Only on the right plan. On ChatGPT Business or Enterprise, everyday customer details are usually acceptable: OpenAI doesn't train on that data by default and will sign a data processing addendum. On the personal plans (Free, Go, Plus and Pro), keep anything that identifies a customer out, even with training switched off, because no processor contract covers it.
"Safe" also depends on what the data is and what you've already promised customers. So you'll need three things: a way to sort customer data into bands, a rule for which ChatGPT plan each band can go into, and a two-minute routine for stripping identifiers when a personal plan is all you have. All three are below, along with what to do if something has already been pasted.
What happens to a message after you press send
Most worries about ChatGPT come from not knowing where the text goes. Here is the path, as OpenAI describes it in September 2026:
- It's stored in your chat history on OpenAI's servers until you delete it. Deleted chats are removed from OpenAI's systems within 30 days, unless they've already been de-identified or OpenAI has to keep them for security or legal reasons.
- On personal plans it can be used to train future models unless you switch off "Improve the model for everyone" in Settings, under Data Controls. On business plans it isn't used for training by default.
- It can feed memory. If memory is on, details from the chat can shape later conversations. Deleting the chat doesn't necessarily delete a memory saved from it; how ChatGPT's memory settings work covers the clean-up.
- Shared links travel. Anyone with a shared chat link can open that conversation, customer details included.
- Connected apps pull data in. If someone has connected Gmail, a drive or a CRM, ChatGPT can read customer data nobody pasted by hand.
Connected apps catch people out precisely because nobody pastes anything. As an illustration, a salesperson at a small furniture maker links their work Gmail to a personal Plus account and asks "What did I promise customers this week?" The answer lists a customer's name, a delivery address that needed changing and a complaint about a damaged table, all pulled from the inbox. That's everyday customer data sitting in a personal account, and no one typed a word of it. On personal accounts, disconnect work mailboxes and drives in the account's settings. On Business, admins decide which apps the workspace may use, so the choice sits with the business rather than each user.
Temporary Chat is the one exception worth knowing. A temporary chat doesn't appear in history, doesn't create memories and isn't used for training, though OpenAI may keep a copy for up to 30 days for safety checks. It's useful for a one-off task, but it doesn't turn a personal plan into a business one.
Your plan matters more than any single setting
The biggest difference between plans isn't a toggle. It's the contract and who controls the account.
| Plan | Trains on your content by default? | Data processing addendum? | Who controls the account | Identifiable customer data? |
|---|---|---|---|---|
| Free, Go, Plus, Pro | Yes, unless each user switches it off | No, personal accounts can't sign one | Each individual | No: anonymised or generic work only |
| ChatGPT Business | No | Yes | Your workspace owner | Yes, for everyday details, with written rules |
| ChatGPT Enterprise | No | Yes | Your admins, with extra controls such as retention settings for qualifying organisations | Yes, including more sensitive work after a proper review |
| API (a tool built on OpenAI's models) | No, by default | Yes | Whoever built the tool | Depends on how the tool stores and handles data |
Why the addendum matters: under data-protection law such as the GDPR, when you hand customers' personal data to a supplier to handle on your behalf, you generally need a written contract with that supplier setting out what they may do with it. The personal plans don't come with one, and switching off training doesn't create one. That's the gap most small businesses miss. Your data-protection adviser can tell you exactly what your situation requires.
ChatGPT Business costs $25 per user a month on monthly billing or $20 a month billed annually, with a minimum of two seats. If you're weighing it against Plus, ChatGPT Plus vs ChatGPT Business goes through the differences beyond privacy.
Sort customer data into three bands before anyone pastes
A rule staff can apply in two seconds beats a policy they have to look up. Sort everything into one of three bands:
| Band | What's in it | Where it can go |
|---|---|---|
| 1. Nobody identifiable | Anonymised summaries, product questions, template wording, totals ("42 printer tickets last month"), your own prices and processes | Any plan, including free ones |
| 2. Everyday personal details | Names, email addresses, phone numbers, order or ticket history, account notes, ordinary correspondence | A business plan with a signed addendum, and only the fields the task needs |
| 3. Never in a chat assistant | Passwords, card numbers, bank details, ID documents, health information, data about children, anything a contract or NDA says can't go to third-party tools | Nowhere without a specific, approved process (and usually a specialist tool) |
A quick test for borderline cases: if this text leaked tomorrow, would you have to tell anyone? If yes, it's band 2 at least. If the answer involves a bank, a regulator or a client's lawyer, it's band 3. A few cases that come up often, sorted with that test:
- A business contact's name and job title copied from their company website. Band 2. Being public doesn't stop it being personal data, though it's the everyday kind a business plan can take.
