ChatGPT Privacy Center Guide: Memory, Personalized Ads, Temporary Chat, Connected Apps, Model Improvement, Data Export, and Account Security


What the ChatGPT Privacy Center is—and what it is not
OpenAI says the ChatGPT Privacy Center is rolling out as a signed-in product area for Free, Go, Plus, Pro, and Business users on web, iOS, and Android. The rollout does not include Enterprise, Edu, or Healthcare, and the practical experience can still vary by plan, region, account, app version, rollout status, and workspace policy. For administrators, security teams, and advanced users, the most important starting point is this: Privacy Center is an explanatory navigation layer for privacy-related settings, not a single master switch that changes every data, memory, app, ad, security, and account-retention behavior at once.
OpenAI’s Privacy Center documentation groups privacy information under three broad areas: Personalized chats and ads, Chat privacy, and Data use and access. Those groupings are useful because they put commonly confused topics—Memory, personalized ads, location, Temporary Chat, plugins and apps, multifactor authentication, model improvement, export, and deletion—into one review path. Opening the Privacy Center, however, does not itself turn off training, delete chats, remove memories, disconnect apps, disable ads personalization, export data, close an account, or override a Business workspace policy. Users still need to follow the linked settings, confirm the current state, and understand which controls are account-wide, which are conversation-specific, which are provider-specific, and which are set by an organization.
The rollout boundary matters for enterprises and schools because OpenAI states that Enterprise, Edu, and Healthcare are not included in the Privacy Center rollout described in its Help Center article. That exclusion does not mean those plans have no privacy, data, security, or administrative controls; it means the specific Privacy Center surface described by OpenAI is not the place where those users should expect to manage them. Managed organizations should review their workspace administration documentation, contracts, internal retention policies, identity provider rules, connected-app approvals, and legal obligations rather than assuming that a personal-account Privacy Center setting represents the organization’s policy.
For individual users, the Privacy Center is best treated as a guided checklist. It helps identify the places where privacy-related behavior is explained or configured, but it does not collapse all data lifecycle questions into a single “private” or “not private” state. A user might disable model improvement, keep chat history, allow Memory, use a connected app, and enter Temporary Chat for a sensitive brainstorming session. Another user might disable Memory, disconnect an app, keep personalized ads off, and still retain historical chats. Both configurations can exist because the controls address different systems and different lifecycle events.
For Business users, the same distinction is operationally important. A user may see privacy explanations, but organization policy can determine what is available, how content is used, which connectors or apps are permitted, what data retention expectations apply, and how workspace administrators manage access. Personal settings should not be treated as a way to bypass managed-workspace policy. If a user is unsure whether a conversation belongs in a personal account, a Business workspace, or a regulated environment, the conservative rule is to stop, classify the content, and ask the organization’s approved support channel before pasting confidential, regulated, privileged, or customer-identifying material into any AI tool.
Availability: plans, surfaces, and rollout boundaries
OpenAI describes Privacy Center as rolling out to signed-in Free, Go, Plus, Pro, and Business users on web, iOS, and Android. The wording “rolling out” is significant because it does not guarantee that every eligible user will see the same experience at the same time, on every device, in every region, or under every workspace configuration. Product teams and administrators should avoid writing procedures that depend on a newly visible Privacy Center screen until they have verified the experience in the exact account types, platforms, and regions their users rely on.
| Dimension | OpenAI-documented boundary | Operational interpretation |
|---|---|---|
| Included plans | Signed-in Free, Go, Plus, Pro, and Business users are included in the rollout described by OpenAI. | Teams should verify availability account by account before relying on Privacy Center as a support workflow. |
| Excluded plans | Enterprise, Edu, and Healthcare are not included in the Privacy Center rollout described by OpenAI. | Managed and regulated deployments should use their administrative, contractual, and compliance processes instead of assuming personal-account behavior applies. |
| Supported surfaces | OpenAI names web, iOS, and Android. | Instructions should specify the tested surface because mobile and web experiences can differ during rollouts. |
| Control behavior | Privacy Center explains options and links to existing settings. | Opening Privacy Center is not equivalent to changing a setting, deleting content, exporting data, or revoking an app. |
| Workspace policy | Individual controls depend on plan, region, account, and workspace. | Personal choices do not override managed-workspace controls, provider permissions, or administrative policy. |
The surface distinction is not cosmetic. A user who reviews a setting on iOS may later use ChatGPT on the web, or a Business user may use a workspace on a managed laptop and a personal account on a phone. OpenAI’s Data Controls documentation states that the model-improvement choice applies account-wide across devices, but that does not mean every privacy-related control is identical in scope, timing, or downstream effect. Administrators should write instructions that separate “where you can find the explanation” from “what the setting changes” and “what evidence confirms the change.”
When documenting internal procedures, use exact account language. “Check your personal ChatGPT Data Controls” is different from “check whether the Business workspace permits a connector” and different again from “submit a Privacy Portal request.” Mixing those categories causes mistakes such as expecting a Temporary Chat to erase all traces immediately, expecting app disconnection to delete provider-held data, or expecting a model-improvement opt-out to remove existing chats from history. The Privacy Center can point users toward these areas, but the lifecycle rules come from the underlying controls and policies.
The privacy-control map: separate systems, separate outcomes
A useful Privacy Center review starts by mapping each topic to the system it actually affects. Memory affects saved personalization information. Personalized ads affect how eligible ad experiences may be tailored. Location can be used for relevant experiences as described by OpenAI’s Privacy Center materials, but users should not assume it is the only signal that can affect a service. Temporary Chat changes how a particular chat behaves while temporary. Connected apps involve third-party provider permissions and data flows. Model improvement is an account-level data-use choice for eligible personal accounts, with separate considerations for Codex. Multifactor authentication reduces account-takeover risk but does not delete data. Export and deletion are account data actions. Workspace policy can limit, supersede, or separately govern many of these areas.
| Privacy Center topic | What it helps you review | What it does not automatically do | Conservative decision rule |
|---|---|---|---|
| Memory | Whether ChatGPT can save and use remembered information for personalization. | It does not delete every source where the information appears, and turning Memory off does not disconnect apps. | For sensitive facts, check chats, archived chats, files, memory summaries, and connected app sources before assuming removal is complete. |
| Personalized ads | Ad personalization choices for eligible users where ads are available. | It does not convert an ad-supported eligible plan into a paid ad-free plan or change Business, Enterprise, Edu, or Healthcare ad status. | Review ad personalization separately from model-improvement and Memory settings. |
| Location | How location-related information may support relevant experiences. | It is not a universal privacy shield for all location inference or account activity. | Avoid entering precise sensitive locations unless necessary and appropriate for the task. |
| Temporary Chat | Whether a specific new conversation is temporary and whether it is Personalized or Unpersonalized. | It is not instant deletion and may be retained up to 30 days for safety purposes. | Choose the Temporary Chat mode before the first message and do not include sensitive content unless the use is justified. |
| Apps and plugins | Connected app access, provider data sharing, and app-related permissions. | Disconnecting an app does not automatically delete past chats, files, memories, other connected accounts, or administrator-managed sync. | Review the provider account, ChatGPT connection, workspace sync settings, and existing artifacts as separate cleanup tasks. |
| Model improvement | Whether eligible personal-account content may help improve models. | Turning it off does not remove chats from history. | Decide model-improvement participation separately from retention, export, deletion, and Temporary Chat use. |
| MFA | Account security against unauthorized sign-in. | It does not classify data, remove access from connected apps, or change model-improvement choices. | Enable strong authentication where available, maintain recovery access, and review active sessions under the account’s security options. |
| Export | Obtaining a copy of account data through available export options. | Export is not deletion, and the exported archive becomes a sensitive file you must protect. | Store exports only in approved locations and delete local copies when no longer needed. |
| Deletion | Account or data deletion routes described by OpenAI. | It may not replace provider-side deletion, workspace retention, legal holds, or organization-managed records. | Before deleting, export what you are authorized to keep and review consequences for access, subscriptions, and workspace membership. |
| Workspace policy | Organization-level administration for Business and managed environments. | Personal controls do not override organization policy. | When in doubt, follow the stricter organization rule and escalate through approved channels. |
This map is intentionally procedural rather than legal advice. Privacy, employment, education, healthcare, government, advertising, and regulated-industry duties depend on facts that a general product guide cannot assess. The practical goal is to prevent common operational mistakes: assuming one toggle erases all data, assuming app disconnection reaches into third-party systems, assuming Temporary Chat is a zero-retention mode, or assuming a personal setting authorizes use of confidential company material.
This article explains how Temporary Chat can either remain non-personalized by default or optionally use existing personalization sources such as memory, plugins, and custom instructions, with privacy implications for saving and use. The ChatGPT Temporary Chat Personalization Explained: Memory, Plugins, Custom Instructions, Saving, and Privacy article is a focused companion for Temporary Chat Personalization because it is the exact match for the marker because the current privacy guide discusses Temporary Chat behavior, personalization sources, memory, saving, and privacy controls.
Memory is separate from chat history, files, apps, and model improvement
OpenAI’s Memory documentation says Memory is separate from chat history. That distinction is central to any privacy review because users often delete a chat and assume every personalization fact from that chat is gone. OpenAI’s source notes for this topic state that deleting a chat does not necessarily delete a memory saved from it. Full deletion may require removing every source where the information appears, including chats, archived chats, files, the memory summary, and connected apps. Therefore, a privacy cleanup workflow should not stop after deleting the visible conversation.
A practical example shows the risk. Suppose a user tells ChatGPT during a planning conversation that they manage payroll for a small clinic, uploads a staff-policy file, connects a calendar or storage app, and later asks ChatGPT to remember a preferred reporting style. If the user deletes only the original chat, the same general information may still exist in a memory summary, in an uploaded file, in an archived chat, or in a connected app’s source data. The correct review is source-by-source: locate the chat, inspect archived material, review uploaded files, inspect saved memories, and assess any connected app that may surface the same information again.
Turning Memory off is also not the same as disconnecting apps. OpenAI’s notes explicitly state that turning memory off does not disconnect apps. This means a user can stop ChatGPT from creating or using saved memories while still having a connected app that may provide relevant content when permitted. Conversely, disconnecting an app does not automatically delete saved memories or chats. The systems are related in user experience, but they are not the same lifecycle control.
For households, Memory can be useful but should be reviewed with extra caution on shared devices or shared accounts. A parent who uses one personal account for family planning, tutoring, and work drafts can accidentally mix preference information across contexts. The safer practice is to avoid shared accounts for materially different privacy contexts, avoid entering children’s unnecessary personal information, and review saved memories periodically. If a child or student needs help, use age-appropriate, school-approved, or parent-approved workflows rather than placing sensitive educational, health, behavioral, or identity information into a general personal account without a clear need.
For legal-technology professionals, Memory requires careful separation from privileged or confidential matter handling. This guide does not provide legal advice, but the operational warning is straightforward: do not place privileged, confidential, client-identifying, sealed, or restricted material into an AI account unless your organization has approved that use, the correct workspace and contractual controls are in place, and the matter team understands the retention, access, and deletion implications. A personal Memory setting should never be used as a substitute for a firm-approved information governance process.
