Skip to content
,
ChatGPT · Part 8

Privacy, work rules, and when not to use it

14 min read
Privacy, work rules, and when not to use it, with the official product logo. Editorial illustration for Analytics Made Simple.

Before you paste anything into ChatGPT, check three things: whether your company allows it for that kind of information, whether the account you are using is a work account or a personal one, and whether a person will check the answer before it goes out. ChatGPT is useful, but it is not a legal sign-off, not your company’s official record, and not a way around your company’s rules. Imagine you paste a messy customer email thread into ChatGPT late at night, and the reply sounds just like your best support person. Then you notice it invented a refund policy, and the thread you pasted included a customer’s phone number.

This post closes out Learn ChatGPT from scratch. Earlier posts in the series covered what ChatGPT is, the paid plans, your first few minutes with it, the desktop app, what ChatGPT remembers, using voice, images, and files, and connecting it to other apps. Here we lock in judgment: privacy basics, work rules, when the product is the wrong tool, and a good-enough checklist you can run in thirty seconds before you paste, upload, or connect anything. After this, the site continues with a product map and deeper tutorials. The goal is not fear. It is fewer expensive mistakes.

Privacy in plain English, what actually matters

Privacy talk online often turns into rumor. Keep three separate questions in mind, because people tend to mash them into one:

  1. Who can see this content later? Chat history, shared links, workspace admins, compliance exports, and any third-party apps you connected.
  2. Is this content used to train models? Consumer defaults and business defaults differ, settings can change, and it is worth re-checking Data Controls now and then.
  3. Does my employer allow this data class in this product? That answer lives in company policy, not in a shiny pricing page.

OpenAI’s public materials, its Help Center and enterprise privacy pages, generally describe a split. For many business offerings (ChatGPT Business, Enterprise, Edu, and API (the way your own programs use ChatGPT’s models without the chat window) customers under business terms), inputs and outputs are not used to train models by default. For many consumer or personal plans, content may be used to improve models depending on your Data Controls, often labeled “Improve the model for everyone,” and you can usually opt out. History retention, Memory, shared chats, and connected apps all add extra paths content can travel. None of that replaces a lawyer or a formal review of the data processing agreement (DPA), the contract that says how a vendor may handle your data, for a regulated industry. It is orientation, so you stop treating “I have Plus” as “Legal said yes.”

Controls worth knowing by name

ControlWhat it roughly doesWhy you care
Data Controls / model improvementWhether new chats may train models (consumer side)Lower training exposure if you opt out; still not a work-policy waiver
Chat historyWhether conversations stick in your accountEasier revisit vs less residual content
MemoryFacts that can stick across chatsHelpful until stale or sensitive
Shared linksOther people can open a conversation viewEasy leak if you share the wrong URL
Apps / connectorsThird parties receive context under their own termsYour privacy story now includes their policies too
Workspace admin settingsWhat members may use at workThe real gate for company data

A practical habit: once a quarter, open Settings and write down your Data Controls, Memory status, and connected apps. If you changed jobs, rotate your credentials. If you connected a CRM (the software a company uses to track customers and deals) “just to try it,” disconnect it.

Work rules beat product features

Companies care about data class, retention, logging, who handles the data downstream, and who gets sued if something leaks. ChatGPT cares about being a useful product. Those are different jobs. When they conflict, work rules win if you want to keep your job and your customers.

It helps to translate product language into policy language, because the two do not automatically mean the same thing:

  • “I can log in” is not the same as “this data is approved.”.
  • “Business plan says no training by default” is not the same as “customer contracts allow this software.”.
  • “The model removed the Social Security number from the summary” is not the same as “the number never entered the system.”.
  • “We used a connector with Always ask” is not the same as “write access is gone.”.

If your org has an approved ChatGPT Business or Enterprise tenant, use it for work. If it does not, do not build a shadow AI stack out of personal subscriptions and shared customer exports. Escalate instead. The boring path is the professional one. The same is true for schools and healthcare: Edu or specialized tools may already exist, and freestyle pasting into a personal account is still freestyle pasting, no matter the industry.

A simple data-class ladder for sessions

Data class (examples)Personal Free/Plus habitApproved company workspace
Public marketing copy, your own non-sensitive notesUsually fineFine
Internal non-secret drafts (generic process notes)Only if policy allows personal toolsPrefer company tenant
Customer names, tickets, contracts, pricing sheetsNo, unless explicitly allowed (rare)Only on approved paths and scopes
HR raw files, health, finance identifiers, secretsNoUsually specialized systems or heavy review
Credentials, keys, full card numbers, government IDsNeverNever in chat; use vaults and proper workflows

The upload ladder and the connector ladder from earlier posts in this series sit underneath this table. If the data class is forbidden, no amount of clever prompting makes the paste okay.

When ChatGPT is the wrong tool

Using ChatGPT for everything is how teams get fluent and reckless at the same time. The cases below are high-signal stop signs, not anti-AI slogans. They are moments where the shape of the job does not match the shape of the tool.

