It is the most sensible question an owner can ask, and it deserves a straight answer rather than a scare story. ChatGPT is a genuinely good tool, and this page will not pretend otherwise. The difference worth understanding is what each tool has read, and where your words go when you use it.
What ChatGPT has read, and what it has not
ChatGPT was trained on an enormous sample of public text. It knows what a warranty is. It knows roofing in general, plumbing in general, and roughly what things cost in general. It has never read your warranty terms, your price book, your installation specs, or the manufacturer bulletin that changed your fastener pattern last spring. Ask it whether your 30-year shingle warranty covers wind damage on a low-slope tear-off and it will assemble an answer from the industry average — fluent, reasonable-sounding, and unconnected to the document that actually governs the claim. Plausible and wrong are fully compatible, and the tool's confidence is identical in both cases.
Where your words go when you paste them
This is published policy, not a secret. OpenAI's own documentation states that conversations on personal free and paid accounts are used to train future models by default — the setting can be turned off — while business and API tiers are opted out by default. The practical problem is not the policy. It is that the employee summarizing a customer dispute at nine at night is almost always on a free personal account, not the company tier, and nobody in the office knows it happened.
Deletion is a policy until a court gets involved
In the New York Times copyright suit against OpenAI, a federal magistrate ordered in May 2025 that output logs be preserved — including conversations users had already deleted — and OpenAI was later ordered to produce twenty million de-identified chat logs to the plaintiffs. The preservation obligation was substantially lifted that October, but the lesson stands. When your text sits on a vendor's servers, your delete button is subordinate to other people's litigation. Nothing you sign with the vendor changes what a court can order the vendor to do.
A court has already ruled on the consumer tier
In February 2026, a federal court in the Southern District of New York held that documents an executive generated using the consumer tier of an AI chatbot — analyses of his own legal exposure, shared with his lawyers — were protected by neither attorney-client privilege nor the work-product doctrine. The reasoning turned on the platform's terms: because they permitted retention and disclosure of the data, there was no reasonable expectation of confidentiality to begin with. You may never face a grand jury. The principle is broader than lawyers: what goes into a consumer chatbot is not private in the way most people assume it is.
What a private system does differently, and what it does not
A private system inverts the arrangement. The model runs on hardware you control. Before answering, it retrieves the relevant passages from documents you supplied — your warranty terms, your price book — answers from those passages, and cites the document and section it drew from. Built properly, it says "that is not in the documents" instead of improvising.
Now the honesty. Retrieval reduces wrong answers; it does not eliminate them. A Stanford study published in the Journal of Empirical Legal Studies in 2025 tested the leading commercial legal research AIs — purpose-built retrieval systems from major publishers — and still measured wrong or fabricated answers on roughly one query in six for one product and one in three for another. The vendors disputed parts of the methodology; the direction of the finding is not in doubt. Anyone who tells you their system never makes things up is selling something. And the stakes of a wrong answer are yours either way: in 2024 a Canadian tribunal held Air Canada liable for its website chatbot's incorrect answer about bereavement fares. The award was just over eight hundred Canadian dollars. The principle — a business is bound by what its bot tells a customer — was the expensive part.
When ChatGPT is still the right tool
Drafting an email. Rewriting a job posting. Explaining what "indemnification" generally means before you call your lawyer. These are public-knowledge tasks that involve no customer data, and the cheap general tool wins them outright — we would tell you to keep using it. A private system earns its cost only when the answer lives in your paperwork, or when the words themselves must not leave your building. Most businesses eventually want both, because they are different tools for different questions.
The version to say out loud at the office
If a colleague asks what the difference is, it fits in two sentences. ChatGPT answers from what it read on the public internet, and whatever you type travels to someone else's servers under their terms. A private system answers from documents you gave it, on a machine you control, and shows you the page the answer came from. The house rule that follows: if the question needs our paperwork, or contains a customer's name, it does not go in the public tool.
Where to start
Run a ten-minute experiment. Pick one question your staff answers every week that has a written answer — a warranty boundary, a price tier, a spec tolerance. Ask ChatGPT. Then open the actual document. The distance between the two answers, measured on your own paperwork, is everything this page was trying to say.