38 Total
17 High severity
19 Medium severity
2 Low severity

Key Facts

Who has access to API business data stored on OpenAI's systems?
OpenAI limits access to API business data stored on its systems to authorized employees with specific need-based roles and specialized third-party contractors.
What does OpenAI do with API inputs and outputs to provide the services and to identify abuse?
OpenAI may securely retain API inputs and outputs for up to 30 days to provide the services and to identify abuse.
Who does OpenAI reserve fine-tuned models exclusively for?
OpenAI reserves fine-tuned models exclusively for the customer who created them and does not serve, share, or use them to train other models.
Does OpenAI serve, share, or use fine-tuned models to train other models?
OpenAI reserves fine-tuned models exclusively for the customer who created them and does not serve, share, or use them to train other models.
When does OpenAI remove API inputs and outputs from its systems?
OpenAI removes API inputs and outputs from its systems after 30 days unless legally required to retain them.
Does OpenAI remove API inputs and outputs from its systems after 30 days unless legally required to retain them?
OpenAI removes API inputs and outputs from its systems after 30 days unless legally required to retain them.
What may OpenAI run through automated content classifiers and safety tools?
OpenAI may run business data submitted to its services through automated content classifiers and safety tools, including to better understand how its services are used.
Can OpenAI run business data submitted to its services through automated content classifiers and safety tools?
OpenAI may run business data submitted to its services through automated content classifiers and safety tools, including to better understand how its services are used.
Can OpenAI sign Business Associate Agreements?
OpenAI is able to sign Business Associate Agreements in support of customers' compliance with HIPAA.
What does OpenAI do in support of customers' compliance with HIPAA?
OpenAI is able to sign Business Associate Agreements in support of customers' compliance with HIPAA.
Stay ahead of the changes
Track OpenAI and get the diff the day its terms change.
Summary

This document governs how OpenAI handles your business data when you use its enterprise products or API. By default, OpenAI does not use your data to train its models, and it deletes your API inputs and outputs after 30 days. Only a narrow set of authorized OpenAI employees can access your conversations, and only for specific permitted reasons.

Analysis

This document establishes OpenAI's data handling obligations and customer rights for enterprise and API use of its services. It sets a default of no model training from business data, with training permitted only upon explicit customer opt-in, and imposes a 30-day retention ceiling on API inputs and outputs followed by deletion unless law or harm-protection purposes require longer retention. Access to customer conversations and API business data is restricted to authorized personnel for an exhaustive set of enumerated purposes. Customers retain intellectual property rights over their inputs and outputs to the extent permitted by law, and fine-tuned models are exclusively reserved for the creating customer with no sharing or cross-training permitted.

What this means for you

As a business customer, your data is not used for model training unless you explicitly opt in, and your API inputs and outputs are deleted after 30 days by default. Your fine-tuned models are kept exclusively for your use and never shared with other customers or used to train other models. You own the rights to your inputs and the outputs you receive, to the extent permitted by law. If you have a qualifying use case, you can request zero data retention for eligible API endpoints.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

7 important changes detected

8 versions captured · Last updated: July 2026

What changed No material change detected. The sentence describing data usage for model training remains identical in both versions. The policy continues to state that data from ChatGPT Business, ChatGPT Enterprise, ChatGPT for Healthcare, ChatGPT Edu, ChatGPT for Teachers, and the API Platform (after March 1, 2023) is not used for training unless users have explicitly opted in to share their data.
Why this matters The policy language regarding data use for model training has not changed. By default, data from ChatGPT Business, ChatGPT Enterprise, and related products is not used for training models unless users have explicitly opted in to share their data with OpenAI.
View full change record →

July 18, 2026

medium
What changed OpenAI modified two sentences in its Enterprise Privacy policy as detected on July 18, 2026. The first change was purely formatting, moving the title 'Enterprise privacy at OpenAI' to appear before the 'Updated' date. The second change altered the language describing workspace admin control over data retention, replacing 'Your workspace admins control how long your workspace data is retained' with 'Your workspace admins can control how long your data is retained.' The shift from 'control' to 'can control' introduces conditional language that may permit admins to retain data without explicit time limits, whereas the previous phrasing stated admins directly exercise retention control.
Why this matters The updated terms state that workspace admins 'can control' data retention rather than directly controlling it. This conditional phrasing may suggest that retention control is optional or contingent rather than a guaranteed capability. Enterprise customers relying on admin-driven data retention policies should clarify with OpenAI whether this change affects their ability to set specific retention timelines for workspace data.
View full change record →

July 1, 2026 low

OpenAI updated its Enterprise Privacy policy on July 1, 2026 with four minor formatting adjustments to hyperlink syntax and spacing in the document. These changes affect how hyperlinks to the …

View change record →
June 1, 2026 low

OpenAI updated three sentences in their Enterprise Privacy policy on June 1, 2026, removing spacing characters around hyperlinks in language describing Data Processing Agreements, Student Data Privacy Agreements for ChatGPT …

View change record →
May 28, 2026 high

OpenAI updated its Enterprise Privacy terms on May 28, 2026 to expand workspace admin authority over end user conversations. Previously, only end users could view their own conversations, and end …

View change record →
May 22, 2026 low

OpenAI updated formatting in its Enterprise Privacy document on May 22, 2026 by modifying spacing around hyperlinks in three sentences. The changes involve adjusting whitespace before the opening parentheses in …

View change record →
May 19, 2026 low

OpenAI updated a hyperlink in its Enterprise Privacy document on May 19, 2026. The previous link text 'Learn more about ChatGPT Business' was modified to 'Learn more about ChatGPT Business …

View change record →
Featured, High severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

38 provisions
12 featured
10 clause types
17 high severity
Restricted or Prohibited Content/Industries 1
Stay ahead of the changes

Monitoring

OpenAI has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle API access limited to authorized employees and contractors and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

BIPA
Illinois, USA
View official text ↗
CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
DMCA
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
UK GDPR
United Kingdom
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗

Related Analysis

Privacy · May 3, 2026
OpenAI Privacy Policy Update May 2026: New Terms Authorize Advertiser Data Sharing

OpenAI expanded its data sharing terms to include third-party marketing partners. The updated policy authorizes the use of personal data fo…

Dependency Governance · June 11, 2026
AI Dependency Governance: How API Terms Govern Every App Built on OpenAI, Anthropic, and Google

872 provisions across 8 AI platforms. The terms your AI provider sets become the terms your product operates under.

Platform Analysis · June 12, 2026
OpenAI Changed Its Privacy Policy 4 Times in One Week. Here Is What Actually Changed.

Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.

Regulatory Analysis · June 28, 2026
The Great American AI Act, Explained: What the First Federal AI Law Would Require

The bill does not regulate most AI startups directly. But it changes the companies they depend on. Here is what the first federal AI law wo…

Regulatory Analysis · July 8, 2026
The AI Foundation Model Transparency Act, Explained

H.R. 8094 would make the FTC the referee for AI model disclosure. It also names system cards as a way to comply, which turns a voluntary in…

Archival ProvenanceSource & Archival Record
Last Captured July 26, 2026 00:06 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000825
Version ID CA-V-005281
SHA-256 29a1341f788b9e0b01a2a871cd81c35ddbcbf7f446481bbe51d0e7ac8117f13d
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans