
Start here
Before pasting a client's details, a colleague's message, a password or a page from a contract into a chat window, the practical question is not whether the assistant seems trustworthy in general, but what its own documentation and the relevant regulator guidance say happens to that text afterward. The UK's data protection regulator maintains guidance on applying data protection law to AI systems, aimed at organisations that must account for personal data wherever it goes, including into an AI product.
What the documents say
OpenAI's help center states that content sent to consumer products such as ChatGPT may be used to train its models unless a person opts out through 'Improve the model for everyone' in Settings, or the separate privacy portal option. Even after opting out, the same page notes a conversation attached to a thumbs up or down rating can still be used, since feedback is handled separately from the general training toggle. Separately, the UK's National Cyber Security Centre, writing for organisations building products on large language models, documents a limitation worth knowing before pasting anything sensitive: its blog post states that 'research is suggesting that an LLM inherently cannot distinguish between an instruction and data provided to help complete the instruction.' Pasted content becomes part of the same undifferentiated context the model reasons over, with no guaranteed internal wall between an instruction and the material fed into it.
Check this
This is an editorial checklist built from the documents above. Before pasting, ask whether the text names another person who has not agreed to it being processed this way. Check the account's current data-use setting, since a business or enterprise tier can carry different rules than a personal one, as OpenAI's page notes. Ask whether the material sits under a contract, a non-disclosure agreement or a confidentiality duty that pasting would break, regardless of what any setting does.
What holds and what fails
Turning off a training toggle changes what is used to update a model; it does not retract text once sent, delete it from every log, or guarantee no one reviews it. The check holds for reducing avoidable exposure; it fails for anyone who treats an opt-out as secrecy. This is an editorial reading of the cited pages, not legal advice about a specific document or dispute.
- Check the account's data-use setting before pasting anything you would not want reused.
- Redact names and identifying details from other people's messages before pasting them in.
- Treat anything under a confidentiality duty as off-limits regardless of the setting.
A setting only ever controls what happens next, not what has already been sent.
Sources & reading trail
Regulator hub page directing organisations to detailed UK GDPR guidance on personal data in AI systems.
Source published: Not established · Retrieved: 16 September 2026
States the training opt-out setting and that feedback-attached conversations may still be used regardless of it.
Source published: Not established · Retrieved: 16 September 2026
States that an LLM cannot reliably distinguish an instruction from the data provided alongside it.
Source published: Not established · Retrieved: 16 September 2026
Documentation, regulator guidance and studies establish the record; the checks and the boundary are AI Use Field Guide editorial analysis. This retrospective draft does not imply the site published on the event date.