All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
ChatGPT collects more than most people realize. OpenAI's privacy policy, updated February 6, 2026, says it collects your prompts, uploaded files, images, audio and video, your IP address, your device details, your general location, and your date of birth. Connect your contacts, and it uploads your device address book too.
But two big changes have raised even more data privacy concerns. OpenAI started testing ads in ChatGPT in the U.S. in February 2026, and ad personalization can draw on your past chats and memory. A federal judge also ordered OpenAI to hand over 20 million conversations in a copyright case, showing how easily chatbot logs can be pulled into litigation.
Below we cover what ChatGPT collects, five things you should never type into it, how to turn off training and memory, and what parents should know.
What data does ChatGPT collect?
5 things you should never tell ChatGPT
5 ChatGPT risks to look out for
How to delete your ChatGPT data and turn off training
Is ChatGPT safe for kids?
How to use ChatGPT more safely
Bottom line: Is ChatGPT safe?
FAQs
Is ChatGPT safe?
ChatGPT is reasonably safe to use, with one large caveat: it isn't private. OpenAI stores your conversations, uses them to improve its models unless you turn that off, and can be legally required to produce them. Your chats don't carry the legal privilege that protects what you tell a lawyer, doctor, or therapist.
So the useful question isn't whether ChatGPT is safe. It's what is safe to input into the chat. Keep identifying, medical, financial, and work information out of the chat box, and your risk drops sharply. Type those things in, and you've handed them to a company that may have to produce them in court.
What data does ChatGPT collect?
ChatGPT collects a lot of data. The entire premise of large language model (LLM) software is built on reading and analyzing billions of data points for machine learning.
Here's what OpenAI's privacy policy says it collects.
What you give it:
- Account information. Your name, contact details, account credentials, date of birth, payment information, and transaction history
- Everything you put in. Your prompts, plus files, images, audio, video, and data from any services you connect
- Your device address book, if you choose to connect your contacts
What it collects automatically:
- Log data. Your IP address, browser type and settings, and the date and time of every request
- Usage data. The features you use, the actions you take, your time zone, your country, your device type, and the people you interact with
- Device information. Device name, operating system, device identifiers, and browser
- Your general location, based on your IP address. Some features let you share precise GPS location if you choose.
- Cookies and similar technologies
What it gets from elsewhere:
- Data from security and safety partners, and from marketing vendors
- Publicly available information from the internet, used to develop its models
Whether it's Zoom gathering AI data to train its tool, Bing crawling the web to make its search more sophisticated, or Meta harvesting your social media data, AI learns through data collection.
Does ChatGPT save your chats?
Yes. OpenAI saves your conversations by default and uses them to improve its models unless you turn that setting off. When you do delete something, OpenAI says it removes the data from its systems "within 30 days," with exceptions.
The biggest exception is legal. OpenAI's policy states it plainly: "If we are legally required to retain your data (for instance, we receive a lawful subpoena) then we may retain it for the duration of the relevant legal or regulatory obligation."
That isn't hypothetical. Chatbot conversations have already turned up in court, and in January 2026 a federal judge ordered OpenAI to produce 20 million ChatGPT conversations in copyright litigation brought by news organizations.
There's one more catch. If you had model training turned on, OpenAI notes that deleted content may already have been "de-identified and disassociated from your account." Deleting the chat doesn't remove it from what the model learned.
Is ChatGPT private?
No. Your conversations are private from other users, but not from OpenAI or a court. OpenAI also says it monitors content submitted on its platforms to prevent fraud and misuse, and that it may share your data with government authorities when it believes it's legally required or necessary to protect safety.
OpenAI stores data on servers in the United States and in other countries where its affiliates, partners, and vendors operate.
There's one way a chat stops being private that has nothing to do with OpenAI's policies. ChatGPT lets you share a conversation through a link, and OpenAI's privacy policy lists that as a disclosure path. Those links can be picked up by search engines once they've been posted anywhere crawlable. 404 Media found roughly 100,000 shared ChatGPT conversations searchable on Google, and shared Claude chats turned up the same way, exposing medical records, internal company documents, and children's names and phone numbers.
Deleting the chat afterward may not undo it. Once a page has been indexed or archived, copies can persist somewhere else.
Does ChatGPT use your chats to show you ads?
It can, and this part is new. OpenAI began testing ads in ChatGPT in the U.S. on February 9, 2026. Ads appear on the Free and Go plans. Plus, Pro, Business, Enterprise, and Edu accounts don't get them, and OpenAI says it doesn't show ads to accounts it identifies as belonging to users under 18.
