Guide to using ChatGPT for confidential work

Is It Safe to Use ChatGPT for Confidential Work?

Free ChatGPT can train on your chats unless you opt out. Here is what that setting changes, what it does not, and safer ways to handle confidential work.

Venice.aiVenice.ai

You paste a contract clause, a client brief, or a chunk of private source code into ChatGPT because the tab is already open. On the free tier, OpenAI can use those conversations to train models unless you opt out. The chat is also tied to an account that asks for an email and, for some accounts, a phone number, which makes this a weak default for confidential work.

The sections below cover what the training toggle changes, what it leaves in place, and which products are built for stricter handling.

Short answer

Free-tier ChatGPT is not a safe default for confidential work. OpenAI's data controls FAQ says ChatGPT trains on user conversations by default for free-tier users, and that you can opt out in settings. Opting out stops that training use, but it does not turn the chat into a system where OpenAI cannot hold the text.

For contracts, customer data, or unpublished code, use a host that does not train on inputs and that states whether the prompt is stored.

On Venice, Private mode does that: the prompt and response are not stored, and inputs are not used for training. Pro adds TEE for hardware-isolated inference and E2EE, which keeps the prompt encrypted until it reaches a verified TEE.

Why is ChatGPT a weak default for confidential work?

OpenAI's consumer product is built to improve from use, and the free tier reflects that: conversations are used for training unless you change the control. The same help article says you can opt out, which is worth doing right away if you already have work material in a free account. Even after that, the remaining product is still an OpenAI service attached to your login.

A training opt-out is not a storage opt-out, and it is not end-to-end encryption. Ordinary ChatGPT sessions are protected in transit by HTTPS. For example, that stops someone on the same cafe Wi-Fi from reading the request, but it does nothing to stop the operator of the service from processing the text. Venice's own privacy page draws the same distinction across its four modes, where Private means the prompt and response are not stored.

E2EE, which is Pro only, goes further: the prompt is encrypted on your device and is decrypted only inside a verified TEE. Free ChatGPT offers neither of those guarantees.

Claude handles this differently, though not more simply. Since August 2025, new and existing Claude consumer users on Free, Pro, and Max have had to choose whether chats are used for training. There is no default either way. Opting in extends retention to 5 years, while opting out keeps the standard 30-day retention. Safety-flagged conversations may still be used for training even if you opted out, as Anthropic documents in its consumer terms update.

Commercial Claude products, including the API, are excluded from that consumer training policy by default, though Anthropic still receives the text you send to the API.

If the document would be a problem in someone else's hands, the useful question is not which chatbot feels professional, but who receives the text, whether they store it, and whether they train on it. You can see how the major providers compare on those defaults in Which AI companies train on your conversations.

What you can do about it

1. Turn off ChatGPT training before you paste anything else

Open ChatGPT settings and use the data control OpenAI documents in the data controls FAQ, then confirm the training toggle is off on the account that already holds your work chats rather than only on a new login. If you are staying in ChatGPT for low-sensitivity drafts, this is the fastest fix available.

  • Difficulty: Easy
  • Best for: Free-tier accounts that already exist, when the material is sensitive but you are not ready to move tools.

2. Strip names and identifiers, then paste a short excerpt

Replace client names, account numbers, email addresses, and internal hostnames with placeholders before the text goes into any chatbot. Then paste only the clause you need explained instead of the whole file, because a model can summarize a redacted paragraph without the signature block.

  • Difficulty: Easy
  • Best for: One-off questions where the risk is the identifiers, not the general topic.

3. Keep a second account for anything that is not public

Use a work login only for material your employer has approved, and keep personal experiments off it. ChatGPT requires an account and an email, and some accounts require a phone number, so a separate login does nothing about training on its own and has to be paired with the opt-out. If your company has a contract with OpenAI, follow that contract, since the training default described here applies to the free-tier consumer product.

  • Difficulty: Easy
  • Best for: People who still need ChatGPT for public research and want confidential files kept out of that account.

4. Move confidential prompts to a host that does not train on them

Venice does not train models on user inputs. In Private mode, inference runs on Venice-controlled GPUs or zero-data-retention partner infrastructure, the prompt and response are not stored, and conversation history stays in the browser. The default text model, Kimi K2.5, does not log conversations.

If you switch that chat to Claude, GPT, or another third-party model, the provider receives the conversation content. Your Venice identity is stripped, but the provider can still store what it received, so stay on a Private model for confidential text.

  • Difficulty: Medium
  • Best for: Contracts, memos, and code you do not want used as training data.

5. Use Pro E2EE when you do not want Venice to read the prompt

On Pro E2EE, the prompt is encrypted on your device, stays encrypted through Venice, and is decrypted only inside a verified TEE. A verification icon on the response opens an attestation report.

The limits come with the feature. There is no web search and no memory, replies are slower, the model list is shorter, and it is text only. File upload belongs to TEE rather than E2EE, so anything you want handled under E2EE has to be pasted in as text. Pro starts at $18/month.

