In the space of three short years, ChatGPT has changed the way consumers and businesses interact with technology. After achieving 100 million active users in a record two months, it has become a desktop and mobile device staple.
But as we come to rely on it for everything from writing emails to business planning, one important question keeps resurfacing. Is it actually safe?
Yes: for everyday use, ChatGPT is safe, as long as you treat every chat as if it were public.
That one rule is what keeps the answer a yes: never share personal, financial or corporate information in a chat or prompt. Treat anything you type as potentially visible to the public.
While your traffic is encrypted in transit and at rest, and OpenAI’s safeguards are indeed genuine, your conversations are also used to train its models by default, and are kept until you delete them.
And yes, it is legitimate. ChatGPT is a real product from a well-known company, and the thing to be suspicious of is the counterfeit apps, lookalike websites and emails that borrow its name - not the official tool itself.
Where ChatGPT is fine
- Drafting, editing, explaining, brainstorming and summarizing material that is already public.
- Tasks where a wrong answer costs you a minute, not money, credentials or a job.
Where it is not
- Anything personal, financial, health-related or internal to your employer - in a prompt, an uploaded file, or a throwaway “just for context” aside.
- Legal, medical, tax or safety decisions taken on the answer alone.
- Answers treated as fact. Even the source cited for a claim can turn out to be broken, unrelated or invented.
Three habits cover most of the risk
- Assume every chat is public: the Red List below covers exactly what never to type.
- Turn off model training in Settings → Data Controls (“Improve the model for everyone”), and use Temporary Chats for anything sensitive.
- Check before you act on it: confirm what matters against a primary source rather than accepting it because it reads confidently.
The rest of this guide is built in four steps: what never to type, the risks worth knowing, how ChatGPT works and what it stores, and the settings and habits that put you back in control.
The “Red List”: Information you should never share
Treat every chat as if it might be shared publicly. Never enter:
- Personal identifiers: Social security numbers, passport numbers, addresses, etc.
- Financial information: Card numbers, bank account details, tax IDs, etc.
- Passwords, API keys, or any other secrets (e.g. MFA tokens).
- Company data: Source code, client lists, internal documents, non-public financial reports, legal documents.
- Health information: Anything covered by HIPAA, GDPR or similar laws.
The list is short because the rule behind it is: if you would not email it to a stranger, do not type it into a chatbot. Catching yourself mid-prompt is far easier than trying to remove something afterwards, as your chats are stored by OpenAI, and a deleted chat is not removed immediately.

The seven biggest ChatGPT security risks
The risks of using ChatGPT fall into seven groups: account and data breaches, privacy and training, prompt injection, fake apps and phishing, misinformation, malware and social engineering, and shadow AI at work.
1. Data breaches and credential theft
In March 2023, a bug in the open-source library Redis temporarily exposed parts of other users’ chat titles, messages, and potentially payment-related information. Although this bug was quickly patched, there’s always the risk that threat actors manage to exploit a zero-day vulnerability to access OpenAI/ChatGPT databases, or find another way in.
Your account may also be targeted separately. In 2024, security firm Group-IB found over 100,000 stolen ChatGPT credentials on the dark web, mostly lifted from devices compromised by malware. Once someone steals your password, they can read your entire chat history.
2. Privacy and AI training
By default, OpenAI uses your conversations to train future models (if you’re using the consumer-grade version). Authorized employees or contractors may read anonymized snippets for annotation. While identifiers are removed, context can still reveal sensitive information. In corporate versions, human reviews are “highly limited to only what is necessary for security, abuse monitoring, and legal compliance.”
3. Prompt injection attacks
Attackers can craft prompts that bypass built-in guardrails, potentially forcing the model to reveal restricted content. For example, attackers hiding malicious instructions on webpages or social media profiles scanned by ChatGPT.
4. Fake apps and phishing scams
App stores and browser-extension sites are full of counterfeit ChatGPT apps that look like the real thing but are designed to harvest logins and/or install malware. Only download apps published by OpenAI itself.
5. Misinformation and hallucinations
ChatGPT sometimes presents false information in a very trustworthy manner. This misbehavior is also known as a “hallucination.” Hence, treat all answers as unverified until confirmed by a primary source.
