Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that user-submitted content, including prompts, files, images, audio, and video, may be used by OpenAI to train the AI models that power its Services, subject to a user-controlled opt-out.
This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a default opt-in posture for AI model training using personal user content, requiring users to affirmatively opt out rather than affirmatively consent; in jurisdictions where secondary use of personal data for AI training requires opt-in consent, this posture may require evaluation under applicable law.
The updated policy explicitly discloses that OpenAI receives information from advertisers and other data partners for Free and Go users, and uses this data to personalize ads and measure ad effectiveness. The policy now states that Free and Go users can control what data OpenAI uses to personalize ads through advertising controls in account settings. This represents clarified disclosure of an existing practice rather than a new authorization.
View change record →The updated privacy policy now explicitly states that OpenAI receives information from advertisers and other data partners, which is used to personalize ads shown to Free and Go users and to measure the effectiveness of those ads. For example, the policy notes that OpenAI could receive information about purchases users make from advertisers. The policy now includes a dedicated section on ad personalization and measurement as a primary use of personal data for these user tiers. You can manage what data OpenAI uses for ad personalization by accessing the advertising controls in your account settings or by using the Data Controls option.
View change record →The updated policy now explicitly authorizes OpenAI to promote products and services to users through direct marketing on third-party properties and to share limited information with select marketing partners (who are not service providers) to support these efforts. The policy states that some marketing partners may receive information through cookies and similar technologies. The revised terms establish that these marketing practices are subject to user choices and controls, with additional information and opt-out options available. You can make choices about the use of your information for third-party product promotion purposes through controls referenced in the policy.
View change record →Under this provision, user-submitted content including prompts and uploaded files is used to train OpenAI's AI models unless the user opts out through account settings or privacy.openai.com. The policy also notes that content which has already been de-identified and disassociated from an account prior to a deletion request may not be removed from training datasets.
Cross-platform context
See how other platforms handle User Content Used to Train AI Models and similar clauses.
Compare across platforms →Monitoring
OpenAI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"As noted above, we may use Content you provide us to improve our Services, for example to train the models that power ChatGPT. Read our instructions on how you can opt out of our use of your Content to train our models.Excerpt from OpenAI's Privacy Policy
1) REGULATORY LANDSCAPE: This provision engages GDPR Article 6 lawful basis requirements and Article 9 for any special category data that may appear in user prompts, enforced by EU data protection authorities including the Irish Data Protection Commission as lead supervisory authority for OpenAI Ireland Limited. For US users, it engages CCPA and CPRA provisions regarding the use of personal information for purposes beyond the primary transaction, and may interact with emerging state AI transparency and consumer protection statutes. The FTC Act's unfair or deceptive practices standards are relevant to whether opt-out disclosures and mechanisms are sufficiently clear and accessible. 2) GOVERNANCE EXPOSURE: Medium. The default opt-in structure for AI model training is operationally significant because personal data submitted by users as prompts, including potentially sensitive information, is used for a secondary commercial purpose unless users locate and activate the opt-out. The policy acknowledges that already de-identified content may not be retrievable or deletable after the fact, which creates a practical limitation on the effectiveness of the deletion right for content already incorporated into training data. 3) JURISDICTION FLAGS: EU and UK users are directed to a separate policy version, suggesting different consent mechanisms may apply in those jurisdictions. California users have CPRA-based rights to know about secondary uses, and the opt-out mechanism must satisfy CPRA's requirements. Users in jurisdictions with emerging AI-specific legislation, including the EU AI Act as it comes into force, may have additional rights regarding automated processing of their personal data. 4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise and API customers are explicitly excluded from this policy; their data governance is addressed in separate customer agreements. Procurement teams deploying ChatGPT for employee use under free or consumer accounts should note that those accounts remain subject to this opt-out-based model training provision unless account settings are configured. B2B compliance teams should verify whether their deployment model falls under the API agreement or consumer terms. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should audit whether their users or employees have activated the model training opt-out if organizational policy requires it. Data mapping updates should reflect that user content submitted to ChatGPT consumer services may flow into model training datasets absent affirmative opt-out. For organizations in sectors handling sensitive data, internal policies may need to address whether employees should use Temporary Chat mode or opt out of model training by default.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes a default opt-in posture for AI model training using personal user content, requiring users to affirmatively opt out rather than affirmatively consent; in jurisdictions where secondary use of personal data for AI training requires opt-in consent, this posture may require evaluation under applicable law.
Under this provision, user-submitted content including prompts and uploaded files is used to train OpenAI's AI models unless the user opts out through account settings or privacy.openai.com. The policy also notes that content which has already been de-identified and disassociated from an account prior to a deletion request may not be removed from training datasets.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.