Common Ground
    Submit Experience
    ChatGPT logo

    ChatGPT

    by OpenAI
    Chat/LLMFedRAMP Low AuthorizedPrivacy: Warning rating
    $0

    Free Tier Ratings

    4Safe
    4Caution
    4Risk

    Last Reviewed: 2026-03-23

    GPT-5 access with rate limits. As of Feb 2026, Free users may see ads (testing in US). No nonprofit discount.

    Quick Take

    The most widely used AI assistant, now operating on GPT-5. Privacy practices vary dramatically by tier. Free and Plus users have their data used for training by default (opt-out available), and Free/Go users are subject to an advertising pilot as of February 2026. Business and Enterprise tiers never train on your data. ChatGPT Enterprise and API Platform received FedRAMP 20x Low authorization in early 2026. OpenAI now holds ISO 27001, 27017, 27018, 27701, and 42001 certifications. A 20% nonprofit discount on Business tier ($20/user/month annual) is available via Goodstack verification. HIPAA BAAs are available for ChatGPT Enterprise and ChatGPT for Healthcare (sales-managed) — not for Business tier. Common Sense Media: Warning rating. Ads & Tracking category scored 0% due to unclear policies.

    Ratings by Use Case

    How safe is this tool for your specific work? (Showing Free tier)

    Marketing copy

    Safe

    Public content, low risk even with training enabled.

    Image generation

    Safe

    Image generation included. Generated images are yours to use.

    General research

    Safe

    No sensitive data involved in public research queries.

    Educational content

    Safe

    Safe for public-facing educational materials.

    Grant writing

    Safe with Precautions

    Safe if you disable training in Settings > Data Controls OR use Temporary Chat. Remove identifying details if training is enabled.

    Safe if you disable 'Improve the model for everyone' in Data Controls OR use Temporary Chat

    Donor communications

    Safe with Precautions

    Safe if you disable training OR use Temporary Chat. Never input real donor names or giving amounts.

    Safe if you disable training in Data Controls OR use Temporary Chat

    Board materials

    Safe with Precautions

    Safe if you disable training OR use Temporary Chat. Avoid strategic details if training is enabled.

    Safe if you disable training in Data Controls OR use Temporary Chat

    Meeting summaries

    Not Recommended
    Risk: Meeting content often contains names, decisions, and sensitive discussions. Even with training disabled, 30-day safety retention and potential human review create risks. As of Feb 2026, Free users may also see ads served using in-app context signals.

    Translation

    Safe with Precautions

    Safe if source content contains no PII, or use Temporary Chat mode.

    Safe if you source content contains no PII, or use Temporary Chat

    Program documentation

    Not Recommended
    Risk: Client data should not enter consumer tiers. The 30-day safety retention, potential human review, and as of Feb 2026, ad personalization using in-app context create compliance risks for most nonprofit privacy policies.

    Data analysis

    Not Recommended
    Risk: Constituent data requires the contractual protections of Business or Enterprise tiers. Consumer tiers lack data processing agreements.

    Financial work

    Not Recommended
    Risk: Donor giving history and financial details are sensitive PII that need business-tier protections. Consumer tiers lack DPAs and have 30-day safety retention.

    Policy Snapshot

    As of 2026-03-23
    Data Training

    Yes, by default

    Your conversations train OpenAI models unless you opt out in Data Controls. As of Feb 2026, Free users may also see ads served using in-app context signals (chats and memories if enabled).

    Opt-Out

    Yes

    Settings > Data Controls > 'Improve the model for everyone' toggle. Temporary Chat also prevents saving and training. Ad personalization can be disabled in advertising controls.

    Human Review

    Possible

    OpenAI authorized staff may review conversations for safety, abuse monitoring, and model annotation purposes. Flagged content may be reviewed by human reviewers.

    Retention

    30 days (safety)

    Conversations retained for up to 30 days for safety and abuse monitoring, even if training is disabled or history is off. Temporary Chats are deleted within 30 days.

    Security

    Basic encryption

    Encryption in transit and at rest. SOC 2, ISO, and FedRAMP certifications apply only to Business, Enterprise, and Edu tiers — not consumer tiers.

    This tool's ratings change significantly between tiers.

    Free/Plus/Pro tiers: 4 Red ratings. Business tier: 0 Red ratings.

    Switch tiers above to see the difference.

    Key Distinctions

    Pro tier is NOT a business tier

    Despite costing $200/month, ChatGPT Pro uses consumer data policies. Your conversations can train models unless you opt out. For organizational use with sensitive data, Business tier is required.

    No BAA on Business tier

    OpenAI does not offer Business Associate Agreements for ChatGPT Business. Healthcare nonprofits handling PHI should use ChatGPT Enterprise (sales-managed) or ChatGPT for Healthcare, both of which support HIPAA BAAs.

    30-day safety retention even when opted out

    CRITICAL: Even when you opt out of training, OpenAI retains conversations for up to 30 days for safety monitoring on consumer tiers. This data may be subject to human review for flagged content.

    Temporary Chat as privacy tool

    On consumer tiers, Temporary Chat mode prevents conversations from being saved or used for training. Temporary chats are deleted within 30 days. Useful for occasional sensitive queries when you don't need history.

    Free users now see ads (as of Feb 2026)

    OpenAI began testing ads on Free and Go plans in February 2026. Ads are personalized using in-app context (current conversation and ad interaction history). Ad personalization can be disabled in settings, but ads may still appear. Plus, Pro, Business, Enterprise, and Edu plans are ad-free.

    Recent Changes

    2026-03-18

    GPT-5.4 mini released; model picker simplified to Instant/Thinking/Pro/Auto options for Business, Enterprise, and Edu plans.

    2026-03-05

    GPT-5.4 Thinking released with enhanced reasoning, coding, and agentic capabilities.

    2026-02-09

    Privacy policy updated (effective Feb 9, 2026): Formalized ad program for Free/Go users; ads use in-app context (not conversations shared with advertisers); more specific data retention timelines; added documentation for Atlas, Sora 2, Saved Memories, Temporary Chats, and parental controls. Ad personalization on by default for Free/Go; opt-out available in settings.

    2026-01-20

    Age prediction system rolled out on consumer plans: uses behavioral signals to estimate if an account belongs to a user under 18, for additional safeguards.

    2026-01-08

    OpenAI for Healthcare launched: ChatGPT for Healthcare provides HIPAA-supporting workspace with BAA available (sales-managed), data not used for training, and clinical search capabilities.

    2026-01-07

    ChatGPT Health space launched (web/iOS; US, excluding EEA/Switzerland/UK): connects health records and wellness apps; health data kept separate and not used to train models.

    2025-12-11

    GPT-5.2 released with improved knowledge cutoff (August 2025), enhanced spreadsheet understanding, coding, vision, and reasoning capabilities.

    2025-11-12

    GPT-5.1 released with enhanced steerability, faster responses, and new tone/personality controls (presets + granular settings).

    2025-09-29

    Parental Controls launched: parent-teen account linking with content protections, quiet hours, feature toggles, and model training opt-out control for teens.

    2025-08-25

    ISO/IEC 27001:2022 certificate obtained (plus 27017, 27018, 27701), covering API, ChatGPT Enterprise, and ChatGPT Edu. ISO 42001 (AI Management) also obtained.

    2025-08-07

    GPT-5 released as the new default model for all ChatGPT users. Auto-switching system introduced combining previous models into one smart, fast model.

    2025-07-08

    Flexible credit-based pricing introduced for ChatGPT Business and Enterprise plans: credit pool for advanced models, unlimited core model access retained.

    Bottom Line

    For organizations with 5+ staff

    Apply for OpenAI for Nonprofits for 20% off Business tier ($20/user/month annual). This gets you no-training policies, admin controls, SOC 2 and ISO compliance. Compare to Claude's 75% discount before deciding — OpenAI's ecosystem of connectors and GPT-5 capabilities may justify the cost for some organizations.

    For organizations with fewer than 5 staff

    Business tier minimum is only 2 users, so small teams can qualify. For solo use, Plus with training disabled and Temporary Chat for sensitive work is a reasonable option. Free tier now shows ads (Feb 2026) — Plus eliminates ads and is still $20/month.

    For health data or vulnerable populations

    ChatGPT Business does NOT offer BAAs. Healthcare nonprofits handling PHI should use ChatGPT Enterprise or ChatGPT for Healthcare (both require sales engagement for BAA). Alternatively, Microsoft Azure OpenAI Service offers HIPAA coverage under Microsoft's enterprise BAA with a familiar procurement path.

    From the Community

    No community experiences yet.

    Be the first to share yours →

    Get Alerts for ChatGPT

    We'll notify you when this tool changes their policies.

    Expect updates only when something changes. Unsubscribe anytime.