That applies to the sources behind an answer as much as to the answer itself. A wrong claim usually arrives with a citation attached, and the link can be broken, unrelated, or simply invented.
6. Malware and social engineering
Threat actors can persuade ChatGPT to return code snippets or phishing templates that help them to execute cyberattacks. It can also help generate convincing deepfakes for fraud and extortion, even create malware on the fly. All told, AI has dramatically lowered the technical barrier for criminals, as the UK’s NCSC warns. “Jailbreak-as-a-service” offerings on the dark web make their job even easier.
7. Shadow AI in the workplace
When employees use public ChatGPT for internal tasks, they might unwittingly share confidential data with the LLM, presenting security and compliance risks. In 2023, Samsung staff accidentally uploaded source code and meeting notes to the chatbot, forcing the Korean tech giant to ban external AI tools. A fifth (20%) of global organizations said they suffered a data breach over the past year due to security incidents involving shadow AI, according to IBM.
If you need to brief colleagues on what is and is not safe to paste into an AI tool, see ESET’s guide to what employees need to know before chatting with ChatGPT.
How ChatGPT works
ChatGPT runs on a large language model (LLM) – a predictive system trained on huge amounts of text and code. It doesn’t think like we do. It merely identifies statistical patterns in language to generate the most likely next word or phrase.
Every prompt you type into ChatGPT is processed and stored on OpenAI’s servers unless you request deletion. That’s why it’s important to think carefully about what data you share with the tool. This is the key to minimizing security and privacy risks while using it.
OpenAI’s security and privacy protections
OpenAI has invested heavily in enterprise-grade security. But there are differences between the level of security and privacy provided by default in the consumer and corporate (ChatGPT Enterprise/Business/API) versions.
Security provisions include:
- Encryption: All traffic uses TLS 1.2+ in transit and AES-256 encryption at rest – the same standards banks rely on. Enterprise customers can use Enterprise Key Management (EKM) to control their own encryption keys
- Compliance and audits: Regular users benefit from compliance with GDPR, CCPA and other data protection/privacy regulations. But business versions get independently audited to SOC 2 Type 2 and CSA STAR, and align with best practice standards ISO/IEC 27001, 27017, 27018, and 27701
- Bug Bounty Program: Ethical hackers are paid to report vulnerabilities before threat actors can find and exploit them
- Pen testing: The OpenAI API and ChatGPT business plans undergo regular penetration testing to check for new vulnerabilities
- Incident response: OpenAI’ security team works 24/7/365 to monitor and rapidly respond to suspicious activity
- Access Controls: Regular users get multi-factor authentication (MFA) for accounts. But business customers can also enforce Single Sign-On (SSO) via SAML, use an admin console for user management, domain verification, and role-based access controls (RBAC)
- Content Moderation: A mix of guardrails, automated filters and human reviewers screen out malicious or illegal material
- Local data storage: Eligible ChatGPT Enterprise, Edu, and API platform customers can take advantage of data residency in the US, Europe, UK, Japan, Canada, South Korea, Singapore, Australia, India, and the UAE to comply with local sovereignty requirements
- Data ownership and training: By default, consumer prompts are used for model training. For business versions, data is excluded from model training by default and the organization owns and controls its own inputs and outputs, or at least that is what OpenAI claims.
Note: These measures are largely designed to protect ChatGPT’s own infrastructure. But they can’t always mitigate users’ own mistakes or completely prevent abuse.
What data does ChatGPT collect – and who can see it?
The short version: Everything you type is stored on OpenAI’s servers, staff and contractors can review some of it for training, safety and annotation, and it is kept until you delete it. That is not unusual for a cloud service—but “stored” is not the same as “private”, and the settings further down this guide are what close the gap between the two.
Data Type What It Includes Who Can Access It Prompts & History Everything you type and the AI’s replies (including uploaded files and images). Authorized OpenAI staff / contractors (for model training unless you opt out). In business versions, this access is more restricted (as above) and data is only used for training if customers opt in Account Details Email, name, phone number, payment info (Plus/Business/Enterprise) OpenAI for billing and support Usage Data IP address, browser, device type, approximate location OpenAI for analytics and security monitoring
For Free and Plus account holders, chats are stored indefinitely unless you delete them. They’re then scheduled for permanent deletion from the system within 30 days. If you turn off “Chat History & Training” (or use Temporary Chat mode), chats will not be saved in your visible history or used for training, but a copy is retained for up to 30 days for abuse and misuse monitoring before being permanently deleted.
For ChatGPT Business and Enterprise customers, chats are saved in your history until manually deleted. Admins on the Enterprise plan have more granular control over retention settings.
Ten good habits to protect your data
- Use only official platforms: chat.openai.com or the verified ChatGPT mobile app available on Google Play and Apple‘s App Store.
- Create a strong, unique password via a password manager.
- Enable Multi-Factor Authentication (MFA): Log in to your account. Select Settings → Security → Multi-Factor Authentication.
- Turn off data training: Settings → Data Controls → toggle off “Improve the model for everyone.”
- Use Temporary Chats (available on all versions) for sensitive topics – as these aren’t stored or used for training. To start a Temporary Chat, open a new chat and click the circular “Temporary” button in the top-right corner of the page.
- Follow the Red List as above.
- Use anonymized examples rather than providing real information/files in prompts.
- Use a VPN on public Wi-Fi to encrypt traffic.
- Delete chat history regularly (Settings → Data Controls → Clear History).
- Log out on shared devices so no one else can hijack your account.
How to check a link ChatGPT gives you
Fake apps are only half of the phishing problem. The other half is the link an answer hands you - a source cited for a fact, a “download here” button, or a shop the chatbot says is legitimate. Two checks take under a minute, and neither needs any software.
Read the destination before you click. Hover or long-press the link and look at the full address, not the underlined text. Shortened links, a string of words where a company name should be, and domains that add “-login”, “-verify” or “-security” are the three patterns worth stopping on. If an answer says a site is official, open it from a search engine or your own bookmark instead of from the chat window.
Verify the claim, not just the link. A citation proves that a source exists, not that the source agrees with the answer. Check the fact on the original page and remember that an AI can cite a page that has since been taken down or replaced.
If you want the verdict checked for you, ESET Link Checker is free: paste any URL and it reports whether the destination is safe, unsafe, or suspicious.
And ESET HOME Security goes a step further with AI Conversation Security, part of the Browser Privacy & Security browser extension. It scans every ChatGPT response for references to unreliable or unsafe sources and for malicious code and marks a flagged source link or script with a warning icon you can hover over before you decide to click.
ESET also offers a free AI Skills Checker that analyses an AI skill or add-on and checks every URL it references - useful if you use AI agents rather than just the chat window.
How to turn off data training
- Log in to ChatGPT.
- Click your name (bottom left or top right).
- Go to Settings → Data Controls.
- Locate “Improve the model for everyone.”
- Toggle it OFF.
When this is disabled, OpenAI will no longer use your future conversations for model training. Combining this with the temporary chat function is the closest thing to a private chat on Free, Plus and Pro plans. Enterprise accounts already have model training off by default.
Safety tips for businesses, parents, and high-risk professions
Businesses
Public ChatGPT plans are not suitable for confidential data. ChatGPT Enterprise offers better levels of security and privacy. But a locally managed, open source AI chatbot would be a better option for the security-conscious business, although there would be extra management and deployment overheads to consider.
Feature Free / Plus Enterprise Model training Manual opt-out Disabled by default Data retention Chats saved until manually deleted Zero or custom retention possible Data ownership Shared license Customer owns data Compliance GDPR, CCPA, etc. SOC 2 Type 2 / GDPR / CCPA Access control Standard login, MFA MFA plus SSO / SAML integration, RBAC and domain verification
Parents
ChatGPT’s minimum age for users is 13 years. The main risks for teens are misinformation, over-reliance on the tool for homework, and possible exposure to inappropriate content. There are also cases of “AI psychosis” and chatbots reinforcing users’ delusions. Since October 2025, OpenAI’s Parental Controls let parents and carers monitor usage and apply content filters.
High-risk users
Doctors, lawyers, financial advisors, and others in high-risk professions should never input client or patient data into the public tool.
- Healthcare: Violates HIPAA – potential fines and license risk.
- Legal: Breaches attorney-client privilege.