If ad personalization is on, ad selection can use your current chat thread, how you interact with ads, and your past chats and memory. OpenAI says advertisers never receive your chats, chat history, memories, name, email, precise location, or IP address, and that it doesn't sell user data to advertisers. Advertisers get aggregated numbers like views and clicks.
You can change this. Go to Settings > Ad Controls, where you can turn off ad personalization, see the topics being used to target you, and delete your ads data. OpenAI says deleted ad data can take up to 30 days to clear its systems. Turning off personalization doesn't remove ads; it narrows what informs them.
Two other things worth knowing: ads don't appear in Temporary Chats, and OpenAI says ads aren't eligible to run near personal health, mental health, or political content.
5 things you should never tell ChatGPT
The Wall Street Journal put a version of this list on the map in March 2025.[1] The categories still hold up. What's changed since is why they matter: your chats can now be subpoenaed, and they can now feed ad targeting.
1. Identifying information
Your Social Security number, driver's license or passport number, date of birth, home address, and phone number. OpenAI says it removes deleted data within 30 days, but the subpoena exception means a court can reach it first. Anything you'd redact before handing a document to a stranger belongs out of the prompt.
2. Medical and health details
A chatbot isn't a doctor, and your conversation with it isn't covered by HIPAA. ChatGPT's memory can also carry a health detail forward into future chats unless you delete every place it appears. If you want to ask a health question, strip out anything that identifies you.
3. Financial information
Account numbers, balances, card details, and the specifics of your finances. OpenAI's policy says it already collects your payment information and transaction history, so there's no reason to add more by typing it into a prompt.
4. Work and client information
Source code, contracts, client names, internal documents, and unreleased plans. This is the one most likely to cost you your job rather than your money. On a personal account, your employer has no visibility into where that content goes, and OpenAI may use it to improve its models unless you've turned that off.
5. Passwords and account credentials
Some people paste logins into ChatGPT so it can complete a task for them. Don't. Credentials in a chat log are credentials in a database you don't control, and stolen ChatGPT logins already trade on dark web markets. Use a password manager instead.
What else to keep out of ChatGPT
Three more that don't make most lists:
- Other people's information. Your decision to share doesn't cover your coworker's salary, your friend's diagnosis, or your kid's school schedule.
- Details of a legal matter. A federal judge has already ruled that a user's chatbot conversations about a potential legal defense weren't privileged, because the chatbot isn't a lawyer.
- Anything you wouldn't read aloud in a courtroom. That's the practical test, and it covers the cases nobody has thought of yet.
5 ChatGPT risks to look out for
Beyond what you type in, there are five risks worth knowing about.
1. AI-powered phishing scams
AI-powered phishing scams are more malicious than standard phishing due to the level of personalization they can achieve.
A phishing scam is usually released en masse to see what audiences it can hook — hence the name. AI-powered attacks can act more like spear phishing — targeted and precise. Sensitive data already in the wild gets harvested by hackers and fed into AI to create convincing, personalized attempts, making it harder to spot phishing scams.
Given the sophistication of these emails, a good rule to follow is to double-check the source and respond only via the verified website.
For instance, if the U.S. Postal Service (USPS) says your package needs additional information to be delivered, don't click the link provided in the email. Rather, go to usps.com and log in from there. If the request is valid, there should be a message or alert waiting for you.
2. AI-powered malware
Just as ChatGPT can take your resume and tailor it to a job description, hackers can use AI to create polymorphic malware. That means it's sophisticated enough to change its behavior to avoid detection.
Malware samples captured in the wild are shared and categorized to help anti-malware software recognize and block them. When malware becomes polymorphic, each new strain needs to be identified and categorized all over again.
3. Inaccurate info
One of the biggest criticisms from ChatGPT's early adopters was the misinformation in many of its answers.
Ask it for a recipe, and you'll likely get a good one. Ask it to verify something for you, and you can get a confident answer built on aggregated data that's wildly inaccurate. OpenAI's own privacy policy says you "should not rely on the factual accuracy of output from our models."
AI models are also updated without notice, and accuracy can vary between versions. Make sure you always double-check your facts.
4. Malicious ChatGPT apps and plugins
ChatGPT itself is not malicious, but there are malicious apps and plugins out there that claim to be ChatGPT.
If you accidentally download and install one of these, a good antivirus and anti-malware can keep the hackers from installing more on your machine. To avoid them in the first place, make sure you're only using ChatGPT from OpenAI's website or from a verified source.
