Is ChatGPT Safe?
For most everyday use, yes. ChatGPT is a mainstream product from a large company, it uses an encrypted connection, and it is not quietly reading your other apps. The real risk sits somewhere else: in what you type into the box, and in whether you trust the answer that comes back. Manage those two things and the rest is manageable too.
What OpenAI actually keeps
Your chats are saved to your account. They stay there until you delete them, and they show up in your history across every device you sign in on.
When you delete a chat, it disappears from your account straight away. OpenAI then schedules it for permanent deletion from its systems within 30 days, with exceptions for de-identified data or legal obligations.
Files you upload are handled separately. Deleting a chat does not always delete the file that went with it — those live in your Library and need deleting on their own.
There is also Memory, which pulls useful details out of your chats and reuses them later. Convenient — and also a record of you. Read exactly what it holds in Settings → Personalization → Memory, edit any line, or delete the lot.
One piece of history worth knowing: a US court once ordered OpenAI to preserve logs that would normally be deleted. That blanket order was terminated in October 2025, and now applies only to accounts the plaintiff has specifically named.
Three settings worth changing today
Most people never open Data Controls. These three are where the actual privacy lives.
- “Improve the model for everyone.” The training toggle, in Settings → Data Controls on the web, or the side menu → profile icon → Data Controls on mobile. Turn it off and your chats stay in your history but stop feeding model training. It follows your account across devices.
- Temporary Chat. An incognito window for ChatGPT. It stays out of your history, is not used for training, neither reads nor writes Memory, and leaves OpenAI’s systems within 30 days.
- Memory. Leave it on if you like the personalisation, off if you would rather start fresh each time. “Delete and turn off memory” does both at once.
Turning training off is not the same as turning storage off. Your chats still exist on your account until you remove them.
The rule that matters most: what not to type in
This is where people actually get hurt, and no setting saves you from it. Once you paste something, it has left your control.
Keep these out of a personal ChatGPT account:
- Customer or client records — names, addresses, order details, anything belonging to someone who never agreed to this.
- Medical records and test results, yours or anyone else’s.
- Passwords, API keys, access tokens and recovery codes.
- Code under NDA, and internal documents your employer hasn’t cleared for AI tools.
- Card numbers, account numbers and tax IDs.
Your plan changes the maths. On Business, Enterprise and Edu, OpenAI does not train on your data by default, admins control retention, and you keep ownership of what goes in and out. A personal account has none of that. If the work is your employer’s, use your employer’s workspace — and if there isn’t one, ask before you paste.
There is a flip side. On Business and Enterprise, an admin can view, export and delete workspace conversations. That protects the company. It also means work chats are not private from work.
Third parties matter too. In November 2025, an attacker exported data from Mixpanel, an analytics provider OpenAI used. Names, email addresses, rough locations and browser details were exposed for some users. Chats, passwords, API keys and payment details were not. “Safe” always includes everyone a service hands your details to.
Wrong answers are a safety problem too
Privacy gets the headlines, but the likeliest way ChatGPT causes you real trouble is by being confidently wrong.
It invents things. Studies of fabricated references keep finding the same pattern: a large share of the citations chatbots produce either do not exist or do not say what the model claims. Lawyers have been sanctioned for filing them.
Health questions are the sharp end. Research keeps flagging a meaningful slice of chatbot medical answers as problematic, and there is now US litigation over advice a chatbot gave. ChatGPT is a decent way to understand a term your doctor used. It is not a way to decide whether that chest pain needs an ambulance.
One habit fixes most of this. Ask for sources, then open them yourself. If the link does not exist, neither does the fact.
Fake ChatGPT apps and phishing pages
The app is safe. The thing pretending to be the app usually isn’t.
Attackers buy search ads and build download pages that copy OpenAI’s design closely enough to pass a glance, then serve password-stealing malware to Windows and Mac users. Fake “AI tool installers” carrying infostealers have run steadily through 2026.
There is a cleverer version. Attackers have abused ChatGPT’s own share-link feature to host fake outage pages on a real OpenAI domain, so the address bar looks legitimate and corporate web filters let it through. The page then asks you to run a command to fix it. Don’t.
Three rules cover it:
- Get the app from chatgpt.com, the Microsoft Store, the App Store or Google Play. Never from an ad.
- No legitimate service will ever ask you to paste a command into your terminal to fix a login problem.
- Turn on two-factor authentication for your OpenAI account, so a stolen password on its own is not enough.
If a teen in your house uses it
The minimum age is 13, and OpenAI now separates teens from adults rather than treating everyone the same.
ChatGPT for Teens launched in August 2026. It switches on for anyone the system estimates is under 18, or who says they are 13 to 17. It applies stricter handling around self-harm, violence, eating disorders and sexual content, and it is instructed not to use romantic language or encourage emotional dependence.
Parents can link an account and get real controls: Quiet Hours, certain settings locked, and safety notifications if a conversation heads somewhere worrying.
Age prediction is an estimate, not an ID check. It will occasionally misread an adult or miss a teen using a birthday that isn’t theirs. Treat it as a sensible default, then have the conversation anyway.
What a VPN does and doesn’t do here
Being straight about this matters more than selling you something.
A VPN encrypts the connection between your device and a VPN server. That is the whole job. So:
- It does not change what OpenAI stores about your account. Your chats, your Memory, your history — identical with the VPN on or off.
- It does not make you anonymous to ChatGPT. You are signed in. That is the identifier that counts.
- It cannot stop you pasting something you shouldn’t, and it cannot make a wrong answer right.
- It would not have helped with the Mixpanel incident. That data was already handed over.
What it does do is smaller and real. On café, hotel or airport Wi-Fi, the network owner sees a connection to a VPN server instead of a list of the services you use. Your internet provider sees the same. And on Premium, Smart Filter blocks ad and threat domains in the browser — exactly where those fake download pages live.
Useful, then. Just not a privacy setting for ChatGPT.
Try Planet VPN
If most of your ChatGPT use happens on Wi-Fi you don’t own, protecting the connection is a sensible baseline.
The free plan gives you six locations with no registration and no credit card — a short ad funds it. Premium starts at $1.99 a month and adds 60+ locations across 1,260+ servers, up to 10 devices, split tunneling, Double VPN and the Smart Filter that blocks ad and threat domains in your browser.
Apps cover Windows, macOS, Linux, Android and iOS, with extensions for Chrome, Edge, Opera and Firefox. Planet VPN keeps no activity logs and stores only an email address if you subscribe. Over 15 million people use it.
It won’t manage what you type into ChatGPT. That part is still yours — and now you know which parts matter.
FAQ
Can OpenAI staff read my conversations?
A small number of authorised people can review conversations for abuse investigations, security work and legal obligations. It is not routine reading. Temporary Chats may still be reviewed for abuse monitoring even though they never enter your history.
If I turn off training, are my old chats removed from the model?
No. The toggle applies going forward. Anything already used in training cannot be pulled back out — a good argument for changing the setting now rather than later.
Is it safe to upload work documents to ChatGPT?
On a Business, Enterprise or Edu workspace, usually yes: training is off by default and your admin controls retention. On a personal account, treat every upload as something that has left your control. Check your employer’s policy first.
Does deleting a chat really delete it?
It leaves your account immediately and is scheduled for permanent deletion within 30 days, with exceptions for de-identified data and legal obligations. Files in your Library need deleting separately.
How do I know a ChatGPT app is the real one?
Check the publisher name in the store listing, and download only from chatgpt.com or an official app store. Search ads are the main distribution channel for fakes, so type the address instead of clicking the first result.