Personalized ads, eligible users, and location review
OpenAI’s Privacy Center documentation includes personalized ads and location among the topics it explains. OpenAI states that ads may appear for eligible Free and Go users, and not for Business, Enterprise, Edu, or Healthcare. The Privacy Center can help users understand and navigate ad personalization controls, but ad personalization should not be confused with Memory, model improvement, chat history, or connected-app permissions. Each topic has a different purpose and a different effect on user experience.
For Free and Go users in regions where ChatGPT Ads are available, personalized ads controls are relevant because OpenAI says users can control ad personalization. OpenAI has also stated in its advertising materials that ads are clearly labeled and separate from answers, do not influence ChatGPT answers, conversations remain private from advertisers, and customer data is not sold to advertisers. Those statements describe OpenAI’s advertising approach, but they do not remove the need for users to review personalization settings, avoid entering unnecessary sensitive information, and distinguish between an answer generated by ChatGPT and a labeled ad placement.
For Plus and Pro users, the relevant privacy review may be less about seeing ads and more about preventing category confusion. A user might pay for a plan that is not described in the cited rollout as ad-supported and still have Memory enabled, connected apps active, or model-improvement settings to review. Paid status should not be treated as a substitute for checking data controls. Similarly, Business status changes ad eligibility according to OpenAI’s Privacy Center notes, but it does not eliminate the need to understand workspace policy, app permissions, exports, and account security.
Location review should be handled conservatively. If a task does not require precise location, do not provide it. “Find tax obligations for my exact home address,” “write a dispute letter for my landlord at this address,” or “summarize my child’s school situation using our neighborhood and medical details” can introduce unnecessary sensitivity. When location context is useful, use the least specific level that supports the task, such as country, state, province, city, or regulatory jurisdiction, and verify high-stakes guidance with qualified local sources.
For advertisers, founders, and growth teams, the Privacy Center’s personalized ads area should not be interpreted as a campaign-operations dashboard or a compliance guarantee. User ad controls affect user experience; they do not validate advertiser eligibility, creative policy, consent obligations, language requirements, consumer-protection duties, tax treatment, regulated-sector restrictions, or measurement accuracy. Campaign launch, external publication, targeting decisions, and budget commitments require authorized human review and, where appropriate, qualified legal and regional advertising review.
Temporary Chat is a conversation mode, not a universal eraser
OpenAI’s Temporary Chat documentation says Temporary Chats can be Personalized or Unpersonalized, chosen before the first message. Neither option creates or updates memories while temporary. Temporary Chats are not used for model improvement while temporary, and OpenAI says they may be retained up to 30 days for safety purposes. Saving a Temporary Chat converts it to a regular chat and applies the normal history, personalization, and model-improvement settings. These details matter because many users mistakenly treat Temporary Chat as an immediate deletion mechanism or a guarantee that no content can be retained for any purpose.
The choice between Personalized and Unpersonalized Temporary Chat should be made before the conversation begins. A Personalized Temporary Chat can use existing memory or enabled tools as documented by OpenAI, while an Unpersonalized Temporary Chat is intended to avoid using personalization. The right choice depends on the task. If the user wants help drafting a travel packing list based on remembered preferences, personalization may be useful. If the user wants a neutral critique of a sensitive draft without using prior preferences, an unpersonalized temporary mode is the more cautious workflow.
Temporary Chat is especially useful as a boundary-setting tool for one-off tasks, but it does not authorize reckless data entry. Do not paste secrets, passwords, private keys, access tokens, full medical records, student records, privileged legal documents, customer lists, unreleased financials, or unnecessary personal identifiers merely because the chat is temporary. Temporary status affects the documented lifecycle of the chat, but it does not convert inappropriate input into appropriate input.
A safe operating procedure for sensitive but permissible work is to decide the mode first, minimize the input, remove direct identifiers where possible, avoid attaching unnecessary files, and document whether the output can be saved or copied into another system. If the output will be used for a consequential purpose—legal filing, HR action, medical decision, financial transaction, public statement, school discipline, campaign launch, purchase, booking, payment, or permission change—an authorized human must review and approve the final action outside ChatGPT.
Saving a Temporary Chat is a material change. OpenAI’s notes state that saving converts it into a regular chat and applies normal history, personalization, and model-improvement settings. Users who choose Temporary Chat because they do not want a conversation retained in ordinary history should avoid casually saving it later. If a team writes procedures around Temporary Chat, include a clear warning: saving changes the lifecycle category of that conversation.
Connected apps create provider, account, workspace, and memory questions
OpenAI’s app privacy documentation states that connected apps may receive relevant conversation content and, when permitted, relevant existing memories plus technical or location information. Provider terms apply. This means the privacy review does not end inside ChatGPT. A connected app can involve the user’s provider account, the provider’s own retention and access rules, workspace administrators, sync settings, direct-action permissions, and artifacts that remain after the connection is changed.
Disconnecting an app stops future access through that account, but OpenAI’s notes say it does not automatically delete existing chats, files, memories, other connected accounts, or administrator-managed sync. This is one of the highest-risk misunderstandings in connected-app governance. A user may disconnect a storage, productivity, or workflow app and believe that all previously surfaced content is gone. In reality, cleanup may require reviewing ChatGPT chats, uploaded files, saved memories, the provider’s own account records, other linked accounts, and any workspace-managed sync or administrator-approved connector configuration.
For enterprise administrators and security teams, connected-app review should be treated as a permissions inventory rather than a single-user preference. Identify which apps are permitted, which users or groups can connect them, whether direct actions are allowed, whether workspace sync is active, what provider-side scopes are granted, who can administer the provider account, and what logs or audit records are available under the organization’s plan and policies. Do not assume a user-level disconnect resolves provider-side retention, shared-drive indexing, administrative sync, or data already included in prior conversations.
For knowledge workers, the practical question before connecting an app is: “What content could become relevant to my prompt, and am I authorized for ChatGPT to use it in this context?” A calendar connector might expose meeting titles. A document connector might surface drafts, customer names, contract terms, or internal strategy. A code or storage connector might reveal proprietary implementation details. If the answer requires confidential, regulated, or client-sensitive material, use the approved workspace and follow the organization’s AI, data classification, and third-party access rules.
For developers and Codex users, app and environment access should be separated from model-improvement controls. OpenAI’s Data Controls documentation notes that on personal plans, the model-improvement control also applies to Codex tasks, but Codex has a separate setting for training on full environments. That distinction means a developer should not assume that one ChatGPT privacy setting covers repository contents, terminal environments, files, dependencies, issue trackers, or connected developer tools in every context. Review Codex-specific settings and avoid exposing secrets, production credentials, private keys, customer data, or unapproved proprietary code.
Model improvement: account-wide choice, plan defaults, and Codex caveats
OpenAI’s Data Controls FAQ states that Data Controls apply account-wide across devices for the model-improvement choice. For eligible personal accounts, users can control whether content helps improve models. OpenAI’s Privacy Center notes also state that Business, Enterprise, Edu, and Healthcare content is not used to train models by default. These are plan-sensitive statements, so users should verify their current plan, account type, and workspace before relying on a default or a visible setting.
Turning model improvement off does not remove chats from history. This is a crucial distinction for privacy reviews, discovery concerns, household sharing, internal records, and personal cleanup. Model improvement is about whether eligible content may help improve models; chat history is about whether the conversation remains visible or retained under the applicable product behavior. A user who wants both to stop future model-improvement use and to remove old visible conversations must review both controls separately.
Temporary Chats are different again. OpenAI says Temporary Chats are not used for model improvement while temporary and may be retained up to 30 days for safety purposes. If a Temporary Chat is saved, it becomes a regular chat and normal settings apply. Therefore, a decision tree for a sensitive one-off task should ask three separate questions: should this be Temporary Chat, should it be Personalized or Unpersonalized, and what happens if the user later saves or copies the output?
For Codex users on personal plans, OpenAI’s Data Controls FAQ adds an important caveat: the personal-plan model-improvement control also applies to Codex tasks, but Codex has a separate setting for training on full environments. Developers should not paste credentials or regulated data into prompts, should not rely on opt-outs as a substitute for repository hygiene, and should not give an agent access to production environments unless the organization has explicitly authorized that workflow. Human approval remains mandatory for commits, merges, deployments, destructive commands, secret changes, network changes, external messages, and production actions.
A practical review script for individuals is: confirm the account type, inspect the model-improvement setting, inspect Memory separately, review whether any active chat is Temporary or regular, check connected apps, and then decide whether to delete, export, archive, or retain particular content. A practical review script for organizations is: confirm workspace defaults, document which user-visible settings are allowed, train users not to move confidential work into personal accounts, and periodically sample whether procedures still match the live product surfaces.
Account security, MFA, export, deletion, and workspace policy belong in the same review
Privacy controls are incomplete without account security. If an attacker or former collaborator can access the account, they may be able to view chats, files, settings, connected apps, and other account artifacts regardless of how carefully the user configured model-improvement or Memory. OpenAI includes multifactor authentication in the Privacy Center topic set, which is appropriate because authentication controls reduce the risk that privacy choices are defeated by unauthorized sign-in.
This article covers OpenAI’s Advanced Account Security mode for ChatGPT and Codex, including passkeys, physical security keys, and phishing-resistant authentication that reduces reliance on passwords. The OpenAI Advanced Account Security: How Passkeys Replace Passwords for ChatGPT and Codex article is a focused companion for Passkeys and MFA because it directly supports the account-security section by adding focused context on passkeys and stronger authentication controls.
Export should be treated as a sensitive-data operation. OpenAI’s Privacy Center points users toward export or deletion options, but exporting creates a copy that may contain private conversations, uploaded-file references, account data, or other sensitive material depending on what the export includes at the time. Store exports only in locations you control and are authorized to use. Do not email exports casually, upload them to unapproved file-sharing systems, or attach them to support tickets unless the receiving process is approved for that data.
Deletion requires more care than most users expect. Account deletion, chat deletion, memory deletion, file deletion, app disconnection, provider-side deletion, workspace retention, and Privacy Portal requests are related but distinct routes. OpenAI’s notes for this guide make clear that full deletion of information can require action across chats, archived chats, files, memory summary, and connected apps. In managed environments, organization policy, administrator-managed sync, legal holds, and provider records may introduce additional retention or access considerations.
Before deleting an account or important data, confirm whether you need an authorized export for records you are permitted to keep, whether subscriptions or workspace access will be affected, whether any connected apps should be disconnected first, and whether your organization requires a formal offboarding or data-subject-request process. Do not delete business records, school records, legal matter records, regulated records, or investigation-related material if your organization has instructed you to preserve them. When records obligations are unclear, pause and escalate to the appropriate administrator, counsel, privacy officer, or records owner.
Workspace policy is the final layer in the opening privacy map. Personal settings do not override managed-workspace policy. A Business, Enterprise, Edu, or Healthcare environment may have defaults, contractual commitments, access controls, app approvals, retention expectations, and administrative workflows that differ from a personal account. The Privacy Center is helpful for understanding product concepts, but a user handling company, school, patient, government, client, or regulated data must follow the rules of the environment that owns the data.
