Guide · For recruiters

What ChatGPT does with the files you upload

A CV attached to a chat does not vanish when the chat ends. Here is what OpenAI's own policies say happens to an uploaded file on each plan — training, storage, Library, deletion — what Claude and Gemini do differently, and the clean-up routine that stops candidate data piling up in places you never look.

Short answer

It depends on the plan, and on two settings most people never open. On ChatGPT Free, Plus and Pro, a file you attach is kept with the chat until you delete it, is also saved to your Library where that feature exists, and can be used to improve OpenAI's models unless you have turned off “Improve the model for everyone” or used a Temporary Chat. ChatGPT Business, Enterprise, Edu and the API are not used for training by default.

Deleting the chat does not delete the Library copy — you remove that separately. Deleted chats are scheduled for permanent deletion within 30 days; Temporary Chats are deleted within 30 days on their own. And no setting changes the first fact: the moment you press upload, a third party holds the candidate's CV. The rest of this page is the detail.

Training: which plans learn from your uploads

“Does ChatGPT train on uploaded files?” has a different answer for each kind of account. As of August 2026, according to OpenAI's own published pages:

Two common mistakes. The training switch is about training only: turning it off deletes nothing and shortens no retention. And a Plus plan you signed up for yourself is a consumer plan, whoever pays; the business defaults apply only inside a Business, Enterprise or Edu workspace your organisation has set up.

Storage: how long an uploaded file stays, and where

Training gets the attention. Storage is where CVs actually accumulate. OpenAI's Chat and File Retention Policies page sets out the following, as of August 2026:

In practice: a CV uploaded in February can still be sitting in your Library in August, and a shared Project called “Q2 shortlist” holds every CV dropped into it for as long as it exists. Storage time is also a legal matter. The GDPR's principles (Art. 5) include data minimisation and storage limitation, and where an AI vendor processes candidate data on your behalf, Art. 28 calls for a contract setting out what the vendor may do with it; the UK ICO's AI and data protection hub carries the regulator's own guidance. In Israel, the Privacy Protection Authority's Amendment 13 guidance lists minimising data you don't need among its suggested basic steps. This guide describes the rules; it is not legal advice.

ChatGPT, plan by plan

The same facts in one table, as of August 2026. Policies change; check the linked sources before relying on a detail.

Plan Used for training by default? How long files are kept Where to delete
Free, Plus, Pro — ordinary chat Yes, unless “Improve the model for everyone” is off (Settings → Data Controls; account-wide) With the chat until you delete it (then permanently within 30 days); the Library copy stays until removed there Delete the chat (not archive), then delete the file from your Library
Free, Plus, Pro — Temporary Chat No Deleted from OpenAI's systems within 30 days; not saved to history; no memories Nothing to delete; removed within 30 days on its own
Files in a custom GPT or Project See your plan's row Until the GPT or Project is deleted, then removed within 30 days Delete the file from the GPT or Project, or delete the GPT or Project itself
Business (formerly Team) No Chats until you delete them, same 30-day window; additional workspace data controls Delete the chat and the Library file; ask your admin what else is configured
Enterprise, Edu, Healthcare No Set by the workspace retention policy (Library files included); transient non-Library files in Enterprise expire after 48 hours Your admin controls retention; delete the chat and file yourself as well

The API (for teams building their own screening tools) is also not used for training by default, per the same enterprise privacy page; its retention terms are documented separately by OpenAI.

Claude and Gemini, briefly

Claude (Anthropic). On the consumer plans (Free, Pro, Max), a chat can be used to improve Claude by three routes: if you allow it in Privacy Settings, if you give the chat a thumbs-up or thumbs-down, or if the chat is flagged for safety review. An Incognito chat is never used to improve the model, whatever your settings. Giving a thumbs-up or thumbs-down also stores the related conversation for up to five years, de-linked from your user ID. Claude for Work and the API are governed by commercial terms. (Source: Anthropic Privacy Center — Is my data used for model training?; see also the Anthropic privacy policy.)

Gemini (Google). Review your Gemini Apps Activity settings. Whatever the provider, the checks are the same: training setting, retention rule, where uploads are listed separately from chats, and whether a business tier exists.

The manual routine: keep uploads from piling up

Everything below uses the tools' own settings and costs nothing but attention. Steps 1–3 are done once per account; steps 4–8 repeat for every CV.

  1. Work out which account you are actually using

    Signed up yourself, free or paid? Consumer plan, consumer defaults. Invited into a Business, Enterprise or Edu workspace by your organisation? Its data controls apply — ask the admin what retention has been configured.

  2. On consumer accounts, turn off model training

    ChatGPT: Settings → Data Controls → Improve the model for everyone → off. It is account-wide, so once is enough. Claude: Settings → Privacy → check the model-improvement setting. Gemini: review Gemini Apps Activity.

