
Is It Safe to Put Client Data in ChatGPT? 2026 Rules
By Emily Terrell — Top Coach and Speaker at Tom Ferry International. Licensed since 2016. Closing 70+ deals/year while coaching agents nationwide.
Putting client data in ChatGPT is safe only on accounts that exclude your inputs from model training — ChatGPT Business, Enterprise, Edu, or the API. Personal Free, Go, Plus, and Pro accounts train on your conversations by default. This guide covers the exact account settings, the redaction rule, and the brokerage policy questions to ask.
Key Takeaways
- Safety is a property of your account tier, not of ChatGPT as a product — the same prompt is compliant on one plan and a disclosure risk on another.
- Paying for Plus or Pro buys capability, not privacy. Business, Enterprise, Edu, and API accounts are the tiers excluded from training by default.
- A retention policy is a promise a company makes, and a court can override it — the 2025 New York Times litigation proved that in writing.
- Redaction beats permission. Strip names, addresses, contact details, and financial specifics and you get the same output with none of the exposure.
- Your biggest risk isn’t you. It’s a team member or VA pasting a full CRM export into a free account to clean it up.
What is client data in an AI tool?
Client data is any information a buyer, seller, tenant, or landlord gave you because you’re their agent — names, addresses, phone numbers, email addresses, loan pre-approval amounts, bank statements, divorce or relocation circumstances, and the single most valuable item in the file: motivation. When you paste that into a chat window, you’re transmitting it to a third-party vendor. The question is never whether the vendor is trustworthy. It’s what your contract with that vendor actually says, and whether you have one at all.
There’s a second category agents forget: data that isn’t confidential on its own but becomes identifying in combination. “Seller on Bandera Road” plus “needs to close before the school year” plus “divorce” is a named person to anyone in your market, even with the name stripped.
Why this matters for real estate agents
Volume is the problem. According to NAR’s 2025 Member Profile (August 2025), the typical Realtor completed 10 transaction sides in 2024 with a median sales volume of $2.5 million. That’s ten files of financial and personal information moving through one agent’s hands in a year — and the average agent is now running some portion of that through an AI tool for descriptions, follow-up, CMAs, and marketing copy.
Confidentiality isn’t a preference you can trade for speed. Under the REALTOR® Code of Ethics, the obligation to preserve the confidentiality of client information continues after the transaction closes. Risk guidance for brokerages is direct on this point: don’t put confidential, proprietary, or personal client information belonging to your client, your brokerage, or anyone else into a generative AI platform, because the terms of use on most consumer platforms permit the platform to use what you provide.
NAR’s own legal team has flagged three related traps — accuracy, copyright, and scope. Chloe Hecht, NAR senior counsel, warns that AI platforms are not fully accurate, which makes agent oversight critical, and cautions against using AI to draft contracts, modify standard forms, or give legal advice, since Article 13 of the Code and many state statutes prohibit the unauthorized practice of law.
“Your brokerage doesn’t need an AI policy because AI is risky. It needs one because one team member pasting a CRM export into a free account creates a disclosure you can’t take back.” — Emily Terrell, Tom Ferry Coach
The three-layer safety check
Run these in order. If layer one fails, nothing below it matters.
Which ChatGPT account are you actually typing into?
This is the whole ballgame, and most agents have never checked. OpenAI’s documentation states that by default it does not train on inputs or outputs from business products, including ChatGPT Business, ChatGPT Enterprise, and the API, and that organizations are opted out of data sharing unless they explicitly opt in. Personal accounts work differently: on Free, Go, Plus, and Pro plans, conversations may be used to improve future models unless you turn that off yourself.
The setting lives in Settings → Data Controls → “Improve the model for everyone.” Turn it off. Then understand what that does and doesn’t fix: it’s forward-looking only. Anything already included in a completed training run cannot be pulled back out.
If you have an assistant, a transaction coordinator, or a VA, check their account too. Yours being configured correctly does nothing for the one they opened on a personal Gmail in 2024.
What does the platform keep, and for how long?
Here’s the part nobody in real estate talks about. In May 2025, a federal magistrate judge in the New York Times copyright case ordered OpenAI to preserve and segregate output log data that would otherwise have been deleted — overriding the company’s own 30-day deletion policy for consumer accounts. Chats users believed they had deleted were still there.
OpenAI has since confirmed that obligation ended on September 26, 2025, and that deleted conversations and Temporary Chats are again removed within 30 days, with a limited set of April–September 2025 data still held under legal hold. Enterprise and Edu accounts were carved out of the preservation order throughout. In late 2025 the court went further and ordered production of 20 million de-identified chat logs to the plaintiffs.
The lesson isn’t that OpenAI behaved badly — the company fought the order publicly and largely won. The lesson is structural, and it applies to every vendor you’ll ever use: a retention policy is a promise, and a court can vacate it overnight without consulting you or your client.
What do your brokerage and your license require?
Your platform settings are the floor, not the ceiling. NAR now publishes a brokerage AI policy template covering client and consumer data, MLS content, CRM, transaction documents, and valuations — which tells you that brokerages are actively writing these rules right now, and that a brokerage without guardrails is treating AI as a compliance exposure rather than a productivity tool.
Ask your broker three questions this week: Which AI tools are approved? Who owns the workspace settings? What categories of data are prohibited? If nobody can answer, you’ve found a project — and, if you’re a team leader, a liability sitting on your desk.
This is general information, not legal advice. Confirm your specific obligations with your broker and a licensed attorney in your state.
The redaction rule: what to strip before you paste
The fastest fix isn’t a new subscription. It’s learning that the model doesn’t need to know who the client is to do the work.
