10 Total
0 High severity
10 Medium severity
0 Low severity
Get alerted the next time OpenAI changes these terms. Follow OpenAI →
Summary

This document sets out how OpenAI handles the data you send through its API and products. By default, OpenAI does not use your business data to train its AI models — training only happens if you explicitly opt in. Your API data is kept for up to 30 days and then deleted, and only a narrow set of people can access your conversations for specific, limited reasons.

Analysis

This document establishes OpenAI's data handling obligations and rights for its API and related products. By default, OpenAI does not use business data to train its models; model training on user data requires explicit opt-in. API inputs and outputs may be retained for up to 30 days for service provision and abuse identification, after which they are removed from OpenAI's systems unless a legal obligation requires retention. Employee access to conversation data is strictly limited to three enumerated purposes, and specialized third-party contractors may access data solely for abuse and misuse review under confidentiality and security obligations. Users retain all rights to their inputs and own outputs they rightfully receive to the extent permitted by law, and fine-tuned models are reserved exclusively for the customer's use and are never shared with or used to train models for other customers.

What this means for you

As an individual using OpenAI's API or related products, your inputs and outputs are held for up to 30 days and then removed, unless a legal obligation applies. OpenAI does not use your data to train its models unless you have explicitly opted in. Employees can access your conversations only to resolve incidents, to recover your conversations with your explicit permission, or as required by law. If you have a qualifying use-case, you can request zero data retention on eligible endpoints. Under ChatGPT Enterprise, ChatGPT for Healthcare, and ChatGPT Edu, you control how long your data is retained. You keep all rights to your inputs and own the outputs you rightfully receive, to the extent permitted by law.

Institutional Analysis
Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

7 important changes detected

8 versions captured · Last updated: July 2026

What changed In an update detected on July 26, 2026, OpenAI's API Data Usage Policy retained its existing language stating that data from ChatGPT Business, ChatGPT Enterprise, ChatGPT for Healthcare, ChatGPT Edu, ChatGPT for Teachers, and the API Platform (after March 1, 2023) is not used for model training by default, unless users explicitly opt in to share data to improve services. The BEFORE and AFTER text are identical, indicating no operational change to the default data usage policy.
Why this matters The updated terms do not alter the existing data usage policy. Data from ChatGPT Business, ChatGPT Enterprise, ChatGPT for Healthcare, ChatGPT Edu, ChatGPT for Teachers, and the API Platform (after March 1, 2023) continues to be excluded from model training by default unless users explicitly opt in to share data to improve services. No change to consumer rights or data handling practices is reflected in this update.
View full change record →

July 16, 2026

medium
What changed OpenAI modified two sentences in its Enterprise Privacy Policy, detected on July 16, 2026. The opening section now includes a formatting change (addition of 'Enterprise privacy at OpenAI' as a header). More substantively, the language describing workspace admin control over data retention was changed from 'Your workspace admins control how long your workspace data is retained' to 'Your workspace admins can control how long your data is retained.' This shifts the framing from an affirmative control right to a permissive capability, and removes the word 'workspace' before 'data,' potentially broadening the scope of data subject to admin control beyond workspace-specific data.
Why this matters The updated policy now states that workspace admins 'can control' data retention rather than 'control' it, introducing subtle ambiguity about whether retention control is a guaranteed right or a permitted option. Additionally, the removal of the word 'workspace' before 'data' broadens the scope of data potentially subject to admin control beyond workspace-specific information. These changes could affect how enterprise customers understand the extent of their administrative authority over data retention practices.
View full change record →

June 28, 2026 low

OpenAI removed the phrase 'Enterprise privacy at OpenAI' from the opening header of their privacy policy on June 28, 2026. The document previously opened with this title above the 'Updated: …

View change record →
May 29, 2026 low

OpenAI updated its API Data Usage Policies on May 29, 2026 by modifying three hyperlinked references within the document. The changes involved adjusting whitespace and link formatting around the Data …

View change record →
May 28, 2026 medium

OpenAI updated its API Data Usage Policies on May 28, 2026 to clarify workspace admin authority and data retention rules. Previously, the terms stated that end users controlled whether their …

View change record →
May 24, 2026 low

OpenAI made minor formatting adjustments to three hyperlinks in their API Data Usage Policies on May 24, 2026. The changes affected the Data Processing Agreement link, the Student Data Privacy …

View change record →
May 19, 2026 low

OpenAI modified a single hyperlink in its API Data Usage Policies on May 19, 2026. The phrase 'Learn more about ChatGPT Business' previously linked directly to that resource; the updated …

View change record →
Featured, Medium severity
Monitoring

OpenAI has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Mapped Governance Frameworks

DMCA
United States Federal
View official text ↗

Related Analysis

Privacy · May 3, 2026
OpenAI Privacy Policy Update May 2026: New Terms Authorize Advertiser Data Sharing

OpenAI expanded its data sharing terms to include third-party marketing partners. The updated policy authorizes the use of personal data fo…

Dependency Governance · June 11, 2026
AI Dependency Governance: How API Terms Govern Every App Built on OpenAI, Anthropic, and Google

872 provisions across 8 AI platforms. The terms your AI provider sets become the terms your product operates under.

Platform Analysis · June 12, 2026
OpenAI Changed Its Privacy Policy 4 Times in One Week. Here Is What Actually Changed.

Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.

Regulatory Analysis · June 28, 2026
The Great American AI Act, Explained: What the First Federal AI Law Would Require

The bill does not regulate most AI startups directly. But it changes the companies they depend on. Here is what the first federal AI law wo…

Regulatory Analysis · July 8, 2026
The AI Foundation Model Transparency Act, Explained

H.R. 8094 would make the FTC the referee for AI model disclosure. It also names system cards as a way to comply, which turns a voluntary in…

Archival ProvenanceSource & Archival Record
Last Captured July 26, 2026 00:05 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000789
Version ID CA-V-005280
SHA-256 29a1341f788b9e0b01a2a871cd81c35ddbcbf7f446481bbe51d0e7ac8117f13d
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Create free account Compare plans