Is ChatGPT safe?
As software, yes. It is a mainstream product from a major company, not a malware risk, and it carries real security controls — Lockdown Mode, session management, parental controls. The parts that need your attention are elsewhere: on a personal plan your conversations train models by default until you turn that off, and its answers are unreliable enough that OpenAI itself says to treat them as a first draft.
Four questions wear the word safe. They have different answers.
Safe from malware and scams? Yes, if you use the real thing. ChatGPT is a mainstream product distributed through the web, the App Store, Google Play and official desktop apps. The genuine risk in this space is the surrounding ecosystem — fake "free ChatGPT Plus" sites, browser extensions and lookalike apps that harvest credentials. Those are threats adjacent to ChatGPT, not from it.
Safe for your data? Not by default, on a personal plan. Conversations are stored and may be used to train OpenAI's models until you turn off "Improve the model for everyone" in Data Controls — one toggle, account-wide, changeable at any time, not retroactive. Business, Enterprise and Edu workspaces are excluded from training by default. OpenAI also states it reviews conversations to improve systems and check policy compliance. Full detail on whether chats are private.
Safe for children? Partly, with work. OpenAI ships parental controls for linked teen accounts, including the ability to opt a teen out of model training, control whether they can create or edit images, and disable device location sharing. Ads are not shown to accounts identified as under 18, and a ChatGPT for Teens experience adds reminders before some image uploads. None of that makes it a children's product, and none of it is on by default for an account a child sets up themselves.
Safe to rely on? No, and this is the risk that actually costs people something. OpenAI's own guidance names fabricated citations and overconfident wrong answers as known failures, and instructs users to treat output as a first draft. The accuracy question is separate enough to have its own page.
The controls that exist, and what each implies.
An opt-in setting, available to all logged-in users, that restricts network-enabled capabilities — live web browsing, deep research, agent mode, file downloads and some web-derived images — specifically to reduce the risk of data exfiltration from prompt-injection attacks. Personal users find it in Settings → Security; workspace admins can configure it for members.
Read that as a risk disclosure as well as a feature. Prompt injection — hostile instructions hidden in a web page or document that the model then follows — is a real, unsolved class of attack across the industry, and it gets more serious the more an assistant can do rather than say. A vendor shipping a switch to turn the internet off is being straight with you about that.
The most likely bad outcome for an ordinary user is not a model failure, it is somebody else reading their chat history. OpenAI has been adding to this area: advanced account security, active session controls to see and end logged-in sessions, and the ability to add a password to an account originally created with Google, Apple or Microsoft sign-in.
Worth doing today if you have not: check active sessions, and remember that your chat history is only as protected as the account it sits behind. Anything you would not want read by whoever compromises that login should go in a Temporary Chat, which is not saved to history, creates no memories and is deleted after 30 days.
A share of this cluster is asking something heavier — whether it is safe to talk to about difficult personal things. That deserves a straight answer rather than a product feature list.
OpenAI states that safety systems may use limited safety-relevant context in rare high-risk situations even when memory and personalization are off, and has added a trusted-contact feature. Ads are excluded from conversations about personal health, mental health and politics. But it is not a clinician, it is not confidential in the sense a professional relationship is, and its answers carry the same reliability caveats as everything else. If something is serious, it is worth talking to a person who is qualified and who is bound by rules ChatGPT is not.
That is your employer's call rather than a technical one, and the honest input to that decision is: on a personal plan, training is on until you turn it off and the content is stored. On Business, Enterprise and Edu, OpenAI states content is not used for training by default and additional admin controls exist.
The practical failure is not malice, it is habit — pasting a client document into whichever account is already logged in. If your organisation has a workspace, use it; if it does not and you handle other people's data, that is a conversation worth having before the paste, not after. Plus vs Team sets out what actually changes.
Three ways to tighten it.
All three are OpenAI's own controls or plans — no workarounds, nothing unsupported. We have not audited any vendor's internal handling; these are published behaviours.
Frequently asked.
Quick follow-ups people search after this question.