Is ChatGPT Private? What OpenAI Keeps, Who Can Read It, and What to Use Instead

No, not by default. What OpenAI keeps from your ChatGPT conversations, who can read them, the court fight that preserved deleted chats, how to lock ChatGPT down, and the private AI you can verify instead of trust.

13 min read
A laptop showing a chat window on a desk at night beside a stamped file folder, a rain-streaked city behind it, in black and white
Share

No. Not by default, and not in the way most people assume.

OpenAI keeps your ChatGPT conversations on its servers until you delete them, trains its models on them unless you opt out, has humans review flagged chats, and hands chat content to police who show up with a warrant. Deleting a chat starts a 30-day clock, and in 2025 a federal court forced OpenAI to hold on to chats users had already deleted. Temporary Chat and the training toggle shrink your exposure, but OpenAI can still read every word you type.

I use ChatGPT. My boys ask our voice assistant, which they named Daryl, how fast the fastest fish in the sea swims.

For anything that matters I use Maple, a private AI app built by OpenSecret. Disclosure: Ten31, where I'm Managing Partner, is an investor in OpenSecret, and Maple has sponsored this show. Its co-founder Mark Suman has been on TFTC three times, and his arguments run through this piece.

Bring the lens bitcoiners already use for money. Privacy is either a property you can verify or a policy you're trusting. ChatGPT is the second kind.

Key takeaways

  • ChatGPT keeps your chats until you delete them. Deleted chats are purged within 30 days unless OpenAI has a security or legal reason to keep them.
  • Your chats train OpenAI's models by default. You can switch that off, but a thumbs up or down can still send the whole conversation into training.
  • Staff, employers and police can read them. OpenAI reviews flagged conversations, business admins can export chats, and warrants reach chat content.
  • There's no legal privilege. Sam Altman admits OpenAI can be forced to produce your chats, and a federal judge ruled in 2026 that a defendant's AI chats weren't privileged.
  • Private AI you can verify exists. Local models keep everything on your machine, and enclave-based apps like Maple check the server's code before sending a word.

Is ChatGPT private?

Private means nobody but you can read it. ChatGPT fails that test by design, because OpenAI holds the plain text of your conversations on its own servers. Every privacy setting it offers is a rule about what it does with text it can already read.

Bitcoiners know this model. It's the custodial exchange, and OpenAI keeps pushing further in that direction, with ChatGPT Work now holding your logged-in website sessions on OpenAI's servers.

Paying doesn't change the architecture. Plus and Pro run under the same consumer rules as the free tier, minus the ads. Business and Enterprise plans aren't trained on by default, but your employer's workspace admins can view, export and delete your conversations.

Does ChatGPT save your conversations?

Yes. OpenAI's retention policy is blunt: "Chats are saved to your account until you delete them manually." Delete one and it's scheduled for permanent deletion within 30 days, unless OpenAI has de-identified it or "must retain it longer for security or legal obligations."

Memory widens the footprint. ChatGPT automatically remembers context from your chats, files and connected apps, and wiping the memory summary doesn't wipe what it learned. To fully remove something, OpenAI says you have to delete every place it appears. On his November 2025 episode, Mark compared it to a biographer who writes your life story and never lets you read it.

Temporary Chat is the closest thing to off the record. Those chats stay out of your history and aren't used for training, but OpenAI keeps a copy for up to 30 days "for safety purposes."

The court order that kept "deleted" chats

On May 13, 2025, in The New York Times' copyright suit against OpenAI, Magistrate Judge Ona Wang ordered OpenAI to "preserve and segregate all output log data that would otherwise be deleted", including chats users had asked to delete. OpenAI said that covered Free, Plus, Pro and Team users and most API customers.

The order ended September 26, 2025, under a stipulation Judge Wang signed on October 9. OpenAI still holds the logs it preserved before then, except for users in Europe, Switzerland and the UK, and it keeps preserving chats from accounts tied to domains the news plaintiffs flagged.

Then it went further. In January 2026, Judge Sidney Stein upheld an order forcing OpenAI to hand over 20 million de-identified ChatGPT logs, noting users "voluntarily submitted their communications." As of September 2026 the case grinds on. The Times accuses OpenAI of deleting billions of outputs in violation of the preservation order, which OpenAI denies, and OpenAI moved for summary judgment on September 4 with no trial date set.

