ChatGPT privacy

Is It Safe to Upload Confidential Company Documents to ChatGPT?

A decision framework for ChatGPT uploads covering workspace type, training controls, retention, administrator access, data minimisation, and document preparation.

Published August 19, 20268 min readReviewed against official sources

Start with the workspace, not the brand name

ChatGPT is offered through personal workspaces, managed business workspaces, and separate API services. They do not all use the same defaults or data lifecycle. Before considering a confidential file, identify the exact product, account, workspace, and feature that will receive it.

OpenAI states that content from ChatGPT Business, Enterprise, Edu, Healthcare, Teachers, and its API is not used to train models by default. For a personal ChatGPT workspace, users can turn off model improvement in Data Controls. These are useful controls, but they answer only the training question.

Storage is separate. OpenAI's retention documentation explains that chats remain until deleted in ordinary use, subject to stated deletion timelines and exceptions. Temporary Chats are not used for training or placed in history, but OpenAI says a copy may be kept for up to 30 days for safety purposes.

Five questions to answer before an upload

  1. Is this use approved? Check the organisation's AI, client, security, records, and sector-specific rules.
  2. Which workspace receives it? Confirm whether it is personal or managed and whether a contract governs business data.
  3. Who can access it? Managed-account administrators may be able to access, audit, retain, or delete account data depending on configuration and law.
  4. How long can it remain? Review chat, file, library, and temporary-chat retention separately.
  5. Does a feature send data onward? Actions, connectors, or other third-party integrations can apply a different recipient's privacy terms.

If any answer is unknown, stop before uploading. A useful AI result rarely requires the whole source document while those questions are unresolved.

Classify the content in the file

Confidential company documents often combine several risk types: personal data, customer terms, forecasts, credentials, legal advice, trade secrets, or information received under a nondisclosure agreement. Removing names alone does not address all of them.

QuestionSafer response
Does AI need the complete file?Extract only the relevant pages, rows, or paragraphs.
Must identities remain?Use consistent placeholders such as Customer A and Project B.
Are exact values required?Round, bucket, or replace values when precision is unnecessary.
Could context re-identify the subject?Generalise dates, locations, roles, and rare details together.
Does the file contain hidden data?Inspect comments, changes, properties, attachments, and format-specific objects.

A practical decision rule

Use three independent gates. First, the destination must be approved. Second, the copy must contain only the information needed for the stated task. Third, a person responsible for the data must review the exact output. Passing one gate does not compensate for failing another.

For example, a business workspace with training disabled by default can still be the wrong place for a privileged legal memo if policy prohibits the use. Conversely, a permitted use can still be careless if the complete workbook is uploaded when a small synthetic table would answer the question.

When the consequence of disclosure is high, consider a synthetic example, an internally hosted model, an approved API configuration, or no upload at all. The correct outcome of a preflight review is sometimes to stop.

Official sources

This guide uses primary sources available on August 19, 2026. Product policies and software features can change, so confirm current terms before handling sensitive material.