- Financial advisors: May violate SEC, FINRA, GDPR and other regulations.
ChatGPT vs. the rest: Privacy comparison
Feature OpenAI ChatGPT Google Gemini Anthropic Claude Default training Opt-in (by default) Opt-in (by default) Opt-out (by default) Business version ChatGPT Enterprise Gemini for Workspace Claude Enterprise Business data use Zero retention possible Zero retention possible Zero retention possible Compliance SOC 2 Type 2, GDPR SOC 2 Type 2, GDPR, HIPAA SOC 2 Type 2, GDPR, HIPAA Data deletion Manual (user or admin) Auto-delete configurable (3–36 months) Manual
Takeaway: Anthropic’s Claude remains the most privacy-centric chatbot by default, but all enterprise-tier plans offer comparable protections when configured properly.
What to do if your ChatGPT account is hacked
1. Change your password immediately.
2. Enable MFA: Settings → Security → Multi-Factor Authentication.
3. Check API keys for unauthorized use and revoke any unknown ones.
4. Contact OpenAI Support to report the incident.
5. Review chat history for suspicious activity.
6. Log out from all other devices: Settings → Security.
7. Review any connected apps for suspicious activity and revoke unknown access.
8. Run anti-malware scans on your device(s)
Speed matters – the sooner you act, the lower the risk of further exposure.
What the lawsuits changed for users
ChatGPT has been in court almost since it launched. The cases cover what the model was trained on, what happened to your chats while they run, and who controls the company. Only the second really touches you.
Training data. The New York Times sued OpenAI and Microsoft in December 2023 over millions of articles and books used without a license; that case and a later suit by nearly 400 newspapers are still pending. In Europe the Munich Regional Court ruled on 11 November 2025 that ChatGPT had infringed copyright on nine German songs - a first-instance decision, not yet final. However, none of this is about what you type in.
Your chats. The New York Times case put OpenAI under a court order to retain consumer and API content indefinitely, including chats users had deleted. OpenAI says that order ended on 26 September 2025 and normal retention resumed: deleted chats, Temporary Chats and API data are removed within 30 days again. The Times still wants the April–September 2025 set preserved; OpenAI says it stays locked down and has not been handed over. If you delete a chat today, it goes on the normal 30-day clock - and Temporary Chats remain the cleanest option for anything sensitive.
Harm cases and ownership. The parents of a 16-year-old who died by suicide sued OpenAI in August 2025 over wrongful death and failure to warn. OpenAI has denied liability, arguing misuse and Section 230; the case is ongoing and no finding has been made against OpenAI, although the company subsequently rolled out parental controls and additional safeguards for teen users.
The future of AI safety
AI regulation is accelerating. The EU AI Act will require new levels of transparency and data governance from providers. Expect OpenAI and its competitors to add on-device processing (which includes workload protection), more impactful user-controlled settings (which will be similar to Claude’s default settings), and real-time audit logs defined by relevant regulatory bodies.
Expert tips and insights
“While users have adopted large language models such as ChatGPT into their daily routines, the security and privacy risks connected with these services remain unclear. Despite this, many companies are quick to jump on the bandwagon, incorporating AI agents and off-the-shelf models from online marketplaces into their systems - often without fully understanding where these tools fit or how to protect users’ personal data.
This rush for convenience could lead to serious data breaches, privacy leaks, and unauthorized access, especially as businesses use “black box” AI models with unclear origins or training data. At the same time, AI-generated scams—such as deepfakes, fake reviews, and phishing emails—will become harder to spot, allowing even inexperienced criminals to run convincing frauds and influence campaigns.
AI-powered fake social media profiles and bots will blur the line between real and artificial, making it tougher to know what’s genuine online. As a result, users need to be more cautious than ever, as the services they trust may be using AI in ways that increase both convenience and risk, while industry standards for managing and securing these technologies struggle to keep up.“
- Juraj Jánošík, ESET Head of AI
Final verdict
So, is ChatGPT safe? Even if you take sensible precautions, AI and AI agents expand the attack surface and can expose you (and your organization) to extra risk. OpenAI has built some security into its products, but its business model still relies on data collection. Your security and privacy depend on how you manage that data.
