PrivacyPick
ChatGPT logo

ChatGPT

5.4
out of 10
Visit ChatGPT →
IP AnonymizationUndisclosed
Storage ModelServer-encrypted
RetentionUntil deleted; ~30 days after deletion
Provider TrainingOpt-out by default
JurisdictionUnited States
Free TierLimited free tier
Telemetryalways-on
Established2022
WebWindowsmacOSAndroidiOS
GPT-5.6 LunaGPT-5.6 SolGPT-6 AstraGPT-6 SolGPT-6.1 Sol
Go (individual, monthly)
$6.00/mo
Plus (individual, monthly)
$20.00/mo
Pro (individual, monthly)
$100.00/mo

Published October 1, 2026By Juan Martinez

In This Article

ChatGPT is the product that made consumer AI chat a category, launched by OpenAI on 30 November 2022 and now the default for most people who use an assistant at all. It is reviewed here on the same five criteria as every other assistant in this section, which produces an unusual result: enormous scores on what the product does, low scores on how it handles what you tell it. The core facts are that an account is mandatory, conversations are stored on OpenAI’s servers in a form OpenAI can decrypt, and model training on consumer chats is enabled by default with an opt-out the user has to find. None of that makes ChatGPT a bad product; it makes it a product built for capability first, which is a different thing from the architecture-first designs the rest of this category is built on.

Privacy Architecture

Nothing about ChatGPT works anonymously. An account is required before the first message, which ties every conversation to an email address or a linked identity from the outset. OpenAI’s Privacy Policy lists IP address, browser type and settings, device information, usage data, and location inferred from IP among the data received through normal use, and there is no claim anywhere in the documentation that the IP address is separated from the request before processing. That is a meaningful absence rather than a neutral one: products that do strip identity at a proxy layer say so explicitly and describe the mechanism, because it is the kind of claim worth making.

Conversations are encrypted in transit with TLS 1.2 and at rest with AES-256, according to OpenAI’s own security FAQ. This is standard infrastructure hygiene and it protects against the right things — a stolen disk, a network attacker — but it is not zero-access encryption. OpenAI holds the keys and can read conversation content, which it does for abuse review, for model improvement where training is enabled, and in response to a valid legal demand. The practical distinction matters more than the cryptography does: with zero-access encryption the operator cannot produce plaintext even when compelled, and with server-side encryption the question of who reads your chats is a policy question rather than a mathematical one. ChatGPT is firmly in the second category. There is no trusted-execution or confidential-compute claim for the consumer product.

The training default is the single most consequential setting here. OpenAI’s own help documentation states that for services for individuals — ChatGPT and Codex — it may use your content to train its models, and that opting out means turning off “Improve the model for everyone” under Settings, Data controls, or selecting “Do not train on my content” in the Privacy Portal. The opt-out is real, it is not buried behind a support ticket, and it works. But it is an opt-out, which means the default for every Free, Go, Plus and Pro user is that their conversations are training material until they intervene.

There is a trap inside the opt-out that deserves stating plainly, because it is not obvious. OpenAI documents that even after opting out, choosing to give feedback on a response — the thumbs up and thumbs down buttons sitting under every answer — may result in the entire conversation attached to that feedback being used for training. Those buttons read as a product rating widget, not as a consent mechanism, and a user who has deliberately opted out can re-enter the training set with one click on something that looks like it only expresses an opinion about the answer’s quality.

The contrast with OpenAI’s business tiers is worth laying out because it shows the default is a choice rather than a technical necessity. OpenAI states that by default it does not use inputs or outputs from ChatGPT Business, Enterprise, Edu, or the API to improve its models. The protective default exists, is implemented, and is applied to the customers whose procurement teams negotiate data terms. The individual paying $20 a month, and more pointedly the one paying nothing, gets the opposite default and has to protect themselves by hand.

The data controls that do exist are not nothing, and dismissing them would be unfair. Conversations can be exported and deleted, Memories can be managed and cleared individually, the training toggle is accessible and effective, and Temporary Chat gives a per-conversation mode that is excluded from training, kept out of chat history, and deleted automatically. The caveat on Temporary Chat is that saving one converts it into an ordinary conversation under ordinary settings. These are genuine controls, better than many mainstream services offer. They are also all user-operated, which means they protect the people who already know to look for them.

Trust & Transparency

OpenAI holds a SOC 2 Type 2 report, assessed by an independent third-party auditor against security, confidentiality, privacy and availability criteria, along with ISO/IEC 27001:2022, 27017:2015, 27018:2019 and 27701:2019 certifications. In a category where independent assessment is otherwise close to nonexistent, that is a real distinction and this review credits it as one.

The qualification is about access rather than existence. OpenAI’s Trust Portal is titled as covering its ChatGPT services including Enterprise and Edu, runs on a vendor-security-review platform, and offers the SOC 2 report by request rather than publishing it — in practice, through a sales conversation. A reader on a Plus subscription who wants to check what the auditor actually examined cannot open the report the way they can open a published audit from a privacy-focused vendor. The portal also does not state the report’s period or issue date publicly, so even the recency of the assessment is not externally checkable. The audit is real and the scope statement is credible; it is simply addressed to procurement departments rather than to users.

On incident disclosure the record splits cleanly in two, and the two halves point in opposite directions. The March 2023 Redis bug was handled about as well as an incident of that kind can be: self-detected, service taken offline, affected users notified directly, a detailed public technical write-up within days naming the exact root cause, and a patch contributed upstream to the open-source library at fault. OpenAI wrote that it had fallen short of its users’ expectations and apologised. That is a model response, and it should count in the company’s favour.

The internal forum breach from the same year is a different story. A hacker reached an internal employee messaging system and took details of discussions about the design of OpenAI’s AI technologies. Executives told staff at an April 2023 all-hands and informed the board, then decided not to disclose publicly, reasoning that no customer or partner data was involved, and did not notify the FBI or other law enforcement, having concluded the intruder was a private individual with no foreign-government connection. The public learned about it roughly sixteen months later through investigative reporting. The reasoning for staying quiet is defensible on its own terms — no user data was lost, and there is no legal notification duty for an internal-information breach of that kind. But a company’s disclosure instinct when nothing legally obliges it is precisely the thing a trust rating is trying to measure, and here the instinct was to say nothing until someone else did.

Everything else about the product is closed. Model weights, client code, and server infrastructure are all proprietary, so every privacy claim in this review rests on documentation and attestation rather than on anything inspectable. Jurisdiction is the United States, with OpenAI OpCo, LLC in San Francisco as controller for most of the world and OpenAI Ireland Limited in Dublin as controller for EEA, UK and Swiss users. The Irish arrangement brings those users under GDPR with a European supervisory authority, which is a genuine structural difference and not merely cosmetic. For everyone else, the US sits inside the surveillance-sharing arrangement commonly called the Fourteen Eyes, and unlike a service built around holding nothing, ChatGPT stores conversations it can read — so a legal demand has something substantial to reach.

Security Incident History

Two incidents are confirmed. They are unrelated, differ in severity, and say different things about the company.

The first is the Redis bug of 20 March 2023. A fault in the open-source redis-py client — a race condition in how connections were reused from the pool after a request was cancelled — caused some simultaneously active users to see the titles of other users’ conversations in their sidebar, and in some cases the first message of a newly created conversation. Subsequent investigation found the same bug could have exposed payment-related information belonging to 1.2% of ChatGPT Plus subscribers active during a nine-hour window that day: first and last name, email address, payment address, card type, the last four digits of the card number, and the card expiration date. Full card numbers were never exposed. OpenAI found the problem itself, took ChatGPT offline, notified affected users individually, published a technical post-mortem within days, and sent a patch to the library’s maintainers. For a privacy evaluation, the exposure of chat titles is the more unsettling detail — the titles are generated from conversation content — but the response was fast, complete, and public.

The second is the internal breach described above: in early 2023 an attacker accessed an internal employee messaging system and took details of discussions about the design of OpenAI’s AI technologies from an internal forum. The systems holding and training the models themselves were not reached, and no customer or partner data was taken. OpenAI briefed employees in April 2023 and informed its board, chose not to disclose publicly, and did not contact law enforcement. The incident surfaced sixteen months later in press reporting.

The practical read for a user is narrow and should not be overstated. One incident exposed a small amount of user data for a short window and was handled transparently; the other exposed no user data at all. Neither is a pattern of leaking conversations. What the pair establishes is that OpenAI’s engineering can fail in ways that cross user boundaries, and that its disclosure decisions are discretionary rather than reflexive.

Features

This is where ChatGPT is straightforwardly ahead of everything else in the category, and pretending otherwise would be dishonest. The model lineup spans several generations simultaneously and is gated by tier — at the time of this review that meant a baseline model available free and without a message cap, with more capable reasoning models unlocked on Plus and the newest and heaviest reserved for Pro. OpenAI revises this lineup frequently enough that any specific list is a snapshot rather than a stable fact, but the shape is consistent: free users get a competent general model, and paying users get the current frontier.

