Can I Use ChatGPT for My Business? What’s Safe to Paste and What Isn’t
Revised August 22, 2026
What happens if I put confidential information into ChatGPT?
Nothing visible happens, and that is exactly the problem. On a free or personal paid account, the text is stored in your chat history, and unless you have turned training off, OpenAI states it may use that content to improve its models. It is not published, and no stranger can search it. But you have handed a third party information you may have promised someone else you would keep.
Keep reading ↓Imagine it’s a Wednesday afternoon and you’re parked outside a job in Brentwood with forty minutes before your next call. A proposal is due by five. You open the chat app on your phone and paste in the customer’s name, their address, the scope you sketched on the back of an invoice, and the price you landed on. Twenty seconds later you have a clean, professional document. It reads better than anything you have sent this year.
Maybe you’ve done a version of that. Maybe your office manager in Hazelwood has, or your bookkeeper who works from home in Collinsville and has been quietly running your collections letters through the same free tool since spring. Nobody did anything reckless. Everybody was busy.
And somewhere around the third or fourth time, the question shows up: was that okay? That is the question most owners ask third, after “does it work” and “what does it cost.” It should be first, and the good news is that it has an answer. Not a lawyer’s answer. A practical one, made of published policies you can read yourself and four settings screens you can fix in ten minutes.
What happens if I put confidential information into ChatGPT?
Nothing visible happens, and that is exactly the problem. On a free or personal paid account, the text is stored in your chat history, and unless you have turned training off, OpenAI states it may use that content to improve its models. It is not published, and no stranger can search it. But you have handed a third party information you may have promised someone else you would keep.
So the real damage is almost never the dramatic version people picture. Your customer list does not pop out of the machine in front of a competitor. The damage is quieter and more ordinary: you broke a term in a contract you signed, or you moved regulated records to a vendor you have no agreement with, or you now cannot tell a client what happened to their file because you have no record of what went where.
It also is not fully undoable. OpenAI’s own help documentation, updated on August 18, 2026, says a deleted chat is scheduled for permanent deletion from its systems within 30 days, unless it has already been de-identified and disassociated from your account, or unless the company must retain it for security or legal obligations. Read that carefully. Deleting the conversation cleans up your account. It does not reach back into anything already used for training.
None of which means put the phone down. Millions of businesses use these tools daily without incident, and our broader piece on how local businesses can actually use AI covers what they are good for. This one covers where the line sits.
Which tier decides who is allowed to train on what you type?
Consumer tiers and business tiers are two different contracts, not two price points. On consumer tiers, your content may be used to train models unless you opt out. On business tiers, the vendor agrees up front not to train on it at all. Every major provider draws the line in the same place, and each publishes it. Here is what all four say right now.
OpenAI (ChatGPT, Codex)
OpenAI’s help center article on how your data is used to improve model performance, updated August 18, 2026, splits its products in two. For services for individuals such as ChatGPT and Codex: we may use your content to train our models, with an opt-out. For services for businesses: by default, we do not train on any inputs or outputs from our products for business users, including ChatGPT Business, ChatGPT Enterprise, and the API. That is the whole distinction, stated by the vendor, in one page.
Anthropic (Claude)
Anthropic’s consumer article, dated March 16, 2026, says it will use your chats to improve its models if you choose to allow it in Privacy Settings, if a conversation is flagged for safety review, or if you opt in to a program such as its Trusted Tester Program. Incognito chats are excluded even when Model Improvement is switched on. For commercial products the company’s published position is the opposite default: by design it will not use inputs or outputs from Claude for Work or the Anthropic API to train its models.
One detail owners miss: Anthropic states that pressing the thumbs up or thumbs down button stores the entire related conversation in its back end for up to five years. That click is not a small gesture.
Google (Gemini)
Google’s Gemini Apps Privacy Hub is the bluntest of the four. Keep Activity is on by default for users 18 and over, human reviewers read some conversations, and Google tells you in plain words not to enter data that is confidential or that you would not want a reviewer to see. With Keep Activity on, activity older than 18 months is auto-deleted by default and you can change that to 3 months, 36 months, or never. With Keep Activity off, conversations are still held for up to 72 hours so Google can serve the request and process feedback.
Microsoft (Copilot)
Microsoft splits on account type rather than plan name. Signed in with a personal Microsoft account, conversation history is retained 18 months by default and your conversations may be used for model training unless you opt out. Signed in with a work or school account, Microsoft Learn’s enterprise data protection page, last updated August 18, 2026, states that the prompts, responses, and data accessed through Microsoft Graph are not used to train foundation models. Same product name on the icon. Different contract underneath.
