Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This document sets out how OpenAI handles the data you send through its API and products. By default, OpenAI does not use your business data to train its AI models — training only happens if you explicitly opt in. Your API data is kept for up to 30 days and then deleted, and only a narrow set of people can access your conversations for specific, limited reasons.
This document establishes OpenAI's data handling obligations and rights for its API and related products. By default, OpenAI does not use business data to train its models; model training on user data requires explicit opt-in. API inputs and outputs may be retained for up to 30 days for service provision and abuse identification, after which they are removed from OpenAI's systems unless a legal obligation requires retention. Employee access to conversation data is strictly limited to three enumerated purposes, and specialized third-party contractors may access data solely for abuse and misuse review under confidentiality and security obligations. Users retain all rights to their inputs and own outputs they rightfully receive to the extent permitted by law, and fine-tuned models are reserved exclusively for the customer's use and are never shared with or used to train models for other customers.
As an individual using OpenAI's API or related products, your inputs and outputs are held for up to 30 days and then removed, unless a legal obligation applies. OpenAI does not use your data to train its models unless you have explicitly opted in. Employees can access your conversations only to resolve incidents, to recover your conversations with your explicit permission, or as required by law. If you have a qualifying use-case, you can request zero data retention on eligible endpoints. Under ChatGPT Enterprise, ChatGPT for Healthcare, and ChatGPT Edu, you control how long your data is retained. You keep all rights to your inputs and own the outputs you rightfully receive, to the extent permitted by law.
Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.
7 important changes detected
8 versions captured · Last updated: July 2026
OpenAI removed the phrase 'Enterprise privacy at OpenAI' from the opening header of their privacy policy on June 28, 2026. The document previously opened with this title above the 'Updated: …
View change record →OpenAI updated its API Data Usage Policies on May 29, 2026 by modifying three hyperlinked references within the document. The changes involved adjusting whitespace and link formatting around the Data …
View change record →OpenAI updated its API Data Usage Policies on May 28, 2026 to clarify workspace admin authority and data retention rules. Previously, the terms stated that end users controlled whether their …
View change record →OpenAI made minor formatting adjustments to three hyperlinks in their API Data Usage Policies on May 24, 2026. The changes affected the Data Processing Agreement link, the Student Data Privacy …
View change record →OpenAI modified a single hyperlink in its API Data Usage Policies on May 19, 2026. The phrase 'Learn more about ChatGPT Business' previously linked directly to that resource; the updated …
View change record →OpenAI has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.
OpenAI expanded its data sharing terms to include third-party marketing partners. The updated policy authorizes the use of personal data fo…
872 provisions across 8 AI platforms. The terms your AI provider sets become the terms your product operates under.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
The bill does not regulate most AI startups directly. But it changes the companies they depend on. Here is what the first federal AI law wo…
H.R. 8094 would make the FTC the referee for AI model disclosure. It also names system cards as a way to comply, which turns a voluntary in…
Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.