ChatGPT
- Your data trains their AI unless you switch it off in settings.
- Your data is used for personalized ads, including by third-party ad companies.
- Data is shared with partners and affiliates; you can opt out.
- The policy describes staff access for safety and legal checks.
You own chats, can turn off training and memory, but ads, and a $100 cap still apply.
Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.
Collected
Account info, your chats and uploads, device and usage data, and sometimes contacts or location.
Read the exact line
Privacy policy
“We collect Personal Data that you provide in the input to our Services (“Content”), including your prompts and other content you upload, such as files”
Training
They use your content to run and improve ChatGPT, and Free/Go users can see personalized ads.
Read the exact line
Privacy policy
“As noted above, we may use Content you provide us to improve our Services, for example to train the models that power ChatGPT.”
Sharing
Vendors, affiliates, and marketing partners can get data; they say they do not sell it.
Read the exact line
Privacy policy
“We don’t “sell” Personal Data. Depending upon your choices, we may share limited data with select marketing partners”
Kept
You can delete chats in the app; they say most of it is gone within 30 days.
Read the exact line
Privacy policy
“Once you choose to delete Personal Data, we will remove it from our systems within 30 days unless we need to retain it for longer as described below”
Controls
You can turn off training, wipe memories, use Temporary Chat, export data, and opt out of ads.
Read the exact line
Privacy policy
“You can easily choose whether your Content can be used to improve and train our models.”
Fine print
Auto-renewing paid plans, and capped at $100.
No exact line could be verified.
Expand “Read the exact line” to see the source alongside the explanation.
What you can turn off
The controls and opt-outs their own documents describe, and where they say to find them.
Turn off using chats to train models
Account settings / data controls (privacy.openai.com and in-app Data controls)
Turn off ad personalization or marketing sharing
Account advertising controls; Settings > Data Controls; or Your Privacy Choices / GPC
Export or delete chats and memories
ChatGPT account data controls; delete chats, Saved Memories, or the whole account
If a switch is not where they say, the deletion request above still applies.
Line by line
The lines that matter most, worst first.
If they cause harm, they generally will not pay more than what you paid in a year or $100.
Read the exact line
Terms of service
“OUR UNDER THESE TERMS WILL NOT EXCEED THE GREATER OF THE AMOUNT YOU PAID FOR THE SERVICE THAT GAVE RISE TO THE CLAIM DURING THE 12 MONTHS BEFORE THE AROSE OR ONE HUNDRED DOLLARS ($100).”
For example, if a bug deleted important work, they might only owe you $100 if you were on a free plan.
If you cancel a paid plan, you usually do not get money back for unused time.
Read the exact line
Terms of service
“Payments are non-refundable, except where required by law.”
For example, if you cancel Plus two days after renewal, they keep that month’s fee unless local law says otherwise.
If you are on a free or Go plan, they can show ads tailored to you unless you change settings.
Read the exact line
Privacy policy
“For Free and Go users, to personalize the ads you see on our Services (subject to your settings), and to measure the effectiveness of ads shown on our Services.”
For example, they might use what you chat about and partner purchase data to pick ads you see.
If you tap connect contacts, they upload your address book, including people who do not use ChatGPT.
Read the exact line
Privacy policy
“Contact Data: If you choose to connect your device contacts, we upload information from your device address books and check which of your contacts also use our Services.”
For example, your friend’s phone number could be uploaded even if they never signed up.
Your prompts and uploads can be used to train AI unless you turn that off.
Read the exact line
Privacy policy
“we may use Content you provide us to improve our Services, for example to train the models that power ChatGPT.”
For example, a private draft you paste in could help train future models if training is still on.
They can shut your account if they decide you broke the rules, without promising advance warning.
Read the exact line
Terms of service
“We reserve the right to suspend or terminate your access to our Services or delete your account if we determine:”
For example, a flagged chat could lead to a sudden lockout of your history.
You keep rights to what you type and they assign you rights in what the AI writes back.
Read the exact line
Terms of service
“As between you and OpenAI, and to the extent permitted by applicable law, you (a) retain your ownership rights in Input and (b) own the Output.”
For example, you can reuse a story ChatGPT wrote for you as yours, as far as OpenAI is concerned.
Memory that carries facts about you across chats can be controlled in settings.
Read the exact line
Privacy policy
“You can decide whether we will remember details between chats to make Content more personalized and relevant.”
For example, you can delete a saved memory that it knows your job or turn remembering off.
Words to know
Legal words from the lines above, in plain English.
- personal data
- Any information that is about you or can be linked to you, from your name to your phone's ID. For example, your email, your IP address and the list of apps on your phone are all personal data.
- inputs and outputs
- Inputs are what you type, say or upload to an AI; outputs are what it gives back to you. For example, the question you ask a chatbot is an input and its answer is an output, and both may be stored.
- prompt
- What you type or say to an AI to get a response. For example, asking a chatbot to write a birthday message is a prompt, and it may be stored.
- model training
- Using your content and conversations as examples to teach an AI system, which can then echo them in future answers. For example, a story you write in a chatbot may be studied by the company to make the next version of the bot.
- sell or share
- Under California law, selling means passing your data to others for money or other value; sharing means passing it on for targeted ads. For example, letting an ad network use your browsing history in return for ad space counts as a sale.
- retention
- How long a company keeps your data before deleting it. For example, a policy might keep your messages for 30 days after you delete them, or for as long as it likes.
- limitation of liability
- A cap on what the company will ever pay you if something goes wrong, often only what you paid in the last year. For example, if a leak of your data costs you thousands, the most you may get back is a month's subscription fee.
How we got here · grade C · score 45/100 · 15 of 15 policy answers backed by a verified quote · 0 not stated
What does the app collect beyond what it needs to work?
Besides account info and chats, they collect usage, device IDs, logs, optional contacts, optional precise location, cookies, and partner/ad data.
Does it record your voice, face or body, and what happens to that?
Audio and video you upload count as Content, which they may keep with your account and use to train models unless you opt out.
Are your chats and uploads used to train AI models, and is that off by default?
Content can be used to train models by default, but they say you can turn that off in account settings, and Temporary Chat is excluded.
Can employees or contractors read your conversations, and when?
They say they monitor content to stop fraud, illegal activity, and misuse and to protect safety, not that they routinely sample chats for other reasons.
Are you profiled or tracked for advertising?
Free and Go users get personalized ads; they get data from advertisers and share limited data with marketing partners via cookies.
Do they sell or share your data, and can you opt out?
They say they do not sell personal data, but they share limited data with marketing partners for ads, with an opt-out.
What rights do they take over what you type and what the AI makes?
You keep ownership of input and they assign you ownership of output; they still may use content to run and improve the service.
How long do they keep your data after you delete it, and can you delete it in the app?
You can delete chats or your account in the app; they say they remove it within 30 days unless safety, legal, or already used for training.
Does it build a lasting memory or profile of you, and can you see, edit or turn it off?
They remember details across chats if you allow it; you can delete specific Saved Memories and decide whether remembering is on.
Do they commit to basic security, and have they leaked data?
They describe commercially reasonable technical and organizational security measures, but no independent audit is named here.
Is there a real age gate, and are teens protected?
You must be 13 or older; under 18 needs parent permission. They do not describe a hard age check beyond that.
Will they tell you when the rules change, and is the policy specific?
Terms are dated and they promise 30 days’ notice for material adverse term changes; the privacy policy lists data types and purposes.
Can they close your account without warning, and can you get your data out first?
They can suspend or delete your account for rule breaks, legal reasons, or risk, without promising notice first (inactivity over a year does get notice).
If something goes wrong, who pays?
The service is “as is,” with no warranties, and their total liability is capped at what you paid in 12 months or $100. Businesses must indemnify them.
Do subscriptions renew on their own, and can you get a refund?
Subscriptions auto-renew until you cancel. Payments are non-refundable except where law requires it; they give 30 days’ notice of price increases.
If this app can act for you, does it warn you about scams?
May transact on unsafe websites on your behalf. OpenAI says a link check does not make the page trustworthy. This line is not from the privacy policy. We did not test the product. Keeping your data safe when an AI agent clicks a link (2026)
The privacy policy is 4,022 words at a college graduate level (Flesch reading ease 38.2); the terms are 3,305 words at a college level.