Conversations and code you enter into ChatGPT or Codex may be used to train models on personal plans, depending on your settings. A Pro subscription does not automatically exclude your data from training. However, discovering that training was enabled does not, by itself, establish that confidential information was disclosed to someone else.

Conversations and tasks

Check the setting for the same account

ChatGPT's “Improve the model for everyone” setting also applies to Codex on personal plans. Opting out covers new conversations and tasks started afterward.

Codex environments

Check a separate setting

Official documentation describes Include environments. Turning off training for conversations and tasks does not change this setting.

Retention and human access

Training off ≠ all data deleted

Retention and access for purposes such as safety and support are separate. Stopping training use and deleting stored data are different actions.

Sources: OpenAI's Data Controls and data handling in consumer services. Checked October 4, 2026.

Jump to a section (contents)

1. Default settings and differences between plans

Personal plans and business offerings have different training defaults. This does not mean that an account you previously opted out is currently opted in. Official guidance: keeping history while disabling training.

Personal Free, Plus, and Pro

Data sharing is on by default

You can opt out through ChatGPT's Data Controls. Paid Pro accounts follow the same rule.

For Codex on personal plans, conversations and tasks follow the same setting as ChatGPT. Check environment training separately.

Business, Enterprise, Edu, and the API

Not used for training by default

Check your workspace and your organization's retention and access policies. For the API, also check whether your organization has enabled data sharing.

No training does not mean no processing or storage.

For the API, organization owners can enable data sharing. Official guidance: training use across services.

2. Checking settings for ChatGPT and Codex

For Codex on a personal plan, start with the same OpenAI account you use to sign in to Codex. If ChatGPT in your browser and the Codex app use different accounts, checking just one is not enough.

  1. Match the accounts Check the signed-in account and workspace in ChatGPT and Codex.
  2. Open settings In ChatGPT, go to Settings → Data Controls.
  3. Check the switch Look at the state of “Improve the model for everyone.”
  4. Decide for yourself To stop training use, turn it off and save. If it is already off, no change is needed.

Where this setting applies

The same account → across devices

ChatGPT New conversations after opting out
Codex on personal plans New tasks after opting out

Other accounts are unchanged. Check Include environments and the exception for feedback you submit separately.

Official guidance says this choice is tied to your signed-in account and applies across devices. You can also opt out of training on conversations and Codex tasks through “Do not train on my content” in the Privacy Portal. You do not need to use both methods. The opt-out covers new conversations and tasks after you opt out. Official guidance: the steps and their application to Codex.

This action does not change Include environments, discussed below. Record the results separately—for example, “Account A: conversation and task training off” and “Environment setting: could not verify”—so that unknowns remain visible. If you have multiple accounts, check each one yourself.

3. When you cannot find Include environments

Include environments is an independent setting that controls whether Codex environments may be used for training. The material checked for this article does not publish a complete list of files covered, the detailed local and cloud scope, or the current default. Official guidance: Codex's independent setting.

What our screen check established

In the documentationOfficial help still describes the independent Include environments setting.
On the screenThe official link led to “Legacy Codex Cloud.” Environment settings showed diff display and branch format options, but not the relevant switch.
Status unknownWe could not verify where the setting is or whether it is on or off for this account. Its absence does not establish that it is off or discontinued.

Having zero cloud environments does not prove that environment training is off. We do not recommend creating a new environment just to look for the setting.

Check conditions, routes tried, and what remains unknown

Official material uses “full environments”; another document says “additional context from your Codex environments.” This indicates context broader than conversation text alone, but it does not establish a complete inventory or scope.

On October 4, 2026, the account holder opened the screens in a Windows browser using a personal Pro account. We reviewed the screenshots they provided. The AI did not change any settings. Browser and app version numbers were not obtained.

  1. The Codex settings link in official help led to “Legacy Codex Cloud.”
  2. Environment settings offered diff display and branch format, but did not show Include environments.
  3. A data-settings URL mentioned in earlier user guidance redirected this account to the ChatGPT home screen.

The documented setting and the settings screen reachable by this account did not match. Official documentation describes the migration between legacy and new cloud environments, but that alone does not explain why the setting was missing. Nor can we conclude that it is missing for all users. Official guidance: cloud environments.

What to ask official support

If you need confirmation, ask official support for the current location of the setting, its state for your account, its default, and its scope across local, legacy cloud, and new cloud environments. You can describe the screen names and redirect destinations without sending task code or confidential conversations. Treat the state as unknown until you receive an answer.

