AI Safety Guide

ChatGPT Privacy Center and Security History: a 15-minute privacy checkup

ChatGPT now has a Privacy Center and a log of sign-ins and security changes. Here's what they do, what they don't, and how to use them for a quick, practical privacy checkup.

ChatGPT Privacy Center and Security history privacy checkup

Short answer ChatGPT added two privacy tools in September 2026: a Privacy Center that explains your options and links to the right settings, and a Security history log of sign-ins and security changes. Neither changes anything on its own. A useful checkup takes about fifteen minutes: review memory, decide on model training, check connected apps and plugin permissions, turn on multi-factor authentication and scan your security history for anything unfamiliar.

ChatGPT has quietly become a place where people keep a lot of their lives. It may know your job, your family’s names, your travel plans and, if you have connected them, your email, calendar or health records. That makes the settings behind it more important than they were when it was mainly a chatbot for one-off questions.

In late September 2026 OpenAI added two features that make those settings easier to find. According to OpenAI’s release notes, the Privacy Center began rolling out on September 21 and Security history arrived on September 25. This guide explains what each one does, what it doesn’t do, and how to use them for a practical privacy checkup. It is based on OpenAI’s own help documentation as of September 2026; menus can move, so if a path below doesn’t match your screen, the Privacy Center itself is the best place to start.

What is the ChatGPT Privacy Center?

OpenAI describes the Privacy Center as a hub where you can “learn about your privacy options and find the settings that manage them.” The important word is learn. The Privacy Center is mostly an explainer with shortcuts. The actual switches still live in ChatGPT’s Settings menu; the Privacy Center tells you what they mean and takes you to them.

According to OpenAI’s help article, it groups information into three areas:

  • Personalized chats and ads: memory, personalized ads (for Free and Go users) and location sharing.
  • Chat privacy: how Temporary Chat works.
  • Data use and access: connected apps and their permissions, multi-factor authentication, whether your chats help improve OpenAI’s models, and requests to export or delete your data.

OpenAI says it is rolling out to Free, Go, Plus, Pro and Business users on web and mobile. Enterprise, Edu and healthcare workspaces are excluded, and availability can still vary by region, account status and workspace settings. If you use ChatGPT through an employer’s Business workspace, your administrator may control some of these options.

How do you open the ChatGPT Privacy Center?

OpenAI lists these routes:

Where you use ChatGPTHow to open Privacy Center
WebAccount menu → Help → Privacy center
iPhone and iPadSettings → Privacy Center
AndroidSettings → Privacy center
Desktop appHelp menu → Privacy center, if shown (opens in your browser)

If you don’t see it yet, the feature may not have reached your account. Everything in the checklist below can still be done directly from Settings.

What does Security history show?

Security history is a log of what has happened to your account’s security. OpenAI says it shows “sign-ins, sign-outs, and changes to multi-factor authentication (MFA), passkeys, and other security settings,” with a timestamp, location and device details for each event. On the web you’ll find it under Settings → Security and login → Security history.

This is the feature most people will never think about until they need it. If you get an unexpected “new sign-in” email, or ChatGPT starts showing chats you don’t recognise, the log is how you check whether someone else has been in your account. It is also a quick way to confirm that an old phone or a shared computer is no longer signed in.

Security history is a record, not a lock. It won’t stop anyone signing in. For that you need a strong password and multi-factor authentication, covered in step five below.

Step 1: Review what ChatGPT remembers

Memory is where most personal detail accumulates, and it is more layered than many people realise. OpenAI’s Memory FAQ describes two separate things:

  • Saved memories: details you explicitly asked ChatGPT to remember, or that it saved as useful context.
  • Chat history reference: relevant information ChatGPT draws from your past conversations, which can change over time.

Go to Settings → Personalization → Memory. OpenAI says you can read a memory summary there, “a high-level view of information that ChatGPT may use to personalize responses,” highlight text to correct it, and in some cases choose “Don’t mention this again.”

The detail that catches people out: deleting a chat does not necessarily delete a memory created from it. OpenAI says this plainly and more than once. To remove something thoroughly, it suggests checking several places: the memory summary, saved memories, regular and archived chats, files in your Library and connected apps. OpenAI also says it may keep logs of deleted saved memories for up to 30 days for safety and debugging.