1. You need ground truth from systems

Revenue this week, inventory on hand, who owns account X, whether invoice 4412 is paid: those live in databases, warehouses, CRMs, and finance systems. ChatGPT can help you write the SQL (the standard language for asking a database questions), explain a schema (the layout of the data), or draft a ticket. But it cannot be the source of truth. Ask “what was our annual recurring revenue (ARR) in Q2?” with no connected, trusted system behind it, and you get a confident answer with no way to trace where it came from. Query the system first. Then use the model to help make sense of what you found.

2. You need licensed professional advice

Law, medicine, tax, regulated financial advice, and many compliance judgments require a licensed human who owns the risk. The model can explain concepts, outline questions to ask a professional, and help you organize documents. It should not be the final medical plan, legal strategy, or tax filing position you “just go with.” If the stakes are personal health, immigration, criminal exposure, or real money, pay for real advice.

3. You need offline, private-only handling

Some data must not leave a controlled network or device: air-gapped research, certain government work, some merger clean rooms, some clinical environments. Cloud chat is the wrong shape for any of that. Use local tools, an approved virtual desktop infrastructure (VDI), a locked-down computer you reach remotely, or vendor products that match the control package your org requires. Turning off training is not the same as never sending the data anywhere.

4. Policy bans personal AI, or this vendor

If the handbook, InfoSec page, or your manager says no personal generative AI for company data, that is the answer. Debating the model’s quality misses the point. Use the company-approved stack or get a written exception. Shadow tools create data flows nobody logged, and Security cannot defend those in an audit.

5. You need to ship code without review

Coding help from a desktop coding mode, or any agent that edits repositories, can speed up your work. But it does not replace tests, code review, threat modeling for sensitive paths, or ownership of the change. “Green tests the model wrote” is not a merge policy. If you would not merge a junior engineer’s pull request (PR) unreviewed, do not merge an agent’s either. A later post in this series on coding agents will drill into this further. The judgment starts here: no blind shipping.

6. You need real-time, multiplayer collaboration as the main job

ChatGPT can draft an agenda and a document. But it is a weak substitute for a live negotiation, a design workshop with real power dynamics in the room, or a multi-party contract redline where relationships and authority matter. Use shared docs and meetings for the multiplayer layer. Use the model as a prep coach, not as the other party.

The good-enough checklist

Most days you do not need a full risk committee. You need a short gate you will actually use. If you cannot check these boxes, slow down or switch tools.

  • Draft or exploration, not final licensed advice. You are not asking the model to be your lawyer, clinician, or accountant (CPA) of record.
  • You can verify claims against sources you control. Files, dashboards, tickets, or humans who own the fact. If verification is impossible, treat the output as brainstorming only.
  • Stakes are reversible or low. A bad internal outline is cheap. A wrong public statement, wire instruction, medical step, or production deploy is not.
  • You will edit before you send it. Your name is on the email, the PR, or the deck, so read it the way a skeptical manager would.
  • Policy allows the tool and the data class. Correct workspace, correct connectors, no forbidden personal information or secrets.

There is an optional sixth box for agentic or write-capable sessions: you know how to undo or stop the action (recall the message, revert the PR, disconnect the app, kill the run). If “undo” is folklore rather than something you have actually tried, you are not ready to grant “Never ask” permissions.

Worked examples: pass vs fail the gate

Example A: rewrite a blog outline (usually a pass)

You paste your own outline for a public AMS-style post. There is no customer data, you will edit every claim, and the stakes are low. Policy allows personal or company ChatGPT for marketing drafts, so this is good enough. Use ChatGPT, but still fact-check anything that looks like a statistic.

Example B: “summarize this customer dispute and draft a refund email” (often a fail)

The thread has names, order IDs, and payment hints, and your personal Free account is not the approved channel. The draft may invent a refund policy that does not exist. The stakes include money and trust. This fails until you use the approved workspace, strip identifiers or use the ticket tool’s own AI features if it has any, and let a human who owns refunds review it before it sends.

Example C: “what was last month’s churn?” with no data attached (a fail)

There is no ground truth here, so the model will invent a plausible-sounding chart in prose. This fails. Pull the metric from the warehouse or business intelligence (BI) tool first. Then ask ChatGPT to help explain the drivers using the numbers you pasted from that system, and still treat its explanations as guesses to check, not facts.

Example D: a coding agent opens a pull request (a conditional pass)

This passes only if the tests run, a human reviews the diff, secrets stay out of the prompt, and the change sits in a branch you can roll back. It fails if the plan is “merge what the agent did because it looked confident.”

Hallucinations, overconfidence, and your reputation

The model is trained to continue text that looks helpful. Helpful-looking text can still be wrong about citations, APIs, case law, drug interactions, and your internal process. Overconfidence is a feature of the interface, not proof that something is true. Your career risk is not “AI made a mistake.” It is “you forwarded a mistake with your name on it.”

