Blog

Does ChatGPT store your data?

WitnessAI | August 29, 2026

ChatGPT stores conversation data by default. Retention depends on the subscription tier and account settings. In some cases, a court order can also change the retention period. The answer to “does ChatGPT store your data” therefore differs between personal and enterprise accounts.

The stakes became concrete in 2025. A federal preservation order required OpenAI to retain deleted and temporary chats from certain accounts for roughly five months. Organizations whose employees used personal accounts during that period may have limited visibility into conversations held for litigation.

This article explains what each ChatGPT tier retains and why deletion windows can change. It also covers how AI risk management governs what reaches ChatGPT, along with workforce governance and runtime defense.

Key takeaways

  • ChatGPT stores conversations by default, but retention, training use, deletion controls, and contractual protections vary across consumer, business, Enterprise, and API configurations.
  • Deleting a chat doesn’t always end retention because legal holds can extend storage and saved memories may preserve information separately from the original conversation.
  • Personal-account use creates an enterprise accountability gap by placing employee activity outside approved contracts, administrator settings, and organizational visibility.
  • Audit trails are essential for proving which data reached ChatGPT, which controls applied, and whether prompts or outputs may become discoverable electronic evidence.

Does ChatGPT store your data? What each tier retains

Yes. ChatGPT retains conversation data on consumer and business tiers alike. The tiers differ in whether content is used for training and how deletion works. They also assign retention controls differently.

Retention varies between consumer and business use. API use has its own rules.

  • Consumer accounts: On Free, Plus, and Pro accounts, chats stay on the account until a user deletes them. Deleted chats are generally scheduled for permanent removal within the 30-day deletion window, unless they have been de-identified or a legal obligation requires longer retention. On consumer plans, content may be used for model training by default unless the user opts out. Temporary Chats are excluded from training and ordinarily auto-deleted within 30 days.
  • Business and Enterprise accounts: Business tiers reverse the training default. Business-tier data isn’t used to train models by default, and Enterprise admins control retention duration for their workspace. Deleted conversations are ordinarily removed within 30 days unless OpenAI is legally required to keep them. Enterprise customers can access a data processing agreement. Consumer accounts don’t have equivalent enterprise contractual controls.
  • API configurations: Standard API inputs and outputs may be retained for a limited period for abuse monitoring. Qualifying customers can request Zero Data Retention for eligible endpoints. Some stateful API features retain data until the customer deletes it and aren’t eligible for ZDR. API settings determine how much data OpenAI keeps, so using the API doesn’t automatically guarantee zero storage.

If your organization processes personal data, check whether its arrangements satisfy the GDPR’s processor requirements. The available controls depend on the tier and contract. Endpoint configuration matters too.

Why deleted ChatGPT conversations may not be gone

The 30-day deletion window is a commitment with exceptions. Deleted chats are removed from the account and ordinarily scheduled for permanent deletion. However, de-identification and legal obligations can extend retention.

Two mechanisms can stretch the expected window:

  • Litigation holds: Court-ordered litigation holds can override standard deletion timelines. When a preservation order is issued, providers may have to retain chats, Temporary Chats, and API traffic that would otherwise be deleted. These orders often carve out enterprise-tier and Zero Data Retention customers, leaving consumer and standard API users most exposed.
  • Persistent memory: Research on saved memories shows that saved memories can persist separately from an individual conversation and create persistent memory risks across chat sessions. Deleting a chat therefore may not remove information carried forward through memory. The same study found that persistent instructions can enable continuing data exfiltration across sessions.

These mechanisms show why the default deletion period may not define the final retention period.

The blanket obligation ended in September 2025. OpenAI continues to hold historical April through September 2025 user data in a restricted legal-hold environment, and some flagged users remain affected.

You may have limited visibility into either mechanism when employees use personal accounts. Those accounts sit outside the contracts and retention settings the organization controls. They also don’t appear in its admin consoles. If your team handles regulated data, treat the 30-day figure as a default. Legal obligations can extend it.

The gap between OpenAI’s controls and your accountability

OpenAI’s business tiers address much of the storage risk on paper. Those controls offer less protection when employees use personal accounts instead.

Employees’ use of personally selected tools creates Shadow AI. These accounts may use training-on defaults and offer no enterprise data-processing agreement. They also offer no admin oversight and include the types of accounts swept into the 2025 preservation order.

