Ethan Ha

Security3 min read

The ChatGPT Privacy Checklist I Actually Use

By Ethan Ha

The three settings from the video first. Then the rest of the checklist I actually run on a ChatGPT account.

OpenAI moves menu labels sometimes — if a name doesn’t match, search Settings for the words in bold. Paths below are for chatgpt.com on desktop; mobile is the same ideas under the profile / settings menu.

The three from the video

1. Stop new chats training the model

Settings → Data Controls → turn off Improve the model for everyone.

That stops *new* chats from being used to improve the model. It does not magically erase everything you already sent.

2. Audit what it remembers about you

Settings → Personalization → Memory.

ChatGPT now tends to show a Memory summary rather than a complete itemized list of every saved fact. Review what’s there, and delete or correct anything you would not want used going forward (job, health, family, location, passwords-adjacent details).

Deleting or changing Memory does not retroactively scrub past chats. Older threads can still contribute to how the product personalizes replies. For sensitive topics, prefer a Temporary + Unpersonalized chat (step 3) and delete those threads when you’re done.

3. Private conversations: Temporary + Unpersonalized

Start a Temporary Chat, then choose Unpersonalized.

Use this for anything sensitive: it should stay out of your normal history, skip creating memories, and stay out of training. Still don’t paste secrets you can’t afford to leak — no system is perfect.

Full checklist (do these next)

4. Shared links

Settings → Data Controls → manage Shared links (or Linked chats).

Revoke anything you shared publicly that you wouldn’t post on your profile. Shared links can expose whole threads.

5. Connected apps & connectors

Settings → apps / connectors / integrations (wording varies).

Disconnect anything you don’t actively use — email, drive, calendars, coding tools. Connected apps widen what a chat can reach.

6. Custom instructions & personalization text

Settings → Personalization → custom instructions / “about you” fields.

Wipe leftover bios, company names, or “always remember I’m…” lines you pasted months ago.

7. Voice & multimodal leftovers

If you use voice or image upload: treat those like chat text. Don’t dictate passwords, 2FA codes, or ID photos. Delete those threads when you’re done.

8. Export, then delete what you don’t need

Settings → Data Controls → Export data if you want your own archive.

Then delete old chats you no longer need. Export ≠ “OpenAI forgot it overnight” — it’s for *your* copy. Deletion is the cleanup step.

9. Check the right account

Many people have a free personal login *and* a work / ChatGPT Business or Enterprise login.

Privacy defaults differ. Run this checklist on every account you actually use.

10. Browser & device hygiene

  • Sign out of shared computers.
  • Don’t save the ChatGPT password in a browser profile other people use.
  • Skip random “ChatGPT privacy cleaner” extensions — most are unnecessary; some are shady.

What I never paste into ChatGPT

  • Passwords, API keys, private keys, session cookies
  • Full bank / card / government ID details
  • Customer PII from a product you ship (use redacted examples)
  • Anything you’d regret in a screenshot dump

For product / code work, prefer a setup you control — see the security prompt checklist I run before every launch.

Quick re-check (30 seconds)

  1. Improve the model for everyone → off
  2. Memory summary → reviewed (know it won’t scrub old chats)
  3. Sensitive stuff → Temporary + Unpersonalized
  4. Shared links + connected apps → clean

Same skill, different job

Privacy settings are one layer. If you also build with AI: security checklist before launch and AI codes for builders.

Brands: partner with me

Keep reading

← Back to Resources