Operational warning: Do not treat Privacy Center as a “make everything private” button. Treat it as a review hub that points to multiple controls. For every sensitive workflow, identify the account, plan, workspace, chat mode, Memory state, app connections, model-improvement setting, export/deletion requirements, and human approval path before adding confidential or consequential content.
Memory and Temporary Chat: what changes, what persists, and what training controls do not erase

OpenAI’s Privacy Center puts Memory, Temporary Chat, and model-improvement controls near each other because they all affect personalization and data handling, but they are not the same switch. Memory governs information ChatGPT may remember for future personalization. Temporary Chat changes how a particular conversation is treated while it remains temporary. Model-improvement controls govern whether eligible content may be used to improve OpenAI’s models. A practical privacy review has to test each control by its effect, not by its label.
OpenAI’s Memory documentation distinguishes between the visible chat history and the saved information ChatGPT may use later. A chat can contain facts about a user, but that does not mean every fact is a saved memory; conversely, a saved memory may continue to exist even after the source chat is deleted. This distinction matters for anyone cleaning up sensitive client matters, family information, classroom records, research notes, product plans, or personal preferences that should no longer influence future responses.
Temporary Chat is often misunderstood as a deletion tool. OpenAI says Temporary Chats are not used for model improvement while temporary and may be retained for up to 30 days for safety purposes. OpenAI also says Temporary Chat can be Personalized or Unpersonalized, and the choice is made before the first message. Neither option creates or updates memories while the chat is temporary. If the user later saves that Temporary Chat, OpenAI says it becomes a regular chat and normal history, personalization, and model-improvement settings apply.
For developers, founders, administrators, and legal-technology teams, the safest working model is to treat these as separate lifecycle decisions: whether information is visible in chat history, whether information is saved as memory, whether a temporary session remains temporary, whether account-wide model-improvement controls permit use for training, and whether a connected app or workspace policy can access or synchronize related content. No single Privacy Center page should be treated as a master delete button or as a substitute for a records-retention review.
Memory summary: saved facts are a separate personalization layer
OpenAI describes Memory as a feature that lets ChatGPT remember information across chats so responses can be more helpful. The Memory FAQ says memory is separate from chat history. In operational terms, that means a user may need to inspect at least two places when removing information: the conversation where a fact appeared and the memory area where a fact may have been saved for future personalization.
A saved memory can be simple, such as a preferred writing style, a role, a recurring project, or a personal preference. It can also be more sensitive if the user has shared family details, medical context, workplace information, school information, or client-specific facts. OpenAI’s documentation is the factual boundary here: users should not assume every mention is saved, but they also should not assume deleting the source chat removes every memory that may have been derived from it.
In a workplace setting, this separation creates a practical review requirement. If a user says, “Forget that I work on Project Falcon,” deleting only the chat where the project was discussed may not remove a saved memory if one exists. The user must also review saved memories and remove the relevant memory entry. If the project appeared in uploaded files, archived chats, connected app content, or synchronized workspace material, those sources may require separate handling according to the available controls and organization policy.
For families and educators, the same distinction applies to youth-related or student-related information. A parent or teacher who used ChatGPT to draft educational materials should avoid placing identifiable student information into prompts unless they have a permitted and appropriate basis to do so. If such information was already used, cleanup should not stop at the visible chat. The user should also review saved memories and any files or apps involved in the workflow.
Chats versus saved memories: the deletion path is source-by-source
OpenAI’s Memory FAQ warns that deleting a chat does not necessarily delete saved memory. This is the most important rule in the Memory section because it prevents a false sense of cleanup. A chat is the conversation record. A saved memory is a separate personalization item. A file is a separate artifact. A connected app or plugin integration can be another separate source of content, depending on the app and the permissions granted.
A conservative deletion workflow should start by identifying where the information appears. The user should check active chats, archived chats, uploaded files, saved memories, and connected apps that may have supplied or received relevant content. If the user operates inside a managed workspace, administrator policy may also affect what can be accessed, retained, exported, or deleted. Personal settings do not override managed-workspace controls.
For a founder, the source-by-source rule matters when confidential product strategy was discussed in multiple contexts. A roadmap detail might exist in a regular chat, a file uploaded for summarization, a saved memory about the company’s preferred market, and a connected app that supplied meeting notes. Removing the roadmap from one location does not prove the other locations have been cleaned. The review should document each source checked and the control used.
For a legal-technology professional, the decision rule is stricter: do not rely on Memory deletion as a legal hold, retention, privilege, confidentiality, or e-discovery process. OpenAI’s controls can help manage ChatGPT personalization and account data, but they do not replace matter-specific records governance, client consent analysis, protective orders, or professional responsibility review. If privileged or confidential material may have been entered, involve the appropriate authorized person rather than trying to solve the issue through a single product toggle.
Recommended memory cleanup workflow for sensitive or stale information
Recommendation, not an OpenAI promise: use a source inventory whenever you remove sensitive or outdated information from ChatGPT. The goal is to avoid deleting the visible chat while leaving personalization or related artifacts intact. This workflow is intentionally conservative because OpenAI’s documentation separates chats, saved memories, files, apps, and workspace controls.
- Define the information to remove. Write a short description that avoids repeating secrets, regulated data, or unnecessary personal identifiers. For example: “the former employer name used in resume drafts” is safer than restating every private detail.
- Check saved memories. Review the memory summary or saved memory area available in the account. Delete any memory that contains the stale or sensitive fact.
- Check active and archived chats. Search or review conversations where the fact may have appeared. Delete or manage those chats according to the controls available in the account and any applicable workplace policy.
- Check files. Remove uploaded files that contain the information if the account and plan expose file-management controls. Do not assume deleting the chat removes every uploaded artifact in every context.
- Check connected apps. Review whether an app supplied or received the relevant information. Disconnecting an app stops future access through that account, according to OpenAI’s apps documentation, but it does not automatically delete prior chats, files, memories, other connected accounts, or administrator-managed sync.
- Check workspace policy. In Business or other managed environments, confirm whether organization controls, retention policies, or sync settings change what the individual user can do.
- Retest personalization carefully. In a new regular chat, ask a non-sensitive question that would reveal whether the stale preference still affects personalization. Do not paste the sensitive information back into ChatGPT just to test deletion.
This workflow deliberately avoids prompting ChatGPT with the very secret or personal detail the user wants to remove. For example, instead of asking, “Do you remember my child’s full name, school, and diagnosis?” ask a narrower, non-identifying question such as, “Do you have any saved memories about my family or school planning that I should review?” Then inspect and remove memory entries through the available settings rather than expanding the sensitive record in a new chat.
Turning Memory off: useful boundary, limited scope
Turning Memory off changes whether ChatGPT uses or saves memory according to the controls available to the user, but OpenAI’s source notes make clear that turning off Memory does not disconnect apps. This is a critical operational boundary. If a connected app has permission to provide relevant content, or if a workspace has synchronization configured, the Memory toggle alone does not end every data pathway.
Users should treat “Memory off” as a personalization setting rather than as an account-wide data purge. It may be appropriate for people who do not want ChatGPT to accumulate persistent preferences, for professionals who switch among clients or roles, or for households where multiple people might use one account contrary to best practice. It does not remove the need to delete existing memories, manage chat history, review files, disconnect apps, or adjust model-improvement settings where available.
For enterprise administrators and Business workspace owners, the decision is not only “Memory on or off.” The more useful review asks which roles are allowed to use personalization, whether users understand that memory and history differ, whether client or regulated data is prohibited in prompts, and whether connected apps introduce data from systems that have their own retention and access rules. A short internal policy can prevent users from assuming that a memory toggle is the same as records deletion.
Sample internal policy language: “Users must not place secrets, credentials, regulated personal data, or client-confidential material into ChatGPT unless the use is authorized for the account and workspace. Turning Memory off does not delete prior chats, files, or connected-app content. Users who need to remove information must review saved memories, chats, archived chats, files, and connected apps, and must follow any workspace retention requirements.”
Personalized versus Unpersonalized Temporary Chat
OpenAI’s Temporary Chat documentation states that users can choose Personalized or Unpersonalized Temporary Chat before sending the first message. That timing matters. The mode is not something a user should assume can be retroactively corrected after a sensitive prompt has already been sent. The decision should be made before the first message in the conversation.
Personalized Temporary Chat can use existing memory or other personalization features available to the account, but it does not create or update memories while temporary. This option fits short-lived work where the user wants ChatGPT to use established preferences but does not want the conversation to become a normal history item unless saved later. A benign example is asking for a temporary rewrite in a known tone without adding a new long-term preference.
Unpersonalized Temporary Chat is the more conservative option when the user does not want existing memory to shape the response. It is useful for a one-off comparison, a neutral second opinion on public text, or a session where a user wants to avoid prior preferences influencing the answer. It still should not be treated as a secure vault for secrets, credentials, confidential client files, or regulated personal information.
Neither Temporary Chat option creates or updates memories while the chat remains temporary, according to OpenAI’s documentation. That does not mean the conversation is instantly erased or completely unavailable for every purpose. OpenAI says Temporary Chats may be retained for up to 30 days for safety purposes. Users who need strict deletion, retention, privilege, or compliance treatment should not rely on Temporary Chat alone.
What happens if a Temporary Chat is saved
OpenAI says saving a Temporary Chat converts it into a regular chat. That conversion is a lifecycle change. Once saved, the conversation should be evaluated under the normal history, personalization, and model-improvement settings that apply to the account or workspace. Users should not save a Temporary Chat unless they are comfortable with the ordinary treatment that follows.
A practical example: a product manager starts an Unpersonalized Temporary Chat to compare public release-note wording without using existing preferences. If they save the session because the draft is useful, it becomes a regular chat. At that point, the user should consider whether the content belongs in history, whether the account’s model-improvement controls allow eligible use, and whether the conversation contains any information that should be removed or redacted before continuing the work in a regular chat.
Another example: an attorney tests a generic clause explanation in Temporary Chat without entering client facts. Saving the chat may be reasonable if it contains only public, generic research notes and the account is approved for that purpose. It would not be appropriate to use saving as a way to preserve confidential matter analysis unless the account, workspace, client authorization, and professional obligations support that workflow. This guide does not provide legal advice; it flags the product-behavior boundary that should trigger review.
The safest decision rule is simple: choose Temporary Chat before the first message when the session should not begin as ordinary history, avoid entering sensitive material that requires guaranteed deletion or strict confidentiality, and do not save the chat unless the content is suitable for regular chat treatment under the account’s settings and policy.