Personal-account use also raises HR policy and brand-liability questions. HR and brand owners therefore join security and legal teams in deciding which uses are permitted. Compliance teams also need a role in those decisions.

Even with the right enterprise tier, your organization remains responsible for how employees use it. Under the AI shared-responsibility model, providers and customers have different obligations for people, governance, behavior, and policy. Model providers secure infrastructure. Prompt content and account selection generally remain enterprise obligations that vendor contracts rarely transfer away. The same applies to output handling.

Keyword and regex-based controls provide limited awareness of conversational intent. A paragraph of unreleased drug research may contain no word like “confidential” for a rule to match. Approved-tier admin controls also see activity only inside the provider’s managed environment. Network-level discovery can give security teams visibility into employees’ activity outside those controls.

Closing this gap is an AI risk management problem, broader than AI governance or compliance alone. It benefits from continuous discovery of AI destinations visible at the network layer, followed by classification of each interaction’s intent.

Enforcement as data moves also helps. So does an audit trail of evidence that can support regulatory review. These controls operate between employees and ChatGPT, outside either party’s console.

WitnessAI Control
CONTROL

Can You Prove How Your Organization Governs AI?

WitnessAI generates granular audit trails, enforces policies across every role and region, and redacts sensitive data before it ever leaves your network. Compliance-ready from day one.

See How Control Works

Governing what reaches ChatGPT with AI risk management

Effective ChatGPT governance starts before data reaches the model. When AI traffic is routed through or integrated with an enforcement layer, network-level controls can help organizations observe, classify, and enforce policies independently of the ChatGPT tier or account an employee uses.

Effective governance begins with discovery. Network-level visibility can reveal AI applications employees actually use, including activity outside the browser such as native applications, Windows Copilot, and developer tools, when that traffic is visible through the deployed integration. Without this visibility, shadow-AI use remains invisible to admin consoles tied to approved business accounts.

Discovery alone isn’t enough. Conversational context matters more than keywords, because a paragraph of unreleased research or a sensitive customer detail may contain nothing a regex would flag. Intent-based classification of user prompts helps distinguish legitimate business activity from higher-risk uses, while bidirectional visibility and runtime controls can also evaluate model responses.

That classification supports a wider range of enforcement actions than a simple allow-or-block model:

  • Allow: Legitimate work proceeds without interruption, keeping approved AI workflows available.
  • Warn: A user drifting against policy receives guidance before proceeding, allowing course correction without blocking productive work.
  • Block: Depending on the configured policy and protection path, a violating or malicious prompt can be stopped before it reaches the model.
  • Route: Redirect sensitive queries to an approved internal model, keeping the interaction within trusted infrastructure.

When tokenization is configured, sensitive information such as PII can be replaced before it reaches the AI model and restored for downstream workflows. This allows the model to operate on tokenized values rather than the original sensitive values.

Runtime protections also matter on the response path. Inspecting prompts before they reach the model and responses before they reach the user helps detect prompt injection and jailbreak attempts and filter harmful output. These checks complement existing network security controls by adding conversational awareness.

WitnessAI for Employees
FOR EMPlOYEES

Your Employees Are Already Using AI. Are You Governing It?

WitnessAI gives you full visibility into employee AI usage, classifies intent behind every interaction, and enforces smart policies, without slowing anyone down.

Learn About WitnessAI For Employees

Documenting ChatGPT data storage for the board

Whether ChatGPT stores your data depends on the tier. Your organization must also prove which data reached each tier and which policy applied. That proof becomes especially important when prompts and outputs become electronic evidence that must be disclosed in a case, known as discoverable ESI.

The 2025 preservation dispute showed how quickly organizations can be asked to produce evidence. Without internal evidence, you must rely on retention records from vendors and courts.

WitnessAI gives security and compliance leaders visibility into AI interactions routed through or integrated with the platform. Its intent-based policy engine can govern user activity, while bidirectional runtime protections can inspect prompts and responses in supported deployment paths. Audit trails provide evidence of the controls and policies WitnessAI applied to those interactions.

See how the platform works against your organization’s AI traffic, then schedule a demo to evaluate the controls in your environment.

FAQs about ChatGPT data storage