Mark put it plainly when we talked in November 2025. A retention promise "is just a business promise," and "the courts can just immediately tell" a company to keep your data longer than it said it would.

Who can see your ChatGPT conversations?

More people than you'd guess.

OpenAI. The privacy policy lets OpenAI prevent misuse "including by monitoring any Content submitted." When its systems flag someone planning to hurt others, a small team of human reviewers reads the conversation, and imminent threats can go to law enforcement.

Your employer. On ChatGPT Business and Enterprise, workspace admins can view and export your chats.

The government. OpenAI's law enforcement policy releases your name, email and payment details for a subpoena and your chat content for a warrant. Its latest transparency report shows that from July through December 2025 it received 75 requests for chat content and handed over data in 62 of them.

Anyone with a link. A shared link from a personal account works for anyone who has it, never expires, and deleting it doesn't erase copies someone already saved.

Courts, cops and the missing privilege

Sam Altman said it on Theo Von's podcast in July 2025. Talk to a therapist, lawyer or doctor and "there's legal privilege for it," but OpenAI would be "legally required to produce those conversations today". No AI privilege law exists.

Judges have noticed. In February 2026, Judge Jed Rakoff ruled in United States v. Heppner that documents a defendant generated with Anthropic's Claude had neither attorney-client privilege nor work-product protection, in part because Anthropic's privacy policy reserves the right to share user data with third parties. OpenAI's policy reserves the same kind of right.

So have the cops. In October 2025, Homeland Security Investigations served the first known federal search warrant asking OpenAI for user data, and OpenAI apparently complied. That same month, prosecutors charging a man over the Palisades Fire cited an image he'd made with ChatGPT and a question he'd asked it about whether you're at fault if your cigarette starts a fire.

Does ChatGPT use your data for training?

Yes, unless you tell it not to. You opt out by turning off "Improve the model for everyone" under Settings, then Data Controls. The catch sits in that same help article: give feedback and "the entire conversation associated with that feedback may be used to train our models," even with the setting off.

Business, Enterprise and API customers get the opposite default.

In May 2026, Canada's privacy commissioner and provincial regulators found that OpenAI should have obtained express consent before training on users' conversations. Mark's view from our November 2025 conversation: "at the least it should be opt in."

Does ChatGPT sell or share your data?

OpenAI's privacy policy says "We don't 'sell' Personal Data." It does share data with vendors, affiliates, marketing partners, and government authorities when the law requires it.

It also shows ads to Free and Go users. With ad personalization on, ChatGPT picks ads using your past chats and memories, while OpenAI promises to keep "your conversations with ChatGPT private from advertisers".

Fine. They don't need to sell your data when they can rent out your attention with it.

Can ChatGPT conversations get leaked?

They already have.

In March 2023, a bug let some users see the titles of other people's chats and exposed the names, emails, payment addresses and last four card digits of 1.2% of Plus subscribers active in a nine-hour window.

In July 2025, shared conversations started showing up in Google and Bing through an opt-in "discoverable" checkbox. OpenAI pulled the feature, admitting it "introduced too many opportunities for folks to accidentally share things they didn't intend to." Mark pointed out on our November episode that the Internet Archive had already grabbed copies. I've sent ChatGPT share links to the Ten31 team myself, and I couldn't swear to him that none of them hit Google.

It's an industry problem. We covered how every major AI lab's hidden reasoning was exposed by a single bad key, and how researchers found OpenAI's identity verification vendor running hundreds of checks on users' selfies.

What you should never tell ChatGPT

Don't type anything you wouldn't want read aloud in a deposition. Google gives Gemini users nearly the same warning: don't enter confidential information you wouldn't want a reviewer to see.

Keep these out:

  • Seed phrases, private keys, passwords and API keys. Obvious to freaks, but people paste screenshots and config files every day.
  • Account numbers, Social Security numbers and ID documents.
  • Health details and relationship problems you'd hate to see in a court filing.
  • Client files, if you're a lawyer, accountant, doctor or advisor. The Heppner ruling treated an AI company as a third party.
  • Company secrets. Mark's point on our first OpenSecret conversation was that a model trained on your deal analysis gets smarter for your competitors.
  • Anything tied to a crime, a lawsuit or a divorce. Your chat history is evidence.

