It depends on which plan you are on. For anyone weighing legal AI for in-house counsel, this is the first question that matters. ChatGPT on a consumer tier (Free, Plus, or Pro) is not built for legal confidentiality by default, and your inputs may be used to improve OpenAI's models unless you opt out. ChatGPT Team and Enterprise are different: OpenAI states it does not train on that content by default and offers business data controls. For client-confidential work, the plan and its written terms decide the answer, and ABA Formal Opinion 512 makes confirming them your duty. This is general information, not legal advice.
TL;DR
- Consumer ChatGPT is not confidential by default. Free, Plus, and Pro inputs may be used to improve models unless you turn that off. Pro is a consumer contract, not a business one.
- Team and Enterprise are different. OpenAI states it does not use Team or Enterprise content to train its models by default, and offers admin controls and a data agreement (OpenAI, 2026).
- Opting out is not the same as a no-train contract. A settings toggle on a consumer plan is weaker than a signed commitment with a DPA.
- ABA 512 sets the bar. You must know how the tool handles data and, in general, get informed client consent before entering confidences. Boilerplate consent is not enough.
- "Confidential" means more than no-train. It also means encryption, access control, retention limits, and a data agreement you can point to.
- When in doubt, do not paste. Anonymize, use a business plan with a data agreement, or use a tool whose terms are built for client data.
What "confidential" actually means for legal AI
Lawyers throw the word "confidential" at a tool and expect it to mean one thing. It actually means a stack of separate guarantees, and a tool can pass one and fail the others.
- No training on your inputs. Your prompts and documents are not fed back into the model.
- Encryption in transit and at rest, so data is protected on the wire and on disk.
- Access control. Only authorized people in your org can see the data, with admin oversight.
- Retention limits. Data is deleted on a clear schedule, not kept forever (subject to legal holds).
- A written data agreement, typically a DPA, so the commitment is contractual, not a blog promise.
"Is ChatGPT confidential" really means "does the plan I am on deliver all five." For most consumer use, the honest answer is no.
Consumer vs Team vs Enterprise: the split that decides everything
OpenAI's consumer terms and its business terms are different products. This is the single most important distinction for a lawyer, so here it is plainly.
| Plan | Trains on your inputs (default) | Data agreement | Built for client-confidential work? |
|---|---|---|---|
| Free / Plus / Pro (consumer) | May be used to improve models unless you opt out | Consumer terms only | No, not by default |
| Team (business) | Not used to train models by default (OpenAI, 2026) | Business terms; admin controls | Closer, with controls |
| Enterprise (business) | Not used to train models by default (OpenAI, 2026) | Typically a DPA, admin controls, audit options | Yes, with the agreement in place |
Two traps to flag. First, the Pro plan is a consumer contract, so the higher price does not buy business data terms. Second, turning off training in consumer settings is not a no-train contract; it is a toggle that can change, not a signed commitment. Always confirm the current terms directly, because vendor policies move.

For the broader map of where your inputs travel across any legal AI tool, see where your legal AI data actually goes.
Which ChatGPT plan is safe for client-confidential work by default?
The training-on-inputs risk, concretely
Why does training matter so much for a lawyer? Because if a tool learns from your inputs, a client confidence you pasted could, in principle, surface or influence a later output to someone else. ABA Formal Opinion 512 names exactly this concern: lawyers should be aware that information put into a tool could improperly end up in a later output.
That is the structural risk consumer training creates. Even if the odds of a specific leak are low, the duty of confidentiality is not a probability game. You either control where the data goes or you do not.
This is also why a vendor's no-train claim is worth verifying rather than trusting on faith. We walk through how to actually check one in we do not train on your data: how to verify it.
What ABA Formal Opinion 512 requires
The confidentiality duty under Model Rule 1.6 does not pause for new technology. ABA Formal Opinion 512, issued July 2024, applies it to generative AI directly.
The opinion requires lawyers to understand how a tool uses the data they put in, and to put safeguards in place so client information is not exposed to unauthorized third parties. It goes further on consent: lawyers should generally get the client's informed consent before entering client confidences into a tool that could expose them, and it states that boilerplate consent buried in an engagement letter is not adequate.
In short, you have to know the tool's data handling, match the tool to the sensitivity of the matter, and get real consent where it counts. Our ABA Formal Opinion 512 guide covers the full set of duties. Check your own state bar too, since several have issued their own AI guidance.