Strip these every time: full names, street addresses tied to a name, phone numbers, email addresses, Social Security numbers, loan amounts, pre-approval letters, bank statements, and any sentence describing why the client has to move.
Replace with structure. Instead of “The Hendersons at 1420 Oak Trace need to sell because Mark got transferred to Austin and they’re pre-approved at $520K,” you write: “Seller, relocating for work, 45-day close, mid-$400s range, north-central San Antonio, wants max exposure in 30 days.” You get an identical marketing plan. You transmitted nothing.
Three tests before any paste:
- Could a stranger identify this person from what’s on screen? If yes, cut more.
- Would I be comfortable if this text appeared in a discovery sample? Not “will it” — “would I be comfortable.”
- Does the output actually improve because of the identifying detail? Almost always no. That’s the point.
How I use this in my own business
I close 70+ transactions a year in roughly five hours a week of active management, and AI is doing real work inside that number — listing marketing suites, follow-up sequences, CMA narratives, social content. None of it touches a client’s name.
My workflow has one gate in front of it. Before anything goes into a chat window, it goes through a redaction step that converts the file into a profile: property type, price band, submarket, timeline, seller situation in three words, target buyer. Sixty seconds of work. The prompt library I use is built around those profile fields, which means the redaction isn’t a separate discipline anyone has to remember — the template simply has no field where a name would go. That’s the trick. Don’t rely on judgment at 9pm. Build the system so the unsafe version isn’t available.
The second gate is the account itself. Anyone touching client-adjacent work in my business operates in an approved workspace with training disabled, and the raw client file lives in the CRM and the transaction platform where it belongs — never in a chat thread.
When I demonstrate a full listing marketing suite built in two minutes on stage, the input is a redacted profile. Feet on the desk, coffee in hand — and nothing on that screen belongs to a real seller.
Common mistakes
Assuming the paid plan is the private plan. It isn’t. Consumer subscriptions unlock capability, not a different data agreement. The tiers excluded from training by default are the business, enterprise, education, and API contracts.
Turning off training and calling it done. The toggle is forward-looking. It doesn’t retrieve anything already used, and it doesn’t govern retention, legal holds, or subpoenas.
Uploading the document instead of typing it. Agents who carefully avoid typing a name will drag in a full pre-approval letter, a closing statement, or a CRM export without a second thought. A file upload is the same transmission with more data in it.
Letting the VA operate on a personal account. This is the single most common real exposure I see. Your policy is only as strong as the least-configured account in your business.
Using AI to touch contract language. Separate from privacy, this is a licensing issue. Drafting or modifying contract terms can constitute unauthorized practice of law under Article 13 and state statute. Keep AI on marketing, communication, and analysis — not on forms.
Frequently Asked Questions
Does ChatGPT train on my conversations?
On personal accounts — Free, Go, Plus, and Pro — yes, by default. You can turn it off under Settings → Data Controls by switching off “Improve the model for everyone.” OpenAI states it does not train on inputs or outputs from ChatGPT Business, ChatGPT Enterprise, ChatGPT Edu, or the API unless the organization explicitly opts in.
Is ChatGPT Plus private enough for client information?
No. Plus is a consumer subscription, not a business data agreement. Paying upgrades your capabilities and limits, not the legal terms governing your inputs. If you need client-adjacent data in an AI tool, move to ChatGPT Business, Enterprise, or the API, where exclusion from training is the contractual default rather than a setting you maintain.
Are deleted ChatGPT conversations really deleted?
Under current policy, deleted conversations and Temporary Chats are removed within 30 days. But in May 2025 a court order suspended that policy entirely for consumer accounts, and preserved logs from that period were later sampled for litigation. Deletion is a company policy, not a guarantee, and a court can override it without notice.
What client information should never go into an AI tool?
Names, street addresses linked to a name, phone numbers, email addresses, Social Security numbers, financial account details, loan amounts, pre-approval letters, bank statements, and the client’s reason for moving. Also avoid detail combinations that identify someone indirectly — a street, a timeline, and a life circumstance together are effectively a name in a small market.
Does using AI violate the REALTOR® Code of Ethics?
Using AI isn’t a violation. Disclosing confidential client information to a third-party platform can be, since the confidentiality obligation continues after closing. Accuracy obligations under the Code also apply to AI-generated listing content, and using AI to draft or modify contract language can raise unauthorized-practice-of-law issues under Article 13.
Should my brokerage have an AI use policy?
Yes, and NAR publishes a template brokerage AI policy covering client and consumer data, MLS content, marketing, transaction documents, CRM, and valuations. Without one, every agent makes governance decisions individually — which means your brokerage’s actual policy is whatever the least careful person on the roster decided last Tuesday.
How do I use AI on a listing without exposing the seller?
Convert the file into a redacted profile before you prompt: property type, price band, submarket, timeline, seller situation in three words, target buyer. Build that structure into your prompt templates so there’s no field where identifying data would go. The output quality is identical, because the model was never using the name.
Bring this to your team or event
Emily Terrell speaks at brokerage events, real estate conferences, and team trainings on AI, systems, and social media — the exact playbook in this post, delivered live to your audience. As a Top Coach and Speaker at Tom Ferry International and an active agent closing 70+ transactions a year, Emily speaks from the stage about what’s working right now, not theory. Recent stages include NAHREP and eXp Con.
Book Emily to speak at your next event:
Email: eterrell@yourcoach.com
Phone: (210) 400-9191
Web: coachemilyterrell.com
For real estate agents who want to implement this: Get the weekly real estate prompt library at weeklyrealestateprompts.com or follow @coachemilyterrell on Instagram for daily systems and AI breakdowns.