Model switching within a conversation is built in, limited only by what the subscription tier exposes. Web search is integrated directly into the chat rather than bolted on. File upload works across documents, images, and data files, with limits that tighten considerably on the free tier. Beyond that core, the surface is unusually large: image generation, voice conversation, deep research runs that compile sourced reports, data analysis with code execution, vision, Projects for grouping related conversations with shared context, scheduled tasks that run on their own, custom GPTs, a desktop browser agent, Codex for coding work, and extensions for Excel, Word, PowerPoint and Google Sheets. The Pro tier adds an always-on agent and the largest memory and context allowances.

Memory deserves a note because it cuts both ways. ChatGPT retains details across conversations, which is what makes it feel useful over weeks rather than minutes, and memory capacity scales with the paid tier. It also means the product accumulates a persistent profile of the user on OpenAI’s servers by design. Memories can be viewed, edited, and deleted individually, so the control is there — but accumulation is the default behaviour, not an option that was enabled.

Business and Enterprise tiers exist above the consumer plans, priced per seat on request. Beyond the different training default, they add administrative controls, shared workspace features, and company knowledge integration. They are outside what this review scores, but their existence is the reason the consumer defaults look the way they do.

Usability

Low friction is the whole point and the execution is polished. The web interface at chatgpt.com requires no installation and is how most people use the product. Native desktop applications cover macOS 14 and later on Apple Silicon or Intel, and Windows 10 build 17763.0 and later. Mobile apps cover iOS and Android. An official Chrome extension is also offered. The interaction model needs no explanation to anyone who has used a messaging app, which is a large part of why this product reached the scale it did.

Two things take points off. There is no Linux desktop client, which for a tool heavily used by developers is a conspicuous gap; Linux users are left with the browser. And the desktop story is currently confusing: OpenAI ships a new unified ChatGPT app combining Chat, Work and Codex alongside a separately maintained older application called ChatGPT Classic. Two apps with near-identical names, both supported, with no obvious signal about which one a given user should install, is the kind of transitional mess that resolves eventually but is live right now.

Price & Value

The free tier is genuinely useful rather than a trial. Unlimited text conversations on the base model, subject to abuse guardrails, covers most of what a casual user actually does. The restrictions land on uploads, image creation, voice, deep research, memory and context size, and Codex access — real limits, but ones that leave ordinary text work intact.

Go at $6 a month expands messages, uploads, image generation and memory, and OpenAI states on its own pricing page that this plan may include ads. That is unusual enough among paid AI subscriptions to flag: paying a smaller amount buys a product that may monetise attention as well, and an ad-supported layer sitting on a service that holds your conversation history is a combination worth understanding before choosing it over the free tier.

Plus at $20 a month is the plan most people mean when they say they pay for ChatGPT, and against the rest of the category it is priced in line while delivering considerably more. Pro from $100 a month, with three usage tiers to choose between, targets heavy professional use with maximum memory, context, deep research, and unlimited image generation.

The value judgment turns on what is being bought. Measured in capability per dollar, ChatGPT is competitive and arguably the best buy in the category. Measured in privacy per dollar, paying changes almost nothing — Free, Go, Plus and Pro share the same training default, the same storage model, and the same mandatory account. Better data handling is not a feature you can purchase on the consumer ladder; it arrives only at the organisational tiers.

