Guides11 min read

Is ChatGPT safe? An honest answer, with receipts

It depends entirely on what you'd be uncomfortable seeing in a stranger's search results, a training dataset, or a court exhibit. Here's what actually happens to what you type.

All posts

As AI models have become more powerful, the policies and infrastructure meant to protect our most confidential data have lagged behind. In only the past few months, Apple has sued OpenAI alleging trade secret theft, Anthropic accidentally let thousands of private sessions surface on Google, and xAI's Grok uploaded entire user codebases to the cloud.

The variety of ways that AI can leak our data has exploded. ChatGPT users not only need to trust that OpenAI will honor their privacy policy, they must also hope that OpenAI servers don't get hacked, or that their infrastructure doesn't expose a major design flaw, or that they don't get subpoenaed, which forces them to hand over private user chats.

All of these have happened before.

What happens to things you type into ChatGPT

Before we get into OpenAI's laundry list of previous exploits, you should understand what happens to your data in ChatGPT every day, by default. The process below is a feature, not a bug — it's how ChatGPT is intentionally designed to work on most available plans.

1. Your prompts are used to train OpenAI models (by default)

OpenAI's help center says that, on personal accounts, “data sharing is enabled for you by default.”

The setting is called “Improve the model for everyone” and lives three menus deep under Data Controls. Until you find it and switch it off, all your conversations are eligible training material for future models. Your medical report, work contracts, random 3am questions — all of it.

Recently there have even been reports that OpenAI may have ‘inadvertently' used several mathematicians' private sessions to improve their model, which then helped OpenAI solve one of the Millennium Prize problems ahead of the mathematicians themselves. Your data could be used against you.

2. Other people can read your chats

All your ChatGPT sessions get stored — in plaintext — on OpenAI's infrastructure, and authorized employees as well as third-party contractors can access them for abuse review, support, and legal requests. This is standard for any cloud service (it's disclosed in OpenAI's privacy policy), but it's still worth saying out loud, because switching off training doesn't change who can see your data.

3. Deleting a chat doesn't necessarily delete it

Whenever you delete a ChatGPT conversation, it gets “scheduled for permanent deletion within 30 days.” This is the normal case — however, OpenAI's terms also let it keep your data longer for legal or security reasons, and in 2025 a federal court used that clause to freeze deletion for every consumer account for about four months, Temporary Chats included. More on that below.

4. There's no ‘privilege'

When you talk to a doctor, a lawyer or a therapist, the law protects those conversations. When you talk to ChatGPT about the same things, nothing does.

OpenAI's CEO Sam Altman said so himself on a July 2025 podcast: “if you go talk to ChatGPT about your most sensitive stuff and then there's a lawsuit or whatever, we could be required to produce that.” He called for a new kind of “AI privilege” — but until one exists, your chat history is discoverable evidence.

“If you go talk to ChatGPT about your most sensitive stuff and then there's a lawsuit or whatever, we could be required to produce that.”

Sam Altman, CEO of OpenAI, July 2025

Four months later, a court required exactly that: twenty million ChatGPT conversations. Which brings us to the part of the story that isn't about design choices.

A short history of ChatGPT chats getting out

Even if OpenAI enforced their privacy policy to a ‘T', there are still a dozen different ways user data can — and has — leaked. Below is every documented case we could find of ChatGPT user data being exposed, retained against users' wishes, or ordered to be handed over.

We've tagged each one by who was actually responsible, because not all of these are OpenAI's fault. The ‘fault' is secondary anyway — the fact that this can happen in the first place is the issue.

Mar 2023OpenAI bug

Users saw strangers' chat titles — and payment details

A caching-library bug showed logged-in users other people's conversation titles, and for some, the first message of a new chat. It also exposed names, emails, billing addresses and partial card details for about 1.2% of Plus subscribers active in a nine-hour window.

