Skip to content
Pylon Digital

AI security & privacy · Guide

Where does ChatGPT store your data? Plans, regions and Australian options

Where does ChatGPT store your data? On personal plans, OpenAI stores content in the US and around the world. As at September 2026, new ChatGPT Enterprise and Edu workspaces and approved API customers can store content at rest in Australia, and ChatGPT Business is gaining a region choice. On every plan, the model still processes prompts offshore.

Published
Last reviewed
Reading time
7 min read

Where does ChatGPT store your data on each plan?

It depends on the plan. On personal plans, OpenAI says content is stored on its own and its service providers’ systems “in the US and around the world”. ChatGPT Business is gradually adding a storage-region choice, while new ChatGPT Enterprise and Edu workspaces and approved API projects can already store content at rest in Australia. The position as at September 2026:

PlanWhere content is storedUsed to improve models?Deletion
Free, Go, Plus, ProUS and around the worldYes, unless the user turns it off in Data controlsDeleted chats removed within 30 days, unless already de-identified or kept for security or legal reasons; temporary chats held up to 30 days
BusinessA region chosen at checkout, where that option has rolled out; with a non-US region, a copy of prompts and responses is also kept in the US for a limited timeNot by defaultChats kept until deleted; deleted chats removed within 30 days, with legal and security exceptions
Enterprise, EduA chosen region for new workspaces, including AustraliaNot by defaultOwners can set a workspace retention period; deleted conversations removed within 30 days unless legally required
APINo regional commitment by default; Australia for approved projectsNot unless you opt in (since 1 March 2023)Abuse-monitoring logs kept up to 30 days by default

Sources: OpenAI consumer data, OpenAI enterprise privacy, ChatGPT Business storage, ChatGPT data residency and OpenAI API data controls.

The practical point for a firm is that the plan, not the product name, decides where client information ends up. A staff member pasting a client email into a personal ChatGPT account is on the first row, whatever the firm has bought. Our guide to setting up ChatGPT Business securely covers moving staff onto a managed workspace.

Does data residency mean ChatGPT processes data in Australia?

No. Data residency controls where content is stored at rest, not where the model processes it. As at September 2026, OpenAI offers inference residency, which keeps the model’s processing in-region, only in the United States, Europe and the United Arab Emirates. An Australian ChatGPT Enterprise workspace stores its conversations in Australia but sends prompts offshore to be answered.

The fine print matters:

  • What the Australian option covers. Conversations, uploaded files, custom GPTs, memory, image generation and Code Interpreter outputs, plus their backups and replicas.
  • What it may not cover. Workspace metadata and name, billing information, user logins, transient processing, and anything sent through connected apps, MCP servers or web search, which follows that provider’s own terms.
  • New workspaces only. OpenAI describes residency as set when a workspace is provisioned, so an existing workspace may need to be recreated. Confirm this with OpenAI before planning a migration.
  • Business plans. Choosing a non-US region still leaves a copy of every prompt and response in the United States for a limited time for safety, abuse monitoring and enforcement, and the region choice does not include inference residency.
  • The API. OpenAI’s Australian endpoint (au.api.openai.com) offers storage but not processing, requires approval for Modified Abuse Monitoring or Zero Data Retention, and adds a 10% charge for eligible models released on or after 5 March 2026.

How long does OpenAI keep your data?

Usually up to 30 days after deletion, with exceptions. Deleted ChatGPT conversations are removed from OpenAI’s systems within 30 days unless OpenAI must keep them for legal or security reasons, and on ChatGPT Enterprise and Edu, owners can set a workspace retention period so conversations are not kept indefinitely.

The API is more granular. By default, abuse-monitoring logs, which can contain prompts and responses, are kept for up to 30 days. The Responses API stores application state for 30 days by default unless a request sets store to false, and files, vector stores and assistant threads are kept until you delete them. Approved customers can apply for zero data retention or Modified Abuse Monitoring, which exclude customer content from those logs for eligible endpoints (OpenAI).

Does Australian privacy law require data to stay in Australia?

No. The Privacy Act 1988 does not require personal information to stay on Australian soil. It regulates how an organisation handles that information wherever it goes, so location still changes your obligations and your risk.

  • Overseas disclosure. Before disclosing personal information to an overseas recipient, an APP entity must take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, and section 16C can make the entity accountable for the recipient’s breaches (OAIC APP 8 guidelines).
  • Use or disclosure. The OAIC treats information that stays within your effective control as a use rather than a disclosure, and says entering personal information into a publicly available chatbot discloses it to the chatbot’s owner (OAIC AI guidance).
  • Security. Since 11 December 2024, APP 11 states that reasonable steps to protect personal information include technical and organisational measures (Privacy and Other Legislation Amendment Act 2024).
  • Best practice. The OAIC recommends that organisations do not enter personal information, particularly sensitive information, into publicly available generative AI tools.

Where data sits is also only part of the question. Which laws can reach it depends on who controls it and under what contract, not only on the data centre’s address. Our plain-English guide to AI and the Australian Privacy Principles goes further.

Which AI services can store or process data in Australia?