- A complaint email that mentions a child's allergy. Band 3: health information about a child. Summarise it yourself ("customer reports an allergy concern about an order") before any AI step.
- A one-line product question signed with a first name. Band 1 once the name is deleted; the question itself identifies nobody.
- A screenshot of your CRM. Treat it as the most sensitive field visible on screen. Images carry every column in view, including the ones you forgot were there.
For a fuller method covering your whole business, not only customer data, see how to classify business data before using AI tools.
Banding works column by column, too. Say a small online florist wants ChatGPT to spot which bouquets sell best in which weeks, and starts from its order export. Sorted for that task, the columns look like this:
| Column | Band | Needed for this task? |
|---|---|---|
| order_date, product, order_value | 1 on their own | Yes: this is the whole analysis |
| customer_name, email, phone | 2 | No: delete |
| delivery_address | 2 | No: delete (keep a region column only if you're analysing delivery areas) |
| gift_message | 2, sometimes 3 ("so sorry about your diagnosis") | No: delete |
| card_last_four, payment_ref | 3 | No: delete before the file leaves the shop's system |
Three columns survive out of ten, and all three are band 1 once they're separated from the rest. At that point the analysis can run on any plan. Most sales and stock questions shrink like this once you ask what the task actually needs.
Worked example: a six-person IT support firm and its ticket queue
Take an illustrative six-person IT support firm. Four technicians pay for ChatGPT Plus themselves and expense it at $20 each, $80 a month in total. They paste ticket threads in to summarise error logs and draft replies. A typical thread holds the client contact's name and email address, device names, internal IP addresses and, now and then, a password a user typed into the ticket.
The owner has two realistic options:
- Stay on personal plans and strip every ticket. Stripping takes about two minutes per ticket. At 60 tickets a week, that's two hours of technician time. Costed at $40 an hour, it's $80 a week, or roughly $347 a month, and it relies on everyone doing it every time.
- Move everyone to ChatGPT Business. Six seats on annual billing cost $120 a month ($150 on monthly billing). That's $40 a month more than the expensed Plus accounts, with a signed addendum, no training on the data by default, and accounts the business owns when someone leaves.
At this volume, the business plan is cheaper than the stripping routine and removes the reliance on everyone remembering. One rule survives either way: passwords are band 3. Technicians delete them from the ticket before any AI step, and any credential that has appeared in a ticket gets changed regardless.
At five tickets a week the maths flips, and a stripping routine on a personal plan is perfectly reasonable for band 1 and anonymised band 2 work.
Stripping identifiers in about two minutes
When you have to use a personal plan, remove what makes the text about a real person before it leaves your screen:
- Replace names with placeholders: [CUSTOMER_A], [TECH_1], [COMPANY_1].
- Delete email addresses, phone numbers, street addresses and account or order numbers, or swap them for [EMAIL_1] and so on.
- Generalise details that could identify someone in context: "a 12-seat office" rather than the company name, "last Tuesday" rather than a date tied to a known incident.
- Keep a note of what each placeholder stands for on your own machine if you need to swap them back.
- Read it once more as if you were the customer. Could you recognise yourself? If so, generalise further.
Here's that routine applied to one illustrative ticket from the IT firm above, line by line:
| In the original ticket | After stripping |
|---|---|
| The office manager's full name and signature block | [CUSTOMER_A] |
| The dental practice's name in the subject line | [COMPANY_1] |
| "Backup failed again on RECEPTION-PC-02 (192.168.1.40)" | "Backup failed again on [DEVICE_1]" |
| "Ring me on my mobile" plus the number | Deleted |
| "My login's the usual one, password Harbour2026!" | Deleted entirely, and the password changed with the client that day |
| "Third time since the basement flooded in March" | "Third time since an earlier office incident" |
The flooding line is the one people miss. It contains no name, but anyone who knows the client would recognise it, so it gets generalised along with everything else.
Then tell ChatGPT to respect the placeholders, so it doesn't invent realistic-looking details in their place:
Personal details in the text below have been replaced with placeholders
such as [CUSTOMER_A], [COMPANY_1] and [EMAIL_1].