The best tools that don't have this problem

1. Venice

Venice is the practical alternative when you need a host that will read private text without training on it. Private mode is the default path: the prompt and response are not stored, inputs are not used for training, and history stays in the browser. Pro adds TEE for hardware-isolated inference, where file uploads still work, and E2EE for text only.

The free tier includes 10 text prompts a day plus API access, and Pro is $18/month, with BTC and USDC accepted at checkout. Signing up does not require a phone number for know your customer checks.

  • What it does differently: The privacy mode is named on the privacy page, and third-party models are labeled as an anonymizing proxy rather than as private from the lab that runs them.
  • Pricing: Free, then Pro $18/month, Pro Plus $68/month, Max $200/month.
  • Best for: Confidential drafts when you can stay on a Venice-hosted private model.

Private mode depends on Venice and its partners honoring the no-storage contract, which is a weaker check than TEE attestation on the hardware. Venice does not advertise SOC 2, HIPAA, ISO 27001, PCI, or FedRAMP. If a customer contract requires one of those reports, Venice will not satisfy it.

2. Anthropic API

Anthropic's consumer training choice does not apply to the API. Commercial products are excluded from that training policy by default, and that covers the API, Claude for Work, and Claude Gov. You are still sending the document to Anthropic, so the API is the right pick when the answer has to come from Claude and your team can accept that Anthropic processes the text.

  • What it does differently: Training exclusion is a commercial default rather than a consumer toggle you might forget.
  • Pricing: Claude Pro for the consumer app is $20/month, or about $17/month billed annually, and API use is separate at Anthropic's token rates. On Venice, Claude Opus 5 is listed at $6 per 1M input tokens and $30 per 1M output tokens, and that Venice path is still Anonymous, so Anthropic receives the content.
  • Best for: Teams that want Claude under a commercial training exclusion and do not need a no-storage host.

3. OpenRouter

OpenRouter does not store prompts or completions by default. It does keep request metadata such as token counts, latency, model, and timestamps. Prompt logging is opt-in, as OpenRouter describes in its data collection guide, and the upstream provider still receives the prompt, so your effective privacy is OpenRouter's setting plus the policy of the lab you selected.

  • What it does differently: One API key reaches many models, with a documented default of not keeping the prompt text.
  • Pricing: Free includes 25+ models and 50 requests a day, and pay as you go bills provider rates with no markup. Card credit purchases add a 5.5% fee with an $0.80 minimum, while crypto top-ups are 5%.
  • Best for: Developers who will read the upstream privacy policy for the specific model ID they call.

OpenRouter is not a substitute for Venice E2EE, because the lab running the model can still read the prompt.

Is it safe to use ChatGPT for confidential documents?

Not as a default. Free-tier ChatGPT trains on conversations unless you opt out, and the chats stay attached to your account. If you keep using it, opt out, redact identifiers, and move anything you cannot afford to share to a host with a no-training rule and a clear storage rule. For most people that host is Venice Private mode, and you can read about the API version of this in LLM APIs for private document processing.

Does opting out of ChatGPT training make it private?

It stops the free-tier training use that OpenAI documents, but it does not encrypt the prompt so that OpenAI cannot process it, and it does not move history onto your device alone. The opt-out is a necessary setting change rather than a privacy guarantee, and once it is done you still have to decide whether an account-based product is acceptable for the file in front of you.

Will Claude keep my confidential chat if I opt out?

If you opt out of training on Claude Free, Pro, or Max, Anthropic's standard retention for that choice is 30 days, while opting in extends it to 5 years. Safety-flagged chats may still be used for training even if you opted out. The API sits outside that consumer policy by default, though Anthropic still receives API inputs. Neither choice matches Venice Private mode, where the prompt and response are not stored.

Is there a free way to run confidential prompts?

Venice's free tier includes 10 text prompts a day on base models, including the default Kimi K2.5, which does not log conversations. That is enough to test a redacted clause, though it is a small daily cap for a full contract review. Pro at $18/month removes the text cap and adds TEE and E2EE. OpenRouter's free tier is 50 requests a day across 25+ models, with the upstream lab still receiving the prompt.

Can I keep using ChatGPT if I never paste the secret parts?

Yes, ChatGPT is fine for public research, approved copy, and coding questions that never include a private repository. It is not fine if a confidential contract, client email, or unpublished source file gets pasted into that same chat later. Use a different tool when the model needs the original file. If a short redacted excerpt is enough, turn training off and strip names before you paste.

What should I use for private document analysis?

Use Venice when the file should not be stored or used for training, and keep the model on Private or Pro TEE if you are uploading. E2EE applies to text you paste rather than to PDFs, and there is a longer walkthrough of the document workflow in private AI document analysis. Use the Anthropic API when Claude is the requirement and a commercial training exclusion is all your team needs.

If the next file is confidential, opt out of ChatGPT training, then run the text on a Private model at venice.ai/chat. If you need a mode where the response comes with an attestation report you can check, Pro E2EE does that, within the text-only limits described above.

Back to all posts