home / guides / Can Employees Put Customer Data Into ChatGPT? (What's Safe, What Isn't)

Guide

Can Employees Put Customer Data Into ChatGPT? (What's Safe, What Isn't)

A plain-language answer on what's safe to type into ChatGPT, Gemini, and Copilot — and what never is.

Updated 2026-09-27 · 8 min read · yforest AI Labs

Key takeaways

  • The free, consumer version of ChatGPT, Gemini, or Copilot is built for individuals — by default, some of what you type can be used to improve the underlying model, and none of these tools were designed to hold customer records.
  • Paid business plans (ChatGPT Business/Enterprise, Google Workspace's Gemini, Microsoft 365 Copilot) come with a different default: the vendors state that prompts and data from those plans are not used to train the underlying models.
  • "Not used for training" is not the same as "safe for anything." A business plan still means the vendor's servers process the data — you're extending your data boundary to them, not eliminating the risk.
  • Some categories of customer data — health details, full account numbers, Social Security numbers, anything covered by a contract's confidentiality clause — shouldn't go into any general-purpose AI tool, on any plan, without a specific reason to trust that tool.
  • The fastest fix isn't a ban. It's telling your team which plan you're actually on, what that plan does with data, and what's off-limits regardless.

Somewhere on your team, right now, someone is probably deciding — on their own, in the moment — whether it's fine to paste a customer's name and order history into ChatGPT to draft a response. They don't have bad intentions. They just don't know the answer, and there's a good chance you don't either, because the honest answer depends on which version of the tool they're using.

This guide gives you that answer in plain terms: what the free version of these tools does with your data, what the paid business version does differently, and where the line sits regardless of which one your team is on.

Why the question matters more than it sounds

"Can I paste this into ChatGPT?" sounds like a small question. It isn't, because the answer determines whether a customer's information leaves your company's control and lands somewhere you can't see, can't delete, and can't audit. Once text is submitted to a public AI tool, you're trusting that vendor's data-handling terms — not your own.

The scale of this is bigger than most owners assume. Research from UpGuard, reported by Cybersecurity Dive, found that more than 80% of workers use AI tools their employer never approved, while fewer than half say they understand their company's AI policies. Separately, Cyberhaven's analysis of workplace AI activity found that 39.7% of AI interactions involve sensitive data — prompt text, pasted content, or uploaded files that include information the business would not want leaving its systems.

FindingSource
More than 80% of workers use AI tools their employer never approvedUpGuard, reported by Cybersecurity Dive
39.7% of AI interactions involve sensitive dataCyberhaven, 2026 AI Adoption & Risk Report

Put together, that's a lot of customer data moving into tools nobody signed off on, without anyone checking what those tools actually do with it. The fix starts with understanding the one distinction that matters most: which plan is actually installed on your team's laptops.

Consumer plans and business plans are not the same product

"ChatGPT" isn't one thing. Neither is "Gemini" or "Copilot." Each of these brands covers a free or low-cost consumer tier aimed at individuals, and a separate paid business tier aimed at companies — and the two tiers come with different default data-handling terms. Confusing the two is the single most common reason a business ends up with looser data practices than its owner assumes.

The practical difference usually comes down to one question: does the vendor use what you type to improve its models by default? On the consumer side, the answer is often yes unless you turn a setting off. On the business side, the vendors we checked all state the opposite default. That's a meaningful gap, and it's worth confirming which side of it your team is actually using before you decide what's safe to type.

What the major vendors say, in their own words

Rather than guess, we went to each vendor's own current documentation. Here's what each says about training data, checked directly from their published pages.

ToolConsumer/free tierBusiness tier
OpenAI ChatGPTData from individual consumer accounts may be used to improve models unless the user opts out"By default, we do not use your business data for training our models" — applies to ChatGPT Business, Enterprise, Edu, and the API
Google GeminiConsumer Gemini app activity may be used to improve Google's AI products, per Google's consumer privacy termsGoogle states Workspace data "is not reviewed by humans or otherwise used for generative AI model training outside your domain without permission"
Microsoft CopilotConsumer Copilot (the free, personal version) follows Microsoft's consumer product termsMicrosoft states prompts, responses, and Microsoft 365 data "aren't used to train foundation LLMs, including those used by Microsoft Copilot"
Tip

Vendor data-use terms change. Before you rely on any claim in this table for a real decision, check the vendor's current page yourself — the links are in Sources below — because policies like these get updated more often than most companies re-read them.

Notice what none of these business-tier statements say: they don't say the data is deleted, encrypted end-to-end, or invisible to the vendor's own staff for support and abuse-monitoring purposes. "Not used for training" answers one specific question — will this text end up shaping a future model response to someone else — and it's a real, useful protection. It does not answer every question a business should ask before typing in customer information. For that, see our full AI vendor security checklist.

