It depends entirely on what you'd be uncomfortable seeing in a stranger's search results, a training dataset, or a court exhibit. Here's what actually happens to what you type.
As AI models have become more powerful, the policies and infrastructure meant to
protect our most confidential data have lagged behind. In only the past few
months, Apple has sued OpenAI alleging trade secret theft, Anthropic
accidentally let thousands of private sessions surface on Google, and xAI's Grok
uploaded entire user codebases to the cloud.
The variety of ways that AI can leak our data has exploded. ChatGPT users not
only need to trust that OpenAI will honor their privacy policy, they must also
hope that OpenAI servers don't get hacked, or that their infrastructure doesn't
expose a major design flaw, or that they don't get subpoenaed, which forces them
to hand over private user chats.
All of these have happened before.
What happens to things you type into ChatGPT
Before we get into OpenAI's laundry list of previous exploits, you should
understand what happens to your data in ChatGPT every day, by default. The
process below is a feature, not a bug — it's how ChatGPT is intentionally
designed to work on most available plans.
1. Your prompts are used to train OpenAI models (by default)
OpenAI's help center says that, on personal accounts, “data sharing is enabled
for you by default.”
The setting is called “Improve the model for everyone” and lives three menus
deep under Data Controls. Until you find it and switch it off, all your
conversations are eligible training material for future models. Your medical
report, work contracts, random 3am questions — all of it.
Recently there have even been reports that OpenAI may have ‘inadvertently'
used several mathematicians' private sessions to improve their model, which then
helped OpenAI solve one of the Millennium Prize problems ahead of the
mathematicians themselves. Your data could be used against you.
2. Other people can read your chats
All your ChatGPT sessions get stored — in plaintext — on OpenAI's
infrastructure, and authorized employees as well as third-party contractors can
access them for abuse review, support, and legal requests. This is standard for
any cloud service (it's disclosed in OpenAI's privacy policy), but it's still
worth saying out loud, because switching off training doesn't change who can see
your data.
3. Deleting a chat doesn't necessarily delete it
Whenever you delete a ChatGPT conversation, it gets “scheduled for permanent
deletion within 30 days.” This is the normal case — however, OpenAI's terms also
let it keep your data longer for legal or security reasons, and in 2025 a
federal court used that clause to freeze deletion for every consumer account for
about four months, Temporary Chats included. More on that below.
4. There's no ‘privilege'
When you talk to a doctor, a lawyer or a therapist, the law protects those
conversations. When you talk to ChatGPT about the same things, nothing does.
OpenAI's CEO Sam Altman said so himself on a July 2025 podcast: “if you go talk
to ChatGPT about your most sensitive stuff and then there's a lawsuit or
whatever, we could be required to produce that.” He called for a new kind of “AI
privilege” — but until one exists, your chat history is discoverable evidence.
“If you go talk to ChatGPT about your most sensitive stuff and then there's a
lawsuit or whatever, we could be required to produce that.”
Sam Altman, CEO of OpenAI, July 2025
Four months later, a court required exactly that: twenty million ChatGPT
conversations. Which brings us to the part of the story that isn't about design
choices.
A short history of ChatGPT chats getting out
Even if OpenAI enforced their privacy policy to a ‘T', there are still a dozen
different ways user data can — and has — leaked. Below is every documented case
we could find of ChatGPT user data being exposed, retained against users'
wishes, or ordered to be handed over.
We've tagged each one by who was actually responsible, because not all of these
are OpenAI's fault. The ‘fault' is secondary anyway — the fact that this can
happen in the first place is the issue.
Mar 2023OpenAI bug
Users saw strangers' chat titles — and payment details
A caching-library bug showed logged-in users other people's conversation
titles, and for some, the first message of a new chat. It also exposed
names, emails, billing addresses and partial card details for about 1.2% of
Plus subscribers active in a nine-hour window.
Jun 2023Third party
100,000+ ChatGPT logins found on the dark web
Group-IB found 101,134 infected devices with saved ChatGPT credentials in
malware logs. Not OpenAI's breach — but because ChatGPT keeps every chat by
default, a stolen password handed the buyer the victim's entire history.
