Yes, ChatGPT Saves Your Data. Here's How to Keep It Secure. (2024)

ChatGPT swept the world off its feet in November 2022 and the generative AI revolution it ushered in doesn’t seem like it will disappear anytime soon. Organizations across the world are embracing AI as a do-it-all virtual assistant to review software code, write web content and find insights from financial data, among other things.But what happens with all the information you enter into ChatGPT with your prompts?

Does ChatGPT save your data? Yes, it does – and it probably saves more of it than you realize.

ChatGPT collects both your account-level information as well as your conversation history. This includes records such as your email address, device, IP address and location, as well as any public or private information you use in your ChatGPT prompts.

Here’s what that means for your business, and how you can keep your sensitive data secure.

What types of data does ChatGPT store?

If you work in IT, then what I’m about to say next probably won’t surprise you. Yes, ChatGPT saves your data.

There are two types of personal information that OpenAI says it collects in its privacy policy: personal information it receives automatically, and the personal information you provide.

The personal information ChatGPT receives automatically is no different from any other SaaS app, and includes:

  • Device data, including what device and operating system you use.
  • Usage data, including your location, the time and the version you use.
  • Log data, including your IP address and the browser you use.

All this data is used by OpenAI to analyze how its users interact with ChatGPT. But ChatGPT also saves the data you provide, which includes:

  • Account information, including your name, email address and contact details.
  • User content, including the information you use in prompts and the files you upload.

The data you provide is used to help OpenAI train the ChatGPT model to become better at answering questions and helping users.

With OpenAI collecting and storing identifying information about you and the user content you submit, countless companies across the world have moved to ban employees from using it.

However, at Forcepoint, we don’t think that’s the right move.

The risks of ChatGPT saving your data

When ChatGPT saves your data, the primary risk is that it will result in a data leak or a data breach. Though unintentional, even a common Q&A with ChatGPT can open up a business to data security risks. These include:

  • ChatGPT training from your data and sharing sensitive information, such as intellectual property or personally identifiable information, with other users outside of your organization.
  • OpenAI itself becoming a victim of a data breach, exposing the data your users have submitted.

To OpenAI’s credit, the company has made it possible for users to stop ChatGPT from training its models on your conversations. Users should take the time to turn off chat history but reviewing generative AI security on a user-by-user basis is a recipe for sensitive data to slip through the cracks.

Treating ChatGPT and generative AI as you would any other third-party software vendor is key to ensuring your organization keeps users happy and productive and its most sensitive information secure.

Take the time to develop an organizational view on generative AI depending on who should have access to it, what types of activities it can be used for, and what sort of AI programs can be used safely. This information can then feed a comprehensive strategy for securing generative AI.

Forcepoint and generative AI security

You can’t outright block generative AI. The technology isn’t going anywhere and it’s too important of a tool to ignore.

Instead, Forcepoint generative AI security solutions enable organizations to unlock the potential of AI, safely.

Forcepoint ONE SSE, part of our Data-first SASE platform, is uniquely capable of monitoring traffic to generative AI applications and preventing access by unauthorized users on both managed and unmanaged devices. Forcepoint ONE uses Threatseeker URL categorization and filtering to ensure policies are applied to the hordes of new generative AI applications that are constantly emerging, ensuring consistent coverage.

Forcepoint DLP is being used for ChatGPT by extending data security controls to the web and public cloud and preventing sensitive information from being pasted or uploaded into the chat. It prevents data from being unintentionally leaked to ChatGPT, even if the user has turned off conversation history with OpenAI.

ChatGPT saving data isn’t a security risk in and of itself but embracing generative AI without a robust data security strategy that takes it into consideration is. Talk with a Forcepoint expert today to learn how your organization can secure the use of generative AI.

###

Note:This is the sixth post in our AI In Business series. You can check out all other posts in the series via theForcepointAI tag. Here’s a list of my other posts in the series:

  • Part 1—Building an AI Strategy for Business
  • Part 2—AI in Marketing
  • Part 3—What if AI is Overhyped?
  • Part 4—The Economic Potential of AI
  • Part 5—Open or Closed LLM?
Yes, ChatGPT Saves Your Data. Here's How to Keep It Secure. (2024)

FAQs

How secure is my data in ChatGPT? ›

Is ChatGPT confidential? No, ChatGPT is not confidential. The app logs users' conversations and other personal data to train its model. OpenAI can also share users' private information with third parties like vendors or legal authorities.