How to make ChatGPT more private

If you're keeping ChatGPT, and plenty of us are, do this this week:

  1. Turn off training. Go to Settings, then Data Controls, and switch off "Improve the model for everyone." Stop hitting thumbs up and down.
  2. Use Temporary Chat for sensitive questions, and pick the non-personalized version so it doesn't pull in your memories.
  3. Delete and turn off memory under Settings, Personalization, Memory, then delete the old chats that fed it.
  4. Delete old chats and every shared link you don't need.
  5. Turn off ad personalization if you're on the Free or Go plan.
  6. Keep your identity out. Skip the Google sign-in tied to your whole life, and scrub names and numbers before you paste.

Every step on that list is a request OpenAI chooses to honor. You don't hold the lock on any of them, and a court order or warrant reaches whatever OpenAI still has.

Is Claude or Gemini more private than ChatGPT?

Marginally, and in different ways. All three companies can read what you send.

Claude. Since Anthropic's August 2025 terms update, you choose whether your chats train its models. Say yes and Anthropic keeps them for five years. Say no and it's 30 days. Chats flagged by its safety systems are kept up to two years, and Incognito chats never train the model.

Gemini. Google's privacy hub says human reviewers, including people at outside contractors, read some conversations, and reviewed chats are kept up to three years even after you delete your activity. Turn Keep Activity off and chats still sit with your account for 72 hours. Leave it on, which is the default for adults, and auto-delete kicks in at 18 months.

Here's the comparison as of September 2026.

AssistantKeeps chatsTrains on them?Who can read themPrivacy rests on
ChatGPT (Free, Plus, Pro)Until you delete, then up to 30 daysYes, unless you opt outOpenAI reviewers, business admins, warrantsOpenAI's policy
Claude30 days, or 5 years if you allow trainingYour choiceAnthropic's safety team, legal processAnthropic's policy
Gemini18 months by default; reviewed chats up to 3 yearsYesGoogle and contract reviewersGoogle's policy
MapleEncrypted history on your accountNoBuilt so Maple can'tAn attestation your app checks
VeniceOn your deviceNot statedModel providers in Anonymous modeContracts, or attestation in TEE modes
Proton LumoZero-access encrypted historyNoLumo's servers while answeringProton's policy
Brave LeoNot storedNoNobody keeps itBrave's policy
Duck.aiOn your deviceProviders barredOpenAI, Anthropic and others, minus your IPDuckDuckGo's contracts
Local modelYour own diskNoYouYour own hardware

What private AI looks like

Mark laid out the spectrum on our first conversation about OpenSecret in February 2025. At one end, a model on your own computer with the internet unplugged. At the other, ChatGPT, where "you're just trusting this company." In between sit "private AI" services he compared to old VPNs: "you're hoping that they don't log."

Local models

Run an open-weight model on your own hardware with Ollama and nothing you type leaves the machine. Privacy Guides recommends only local tools for AI chat, and Mark agrees: "the most private AI is the local AI, where you can turn off your Internet."

The catch is horsepower. LM Studio recommends 16GB of RAM just to get started, and the open models that rival ChatGPT need far more than most people own.

Confidential computing

Secure enclaves are chips that wall off memory the server's owner can't inspect. The hardware signs a report, called an attestation, stating exactly what code is running, and your app checks it before sending anything.

Apple built the reference design. Private Cloud Compute is built so personal data is "never available to anyone other than the user, not even to Apple staff, not even during active processing," and Apple offers bounties of up to $1 million to researchers who break it. It only powers Apple Intelligence, though, so you can't bring it your own questions.

Where Maple fits

Maple applies that design to a general assistant that runs on the web, iOS, Android, macOS, Linux and Windows. Here's the chain, from its open-source code:

  1. The backend handling your login, keys and encrypted storage runs inside AWS Nitro Enclaves.
  2. Your app checks the enclave's signed attestation against approved code measurements before trusting the connection, and production apps refuse to connect if the check fails.
  3. Each server build's measurement is signed and added to a public history, so anyone can rebuild the code and compare.
  4. Messages travel encrypted to that enclave. Proxies along the way see size and timing, not content.
  5. Models run on confidential-computing GPUs at Tinfoil and at Edgeless Systems' Privatemode.