Notice what is missing from all four: the personal paid upgrade. Paying for the consumer plan buys you a better model and more capacity. It does not change the data terms by one line. What changes the terms is a workspace or business account with business terms attached to it. If the reason you never moved is that nobody explained that difference, you are the reason this article exists.
What is actually safe to paste, which is more than most owners assume
Almost everything you do in a week is safe to paste. Your own marketing copy, your public pricing, your website text, a job posting with no names in it, a generic warranty letter, your notes turned into a checklist, a rewrite of something you already published, an error message off a piece of software. If you would be comfortable seeing it in your own newsletter, it is fine.
The trick that frees up most of the rest is redaction, and it takes fifteen seconds. The model does not need the customer’s name to write the collections letter, or the address to describe the scope. Swap in Customer A, 1980s ranch, unit is 14 years old, and you get the same output with none of the exposure. Paste the shape of the problem, not the identity attached to it.
What should never go into a consumer chatbot?
Six categories stay off the table on a consumer tier, whether or not you turned training off. Each one carries an obligation that lives with you rather than with the vendor.
- Customer personal data. Names paired with addresses, phone numbers, account numbers, or anything else identifying. A CRM export, a route list, a spreadsheet of past jobs.
- Employee records. Social Security numbers, I-9s, W-4s, background check results, medical leave notes, disciplinary write-ups, and performance reviews with a real name on them.
- Anything under a confidentiality obligation. If you signed an NDA, if a client contract says you will keep their material confidential, or if you are a subcontractor bound by the general contractor’s terms, the obligation follows the document into the chat box.
- Health information. Patient details, treatment notes, injury reports, insurance claim files. This is the category with the sharpest legal edge and the one people paste most casually.
- Payment details. Card numbers, bank account and routing numbers, full merchant statements, a screenshot of a processor dashboard with account data visible.
- Unreleased contracts and bids. The bid you have not submitted, the letter of intent, the lease under negotiation, the pricing you are about to hand a general contractor. Confidential today, public next month, and the gap is exactly when it matters.
If you want the short version to tape to a wall: no names, no numbers that identify a person, no health, no money credentials, nothing somebody else made you promise to protect.
Unrelated, and we know it — if that panel is humming, call an electrician.
If you handle health records, financial files, or client matters, convenience does not move the obligation
The obligation belongs to you, not to the software. A dental office, a home health agency, a chiropractor, a tax preparer, a title company, a lawyer — each of those is already under rules that say what a third party has to sign before it touches the file. A chat box being fast has no effect on any of that. This is not legal advice, and it is not a substitute for asking your own counsel or compliance person. It is a flag that the question exists and that it is yours.
The concrete version, on health information, is a Business Associate Agreement. OpenAI publishes a list of which of its products are HIPAA eligible with a BAA, updated August 18, 2026: ChatGPT for Healthcare, ChatGPT for Enterprise with Regulated Workspace, ChatGPT FedRAMP, ChatGPT for Clinicians, API with Modified Retention, and API FedRAMP with Modified Retention. Look at what is not on that list. ChatGPT Free, Plus, and Pro are not on it. Neither is ChatGPT Business, the self-serve team plan. If you handle protected health information, the plan you almost certainly signed up for is not one of the eligible ones.
Microsoft states its own position in a footnote on the enterprise data protection page updated August 18, 2026: Microsoft Copilot and Copilot Chat support HIPAA compliance for properly configured implementations, and HIPAA compliance does not apply to web search queries, because those queries are not covered by the Data Protection Addendum and BAA. So even inside a compliant deployment, one part of the product sits outside the agreement.
For lawyers on either side of the river, the confidentiality duty is written into the professional conduct rules directly. Missouri Rule 4-1.6 requires a lawyer to make reasonable efforts to prevent inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client. Illinois Rule 1.6 covers the same ground for Illinois lawyers. Neither rule mentions AI, and neither has to. Reasonable efforts is a standard that adapts to whatever tool you just adopted.
The practical takeaway is short. Before the tool touches a regulated record, somebody checks whether a signed agreement covers it. If the answer is no, the record does not go in. That is an afternoon of work once, not every week.
Somebody already pasted something they shouldn’t have. What now?