Jun 2023Third party

100,000+ ChatGPT logins found on the dark web

Group-IB found 101,134 infected devices with saved ChatGPT credentials in malware logs. Not OpenAI's breach — but because ChatGPT keeps every chat by default, a stolen password handed the buyer the victim's entire history.

Jul 2024Design flaw

The Mac app stored every chat in plain text

OpenAI's macOS app saved conversations as unencrypted files readable by any other process on the machine. A developer demonstrated a separate app reading chat history in real time. OpenAI encrypted local storage after it went public.

May 2025Court order

A court orders OpenAI to keep every chat, including deleted and “temporary” ones

A magistrate judge ordered OpenAI to “preserve and segregate all output log data that would otherwise be deleted.” Free, Plus, Pro and Team users were all covered. OpenAI began complying in mid-May and told users on June 5.

Jun 2025Court order

OpenAI appeals. Loses.

OpenAI argued users who chose to delete deserved privacy; the district judge pointed to OpenAI's own terms, which allow retention to meet legal requirements. The blanket order was lifted in October 2025, but everything captured in the meantime stays preserved.

Aug 2025Design flaw

Roughly 4,500 shared chats indexed by Google

A “make this chat discoverable” checkbox on shared links let search engines index them. Reporters found thousands in Google results — resumes, names, email addresses, children's names, and deeply personal disclosures. OpenAI removed the feature on August 1.

Nov 2025Third party

Analytics vendor breach exposes API users' names and emails

An attacker exported a dataset from Mixpanel, OpenAI's analytics provider: names, emails, approximate locations, browser data and org IDs. OpenAI says no chat content was involved. A reminder that your data lives with every vendor in the chain.

Nov 2025Court order

20 million private conversations ordered handed to the New York Times

The court ordered OpenAI to produce a random sample of 20 million ChatGPT conversations to the Times and co-plaintiffs. The Times had asked for 1.4 billion. OpenAI called it “an invasion of user privacy,” lost the argument to pre-filter, and was ordered to produce the full de-identified set.

Feb 2026Vulnerability

A single prompt could silently exfiltrate your files

Check Point Research found that ChatGPT's code-execution sandbox could smuggle data out through DNS queries, bypassing every guardrail and approval dialog. Fixed February 20; no known exploitation.

One more for completeness: in January 2024, an Ars Technica reader reported opening ChatGPT to find strangers' conversations, including pharmacy portal passwords. OpenAI disputed that this was a leak and attributed it to the reader's account being compromised. We've left it off the main list for that reason.

Why this keeps happening

If you look at the list above, it includes multiple failure modes: some are bugs, some are court orders, some are vendor flaws.

That's the thing: OpenAI isn't uniquely careless. Actually, by the standards of companies that store hundreds of millions of people's private text, they may even be above average. The problem is structural.

Most cloud chatbots hold on to your words, and once they hold them, every future bug, subpoena, policy change or acquisition is a claim on your data. “We promise” is just a policy, and policies can get overridden by judges or quarterly priorities or overworked engineers.

The only privacy guarantee that survives a subpoena is not having the data.

How to protect yourself

OpenAI says they ‘won't' misuse your data, but that promise has already been broken dozens of times. The only way to protect yourself is to use an AI that can't misuse your data — AI that, by design, can't let anyone read, store or train on your data.

This is how we built Wisp, because we wanted an AI assistant we could ask about a contract or a medical checkup without a small inside voice asking where it was going.

Like ChatGPT, Wisp is a desktop AI app that works with your files, connects to your tools and creates skills or workflows. But unlike ChatGPT, Wisp was designed so that nobody — including anyone at Wisp — can see or train on your data, while your chat sessions are only stored on your own machine.

Here's what makes Wisp different:

Your chats stay local

The Wisp app, the agent and your entire conversation history live only on your computer, in an encrypted database. There is no server-side copy of your chats for others to leak, index, or subpoena — if a court asks us for your conversations, the honest answer is the only one available: we don't have them.

