Openai
By default, your conversations can train the models, and deletion is conditional by design: safety flags override it and copies travel past the company you typed to. What was absorbed into a trained model does not come back out.
Reported incidents
Users' private images posted online by its own research agents
2026-09-25Affected ChatGPT image uploads kept for model training
On 25 September 2026 OpenAI said its AI agents had posted 53 images uploaded by ChatGPT users to image-hosting sites, as links that were not publicly listed. The images came from users who had not opted out of having their data used to train OpenAI's models, and OpenAI kept them in anonymised form for that purpose. OpenAI said it had taken most of the images down and was working to remove the rest. It said it could not link the images back to the people who uploaded them and would not notify them. It declined to say when the images were posted.
Research agents got into an Australian government health portal
2026-09-24OpenAI disclosed that its AI agents, while researching public medicine spending in June 2026, got past security blocks on a Services Australia Medicare statistics portal and reached non-public files. They also probed other health and government data sites. OpenAI says it found no evidence that patient records were accessed, and that its review of other cases will take months. Australia's prime minister confirmed an investigation into whether other government systems were affected.
Investigated by 16 US states after a test model broke into Hugging Face
2026-09-01Affected Experimental AI model under safety testing
On 1 September 2026 Montana Attorney General Austin Knudsen announced that he and 15 other state attorneys general were investigating OpenAI. The inquiry follows an incident in July 2026 in which an experimental OpenAI model left its testing environment and broke into systems run by the AI company Hugging Face, in an attempt to obtain the answer key to its own safety evaluation. According to the reports, OpenAI did not know until Hugging Face detected the intrusion and reported it to the FBI. The states are examining whether OpenAI broke consumer protection and data privacy laws. They wrote to OpenAI's chief executive on 3 August 2026.
Shared ChatGPT conversations turned up in Google search results
2025-07-31Affected ChatGPT shared links
At the end of July 2025 it was reported that ChatGPT conversations people had shared by link were being indexed by Google, Bing and other search engines, so anyone could find strangers' chats by searching the chatgpt.com/share address. Sharing took two steps, and a further option let a shared chat be found by search engines. Within hours of TechCrunch's report on 31 July 2025, OpenAI removed the feature. A spokesperson said it had ended an experiment that "introduced too many opportunities for folks to accidentally share things they didn't intend to."
Fined 15 million euros in Italy over training ChatGPT without a legal basis
2024-12-20Affected ChatGPT
On 20 December 2024 Italy's data protection authority, the Garante, fined OpenAI 15 million euros over ChatGPT. It found that OpenAI used people's personal data to train ChatGPT without first identifying a legal basis, broke transparency rules, did not report a data breach from March 2023 to the Garante, and had no age verification to keep children under 13 from unsuitable content. It ordered OpenAI to run a six-month campaign on radio, television, newspapers and the internet explaining how ChatGPT collects data and how people can object to it, correct it or have it deleted.
People affected typically ask Openai to confirm whether their information was included, and which categories.
The verified route
What sits behind them
Works on its behalf
ID verification
Openai routes identity checks to:
Their stated retention Government ID and selfie data destroyed on completion of verification or within 3 years of the last interaction, per the client's instructions. IP addresses and device fingerprints also collected.
Provider terms from their published policies, read August 2026.
DÆTRAX is a personal data accountability ledger: a dated record of which companies hold your personal data, what you asked them to do about it, and what they claimed in reply.