You drag a PDF into ChatGPT, get your summary, and move on with your day. That file, though, didn’t vanish. On a standard personal account it sits in OpenAI’s systems long after the chat is gone, and if you’re on a free or Plus plan, its contents can even train future versions of the model. There’s a short list of files you should never upload to ChatGPT, and most people break at least three of these rules every week.
Your file outlives the chat
Deleting a conversation feels like deleting the evidence. It isn’t.
OpenAI’s own retention policy says files tied to a chat stick around for as long as the chat exists, and even after you delete the conversation, the file can stay in their systems for up to 30 days before it’s purged. Meanwhile, anything you paste or upload can be reviewed and used to improve the model on consumer plans unless you switch it off yourself.
The table below shows how the plans actually differ, because the differences matter:
| Plan | Trains on your uploads? | What happens to files |
|---|---|---|
| Free and Plus | Yes, by default | File lives with the chat, purged up to 30 days after deletion |
| Temporary chat | No | Conversation and files auto-delete within 30 days |
| Business and Enterprise | No, excluded by default | Conversation files expire in hours, library files persist |
There’s one more wrinkle from the weird side of legal history. During the New York Times’ copyright case against OpenAI, a court order forced the company to preserve chat logs and uploads indefinitely for a stretch of 2025. The normal deletion cycle came back later, but the lesson stuck around: “deleted” is a promise about the future, not a guarantee about copies that already exist.
The files that should stay on your device
Some uploads are just asymmetric bets. You get a mildly better answer, and you hand over the keys to your life. Here’s the short list of files to never upload to ChatGPT, no matter how good the answer sounds.
Tax returns. A single return bundles your Social Security number, your income, and your bank routing details into one convenient package. That’s the jackpot file in any data exposure, and there’s no tax question a chatbot can answer that justifies it.
Medical records and lab results. Consumer chatbots aren’t built or certified to handle protected health information. We’ve written before about using AI for medical advice safely, and the summary version is: describe symptoms in your own words, keep the paperwork out of it.
Scanned IDs. A passport or driver’s license photo is enough for someone to open credit in your name. Nothing you need from ChatGPT requires it.
Passwords, API keys, and one-time codes. There is no scenario where a chatbot needs your login secrets. If you’re pasting an error message that includes a key, stop and swap in a placeholder first. Rotate anything you’ve already exposed, because chat logs leak in breaches more often than anyone likes to admit.
Work files are a bigger risk than personal ones
Your own tax return burns you. Your company’s roadmap burns you and everyone who works with you.
Contracts under NDA, internal strategy decks, client lists, unreleased pricing: uploading them can breach confidentiality agreements even when you personally have every right to read them. NDAs sit at the top of the list of work documents to never upload to ChatGPT, because breaking one isn’t a privacy oops, it’s a contract violation with your name on it. The numbers on this are worse than most people guess. One industry study found roughly 11% to 12% of everything employees paste into ChatGPT is confidential business information, and separate research flagged sensitive data in more than 20% of files uploaded across AI tools.
Here’s the test I use before any work upload. If the file names a client, a coworker, or a dollar figure that isn’t mine, it doesn’t go in. My curiosity about a faster summary is not worth a conversation with legal.
Metadata leaks too
Even harmless-looking files carry stowaways. And metadata doesn’t change what you should never upload to ChatGPT, but it changes why, because it exposes other people, not just you.
Word documents hold onto author names, tracked changes, and comment threads unless you strip them. Phone photos embed GPS coordinates that show exactly where the picture was taken. Spreadsheets hide tabs nobody remembers creating, and a sloppy scan can catch someone else’s account number in the corner.
The fix is boring and effective. Before uploading anything, strip the metadata, crop the scan, and check for hidden sheets. Two minutes of cleanup beats a year of worrying.
How to keep using ChatGPT without the risk
Good news: you don’t have to quit the tool. You just need three habits, and together they cover most of what people never think to check before they upload files to ChatGPT.
First, redact before you upload. Replace real names, account numbers, and addresses with placeholders like [CLIENT A]. The model summarizes just as well, and the sensitive part never leaves your device. This is the single highest-value habit on this page.
Second, flip the training switch. Open Settings, go to Data Controls, and turn off “Improve the model for everyone.” Your uploads stop feeding future models. Retention doesn’t change, so pair this with the next one.
Third, use temporary chats for anything touchy. Temporary conversations aren’t used for training and auto-delete within 30 days. For business users, the workspace tiers exclude your data from training by default and give you tighter retention controls, which is why companies that care about this stuff buy seats instead of hoping for the best.
If you’re watching costs, note that OpenAI paused new Pro sign-ups recently while demand caught up, so the Business upgrade conversation can wait a week without the sky falling. And if the local-AI route interests you, our look at Gemini Nano’s 4 GB arrival in Chrome shows where on-device models are heading.
The takeaway
Knowing what to never upload to ChatGPT is most of the battle. The tool is a workhorse, not a vault. Run every upload through the same gut check you’d use before emailing a stranger, redact what doesn’t need to be there, and keep tax documents, medical records, and IDs on your own machine.
Do that, and you get the speed of AI document work without handing over the parts of your life that can’t be un-leaked.
For OpenAI’s official retention details, see the ChatGPT chat and file retention policy on their help center.