Several services can store data in Australia, fewer can also process it there, and the answer often differs by model. This table reflects each provider’s documentation as at September 2026. These lists change every few months, so check the linked source before relying on a row.

ServiceStorage in AustraliaModel processing in AustraliaWorth knowing
ChatGPT Enterprise or EduYes, for new workspacesNoIn-region processing is offered only in the US, Europe and the UAE (OpenAI)
ChatGPT BusinessRegion choice at checkout rolling out; confirm Australia is offeredNoA US copy of prompts and responses is kept for abuse monitoring
OpenAI APIYes, for approved projectsNoNeeds Modified Abuse Monitoring or Zero Data Retention
Azure OpenAI in Microsoft Foundry, Standard deployment in Australia EastYesYes, within Microsoft’s Australian geographyGlobal deployments can process anywhere, and new models reach region-bound deployments last (Microsoft Learn)
Microsoft Copilot (Microsoft 365)Follows your Microsoft 365 data locationPlanned for December 2026Anthropic models are on by default and excluded from in-country processing (Microsoft Learn)
Gemini on Google Cloud (Vertex AI, now documented as Gemini Enterprise Agent Platform), SydneyYesYes, for the models Google lists for that region onlyThe global endpoint carries no residency commitment (Google Cloud)
Gemini in Google WorkspaceNo: Workspace data regions are the US, Europe or no preferenceNo Australian option documentedContent is not used for training outside your domain without permission (Google)
Anthropic’s Claude APINo: storage is US only (Anthropic)No: US or global routingAnthropic offers other regions, including Australia, through cloud partners (Claude)
Claude on Amazon Bedrock, AU inference profileBedrock does not store inputs or outputs by default (AWS)Yes, across Sydney and MelbourneOnly some Claude models are offered through the AU profile; check the current list before you design around one

Microsoft’s local processing date comes from its Copilot roadmap, which lists December 2026 for Australia.

What should a firm do next?

Decide what level of control each kind of information needs, then pick the service that meets it. A common result is a business AI plan for general work and a tighter option for client files.

  1. Move everyone onto business accounts. Personal plans store content in the US and elsewhere, and training is on unless each user opts out.
  2. Decide whether storage or processing is the requirement. Read client contracts and engagement terms for data-location clauses. Some ask for data to be held in Australia without saying whether processing counts.
  3. If Australian storage is enough, ChatGPT Enterprise with Australian residency may meet it. Set retention and review which connected apps are allowed, because apps and web search sit outside residency.
  4. If Australian processing is required, look at region-bound deployments on Azure, Amazon Bedrock or Google Cloud, or a private assistant built on one of them.
  5. Record the decision in your AI policy and privacy policy, and recheck it every quarter.

For example, a 40-person accounting firm whose largest client’s contract requires both storage and processing in Australia might keep ChatGPT Business for newsletters and internal drafting, and use a private assistant for that client’s files. The firm should put those files only into a private assistant whose provider confirms in writing that storage and processing stay in Australia, and ask the same of any private AI service, including ours. We compare the options for legal work in private AI vs ChatGPT for law firms.

This is general information, not legal advice.

Questions

Frequently asked questions

Does ChatGPT store data in Australia?

Only on some plans. As at September 2026, new ChatGPT Enterprise and Edu workspaces can store conversations, files and custom GPTs at rest in Australia, and approved API customers can do the same for API projects. Personal plans store content in the US and elsewhere, and ChatGPT Business is gradually rolling out a region choice. In every case the model still processes prompts offshore.

Does ChatGPT use my data for training?

On personal plans, it can. OpenAI may use content from Free, Go, Plus and Pro accounts to improve its models unless the user turns this off in Data controls. By default, OpenAI does not train on content from ChatGPT Business, Enterprise, Edu or the API. Firms should still require business accounts for work, because they cannot control the setting on a staff member's personal account.

How long does ChatGPT keep deleted chats?

Usually up to 30 days. OpenAI says deleted conversations are removed from its systems within 30 days unless it must keep them for legal, security or safety reasons, and personal-plan chats that were already de-identified can be kept. Temporary chats are also held for up to 30 days. On ChatGPT Enterprise and Edu, owners can also set a workspace retention period.

Does Microsoft Copilot process data in Australia?

Not yet, as at September 2026. Microsoft stores Copilot prompts and responses with your other Microsoft 365 content, but says customers outside the EU may have queries processed in the US, the EU or other regions. Its roadmap lists local processing of supported Copilot interactions in Australia for December 2026. Anthropic models used inside Copilot are excluded from in-country processing commitments.

What is the difference between data residency and zero data retention?

Data residency decides where stored data sits; zero data retention decides whether the provider keeps prompts and responses at all. You can have one without the other. OpenAI, for example, requires API customers who choose its Australian storage option to be approved for Zero Data Retention or Modified Abuse Monitoring, which keep customer content out of its abuse-monitoring logs.

Secure by design. Set up correctly. Fully managed.

Talk to us before you commit to anything

Start with a free 45-minute discovery call. We look at your systems and priorities, then recommend a first step with a fixed scope, or tell you if we are not the right fit.

Book a free 45-minute discovery call