20 July 2026

What happens to what I type into ChatGPT?

It's the question at the back of the room in every AI training session, and it deserves a straight answer: when you type something into ChatGPT — or Claude, or Gemini — where does it go? Who can see it? And is it feeding the machine?

The short version

Everything you type is sent to the company's servers, processed there, and stored in your chat history. Depending on the product and your settings, it may also be reviewed by staff in rare cases and used to train future models. "May" is doing work in that sentence — the details differ by company, by whether you're on a free, paid or business account, and by settings most people have never opened. So rather than a table of policies that will be out of date by the time you read it, here are the rules of thumb that survive the policy changes.

Five rules of thumb

  1. Assume anything you type could be read by a stranger. Not because it routinely is — but because if a sentence would be a problem in a stranger's hands, that sentence doesn't belong in a chat window. This single habit prevents almost every possible mishap.
  2. Never paste in personal data about identifiable people. Donor lists, staff HR issues, participants' details, a young person's safeguarding note. This isn't primarily an AI issue — it's your data protection obligations wearing a new hat. If you wouldn't email it to an external consultant without a data agreement, don't paste it into a consumer chatbot. Anonymise first: "a participant" rather than a name, patterns rather than records.
  3. Consumer accounts and business accounts are different animals. The free and personal versions of these products have historically been the ones that use conversations for training (usually with an off-switch buried in settings — go and find it today). The business and enterprise tiers generally promise not to train on your data, because companies wouldn't buy them otherwise. If your organisation is using AI for real work, this is the strongest argument for one organisational account instead of everyone's personal logins: you choose the settings once, and you know where work material lives.
  4. "Deleted" means "eventually". Deleting a chat removes it from your view; companies typically retain data for some period for legal and safety reasons. Occasionally a court case freezes retention entirely. Treat deletion as tidying, not shredding.
  5. Relax about the rest. Draft copy, public information, your own writing, anonymised spreadsheets, the strategy document your whole board has seen — this is not sensitive material, and treating it as if it were means forfeiting most of what these tools are useful for. The goal is calibration, not paranoia.

What about the training question itself?

Some people object to their words training future models on principle, separate from any privacy risk — a smaller cousin of the argument artists have been making all along, and a perfectly coherent position. If it's yours, the off-switches exist: training opt-outs in the consumer products, or business tiers where opting out is the default. You don't have to accept the trade to use the tools.

Make it a decision, not a drift

The risk for most arts organisations isn't a dramatic breach. It's drift: five staff on five personal accounts with five different settings, pasting who-knows-what, because nobody ever decided anything. One meeting fixes it. Decide which tool, on what account, with which settings; write down what must never go in (rule 2 is your starting text); and put it in the one-page policy everyone actually reads. Then the question at the back of the room gets the best possible answer: "Here's exactly where it goes — we checked."

The image above was AI-generated — as ever, we'll always tell you.