Conversations and code you enter into ChatGPT or Codex may be used to train models on personal plans, depending on your settings. A Pro subscription does not automatically exclude your data from training. However, discovering that training was enabled does not, by itself, establish that confidential information was disclosed to someone else.
Conversations and tasks
Check the setting for the same account
ChatGPT's “Improve the model for everyone” setting also applies to Codex on personal plans. Opting out covers new conversations and tasks started afterward.
Codex environments
Check a separate setting
Official documentation describes Include environments. Turning off training for conversations and tasks does not change this setting.
Retention and human access
Training off ≠ all data deleted
Retention and access for purposes such as safety and support are separate. Stopping training use and deleting stored data are different actions.
Sources: OpenAI's Data Controls and data handling in consumer services. Checked October 4, 2026.
Jump to a section (contents)
Contents
- 1. Default settings and differences between plans
- 2. Checking settings for ChatGPT and Codex
- 3. When you cannot find Include environments
- 4. How risky is it if training was enabled?
- 5. What to do if you entered confidential information
- 6. The limits of opting out, deletion, and Temporary Chat
- 7. Sharing less confidential information during development
- FAQ
1. Default settings and differences between plans
Personal plans and business offerings have different training defaults. This does not mean that an account you previously opted out is currently opted in. Official guidance: keeping history while disabling training.
Personal Free, Plus, and Pro
Data sharing is on by default
You can opt out through ChatGPT's Data Controls. Paid Pro accounts follow the same rule.
For Codex on personal plans, conversations and tasks follow the same setting as ChatGPT. Check environment training separately.
Business, Enterprise, Edu, and the API
Not used for training by default
Check your workspace and your organization's retention and access policies. For the API, also check whether your organization has enabled data sharing.
No training does not mean no processing or storage.
For the API, organization owners can enable data sharing. Official guidance: training use across services.
2. Checking settings for ChatGPT and Codex
For Codex on a personal plan, start with the same OpenAI account you use to sign in to Codex. If ChatGPT in your browser and the Codex app use different accounts, checking just one is not enough.
- Match the accounts Check the signed-in account and workspace in ChatGPT and Codex.
- Open settings In ChatGPT, go to Settings → Data Controls.
- Check the switch Look at the state of “Improve the model for everyone.”
- Decide for yourself To stop training use, turn it off and save. If it is already off, no change is needed.
Where this setting applies
The same account → across devices
Other accounts are unchanged. Check Include environments and the exception for feedback you submit separately.
Official guidance says this choice is tied to your signed-in account and applies across devices. You can also opt out of training on conversations and Codex tasks through “Do not train on my content” in the Privacy Portal. You do not need to use both methods. The opt-out covers new conversations and tasks after you opt out. Official guidance: the steps and their application to Codex.
This action does not change Include environments, discussed below. Record the results separately—for example, “Account A: conversation and task training off” and “Environment setting: could not verify”—so that unknowns remain visible. If you have multiple accounts, check each one yourself.
3. When you cannot find Include environments
Include environments is an independent setting that controls whether Codex environments may be used for training. The material checked for this article does not publish a complete list of files covered, the detailed local and cloud scope, or the current default. Official guidance: Codex's independent setting.
What our screen check established
Having zero cloud environments does not prove that environment training is off. We do not recommend creating a new environment just to look for the setting.
Check conditions, routes tried, and what remains unknown
Official material uses “full environments”; another document says “additional context from your Codex environments.” This indicates context broader than conversation text alone, but it does not establish a complete inventory or scope.
On October 4, 2026, the account holder opened the screens in a Windows browser using a personal Pro account. We reviewed the screenshots they provided. The AI did not change any settings. Browser and app version numbers were not obtained.
- The Codex settings link in official help led to “Legacy Codex Cloud.”
- Environment settings offered diff display and branch format, but did not show Include environments.
- A data-settings URL mentioned in earlier user guidance redirected this account to the ChatGPT home screen.
The documented setting and the settings screen reachable by this account did not match. Official documentation describes the migration between legacy and new cloud environments, but that alone does not explain why the setting was missing. Nor can we conclude that it is missing for all users. Official guidance: cloud environments.
