Not private the way most people mean it, and hiding them is the wrong control to reach for. A chat you delete is not a chat that never happened, and a chat none of your staff can see is not a chat nobody can read.
The useful version of this question is not whether to hide anything. It is knowing exactly who can already read a work chat, because there are three of them, they are governed by three different mechanisms, and the setting most owners reach for first only touches one.
Reader one: the vendor, deciding whether to learn from your words
On the consumer ChatGPT tiers, this is on by default. The plan comparison table lists “Content is used to train our models” against Free, Go at 8 dollars a month, Plus at 20 dollars a month and Pro from 100 dollars a month, with “Opt-out available” on each (chatgpt.com/pricing). Default on, switchable off, and the switch is one screen: Settings, then Data Controls, then turn off “Improve the model for everyone.” OpenAI is specific about what that does and does not change: “Your conversations will still appear in your chat history but won’t be used to train ChatGPT” (help.openai.com).
Google states the human part more plainly than most owners expect. For Gemini, “A subset of chats are reviewed by human reviewers (including Google’s trained service providers) to help improve Google services,” and the instruction that follows is unambiguous: “Please don’t enter confidential information that you wouldn’t want a reviewer to see or Google to use to improve our services.” Gemini Apps Activity keeps that history on an 18-month default, which you can change to 3 months, 36 months, or indefinite (support.google.com).
Anthropic’s consumer default is the narrowest of the three. It says it will use your chats to improve its models if you choose to allow it, if a conversation is flagged for safety review, or if you otherwise explicitly opt in, and that “Your Incognito chats are not used to improve Claude, even if you have enabled Model Improvement” (privacy.claude.com).
Three vendors, three different defaults. That is the first reason a blanket staff rule like “do not put anything sensitive in AI” tends to fail: it is a rule about behavior when the actual variable is which account the behavior happens in.
Reader two: you, if you pay the bill
This is the reader almost nobody asking this question has counted, and it applies specifically to the plan sold to small businesses. On ChatGPT Business, OpenAI’s enterprise privacy page states that “Workspace admins have control over workspaces and can view, access, export, and delete end user conversations in the workspace” (openai.com).
That is a documented administrative feature, not a leak, and it is the honest trade for the protections that come with a business workspace. But it inverts the question. At a company on ChatGPT Business, the person wondering whether to hide their chats is frequently the same person with the ability to read everyone else’s. If you are the owner, you are not only exposed to this reader, you are this reader.
Reader three: a court, and why “delete” is a conditional promise
OpenAI’s retention commitment for its business workspaces carries a clause worth reading slowly: deleted conversations are removed from its systems within 30 days, “unless we are legally required to retain them” (openai.com).
That clause is not theoretical. It has already been triggered once, in public, and the episode is the most useful thing an owner can know about AI chat privacy. During the New York Times copyright litigation, OpenAI was placed under a preservation order covering consumer ChatGPT and API content, including chats users had already deleted. By OpenAI’s own account the obligation ended on September 26, 2025, after which it returned to standard practice, with deleted conversations and Temporary Chats automatically deleted within 30 days (openai.com).
Two details in that account matter more than the headline did.
The first is where the protective line actually fell. OpenAI listed the affected users as anyone with “a ChatGPT Free, Plus, Pro, and Team subscription or if you use the OpenAI API (without a Zero Data Retention agreement),” and stated that the order “does not impact ChatGPT Enterprise or ChatGPT Edu customers” (openai.com). Read that list again. Paying did not put you outside it. A paid team subscription was inside the order; the excluded tiers sat further up the stack. The boundary that mattered was contractual tier, not whether money changed hands.
The second is that it is not entirely finished. OpenAI says the Times “continues to demand that OpenAI keep a specific set of user data from April-September 2025,” which it stores in locked-down form, “accessible only to a small, audited OpenAI legal and security team” (openai.com).
So deletion is a genuine control against reader one and reader two. Against reader three it is a request that a court can suspend, across a window nobody knew was a window while they were typing in it. That is the real answer to “should you hide your chats.” Hiding is a control you apply after the fact to a record you do not fully govern. The controls that work are the ones applied before.
Four moves that actually change your exposure
1. Decide which account each kind of work happens in, and write the split down. Not a list of forbidden topics, which nobody can apply consistently under time pressure, but a split by account: client names, contracts, financials, employee matters and anything covered by a customer agreement go in the business workspace, and everything else can go anywhere. This is the one move that changes all three readers at once, because the tier sets the training default, the admin visibility and the retention terms together.
2. Turn off the training toggle on every consumer account your team already uses. Settings, Data Controls, “Improve the model for everyone,” off (help.openai.com). For Gemini, set the Gemini Apps Activity auto-delete window down from its 18-month default (support.google.com). Do this even after you move to a business plan, because personal accounts do not disappear when a company plan arrives.
