Is it safe to put client data in ChatGPT

Is client data safe in ChatGPT?

The honest answer: free ChatGPT, no. ChatGPT Enterprise, mostly yes. But for regulated work, "mostly" is not good enough. Here is what actually happens to your data, and the safer routes.

Someone in your team is already doing it. Pasting a client contract into a chat window to summarise it. Uploading a spreadsheet of customer details to check the numbers. It takes ten seconds, saves an hour, and nobody reads the terms. So the question is not whether client data touches AI. It is whether that is safe, and what to do instead if it is not.

What actually happens to data you paste into ChatGPT

On the free and Plus tiers, OpenAI may use your conversations to train its models. That means a client's contract, a patient's letter or a customer's complaint can end up influencing what the model says to a stranger next year. Prompts can also be reviewed by human checkers, and they are stored on OpenAI's servers, in the United States, under a US privacy policy.

Three separate problems sit inside that one sentence:

  • Confidentiality. You may have promised the client, in a engagement letter or an NDA, that their material stays with you. "We pasted it into a chatbot" is not an exception anyone negotiated.
  • Compliance. If the data includes anything personal under UK GDPR, you are transferring it to a third-party processor. Free ChatGPT is not set up to be a processor for you, and there is no UK data residency.
  • Control. Once it is in, getting it out again is not straightforward. Deletion settings exist, but they are your responsibility to find, set and verify.

What ChatGPT Enterprise changes

To be fair to OpenAI: the Enterprise tier is a different arrangement. Training on your data is off by default, data is encrypted, retention controls exist, and there is SOC 2 compliance and admin oversight. For a general office assistant, it is a serious option, and our full comparison of the enterprise platforms says so plainly.

But notice what did not change: the data still leaves your environment. It still sits on someone else's servers, under someone else's policy, in a jurisdiction you do not control. For most work that is fine. For regulated material, client-identifiable files, or anything your contracts say you will protect, "a big company promises to be careful" may not be the standard you are held to.

The question behind the question

When an owner asks "is it safe", they are usually really asking: can my team get the productivity without the exposure? The answer is yes, but not by being careful with ChatGPT. It comes from changing where the AI lives.

The pattern that works looks like this:

  1. The AI runs where the data already is. Documents stay in your storage, in your region or your own cloud account, and the AI comes to them rather than the other way round.
  2. You choose the model per task. Sensitive material goes to a model that never leaves your environment. General work can use frontier models. The point is that it is your decision, not a default.
  3. Knowledge is managed, not pasted. Instead of re-pasting the same client file into chat windows, it is uploaded once to a controlled knowledge base, with a record of what the AI knows and where each answer came from.
  4. There is an audit trail. When a client or an auditor asks what happened to their data, "the agent processed it under our policy, here is the log" is an answer. "Someone on the team used the free version" is not.

A quick decision guide

  • Public information, no names, no clients? Free ChatGPT is fine. Enjoy.
  • Internal work, nothing regulated, team-wide use? ChatGPT Enterprise or Copilot. Buy the assistant; it is good at this.
  • Client documents, personal data, regulated material, contractual confidentiality? This is where pasting into any hosted chat is the wrong tool, and where a platform that keeps data in your environment is worth paying for.
  • That third row is the one we built Odokai for: agents that work on your documents where they live, with your choice of model, an auditable record of everything, and a fixed bill. If you want to see how that feels in practice, the walkthroughs show real work being done in about three minutes at a time.

    The honest bottom line

    Is client data safe in ChatGPT? On the free tier, treat every paste as a disclosure you cannot take back. On Enterprise, the vendor risk is managed, but the data still leaves your building. If your work is regulated or your contracts promise confidentiality, the safe route is not a better chatbot. It is AI that lives where your data lives.

    We compare ChatGPT Enterprise, Copilot, Claude and Odokai across commercial terms, capabilities and security controls in full, including our own gaps, because a comparison that hides the weaknesses is marketing, not advice: read the comparison.

From the Blog

Notes on governed models, operational automation, and how teams move from AI-assisted pilots to broader adoption.

Wondering about your own data?

Name the documents your team handles and we will tell you straight how AI can work on them without the exposure.