Jul 2024Design flaw
The Mac app stored every chat in plain text
OpenAI's macOS app saved conversations as unencrypted files readable by any
other process on the machine. A developer demonstrated a separate app
reading chat history in real time. OpenAI encrypted local storage after it
went public.
May 2025Court order
A court orders OpenAI to keep every chat, including deleted and “temporary” ones
A magistrate judge ordered OpenAI to “preserve and segregate all output log
data that would otherwise be deleted.” Free, Plus, Pro and Team users were
all covered. OpenAI began complying in mid-May and told users on June 5.
Jun 2025Court order
OpenAI appeals. Loses.
OpenAI argued users who chose to delete deserved privacy; the district judge
pointed to OpenAI's own terms, which allow retention to meet legal
requirements. The blanket order was lifted in October 2025, but everything
captured in the meantime stays preserved.
Aug 2025Design flaw
Roughly 4,500 shared chats indexed by Google
A “make this chat discoverable” checkbox on shared links let search engines
index them. Reporters found thousands in Google results — resumes, names,
email addresses, children's names, and deeply personal disclosures. OpenAI
removed the feature on August 1.
Nov 2025Third party
Analytics vendor breach exposes API users' names and emails
An attacker exported a dataset from Mixpanel, OpenAI's analytics provider:
names, emails, approximate locations, browser data and org IDs. OpenAI says
no chat content was involved. A reminder that your data lives with every
vendor in the chain.
Nov 2025Court order
20 million private conversations ordered handed to the New York Times
The court ordered OpenAI to produce a random sample of 20 million ChatGPT
conversations to the Times and co-plaintiffs. The Times had asked for 1.4
billion. OpenAI called it “an invasion of user privacy,” lost the argument
to pre-filter, and was ordered to produce the full de-identified set.
Feb 2026Vulnerability
A single prompt could silently exfiltrate your files
Check Point Research found that ChatGPT's code-execution sandbox could
smuggle data out through DNS queries, bypassing every guardrail and approval
dialog. Fixed February 20; no known exploitation.
One more for completeness: in January 2024, an Ars Technica reader reported
opening ChatGPT to find strangers' conversations, including pharmacy portal
passwords. OpenAI disputed that this was a leak and attributed it to the
reader's account being compromised. We've left it off the main list for that
reason.
Why this keeps happening
If you look at the list above, it includes multiple failure modes: some are
bugs, some are court orders, some are vendor flaws.
That's the thing: OpenAI isn't uniquely careless. Actually, by the standards of
companies that store hundreds of millions of people's private text, they may
even be above average. The problem is structural.
Most cloud chatbots hold on to your words, and once they hold them, every future
bug, subpoena, policy change or acquisition is a claim on your data. “We
promise” is just a policy, and policies can get overridden by judges or
quarterly priorities or overworked engineers.
The only privacy guarantee that survives a subpoena is not having the data.
How to protect yourself
OpenAI says they ‘won't' misuse your data, but that promise has already been
broken dozens of times. The only way to protect yourself is to use an AI that
can't misuse your data — AI that, by design, can't let anyone read, store or
train on your data.
This is how we built Wisp, because we wanted an AI assistant we could ask about
a contract or a medical checkup without a small inside voice asking where it was
going.
Like ChatGPT, Wisp is a desktop AI app that works with your files, connects to
your tools and creates skills or workflows. But unlike ChatGPT, Wisp was
designed so that nobody — including anyone at Wisp — can see or train on your
data, while your chat sessions are only stored on your own machine.
Here's what makes Wisp different:
Your chats stay local
The Wisp app, the agent and your entire conversation history live only on your
computer, in an encrypted database. There is no server-side copy of your chats
for others to leak, index, or subpoena — if a court asks us for your
conversations, the honest answer is the only one available: we don't have them.