Pros and Cons

  • The widest feature set in the category: multiple selectable model generations, web search, file upload, image generation, voice, deep research, data analysis, Projects, scheduled tasks, custom GPTs, and a coding agent
  • The free tier allows unlimited text conversations on the base model rather than metering them, subject to abuse guardrails
  • The training opt-out is real and accessible — a single toggle under Settings, Data controls, or an equivalent selection in the Privacy Portal
  • Temporary Chat gives a per-conversation mode excluded from training, kept out of history, and deleted automatically
  • Conversation export, chat deletion, and individual Memory management are all available to the user directly
  • A SOC 2 Type 2 report assessed by an independent third-party auditor, plus ISO/IEC 27001, 27017, 27018 and 27701 certifications
  • The March 2023 Redis incident was self-detected, publicly documented in technical detail within days, communicated to affected users individually, and patched upstream in the open-source library at fault
  • Desktop apps for macOS and Windows, mobile apps for iOS and Android, a Chrome extension, and a web interface needing no installation
  • EEA, UK and Swiss users have OpenAI Ireland Limited as data controller, placing them under GDPR with a European supervisory authority
  • Encryption in transit with TLS 1.2 and at rest with AES-256
  • Training on conversations is enabled by default for every individual tier — the user must opt out, while business and education tiers get the protective default automatically
  • Rating a response with thumbs up or down can send the entire conversation into the training set even after opting out, through a control that looks like a product rating rather than a consent choice
  • Storage is server-side and operator-readable, not zero-access: OpenAI can decrypt conversations for abuse review, model improvement, or a legal demand
  • An account is mandatory — there is no anonymous way to use the product
  • No claim anywhere in the documentation that the IP address is separated from the request before processing, and IP is collected and retained as log data
  • No trusted-execution or confidential-compute claim for the consumer product, so no privacy claim is cryptographically verifiable
  • An internal systems breach in early 2023 was deliberately not disclosed publicly and became known only through press reporting around sixteen months later; law enforcement was not notified
  • The SOC 2 report is not published — access runs through a request process aimed at enterprise buyers, and the report's period and issue date are not stated publicly
  • Model weights, client code, and server infrastructure are all closed source, so every privacy claim rests on documentation rather than inspection
  • Paying more does not improve data handling: Free, Go, Plus and Pro share the same training default, storage model, and account requirement
  • The $6 Go plan may include ads, per OpenAI's own pricing page
  • No Linux desktop client, and two desktop applications ship in parallel under confusingly similar names

Our Rating

ChatGPT is the capability benchmark for this category and nowhere near its privacy benchmark, and both halves of that sentence are meant literally. If the task is getting the most capable assistant available, with the broadest tooling, on every platform except Linux, for a price that is reasonable against what it does, this is the straightforward answer and the score on Features reflects that honestly. If the task is limiting who can read what you type, the architecture works against you: an account you cannot avoid, storage OpenAI can decrypt, no claim that your IP is ever separated from your request, and a training default that treats consumer conversations as training material until you intervene. The controls to push back exist and they function, which is why this does not score at the bottom — but they are opt-outs, they require knowing they exist, and one of them can be undone by clicking a thumbs-up.

The resulting number should be read as what it is: a baseline, not a warning. ChatGPT is what most people already use, scored on the same five criteria as everything else in this section so that the privacy-first entries have something concrete to be compared against. The gap between this score and theirs is almost entirely Privacy Architecture, and that gap is the answer to why those alternatives exist at all. For anyone whose use is casual and non-sensitive, the honest advice is that ChatGPT is fine and the free tier is a good deal — with the training toggle turned off and the thumbs buttons left alone. For anything that would be damaging to see stored, read by a reviewer, or produced under legal compulsion, the architecture here offers no protection, and that is a design choice rather than an oversight.

  • Privacy Architecture1.5/10

    Four of the five fields this category scores sit at or near the bottom of their scale and none reach the top: an account is mandatory, no documentation claims the IP address is separated from the request, storage is server-side and operator-readable rather than zero-access, and training on consumer chats is on by default rather than contractually forbidden. The working opt-out, export and deletion tools are real, but they are account-management features, not an architectural property of this category — they are credited in Usability and Trust & Transparency instead of offsetting the score here

  • Trust & Transparency4.5/10

    A SOC 2 Type 2 report and four ISO certifications exist and are real, but the report is released through a sales request rather than published, and the record on disclosure is split: a same-week public technical post-mortem of the 2023 Redis bug against a sixteen-month silence on an internal breach that only became public through press reporting

  • Features8.7/10

    The widest feature surface in the category — several model generations selectable per tier, web search, file upload, image generation, voice, deep research, Projects, scheduled tasks, custom GPTs, a coding agent, and document and spreadsheet integrations

  • Usability8.0/10

    Desktop apps for macOS and Windows, mobile apps for both platforms, a browser extension, and a web interface that needs nothing installed, with a near-zero learning curve — held back by the absence of any Linux client and by two desktop apps shipping in parallel under confusingly similar names

  • Price & Value7.0/10

    The free tier is genuinely usable for everyday text work rather than a demo, and $20/month buys an unusually large amount of capability — but the $6 tier may carry ads, and the privacy defaults are worst for exactly the unpaid users who have the least leverage to change them

Overall5.4/10

Privacy Architecture 30% · Trust & Transparency 20% · Features 20% · Usability 20% · Price & Value 10%

See our rating methodology →

Ready to try ChatGPT?

Visit ChatGPT →

Last updated: October 1, 2026By Juan Martinez