Keep every placeholder exactly as written in your reply.
Don't guess or invent real names, addresses, dates or contact details.
Task: draft a reply to [CUSTOMER_A] explaining that the backup job
failed because the storage quota was full, what we've done about it,
and what they need to do before Friday.
Ticket thread:
[paste the stripped thread here]
An illustrative reply to that prompt, and what to fix before sending:
Hi [CUSTOMER_A],
Last night's backup on [DEVICE_1] didn't run because the storage
quota was full. We've cleared 40 GB of old versions and increased
your quota to 2 TB, so tonight's job should complete normally.
Before Friday, please ask staff to move old scanned documents out
of the shared Desktop folder, which is where most of the space went.
[TECH_2] will check the job on Thursday morning.
Thanks,
[TECH_1]
The placeholders held, which is the point of the instruction. Two things still need a person. "Increased your quota to 2 TB" isn't in the ticket; the technician cleared space but didn't change the quota, so the model has filled in a likely-sounding action. And [TECH_2] doesn't exist; the model invented a second placeholder to name someone for the Thursday check. Fix both, swap the placeholders back from your note, and it's ready to send.
Stripping has limits. A rare incident at a small, well-known client can identify them even with every name removed. How to anonymise client data before pasting it into AI covers the harder cases, including what counts as properly anonymised rather than just renamed.
What your contracts and privacy notice may already say
Even on the right plan, you can break a promise you've already made. Check three documents:
- Client contracts and NDAs. Many business-to-business contracts restrict passing client information to third parties or require notice before you add a new supplier. An AI vendor is a new supplier.
- Your privacy notice. It should describe the kinds of suppliers that handle customer data. If an AI tool is now one of them, update the notice.
- Supplier questionnaires you've answered. If you told a client in writing that their data stays in named systems, adding ChatGPT quietly contradicts that.
Where a contract needs notice or consent, a short plain email usually opens the conversation. An illustrative version the IT support firm might send a client before moving ticket work into ChatGPT Business:
"Hi [first name], from next month we'll use ChatGPT Business, provided by OpenAI, to help summarise support tickets and draft replies. It runs under a business agreement in which OpenAI doesn't use your data to train its models, and we only include the details each ticket needs. Passwords and payment details are never entered. If your contract with us requires your written consent for a new supplier, reply to this email and we'll hold off until that's agreed."
Whether an email like that is enough depends on the wording of the contract, so if a clause is strict, check it with a solicitor before relying on notice alone.
If you're unsure whether your plan and paperwork meet data-protection law such as the GDPR, ask your data-protection adviser or a solicitor. The steps here are practical ones, not a view on the legal position for your business. For the specific question of training, does ChatGPT train on client data? compares the plans in more detail.
Settings to check this week
Whichever plan you're on, run through this list once and put a date in the diary to repeat it each quarter:
- Business plan: confirm in the workspace settings that you're on Business or Enterprise, not a personal account with a company email address. Review which connected apps are allowed.
- Personal plans: in Data Controls, turn off "Improve the model for everyone" on every account used for work. Review saved memories and delete any that mention customers.
- Old chats: search chat history for customer names and delete conversations you no longer need.
- Shared links: revoke any shared conversation that contains customer details.
- A pinned rule: one line every person can remember: "No passwords, card numbers, bank details or ID documents in any AI tool, ever."
If customer data has already gone into a personal account
It happens. Handle it calmly and in order:
- Delete the chat and any saved memory that came from it. Remember that deletion completes within 30 days, not instantly.
- Write down what was pasted, when, by whom and into which account and plan.
- Change any credentials that appeared in the text, whatever else you decide.
- Judge the risk. Band 1 or lightly identifying band 2 data in a training-off account is low risk. Band 3 data is serious.
- Decide on reporting quickly. Data-protection law such as the GDPR can require some personal data breaches to be reported to the regulator within 72 hours of you becoming aware of them. If you think it might apply, speak to your adviser the same day.
- Fix the cause: the plan, the rule or the training, so the same thing doesn't happen next week.