What to ask official support
If you need confirmation, ask official support for the current location of the setting, its state for your account, its default, and its scope across local, legacy cloud, and new cloud environments. You can describe the screen names and redirect destinations without sending task code or confidential conversations. Treat the state as unknown until you receive an answer.
4. How risky is it if training was enabled?
An enabled training setting does not tell us that every conversation has already been used for training or disclosed to a third party. Start by separating the ways information could be accessed or used.
Official policies allow human review
Access, as needed, is limited to authorized personnel and service providers under confidentiality obligations. OpenAI describes access controls and logging; it does not say that no human ever sees the content.
When you opt out of training
Model-improvement use is excluded
The usual opt-out stops use for improving models.
Purposes that remain
Safety, support, and legal matters
Necessary review, such as investigating abuse or security issues, does not disappear.
Official guidance: purposes and limits of human access.
Personal-information filtering exists, but is imperfect
The role of Privacy Filter
Detection and masking ≠ a guarantee that every secret is removed
How OpenAI describes Privacy Filter and its limitations
OpenAI says it uses an internal version of Privacy Filter to identify and mask personal information when processing conversations with training enabled. Targets include names, addresses, email addresses, and API keys, but misses and incorrect classifications can occur depending on language and context. This is not a guarantee that every unpublished design, algorithm, or business plan is recognized as confidential and removed. Official explanation: how ChatGPT protects privacy and Privacy Filter's scope and limitations.
Training-data extraction has been studied, but does not yield an individual leakage probability
What the 2023 study showed
Reproduction of text from training
Researchers compared outputs from ChatGPT at the time with public web text they had collected.
What the study does not establish
Evidence that your private chats were leaked
It also cannot quantify the probability of a particular conversation leaking from current models.
The original paper and method: what was compared?
A study published in 2023 demonstrated the extraction of some text and code believed to originate from training from ChatGPT as it existed then. This matters when considering whether a model can reproduce text it learned. Original paper: Scalable Extraction of Training Data from (Production) Language Models.
However, the matches in the study were checked against a large corpus of public web text collected by the researchers. Evidence that an output matched text on a public page is not evidence of extracting private user chats. Results for those models and methods also cannot tell you the probability that your conversation will leak from a current model. The researchers' explanation of their verification method.
Rather than assigning a percentage based only on an enabled setting, it is more practical to prioritize action by the impact if the information you entered became known to others. The following is a framework for deciding what to do, not an estimate of leakage probability.
5. What to do if you entered confidential information
- Active keys, passwords, and private keysMay directly enable actions, spending, or access to dataCheck usage records and permissions yourself. Decide whether the credentials need to be revoked or replaced.
- Customer data and contractually confidential informationImpact on people or organizations, and information-handling obligationsIdentify what you sent and follow the contract and your organization's reporting process.
- Unpublished source code and plansImpact of exposing design or business informationCheck training settings and what you shared. Limit future development inputs to what is necessary.
- Family names, addresses, health information, and schedulesIdentifiability, private life, and other people's privacyCheck conversations, files, memory, and sharing destinations separately.
- Published code and fictional samplesRelatively little additional information may be exposedCheck whether real secrets or personal information have accidentally been included in the sample.
This list does not rank leakage probabilities. For example, the urgency differs between an already expired key and an active key with broad permissions. Even a short fragment can identify a person through a combination of name, workplace, and schedule.
Turning training off does not resecure exposed credentials
If you entered a key, do not paste it into the AI again. Check its permissions, usage records, and expiry with the service yourself. OpenAI advises replacing potentially leaked API keys and checking usage. Official guidance: API key safety.
For routine rotation, the following order can reduce disruption:
- Create a new key Give it the necessary permissions and expiry.
- Update its consumers Change the key used by apps and services.
- Verify operation Check that the new key works.
- Revoke the old key Stop use of the previous key.
If misuse is ongoing, containment—such as revoking the key or disabling permissions—may need to come first. This is general secrets-management guidance, not a blanket instruction to rotate credentials for everyone who had training enabled. OWASP: revoking and rotating secrets.
Separate what you submitted from signs of actual harm
- Submission scope What you sent, to which service and account, and roughly when
- Setting record When you checked and what was on, off, or unknown
- Signs of harm Suspicious actions, usage, or charges
You do not need to duplicate the secret itself in a new request for advice or a public comment. Even without signs of disclosure, record the possibility of training use and the scope of your submissions separately.
