Data safety
Is ChatGPT safe for company data? It depends on the plan.
The same AI tool treats your data very differently depending on whether you use a personal account or a business one. Here's what the major providers say in their own policies, what should never go into a chat window, and a one-page AI policy you can adapt for your team.
The short answer
A business plan is generally the safer choice for company data. A personal account is fine for general questions, but it's the wrong place for customer names, financial records or anything confidential, unless you've changed its settings and understand what they do.
The difference is mostly about training. On personal plans, providers may use your conversations to improve their models unless you opt out. On business plans, the major providers say they don't train on your data by default.
What each provider says
Summarized from each provider's own policy pages as of September 23, 2026. Policies change, so check the source before relying on this for anything sensitive.
| Tool and plan | Used for training? | Details |
|---|---|---|
| ChatGPT Free, Plus, Pro (personal) | May be, unless you opt out | OpenAI says it may use content from its services for individuals to train models. You can opt out in settings or through its privacy portal. Temporary Chats aren't used for training. |
| ChatGPT Business, Enterprise, API | No, by default | "By default, we do not train on any inputs or outputs" from business products. Business costs $20 per user per month billed annually, with a two-seat minimum. |
| Claude Free, Pro, Max (personal) | Your choice | Anthropic asks personal users whether chats can be used to improve its models. If you allow it, data is kept for up to five years. If you don't, the standard retention period is 30 days. |
| Claude Team, Enterprise, API | No, by default | These fall under Anthropic's commercial terms, which the personal-plan change doesn't cover. Team lists "no model training on your content by default." |
| Microsoft 365 Copilot Chat (work account) | No | Under Microsoft's enterprise data protection, prompts and responses aren't used to train foundation models, and your existing Microsoft 365 permissions apply. |
| Gemini in Google Workspace | No, without permission | Google says Workspace content isn't used to train its generative AI models outside your domain without your permission. |
"Not used for training" doesn't mean "never stored." Business plans still store chats so you can see your history, under the provider's security and retention terms. It also isn't the only risk. The bigger everyday risk is an employee pasting something into a personal account the business doesn't control.
The cautionary tale everyone cites
In 2023, Samsung restricted staff use of generative AI tools after engineers uploaded sensitive internal source code to ChatGPT. The company's stated worry was that data sent to outside AI platforms is stored on external servers, where it's hard to retrieve or delete.
That happened on consumer tools, before today's business plans were common. The lesson still holds: the leak wasn't a hack. People pasted something they shouldn't have into an account the company didn't manage.
What should never go into a chat window
Even on a business plan, keep these out unless a specific tool has been set up and approved for them:
- Social Security numbers, bank account numbers and full card numbers
- Passwords, API keys and login links
- Health information about customers or employees
- Client tax return information, if you're a tax preparer. Section 7216 consent rules may apply; see AI for accounting firms.
- Anything you've signed a confidentiality agreement about
A one-page AI use policy you can copy
A small business doesn't need a twenty-page policy. It needs one page people will actually read. Copy this, fill in the brackets, and have everyone sign it. It isn't legal advice; if you're in a regulated field, have your advisor review it.
[Business name] AI use policy
Effective [date]. Owner: [name].
1. Approved tools. For work, use only these AI tools, signed in with your work account: [for example, ChatGPT Business, Claude Team, Microsoft 365 Copilot]. Don't use personal AI accounts for work.
2. Never enter. Social Security numbers, bank or card numbers, passwords, health information, [client tax return information], or anything covered by a confidentiality agreement.
3. Customer information. Use the minimum needed. Use first names or initials where you can.
4. A person checks the output. AI drafts; people decide. Review anything AI writes before it goes to a customer, vendor or government agency. You're responsible for what you send.
5. No prices, promises or legal statements from AI without [owner or manager] approval.
6. New tools. Ask [name] before connecting an AI tool to email, files, QuickBooks or customer systems.
7. Mistakes. If you paste something you shouldn't have, tell [name] the same day. We'd rather know.
8. Review. We review this policy every [six months].
Signed: ____________________ Date: __________
If you want help
For most small businesses, getting this right takes an afternoon: choose one business plan, move people off personal accounts, adopt the policy above, and switch on the settings that matter. If you'd like us to review which tools your team uses and set up the safe version, the first conversation is free.
Sources
- OpenAI: how your data is used to improve model performance (updated March 13, 2026)
- OpenAI: enterprise privacy and ChatGPT Business pricing
- Anthropic: updates to consumer terms and privacy policy and Claude plans and pricing
- Microsoft Learn: enterprise data protection in Microsoft 365 Copilot and Copilot Chat
- Google Workspace: generative AI privacy hub
- CNBC: Samsung bans use of AI like ChatGPT for staff after misuse (May 2, 2023)
Start here
Tell us what eats your week. We'll tell you if we can fix it.
The first conversation is free. If there's a fit, the $999 AI Assessment gives you researched solutions, estimated savings and a clear plan. Implementation is a separate choice.