Judging AI governance

Is ChatGPT safe to use at work?

Short answerChatGPT is safe to use for approved business work when the company chooses the right plan, keeps restricted data out, configures training and retention, controls access, and reviews important output. Personal ChatGPT and Claude accounts follow consumer data rules. Managed business plans provide different training defaults and administrative controls.

For a business, safety is a deployment decision. The plan determines whether prompts can be used for model improvement, how long chats remain, which settings an administrator controls, and which contract applies. Encryption protects data while it travels and while it is stored. The provider still receives and processes the prompt in readable form to generate an answer.

What happens to ChatGPT data by plan

OpenAI plan summary as of October 7, 2026. Confirm the current provider terms and workspace settings before approval.
PlanWhat happens to the data
Free, Plus, and Pro personal workspacesTraining: Consumer content is eligible for model improvement when the user’s setting allows it. Turn off Improve the model for everyone to exclude new conversations. Retention: Regular chats stay until deletion. OpenAI schedules deleted chats for permanent deletion within 30 days, subject to stated exceptions. Temporary Chats have a safety retention window of up to 30 days and are excluded from training. Encryption: OpenAI states that consumer content is encrypted at rest and in transit.
ChatGPT BusinessTraining: Workspace inputs and outputs are excluded from model training by default. Retention: Regular chats stay until user deletion or an applicable workspace retention policy. Deleted chats are scheduled for permanent deletion within 30 days, subject to stated exceptions. Encryption: OpenAI states that business data uses AES-256 at rest and TLS 1.2 or higher in transit.
ChatGPT Enterprise and EduTraining: Workspace inputs and outputs are excluded from model training by default. Retention: Regular chats stay until user deletion or a workspace policy. OpenAI documents custom retention controls for Enterprise. Encryption: OpenAI states that business data uses AES-256 at rest and TLS 1.2 or higher in transit.
OpenAI APITraining: API inputs and outputs are excluded from model training by default; an organization can explicitly opt in. Retention: The endpoint, feature, and organization setting determine retention. Qualifying organizations can configure retention, including zero data retention for eligible API use. Encryption: OpenAI states that business data uses AES-256 at rest and TLS 1.2 or higher in transit.

Sources: OpenAI’s consumer data-handling page, Data Controls FAQ, chat and file retention page, ChatGPT Business privacy page, and business data privacy page, read October 7, 2026.

What happens to Claude data by plan

Anthropic plan summary as of October 7, 2026. Confirm the current provider terms and organization settings before approval.
PlanWhat happens to the data
Claude Free, Pro, and MaxTraining: Anthropic uses chats and coding sessions for model improvement when the user chooses to allow it. Retention: Deleted conversations leave history immediately and are deleted from back-end storage within 30 days. Anthropic documents retention of de-identified training data for up to five years when model improvement is enabled. Encryption: Anthropic states that Claude.ai user data is encrypted in transit and at rest.
Claude Team and EnterpriseTraining: Commercial chats and coding sessions stay out of training unless the customer joins the Development Partner Program or explicitly submits or opts in to training data. Retention: Saved conversations remain in the product. Deleted chats leave back-end storage within 30 days. Enterprise custom retention has a 30-day minimum, with indefinite retention as the documented default. Encryption: Anthropic states that stored data uses AES-256 GCM at rest and TLS 1.2 or higher in transit.
Anthropic APITraining: Commercial inputs and outputs stay out of training unless the customer explicitly opts in through an identified program or feedback route. Retention: Anthropic deletes API inputs and outputs from its back end within 30 days, with stated exceptions for longer-lived features, agreed settings, usage-policy enforcement, and legal requirements. Encryption: Anthropic states that stored data uses AES-256 GCM at rest and TLS 1.2 or higher in transit.

Sources: Anthropic’s pages on consumer retention, commercial retention, commercial model training, Enterprise retention controls, Claude.ai data protection, and the Anthropic Trust Center, read October 7, 2026.

