Chat and it’s still transmitted; delete a chat and a court can preserve it anyway. Settings reduce risk, but they can’t un-send data or override an order. The one control that doesn’t depend on any provider’s policy is not sending the sensitive data in the first place — and that’s a decision you make on your own machine, before anything is transmitted.

How Occlira keeps sensitive data off the servers

Occlira is that step. It detects and removes personal data from documents, spreadsheets, email, audio and images entirely on your own computer — no cloud, no account. You anonymize a file locally, run any AI tool on the anonymized copy, then restore the real values on your machine. There’s nothing sensitive for a provider to store, nothing to feed model training, and nothing for a court order to preserve.

Occlira flagging personal data — names, an organization, dates, an address and a phone number — in a document for local review before it is sent to an AI tool.
Anonymize on your device first, and nothing sensitive reaches the server to be stored, trained on or preserved.

One honest caveat: Occlira’s anonymization is reversible, which in GDPR terms is pseudonymization — strong local minimization, but the mapping (kept on your device) is still personal data, so treat it as control, not a way out of the rules. The mechanics are in anonymize before ChatGPT.

Frequently asked questions

Yes. Everything you type is sent to and stored on OpenAI’s servers to generate the reply. On personal accounts (Free, Plus, Pro) it is also used to train OpenAI’s models by default unless you turn model training off in Settings → Data Controls.

On personal accounts, yes by default. Turn off “Improve the model for everyone” in Settings → Data Controls. The opt-out is forward-looking only — it doesn’t pull your data out of a training run that already happened — and giving a thumbs-up/down on a reply can still send that conversation for training even with the toggle off. Business, Enterprise and API tiers are not trained on by default.

Deleting removes the chat from your view immediately, and OpenAI schedules permanent deletion from its systems within about 30 days — subject to security and legal-hold exceptions. As 2025 showed, a court order can suspend that deletion entirely.

Temporary Chat isn’t saved to your history, isn’t used for training, and doesn’t use or create memories, but OpenAI may keep a copy for up to about 30 days for safety. The text is still transmitted to and processed by OpenAI — and during the 2025 preservation order, even Temporary Chats were retained.

Yes. In May 2025, in the New York Times case, a federal court ordered OpenAI to preserve and segregate output logs that would otherwise be deleted — overriding users’ deletions and Temporary Chat — for Free, Plus, Pro and Team users and standard API customers. Enterprise, Edu and Zero-Data-Retention API customers were excluded. The going-forward obligation ended around 26 September 2025, but data already preserved must be kept.

They can. In January 2026 a judge affirmed an order requiring OpenAI to produce a sample of 20 million “anonymized” conversations to the plaintiffs — and analysts warn that conversational logs are hard to truly anonymize because they routinely contain names, addresses and IDs. Once your data is on a provider’s servers, its retention and disclosure are outside your control.

Yes — that’s the catch. Deleting a chat or switching off Saved Memories does not erase memories already saved; you manage those under Settings → Personalization → Manage memories. Turning off “Reference chat history” does delete what was remembered from past chats (within about 30 days).

Settings reduce risk but can’t un-send data or override a court order. The only control you fully own is not sending it: anonymize the file locally with Occlira, use the AI on the anonymized copy, then restore the originals on your own machine — so there’s nothing sensitive for the provider to store.

Keep sensitive data off the servers

Anonymize locally, then use any AI tool on the copy. Free for 14 days on Windows and macOS.

More: what is PII? · local vs cloud redaction · how your data is handled