Control-versus-effect table for Memory, Temporary Chat, and model improvement
The following table maps the controls discussed in OpenAI’s Privacy Center, Memory, Temporary Chat, Data Controls, and app-privacy documentation to their practical effect. It is not legal advice and it does not override plan, region, rollout, or workspace-specific behavior. Use it as a review checklist before handling sensitive, regulated, confidential, or client-specific information.
| Control or action | Documented effect from OpenAI sources | What it does not necessarily do | Operational decision rule |
|---|---|---|---|
| Open Privacy Center | Explains privacy topics and routes users to existing settings where available. | Does not itself change settings, delete data, disconnect apps, or override organization policy. | Use it as a navigation and review map, then verify the actual setting state. |
| Delete a regular chat | Removes or manages the conversation according to the account’s available chat controls. | Does not necessarily delete a saved memory derived from that chat, nor every file, app artifact, or workspace record. | After deleting a chat, inspect saved memories, files, archived chats, and app connections for the same information. |
| Delete a saved memory | Removes that memory item from the personalization layer available to the user. | Does not necessarily delete the original chat, uploaded file, connected-app source, or workspace copy where the information also appears. | Use memory deletion plus source cleanup when information should no longer appear anywhere in the account workflow. |
| Turn Memory off | Limits the Memory feature according to the controls available for the account. | Does not disconnect apps and should not be treated as a universal deletion or retention control. | Use when persistent personalization is not desired, then separately review existing memories, files, chats, and apps. |
| Start Personalized Temporary Chat | Can use existing personalization such as memory where available, while not creating or updating memories during the temporary session. | Does not make the session a guaranteed immediate deletion channel and does not prevent up-to-30-day safety retention. | Use for short-lived work where existing preferences are helpful but no new memory should be created. |
| Start Unpersonalized Temporary Chat | Runs the temporary conversation without using personalization in the same way as the Personalized option. | Does not create a secure repository for secrets, privileged material, regulated data, or content requiring guaranteed deletion. | Use for neutral, one-off tasks where prior memory should not influence the output. |
| Save a Temporary Chat | Converts the temporary conversation into a regular chat. | Does not preserve the temporary treatment after saving. | Save only if the content is suitable for ordinary history, personalization, and model-improvement treatment under the account’s settings. |
| Turn off model improvement for an eligible personal account | OpenAI says the Data Controls choice applies account-wide across devices for eligible personal accounts. | Does not remove chats from history and does not necessarily affect separate settings such as Codex full-environment training. | Use for training preference, then separately manage history, memory, files, apps, and Codex-specific settings. |
| Use Business, Enterprise, Edu, or Healthcare content | OpenAI states that Business, Enterprise, Edu, and Healthcare content is not used to train models by default. | Does not mean every user has the same Privacy Center rollout, the same controls, or authority to override workspace policy. | Confirm the workspace’s administrative settings and policy before relying on any individual-user assumption. |
| Disconnect a connected app | Stops future access through that account according to OpenAI’s apps documentation. | Does not automatically delete existing chats, files, memories, other connected accounts, or administrator-managed sync. | After disconnecting, review prior artifacts and provider-side obligations separately. |
Model-improvement controls: account-wide choice is not history deletion
OpenAI’s Data Controls FAQ says eligible personal accounts can control whether their content helps improve models, and that the setting applies account-wide across devices. This is a training-use control, not a chat-history delete button. Turning model improvement off does not remove existing chats from history. Users who want to reduce retained visible content must separately manage chat history, saved memories, files, and app-related artifacts where controls are available.
OpenAI states that Business, Enterprise, Edu, and Healthcare content is not used to train models by default. That statement should not be stretched into a claim that every workspace has the same feature rollout, the same Privacy Center surface, or the same user authority. The Privacy Center rollout described by OpenAI covers signed-in Free, Go, Plus, Pro, and Business users on web, iOS, and Android, and does not include Enterprise, Edu, or Healthcare in that rollout note. Managed environments require administrator confirmation.
For personal users, the account-wide nature of the model-improvement setting reduces a common mistake: changing it on one device and assuming another device behaves differently. OpenAI says the Data Controls choice applies across devices for the account. The practical check is to confirm that the signed-in account is the same account on web and mobile, because people often maintain separate personal, school, and work accounts with different settings and policies.
For administrators, the most useful policy distinction is between “training use,” “history visibility,” “memory personalization,” and “external app access.” A user may turn off model improvement but still have a regular chat in history. A user may delete a chat but still have a saved memory. A user may turn off Memory but still have a connected app. A workspace may block or configure settings differently from a personal account. Reviews should track the actual control affected rather than treating “privacy” as one category.
This implementation guide explains how enterprises can build data loss prevention policies for ChatGPT and Codex to manage sensitive data exposure in AI-assisted development and workplace use. The How to Build Enterprise Data Loss Prevention Policies for ChatGPT and Codex: Complete Implementation Guide article is a focused companion for Data Controls for Codex because it best matches a privacy-center discussion of Codex data controls because it focuses on governance and DLP rather than analytics workflows or unrelated Codex data tasks.
Control-name checkpoint: The account-level setting is named “Improve the model for everyone.” On eligible personal plans it applies to ChatGPT conversations and Codex tasks, while Codex has a separate setting for training on full environments; both controls must be reviewed independently.
Codex has a separate full-environment training setting
OpenAI’s Data Controls FAQ includes an important Codex caveat: on personal plans, the model-improvement control also applies to Codex tasks, but Codex has a separate setting for training on full environments. This means a ChatGPT privacy review for developers should include Codex-specific data controls rather than stopping at the general ChatGPT setting.
The phrase “full environment” should trigger a higher-sensitivity review for engineering teams because development environments can contain source code, configuration files, logs, dependency metadata, filenames, tests, internal comments, or accidental secrets. This guide does not add capabilities beyond OpenAI’s documentation; it simply applies the documented separation as an operational warning. If a developer uses Codex, they should inspect both the general model-improvement choice and the separate Codex full-environment training setting where available.
A safe Codex review should avoid pasting tokens, private keys, production credentials, customer data, or proprietary code into a chat merely to ask whether it is covered. Instead, review the settings directly, use approved repositories, keep secrets out of the working tree, and rely on organization-approved procedures for code and data handling. Human approval remains mandatory before commits, merges, releases, destructive commands, permission changes, credential changes, network changes, or production actions.
For founders and small teams, the practical checklist is: identify which account runs Codex, confirm whether it is personal or managed, inspect the account-wide model-improvement setting, inspect the separate Codex full-environment training setting, document the decision, and ensure repositories do not contain unnecessary secrets or regulated data. If the team later moves from personal accounts to a managed workspace, repeat the review because workspace policy and defaults may differ.
Temporary Chat and model improvement: do not confuse “while temporary” with “never after saving”
OpenAI says Temporary Chats are not used for model improvement while temporary. The phrase “while temporary” is the key limitation. If a Temporary Chat is saved, OpenAI says it becomes a regular chat, and normal history, personalization, and model-improvement settings apply. A user who wants a conversation to remain outside ordinary chat treatment should avoid saving it and should avoid entering content that requires stronger guarantees than the Temporary Chat documentation provides.
This distinction affects drafting workflows. A knowledge worker may begin in Temporary Chat to brainstorm a non-sensitive outline without cluttering history. If the outline becomes a long-term project asset and the user saves it, they should then treat the conversation as a normal chat. If the account’s model-improvement setting is on and the account is eligible, the user should not assume the temporary status continues to govern the saved conversation.
For classrooms, instructors should explain the difference before students use the feature. Temporary Chat is not a license to submit copyrighted course packs, exam content, identifiable student information, or confidential school records. If students save a Temporary Chat, it becomes regular history under their account settings. Schools using managed environments should follow their institution’s approved tools, policies, and administrator settings rather than relying on personal-account behavior.
For legal, finance, health, and security work, the conservative rule is stronger: use Temporary Chat only for content that is appropriate for the account even if retained up to 30 days for safety, and do not use it for material that requires guaranteed deletion, privilege preservation, regulatory retention logic, or strict data-residency conclusions. Consult qualified professionals and organization policy for those decisions.
Examples: choosing the right mode before the first message
Example for a writer: A user wants a one-time rewrite of a public biography in a tone ChatGPT already knows they prefer. Personalized Temporary Chat may be suitable because existing memory can help style the answer, and the session will not create or update memories while temporary. If the biography includes private family details, the user should remove them before prompting or use a safer workflow.
Example for a developer: A developer wants a neutral explanation of a public open-source license clause without personal coding preferences influencing the response. Unpersonalized Temporary Chat may be more appropriate. The developer should not paste confidential repository code, access tokens, private vulnerability details, or client data into the session. If the discussion becomes part of an approved engineering record, saving it converts it to a regular chat.
Example for a founder: A founder wants to compare two public positioning statements without adding the new direction to long-term memory. Temporary Chat can help keep the brainstorm from updating memory while temporary. If the founder uploads a confidential investor memo, Temporary Chat should not be treated as a guaranteed deletion or confidentiality mechanism; the better decision is to avoid unnecessary confidential input and use an approved workspace and policy.
Example for a parent: A parent wants a generic list of questions to ask a school counselor. Unpersonalized Temporary Chat may avoid memory-shaped assumptions. The parent should not include the child’s full name, school, diagnosis, address, or other unnecessary identifiers. For safety, educational, or health decisions, the parent should rely on qualified real-world professionals rather than ChatGPT alone.
Example for a security team: An analyst wants a general template for an incident-review checklist. Temporary Chat may be fine if the content is generic. The analyst should not paste live indicators tied to a confidential breach, credentials, internal network diagrams, customer data, or exploit details that could create risk. Publication, notification, containment, access changes, and legal commitments require authorized human approval.
Audit questions for a quarterly privacy review
A quarterly review should produce evidence that the team checked each separate control rather than merely opening Privacy Center. The review can be lightweight for a personal account and more formal for a managed workspace, but it should record the account type, the surfaces reviewed, and any follow-up actions taken. Do not include secrets, tokens, personal identifiers, or privileged content in the review notes.
- Memory: Are saved memories still accurate, necessary, and appropriate for the account’s use? Were stale, sensitive, or cross-client memories removed?
- Chat history: Are regular chats and archived chats consistent with the user’s retention needs and workspace policy?
- Files: Are uploaded files still needed, and do they contain confidential, regulated, or outdated information that should not remain available?
- Temporary Chat habits: Do users understand the difference between Personalized and Unpersonalized Temporary Chat, and do they choose before the first message?
- Temporary Chat saving: Are users aware that saving converts the session into a regular chat with normal settings?
- Model improvement: Has the account-wide setting been reviewed on the correct signed-in account, and is it aligned with the user’s role and policy?
- Codex: If Codex is used, has the separate full-environment training setting been reviewed in addition to the general model-improvement control?
- Connected apps: Are app permissions, provider accounts, workspace sync, and disconnection effects understood and documented?
- Managed policy: For Business or other organization accounts, has an administrator confirmed which individual controls are available and which policies override user choices?
The output of this review should be a short action log: controls checked, settings changed, memories deleted, apps disconnected, files removed, administrator questions raised, and training needed. The log should not reproduce the sensitive content being removed. For example, “removed obsolete client preference memory from personal account” is safer than copying the client name and matter details into the review record.
Sample prompts for safe self-review without re-exposing sensitive details
Sample prompt for memory hygiene: “Help me create a checklist for reviewing saved memories in my ChatGPT account. Do not ask me to paste private facts, names, client information, credentials, health information, student information, or confidential text. Organize the checklist by stale preferences, sensitive personal details, workplace context, family context, and project-specific facts.”
Sample prompt for Temporary Chat decision-making: “Create a decision tree for choosing regular chat, Personalized Temporary Chat, or Unpersonalized Temporary Chat. Assume I may handle public notes, personal preferences, workplace drafts, and confidential material. Include warnings that Temporary Chat may be retained up to 30 days for safety, creates no new memories while temporary, and becomes a regular chat if saved.”
Sample prompt for administrator training: “Draft a one-page internal training note explaining that Memory, chat history, files, connected apps, model-improvement settings, and workspace policy are separate controls. Do not claim any setting deletes all data. Include a checklist users can follow before entering client, regulated, or confidential information.”
Sample prompt for developer privacy review: “Create a Codex and ChatGPT data-control review checklist for a small engineering team. Include account-wide model-improvement settings, the separate Codex full-environment training setting, repository hygiene, secrets exclusion, connected apps, and human approval before commits, merges, releases, destructive commands, permission changes, or production actions.”
These prompts are workflow aids, not privacy guarantees. They help users reason about controls without restating the sensitive content they are trying to protect. Any legal, regulatory, employment, school, medical, security, or contractual decision should be reviewed through the appropriate qualified channel and the organization’s approved policy.
Apps, ads, location, and workspace policy: the settings that cross account boundaries
OpenAI’s Privacy Center groups several controls that are easy to review together because they determine whether ChatGPT can use context from outside the current conversation, whether another provider may receive relevant content, and whether a managed workspace can apply policy above an individual user’s preferences. OpenAI describes the Privacy Center as a place that explains and links to existing settings; opening it does not change settings, delete data, disconnect apps, or override organization policy. Treat this part of the review as an account-boundary audit rather than a single privacy switch.
The practical question is not “is ChatGPT private?” in the abstract. The useful questions are: which account is active, which workspace owns the conversation, which connected app or plugin is being used, whether the app can receive conversation content or relevant memories, whether the user is eligible for ads, whether location information is used for relevance, and whether administrator-managed sync or workspace policy applies. Those answers can vary by plan, region, rollout, workspace, app provider, and provider-side permissions.
For personal users, the highest-risk mistake is assuming that disconnecting one app, deleting one chat, or turning off one personalization feature removes every copy of the same information. OpenAI states that disconnecting an app stops future access through that account, but it does not automatically delete existing chats, files, memories, other connected accounts, or administrator-managed sync. For Business and other managed environments, the highest-risk mistake is assuming personal controls override workspace policy; they do not.
App data sharing: what may leave ChatGPT when an app is used
OpenAI’s app privacy documentation says connected apps may receive relevant conversation content and, when permitted, relevant existing memories plus technical or location information. This matters because a chat that looks like one conversation can involve at least three policy layers: OpenAI’s ChatGPT controls, the connected app provider’s terms, and the permissions or data already available inside the provider account. If a user asks an app to summarize a document from a connected storage provider, the provider interaction may involve the user’s provider account and the provider’s own logs, access rules, retention practices, and enterprise controls.
The safest operational model is to treat each app connection as a scoped integration, not as a cosmetic ChatGPT feature. Before using an app with sensitive work, identify the provider, the provider account, the workspace or tenant, the user identity, and the type of content ChatGPT may pass to the provider to complete the request. If a user connects the wrong personal cloud account while working in a business context, disconnecting that account later may stop future access through that ChatGPT account, but it should not be treated as a retroactive purge of previous chats, app-side artifacts, files, or provider logs.
OpenAI’s documentation also separates app disconnection from Memory. Turning Memory off does not disconnect apps, and disconnecting an app does not automatically delete saved memories. A user who previously asked ChatGPT to remember a preference or role related to a connected app may need to review saved memories separately. Likewise, a user who imported or discussed provider content in chat history may need to review chats, archived chats, files, and the provider system itself.
Recommendation: keep a small inventory for every connected app that is approved for regular use. Record the app name, provider, account type, workspace, permitted business purpose, data classes allowed, whether relevant memories may be used, whether direct actions are allowed, and who can approve disconnection or reauthorization. This inventory does not replace OpenAI or provider controls, but it gives administrators and power users a concrete record to compare against actual account settings.
This playbook explains how ChatGPT can connect to tools such as Box, Notion, Linear, Dropbox, and other app integrations, including workflows that read from and write to connected services. The How to Connect ChatGPT to Your Entire Tool Stack: Complete Playbook for Box, Notion, Linear, Dropbox, and 20+ App Integrations with Write Access article is a focused companion for Connected App Privacy because it is semantically appropriate because connected-app privacy depends on understanding what tool connections and permissions allow ChatGPT to access or modify.
Provider terms and provider-side permissions are part of the privacy boundary
OpenAI’s help material states that provider terms apply when apps are used in ChatGPT. That point is operationally important because provider terms and permissions can determine what the connected service can access, store, process, or disclose after an interaction. ChatGPT may be the interface, but the provider account can remain the authority for files, calendars, messages, tasks, or other external resources.
A legal-technology team reviewing an app connection should therefore ask two separate questions. First, what content may ChatGPT send to the app to satisfy the user’s request? Second, what can the provider account already access once the user authorizes the connection? For example, a document-management connection used for drafting a contract summary may be constrained by the provider account’s document permissions, but the resulting conversation may still contain excerpts or analysis that must be handled under the organization’s confidentiality, retention, and review rules.
Security teams should avoid approving apps solely because the user trusts ChatGPT. Approval should consider the connected provider’s terms, the workspace’s data classification rules, the provider account’s sharing model, and the consequences of asking the app to take an action. Human approval is required before external messages, submissions, payments, purchases, bookings, destructive actions, permission changes, publication, legal commitments, campaign launches, or other consequential operations. That approval requirement should be written into internal usage guidance, not left to individual judgment during a busy workflow.
Operational warning: do not paste secrets, credentials, private keys, access tokens, privileged legal material, regulated personal data, or unnecessary confidential content into a chat merely to test whether an app can process it. Use public, synthetic, minimized, or redacted test data when validating a connection.
Connected accounts and multi-account confusion
Many privacy incidents start with account confusion rather than malicious behavior. A user may be signed into ChatGPT with one identity, connected to a storage provider with another identity, and working inside a browser profile that also contains personal cookies or workplace sessions. When an app can use a provider account, the relevant question becomes: which provider account is connected to this ChatGPT account and workspace right now?
A practical review begins with naming the active ChatGPT account, the active workspace, and every connected provider account visible in settings. If the same provider is connected more than once across personal and work identities, document which one is approved for which task. A founder might allow a personal productivity app for non-sensitive planning but prohibit it for investor materials, payroll, source code, health information, school records, or customer support transcripts. An enterprise administrator might require that only managed provider accounts be used for business workflows, even if personal accounts are technically connectable.
OpenAI’s app disconnection note should shape expectations during cleanup. Disconnecting an app stops future access through that account, but it does not automatically delete other connected accounts. If a user connected a personal and a work version of the same provider, removing one connection does not prove the other is removed. If an administrator manages sync in a workspace, a user’s personal disconnection may not change the admin-managed sync configuration.
This article explains multi-account plugin governance in ChatGPT, covering source attribution, account selection, action approvals, and auditability when personal and work accounts are used in the same environment. The Multi-Account Plugin Governance in ChatGPT: Source Attribution, Account Selection, Action Approvals, and Auditability article is a focused companion for Multi Account Plugin Governance because it is an exact match for the marker and adds the governance context needed for privacy and account-boundary discussions.
Workspace sync and administrator-managed controls
OpenAI’s app privacy notes distinguish personal connected-account controls from workspace controls, provider permissions, direct-action settings, and sync controls. In a managed environment, workspace policy can determine which features, apps, or data flows are available, and an individual’s personal choices do not override those policies. This is especially relevant for Business users because Privacy Center availability includes Business, while Enterprise, Edu, and Healthcare are not included in the rollout described by OpenAI’s Privacy Center article.
For administrators, the key governance task is to define which controls are individual preferences and which are organization policy. A personal user may choose whether an eligible account uses certain personalization or model-improvement settings, subject to availability. A managed workspace may have default protections, app restrictions, sync rules, retention expectations, and audit obligations that are not changed by a user opening the Privacy Center. If a user sees an option in a personal account, that does not mean the same control exists, behaves the same way, or is user-changeable in a managed workspace.
Workspace sync creates another source of lifecycle complexity. If an app is connected through a workspace-managed integration, a user disconnecting an app from a personal context may not stop workspace sync. Conversely, if a user disconnects a provider account, that may stop future access through that account while leaving previous chat content, files, memories, or provider-side artifacts intact. Administrators should publish a removal procedure that states who disconnects the app, who disables workspace sync, who reviews provider-side data, and who verifies that no automated direct-action permissions remain active.
Disconnection limits: what stops, what remains, and what must be checked separately
OpenAI states that disconnecting an app stops future access through that account. That is a forward-looking control. It should not be described to users as a deletion tool, a memory cleanup tool, a provider-account purge, or a workspace-policy override. The same distinction appears elsewhere in Privacy Center topics: deleting a chat does not necessarily delete a saved memory, turning Memory off does not disconnect apps, and turning off model improvement does not remove chats from history.
A complete app cleanup therefore has several steps. First, disconnect the app or provider account where appropriate. Second, review chats, archived chats, and uploaded files that may contain provider-derived information. Third, review Memory because saved facts are separate from chat history. Fourth, check the provider account for files, logs, exports, automations, shared links, or records created outside ChatGPT. Fifth, check workspace settings or ask an administrator whether sync, direct actions, or organization-managed connections are still active.
Sample workflow for administrators: when an employee changes roles, disable or review app access before assigning new sensitive duties. Confirm the employee’s active workspace, connected provider accounts, role-based provider permissions, and any workspace-managed sync. Require a human review before deleting files, revoking access that could disrupt operations, or changing legal, finance, customer, or production systems. Record the date, reviewer, account identifiers in minimized form, and the categories of data checked without copying unnecessary sensitive material into the review log.
| Action or setting | Documented effect from OpenAI sources | What may remain | Operational follow-up |
|---|---|---|---|
| Disconnect a connected app | Stops future access through that account. | Existing chats, files, saved memories, other connected accounts, provider-side records, and administrator-managed sync may remain. | Review ChatGPT artifacts, provider records, other accounts, and workspace sync separately. |
| Turn Memory off | Stops Memory from being used or updated according to the Memory control’s behavior, subject to available settings. | Connected apps are not disconnected merely because Memory is off; existing chats, files, and provider-side data may remain. | Review app connections and saved memory content as separate controls. |
| Delete a chat | Removes the selected chat according to ChatGPT’s chat-deletion behavior. | A memory saved from the chat may still exist; related content may also appear in archived chats, files, apps, or provider systems. | Search for the same information across memory, archived chats, files, and connected services. |
| Use Temporary Chat | Temporary Chats are not used for model improvement while temporary and may be retained up to 30 days for safety purposes. | If saved, the chat becomes a regular chat and normal history, personalization, and model-improvement settings apply. | Choose Personalized or Unpersonalized before the first message and avoid saving sensitive temporary conversations unless intended. |
| Change model-improvement setting on a personal account | Data Controls apply account-wide across devices for the model-improvement choice; on personal plans, the control also applies to Codex tasks, while Codex has a separate full-environment setting. | Turning training off does not remove chats from history, and managed-workspace defaults may differ. | Review history, Temporary Chat use, Codex settings, and workspace policy separately. |
| Open Privacy Center | Explains options and links to existing settings. | No settings change, data deletion, app disconnection, or organization-policy override happens merely by opening it. | Use it as a navigation and review map, then verify each actual control. |
Personalized-ad controls and plan distinctions
OpenAI’s Privacy Center article says ads may appear for eligible Free and Go users, and not for Business, Enterprise, Edu, or Healthcare. The same source notes that users can control ad personalization. Because availability can vary by plan, region, account, app, rollout, and workspace policy, the correct review procedure is to check the signed-in account’s own Privacy Center and advertising controls rather than assume the same options appear for every user in a household, company, or classroom.