Why the consumer default is the actual risk
The danger is rarely that someone chose the wrong plan on purpose. It is that the consumer tier is the path of least resistance. A lawyer signs up with a personal email, lands on Free or Plus, and starts pasting. Nobody read a contract, because a consumer signup does not present one in the way a business agreement does. That is the trap worth naming.
Three things separate the consumer tiers (Free, Plus, Pro) from the business tiers (Team, Enterprise), and each one matters for client data.
- Training use. On consumer plans your inputs may be used to improve the models unless you turn that off in settings. On Team and Enterprise, OpenAI states it does not train on that content by default. Confirm the current setting and the current policy yourself, because both can change and a default is not a promise.
- Retention. Consumer chats are kept and tied to your account, and deletion is a user action rather than a contractual schedule. Business tiers generally offer admin-level retention controls and a documented deletion path. Do not assume a specific number of days; read the plan's current data-retention page and write down what it actually says.
- No data agreement. This is the one that decides it. Consumer terms are a click-through, not a negotiated contract, and there is no DPA. Business tiers are where a data processing agreement, subprocessor commitments, and audit options live. Without a DPA, you are relying on a marketing line, and ABA 512 asks for more than that.
The Pro plan deserves its own warning because the price misleads people. Pro is expensive, so lawyers assume it carries business protections. It does not. Pro is a consumer contract with consumer terms. The premium buys more capability, not a different data agreement.
What to demand in an AI vendor's DPA and subprocessor list
Before any client or matter data goes into a tool, the data agreement is the document that turns vendor promises into something enforceable. You do not need to be a privacy specialist to read one. You need to confirm a handful of terms are present and say what you expect.
- A no-train clause in writing. The agreement should state plainly that your content is not used to train or improve the vendor's models. A toggle in settings is not this. Look for the commitment in the contract itself.
- A defined retention and deletion term. The DPA should say how long data is kept and commit to deletion on request or on termination. Confirm the actual period in the vendor's current terms rather than trusting a sales call.
- A current subprocessor list. Most AI tools route data to other providers: a model host, cloud infrastructure, sometimes analytics. The vendor should publish who those subprocessors are and commit to notifying you before adding new ones. If a vendor cannot tell you which model provider sees your prompts, that is your answer.
- Security and breach-notification terms. Encryption in transit and at rest, access controls, and a commitment to notify you within a defined window if there is a breach. Vague language here is a flag.
- Confidentiality and use-limitation language. The vendor should be contractually barred from using your data for anything beyond delivering the service. Watch for broad "to improve our products" carve-outs that quietly reopen the training door.
- Audit or compliance evidence. A SOC 2 report or equivalent, available on request. It is not a substitute for reading the DPA, but its absence tells you how mature the vendor is.
The subprocessor list matters more than it looks. A no-train promise from the vendor means little if the underlying model provider has different terms for the same data. Trace the chain: your prompt goes to the tool, the tool sends it to a model host, the host has its own policy. Confirm the whole path is covered, end to end.
A confidentiality checklist before you paste anything sensitive
Run this before a client matter, a draft contract, or any privileged material goes into a chatbot. This is general guidance; your bar rules and your client's instructions control.
- Identify the plan. Are you on a consumer tier (Free, Plus, Pro) or a business tier (Team, Enterprise)? Pro counts as consumer.
- Confirm the training default. Is your content used to train the model? On consumer plans, opt out if you have not.
- Find the written terms. Is there a data agreement or DPA you can actually point to, not just a marketing line?
- Check retention. How long is data kept, and can you delete it? Note any legal-hold exceptions.
- Check access and encryption. Who in your org can see it, and is it encrypted in transit and at rest?
- Match tool to sensitivity. High-stakes or privileged material may need a business plan or a tool built for legal data.
- Handle consent. Where required, get the client's informed consent. Do not rely on engagement-letter boilerplate.
- Anonymize when unsure. Strip names, identifiers, and deal-specific details if you are on a consumer tier.
A confidentiality checklist for any AI tool
The checklist above is tuned to ChatGPT's plan structure. This shorter one is tool-agnostic, so you can run it on any AI product a vendor pitches to your team, OpenAI or otherwise. Ten minutes here saves a confidentiality problem later.
- Is there a DPA? If the vendor cannot produce a data processing agreement, treat the tool as consumer-grade regardless of price.
