Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This document governs how OpenAI handles your business data when you use its enterprise products or API. By default, OpenAI does not use your data to train its models, and it deletes your API inputs and outputs after 30 days. Only a narrow set of authorized OpenAI employees can access your conversations, and only for specific permitted reasons.
This document establishes OpenAI's data handling obligations and customer rights for enterprise and API use of its services. It sets a default of no model training from business data, with training permitted only upon explicit customer opt-in, and imposes a 30-day retention ceiling on API inputs and outputs followed by deletion unless law or harm-protection purposes require longer retention. Access to customer conversations and API business data is restricted to authorized personnel for an exhaustive set of enumerated purposes. Customers retain intellectual property rights over their inputs and outputs to the extent permitted by law, and fine-tuned models are exclusively reserved for the creating customer with no sharing or cross-training permitted.
As a business customer, your data is not used for model training unless you explicitly opt in, and your API inputs and outputs are deleted after 30 days by default. Your fine-tuned models are kept exclusively for your use and never shared with other customers or used to train other models. You own the rights to your inputs and the outputs you receive, to the extent permitted by law. If you have a qualifying use case, you can request zero data retention for eligible API endpoints.
Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.
7 important changes detected
8 versions captured · Last updated: July 2026
OpenAI updated its Enterprise Privacy policy on July 1, 2026 with four minor formatting adjustments to hyperlink syntax and spacing in the document. These changes affect how hyperlinks to the …
View change record →OpenAI updated three sentences in their Enterprise Privacy policy on June 1, 2026, removing spacing characters around hyperlinks in language describing Data Processing Agreements, Student Data Privacy Agreements for ChatGPT …
View change record →OpenAI updated its Enterprise Privacy terms on May 28, 2026 to expand workspace admin authority over end user conversations. Previously, only end users could view their own conversations, and end …
View change record →OpenAI updated formatting in its Enterprise Privacy document on May 22, 2026 by modifying spacing around hyperlinks in three sentences. The changes involve adjusting whitespace before the opening parentheses in …
View change record →OpenAI updated a hyperlink in its Enterprise Privacy document on May 19, 2026. The previous link text 'Learn more about ChatGPT Business' was modified to 'Learn more about ChatGPT Business …
View change record →Every distinct legal provision identified in this document. Featured provisions appear above with analysis.
OpenAI has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.
Cross-platform context
See how other platforms handle API access limited to authorized employees and contractors and similar clauses.
Compare across platforms →OpenAI expanded its data sharing terms to include third-party marketing partners. The updated policy authorizes the use of personal data fo…
872 provisions across 8 AI platforms. The terms your AI provider sets become the terms your product operates under.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
The bill does not regulate most AI startups directly. But it changes the companies they depend on. Here is what the first federal AI law wo…
H.R. 8094 would make the FTC the referee for AI model disclosure. It also names system cards as a way to comply, which turns a voluntary in…
Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.