For eligible personal accounts, the important distinction is between seeing ads and personalizing ads. A personalized-ad control is not a promise that every ad disappears, and ad eligibility is not the same as model-improvement participation. Users should review the ad-personalization setting separately from Memory, Temporary Chat, app connections, location, and training controls. If a parent, educator, or employer is documenting usage guidance, the policy should use cautious language: “review and configure available ad-personalization controls on eligible accounts,” not “turn off all advertising everywhere.”
Plan distinctions also matter for procurement conversations. Business, Enterprise, Edu, and Healthcare content is not used to train models by default according to OpenAI’s Privacy Center source notes, while eligible personal accounts can control whether content helps improve models. That training distinction is separate from whether ads appear and separate again from app data sharing. A company should not infer that buying a managed plan automatically solves every connected-app, provider-permission, or location-review question.
Location choices and relevance controls
OpenAI’s Privacy Center includes location as part of its privacy review surface, and OpenAI’s app privacy documentation notes that connected apps may receive technical or location information when relevant and permitted. Location can affect relevance, compliance review, advertising behavior, local features, and provider-side context. Because the exact available controls can vary, the safest instruction is to review the location-related setting shown in the signed-in account and avoid overstating what it changes beyond OpenAI’s documented behavior.
Knowledge workers should treat location as potentially sensitive even when it is approximate. A location cue can imply office presence, travel, school attendance, medical-facility proximity, client-site visits, or jurisdiction. When asking an app to plan logistics, summarize local regulations, draft ads, or coordinate events, avoid adding unnecessary precise location details unless the task truly requires them. For regulated work, confirm jurisdictional assumptions with qualified sources or counsel rather than relying on location-derived suggestions.
Recommendation: create a location-minimization rule for internal training. Users should provide the minimum geography needed for the task, such as country or state when city-level detail is unnecessary, and should not provide home addresses, children’s locations, live travel plans, facility locations, or client-site identifiers unless the organization has approved that use. Any external booking, submission, payment, publication, legal filing, or customer communication still requires human approval.
Data-lifecycle matrix for apps, ads, location, and workspace policy
The following matrix is a practical review aid, not a replacement for OpenAI’s current settings or provider terms. Its purpose is to help teams identify where data may originate, where it may flow, which control is relevant, and what evidence should be captured during a review. It deliberately separates OpenAI settings from provider systems and workspace administration because those are different control planes.
| Data category | Typical origin | Possible recipient or use | Relevant control plane | Lifecycle risk | Review evidence to capture |
|---|---|---|---|---|---|
| Conversation content used with an app | User prompt, uploaded file, selected chat context, or app-specific request. | Connected app provider may receive relevant conversation content to complete the request. | ChatGPT app connection, provider account permissions, workspace app policy. | Disconnecting later stops future access through that account but does not automatically delete prior chats or provider-side artifacts. | App name, provider account, workspace, permitted data classes, reviewer, and date of approval. |
| Relevant saved memories | Memory created from prior non-temporary interactions or user-approved memory behavior. | May be used for personalization and may be shared with an app when permitted and relevant. | Memory settings, app permissions, workspace policy. | Deleting a chat does not automatically delete a saved memory; turning Memory off does not disconnect apps. | Memory review date, categories removed, and confirmation that chats/files/apps were checked separately where needed. |
| Provider files or records | Cloud storage, calendar, email, task manager, document system, or other connected account. | Provider account and connected app may access or process data according to provider permissions and terms. | Provider admin console, user provider permissions, ChatGPT connection, workspace sync. | ChatGPT-side disconnection may not delete provider-side records, logs, automations, or shared links. | Provider account identifier in minimized form, scope reviewed, admin ticket, and removal or retention decision. |
| Personalized-ad signals | Eligible personal account activity and available ad-personalization settings. | Used according to OpenAI’s advertising and personalization controls for eligible accounts. | Privacy Center and ad-personalization controls for the signed-in account. | Ad personalization is distinct from Memory, model improvement, location, and connected apps. | Account plan, region if relevant, setting status, review date, and user-facing guidance. |
| Location or technical information | Account, device, network, app context, or user-provided geography. | May support relevance or be provided to connected apps when relevant and permitted. | Location-related settings, app permissions, provider terms, workspace rules. | Excessive precision can reveal sensitive personal, client, school, health, or travel context. | Minimum necessary location standard, approved use cases, and exceptions requiring review. |
| Workspace-managed sync | Organization-managed ChatGPT workspace or provider integration. | Workspace systems, provider systems, and authorized users according to admin configuration. | Workspace admin settings, provider admin settings, organization policy. | Personal settings do not override managed-workspace policy; personal disconnection may not disable organization sync. | Admin owner, sync purpose, allowed data classes, offboarding procedure, and audit cadence. |
| Model-improvement participation | Eligible personal ChatGPT account content or Codex tasks where applicable. | May help improve models depending on the account-wide Data Controls setting; Business, Enterprise, Edu, and Healthcare content is not used to train models by default according to OpenAI. | Data Controls, Codex-specific full-environment setting, workspace defaults. | Turning training off does not remove chats from history and does not resolve app or provider data sharing. | Setting status, account type, Codex review where relevant, and history cleanup decisions. |
Why personal settings do not override managed-workspace policy
Managed workspaces exist because organizations need controls that are not left entirely to each user. OpenAI’s Privacy Center source notes make the boundary clear: individual controls depend on plan, region, account, and workspace, and personal settings do not override organization policy. A user’s personal preference about personalization, app use, or account configuration should not be interpreted as permission to move regulated, confidential, privileged, or customer data outside approved systems.
For enterprise administrators, the communication challenge is to avoid vague reassurance. Instead of telling employees “Privacy Center handles privacy,” publish a role-specific matrix that states which features are available, which apps are approved, which data classes are prohibited, who approves direct actions, what happens during offboarding, and how users should escalate uncertain cases. Include examples: source code may require repository-scoped tools and review; legal drafts may require matter-level confidentiality and attorney review; student data may require school-approved systems; medical or employment records may require specialized handling and should not be casually used with general-purpose apps.
For end users, the decision rule is simple: when using a managed workspace, follow the workspace rule even if a personal account would let you do more. If the workspace blocks an app, requires a managed provider account, disables a feature, or sets a default, do not bypass it by moving the work into a personal account. That can create confidentiality, retention, discovery, access-control, and audit problems that a later privacy-setting change cannot reliably unwind.
Review questions for apps, ads, location, and workspace controls
Use the following questions as an operational checklist. They are not legal advice and should be adapted by qualified privacy, security, legal, education, or compliance professionals for regulated environments. The goal is to prevent false confidence by forcing every reviewer to name the account, workspace, provider, setting, data class, and follow-up action.
- Which ChatGPT account and workspace am I reviewing? Record whether the session is personal, Business, or another managed context, and do not assume the same controls appear across accounts.
- Which connected apps are active? List the provider, provider account, business purpose, approved data classes, and whether the app is approved for direct actions.
- Could relevant memories be used with the app? Review Memory separately from chat history and remember that turning Memory off does not disconnect apps.
- What provider terms and permissions apply? Check the provider account’s own sharing, logging, retention, admin, and access controls before using the app for sensitive material.
- Is workspace sync managed by an administrator? If yes, personal disconnection or personal Privacy Center changes may not alter the workspace-managed integration.
- What remains after disconnection? Review existing chats, archived chats, uploaded files, saved memories, other connected accounts, provider-side artifacts, and admin-managed sync.
- Is the user eligible for ads? OpenAI states ads may appear for eligible Free and Go users, and not Business, Enterprise, Edu, or Healthcare; verify the signed-in account’s current controls.
- Is ad personalization separate from the issue being reviewed? Do not confuse ad-personalization controls with Memory, model improvement, app data sharing, or location settings.
- What location precision is necessary? Use the least precise geography that satisfies the task and avoid unnecessary home, school, client, facility, or live-travel details.
- Does a human need to approve the next step? Require authorization before external messages, submissions, payments, bookings, purchases, destructive actions, permission changes, publication, legal commitments, campaign launches, or other consequential operations.
- Is the cleanup evidence minimized? Keep enough review evidence to prove the setting or connection was checked without copying sensitive content into a new log.
- Is the policy written for real users? Provide examples for common scenarios such as personal-versus-work storage, contract drafting, school materials, customer records, and engineering repositories.
Sample policy language for teams
Policy proposal: “Employees may use connected apps in ChatGPT only with approved provider accounts and only for approved data classes. Disconnecting an app stops future access through that ChatGPT account but does not delete prior chats, files, memories, provider-side records, other connected accounts, or administrator-managed sync. Users must not move workspace work into personal accounts to bypass app, sync, Memory, ad, location, or model-improvement controls. Human approval is required before any external communication, submission, booking, purchase, permission change, destructive action, publication, legal commitment, or production operation.”
This language is intentionally conservative because the underlying systems are separate. It avoids promising that a single setting deletes data everywhere, avoids implying that an app provider follows the same lifecycle as ChatGPT, and avoids treating personal preferences as a substitute for workspace governance. Administrators should attach the organization’s own data-classification table, approved-app list, incident-reporting path, and offboarding workflow before distributing it.
Practical review prompt that avoids re-exposing sensitive content
Sample prompt: “Help me create a privacy review checklist for my ChatGPT account without asking me to paste confidential content. The areas I need to review are connected apps, provider accounts, app disconnection, Memory, personalized ads, location, model-improvement controls, Temporary Chat, and workspace policy. Ask me for only non-sensitive metadata such as account type, app names, provider categories, and whether the workspace is managed. Do not request secrets, tokens, customer data, legal files, health information, student records, source code, or personal identifiers. Output a table of settings to verify, what each setting does not do, and which items require administrator or human approval.”
This prompt is useful because it keeps the review at the metadata level. It can help a user organize evidence without copying the very information they are trying to protect into a new conversation. If the review involves legal privilege, regulated data, youth data, health information, financial records, security incidents, or employment matters, involve the qualified internal owner before uploading or summarizing any underlying material.
Quarterly privacy review: a practical operating cycle
A useful ChatGPT privacy review is a scheduled operating process, not a one-time visit to the Privacy Center. OpenAI describes the Privacy Center as a place that explains privacy-related options and routes users to existing settings; opening it does not by itself change settings, delete data, revoke app permissions, or override workspace policy. Treat the review as a checklist that confirms what is configured, what data may remain, and which follow-up actions need a human owner.