5. Data privacy issues
If AI is learning from our interactions with it, then it's storing all that data somewhere. That poses security risks.
There's always the concern that one of these AI companies will suffer a data breach and give up swaths of user data as a result. OpenAI holds your prompts, your uploaded files, your account details, and whatever its memory has retained, which makes for a large target.
How to delete your ChatGPT data and turn off training
By default, OpenAI saves your conversations and uses them to improve its models. You can change both, but they're separate controls and it's worth being clear about what each one does.
Turning off Improve the model for everyone stops OpenAI using new conversations to train its models. It does not delete anything. OpenAI is explicit that your conversations "will still appear in your chat history." To remove chats, you delete or archive them. To remove everything, you delete your account, and that can't be undone.
How to turn off training using the web app
- Log in to ChatGPT's website.
- Click your profile icon.
- Click on Settings.
- Click on Data controls.
- Toggle off the control by Improve the model for everyone, or…
- To fully delete your account, click the red delete button beside Delete account.
If you're signed out, you can still do this. Click the ? icon in the bottom-right corner, select Settings, and turn off Improve the model for everyone. The setting syncs across your whole account once you're signed in, so it doesn't matter which device you use.
How to turn off training using the mobile app
- Open your ChatGPT app.
- Open the side-bar menu.
- Tap your profile icon.
- Select Data Controls.
- You can then toggle off Improve the model for everyone or…
- You can Clear chat history, or…
- You can Delete account.
How to remove ChatGPT data without logging in
- Go to the OpenAI Privacy Request Portal.
- Click “Make a Privacy Request” in the top right.
- The pop-up prompts you to select the account verification method, either via email or phone number. You could also select that you don't have an account. We selected email for these instructions.
- You should then see a pop-up with four options: Do not train on my content, Delete my ChatGPT account, Download my data, and ChatGPT personal data removal request.
- Choose Do not train on my content to prevent ChatGPT from using future conversations for its training. You’ll then be prompted to enter your email address.
- Click Send Email, and OpenAI automatically sends your request. You should then receive an email response with a link to verify your identity and begin opting out of ChatGPT using your data for training.
- To delete your account, choose Delete my ChatGPT account and enter your email address.
- Click Send Email, and you’ll then receive an email with a link to verify your information and start the deletion process.
- To have any ChatGPT data that's been collected removed, select the ChatGPT personal data removal request.
- When prompted, add your email address and click Send Email.
- Follow up in 7-14 days if you haven’t heard back.
How to turn off ChatGPT's memory
Memory is separate from training, and it's the control most people miss. When it's on, ChatGPT remembers context from your chats, files, and connected apps and carries it into future conversations.
Controls live at Settings > Personalization > Memory. From the three-dot menu, you can select Delete and turn off memory.
Two things to know before you rely on it. Deleting your memories doesn't delete your past chats, and if you turn memory back on, OpenAI says ChatGPT "may create new memories from chats that remain in your chat history, including older chats." To remove something completely, OpenAI says you have to delete "every source where it appears, including past chats, archived chats, files, the memory summary, and disconnect any connected apps that may contain that information."
Under the older saved memories system, memories sit separately from your chat history, which means deleting a chat doesn't remove a memory created from it.
How to use Temporary Chat
Temporary Chat is the simplest option if you want one conversation to leave no trace. OpenAI says Temporary Chats aren't used to train its models, don't get saved in your history, don't create memories, and show no ads. OpenAI deletes them from its systems after 30 days.
One limit: OpenAI says Temporary Chats "may be reviewed only to monitor for abuse." Temporary isn't the same as invisible. Turning off memory and personalization also doesn't disable safety features, which OpenAI says may still use limited safety-relevant context in rare, high-risk situations.
Is ChatGPT safe for kids?
OpenAI says ChatGPT isn't directed to children under 13 and that it doesn't knowingly collect their data. Users under 18 are supposed to have a parent or guardian's permission.
ChatGPT gives parents more than most chatbots do. Teens and parents can link their accounts, which lets a parent manage certain settings and receive alerts if OpenAI detects a serious safety concern. OpenAI also says it doesn't show ads to accounts it identifies as under 18, using stated age plus behavioral signals. That's more than DeepSeek offers, though less than the ID-based age verification Character.AI now runs.
It's also under pressure to do more. The EU designated ChatGPT under the strictest tier of its Digital Services Act in August 2026, which requires default privacy protections for minors by January 2027. OpenAI is separately facing litigation in Florida over how it marketed ChatGPT's safety for children.
