Updated
The short answer. Start with a written rule that names the data staff must keep out of ChatGPT. Turn off model improvement on personal accounts. Move approved work into a managed ChatGPT Business or Enterprise workspace. Add a gateway when the rule must be checked before a prompt leaves the Windows PC.
No single setting covers every route. Record which accounts, browsers, apps, and connected services staff use, then test each one.
The Monday plan
- Write the boundary. List the customer data that must stay out of AI prompts, including names, contact details, account numbers, case details, health information, credentials, and documents.
- Inventory the route. Record who uses ChatGPT, whether each account is personal or company-managed, which browser or app they use, and which GPTs, apps, actions, or connectors are enabled.
- Change personal settings. Turn off model improvement and use Temporary Chat for work that is allowed under the policy.
- Move company work into a managed workspace. Configure ChatGPT Business or Enterprise controls, and remove unapproved apps and connections.
- Add an enforcement point where required. Route covered ChatGPT traffic through a gateway that checks the prompt before the provider receives it.
- Test and record. Send approved test data through every covered route, verify the result, and save the account, setting, test date, and evidence.
1. Set the policy before changing the tool
A policy tells people what they may send. It gives the owner or IT lead a rule to configure and test. Write one page that names approved accounts, approved uses, prohibited data, the person who grants exceptions, and the date of the next review.
Include pasted text, uploaded files, screenshots, GPT actions, connected apps, and browser extensions. A prompt can carry customer data through any of those routes. Training staff remains necessary because names and passwords require human judgment under the Sentinel coverage described below.
2. Change the settings on personal ChatGPT accounts
On ChatGPT Free and Plus, open Settings, select Data Controls, and turn off Improve the model for everyone. OpenAI states that new conversations will then be excluded from model training. Temporary Chats are also excluded from training and may be retained for up to 30 days (Data Controls FAQ).
These settings change OpenAI’s use and retention of a conversation. The prompt still reaches OpenAI, and the individual controls the setting. Free and Plus provide no organization administration or organization audit log. Use the company policy to limit these accounts to data that is approved to leave the PC.
3. Use ChatGPT Business or Enterprise controls
ChatGPT Team was renamed ChatGPT Business in August 2025 (OpenAI’s rename FAQ). OpenAI states that Business and Enterprise inputs and outputs are excluded from model training by default (Enterprise privacy).
- Business: manage workspace members and app access. Review each app, GPT action, and connected service because third parties follow their own terms.
- Enterprise: add SAML SSO, retention controls, feature controls, app controls, and the Compliance Platform. OpenAI’s Compliance Platform provides 30 days of logs, so export them when the business needs longer retention.
Workspace controls govern activity inside the managed workspace. They do not stop an employee from opening a personal account or another AI site. Browser, device, identity, and network controls determine whether those routes remain available.
4. Put a gateway in front of covered ChatGPT traffic
Use a gateway when the organization needs a technical check before a prompt reaches ChatGPT. SUPERWISE® Sentinel for Windows runs a local gateway and covers ChatGPT in Chrome and Edge on Windows 10 and 11 (Sentinel for Windows).
SUPERWISE Sentinel is an AI gateway: before a prompt reaches ChatGPT or Claude, it replaces emails, phone numbers, account numbers, and API keys with placeholders and logs the request.
Coverage limit. Sentinel does not redact names or passwords. Keep those out of prompts through policy, training, and access controls. Test every data type your firm handles against the configured guardrails before relying on the route.
- Install Sentinel. Download Sentinel for Windows and run the per-user installer.
- Connect the PC. Sign in or create a SUPERWISE account, approve the computer in the browser, and confirm the green Protected banner in the app.
- Check the browser. In the Tools tab, confirm Chrome or Edge shows as protected before staff open ChatGPT.
- Review the record. Confirm the expected guardrail fired and the event appears in the audit trail. SUPERWISE receives counts, the rule that fired, and latency, while raw prompts and responses stay on the gateway (Data privacy).
5. Test the result before approving use
Use synthetic data approved for testing. Do not test with a real customer record.
- Confirm an email address, phone number, account number, and test API key are replaced.
- Confirm a test name and test password remain visible, then record that limitation.
- Repeat the test in each browser, desktop app, personal account, and managed workspace in use.
- Confirm the person responsible can retrieve the gateway event or workspace record.
- Block or remove every route that falls outside the approved boundary.
Recheck after a plan change, a new app or connector, a browser change, or a material vendor notice. Keep the policy, plan name, settings screenshots, test results, source links, and review date together.
Sources
All sources read on 2026-10-07.
- OpenAI, Data Controls FAQhttps://help.openai.com/en/articles/7730893-data-controls-faq
- OpenAI, chat retention and training opt-outhttps://help.openai.com/en/articles/8983778-how-do-i-opt-out-of-my-data-being-used-to-train-future-models
- OpenAI, ChatGPT Team is now ChatGPT Businesshttps://help.openai.com/en/articles/12111915-chatgpt-team-is-now-chatgpt-business
- OpenAI, Enterprise privacyhttps://openai.com/enterprise-privacy/
- OpenAI, apps admin controls for Business and Enterprisehttps://help.openai.com/en/articles/11509118-admin-controls-security-and-compliance-in-apps-enterprise-edu-and-business
- OpenAI, Compliance Platform for Enterprisehttps://help.openai.com/en/articles/9261474-compliance-api-for-enterprise-customers
- SUPERWISE docs, Sentinel for Windowshttps://docs.superwise.ai/docs/sentinel-for-windows
- SUPERWISE docs, PII redactionhttps://docs.superwise.ai/docs/pii-redaction
- SUPERWISE docs, secret and credential detectionhttps://docs.superwise.ai/docs/secret-credential-detection
- SUPERWISE docs, data privacyhttps://docs.superwise.ai/docs/data-privacy