Your chats are confidential

Wisp uses top open-source AI models running inside a Trusted Execution Enclave — a hardware-sealed room that nobody (even Wisp or the GPU provider) can ever access or see inside of. Nothing is logged or stored anywhere outside of your own machine.

Your requests are anonymized

Any identifiable requests (e.g. web search) that you send to AI aren't performed by your machine but by Wisp on your behalf. This stops third parties like Google from building your ad persona or user profile.

Your machine checks before sending anything

Since Wisp uses AI that runs inside sealed hardware nobody can access, the Wisp app first needs to verify that the code running inside that hardware is correct.

To do so, Wisp requests mathematical proof that the AI runs precisely on the promised hardware and runs exactly the promised code. If any part of that proof doesn't match, Wisp doesn't establish a connection with the server, and your conversation stays on your device.

Your Prompts

Encrypted on your machine. Data only stored locally.

Wisp Anonymizer

Masks your identifiable requests (e.g. web search)

AI

Runs inside a closed-off hardware enclave with no access

ChatGPT vs Wisp

Here's the four-point list from the top of this post again, this time with Wisp in the second column:

ChatGPTWisp
Where your chat history livesOpenAI's servers, in plaintextYour machine, encrypted
Used to train modelsYes, by defaultImpossible
Retained after you deleteUp to 30 days, or indefinitely under legal holdDeleted means deleted
Can the company read itYesNo — AI runs inside a sealed enclave, no logs
Can be subpoenaed from the companyYes — 20M chats already wereNothing to produce
Privacy guarantee is…A ‘pinky promise'Every request is mathematically verified by your machine

So… is ChatGPT safe?

For a recipe, a limerick, or a first draft of an email you'd happily post on LinkedIn: sure. But for the things AI is actually most useful for — reading your contracts, summarizing your medical records, debugging code you're paid to keep secret, talking through the thing you can't say out loud yet — ChatGPT has a history of leaking that data, by mistake or otherwise.

If you're going to keep using ChatGPT, do the three things that actually help: turn off “Improve the model for everyone,” never paste anything you couldn't defend in a deposition, and remember that Temporary Chats are just a retention setting, not a privacy guarantee.

And if you'd rather not think about any of that, just use Wisp instead.

AI that can’t leak your data

Switch from “trust us” to privacy by design. Only on Wisp.

Sources and verification

  1. OpenAI, “March 20 ChatGPT outage: here's what happened” (Mar 24, 2023); The Hacker News.
  2. Group-IB, “Group-IB discovers 100K+ compromised ChatGPT accounts on dark web marketplaces” (Jun 20, 2023).
  3. AppleInsider / The Verge on the ChatGPT macOS app storing chats in plain text (Jul 2024).
  4. Order, In re OpenAI Inc. Copyright Infringement Litigation, S.D.N.Y., May 13, 2025; OpenAI, “How we're responding to The New York Times' data demands” (Jun 5, 2025).
  5. Judge Stein order denying OpenAI's objection (Jun 26, 2025); Engadget, “OpenAI no longer has to preserve all of its ChatGPT data, with some exceptions” (Oct 2025).
  6. Sam Altman on This Past Weekend with Theo Von (Jul 2025), as reported by TechCrunch and Business Insider.
  7. Fortune / TechCrunch on shared ChatGPT conversations indexed by Google; OpenAI's removal of the discoverability option (Aug 1, 2025).
  8. OpenAI, “What we know about the Mixpanel security incident” (Nov 26, 2025).
  9. ABA Journal on the order to produce 20 million de-identified ChatGPT logs (Nov 2025); OpenAI, “Fighting the New York Times' invasion of user privacy.”
  10. OpenAI Help Center, “What if I want to keep my history on but disable model training?”
  11. OpenAI Help Center, “How to delete and archive chats in ChatGPT.”
  12. Check Point Research, “ChatGPT data leakage via a hidden outbound channel in the code execution runtime” (fixed Feb 20, 2026).

ChatGPT and OpenAI are trademarks of OpenAI. Wisp is not affiliated with OpenAI.