Turning memory off entirely is an option, but understand what it does. OpenAI says switching Memory off does not delete your past chats, and if you turn it back on later, ChatGPT may build new memories from chats still in your history. If you want a genuinely clean slate, delete the old chats too. Our guide to what AI agent memory stores and how to delete it compares how this works across assistants.

Step 2: Decide whether your chats help train OpenAI’s models

This is a personal choice rather than a right answer. The setting is Settings → Data controls → Improve the model for everyone (on mobile, open the sidebar, tap your profile icon, then Settings). According to OpenAI, when it is off, “your new conversations won’t be used to train OpenAI models.”

Two points worth knowing:

  • The switch affects new conversations. It doesn’t delete anything already in your history, including archived and project chats. Those need deleting separately if you want them gone.
  • If you use ChatGPT without signing in, the setting is saved per browser, so it won’t follow you between devices.

Step 3: Use Temporary Chat for sensitive one-offs

Temporary Chat is the simplest privacy tool ChatGPT has, and the one most worth building into habit. OpenAI says temporary chats don’t appear in your history, don’t create or update memories and aren’t used to improve its models. They may be kept for up to 30 days for safety purposes.

A good rule of thumb: if you’re asking about something you wouldn’t want resurfacing in a future answer (a medical worry, a legal dispute, a difficult family situation, a draft resignation letter), start a Temporary Chat. One catch from OpenAI’s documentation: if you save a temporary chat, it becomes a regular chat and follows your normal memory and training settings.

Step 4: Check connected apps and plugin permissions

Connections are where ChatGPT stops being a chatbot and starts acting more like an agent. Each connected account (Gmail, Google Drive, a calendar, a health record) gives ChatGPT something new to read and, sometimes, to act on. That is useful, and it also widens the range of things that can go wrong, including prompt injection, where text in an email or web page tries to steer the AI.

The Health plugin is a good example of why permissions deserve a look. OpenAI’s release notes say that from September 14, 2026, new Health connections default to “Allow low-risk actions,” which lets ChatGPT use connected health data without asking each time. OpenAI’s Health help page lists the alternatives:

Permission levelWhat it means (per OpenAI)
Always askChatGPT asks for confirmation each time
Allow read actionsRead-only access
Allow low-risk actionsThe default for new connections; reads health data for personalisation
Allow all actionsMarked by OpenAI as elevated risk

You can change this under Settings → Plugins → Health. OpenAI says connected health information and related conversations aren’t used to train models or target ads. It also notes that health conversations can create memories when memory is on, and suggests a dedicated project or Temporary Chat if you want to keep them separate. Health is currently limited to US users aged 18 and over on web and iOS.

For every connection, ask three questions: do I still use this, does it need to be able to act or only read, and would I be comfortable if it read the most sensitive thing in that account? If the answer to the first is no, disconnect it. Our broader walkthrough on reviewing apps connected to your accounts applies the same test to Google, Microsoft and others.

Step 5: Lock the front door with MFA or a passkey

All the privacy settings in the world don’t help if someone else can sign in as you. OpenAI’s account security guide recommends turning on multi-factor authentication, noting that “even if someone gets your password, they would still need the second factor.” It also mentions passkeys and hardware security keys for stronger protection. The Privacy Center links to the MFA setup, and the setting lives under Settings → Security and login.

If you signed up with a Google, Microsoft or Apple account, the security of that account matters as much as ChatGPT’s own settings, so check that it has two-step verification switched on too.

Step 6: Scan your security history

Now open Settings → Security and login → Security history and read down the list. You’re looking for things that don’t fit:

  • a sign-in from a country or city you haven’t been in;
  • a device type you don’t own;
  • an MFA or passkey change you didn’t make;
  • a password change you don’t remember.

Location data from sign-ins is approximate, and travel, VPNs and mobile networks can all make a legitimate sign-in look odd. One strange entry isn’t proof of a break-in, but several together, or a security change you didn’t make, deserve action.

What should you do if something looks wrong?