Recommended workflow: run a personal review every quarter, after any major account or workspace change, before connecting a new app, before using ChatGPT for a new category of work, and before offboarding from an employer-managed workspace. For managed organizations, run a parallel administrator review whenever workspace policy changes, a user population changes, or a connected-app program is expanded. This cadence is operational guidance only; it is not legal or privacy advice.
| Review area | What to verify | Why it matters | Conservative action if uncertain |
|---|---|---|---|
| Privacy Center availability | Whether the signed-in account has access on the current surface, plan, and region. | OpenAI says availability is rolling out to signed-in Free, Go, Plus, Pro, and Business users on web, iOS, and Android, and does not include Enterprise, Edu, or Healthcare. | Use the underlying settings and Help Center documentation instead of assuming Privacy Center is available or complete for the account. |
| Memory | Whether saved memories exist, whether they are still accurate, and whether any should be removed. | OpenAI says Memory is separate from chat history; deleting a chat does not necessarily delete a saved memory from that chat. | Remove the saved memory and then review related chats, archived chats, files, and app artifacts separately. |
| Temporary Chat | Whether the user is selecting the intended temporary mode before the first message. | OpenAI says Temporary Chats can be Personalized or Unpersonalized, create no new memories while temporary, and may be retained up to 30 days for safety purposes. | Start a new conversation in the intended mode rather than continuing an ambiguous thread. |
| Model improvement | Whether the account-wide data-control choice reflects the user’s current preference and plan context. | OpenAI says eligible personal accounts can control whether content helps improve models, while Business, Enterprise, Edu, and Healthcare content is not used to train models by default. | Do not treat the model-improvement setting as history deletion; export or delete account data through the relevant data controls when needed. |
| Connected apps | Which apps are connected, what provider permissions exist, and whether workspace sync or administrator controls are involved. | OpenAI says apps may receive relevant conversation content and, when permitted, relevant memories plus technical or location information. | Disconnect future access only after recording what app, account, workspace, and provider-side cleanup may still be required. |
| Ads and location | Whether the account is eligible for ads and whether ad-personalization or location-related preferences match the user’s expectations. | OpenAI states ads may appear for eligible Free and Go users, not Business, Enterprise, Edu, or Healthcare. | Use plan-specific controls and avoid sharing sensitive information to influence ad relevance. |
| Security | Whether MFA is enabled, recovery options are current, and unrecognized sessions or account changes are investigated. | Privacy settings are only useful if the account itself remains under the right person’s control. | Change the account password, review sign-in methods, enable MFA where available, and contact support if compromise is suspected. |
This enterprise guide covers AI agent governance with an emphasis on security, compliance, and risk management for organizations using agents that can take actions across business systems. The AI Agent Governance for Enterprises: Complete Guide to Security, Compliance, and Risk Management in 2026 article is a focused companion for Managed Workspace Compliance because it fits the managed-workspace compliance marker because it provides broader enterprise governance and compliance context for organization-administered AI environments.
Recommended evidence log for each review
Recommended evidence log: keep a dated record of what was reviewed, what changed, what was left unchanged, and why. The log should not contain passwords, tokens, private keys, personal identifiers, customer records, health information, legal matter details, or proprietary content excerpts. Record settings at a high level, such as “Memory reviewed; two stale memories removed,” rather than copying the sensitive memory text into the log.
Privacy review evidence log
Date:
Reviewer:
Account type or workspace context:
Surface reviewed: web / iOS / Android / other
Privacy Center available: yes / no / not checked
Memory:
- Saved memories reviewed: yes / no
- Memories removed or corrected: count and non-sensitive description
- Related chats/files/apps checked separately: yes / no / not applicable
Temporary Chat:
- Default user practice reviewed: yes / no
- Personalized vs Unpersonalized choice documented for sensitive work: yes / no
Model improvement:
- Account-wide data-control setting reviewed: yes / no
- Codex full-environment training setting reviewed where applicable: yes / no / not applicable
- No assumption made that setting deleted history: confirmed
Connected apps:
- App list reviewed: yes / no
- Provider-side permissions reviewed: yes / no / not applicable
- Workspace sync or administrator controls checked: yes / no / not applicable
- Apps disconnected: list names only, no credentials
Ads and location:
- Ad-personalization controls reviewed where applicable: yes / no / not applicable
- Location-related controls reviewed: yes / no / not applicable
Security:
- MFA reviewed: yes / no
- Recovery methods reviewed: yes / no
- Suspicious activity escalated: yes / no / not applicable
Open issues:
- Owner:
- Deadline:
- Escalation path:
For organizations, the evidence log should identify role-based decisions rather than individual private content. For example, “Marketing team users may connect approved calendar and file apps after provider permission review” is safer than listing private file names. Security and privacy teams should store the log in an approved internal system with access limited to people who need the record for administration, compliance, incident response, or audit preparation.
Export preparation: collect what you need before deleting or offboarding
OpenAI’s Help Center describes export and deletion options in the broader set of data controls. An export is useful before deleting an account, leaving a workspace, investigating a privacy concern, or documenting what information a user wants to preserve. An export should not be treated as proof that every possible provider-side, app-side, workspace-side, or safety-retention record has been removed; it is a user-facing data retrieval step, not a universal erasure certificate.
Recommended preparation: decide why the export is needed before starting. A user who wants a personal archive has different needs from a security team preserving evidence after suspected account compromise. A founder closing a company workspace may need business records preserved under company policy, while an employee leaving a managed workspace may need to avoid taking proprietary or regulated material without authorization.
- Identify the account context. Confirm whether the account is personal, Business, or governed by another organization. Personal controls do not override managed-workspace policy.
- Review connected apps first. Note which apps are connected and whether their provider accounts have separate export, retention, or deletion controls. Disconnecting an app stops future access through that ChatGPT account but does not automatically delete prior chats, files, memories, other connected accounts, or administrator-managed sync.
- Review Memory separately. If sensitive, stale, or inaccurate memories exist, decide whether to remove them before or after export based on your recordkeeping need. Deleting a chat alone may not delete a saved memory.
- Review files and archived chats. OpenAI’s memory guidance warns that full deletion can require removing every source where information appears, including chats, archived chats, files, memory summary, and connected apps.
- Preserve only authorized records. Do not export employer confidential material, student records, client legal files, patient information, trade secrets, or third-party personal data unless you have authority and an approved storage location.
- Protect the export. Store downloaded archives in an encrypted, access-controlled location. Do not upload the archive to another AI tool for summarization unless the data is approved for that destination.
- Record the date and purpose. Add a non-sensitive note to the evidence log stating when the export was requested or completed and why it was needed.
Operational warning: export before deletion when you need a record. Account deletion, workspace offboarding, app disconnection, and provider-side cleanup can affect access to information in different systems. Do not assume you can reconstruct a complete history after those steps are completed.
Export triage table: what to preserve, what to avoid
| Scenario | Export recommended? | Important caution | Human approval needed? |
|---|---|---|---|
| Personal user wants a local archive before deleting an account | Yes, if the user wants to preserve conversation history or account records. | Review saved memories, files, archived chats, and connected apps separately. | Yes, the account holder should confirm the deletion and storage decision. |
| Employee leaving a managed workspace | Only if allowed by employer policy and workspace controls. | Do not take company confidential, client, regulated, or proprietary material without authorization. | Yes, from the appropriate workspace owner, administrator, legal, or security contact. |
| Security team investigating suspected account compromise | Often useful as part of evidence preservation. | Preserve chain-of-custody notes and avoid modifying potential evidence before security review. | Yes, from incident response or the designated security lead. |
| Teacher or parent reviewing a youth account | Only within applicable account authority, school policy, and household rules. | Avoid exposing unnecessary personal, educational, or health-related information. | Yes, from the responsible adult or institution according to policy. |
| Legal-technology team closing a matter workspace | Only under the firm’s retention, privilege, confidentiality, and client-file procedures. | Do not mix client material with personal archives or unapproved AI review workflows. | Yes, from the supervising attorney, records team, or authorized administrator. |
Account deletion preparation: avoid confusing deletion with every other control
Account deletion should be treated as a consequential operation requiring deliberate preparation. It is different from turning off model improvement, disabling Memory, clearing a chat, using Temporary Chat, disconnecting an app, or changing an ad-personalization preference. Those controls affect different systems and future behavior in different ways. Do not claim or assume that one toggle erases all data.
Recommended deletion preparation: make a written plan before submitting a deletion request. The plan should identify the account, the reason for deletion, whether an export is needed, which connected apps or provider accounts must be reviewed, whether workspace policy applies, and who has authority to approve the action. If the account belongs to an organization, do not let an individual user delete business records without checking retention, security, legal, finance, and customer-support obligations.
- Confirm authority. Make sure the person requesting deletion controls the account or is authorized under the organization’s process.
- Complete export if needed. If the user or organization needs a record, complete the export before deletion.
- Review Memory. Delete or correct saved memories separately if the goal includes removing personalization content.
- Review chats, archived chats, and files. Remove content from each place where it appears if the goal is source-level cleanup.
- Review connected apps. Disconnect apps when future ChatGPT access should stop, then review provider-side permissions and retained artifacts separately.
- Review workspace membership. For Business or managed contexts, check whether workspace administrators control data, sync, retention, or access policies.
- Check MFA and recovery methods. Confirm the account is secure before deletion so a compromised actor cannot interfere with the process.
- Record final approval. Add a non-sensitive evidence-log entry naming the approver role, date, and scope.
A deletion request may be appropriate when a user no longer needs the account, when an organization is consolidating accounts, when a duplicate account creates governance risk, or when a person wants to exercise account-level deletion options available to them. It may be inappropriate when litigation holds, employment retention rules, school record requirements, incident investigations, finance obligations, or client-file duties require preservation. Those determinations require qualified internal or external advice; this guide does not provide legal advice.
Privacy Portal versus Privacy Center: use the right route
OpenAI’s Privacy Center and Privacy Portal should not be treated as the same thing. The Privacy Center is described by OpenAI as an in-product area that explains privacy topics and links users to existing settings. It is a navigation and education layer for settings such as Memory, Temporary Chat, model improvement, apps, MFA, export, and deletion. Opening it does not change settings or delete data.
The Privacy Portal is a separate route for privacy-related requests described in OpenAI’s Help Center materials. Use the Privacy Center when the task is to understand or change available account settings. Use the Privacy Portal when the task is to submit a privacy request through the process OpenAI provides. If a managed workspace, school, employer, healthcare organization, or enterprise administrator controls the relevant account or data, the user may also need to work through that organization’s administrator or privacy contact.
| Need | Use Privacy Center? | Use Privacy Portal? | Additional route to check |
|---|---|---|---|
| Understand what Memory does | Yes, where available. | Usually not the first route. | OpenAI Memory Help Center article. |
| Turn model-improvement participation on or off where eligible | Yes, where it links to the relevant data control. | Usually not the first route. | Data Controls FAQ and workspace administrator if managed. |
| Disconnect an app from future account access | Yes, where app settings are surfaced. | Usually not the first route. | Provider-side app permissions and workspace sync settings. |
| Request account export or deletion | Yes, where it routes to existing options. | May be relevant depending on the request path OpenAI provides. | Organization administrator, records owner, or security lead for managed accounts. |
| Submit a formal privacy request | No, not as a substitute for the request process. | Yes, use the official process OpenAI provides. | Local privacy contact or organization administrator if the data is under a managed account. |
Decision rule: if the task is “change a setting I can control,” start with the setting or Privacy Center. If the task is “make a privacy request to OpenAI,” use the Privacy Portal route OpenAI provides. If the task concerns an employer, school, healthcare, enterprise, or other managed account, check the organization’s process before assuming the individual account holder can complete the request alone.