What should never go into any general-purpose AI tool

Regardless of which plan your team is on, some categories of information don't belong in a general-purpose chatbot at all — not because the vendor is untrustworthy, but because these categories carry legal, contractual, or safety obligations that a chat tool wasn't built to satisfy:

  • Full Social Security numbers, government ID numbers, or financial account numbers. There's no legitimate drafting task that requires the full number — mask or omit it instead.
  • Protected health information, if your business is a covered entity or handles PHI on behalf of one. See our guide on HIPAA and AI for medical and dental offices.
  • Passwords, API keys, or login credentials of any kind, for any system.
  • Information covered by a signed NDA or confidentiality clause with a customer or partner — the AI vendor is not a party to that contract.
  • Anything you wouldn't want to see in a data breach notification naming your company. If a leak of that text would require you to notify customers, don't type it in to begin with.

What's usually fine, on a business plan

Not every mention of a customer is a risk. On a paid business plan with training turned off, tasks like these are typically reasonable:

  • Drafting a reply to a support ticket using a general description of the issue, without the customer's full name or account number
  • Summarizing a call transcript for internal notes, with sensitive identifiers removed first
  • Writing a first draft of a policy, proposal, or email template that contains no real customer data at all
  • Analyzing anonymized or aggregated data — total sales by month, not a named customer's individual purchase history

The common thread: the task doesn't require the real, identifiable customer record to work. When it does — when someone genuinely needs the AI tool to process actual customer PII — that's the moment to slow down and check our guide on protecting customer PII when your team uses AI, which covers redaction and data classification in more depth.

Gray areas worth a second look

A few situations don't have a clean yes or no answer, and deserve a specific rule rather than a judgment call in the moment:

Watch for these

AI features built into other software — a CRM's "AI summary" button, an email client's "smart reply" — often route your text through one of these same underlying models. The data-use terms follow whichever plan and vendor sit behind that feature, not the software brand on the box. Check before assuming a built-in AI feature is automatically covered by your business-plan protections.

  • Free trials of business plans. Confirm the training-data default applies from day one of the trial, not only after you pay.
  • Personal accounts used for work. An employee's personal ChatGPT login is a consumer account, even if they only ever use it for work tasks.
  • Browser extensions and third-party wrappers. A tool that calls an AI vendor's API on your behalf inherits that vendor's terms, plus whatever the wrapper itself does with the data — which is a second thing to check, not a reason to skip checking the first.

A rule your team can actually follow

Most businesses don't need a legal memo — they need one sentence people can remember at 4:45pm on a Friday. Something like:

One-line team rule — copy and adapt
We use [PRODUCT NAME, e.g. ChatGPT Business] for work. Never type a customer's full name with their account number, health information, payment details, or password into any AI tool — including this one. If you're not sure whether something is safe to include, leave it out and ask [NAME/ROLE].

Pair that rule with a short list of which tools are actually approved — see our approved AI tools list guide — and you've closed most of the gap between what your team is doing today and what's actually safe. For a fuller written policy that covers this and more, our AI acceptable use policy guide has an 11-section starter template.

When to bring in outside help

If your business handles regulated data as a matter of course — health records, financial account details, legal client files — a one-line rule isn't enough on its own. You need a written policy, an approved-tools list, and someone who owns both. That's the gap our AI enablement and AI safety & compliance services are built to close: we come in, assess what your team is actually doing today, and set up rules that match your real risk instead of a generic template.

◆ Small Business AI Kickstart

Get AI ready today.
Before it's too late.

yforest AI Labs comes to your company, trains your team, and ships your first tools.

FAQ

Is it ever okay to put a customer's name into ChatGPT?

Usually only on an approved business plan, and only when the task doesn't require the full identifiable record. When possible, redact the name and other identifiers first — see our guide on protecting customer PII for how.

Does ChatGPT Business really not use our data for training?

OpenAI's current published terms state that by default, business data is not used to train its models, across ChatGPT Business, Enterprise, Edu, and the API. Confirm this against OpenAI's current page before relying on it, since vendor terms can change.

What's the risk if an employee uses their personal ChatGPT account for work?

A personal account is a consumer account, which typically follows different, often less protective, default data-handling terms than a business plan — and it puts company and customer data outside any agreement your business has with the vendor.

Do AI features built into other software follow the same rules?

Often yes, since many built-in AI features route through one of these same underlying models. Check which vendor and plan sit behind the feature rather than assuming it's automatically covered by your business-plan protections.

What should never go into any AI tool, on any plan?

Full Social Security numbers, payment or account numbers, protected health information, passwords, and anything covered by an NDA. These categories carry obligations a general-purpose chat tool wasn't built to satisfy.

Sources

  1. OpenAI — Enterprise privacy at OpenAI
  2. Google Workspace — Generative AI privacy commitments
  3. Microsoft — Microsoft 365 Copilot data, privacy, and security
  4. UpGuard shadow AI research, reported by Cybersecurity Dive
  5. Cyberhaven — 2026 AI Adoption & Risk Report

This guide is general information, not legal advice. Have a qualified attorney review any policy before you adopt it.