1. What the document is: OpenAI's consumer-facing Privacy Policy: what personal data it collects, why, the legal basis for each use (in GDPR-style tables), how long data is kept, and how it moves across borders. This is the consumer counterpart to ChatGPT_Business_Privacy_Policy.md — the contrast between the two is the most important finding on this page.
What this wiki found — complete, every page
Presence facts, not verdicts — each flagged term links to its definition and the exact clause on this page. Absence of a badge means the term isn't currently flagged here, not that the page is risk-free.
ChatGPT – Privacy Policy
Dataset: GenGA (Generative AI Governance Archive) — 11 AI services, 2025–present
GenGA (Generative AI Governance Archive) is this wiki’s Generative-AI dataset: raw policy snapshots captured by the Open Terms Archive
genai-euproject across 11 GenAI providers (ChatGPT, Claude.ai, DeepSeek, Google Generative AI Services, Le Chat, Llama API, Meta AI, Microsoft Copilot, Perplexity, Qwen Chat, xAI). Unlike PGAv2, GenGA has no pre-tagged risk scores — all risk scoring and keyword tagging on these pages is LLM-assigned by direct reading, spanning 2025–present.
Note: This page contains documented policy clauses. Risk assessment is qualitative and context-dependent. For analysis of patterns across platforms, see:
Source: sources/GenGA/ChatGPT/Privacy Policy/ (raw Markdown captures, Open Terms Archive genai-eu dataset — no pre-tagged JSONL exists for this source)
Last updated: 2026-01-21
Note on methodology: No pre-computed
risk_score/keywordfields exist for this source. Keyword tags and clause analysis on this page are LLM-assigned, using the same rubric/vocabulary as the PGAv2 pages plus new GenAI-specific tags (input license,gdpr). Treat as first-pass analysis, not externally verified ground truth. This wiki’s risk-scoring system was retired project-wide on 2026-06-21 (seemethodology.md§4) — no page, GenGA included, computes or displays a numeric risk score.
Overview
1. What the document is: OpenAI’s consumer-facing Privacy Policy: what personal data it collects, why, the legal basis for each use (in GDPR-style tables), how long data is kept, and how it moves across borders. This is the consumer counterpart to ChatGPT_Business_Privacy_Policy.md — the contrast between the two is the most important finding on this page.
2. Input rights: Unlike the Business tier (opt-in only), consumer ChatGPT trains on your content by default: “When you use our services for individuals such as ChatGPT, Sora, or Operator, we may use your content to train our models.” You have to opt out yourself — either through a privacy-portal toggle (“do not train on my content”) or by using Temporary Chat to exclude a conversation. OpenAI’s stated legal basis for this is “legitimate interests” — a GDPR category that lets a company use your data without asking for consent, so long as it can justify the interest.
3. Output restrictions: Not addressed in this document (see ChatGPT_Terms_of_Service.md for the Terms of Use instead).
4. Non-explicit predatory clauses: The weakest point in this document is that legal basis: instead of asking users to opt in before training on their content, OpenAI opts everyone in by default and justifies it under a broad, self-defined “legitimate interest” (“developing, improving, or promoting our Services… and broader society”).
5. Regulatory references: GDPR is cited explicitly and repeatedly — Article 45(1) (adequacy decisions) and Article 46(2)(c) (Standard Contractual Clauses, the EU’s pre-approved contract for moving data abroad) govern international transfers, alongside the UK Data Transfer Addendum. No EU AI Act reference found.
6. Regional variation: The GDPR-specific legal-basis table (Purpose / Data Type / Legal Basis columns) and EU-only transfer mechanisms (adequacy decisions, SCCs) mark this as the EU/EEA version of the policy, matching the dataset’s genai-eu scope.
7. Key risk to users: The default opt-out model is the main risk: consumer users have to take action — through the privacy portal or Temporary Chat — to stop their conversations from training future models. Business-tier users get no-training by default instead.
Flagged Keywords & Risks (LLM-assigned)
input license,train AI/models— “We may use your content to train our models… You can opt out of training through our privacy portal.” Why it matters: this is the single most consequential clause in the document — consumer content trains OpenAI’s models by default, justified by “legitimate interests” rather than consent, and it’s the direct contrast point with the Business Privacy Policy’s opt-in approach.gdpr— Explicit citations to GDPR Articles 45(1) and 46(2)(c) for international transfers. Why it matters: concrete regulatory grounding — useful for comparing how explicitly different providers cite the law they’re complying with.
Regulatory & Research Context
Pandit et al. (2026) found that all six GenAI services they coded, including OpenAI’s ChatGPT, used inputs and outputs “for other purposes beyond” the immediate service; the default opt-out training clause here — justified by “legitimate interests” rather than consent — is a direct instance of that pattern, and stands in explicit contrast to the opt-in framing this wiki documents on the Business Privacy Policy page. Davidson et al. (2026), who studied OpenAI directly, note the consumer/business divergence in training defaults as part of the broader “regulatory gray areas” their comparative analysis maps across providers’ Terms.
Changes Summary
| Date | What changed |
|---|---|
| 2025-11-11 | Baseline version (first capture in this dataset). |
| 2026-01-21 | Cosmetic only: HTML list-item whitespace (<br> line-break spacing) normalized in the processing-purpose table; no wording change to any clause, including the training/opt-out and GDPR clauses. |
Version History
2025-11-11
- Explicit AI clause: YES
- Non-explicit predatory: YES
- Flagged keywords:
input license,train AI/models,gdpr
Clause: input license, train AI/models
When you use our services for individuals such as ChatGPT, Sora, or Operator, we may use your content to train our models. You can opt out of training through our privacy portal by clicking on “do not train on my content.” To turn off training for your ChatGPT and Operator conversations, follow the instructions in our Data Controls FAQ. Once you opt out, new conversations will not be used to train our models.
Clause: gdpr
We rely on the European Commission’s adequacy decisions pursuant to Article 45(1) GDPR when transferring your Personal Data to any country that has been considered to provide an adequate level of protection. For other jurisdictions, we rely on the Standard Contractual Clauses (“SCCs”) as approved by the European Commission pursuant to Article 46(2)(c) GDPR and on the UK Data Transfer Addendum.
2026-01-21
- Explicit AI clause: YES
- Non-explicit predatory: YES
- Flagged keywords:
input license,train AI/models,gdpr
All clauses unchanged from 2025-11-11 (see above) — this date’s only change was HTML whitespace formatting in the processing-purpose table.