OpenAI’s security guide sets out these steps if you suspect someone has access to your account:

  1. Change your password straight away.
  2. Sign out of every session under Settings → Security and login → Active sessions.
  3. If you use OpenAI’s API, delete any API keys from the API key dashboard.
  4. Go back through Security history for other unfamiliar activity.
  5. Contact OpenAI Support with details of what you found.

Be wary of anyone who contacts you about a ChatGPT security problem and asks for a code, password or payment. Account-takeover scams often begin that way. Our guide to AI agent scams covers the common patterns.

Should you export or delete your data?

Exporting is worth doing once, even if you don’t plan to leave, because it shows you what the account actually holds. OpenAI says Free, Go, Plus and Pro users can request an export in ChatGPT’s settings or through the OpenAI Privacy Portal. Business, Enterprise and healthcare workspace users have to ask their workspace owner.

Deleting your account is also available in settings for personal plans, but OpenAI warns that it is permanent and affects associated data and subscriptions. If you only want to reduce what’s stored, deleting old chats and clearing memories is a gentler first step.

Who needs this checkup most?

Everyone who uses ChatGPT regularly will get something from fifteen minutes in these settings, but it matters most if you:

  • have connected email, files, calendar or health data;
  • share a computer or tablet with family members;
  • use ChatGPT for work and for personal matters on the same account;
  • have used it for months without looking at what memory has collected;
  • signed up with an email and password rather than a secured Google, Apple or Microsoft account.

If you only use ChatGPT signed out, for occasional questions, most of this doesn’t apply. The main setting for you is model training, which is saved in your browser.

Our view on the ChatGPT Privacy Center: useful, but it’s still on you

The Privacy Center and Security history are sensible additions. They collect scattered settings in one place and give ordinary users a way to spot account misuse that previously needed a support ticket. That is editorial judgement, based on OpenAI’s documentation rather than hands-on testing for this article.

What they don’t do is change any default. Memory stays on if it was on, training stays on if it was on, and a Health connection made today still starts at “Allow low-risk actions.” The new tools make good choices easier to find; they don’t make them for you. That’s worth remembering as ChatGPT becomes more agent-like, and as rivals add similar features (we covered the equivalent controls in Meta Muse’s privacy settings).

A 15-minute ChatGPT Privacy Center checklist

  • Open the Privacy Center (web: Account menu → Help → Privacy center).
  • Read your memory summary; correct or delete anything you don’t want kept.
  • Delete old chats you no longer need, remembering that deleting a chat doesn’t always delete a memory made from it.
  • Decide on “Improve the model for everyone” under Data controls.
  • Get into the habit of Temporary Chat for sensitive questions.
  • Remove connected apps you don’t use; set the rest to the lowest permission level that still works.
  • If you use Health, check its permission level under Settings → Plugins → Health.
  • Turn on MFA or a passkey.
  • Scan Security history and sign out of sessions you don’t recognise.
  • Request a data export once, just to see what’s there.

Key takeaways

  • The Privacy Center (from September 21, 2026) explains ChatGPT’s privacy options and links to settings; it doesn’t change anything itself.
  • Security history (from September 25, 2026) lists sign-ins and security changes, with device and location details, under Settings → Security and login.
  • Deleting a chat doesn’t necessarily delete memories created from it; check the memory summary and saved memories separately.
  • New Health connections default to “Allow low-risk actions”; you can change that to “Always ask” or read-only.
  • Multi-factor authentication or a passkey is the single most important protection for an account that holds this much.

ChatGPT Privacy Center and Security history: FAQs

Does the ChatGPT Privacy Center change my settings?

No. OpenAI describes it as a place to learn about privacy options and find the settings that manage them. The switches themselves are still in ChatGPT’s Settings menu.

Where do I find Security history in ChatGPT?

On the web, go to Settings, then Security and login, then Security history. It lists sign-ins, sign-outs and security changes with time, location and device details.

If I delete a ChatGPT conversation, is the memory from it deleted too?

Not necessarily. OpenAI says deleting a chat does not automatically delete a separate saved memory created from it, so check the memory summary and saved memories as well.

Are temporary chats completely private?

OpenAI says temporary chats don’t appear in history, don’t update memory and aren’t used for training, but they may be kept for up to 30 days for safety purposes.

Sources