ChatGPT
ChatGPT · Chat assistant · US · chatgpt.com
services/chatgpt.yamlVendor data-handling terms
The EEA privacy policy states content may be used to improve the models that power ChatGPT and points to the data-controls setting and an opt-out procedure. Temporary Chats are excluded from training.
“As noted above, we may use Content you provide us to improve our Services, for example to train the models that power ChatGPT. / If training is enabled (see your data controls here ) or if you provide feedback, we use the content you share with us to help our models become more accurate and better at solving your specific problems and help improve their general capabilities and safety.”
“We don’t train our models on your organization’s data by default. / You decide whether your data is used for training and model improvement.”
“Once you choose to delete Personal Data, we will remove it from our systems within 30 days unless we need to retain it for longer as described below, or it has already been de-identified and disassociated from your account when you allow us to use your Content to improve our models (opens in a new window) . / For example, Temporary Chats (opens in a new window) will be automatically deleted within 30 days (unless we have to retain them for safety or legal reasons, as described further below).”
“OpenAI processes your Personal Data on servers located outside of the EEA, Switzerland and the UK for the purposes described in this policy. / This includes processing and storing your Personal Data in our facilities and servers in the United States or in countries or territories where our affiliates and partners or our vendors and service providers are located.”
Domains and endpoints
observed means seen in Unseen deployments; vendor-documented means listed by the vendor. Vendors do not publish complete lists.
| Host | Role | Source |
|---|---|---|
| *.oaiusercontent.com | upload | observed |
| chat.openai.com | app | observed |
| chatgpt.com | app | observed |
| ios.chat.openai.com | app | observed |
Assessment
Reasoning: On a consumer account, content is used for training unless the person has found and changed the data-controls setting, and it is processed in the United States under SCCs with no processor agreement for the employer. Deletion is honoured within 30 days, but content already used for training is de-identified and retained. This is the most common personal-account service seen in deployments, which makes the default setting the exposure. Business tiers exclude training by default and give the organisation retention and residency controls, which moves the exposure to which account a person is signed into.
Flags: GDPR Art. 28 (no processor agreement on consumer accounts) · GDPR Chapter V (US processing under SCCs) · Assessed 2026-09-16. The assessment is Unseen's; the terms above are the vendor's.
Changelog
- 2026-09-16Documented. Consumer training, retention, and transfer terms verified against the EEA version of the OpenAI privacy policy. Business-tier terms pending.
- 2026-09-15Listed from the Unseen catalogue with observed domains.
Corrections
Pull request on GitHub, or the form below. Changes are reviewed and recorded in the changelog.