Your chats are confidential
Wisp uses top open-source AI models running inside a Trusted Execution Enclave —
a hardware-sealed room that nobody (even Wisp or the GPU provider) can ever
access or see inside of. Nothing is logged or stored anywhere outside of your
own machine.
Your requests are anonymized
Any identifiable requests (e.g. web search) that you send to AI aren't performed
by your machine but by Wisp on your behalf. This stops third parties like Google
from building your ad persona or user profile.
Your machine checks before sending anything
Since Wisp uses AI that runs inside sealed hardware nobody can access, the Wisp
app first needs to verify that the code running inside that hardware is correct.
To do so, Wisp requests mathematical proof that the AI runs precisely on the
promised hardware and runs exactly the promised code. If any part of that proof
doesn't match, Wisp doesn't establish a connection with the server, and your
conversation stays on your device.
Your Prompts
Encrypted on your machine. Data only stored locally.
Wisp Anonymizer
Masks your identifiable requests (e.g. web search)
AI
Runs inside a closed-off hardware enclave with no access
ChatGPT vs Wisp
Here's the four-point list from the top of this post again, this time with Wisp
in the second column:
ChatGPT
Wisp
Where your chat history lives
OpenAI's servers, in plaintext
Your machine, encrypted
Used to train models
Yes, by default
Impossible
Retained after you delete
Up to 30 days, or indefinitely under legal hold
Deleted means deleted
Can the company read it
Yes
No — AI runs inside a sealed enclave, no logs
Can be subpoenaed from the company
Yes — 20M chats already were
Nothing to produce
Privacy guarantee is…
A ‘pinky promise'
Every request is mathematically verified by your machine
So… is ChatGPT safe?
For a recipe, a limerick, or a first draft of an email you'd happily post on
LinkedIn: sure. But for the things AI is actually most useful for — reading your
contracts, summarizing your medical records, debugging code you're paid to keep
secret, talking through the thing you can't say out loud yet — ChatGPT has a
history of leaking that data, by mistake or otherwise.
If you're going to keep using ChatGPT, do the three things that actually help:
turn off “Improve the model for everyone,” never paste anything you couldn't
defend in a deposition, and remember that Temporary Chats are just a retention
setting, not a privacy guarantee.
And if you'd rather not think about any of that, just use Wisp instead.
AI that can’t leak your datacan’t AI that won’t leak your data
Switch from “trust us” to privacy by design. Only on Wisp.
Sources and verification
OpenAI, “March 20 ChatGPT outage: here's what happened” (Mar 24, 2023); The Hacker News.
Group-IB, “Group-IB discovers 100K+ compromised ChatGPT accounts on dark web marketplaces” (Jun 20, 2023).
AppleInsider / The Verge on the ChatGPT macOS app storing chats in plain text (Jul 2024).
Order, In re OpenAI Inc. Copyright Infringement Litigation, S.D.N.Y., May 13, 2025; OpenAI, “How we're responding to The New York Times' data demands” (Jun 5, 2025).
Judge Stein order denying OpenAI's objection (Jun 26, 2025); Engadget, “OpenAI no longer has to preserve all of its ChatGPT data, with some exceptions” (Oct 2025).
Sam Altman on This Past Weekend with Theo Von (Jul 2025), as reported by TechCrunch and Business Insider.
Fortune / TechCrunch on shared ChatGPT conversations indexed by Google; OpenAI's removal of the discoverability option (Aug 1, 2025).
OpenAI, “What we know about the Mixpanel security incident” (Nov 26, 2025).
ABA Journal on the order to produce 20 million de-identified ChatGPT logs (Nov 2025); OpenAI, “Fighting the New York Times' invasion of user privacy.”
OpenAI Help Center, “What if I want to keep my history on but disable model training?”
OpenAI Help Center, “How to delete and archive chats in ChatGPT.”
Check Point Research, “ChatGPT data leakage via a hidden outbound channel in the code execution runtime” (fixed Feb 20, 2026).
ChatGPT and OpenAI are trademarks of OpenAI. Wisp is not affiliated with OpenAI.