Safe: Drafting emails, summarising public information, creating meeting agendas.
Use Caution: Internal business information, project documentation, customer communications.
Do Not Upload: Credentials, personal information, financial records, health information, confidential contracts, or regulated data.
1. Use the Right ChatGPT Subscription
Recommended order of preference:
✅ ChatGPT Enterprise
✅ ChatGPT Team
✅ Microsoft 365 Copilot
⚠️ ChatGPT Plus (personal use only)
❌ ChatGPT Free for business data
2. Disable Model Training
Settings → Data Controls → Improve the model for everyone → OFF
This prevents future conversations from being used to improve OpenAI's models.
3. Use Temporary Chat for Sensitive Work
For:
- Customer information
- Financial information
- Security investigations
- Contract reviews
- Internal business discussions
Use Temporary Chat.
Temporary chats are not saved in history, do not create memories, and are not used for model training.
4. Disable Memory
Settings → Personalization → Memory → OFF
Memory can retain details across conversations, which is generally undesirable for business use.
5. Delete Existing Memories
Review and remove any existing memories that may contain:
- Customer details
- Project information
- Internal business discussions
6. Enable Multi-Factor Authentication (MFA)
Settings → Security → Multi-Factor Authentication
Protects access to:
- Chat history
- Uploaded files
- Saved memories
- Connected apps
7. Review Connected Applications
Check any connected:
- OneDrive accounts
- Google Drive accounts
- Calendars
- Third-party integrations
Remove anything not required.
8. Remove Old Shared Conversation Links
Settings → Data Controls → Manage Shared Links
Delete links that no longer need to be accessible.
9. Regularly Delete Old Chats
At least quarterly:
- Delete customer-related discussions
- Delete old project discussions
- Delete sensitive business conversations
10. Never Enter Restricted Information
Even with all privacy settings configured correctly:
Do Not Enter:
- Passwords
- MFA codes
- API keys
- Encryption keys
- Bank account details
- Credit card numbers
- Medical records
- Passport details
- Customer databases
- Legal privileged information
Use placeholders and redacted data instead.