Start by not panicking and not deleting. The first move is a written record of what actually happened, because every decision after this depends on it. Then work through six steps in order.
- Write down what went in. What text or file, roughly when, from which account, and whose account it was. Personal login or company workspace matters enormously for what comes next.
- Turn training off on that account now. It is forward-looking only — OpenAI states that once you opt out, new conversations will not be used to train its models — but it stops the bleeding while you sort out the rest.
- Delete the conversation, knowing what deletion does. It removes the chat from the account and schedules it for permanent deletion within 30 days, subject to the de-identification and legal-retention exceptions the vendor publishes. It does not unwind training that already happened.
- Decide whether it is reportable, and get help deciding. This is the step with an actual legal answer, and it is not one to settle from a search result. Call your attorney or your cyber liability carrier. Most policies want notice early, and calling does not commit you to filing anything.
- Check your client contracts before you check the statute. If a customer agreement requires notice of a disclosure, that clock is usually shorter than anything the state imposes, and it is the one people forget.
- Tell the person what the line is. They were trying to get work out the door. If nobody had told them where the boundary was, that is a management gap, not a discipline problem.
On that last point: this happens more than owners think, and it usually happens without anybody meaning to hide it. Our companion piece on staff already using AI without the owner knowing covers why, and how to write the one-page policy that prevents the repeat.
Missouri and Illinois do not handle the aftermath the same way
If a disclosure does turn out to be a reportable breach, which state your affected people live in changes the deadline and the threshold. Most St. Louis metro businesses serve both, so both apply.
Missouri, under RSMo 407.1500, requires notice to affected consumers without unreasonable delay. Notify more than one thousand consumers at once and you must also notify the Attorney General’s office and all consumer reporting agencies. Missouri also lets a business conclude notice is not required if, after an appropriate investigation, identity theft or other fraud is not reasonably likely — but that determination must be documented in writing and kept five years.
Illinois, under the Personal Information Protection Act at 815 ILCS 530, requires notice in the most expedient time possible and without unreasonable delay. Notice to the Illinois Attorney General is triggered at more than five hundred Illinois residents, and it must be given within 45 days of discovery or when consumers are notified, whichever comes first.
Illinois sets a shorter fuse and a lower threshold; Missouri sets a documentation duty that runs five years. Whether pasting into an AI tool is a breach under either statute turns on the specific facts, and this article cannot answer that for you. Both states make the same thing obvious: start the paperwork trail on day one rather than reconstruct it in month three.
The settings that actually matter, named, on each major tool
Four screens, ten minutes, no purchase required. These are the current control names as published by each vendor this month.
- ChatGPT. Settings, then Data Controls, then switch off Improve the model for everyone. It syncs across web and mobile on the same account. Separately, Temporary Chat, reachable from the icon at the top right of the chat screen, is not used for training, does not appear in history, does not create memories, and is deleted from OpenAI’s systems after 30 days, though it may be reviewed to monitor for abuse.
- Claude. Privacy Settings, then Model Improvement. Incognito chats are excluded from model improvement even if that setting is on.
- Gemini. Keep Activity. Off means chats are still held about 72 hours. On means an 18-month auto-delete by default, which you can change to 3 months, 36 months, or off entirely.
- Copilot. On copilot.com, the profile icon, then your profile name, then Privacy, then Training on conversation activity and Training on voice conversations. Microsoft shipped an updated Copilot app on August 18, 2026 and moved some of this documentation, so if your app does not look like the screenshots you find, go to Privacy under your profile menu and read what is there.
Two honest caveats. First, opting out is forward-looking on every one of these platforms; it governs what happens next, not what already happened. Second, none of these settings changes what tier you are on. Turning training off on a free account does not give you a business agreement, and it does not give you a BAA.
The related question owners ask is whether moving staff into a workspace lets them read everyone’s chats. Mostly no. OpenAI’s ChatGPT Business documentation, updated August 20, 2026, states that each member has their own chat history and chooses what to share, and that by default admins and owners cannot see all private member chats. Enterprise and Edu workspaces add a Compliance API for retrieval. Worth knowing before you announce the change, because it is the first thing your team will ask.
If reading four vendor policy pages is not how you want to spend a Thursday, that is fair, and it is roughly what the AI workshops for metro business owners exist to shortcut — sitting down with the actual screens instead of a slide about them.
