← All pages

1. What the document is: OpenAI's consumer-facing Privacy Policy: what personal data it collects, why, the legal basis for each use (in GDPR-style tables), how long data is kept, and how it moves across borders. This is the consumer counterpart to ChatGPT_Business_Privacy_Policy.md — the contrast between the two is the most important finding on this page.

What this wiki found — complete, every page

AI trainingRoyalty-freeSublicensablePerpetual / irrevocableTransferableDerivative works

Presence facts, not verdicts — each flagged term links to its definition and the exact clause on this page. Absence of a badge means the term isn't currently flagged here, not that the page is risk-free.

ChatGPT – Privacy Policy

Dataset: GenGA (Generative AI Governance Archive) — 11 AI services, 2025–present

GenGA (Generative AI Governance Archive) is this wiki’s Generative-AI dataset: raw policy snapshots captured by the Open Terms Archive genai-eu project across 11 GenAI providers (ChatGPT, Claude.ai, DeepSeek, Google Generative AI Services, Le Chat, Llama API, Meta AI, Microsoft Copilot, Perplexity, Qwen Chat, xAI). Unlike PGAv2, GenGA has no pre-tagged risk scores — all risk scoring and keyword tagging on these pages is LLM-assigned by direct reading, spanning 2025–present.

Note: This page contains documented policy clauses. Risk assessment is qualitative and context-dependent. For analysis of patterns across platforms, see:

Source: sources/GenGA/ChatGPT/Privacy Policy/ (raw Markdown captures, Open Terms Archive genai-eu dataset — no pre-tagged JSONL exists for this source) Last updated: 2026-01-21

Note on methodology: No pre-computed risk_score/keyword fields exist for this source. Keyword tags and clause analysis on this page are LLM-assigned, using the same rubric/vocabulary as the PGAv2 pages plus new GenAI-specific tags (input license, gdpr). Treat as first-pass analysis, not externally verified ground truth. This wiki’s risk-scoring system was retired project-wide on 2026-06-21 (see methodology.md §4) — no page, GenGA included, computes or displays a numeric risk score.


Overview

1. What the document is: OpenAI’s consumer-facing Privacy Policy: what personal data it collects, why, the legal basis for each use (in GDPR-style tables), how long data is kept, and how it moves across borders. This is the consumer counterpart to ChatGPT_Business_Privacy_Policy.md — the contrast between the two is the most important finding on this page.

2. Input rights: Unlike the Business tier (opt-in only), consumer ChatGPT trains on your content by default: “When you use our services for individuals such as ChatGPT, Sora, or Operator, we may use your content to train our models.” You have to opt out yourself — either through a privacy-portal toggle (“do not train on my content”) or by using Temporary Chat to exclude a conversation. OpenAI’s stated legal basis for this is “legitimate interests” — a GDPR category that lets a company use your data without asking for consent, so long as it can justify the interest.

3. Output restrictions: Not addressed in this document (see ChatGPT_Terms_of_Service.md for the Terms of Use instead).

4. Non-explicit predatory clauses: The weakest point in this document is that legal basis: instead of asking users to opt in before training on their content, OpenAI opts everyone in by default and justifies it under a broad, self-defined “legitimate interest” (“developing, improving, or promoting our Services… and broader society”).

5. Regulatory references: GDPR is cited explicitly and repeatedly — Article 45(1) (adequacy decisions) and Article 46(2)(c) (Standard Contractual Clauses, the EU’s pre-approved contract for moving data abroad) govern international transfers, alongside the UK Data Transfer Addendum. No EU AI Act reference found.

6. Regional variation: The GDPR-specific legal-basis table (Purpose / Data Type / Legal Basis columns) and EU-only transfer mechanisms (adequacy decisions, SCCs) mark this as the EU/EEA version of the policy, matching the dataset’s genai-eu scope.

7. Key risk to users: The default opt-out model is the main risk: consumer users have to take action — through the privacy portal or Temporary Chat — to stop their conversations from training future models. Business-tier users get no-training by default instead.

Flagged Keywords & Risks (LLM-assigned)

Regulatory & Research Context

Pandit et al. (2026) found that all six GenAI services they coded, including OpenAI’s ChatGPT, used inputs and outputs “for other purposes beyond” the immediate service; the default opt-out training clause here — justified by “legitimate interests” rather than consent — is a direct instance of that pattern, and stands in explicit contrast to the opt-in framing this wiki documents on the Business Privacy Policy page. Davidson et al. (2026), who studied OpenAI directly, note the consumer/business divergence in training defaults as part of the broader “regulatory gray areas” their comparative analysis maps across providers’ Terms.


Changes Summary

DateWhat changed
2025-11-11Baseline version (first capture in this dataset).
2026-01-21Cosmetic only: HTML list-item whitespace (<br> line-break spacing) normalized in the processing-purpose table; no wording change to any clause, including the training/opt-out and GDPR clauses.

Version History

2025-11-11

Clause: input license, train AI/models

When you use our services for individuals such as ChatGPT, Sora, or Operator, we may use your content to train our models. You can opt out of training through our privacy portal by clicking on “do not train on my content.” To turn off training for your ChatGPT and Operator conversations, follow the instructions in our Data Controls FAQ. Once you opt out, new conversations will not be used to train our models.

Clause: gdpr

We rely on the European Commission’s adequacy decisions pursuant to Article 45(1) GDPR when transferring your Personal Data to any country that has been considered to provide an adequate level of protection. For other jurisdictions, we rely on the Standard Contractual Clauses (“SCCs”) as approved by the European Commission pursuant to Article 46(2)(c) GDPR and on the UK Data Transfer Addendum.


2026-01-21

All clauses unchanged from 2025-11-11 (see above) — this date’s only change was HTML whitespace formatting in the processing-purpose table.