3. Use Temporary Chat for one-off sensitive questions. OpenAI’s terms for it are specific: Temporary Chats “are deleted from our systems after 30 days,” are not used to train the models, “may be reviewed only to monitor for abuse,” and do not get saved in history or create memories (help.openai.com). Claude’s Incognito chats serve the same purpose (privacy.claude.com).
4. Tell your team what an admin can see, before they find out on their own. If you move to a business workspace, say plainly that conversations in it are visible to the workspace admin. An owner who skips this conversation does not get privacy for their staff, they get staff quietly using personal accounts for anything they would rather not have read, which puts the most sensitive work back on the tier with training on by default and no contractual protection. The disclosure is what makes the workspace work.
What it costs to move the line
The business tiers are the only place the contractual language changes, and the premium over a consumer seat is smaller than most owners assume. On ChatGPT the annual business rate matches the Plus rate exactly, at 20 dollars per user per month, so a two-person team pays the same 40 dollars either way and the difference is entirely in the terms.
ChatGPT Business is 20 dollars per user per month for 2 or more users billed annually, or 25 dollars per user per month billed monthly, and the plan page states directly: “No training on your business data by default” (chatgpt.com/pricing). OpenAI’s enterprise privacy page repeats the commitment across its business products: “By default, we do not use your business data for training our models” (openai.com).
Claude Team is 20 dollars per seat per month billed annually or 25 dollars billed monthly, for teams of 2 to 150, against Claude Pro at 17 dollars per month annually or 20 dollars monthly (claude.com/pricing).
Google Workspace Business Standard lists at 14 dollars per user per month, currently discounted to 7 dollars per user per month through November 14, 2026, with Gemini included across Docs, Sheets, Slides, Drive, Meet and Chat (workspace.google.com). Its service terms carry the commitment in contract language rather than policy language, which is a meaningful difference: “Google will not use Customer Data to train or fine-tune any of its generative artificial intelligence models supporting the Google Workspace Generative AI Services without Customer’s prior permission or instruction” (workspace.google.com).
If you are weighing how much access to hand any of these tools in the first place, the same logic applies further up the chain, and it is worth running through three questions to ask before giving any AI tool more access. Separately, the rules that already govern how you use AI with customers and job applicants are a different problem from privacy and are covered in this guide to AI ethics and regulations for businesses.
What a chat policy should not turn into
Everything above this heading is documented fact. What follows is the part I would argue for hardest, and it is judgment rather than finding. There is a version of all of it that goes wrong, and it goes wrong in a predictable direction: an owner reads that workspace admins can view, export and delete employee conversations, and treats that capability as a monitoring tool rather than an administrative one.
That trade is bad on its own terms, before it is bad on any other. The value of a shared workspace is that people stop being careful in the wrong way: they paste in the real contract, the real numbers, the actual awkward customer email, and get an answer worth having. A team that believes its drafts are being read produces sanitized prompts, and sanitized prompts produce useless output, which is a slower and more expensive way of not having the tool at all. The capability exists so that a business owns its records when someone leaves. Say that is what it is for, and then use it for that. A team that knows exactly what is visible is a team that can use the thing properly, which is the entire point of paying for it. If output quality is the problem you are actually trying to fix, that is a prompting question, and a master prompt template will do more for it than any policy.
The practical close: open your billing page and find out which account your team is actually typing into today, because on most small teams it is not the one the owner assumes. Then fix the tier before you fix anyone’s habits.
Frequently asked questions
Are my ChatGPT chats used to train the model?
On the consumer tiers, yes by default. The plan comparison lists “Content is used to train our models” with “Opt-out available” for Free, Go, Plus and Pro (chatgpt.com/pricing). You turn it off under Settings, Data Controls, “Improve the model for everyone” (help.openai.com). On ChatGPT Business the default is reversed: “No training on your business data by default” (chatgpt.com/pricing).
Does deleting a chat actually delete it?
Under normal conditions yes, within 30 days. The exception is written into the commitment itself: deleted conversations are removed within 30 days “unless we are legally required to retain them” (openai.com). That exception was live during the New York Times litigation, when a preservation order covered even deleted consumer chats until the obligation ended on September 26, 2025 (openai.com).
Can my employer read what I typed into ChatGPT at work?
On ChatGPT Business, yes. OpenAI states that “Workspace admins have control over workspaces and can view, access, export, and delete end user conversations in the workspace” (openai.com). A personal consumer account has no workspace admin above it, so no equivalent employer access exists there, which is exactly why unclear policies push sensitive work onto personal accounts.
Is paying for a plan enough to keep business data out of training?
No, it depends which paid plan. Plus and Pro are consumer tiers and train by default unless you opt out (chatgpt.com/pricing). The preservation order made the same point about retention: it covered “ChatGPT Free, Plus, Pro, and Team” subscriptions while excluding Enterprise and Edu (openai.com). What changes the terms is the business or enterprise tier, not the fact of payment.
