AI Exposure · AI chatbot

What ChatGPT actually does with your data

The one your staff are probably already using. What happens to what they type depends entirely on whose account it is.

Trains on your data
Depends on the account
Processed
Mostly the US
Can you turn it off
Not for personal accounts
Verified
2 July 2026, against OpenAI's published documents

What AI is in it?

  • The chat itself. Whatever someone types or pastes into the conversation goes to OpenAI's servers to be answered. That includes documents and spreadsheets uploaded as attachments.

Does your data train AI models?

Depends on the account.

On personal accounts, Free, Plus and Pro, conversations are used to improve OpenAI's models by default. The person can turn this off: the setting is called "Improve the model for everyone", under Settings, then Data Controls.

On the business plans, ChatGPT Business (which used to be called Team), Enterprise and Edu, OpenAI says your data is not used for training unless you opt in. The training question is really an account question.

Where is your data processed?

Mostly the US.

For a personal account, assume the United States. The business plans come with published enterprise privacy commitments, and OpenAI now offers data residency for new business workspaces in several regions including the UK, meaning conversations and uploaded files can be stored at rest here.

A personal account has none of that. It is a consumer service under consumer terms.

What changes between free and paid?

The tier is the story.

A member of staff with a personal ChatGPT account is an individual consumer in the eyes of the terms. Your organisation has no contract with OpenAI, no admin view of what is being pasted in, and no say in the settings.

The paid business plans exist precisely to change that. Most charity ChatGPT use I encounter is on personal accounts.

Can your organisation turn it off?

Not for personal accounts.

If staff use personal accounts there is nothing for an administrator to control, because there is no administrator. Nobody in your organisation can see the conversations, change the settings or switch anything off. Business and Enterprise plans add a workspace an admin actually manages.

What does this mean for the people you support?

ChatGPT can only see what someone gives it, but people give it a lot.

A caseworker pasting notes to tidy them up, or a fundraiser uploading a donor export to find patterns, is moving personal data about real people onto a consumer service under terms nobody in your organisation has read, let alone signed.

What to check this week

  1. Find out which accounts are in use. Ask, without blame, who uses ChatGPT for work and whether it is a personal or a work account. An amnesty tone gets honest answers. Punishment tones get silence.
  2. Turn off model improvement on personal accounts. Anyone using a personal account for anything work adjacent should open Settings, then Data Controls, and turn off "Improve the model for everyone".
  3. Give regular users a proper home. If people rely on it weekly, a ChatGPT Business plan or a private alternative puts the use under an agreement your organisation actually holds, and Business workspaces can be set up with UK data residency.

Sources

Everything above is my plain English reading of what OpenAI publishes. The originals:

Vendors change these documents quietly and often. If you spot something out of date, email me and I'll re-verify the entry.

What this page cannot tell you

This page can tell you what ChatGPT does with what goes into it. It cannot tell you what goes into it at your organisation, and that is the half that matters.

The answers above kept splitting on whose account it is, and the free personal kind is invisible to you: it shows up in no system you run and on no bill you pay, and nobody declares it on a survey.

So the next step is not a setting. It is finding out what is being pasted, by whom, from which accounts, which is what a discovery is for. And your team needs a rule clearer than "be careful", which my free Charity AI Policy Generator writes with you in a few minutes.

See your whole toolkit at once

This page covers one tool. The AI Exposure Report Generator covers your toolkit: tick the tools your charity uses and get one report showing what the AI inside each of them does with your data, as a Word document you can table at your next meeting. Free, and nothing you tick leaves your browser.

The Report Generator, start to finish: tick your tools, read your exposure, download the report.

Generate your charity's AI exposure report →

Read the other tools

The same questions, answered for every tool in the directory.

Your office suite

AI chatbots

Meeting notetakers

Charity CRMs

Accounts

Marketing and design


Start with a discovery

The first step is always the same, and it's a small one: a short, fixed-price discovery. Over a couple of weeks I work out what your team is already doing with AI, where your data actually lives, and the one thing worth building first. You get a written report and a call to talk it through, with no obligation to go further. It's genuinely useful on its own, whether or not we end up building anything.

Here's a sample, laid out exactly as the real one is delivered.

Cover of a sample Private AI Discovery report, prepared for a UK charity
See the sample report → PDF, opens in a new tab

For context: I work mainly with UK charities and non profits, with chief executives, operations and finance directors, programme leads, and the people who look after data and IT. Respectfully, I don't work with recruitment or development agencies.

Not sure it's time for that yet? Just email me, tell me who you are and what your organisation does: peter@peterbrady.co.uk