Fact-checked

What does ChatGPT do with my data?

In short

It depends which version you use. With ChatGPT for individuals (Free and Plus), conversations feed into the training of future models by default, unless you opt out. With the API, Team, Business, Enterprise and Edu, OpenAI states that it does not — there, training is an opt-in decision. Either way, what you type is processed by a US provider.

Three versions, three answers

“Do you use ChatGPT?” is not a question that can be answered with yes or no — the product comes in versions that work very differently in data protection terms. Discussions inside a company often talk past each other, because one side is thinking of the personal account and the other of the corporate subscription.

The decisive line runs between the consumer product and the business tiers:

VersionTrains on what you typeWhat that means in practice
ChatGPT Free / PlusYes, unless you opt outThe opt-out has to be set actively — per account, by the individual person.
APINo (opt-in possible)Training only if you explicitly agree to it in the dashboard.
Team / Business / Enterprise / EduNoNo training on input or output, not even by default.

Why “no training” is not the same as “stays with you”

The common worry runs: “Our data ends up in the model and resurfaces for someone else.” For the business tiers that is not the case, according to OpenAI. But that does not answer the real question — it only moves it.

Because even without training, one thing still holds: what you type leaves your building. It is processed by a US provider subject to the CLOUD Act — under certain conditions, US authorities can reach data even when it is stored outside the United States. For professionals bound by confidentiality under section 203 of the German Criminal Code, passing data to a third party is already the critical step, regardless of what that third party then does with it.

And “no training” is a promise, not a structural property. It sits in terms a provider can change. Anyone whose decision has to hold for years should know the difference between “does not do it” and “cannot do it”.

How the legal assessment works out in detail is on our page ChatGPT, Claude & Co. with customer data.

The real risk sits with the personal account

In practice, the carefully chosen corporate subscription is rarely the problem. What happens alongside it is: staff who want to get something done quickly reach for their personal ChatGPT account — with a letter to a customer, a draft contract, an error message including the log.

That is exactly where the default applies under which conversations feed into training. And that is exactly where the organisation has no visibility at all: no record, no way to delete, no data processing agreement.

This shadow use cannot be solved by a ban — it arises from a genuine need. What helps is a tool that is just as quickly to hand internally. More on that under Can I use ChatGPT at work?.

How KOSMO solves it differently

KOSMO runs on-premise or in our German data centre. The question “does the data leave the building?” therefore never arises — it does not.

No model is trained on your content. It serves to answer your question, nothing more. What KOSMO gets better at through use is which sources it draws on inside your own instance — not a model into which knowledge migrates and from which it could no longer be removed.

The practical difference shows when you delete something: remove a document and it takes effect on future answers straight away. With a trained model it would not.

Last checked: 13 August 2026. The statements about OpenAI come from the provider's public policies and were checked on this date. Provider terms change — check where things stand before basing a decision on them. This page is not legal advice.

Sources:OpenAI – How your data is used to improve model performance · OpenAI – Business data privacy, security, and compliance · OpenAI – Enterprise privacy ·

FAQ

Frequently asked questions

Does ChatGPT train on what I type?

With ChatGPT Free and Plus, conversations feed into training by default unless you opt out. With the API, Team, Business, Enterprise and Edu, OpenAI states that it does not — there, training is an explicit opt-in decision.

How do I opt out of training?

In a personal account this can be set in the data controls, or through OpenAI's privacy portal. Important for companies: each person sets this for their own account — the organisation can neither set it nor check it.

Is an Enterprise account enough?

It settles the training question, not the location question. What you type is still processed by a US provider subject to the CLOUD Act. For professionals bound by confidentiality, passing data to a third party is already the critical step.

What about Claude, Gemini or Copilot?

The providers differ in the details, but the basic pattern is the same: business tiers rule out training, while processing still takes place at a US corporation. Our provider comparison gives an overview.

Does KOSMO use our data for training?

No. Your content serves solely to answer your question. No model is trained on it, and none of it has any effect on other customers.

Can I remove data from KOSMO again?

Yes. Remove a document and it takes effect on future answers straight away — because this is about which sources are drawn on, not about a trained model.

The alternative

An assistant that gives nothing away

KOSMO runs on-premise or in our German data centre. Your content is used to answer your question — and never to train a model.

How KOSMO works Request a demo

Partners & supporters