Plain Answers
Is ChatGPT safe for business documents?
It depends on the plan — and the document.
For a public price list or a blog draft, yes — use whatever you like. For anything you're obligated to protect, the honest answer is: not on a consumer plan, and not until you've read the terms for the exact plan you're on. The same chatbot, under the same logo, runs under different rules depending on whether you signed up with a personal email or your company bought a business agreement.
"Is it safe?" is really four questions
When someone in your office asks whether a chatbot is "safe," they're asking four things at once:
- Will my text be used to train the model?
- How long is it kept — and does deleting it actually delete it?
- Can a person at the provider read it?
- Did the person whose information this is ever agree to any of that?
Most people only check the first one. The providers answer all four in writing. You just have to read the right document for the right plan.
Same logo, different rules
The major AI providers separate their consumer products from their business products, and say so in their own documentation. We'd rather quote them than characterize them. These were current when we checked in September 2026; terms change, so follow the links.
Anthropic describes its consumer terms as applying to "users on our Claude Free, Pro, and Max plans," and says those terms "do not apply to services under our Commercial Terms, including Claude for Work." On the consumer side, users choose whether their chats help train future models, and that choice changes how long chats are kept: "We are also extending data retention to five years, if you allow us to use your data for model training. … If you don't choose this option, you will continue with our existing 30-day data retention period." (Anthropic: Updates to Consumer Terms and Privacy Policy(opens in new tab))
Google is admirably direct in its Gemini Apps Privacy Hub: "Please don't enter confidential information that you wouldn't want a reviewer to see" — the sentence goes on to mention use in improving Google's services. The same page notes that work and school accounts "may be subject to different data handling terms." (Google: Gemini Apps Privacy Hub(opens in new tab))
Microsoft says that under its enterprise data protection commitments, "the prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation models" — and adds that the specific controls "will vary depending on a customer's Microsoft subscription plans." (Microsoft: Enterprise data protection in Copilot(opens in new tab))
OpenAI draws the same line, and states it plainly. On its consumer products: "When you use our services for individuals such as ChatGPT and Codex, we may use your content to train our models." On its business products: "By default, we do not train on any inputs or outputs from our products for business users, including ChatGPT Business, ChatGPT Enterprise, and the API." Consumer users can opt out under Settings → Data Controls, with one exception worth knowing: "If you choose to provide feedback, the entire conversation associated with that feedback may be used to train our models." (OpenAI: How your data is used to improve model performance(opens in new tab); see also its enterprise privacy page(opens in new tab))
The pattern is consistent, and it isn't sinister. Consumer plans are priced low or free, and the terms reflect that. Business plans cost more and come with contractual commitments. The mistake is assuming you have the second kind of protection while using the first kind of account.
A sorting rule that works on Monday morning
You don't need a forty-page policy to start. You need three bins:
- Already public, or harmless if it were. Marketing copy, a job posting, a question about Excel formulas. Any tool is fine.
- Internal, but nobody else's secret. Your own meeting notes, a draft process document. Use a business plan whose terms someone at your company has actually read.
- Information you're obligated to protect. Client files, patient or student records, employee records, anything under an NDA or a contract's confidentiality clause. This doesn't go into a consumer chatbot. It goes into a business plan with a signed agreement your advisor has approved — or into AI that runs on hardware you control.
If you work in a licensed or regulated profession, the third bin has rules of its own. We've written a separate page of questions to ask for each:
- Is ChatGPT HIPAA compliant?
- Can law firms use ChatGPT?
- Can therapists use AI for progress notes?
- Can CPAs use ChatGPT with client data?
- Is ChatGPT FERPA compliant?
- Can realtors use AI with client information?
- Can defense contractors use AI tools under CMMC?
- Can nonprofits use AI with client records?
Your staff may already be using it
There's a good chance someone in your office is already pasting work into a personal chatbot account. Not out of carelessness — it saves them real time and nobody told them not to. Banning it rarely works, because the time savings are real and the tool is one browser tab away.
What works is giving people a sanctioned option that's just as easy, and a one-page rule they can remember: which bin, which tool. If the approved tool is slower or worse than the one on their phone, they'll use the one on their phone.
Five things to find in any AI provider's terms
- The training default for your plan, and where the setting lives.
- The retention period — including what happens after you press delete.
- Human review. Whether people can read conversations, under what circumstances, and whether that changes with your settings.
- Subprocessors and location. Who else handles the data, and where.
- Which products the document covers. A privacy page for the enterprise product tells you nothing about the free one.
If you can't find an answer in ten minutes, that's an answer too. Our Independent Technology Review exists for exactly this: we read the vendor's documentation and architecture on your behalf and give you a written assessment before you sign.
What changes when the model runs in your building
All five of those questions assume there's a provider on the other end. There doesn't have to be. Open-weight AI models now run on hardware a small business can buy outright. The assistant on this website runs on a single 24GB graphics card in our own office. Your prompt goes from your keyboard to a machine down the hall and back. There are no terms to read because nobody else is in the loop.
It isn't free, and it isn't the right answer for everything. An entry-level in-house AI server runs roughly $1,500 to $7,500 as a one-time purchase. At the smallest end, our Archivist desktop app runs entirely on one Windows laptop, with no account and no internet connection needed after installation. And for the first bin — the harmless stuff — a public chatbot remains a perfectly good tool. Private AI earns its place the moment the document belongs to someone who trusted you with it.