It is worth saying that the same capability cuts both ways. Used deliberately, ChatGPT is a genuinely useful defensive tool: it can explain an unfamiliar error message in plain language, summarize a security advisory you have not had time to read, help a small business with no security team draft its first checklist, or pressure-test a plan you have already made. The risk was never the assistant itself - it is what you put into it, and how far you trust what comes back out.
Next steps:
- Go to Settings → Security and turn on Multi-Factor Authentication (MFA).
- Go to Settings → Data Controls and toggle off “Improve the model for everyone.”
- For sensitive topics, use Temporary Chats and regularly Clear History.
- Share this guide with your team to avoid any “Shadow AI” incidents.
Managed responsibly, ChatGPT can be a powerful and reasonably safe tool. But only when you stay in control of your own data.
Let AI do its best for you - securely. Take the next step with AI-powered threat detection in ESET HOME Security. Protect your devices and data while you explore the power of ChatGPT.
- Using ChatGPT on mobile? Download ESET Mobile Security for Android - available as a standalone app or included in your ESET HOME Security subscription.
- Running ChatGPT for work? ESET Small Business Security keeps your business safe.
- Checking a link before you click it? ESET Link Checker gives you a free verdict in seconds.
Frequently asked questions
Is ChatGPT confidential?
Not by default, and “confidential” is not the same as “private”. OpenAI uses consumer conversations for model training unless you opt out, and authorized reviewers can access some chats for safety and annotation. Turning off data training and using Temporary Chats makes a conversation far more private, in the same way that ChatGPT Business or Enterprise does. There is no zero-access encryption, so OpenAI can technically reach your chats.
Does OpenAI sell my data?
No. OpenAI states it does not sell user data but may use it for service improvements and share limited information with vendors (e.g., payment processors).
Is ChatGPT legit?
Yes. It is a genuine product built by a well-known company and used by at least 100 million people, so it is not a scam, and using it does not make you a target. But “is it legit?” and “is ChatGPT bad?” are really two questions. As a tool, it is reasonable for everyday work as long as sensitive data stays out of your prompts. What deserves your suspicion is anything impersonating it - counterfeit apps, lookalike websites and emails that borrow the ChatGPT name - and any answer you act on without checking first.
Is the ChatGPT app safe?
Yes – if it is the official app published by OpenAI. Always check the developer name before downloading. And only use official app stores (Google Play, Apple App Store)
Why does ChatGPT need my phone number?
For one-time verification to prevent spam and bot account abuse.
Is ChatGPT HIPAA and GDPR compliant?
Not out of the box. For HIPAA, Free and Plus versions are not compliant. Only Enterprise accounts covered by a signed Business Associate Agreement (BAA) can meet HIPAA standards. For GDPR, it depends on how you use the chatbot. Businesses must at least use ChatGPT Enterprise, ChatGPT Business, or an API with a signed Data Processing Addendum (DPA) to minimize the risk of noncompliance. But even so, this is no silver bullet.
Can ChatGPT be hacked?
Yes. Like any online service, its backend faces possible breaches. Plus, your account could be hacked unless you follow password best practices combined with MFA and phishing awareness.
What data should I not share on ChatGPT?
Consider every prompt as public. For example never type in personal, financial or health information, passwords, or sensitive corporate data.
What should I do if my account is hacked?
Change your passwords, switch on MFA and notify OpenAI. Log out on all devices, run anti-malware scans and look out for suspicious activity.
Can ChatGPT give me a malicious link?
Yes, it can repeat a link that is malicious, and it can also invent one that sounds right. The model does not verify that a source is trustworthy, and it can reproduce a link from its training data that has since been taken over, or build a plausible-looking address for a page that never existed. Never click a link from an AI answer without reading the destination first, and check any page that asks for a login, payment or download against the organization’s own official site.
Does the OpenAI lawsuit affect my ChatGPT data?
A court order in the New York Times case once forced OpenAI to keep consumer chats indefinitely, including deleted ones, but OpenAI states that ended on 26 September 2025 and that deleted chats, Temporary Chats and API data are now removed within 30 days again. The Times still asks OpenAI to preserve an April–September 2025 set, which OpenAI says stays locked down and has not been handed over, and business customers on a Zero Data Retention agreement were never covered.