4. How risky is it if training was enabled?

An enabled training setting does not tell us that every conversation has already been used for training or disclosed to a third party. Start by separating the ways information could be accessed or used.

Official policies allow human review

Access, as needed, is limited to authorized personnel and service providers under confidentiality obligations. OpenAI describes access controls and logging; it does not say that no human ever sees the content.

When you opt out of training

Model-improvement use is excluded

The usual opt-out stops use for improving models.

Purposes that remain

Safety, support, and legal matters

Necessary review, such as investigating abuse or security issues, does not disappear.

Official guidance: purposes and limits of human access.

Personal-information filtering exists, but is imperfect

The role of Privacy Filter

Detection and masking ≠ a guarantee that every secret is removed

What it detects Names, addresses, email addresses, API keys, and similar information
Remaining limitations Misses can depend on context and language. There is no guarantee that every unpublished design or business plan is removed.
How OpenAI describes Privacy Filter and its limitations

OpenAI says it uses an internal version of Privacy Filter to identify and mask personal information when processing conversations with training enabled. Targets include names, addresses, email addresses, and API keys, but misses and incorrect classifications can occur depending on language and context. This is not a guarantee that every unpublished design, algorithm, or business plan is recognized as confidential and removed. Official explanation: how ChatGPT protects privacy and Privacy Filter's scope and limitations.

Training-data extraction has been studied, but does not yield an individual leakage probability

What the 2023 study showed

Reproduction of text from training

Researchers compared outputs from ChatGPT at the time with public web text they had collected.

What the study does not establish

Evidence that your private chats were leaked

It also cannot quantify the probability of a particular conversation leaking from current models.

The original paper and method: what was compared?

A study published in 2023 demonstrated the extraction of some text and code believed to originate from training from ChatGPT as it existed then. This matters when considering whether a model can reproduce text it learned. Original paper: Scalable Extraction of Training Data from (Production) Language Models.

However, the matches in the study were checked against a large corpus of public web text collected by the researchers. Evidence that an output matched text on a public page is not evidence of extracting private user chats. Results for those models and methods also cannot tell you the probability that your conversation will leak from a current model. The researchers' explanation of their verification method.

Rather than assigning a percentage based only on an enabled setting, it is more practical to prioritize action by the impact if the information you entered became known to others. The following is a framework for deciding what to do, not an estimate of leakage probability.

5. What to do if you entered confidential information

  • Active keys, passwords, and private keysMay directly enable actions, spending, or access to data
    Check usage records and permissions yourself. Decide whether the credentials need to be revoked or replaced.
  • Customer data and contractually confidential informationImpact on people or organizations, and information-handling obligations
    Identify what you sent and follow the contract and your organization's reporting process.
  • Unpublished source code and plansImpact of exposing design or business information
    Check training settings and what you shared. Limit future development inputs to what is necessary.
  • Family names, addresses, health information, and schedulesIdentifiability, private life, and other people's privacy
    Check conversations, files, memory, and sharing destinations separately.
  • Published code and fictional samplesRelatively little additional information may be exposed
    Check whether real secrets or personal information have accidentally been included in the sample.

This list does not rank leakage probabilities. For example, the urgency differs between an already expired key and an active key with broad permissions. Even a short fragment can identify a person through a combination of name, workplace, and schedule.

Turning training off does not resecure exposed credentials

If you entered a key, do not paste it into the AI again. Check its permissions, usage records, and expiry with the service yourself. OpenAI advises replacing potentially leaked API keys and checking usage. Official guidance: API key safety.

For routine rotation, the following order can reduce disruption:

  1. Create a new key Give it the necessary permissions and expiry.
  2. Update its consumers Change the key used by apps and services.
  3. Verify operation Check that the new key works.
  4. Revoke the old key Stop use of the previous key.

If misuse is ongoing, containment—such as revoking the key or disabling permissions—may need to come first. This is general secrets-management guidance, not a blanket instruction to rotate credentials for everyone who had training enabled. OWASP: revoking and rotating secrets.

Separate what you submitted from signs of actual harm

  • Submission scope What you sent, to which service and account, and roughly when
  • Setting record When you checked and what was on, off, or unknown
  • Signs of harm Suspicious actions, usage, or charges

You do not need to duplicate the secret itself in a new request for advice or a public comment. Even without signs of disclosure, record the possibility of training use and the scope of your submissions separately.