OpenAI asks you to believe it will handle your data responsibly. Maple built a system that can't read your chats and gave you the tools to check.

Now the limits, because a bitcoiner should know exactly what he's trusting:

  • Your keys aren't only on your phone. Unlike Signal, keys can be derived inside Maple's enclave. The promise is that the enclave runs published code nobody at Maple can quietly change.
  • You're trusting hardware. That means AWS Nitro chips, NVIDIA's confidential GPUs and their attestation roots, and enclaves as a class have had published side-channel attacks. Maple's own README admits source code "does not by itself prove" how the live system is configured.
  • Metadata exists. Maple's privacy notice lists account details, payment information and your IP address.
  • Web search leaves the enclave through Brave's search API, anonymized but readable by Brave.
  • Open models only. You get the Kimi, GLM, DeepSeek, GPT-OSS, Gemma and Llama families, with no GPT, Claude or Gemini. Mark told me in March 2026 that "the open source models have caught up." For most of my work that holds, but the closed labs can still pull ahead on the hardest tasks.

Maple's plans are Free at 25 messages a week, Pro at $20 a month, Max at $100 and Team at $30 per user. Pay for a year of Pro or Max in bitcoin through Zaprite and you get 10% off, though not on Team or inside the iPhone app, and you can open an account with a generated ID instead of an email. Try it at trymaple.ai, or read our Maple AI review for the hands-on version.

The other private options

AI privacy is the new bitcoin privacy

That's the title of Mark's March 2026 episode, and I believe it more every month.

An exchange's promise to hold your coins is a policy. Holding your own keys is a property. An AI company's privacy policy is the same IOU with a different logo, and you just watched a court rewrite one. Don't trust, verify.

The stakes keep climbing. People are handing agents like OpenClaw the run of their entire machine, which Mark called "like a virus" because you're "giving it, like, full root access to everything that you have." Read his full case on giving an AI agent full access to your computer. I run my own agent on a rented server for that reason, as I wrote when I first set up OpenClaw.

Then come the wearables. Mark expects most people to talk to AI through something they wear within three to five years, and OpenAI is reportedly building an always-on home speaker with a camera. If nobody can inspect that code, you paid a few hundred dollars for a wiretap in your kitchen.

Here's the bull case. Mark's argument in March was that people are "much more open" with an AI they know is encrypted, "and that is where the most private AI can now become the most personal AI." I'd never upload our company books to OpenAI, but as I told him during our privacy-first AI conversation, I'm comfortable doing it with Maple. The assistant you can be honest with is the one that's useful.

"Privacy really is upstream from freedom," as Mark put it.

Treat what you type into a chatbot like your seed phrase.

Frequently Asked Questions

Yes. OpenAI staff can review flagged conversations, Business and Enterprise admins can export workspace chats, anyone with a shared link can read that chat, and OpenAI releases chat content to police with a warrant.

For up to 30 days, and longer if they're de-identified or OpenAI has a legal or security reason. A 2025 court order made OpenAI preserve deleted chats until September 26, 2025, and it still holds what it preserved.

Barely. Plus has no ads but follows the same consumer privacy rules, including training by default. Business and Enterprise plans aren't trained on by default, but your employer's admins can access your chats.

No. OpenAI can read your chats, courts can compel them, and a federal judge ruled in 2026 that a defendant's AI-generated documents weren't privileged.

It helps. Temporary Chats stay out of your history and training, but OpenAI can keep a copy for up to 30 days.

It has. A 2023 bug exposed other users' chat titles and some Plus subscribers' payment details, and in 2025 shared chats marked discoverable showed up in Google.

Not from Anthropic. It keeps consumer chats for 30 days, or five years if you allow training, holds flagged chats for up to two years, and its trust and safety staff can access conversations.

A local model on your own computer, because nothing leaves the machine. If you need cloud-scale models, pick one that runs inside secure enclaves your app can verify, like Maple, over one that asks you to trust a policy.

Keep reading

All of TFTC

The Bitcoin Brief

Bitcoin, markets, energy, and the tech reshaping all three.

A daily brief on the freedom tech building a parallel economy, written for the curious and the convicted alike. Signal, not noise. Truth for the Commoner.

Free, daily. Unsubscribe anytime.