Practical steps for safe business use

  1. Use the company-approved workspace or API organization. Keep work out of personal accounts unless the policy expressly approves them.
  2. Record the provider, plan, workspace owner, training setting, retention setting, enabled connectors, and review date.
  3. Name the data that must stay out of prompts, uploads, projects, memories, connectors, and tool output. Start with the AI acceptable use policy template.
  4. Restrict access with company identity controls, remove unused members, and review sharing and connector settings.
  5. Test deletion, retention, export, and audit access with synthetic data before approving a workflow.
  6. Require a person to verify important output before it reaches a customer, changes a system, or supports a consequential decision.
  7. Recheck the provider pages and workspace settings after a plan, model, feature, or contract change.

Encryption answers one part of the question

ChatGPT and Claude encrypt data in transit and at rest according to their published security pages. That protects the connection and stored data against specific access paths. The service processes the prompt to produce an answer, so the business still needs a rule for which information is allowed to leave the device, who can access the account, how long data stays, and how output is reviewed.

For regulated health information, review Is ChatGPT HIPAA compliant? and Is Claude HIPAA compliant?. Those workflows require the eligible product, agreement, configuration, and organizational safeguards described on each page.

Where Sentinel fits

SUPERWISE® Sentinel replaces emails, phone numbers, account numbers, and API keys with placeholders before a prompt leaves the PC, and logs every request. It does not redact names or passwords. Use the PII redaction guide to define the boundary, test supported values, record the documented limits, and verify each covered route.

Sentinel adds a control before the provider receives the prompt. The provider plan, training setting, retention rule, encryption, access controls, contracts, and output review remain part of the company’s approval decision. Use the AI glossary to keep the terms consistent.

Apply the same boundary in the profession guides for accountants, real estate agents, insurance agents, and lawyers.

Frequently asked questions

What are the risks of using ChatGPT at work?
The risks include sending restricted data under the wrong account terms, retaining chats longer than the company intends, enabling unapproved connectors or sharing, relying on incorrect output, and losing the record needed for review.
Does ChatGPT use your data for training?
Content from personal ChatGPT accounts is eligible for model improvement when the user’s setting allows it. A user can turn off Improve the model for everyone. OpenAI excludes Business, Enterprise, Edu, Healthcare, and API data from training by default.
Is ChatGPT encrypted?
Yes. OpenAI states that ChatGPT content is encrypted at rest and in transit. For business data, OpenAI specifies AES-256 encryption at rest and TLS 1.2 or higher in transit. Encryption does not remove the need for data rules, access controls, retention settings, and output review.
Is Claude safe for enterprise data?
Claude Team and Enterprise follow Anthropic’s commercial terms, which exclude customer chats and coding sessions from training unless the customer explicitly participates or opts in. The organization still needs to configure access, retention, connectors, data rules, and review.

Sources

  1. OpenAI Help Center, How OpenAI handles data in consumer services. Read October 7, 2026.
  2. OpenAI Help Center, Data Controls FAQ. Read October 7, 2026.
  3. OpenAI Help Center, Chat and file retention in ChatGPT. Read October 7, 2026.
  4. OpenAI Help Center, Managing data, sharing, and privacy in ChatGPT Business. Read October 7, 2026.
  5. OpenAI, Business data privacy, security, and compliance. Read October 7, 2026.
  6. Anthropic Privacy Center, How long do you store my data? Read October 7, 2026.
  7. Anthropic Privacy Center, How long do you store my organization’s data? Read October 7, 2026.
  8. Anthropic Privacy Center, How do you use personal data in model training? Read October 7, 2026.
  9. Claude Help Center, Configure custom data retention controls for Enterprise plans. Read October 7, 2026.
  10. Anthropic Privacy Center, How does Anthropic protect the personal data of Claude.ai users? Read October 7, 2026.
  11. Anthropic Trust Center, security FAQ. Read October 7, 2026.

Reviewed