What this looks like from the owner’s side of the counter
Here is why this landed in your office before it landed in your field crew. In a small service business the truck hours are billable and the office hours are not. Estimating, permit paperwork, warranty letters, review replies, the third follow-up on an unpaid invoice — that is real work nobody pays for, and on a two-truck operation it gets absorbed at night by whoever is left. AI ate the unbilled hour first because the unbilled hour is where the pain was.
Seasonality sharpens it. The first genuinely hot week and the first hard freeze are when the phone does not stop, and that is exactly when whoever answers it takes the shortcut. What owners in the trades complain to each other about is not the technology. It is learning something went out wrong only after the customer replied. Operators who avoid that do one unglamorous thing: a human reads anything with a customer name on it before it leaves the building.
The other half of getting found is even less glamorous. People search these trades locally, by name and by neighborhood, and a listing that is complete and current is how they land on you instead of the next result. Getting listed on St Louis Near Me Directory is the low-effort half of that.
Would rather have somebody walk the screens with you? See the AI workshops for business owners across the St. Louis metro on St Louis Near Me Directory, then bring the one document you keep pasting in — the estimate, the collections letter, the review reply — and we will draw the line on that document instead of in the abstract.
Frequently asked questions
Is it worth getting ChatGPT for business?
It depends less on features than on whether your people already use it. If staff are pasting work into personal accounts, a business workspace mostly buys you a contract: OpenAI states it does not train on business workspace data by default. If you use it alone, for marketing copy and nothing sensitive, the free tier with training switched off may be enough.
Can businesses use ChatGPT for free?
Yes. There is no rule against a business using the free tier, and plenty do. What you should know is that free, Plus and Pro are all services for individuals under OpenAI’s own classification, which means your content may be used to train models unless you opt out, and no Business Associate Agreement is available on them. Free is fine for work that carries no confidentiality obligation.
Is it okay to use ChatGPT for a business plan?
For structure, drafting and pressure-testing assumptions, yes, and it is one of the better uses. Two cautions. Keep unreleased financials, a signed letter of intent, and any lender’s confidential terms out of it on a consumer account. And verify every number — it does not know your market, your rents, or local wage rates, and will produce a confident figure anyway.
Which AI is best for small business owners?
There is no credible head-to-head answer, and anyone offering one is usually selling something. Pick on two practical grounds: the data terms you can live with, and what you already pay for. If your business runs on Microsoft 365 work accounts, Copilot already sits inside enterprise data protection. Capability gaps between the leaders shift monthly. Contracts do not.
Does ChatGPT business protect my data?
OpenAI’s documentation, updated August 20, 2026, says ChatGPT Business is governed by OpenAI Business Terms and the Enterprise Privacy commitments, and that it does not train on your workspace data by default. Two limits worth knowing before you rely on it: OpenAI does not offer a Business Associate Agreement for ChatGPT Business, and data export is not available from a Business workspace.
Can companies see what you put into ChatGPT?
The vendor can access content in limited circumstances such as investigating abuse, providing support, or meeting legal obligations, and reviewers may see content flagged for safety. Google puts it more bluntly for Gemini, warning users not to enter data they would not want a reviewer to see. Assume a person could read it, and paste accordingly.
What are five things I should never tell ChatGPT?
Customer personal data, meaning names paired with addresses or account numbers. Employee records, including Social Security numbers and medical leave notes. Anything covered by an NDA or a client confidentiality obligation. Health information about a patient or claimant. Payment credentials such as card and bank routing numbers. A sixth belongs there too: unreleased contracts, bids and pricing.
Can my company see my ChatGPT conversations?
If you are signed in to a personal account you pay for yourself, your employer has no window into it. If you are in a company workspace, OpenAI states that each member has their own chat history and that by default admins and owners cannot see all private member chats. Enterprise and Edu workspaces add a Compliance API that can retrieve conversations for compliance purposes, so treat those as reviewable.
Is ChatGPT secure for business?
Security and confidentiality are different questions and get conflated constantly. Encryption is not where small businesses get hurt. The exposures that matter are contractual: whether your tier permits training on your inputs, how long conversations are retained, and whether an agreement covers regulated records. Answer those three for your tier and you have answered the real question.
Can admins see chats in ChatGPT business?
Not by default. OpenAI’s ChatGPT Business documentation states that each member has their own chat history and can choose what to share, and that by default admins and owners cannot see all private member chats. That is a deliberate design choice, and it is worth telling your team when you move them onto a workspace, because assuming otherwise is the most common reason staff quietly keep using a personal account instead.