When contacting support or the Privacy Portal, ask what the procedure covers and what remedies are possible. We cannot promise that a deletion request completely removes information from models already trained on it. Published policies alone also cannot establish whether a particular conversation was selected or has already been used in training. Official policy: privacy and request channels.
6. The limits of opting out, deletion, and Temporary Chat
There is an exception for 👍 and 👎 feedback
Even with training off, the entire conversation associated with feedback may be used for training. For conversations containing confidential information, distinguish the usual opt-out from feedback you actively submit.
Do not rely on the off setting alone when submitting feedback on a confidential conversation. Official guidance: feedback after opting out.
Deleting conversations, files, and memory are separate actions
Conversations
Deletion ≠ archiving
Usually deleted from systems within 30 days after deletion. Exceptions include safety and legal reasons.
Files
Check where they are stored
Library files are managed separately from conversations. Deleting a chat does not necessarily delete its files.
Memory
May remain after a chat is deleted
Saved memories are used for personalization. Check their management settings separately.
Retention exceptions, file locations, and memory within the same account
When you delete a saved ChatGPT conversation, it is immediately removed from your account and is usually deleted from systems within 30 days. Exceptions include data already de-identified and disassociated from your account, or retained for safety or legal reasons. Archiving is not deletion.
Files saved to Library are managed separately from conversations. Deleting a conversation does not necessarily delete those files at the same time. Files in projects and custom GPTs are also handled according to where they are stored. Official guidance: ChatGPT chat and file retention.
Memory personalizes responses and is separate from the training setting. Deleting a conversation does not automatically remove saved memories created from it, so check saved-memory management separately. If several people use the same account and one person's schedule appears in an answer to another, that alone does not establish disclosure to a third party through model training. First distinguish history and memory references within the same account from training of the model as a whole. Official guidance: memory management and its distinction from training.
Saving a Temporary Chat changes how it is handled
Current official guidance says a Temporary Chat may still use existing memories and similar context if you choose personalization. Do not treat Temporary Chat as a mode that sends nothing, or assume it is available for every Codex task. Official guidance: Temporary Chat handling.
7. Sharing less confidential information during development
Your computer
Commands and file operations
Some operations run locally.
The cloud model
Sending necessary code and context
Model requests are a separate communication. Local execution does not establish that nothing leaves your device.
Official security guidance also distinguishes network controls for commands from the client's model and authentication requests. Official guidance: approvals, security, and communication boundaries and ways to use Codex.
An example of reducing input before asking
Production data → reproduce with two fictional records
For design advice, replacing customer names, internal URLs, and unpublished figures may still leave enough information to make a useful assessment.
- What goes into the conversation: code needed to reproduce the issue, fictional inputs, and expected results. Exclude real names and active secrets.
- What belongs in the development environment: do not expose production credentials or private documents beyond what the work requires.
- What goes elsewhere: check public repositories, shared links, plugins, and destinations for submitted logs separately.
- What contracts determine: follow organizational policies and customer agreements. Turning training off does not authorize otherwise prohibited external disclosure.
These practices reduce what you submit; they do not replace training settings or access management. Sharing only necessary information is especially useful when some settings cannot be verified. See precautions when entering information into AI for examples, our Claude Code and Codex comparison for tool differences, and how to opt out of Claude Code training for Claude's settings.
FAQ
Does Pro prevent conversations and code from being used for training?
No. Personal Pro has data sharing enabled by default. Distinguish it from Business, Enterprise, Edu, and the API, where data is not used for training by default.
Does turning training off in ChatGPT turn everything off in Codex?
For the same account on a personal plan, it applies as an opt-out for new Codex conversations and tasks. However, Include environments is a separate setting and is unchanged. There is also an exception for feedback you submit.
If Include environments is missing, can I assume it is off?
No. We could not verify its location or state in this check. Public material and the supplied screenshots do not establish why it is missing or what its default is.
If I discover training was on, should I delete every chat?
First assess the content and its impact. Blanket deletion can remove records you need. Decide separately about future training settings, credentials, and the relevant conversations, files, and memories. Deletion is not guaranteed to undo past training.