Account linking depends on your teen agreeing to it, and either side can unlink at any time. If you want oversight that doesn't rest on the platform's own settings, parental controls work at the device and app level instead. They can limit which apps get installed, cap time per app, and show you what's actually being used.
Aura Parental Controls is our top parental control app for teens. It sets per-app time limits and lets you pause internet access from the dashboard.
How to use ChatGPT more safely
None of this means giving up the tool. It's mostly about what you type and which settings you change.
- Turn off model training. Settings > Data Controls > turn off Improve the model for everyone.
- Turn off memory if you don't want details carried between chats. Settings > Personalization > Memory.
- Turn off ad personalization. Settings > Ad Controls, where you can also delete your ads data.
- Use Temporary Chat for anything sensitive. No history, no memories, no training, no ads.
- Audit your shared chat links. Any conversation you've shared through a link can be indexed by a search engine. Review the links you've created and revoke the ones you no longer need.
- Don't connect your contacts. OpenAI's policy says connecting contacts uploads your device address book.
- Sign up with a masked email. We used Apple's Hide My Email feature for our account, which can't be tied back to us in the event of a data breach.
- Treat every chat as discoverable. If you wouldn't want it read back to you in a deposition, don't type it.
At the very least, you'll have more control over how you keep your data private online.
Bottom line: Is ChatGPT safe?
ChatGPT is safe to use, but it isn't private. OpenAI stores your prompts, files, device details, and general location. It uses your conversations to improve its models unless you turn that off. Its memory carries details between chats, its ads can be personalized using your past chats, and any conversation you share through a link can end up in a search engine. OpenAI can also be legally compelled to produce your conversations, which has already happened.
ChatGPT is best for drafting, summarizing, brainstorming, and learning. For anything touching your identity, your health, your money, or your employer's business, use it with the details stripped out. Turn off training, turn off ad personalization, and use Temporary Chat when it matters.
If there's a teen in your house using AI chatbots, parental controls give you oversight that doesn't depend on OpenAI's settings.
FAQs
Should I tell ChatGPT my real name?
There's no need to. ChatGPT already has the name on your account, so typing it into a prompt only adds it to your conversation log. OpenAI can be legally required to produce those logs, and if memory is on, your name can be carried into future chats. Leave it out of the chat box.
Can ChatGPT be trusted?
Trusted to do what matters here. OpenAI is a real company with a published privacy policy and working data controls, so ChatGPT isn't a scam or malware. But you shouldn't trust it with confidential information because your conversations are stored, may be used for training unless you opt out, and can be produced in legal proceedings. You also shouldn't trust ChatGPT for factual accuracy. OpenAI's own policy says you "should not rely on the factual accuracy of output from our models."
What are the risks of using ChatGPT?
The main ones are data exposure and accuracy. Everything you type is stored and may be used to train OpenAI's models unless you turn that off, and your conversations can be subpoenaed. Beyond that, fake ChatGPT apps and download pages spread malware, stolen ChatGPT logins circulate on dark web markets, and the model can give you confident answers that are wrong.
Is it safe to give ChatGPT your phone number?
Giving your phone number to OpenAI is just as safe as providing it to sign up for any other service.
We would suggest, however, not typing your identifying information, like your phone number, into ChatGPT, as that data is stored and used for machine learning purposes. Who knows if the system will glitch and your number will suddenly be included in someone else’s search results?[1]
Is ChatGPT a scam?
No, ChatGPT is not a scam, although there are ChatGPT-related scams. Scammers and hackers target businesses and individuals and create fake, ChatGPT-cloned sites that ask you for your personal credentials, financial information, and other personal data to access your accounts. Remember that the real ChatGPT is through the parent company, OpenAI, and won’t ask you to provide sensitive information.
What is ChatGPT?
ChatGPT is an AI chatbot from OpenAI that answers questions and generates text conversationally. It can draft and rewrite documents, summarize material, write code, analyze uploaded files, and search the web. For instance, you can paste in your resume and a job description and ask it to restructure the resume for that job.
Does ChatGPT take information from your computer?
Yes. ChatGPT collects information from any device you use to access it, including your IP address, device name, operating system, device identifiers, browser, and your general location based on your IP address. If you choose to connect your contacts, OpenAI says it uploads information from your device address book. Some features also let you share precise GPS location, though that's opt-in.
[1] Nicole Nguyen, "The Five Things You Shouldn't Tell ChatGPT," The Wall Street Journal, March 30, 2025
[2] ChatGPT Bug Temporarily Exposes AI Chat Histories to Other Users