A few habits cut the worst failures:

  • Ask for uncertainty: “List what you are guessing versus what is actually in the file.”.
  • Force empty answers: “If the source does not contain X, write ‘not in sources.’”.
  • Separate draft from decision. Never let the first generation be the last step on something high-stakes.
  • Prefer primary sources for numbers: systems you query, PDFs you opened yourself, humans who own the metric.
  • Watch for policy fiction: invented HR rules, refund policies, or security exceptions that sound official but are not.

Mistakes worth avoiding

MistakeWhy it hurtsReplace with
Treating personal Plus as company approvalShadow IT, training and retention mismatchCompany workspace or written exception
Pasting secrets “just this once”Credentials live in history and maybe moreVaults, redaction, never paste keys
Skipping verification because the tone sounds seniorConfident wrong answers travel farGood-enough checklist every time
Using chat as the warehouseNo lineage, no audit trailQuery systems; use chat for interpretation only
Enabling write connectors for convenienceHard-to-undo actionsRead first; require approvals; least privilege
Ignoring Memory and shared linksStale or leaked contextQuarterly hygiene review
Shipping agent code unreviewedSilent bugs and security holesPull request, tests, and a human owner

A 15-minute privacy and policy drill

  1. Open ChatGPT settings and note the plan type (personal vs workspace).
  2. Find Data Controls. Set model improvement to match your risk comfort on personal accounts. Do not treat that setting as permission for forbidden work data.
  3. Review Memory and delete anything that should not stick around.
  4. Review Apps and connectors. Disconnect the ones you do not use, and confirm write permissions are not set to “Never ask” by accident.
  5. Find your company’s AI policy, or ask IT where it lives, and write three allowed and three forbidden examples for your role.
  6. Print or pin the good-enough checklist near your monitor for a week, until it becomes muscle memory.

What this series covered, and what it did not

Learn ChatGPT from scratch was meant as orientation, not mastery of every surface.

PartFocus
1What ChatGPT is (and is not) in plain English
2Free, Plus, Pro, Business, Enterprise without hype
3Account, first minutes, safe early habits
4Desktop modes: Chat, Work, Codex at map level
5Memory, custom instructions, Projects
6Voice, images, files, upload judgment
7Connectors, apps, write risk, IT policy
8 (this part)Privacy, work rules, when not to use it

This series did not try to turn you into a prompt-engineer influencer, an OpenAI admin, or a production machine learning (ML) engineer. It gave you a stable mental model instead: separate the product from the model from the company. Climb complexity only when the job needs it. Verify against sources you control, and let policy win when the stakes are real.

Where to go after this series

When you finish this series, keep going in this order unless your job forces a different path:

  1. ChatGPT product map: Chat vs Work vs Codex, custom GPTs vs plain chat, the models chooser, and light notes on the API and builder tools. Use this when you keep mixing up product names and surfaces.
  2. ChatGPT everyday tutorial: your first useful weeks of writing, planning, learning, and workplace email, without turning a live agent loose on real, work-critical tasks.
  3. ChatGPT Work tutorial: agentic office work with approvals, multi-step jobs, and when Work beats plain Chat.
  4. ChatGPT Codex / coding tutorial: repos, safe exploration, review, tests, and git-friendly habits, so you never ship blind.
  5. Custom GPTs tutorial: build a simple GPT for a repeating task, covering instructions, knowledge files, and actions at a light depth.

Related AMS paths still apply: Learn for the wider curriculum, the Practical AI and data quality series when you care about pipelines and verification habits, and the Claude and Grok product paths if your workplace standardizes on a different vendor. The judgment in this post transfers no matter the logo: a wrong tool is a wrong tool.

Quick recap

  • Separate “who can see this,” “does it train models,” and “does policy allow this data class.” They are three different questions.
  • Personal plans are not company approval, so use the right workspace for the data you are handling.
  • Wrong-tool cases: ground-truth systems, licensed advice, offline private-only handling, policy bans, shipping code without review, and multiplayer jobs that need humans in the room.
  • Good enough means: a draft rather than licensed final advice, verified against sources you control, reversible stakes, edited before it sends, and cleared by policy for both the tool and the data.

Series notes

This is Part 8, the closing post, of Learn ChatGPT from scratch. Next: the ChatGPT product map, then the everyday, Work, Codex, and Custom GPTs tutorials.

Sources

Privacy defaults, plan names, and admin screens change. Re-check official pages before you write policy or train a team.

Written by

Jose S

Founder & Lead Analyst · Analytics Made Simple

Hands-on data strategist, analytics engineering lead, and educator. Writing practical, no-fluff guides to help everyday teams, analysts, and engineers master SQL, AI systems, and modern data architectures.

Keep going

Same lessons in your feed

Short diagrams, hooks, and weekly tutorials on Substack, Instagram, X, and Facebook.

Google Search Prefer our practical guides in Google Search & Top Stories: