Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The policy authorizes OpenAI to use content submitted by users, including prompts and uploaded files, to train the AI models that power ChatGPT and other services, subject to an opt-out that users can exercise through account settings.
This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that user content submitted during normal use of ChatGPT is available for AI model training by default. The policy notes that content already de-identified and disassociated from an account prior to a deletion request may not be removed from training datasets, which is a material limitation on the practical scope of the deletion right in this context.
Interpretive note: The practical scope of the opt-out (specifically which content is excluded and whether previously processed content is affected) is not fully specified in the document, and the enforceability of the de-identification carve-out under various state privacy laws may vary.
The updated policy removes language describing how OpenAI uses advertiser and data partner information to personalize ads and measure ad effectiveness. The policy also removes the specific mechanism Free and Go users previously had to control ad personalization through account settings. In exchange, the policy adds explicit authorization for OpenAI to identify which of a user's contacts use OpenAI services and to monitor all content submitted on the platform for fraud and misuse detection. The authorization to monitor content and identify contacts now appears in the main policy purposes section rather than in supplementary documentation. You can review the Korea Addendum if you are located in South Korea to understand region-specific privacy rules.
View change record →The updated policy explicitly discloses that OpenAI receives information from advertisers and other data partners for Free and Go users, and uses this data to personalize ads and measure ad effectiveness. The policy now states that Free and Go users can control what data OpenAI uses to personalize ads through advertising controls in account settings. This represents clarified disclosure of an existing practice rather than a new authorization.
View change record →The updated policy removes language that previously described ad personalization controls available to Free and Go users through account settings, though the policy continues to authorize OpenAI to personalize ads and measure their effectiveness for these user tiers. Previously, the policy explicitly stated that 'For Free and Go users, you can use the advertising controls in your account settings to control what data we use to personalize the ads we show you on our Services.' This language is no longer present in the updated version. The policy still lists ad personalization as an authorized use of personal data for Free and Go users, but no longer explicitly describes how users can access controls to manage this practice. You should verify whether advertising controls remain functional in your OpenAI account settings, as the policy no longer explicitly references them.
View change record →Under this clause, prompts and other content submitted to ChatGPT are used to train OpenAI's models unless the user actively opts out. The agreement specifies that content already de-identified before a deletion request is made may remain in training data even after the account deletion is processed.
How other platforms handle this
This is still Your Content, and you are responsible for it and its accuracy, as well as your use of it on our Services and any and all decisions made, actions taken, and failures to take action based on Your Content.
You are responsible for any content, data, or instructions submitted to the Services via any Automated System. Instacart's license to use user content...includes content submitted by or through Automated Systems...
If you use a feature of our Services that is integrated with, facilitated by, or otherwise assisted by artificial intelligence...your inputs are "User Content" and the outputs of that service are "Chegg Content"...
Monitoring
OpenAI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"As noted above, we may use Content you provide us to improve our Services, for example to train the models that power ChatGPT. Read our instructions on how you can opt out of our use of your Content to train our models.Excerpt from OpenAI's Privacy Policy
1) REGULATORY LANDSCAPE: This provision engages CCPA and CPRA (California), which govern use of personal information for purposes beyond the primary transaction and may require disclosure and opt-out rights for secondary uses. Under GDPR (applicable to EEA users via a separate policy), use of personal data for model training may require a valid legal basis such as legitimate interests or consent, and the Article 22 automated decision-making framework may be implicated. The FTC has indicated interest in AI training data practices under its unfair or deceptive practices authority. Multiple US state comprehensive privacy laws enacted through 2025 include provisions on secondary use of personal data that may apply depending on user jurisdiction. 2) GOVERNANCE EXPOSURE: Medium. The default-on nature of training data use, combined with the limitation that de-identified content may not be removable post-deletion, creates exposure under state privacy laws that require meaningful opt-out mechanisms and limit secondary data use. The practical scope of the opt-out (what content is excluded going forward versus what has already been processed) is not fully specified in the document. 3) JURISDICTION FLAGS: California (CPRA secondary use and opt-out requirements), Colorado, Connecticut, Virginia, Texas, and other states with comprehensive privacy statutes create heightened exposure. EEA and UK users are directed to a separate policy, but data processed prior to jurisdictional separation may be relevant. The provision's interaction with GDPR legitimate interests balancing tests is not addressed in this document. 4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers operating under separate API agreements are explicitly excluded from this policy, which limits direct exposure for B2B contexts. However, organizations that allow employees to use consumer-facing ChatGPT accounts should assess whether employee-submitted content is subject to this training data provision and whether that is consistent with internal data governance policies. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should verify that the opt-out mechanism meets the substantive requirements of applicable state privacy laws, including whether it is sufficiently prominent and accessible. Data mapping should distinguish between content processed before and after opt-out to clarify the practical scope of the right. Organizations with employees using consumer ChatGPT accounts may want to issue internal guidance or require use of API-based or Enterprise deployments.
Regulatory citations, enforcement risk, and due diligence action items.
How Meta, TikTok, and Supabase restructured governance language across documents, jurisdictions, and consent frameworks through incremental document updates.
How 10 AI platforms describe the use of user data for model training, improvement, and development, based on archived governance provisions.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes that user content submitted during normal use of ChatGPT is available for AI model training by default. The policy notes that content already de-identified and disassociated from an account prior to a deletion request may not be removed from training datasets, which is a material limitation on the practical scope of the deletion right in this context.
Under this clause, prompts and other content submitted to ChatGPT are used to train OpenAI's models unless the user actively opts out. The agreement specifies that content already de-identified before a deletion request is made may remain in training data even after the account deletion is processed.
ConductAtlas has identified this type of provision across 217 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.