Citenook

Blog · Privacy

Is it safe to paste client files into ChatGPT?

Pasting client files into the free or Plus version of ChatGPT is risky: by default, what you paste can be used to train OpenAI's models, people may review it, and professional bodies warn against it without client consent. Safer options are a business plan with a data contract, turning training off and removing names, or keeping the files on your own computer and only sending short passages, or nothing at all.

This post explains what happens to what you paste in ChatGPT, Claude and Gemini, what lawyers' and accountants' bodies say, and a checklist for using AI with client work. The company policies were checked on 6 October 2026, on each company's own pages. This isn't legal advice; check your own rules and client agreements.

What happens to what you paste

It depends on the product and the plan, not just the company:

ProductUsed for training by default?How long it's kept
ChatGPT Free, Go, Plus, ProYes, until you turn off "Improve the model for everyone"Until you delete it; then within 30 days, unless kept for legal or safety reasons
ChatGPT Temporary ChatNoUp to 30 days
ChatGPT Business, Enterprise, EduNoSet by your admin
OpenAI API (your own key)NoAbuse-monitoring logs up to 30 days
Claude Free, Pro, MaxOnly if "Help improve our AI models" is onWithin 30 days of deleting; up to 5 years if training is on
Claude Team, Enterprise, APINoAPI data deleted within 30 days
Gemini app, personal accountYes, with Keep Activity on (the default for adults)18 months by default; chats reviewed by people up to 3 years
Gemini with a Workspace accountNoSet by your admin

The pattern is clear: consumer plans are the risky ones. Business plans and the API don't train on your data by default, and they come with contracts.

Four things that are easy to miss

  • Rating a reply can share the whole chat. On ChatGPT, a thumbs up or down can send that conversation for training even if you turned training off. Claude keeps rated chats for up to 5 years.
  • People may read your chats. OpenAI says its staff and outside contractors can review conversations, including on business plans and the API when checking for abuse. Google says human reviewers, including service providers, read some Gemini chats.
  • Deleting a chat may not delete the file. In ChatGPT, a file saved to your Library stays there when you delete the chat it came from.
  • The companies warn you themselves. OpenAI's help center says: "Please do not enter sensitive information that you would not want reviewed or used." Google and Anthropic give similar warnings.

Deletion policies can be overridden by courts. In the New York Times lawsuit against OpenAI, a court order made OpenAI keep consumer chats it would otherwise have deleted. That order ended on 26 September 2025, but OpenAI says it still holds some consumer data from April to September 2025 under a legal hold. On 5 January 2026, the court upheld an order for OpenAI to hand over 20 million de-identified consumer chats from December 2022 to November 2024. For confidential work, the lesson is that "deleted within 30 days" is a policy, not a promise that holds in every case.

What professional bodies say

  • Lawyers (US): the American Bar Association's Formal Opinion 512 (July 2024) says that before entering client information into an AI tool that may reuse it, a lawyer needs the client's informed consent, and that boilerplate in an engagement letter isn't enough. It also says lawyers should read the tool's terms and privacy policy.
  • Accountants (UK): the ICAEW warns that putting client data of any kind into tools like ChatGPT is a potential breach of confidentiality.
  • Personal data (UK GDPR): the UK ICO says sharing personal data with a service that processes it for you needs a written contract. OpenAI offers its data processing agreement for Business, Enterprise and the API, not for consumer plans.

Rules differ by country and profession. If yours has published guidance on AI, it applies first.

A safer checklist for client files

  1. Check your client agreement and rules first. Some clients forbid AI tools; some professions need consent.
  2. Don't use a consumer chat for client work. Use a business plan or the API, which don't train on your data by default and offer a data processing agreement.
  3. If you must use a consumer plan, turn off training, use Temporary Chat, and don't rate replies.
  4. Remove names and numbers. Replace client names, emails, phone and ID numbers before pasting.
  5. Send the passage, not the file. Paste the paragraph you need, not the whole contract.
  6. Keep files on your computer when you can. Tools that read files locally, with a model on your computer, send nothing at all.

Where Citenook fits

Citenook was built for this problem. It reads and searches your files on your Mac, and you choose what writes the answer, one chat at a time:

  • A model on your Mac, like Apple Intelligence or a downloaded model: nothing leaves your Mac, even with Wi-Fi off.
  • An online AI with your own key: only your question and the passages picked for that answer are sent, never whole files or file names. Names, emails, phone and ID numbers are hidden first, and you can preview exactly what goes. Because it uses your own API key, the provider's API terms apply. OpenAI's and Anthropic's APIs don't train on your data by default; check the terms of any other service you use.
A Citenook answer with numbered sources and the source sentence highlighted in a made-up contract.
Answers show the exact sentence they came from. Made-up sample contract.

It doesn't replace your judgment or your rules: with an online AI, check that your clients and profession allow it. See privacy and security for every detail of what goes where.

Questions

Does ChatGPT train on what I paste?

On Free, Go, Plus and Pro, yes by default, until you turn off "Improve the model for everyone" in its data controls. Business, Enterprise, Edu and the API don't train on your data by default.

Is ChatGPT Temporary Chat safe for client files?

Temporary Chats aren't used for training and are kept up to 30 days. They're still sent to and stored by OpenAI for that time, so professional rules on confidentiality still apply.

Is Claude safer than ChatGPT?

On consumer plans, Claude only trains on chats if "Help improve our AI models" is on, but keeps them up to 5 years when it is. On business plans and the API, neither trains on your data by default. The plan matters more than the brand.

Can I use AI with client files at all?

Often yes, with the right setup: client consent where needed, a business plan or API with a data agreement, names removed, or files kept on your own computer with a local model. Check your profession's guidance.

Sources, checked 6 October 2026: OpenAI model training, data controls, chat and file retention, consumer services, enterprise privacy, API data, NYT data demands, court order, 5 January 2026; Anthropic training, retention, business plans; Google Gemini Apps privacy, Workspace privacy hub; ABA Formal Opinion 512; ICAEW AI tools guidance; UK ICO controller and processor contracts.

Try it on your own files.

Every feature free for 30 days. No card needed.