MFA and account-security check before any privacy change
Multi-factor authentication belongs in the same review as privacy settings because privacy controls are only meaningful when the correct person controls the account. OpenAI lists MFA among Privacy Center topics, and users should verify account security before exporting data, deleting an account, connecting apps, changing model-improvement settings, or modifying memories. A compromised account can make privacy settings appear correct while the wrong person still has access.
Recommended MFA check: confirm whether MFA is available and enabled for the account, verify that recovery methods are current, and ensure that any recovery email, authenticator method, or sign-in route belongs to the right person or organization. Do not store recovery codes in chats, prompts, shared documents, screenshots, or support tickets. Do not paste one-time codes, passwords, session cookies, API keys, or private keys into ChatGPT or any connected app.
- Start with sign-in hygiene. Confirm the user recognizes the account email, sign-in method, and any organization membership.
- Enable MFA where available. Prefer an authenticator or organization-approved method, following the current OpenAI account settings and workplace policy.
- Check recovery ownership. Make sure recovery channels are controlled by the user or organization, not a former employee, contractor, or shared inbox without governance.
- Review connected apps after MFA. Stronger sign-in does not revoke provider permissions or delete prior app artifacts.
- Investigate anomalies. Unexpected setting changes, unfamiliar connected apps, missing chats, or unexplained exports should be escalated before more changes are made.
Security warning: do not attempt to “test” account security by bypassing controls, sharing credentials, defeating access restrictions, or using another person’s account. Use approved recovery, administrator, or support channels.
Offboarding checklist for employees, contractors, students, and shared projects
Offboarding is where ChatGPT privacy and governance mistakes often surface. A user may have personal chats, employer-managed workspaces, connected apps, temporary conversations, saved memories, exported archives, and provider-side artifacts. Because OpenAI documents these as separate areas with separate effects, the safe offboarding rule is to inspect each layer rather than relying on a single disconnect, deletion, or toggle.
Recommended offboarding workflow: assign one owner for the account decision, one owner for records retention, and one owner for connected-app cleanup. In a small company, those roles may be the founder, security lead, and operations manager. In an enterprise, they may be IT, legal, privacy, and the workspace administrator. In an education setting, they may be the school administrator and the responsible educator under school policy.
| Step | Personal account | Managed workspace | Evidence to record |
|---|---|---|---|
| Confirm account ownership | User confirms whether the account is personal and whether any work content was used. | Administrator confirms workspace membership and policy. | Account context and reviewer role. |
| Preserve required records | User exports only authorized personal records. | Organization preserves records under retention and incident policies. | Export requested/completed, storage location category, and approver. |
| Review Memory | User removes stale or sensitive personal memories if desired. | Administrator follows workspace policy; personal controls may not override organization settings. | Memory reviewed and action summary. |
| Review chats, files, and archives | User deletes or retains according to personal need. | Organization determines what must be retained or removed. | Categories checked; do not copy sensitive content into the log. |
| Disconnect apps | User disconnects apps no longer needed and reviews provider permissions. | Administrator reviews approved apps, sync, and provider-side access. | Apps disconnected and provider review status. |
| Revoke organizational access | Not applicable unless personal account was linked to work systems. | Remove user from workspace or adjust membership according to policy. | Administrator action and date. |
| Secure remaining access | User updates MFA and recovery methods. | Organization confirms no former user controls recovery routes or shared credentials. | MFA/recovery reviewed. |
| Close open issues | User tracks unresolved deletion, export, or provider requests. | Organization tracks tickets through IT, privacy, legal, or security workflows. | Issue owner and deadline. |
For contractors and agencies, require explicit approval before exporting or deleting anything related to the client. For legal-technology teams, offboarding should be aligned with client-file, privilege, confidentiality, and matter-closing procedures. For educators, avoid moving student work or personal data into personal archives. For parents, focus on safety, account access, and age-appropriate use without collecting more private information than necessary.
Issue-escalation path: what to do when settings do not answer the question
Many privacy questions cannot be resolved by reading a single toggle. Escalate when the issue involves suspected compromise, unknown connected apps, disputed account ownership, managed-workspace policy, possible exposure of confidential or regulated data, a formal privacy request, a youth-safety concern, or a conflict between deletion and retention obligations. Escalation is not a sign of failure; it is the correct control when an action may affect other people, business records, legal duties, or security evidence.
- Stop making unnecessary changes. If compromise or data exposure is suspected, avoid deleting chats, disconnecting apps, or changing settings until the security or privacy owner advises what to preserve.
- Capture non-sensitive facts. Record date, account context, surface used, observed issue, app names, and screenshots if allowed by policy. Do not capture secrets, personal data, or privileged content unless the incident process requires it and storage is approved.
- Identify the owner. Personal users should use OpenAI’s official help or privacy request routes. Employees should contact the workspace administrator, IT, security, privacy, or legal team. Students and educators should use the school’s approved support route.
- Separate immediate containment from deletion. A security team may first secure the account and preserve evidence before deciding whether to delete content or submit a privacy request.
- Review connected providers. If an app was involved, check the provider account, provider permissions, and any administrator-managed sync separately from ChatGPT disconnection.
- Document final disposition. Close the evidence log with the action taken, the owner, and any remaining risk or follow-up date.
| Issue | First responder | Escalate to | Do not do |
|---|---|---|---|
| Unknown connected app appears | Account holder or workspace admin | Security team and provider administrator | Do not assume disconnecting the app deletes prior provider-side artifacts. |
| Saved memory contains sensitive or stale information | Account holder | Workspace admin or privacy owner if work-related | Do not assume deleting one chat removes the saved memory or related files. |
| Temporary Chat was saved by mistake | Account holder | Administrator if the account is managed | Do not treat the conversation as still temporary after saving; review normal history, personalization, and model-improvement context. |
| Export contains information that should not be in personal storage | Account holder | Employer, school, legal, privacy, or security owner | Do not upload the archive elsewhere for analysis before approval. |
| Possible account compromise | Account holder or help desk | Security incident response and OpenAI support route as appropriate | Do not share passwords, one-time codes, tokens, or recovery codes in a chat or ticket. |
| Formal privacy request is needed | Account holder or privacy coordinator | OpenAI Privacy Portal and organization privacy contact where applicable | Do not rely on Privacy Center alone as the request submission path. |
Conservative operating rules for high-risk work
Developers, founders, enterprise administrators, security teams, educators, parents, and legal-technology professionals should use stricter rules when ChatGPT may touch confidential, regulated, privileged, youth-related, or security-sensitive material. OpenAI’s product controls are useful, but the safer assumption is that each layer—Memory, chat history, Temporary Chat, connected apps, model improvement, exports, deletion, provider accounts, and workspace policy—must be reviewed separately.
- Use the least sensitive prompt that works. Replace names, account numbers, credentials, personal identifiers, client facts, and confidential excerpts with approved summaries or synthetic examples.
- Choose the conversation mode before the first message. Temporary Chat settings are chosen at the start; do not rely on later cleanup to convert an unsuitable conversation into a safe one.
- Review Memory before sensitive projects. If personalization could create risk, inspect or disable Memory according to your account controls and policy, while remembering that turning Memory off does not disconnect apps.
- Check app permissions before using files or external services. Connected apps may receive relevant conversation content and, when permitted, relevant memories plus technical or location information.
- Do not confuse training controls with deletion. Turning off model improvement does not remove chats from history.
- Protect exports like sensitive archives. Exports may contain conversation content, files, or metadata that should not be emailed, uploaded to unapproved tools, or stored on unmanaged devices.
- Require human approval for consequential actions. External messages, filings, submissions, account deletion, permission changes, purchases, publications, and legal commitments need an authorized person.
For Codex users, include the separate full-environment training setting in the review when applicable. OpenAI’s Data Controls FAQ notes that on personal plans the account-wide model-improvement control also applies to Codex tasks, but Codex has a separate setting for training on full environments. That distinction matters for developers who use repositories, terminals, dependencies, local files, or remote environments in ways that differ from ordinary chat messages.
Final checklist: the privacy review in one pass
The following one-pass checklist is intended for a careful user or administrator who wants a repeatable review without over-collecting sensitive material. It deliberately avoids asking the reviewer to paste private content into a new chat. Use it as an operational checklist and adapt it to your organization’s policy.
One-pass ChatGPT privacy review checklist
1. Account context
[ ] Confirm account type and whether a workspace policy applies.
[ ] Confirm Privacy Center availability, if any, without assuming it changes settings.
2. Security first
[ ] Review MFA availability and status.
[ ] Review recovery methods.
[ ] Escalate suspicious activity before changing or deleting evidence.
3. Memory
[ ] Review saved memories.
[ ] Remove stale or sensitive memories where appropriate.
[ ] Review related chats, archived chats, files, and apps separately.
4. Temporary Chat
[ ] Confirm when to use Personalized Temporary Chat.
[ ] Confirm when to use Unpersonalized Temporary Chat.
[ ] Remember Temporary Chats create no new memories while temporary and may be retained up to 30 days for safety.
[ ] If saved, treat the conversation as a regular chat.
5. Model improvement
[ ] Review account-wide data-control setting where eligible.
[ ] For Codex, review the separate full-environment training setting where applicable.
[ ] Do not treat model-improvement controls as chat-history deletion.
6. Connected apps
[ ] Review connected apps.
[ ] Review provider permissions.
[ ] Review workspace sync or administrator controls.
[ ] Disconnect only with the understanding that past artifacts require separate review.
7. Ads and location
[ ] Review ad-personalization controls where applicable.
[ ] Review location-related settings where applicable.
[ ] Do not provide sensitive information to influence ad relevance.
8. Export and deletion
[ ] Export before deletion if records are needed.
[ ] Protect exports in approved storage.
[ ] Confirm authority before account deletion.
[ ] Use Privacy Portal or official request routes for privacy requests.
9. Evidence log
[ ] Record non-sensitive actions, dates, owners, and unresolved issues.
[ ] Do not record secrets, identifiers, privileged content, or unnecessary personal data.
The central lesson is separation. Privacy Center can help users find and understand controls, but it is not a master switch. Memory is separate from chat history. Temporary Chat is separate from account deletion. Model-improvement controls are separate from history cleanup. App disconnection is separate from provider-side retention and prior artifacts. Managed-workspace policy can limit what a personal user can decide. A reliable privacy practice reviews each layer, records decisions without copying sensitive content, and escalates when account security, legal duties, organizational records, youth safety, or third-party data are involved.
Access 40,000+ AI Prompts for ChatGPT, Claude & Codex — Free!
Subscribe to get instant access to our complete Notion Prompt Library — the largest curated collection of prompts for ChatGPT, Claude, OpenAI Codex, and other leading AI models. Optimized for real-world workflows across coding, research, content creation, and business.
Useful Links
- OpenAI Help: Privacy Center in ChatGPT
- OpenAI Help: Data Controls FAQ
- OpenAI Help: Memory FAQ
- OpenAI Help: Temporary chat in ChatGPT
- OpenAI Help: Data sharing and privacy for apps in ChatGPT
- OpenAI Help: Privacy Portal