Does ChatGPT retain your information? ›

Yes, ChatGPT saves your data. It saves your prompts, chat conversations and account details. These details include your name, email, IP address, and location. Collecting all this information is not uncommon.

Does ChatGPT sell your data? ›

As for how OpenAI stores ChatGPT data, the company says that its systems are located in the US. The company also requires anyone accessing your data to sign confidentiality contracts and uphold other security obligations. Your ChatGPT data isn't sold to advertisers, but OpenAI employees may see it.

Does ChatGPT store your conversations? ›

Yes, ChatGPT saves your chat history and data.

You can view your saved conversations with ChatGPT in the left panel of the ChatGPT homepage.

Can I Delete my ChatGPT history? ›

First, open the menu (via the two lines in the top-left corner). Find the chat in your history, then press and hold the conversation title. You'll see a pop-up with an option to 'Delete' in red at the bottom. Click the Delete option.

Does ChatGPT share your conversations? ›

Key Takeaways. ChatGPT stores user data including email, IP address, browser/device data, and network information, but this is standard for most online accounts. Conversations are stored for 30 days unless flagged as suspicious or violating guidelines. OpenAI may access and use conversations to improve its systems.

Can others see my ChatGPT history? ›

Only members of your workspace with the URL will see the latest messages sent in this conversation. Files you attach to the conversation will not be shared, but any file contents referenced in messages will continue to be visible.

How do I prevent ChatGPT from using my data? ›

go to “Settings & Beta” ⇒ “Data Controls” ⇒ “Chat History & training” and turn the setting off.

Are my ChatGPT conversations private? ›

Yes, all conversations are private. Unless you explicitly share the link to the conversation with others, no one is going to be able to view your conversations or the images in them.

Does OpenAI own your data? ›

OpenAI does retains ownership of fine-tuned models, however access is exclusive to the user who provided the training data. These users can delete their training data or fine-tuned models at any time.

What not to do with ChatGPT? ›

6 Things You Should Never Share with ChatGPT
  1. Sensitive Company Data. ...
  2. Creative Works and Intellectual Property. ...
  3. Financial Information. ...
  4. Personal Data. ...
  5. Usernames and Passwords. ...
  6. ChatGPT Chats.
Oct 3, 2023

Does ChatGPT save conversations forever? ›

As far as we know, yes, archived chats are meant to remain there as long as the account is active. Keep in mind though, we don't know what they might change in the future. I would recommend exporting your data just to be on the safe side.

Does ChatGPT keep data confidential? ›

Forcepoint DLP is being used for ChatGPT by extending data security controls to the web and public cloud and preventing sensitive information from being pasted or uploaded into the chat. It prevents data from being unintentionally leaked to ChatGPT, even if the user has turned off conversation history with OpenAI.

Can I trust ChatGPT? ›

Security and privacy concerns: ChatGPT requires access to user data to provide accurate responses, which raises concerns about data privacy and security. Users need to be careful about the information they share with ChatGPT and ensure that they are using a secure platform to interact with the AI language model.

Is ChatGPT a security risk? ›

As with any tool, ChatGPT will likely have vulnerabilities that can be exploited. Whether the motive is to gain unauthorised access or extract sensitive data, malicious actors can exploit it to their advantage, leaving organisations at risk.

References

Top Articles
Latest Posts
Article information

Author: Saturnina Altenwerth DVM

Last Updated:

Views: 5593

Rating: 4.3 / 5 (64 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Saturnina Altenwerth DVM

Birthday: 1992-08-21

Address: Apt. 237 662 Haag Mills, East Verenaport, MO 57071-5493

Phone: +331850833384

Job: District Real-Estate Architect

Hobby: Skateboarding, Taxidermy, Air sports, Painting, Knife making, Letterboxing, Inline skating

Introduction: My name is Saturnina Altenwerth DVM, I am a witty, perfect, combative, beautiful, determined, fancy, determined person who loves writing and wants to share my knowledge and understanding with you.