AI Agent - Aug 5, 2026

ChatGPT Academic Researchers: Privacy and Data

Privacy claim: what it means

OpenAI says ChatGPT for Academic Researchers workspaces have business-grade privacy and security protections and that data is not used to train OpenAI models by default. That is an important provider statement, but it is not a universal approval for sensitive research.

Review the complete data path

Before use, document:

  • data owner, purpose, classification, and minimum necessary fields;
  • participant consent, ethics or IRB, contract, and funder restrictions;
  • workspace identity, roles, retention, export, and deletion;
  • model, ChatGPT Work, Codex, deep research, skill, and connector paths;
  • source-system authentication and action permissions;
  • processing locations, subprocessors, incident terms, and offboarding;
  • reproducible redaction and independent output validation.

Do not upload protected health, controlled, proprietary, unpublished participant, genomic, or export-sensitive data until the institution has approved that exact path.

Connector boundary

A connector can reveal or act on data allowed by the connected service. Workspace membership does not enlarge source-system authority. Start read-only, narrow sources and actions, test with non-sensitive data, and require confirmation for material writes or external communication.

Frequently asked questions

Is “not trained by default” the same as zero retention?

No. Training use, service retention, logs, workspace history, connector records, and institutional archives are separate questions.

Can Codex access every lab repository?

Only repositories and environments explicitly made available under their authentication, sandbox, and approval controls. Review secrets, data, licenses, network, and write authority.

Does the program certify compliance?

No. Institutional reviewers determine whether a specific configuration and workflow meet applicable requirements.

Official sources

Source check: August 5, 2026.