  3. If the volume justifies it, move to a business tier

    ChatGPT Business, Enterprise and Edu are not trained on by default, and Enterprise and Edu workspaces control retention — the single change that removes the most uncertainty per CV. Our guide to safe AI tools for small recruitment teams compares the options.

  4. Before each upload, strip the identifiers and rename the file

    Name → [PERSON_1], phone → [PHONE_1], email → [EMAIL_1], address → [ADDRESS_1], LinkedIn and portfolio links → [URL_1]; delete the photo, date of birth and any ID number. Check the header and footer, then File → Info → Inspect Document to clear the document properties. Save as candidate-a.docx, not Dana_Cohen_CV.docx. Full field list: how to redact a CV before using AI.

  5. Open a Temporary Chat for the task

    On a consumer plan this is the best available default — not trained on, not in your history, no memories, gone from OpenAI's systems within 30 days. Copy what you need into your ATS and close it.

  6. When the task is done, delete the chat — don't archive it

    If you used an ordinary chat, delete it: archiving keeps the chat and the file; deleting removes it from your account immediately and schedules permanent deletion within 30 days.

  7. Then delete the file from your Library

    The step almost everyone misses: where Library is available, the uploaded file is saved there too and survives the chat's deletion. Open your Library, find the file, delete it.

  8. Empty Projects and custom GPTs, and sweep monthly

    Files in a Project or custom GPT stay until it is deleted, so when a search closes, delete the CVs from the Project or the Project itself. Once a month, walk through Library, Projects, GPTs and archived chats, and re-read the providers' policy pages — they change.

What the manual routine costs

Per CV
6–10 min5–8 to strip identifiers, 1–2 to delete the chat and Library copy
At 20 CVs a day
≈ 2–3 hoursevery day, before any screening happens
What leaks
The copies you forgota Library file from March, a Project nobody emptied, the name in the file name

Our estimates for a recruiter working carefully; your numbers will differ. The settings take minutes, once. The per-CV part — stripping before the upload, deleting after — is what repeats, and what gets skipped on a busy day.

What this doesn't solve

  • The disclosure itself. Settings can stop training and shorten storage; none takes back the upload. A CV with identifiers left in has been shared with a third party the moment it arrives.
  • Re-identification from the rest of the CV. A unique career path or a small employer can still point at one person with every identifier replaced. Pseudonymised is not anonymous — see pseudonymisation vs anonymisation.
  • Your legal footing. Placeholders and tidy retention reduce what you disclose and for how long. They do not create a lawful basis, write your candidate privacy notice or sign a processor agreement. No tool makes you compliant with anything.
  • PDFs on a protected site, scans and images. The popup's “Protect a file” reads Word, text and text-layer PDFs — the kind you can select text in — and returns a rebuilt PDF that keeps the words and the page breaks but not the layout, fonts, images, columns or tables. A protected site is narrower: a PDF attached there passes through unchanged, so a PDF CV reaches ChatGPT exactly as it arrived. Scanned or photographed PDFs are refused rather than quietly passed — there is no OCR — as are PDFs whose text is Hebrew, Arabic or another non-Latin script. Protect those as .docx, or do the manual steps.
  • Perfect detection. At the moment of upload only the always-on rules run: emails, phone numbers, ID, IBAN and card numbers, http/www links and numeric dates. Names and postal addresses need the popup flow with the optional on-device model, which will miss some. Read the output before you rely on it.

Questions recruiters ask

Does ChatGPT store the files I upload?

Yes. On consumer plans a file uploaded in a conversation is kept with that chat until you delete the chat, and — where the Library feature is available — a copy is also saved to your Library, which survives the chat's deletion. Files added to a custom GPT or Project stay until it is deleted; Enterprise, Edu and Healthcare workspaces follow their own retention policy (OpenAI's Chat and File Retention Policies, as of August 2026).

Does ChatGPT train on uploaded files?

On ChatGPT Free, Plus and Pro, yes by default: chats, including attachments, can be used to improve OpenAI's models unless you turn off “Improve the model for everyone” under Settings → Data Controls or use a Temporary Chat. ChatGPT Business, Enterprise, Edu and the API are not used for training by default. Turning training off does not shorten how long the file is stored.

If I delete the chat, is the uploaded file gone?

Not necessarily. Deleting a chat removes it from your account immediately and schedules permanent deletion within 30 days, but a file saved to your Library stays until you delete it from the Library as well. Archiving deletes nothing. Files inside a custom GPT or Project are kept until the GPT or Project itself is deleted.

Is a Temporary Chat enough for candidate CVs?

It is the best consumer-plan default: not used for training, not saved to your history, no memories, deleted from OpenAI's systems within 30 days, though it may be reviewed to monitor for abuse. The CV still leaves your machine and sits with a third party for up to 30 days, so strip identifiers before you attach it.