- Does it train on my inputs? Find the written commitment, not the settings toggle. "We do not train on your data" should appear in the contract.
- Who are the subprocessors? Get the list. Confirm the model provider behind the tool has terms that match the vendor's promises.
- What is the retention period? Read the current number, confirm you can delete data, and note any legal-hold exceptions.
- How is data encrypted? In transit and at rest, with access limited to authorized people in your org.
- Is there breach notification? A defined window and a named contact, in writing.
- Does the matter need consent? Where client confidences are involved, get informed consent. Engagement-letter boilerplate is not enough under ABA 512.
- Can I anonymize instead? If any answer above is shaky, strip identifiers before the data goes in, or do not put it in at all.
What confidentiality looks like in a legal-specific tool
Tools built for lawyers usually start from the assumption that the data is privileged. That tends to mean a no-train commitment in writing, a data agreement, encryption, access controls, and retention you can configure, rather than a consumer toggle.
Vaquill AI is a legal AI suite for in-house counsel built on that assumption, with a no-train stance on your matter data and source-linked answers over real US opinions and statutes. The point is not that a legal tool is magic; it is that the confidentiality terms are written for client data instead of a general consumer audience. Source-linked answers also matter for accuracy, which is a separate problem from confidentiality: a tool that grounds every claim in a real opinion is the kind of legal AI that avoids hallucinating cases, so you are not chasing made-up citations. Verify any vendor's claims the same way you would verify an AI legal citation before filing, using the steps in we do not train on your data.
If you are weighing ChatGPT against this kind of tool for everyday work, our companion guide ChatGPT for lawyers covers the safe tasks, the citation risk, and the division of labor. For the wider picture of using generative AI in-house, from intake review to first-draft contracts, the same plan-and-terms discipline applies to every tool you bring in.
FAQ
Is ChatGPT confidential for legal work? Not on consumer tiers by default. Free, Plus, and Pro inputs may be used to improve models unless you opt out, and there is no business data agreement. Team and Enterprise are built differently, with a no-train default and admin controls, which makes them a closer fit for client data.
Does ChatGPT train on what I type? On consumer plans (Free, Plus, Pro) your inputs may be used to improve models unless you turn that off in settings. On Team and Enterprise, OpenAI states it does not train on your content by default (OpenAI, 2026). Confirm the current terms, since they change.
Is the ChatGPT Pro plan private enough for client data? Pro is a consumer contract, so the higher price does not buy business data terms. For client-confidential matters, a business plan (Team or Enterprise) with a data agreement is the safer choice. Anonymize or avoid pasting sensitive material on Pro.
Can I use ChatGPT and stay compliant with ABA 512? Yes, with care. You must understand how the tool handles data, match the plan to the sensitivity of the matter, and generally get informed client consent before entering confidences. Boilerplate consent in an engagement letter is not enough under the opinion.
Is turning off training the same as a no-train guarantee? No. An opt-out on a consumer plan is a setting that can change, not a signed commitment. A business plan with a written data agreement gives you a contractual no-train term you can point to, which is what client-confidential work calls for.
What should I never paste into consumer ChatGPT? Avoid client-identifying details, privileged communications, deal-specific terms, and anything covered by a confidentiality obligation, unless you have confirmed the data terms and obtained any required consent. When in doubt, anonymize or use a tool built for legal data.
Is a legal-specific AI tool more confidential than ChatGPT? Often, because its terms are written for privileged data: a no-train commitment in writing, a data agreement, encryption, and configurable retention. Do not take it on faith, though. Verify any vendor's claims the way you would verify a citation.
New legal AI guides, weekly.
Further Reading
ChatGPT for Lawyers (2026): Safe Uses, Real Risks, and Better Tools
Read postLegal AI in Microsoft Word: Contract Review, Redlining, and Research in a Word Add-In
Read postBuilt-In Legal AI Skills: Which One to Run for Each Task
Read postWhat a Legal AI Agent Actually Does: One In-House Task, Start to Finish
Read postHow Legal AI Memory Works: Stop Re-Explaining Yourself Every Session
Read postAI Contract Negotiation (2026): How In-House Teams Negotiate Faster
Read post
Co-Founder & CEO · Attorney
Arshita leads product and strategy at Vaquill, building the legal AI suite that solo, small-firm, and in-house US lawyers use to run a matter end to end.