When contacting support or the Privacy Portal, ask what the procedure covers and what remedies are possible. We cannot promise that a deletion request completely removes information from models already trained on it. Published policies alone also cannot establish whether a particular conversation was selected or has already been used in training. Official policy: privacy and request channels.

6. The limits of opting out, deletion, and Temporary Chat

There is an exception for 👍 and 👎 feedback

Even with training off, the entire conversation associated with feedback may be used for training. For conversations containing confidential information, distinguish the usual opt-out from feedback you actively submit.

Do not rely on the off setting alone when submitting feedback on a confidential conversation. Official guidance: feedback after opting out.

Deleting conversations, files, and memory are separate actions

Conversations

Deletion ≠ archiving

Usually deleted from systems within 30 days after deletion. Exceptions include safety and legal reasons.

Files

Check where they are stored

Library files are managed separately from conversations. Deleting a chat does not necessarily delete its files.

Memory

May remain after a chat is deleted

Saved memories are used for personalization. Check their management settings separately.

Retention exceptions, file locations, and memory within the same account

When you delete a saved ChatGPT conversation, it is immediately removed from your account and is usually deleted from systems within 30 days. Exceptions include data already de-identified and disassociated from your account, or retained for safety or legal reasons. Archiving is not deletion.

Files saved to Library are managed separately from conversations. Deleting a conversation does not necessarily delete those files at the same time. Files in projects and custom GPTs are also handled according to where they are stored. Official guidance: ChatGPT chat and file retention.

Memory personalizes responses and is separate from the training setting. Deleting a conversation does not automatically remove saved memories created from it, so check saved-memory management separately. If several people use the same account and one person's schedule appears in an answer to another, that alone does not establish disclosure to a third party through model training. First distinguish history and memory references within the same account from training of the model as a whole. Official guidance: memory management and its distinction from training.

Saving a Temporary Chat changes how it is handled

While it remains temporary Not used for training or added to ordinary history or new memories. May be retained for safety for up to 30 days.
Saved as a regular conversation After the switch, the account's settings apply.

Current official guidance says a Temporary Chat may still use existing memories and similar context if you choose personalization. Do not treat Temporary Chat as a mode that sends nothing, or assume it is available for every Codex task. Official guidance: Temporary Chat handling.

7. Sharing less confidential information during development

Your computer

Commands and file operations

Some operations run locally.

The cloud model

Sending necessary code and context

Model requests are a separate communication. Local execution does not establish that nothing leaves your device.

Official security guidance also distinguishes network controls for commands from the client's model and authentication requests. Official guidance: approvals, security, and communication boundaries and ways to use Codex.

An example of reducing input before asking

Production data → reproduce with two fictional records

A storage bug Replace real user records with fictional inputs.
An API integration bug Hide the key value and describe the error type, permissions, and setting names.

For design advice, replacing customer names, internal URLs, and unpublished figures may still leave enough information to make a useful assessment.

  • What goes into the conversation: code needed to reproduce the issue, fictional inputs, and expected results. Exclude real names and active secrets.
  • What belongs in the development environment: do not expose production credentials or private documents beyond what the work requires.
  • What goes elsewhere: check public repositories, shared links, plugins, and destinations for submitted logs separately.
  • What contracts determine: follow organizational policies and customer agreements. Turning training off does not authorize otherwise prohibited external disclosure.

These practices reduce what you submit; they do not replace training settings or access management. Sharing only necessary information is especially useful when some settings cannot be verified. See precautions when entering information into AI for examples, our Claude Code and Codex comparison for tool differences, and how to opt out of Claude Code training for Claude's settings.

FAQ

Does Pro prevent conversations and code from being used for training?

No. Personal Pro has data sharing enabled by default. Distinguish it from Business, Enterprise, Edu, and the API, where data is not used for training by default.

Does turning training off in ChatGPT turn everything off in Codex?

For the same account on a personal plan, it applies as an opt-out for new Codex conversations and tasks. However, Include environments is a separate setting and is unchanged. There is also an exception for feedback you submit.

If Include environments is missing, can I assume it is off?

No. We could not verify its location or state in this check. Public material and the supplied screenshots do not establish why it is missing or what its default is.

If I discover training was on, should I delete every chat?

First assess the content and its impact. Blanket deletion can remove records you need. Decide separately about future training settings, credentials, and the relevant conversations, files, and memories. Deletion is not guaranteed to undo past training.