The note from step 2 needs only a few lines. A filled-in illustration from the IT firm, after a junior technician pasted a ticket into the wrong account:
When: Tuesday 10:40; noticed 10:50
Who: junior technician
Account: personal ChatGPT Plus; training switch was ON
What: one ticket thread: client contact's name, work email,
office phone, one password
Band: 3 (the password)
Done: chat deleted 10:55; no saved memory found; owner told
11:05; password changed with the client 11:20
Advice: data-protection adviser called 14:00; their view recorded
in the incident file
Cause: technician has a Business seat but was signed into a
personal account in the same browser
Fix: separate browser profile for work; personal AI accounts
removed from work devices
The cause line is the useful one. Nobody broke the rule on purpose; two accounts in one browser made the wrong one easy to use, and that's a thing you can fix in ten minutes.
If you'd like this written down before you need it, an AI incident response plan turns these steps into a one-page template with names against each job.
More questions about customer data and ChatGPT
Does switching off model training make a personal ChatGPT plan fine for customer data?
It removes one risk, not all of them. With training off, your chats still sit in one person's private account that the business doesn't control, there's no data processing addendum covering them, and they leave when that person leaves. For anything that identifies a customer, a business plan is the safer home. Personal plans are fine for anonymised or generic work.
Are Claude and Gemini any safer than ChatGPT for customer data?
They follow the same pattern. Claude Team and Enterprise, and Gemini inside a Google Workspace business plan, don't train on business content by default, while their consumer versions rely on a switch in privacy settings. Judge each one the same way: which plan you're on, whether the vendor will sign a data processing agreement, and who controls the account.
Is uploading a customer spreadsheet different from pasting the data?
No. An uploaded file is the same customer data in a different wrapper, so the same plan rules apply. Before uploading, delete the columns the task doesn't need. If you're asking about sales patterns, the model rarely needs names, email addresses or phone numbers, only order dates, values and product codes.
Further reads
- How to Stop AI Tools Training on Your Business Data — Switch off model training across every AI tool your team uses.
- How to Keep Customer Data Private When Your Team Uses AI — Team-wide habits that keep customer details out of the wrong tools.
- Are ChatGPT, Claude, Gemini and Copilot GDPR-Compliant? — How the main assistants compare on data-protection paperwork.
- Shadow AI: How to Stop Staff Pasting Client Data Into Free Tools — Stop staff pasting client data into free tools you haven't approved.
- What to Check in an AI Tool's Privacy Policy and Terms — Read any AI tool's privacy terms for the clauses that matter.
- GDPR and AI Tools: What a Small Business Must Do — The data-protection steps a small business should take with AI tools.
- AI Ethics for Small Businesses: A Practical Checklist — Twenty-five questions in six groups, each with why it matters and how to check, plus red lines and a nursery example run end to end.
- Can AI Manage Your Calendar and Book Meetings for You? — The five kinds of AI scheduling tool, which one fits who books whom, and the diary rules to write before letting any of them near your calendar.
- Should You Charge Clients Less When AI Speeds Up Your Work? — What to do about your prices when AI cuts the time a job takes: the rules for hourly billing, when fixed fees are fair, and how to tell clients.
- Pros and Cons of Using AI in Your Business, With Real Costs — Every pro and con of business AI with a price attached, a first-year ledger for a small law firm, and the costs that never reach an invoice.
- Do You Need a Lot of Data to Use AI in Your Business? — How much data each common AI task needs, from three example emails to two years of sales history, and why scattered data is the bigger problem.
- What Are the Risks of Using AI in My Small Business? — Eight risks of using AI in a small business, a four-factor score for your own exposure, three example risk profiles, and the cheapest control for each risk.
- Shadow AI: Is Your Team Using AI Without Telling You? — How to find the AI tools your staff use without telling you: an amnesty survey, five afternoon checks, and a keep-move-stop rule for each thing you find.
- Does a Five-Person Business Really Need an AI Policy? — Why a five-person business needs a one-page AI policy rather than a handbook: six triggers, a complete template, and when one page stops being enough.
- AI Mistakes That Damage Customer Trust, and How to Avoid Them — Nine AI mistakes customers notice, why each one stings, how to prevent it, and a 20-minute monthly check that catches problems before customers do.
- Can ChatGPT Read PDFs, Spreadsheets and Photos? What Breaks — What ChatGPT reads well in PDFs, spreadsheets and photos, the features that make it misread or skip things, and a five-minute test before you trust a figure.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: OpenAI help centre articles on data controls, Temporary Chat and chat retention; OpenAI business data privacy and enterprise privacy pages; OpenAI Data Processing Addendum; ChatGPT plan pricing (all checked September 2026).