
OpenAI ChatGPT
Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 10 Feb 2026

AI Trust Summary
Safer Alternatives
Higher-rated software in the same category
Attention Points in AI (1)
AI criteria that require attention. Buy the Premium Analysis to see all 1 criteria.
Ethical AI principles and anti-bias measures not documented
Source: vendor public documents
Compliances in AI (3)
AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.
AI data retention policy clearly documented
Policy on data use for AI training clearly stated
AI training opt-out control available
Source: vendor public documents
Highlights in Privacy (3)
Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.
Safeguards for international transfers are not mentioned
Data controller and processor roles clearly defined
Data controller identity and contact clearly disclosed
Source: vendor public documents
Conformance analysis (20)
AI data retention policy clearly documented
Reference: ISO/IEC 42001 (8.2) + ISO/IEC 27701 (7.4.6)
Policy on data use for AI training clearly stated
Reference: ISO/IEC 42001 (8.2) + ISO/IEC 23894 + EU AI Act
AI training opt-out control available
Reference: ISO/IEC 42001 (8.3) + ISO/IEC 29100 + EU AI Act
Source: vendor public documents
Follow this company and access all 20 criteria
Track score changes, get alerts on policy updates, and view the full conformance analysis
Don't miss any update
Sign up to follow this company and track changes in privacy and AI scores
Why trust the AITS Index: Open Community Audit
Public transparency, peer review and open evidence trails — all verifiable by the community
Trust guarantees
Peer review
users, professionals and experts confirm or contest items online.
Public history
vendor and index changes are versioned and accessible.
Participate
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Understanding Privacy and Security Strengths and Weaknesses of OpenAI ChatGPT
Privacy Strength: Opt-Out Control for AI Training
OpenAI ChatGPT provides users with the ability to opt-out of having their data used for AI training. This feature is essential for users who prioritize privacy and wish to maintain control over their personal information. By enabling this option, users can ensure that their interactions with the software do not contribute to the model's learning process, thereby minimizing the risk of unintentional data exposure. This strength is reflected in the AITS Privacy Score of 75%, indicating a solid foundation in user data control.
Privacy Strength: Clear Documentation of Prompts and Responses
Another notable strength of OpenAI ChatGPT is its clear documentation regarding the use of prompts and responses for AI training. This transparency allows users to understand how their input is utilized, fostering trust in the platform. Users can review this information to make informed decisions about their interactions with the AI. The defined retention period for prompts and responses further enhances user confidence, as it clarifies how long their data will be stored and when it will be deleted.
Privacy Weakness: Lack of Ethical AI Principles
Despite its strengths, OpenAI ChatGPT has significant weaknesses, particularly concerning the documentation of ethical AI principles. The absence of clear commitments to ethical AI use raises concerns about potential biases and discrimination in the model's outputs. Users should be aware that without these principles, there is a risk that the AI may produce biased or unfair results. To mitigate this risk, users can actively monitor the outputs and provide feedback to OpenAI, helping to improve the model's performance and ethical standards over time.
Privacy Weakness: Unspecified International Transfer Safeguards
Another critical weakness is the lack of specified safeguards for international data transfers. This omission can pose risks to data security, especially for organizations operating under regulations such as the GDPR or LGPD, which require stringent protections for personal data. Users should consider implementing additional security measures, such as data encryption and access controls, to protect sensitive information when using the software. Additionally, staying informed about OpenAI's data handling practices can help users make better decisions regarding their data.
Practical Guidance: Settings to Check and Features to Enable
To enhance privacy while using OpenAI ChatGPT, users should familiarize themselves with the available settings. Enabling the opt-out feature for AI training is crucial for those concerned about data usage. Additionally, users should regularly review their data retention settings to ensure they align with their privacy preferences. It is also advisable to limit the sharing of sensitive information during interactions with the AI, as this can further reduce potential risks associated with data exposure.
Practical Guidance: Alternatives and Precautions
For users who are particularly concerned about the weaknesses identified, considering alternative AI solutions that prioritize ethical AI principles and provide robust international data transfer safeguards may be beneficial. Researching competitors with higher AITS Privacy Scores or those that explicitly document their ethical commitments can provide peace of mind. Furthermore, users should stay updated on regulatory changes related to data privacy, such as GDPR and ISO 27701, to ensure compliance and protect their rights as data subjects.
Other AI Tools software
Dive into in-depth research and analysis of each player
Source: vendor public documents
Analyzed Sources
Public documents used in the audit of OpenAI ChatGPT:
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Scope & Limitations
TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).
The content is indicative in nature, intended for screening and comparison, not replacing internal audits.
TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.
Source: vendor public documents






