10 Total
0 High severity
7 Medium severity
3 Low severity
Summary

OpenAI's Privacy Policy (ROW) establishes the data collection, processing, and sharing practices applicable to users of ChatGPT, the OpenAI API, DALL-E, and Sora. The policy authorizes OpenAI to collect and use submitted content—including conversations, uploaded files, images, audio, and video—for model training and improvement, with users able to disable the 'Improve the model for everyone' setting in Data Controls to opt out of training use. The policy permits OpenAI to share user data with third-party API operators, vendors, affiliates, and acquiring entities in connection with business transactions or asset transfers.

Technical / Legal Breakdown

This document is OpenAI's global Privacy Policy (updated February 6, 2026), governing the collection, use, and disclosure of personal data by OpenAI's consumer and API services, including ChatGPT, DALL-E, Sora, and related products, with separate versions for EEA/UK/Switzerland and U.S. users. The policy states that OpenAI collects account information (name, email, payment details), content users provide (text, files, images, audio, video), usage data (log data, device identifiers, IP addresses, browsing activity), and location information; the terms authorize use of this data for service delivery, safety monitoring, research and development, and to train AI models, with users able to opt out of training use in certain contexts. The policy authorizes disclosure of personal data to vendors, service providers, affiliates, business partners, law enforcement, and in connection with mergers or asset sales; it also permits sharing with third-party operators who deploy OpenAI's API, which means user data may flow to entities whose own privacy terms govern further processing. The policy engages GDPR for EEA/UK/Switzerland residents (directing those users to a separate policy), CCPA and multiple U.S. state privacy laws for residents of California, Texas, Virginia, Colorado, and others (addressed in a dedicated section), and COPPA with respect to the stated minimum age of 13. Material compliance considerations include the lawful basis assertions for AI training under GDPR, the adequacy of consent and opt-out mechanisms for U.S. state law purposes, and the scope of data retention tied to legal obligations and business necessity rather than fixed deletion timelines.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial
Medium — 7 provisions
Low — 3 provisions

Monitoring

OpenAI has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle AI Model Training on Conversation Data and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
UK GDPR
United Kingdom
View official text ↗

Related Analysis

Privacy · May 3, 2026
OpenAI Privacy Policy Update May 2026: New Terms Authorize Advertiser Data Sharing

OpenAI expanded its data sharing terms to include third-party marketing partners. The updated policy authorizes the use of personal data fo…

Archival ProvenanceSource & Archival Record
Last Captured March 10, 2026 03:33 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000006
Version ID CA-V-000070
SHA-256 3b160fe944be24fac66984713a224734d9c562d07559a5fc517f7f1fb9dff79d
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans