Guide · checked on 19 September 2026

Can I put client data into ChatGPT?

Personal account · free or paid

You should not.

By default, conversations may be used to train the models; in Copilot and Gemini, some may be read by people. Microsoft and Google write, on their own pages, that you should not put confidential information there.

Recato · any plan

Yes, with a contract.

On every plan, from the cheapest to the most complete, and not only on a business plan: it does not train on your data and it comes with a data protection agreement, for companies and for professionals.

On the business plans of ChatGPT, Copilot and Gemini you can too, provided you buy the right plan and configure it properly. The problem is using the personal account for work, because it is the one within reach.

What they write themselves

“Please don’t enter confidential information that you wouldn’t want a reviewer to see or Google to use to improve our services, including machine-learning technologies.”

“Please don’t enter confidential information that you wouldn’t want a reviewer to see or Google to use to improve our services, including machine-learning technologies.”

Google · Gemini privacy hub
“You shouldn’t provide any confidential or sensitive personal data that you would not want Microsoft to use for purposes explained in this FAQ and in the Microsoft Privacy Statement.”

“You shouldn’t provide any confidential or sensitive personal data that you would not want Microsoft to use for purposes explained in this FAQ and in the Microsoft Privacy Statement.”

Microsoft · Copilot privacy FAQ

Comparison

✕ You should not

Personal accounts

ChatGPTFree, Plus and Pro✕ Trains by default✕ No contract

You can turn training off in the settings. Even so, if you rate an answer with a thumbs up or down, the whole conversation may be used for training. The data protection agreement exists only on the business plans. Deleted conversations leave the systems within 30 days.

Copilotpersonal✕ Trains by default✕ No contract

While signed in; you can turn it off. Conversations are kept for 18 months by default and some are reviewed by people.

Geminipersonal✕ Trains by default✕ No contract

It trains when activity is switched on, which is the default. Some conversations are read by human reviewers and those are kept for up to 3 years, even if you delete them.

Recatoindividual, any plan✓ No training✓ With a contract

Yes. Even on the cheapest plan, it does not train on your data and requests to the model are not kept. Professionals get a data protection agreement; for individuals the same commitments apply, written into the Terms and the Privacy Policy.

✓ Yes, with a contract

Business plans

ChatGPTBusiness and Enterprise✓ No training✓ With a contract

No training by default. Keeping data in Europe is available only on Enterprise and Edu, not on Business.

Microsoft 365 Copilotbusiness✓ No training✓ With a contract

European Union traffic stays within the European Union, with one exception: Anthropic's models, if the administrator enables them. Conversations are kept in the organisation's Microsoft 365, for as long as the administrator specifies.

Geminiin Google Workspace✓ No training✓ With a contract

No training without your authorisation and no human review. The organisation's Workspace contract applies.

Recatobusiness, any plan✓ No training✓ With a PDF to download

Yes. Neither we nor our sub-processors train on your data: it is in the contract. Data is processed in the European Union. Requests to the model are not kept once answered. Conversations remain for as long as the account exists, or you set after how many days (1 to 365) they delete themselves.

What the law says, in a few words

GDPR

Article 28

When you paste a client's personal data into a tool, you hand it to another company. For that to be lawful, that company must process the data solely on your behalf and on your instructions, under a written contract: it is the «processor» of Article 28 GDPR. In personal accounts that contract does not exist, and the provider also uses the conversations for its own purposes. The one answerable to the client is the professional who put the data there.

Lawyers

CCBE guidance, October 2025

Professional secrecy covers everything a lawyer learns in practice, and it extends to everyone who works with them. In October 2025 the CCBE — the council of European bar associations — published guidance on generative AI. The baseline rule: do not enter a client's personal or confidential data without adequate safeguards, such as a contractual duty of confidentiality or non-retention, a data processing agreement, or a system running in an environment the firm controls. It also asks for transparency with the client whenever they might reasonably object. Bars outside Europe set comparable duties — check the rules of your own.

Accountants and other regulated professions

IESBA International Code of Ethics, section 114

The International Code of Ethics for Professional Accountants — issued by the IESBA and adopted by most national accountancy bodies — makes confidentiality a fundamental principle: information acquired through a professional relationship is not disclosed outside it, the duty survives the end of the engagement, and it extends to staff. Auditors, tax advisers, notaries and doctors work under equivalent rules. Pasting a client file into a chat tool with no contract behind it is a disclosure like any other.

Five things you should never paste into an AI chat with no contract

  • Identifying details. Clients' names, tax numbers, addresses and contact details.
  • Sensitive data. Health data, court proceedings or someone's financial situation.
  • Whole documents. Contracts, court pleadings, bank statements, tax returns.
  • Credentials. Passwords for tax, social security or court filing portals.
  • Strategy. That of a case or a deal that is not yet public.

If you really must use a tool with no contract, strip out whatever identifies the person: «Client A» instead of the name, no tax number, no addresses, no dates.

If you have already done it in a personal account, turn training off in the settings, delete those conversations and, if you have a data protection officer, talk to them.

European by default

Recato is built in Portugal and fully compliant with European Union data protection law. The GDPR is not a feature we added for a market — it is the law we were written under, and the EU AI Act applies to us as its obligations come into force.

What that means in practice, rather than in slogans: your data is processed in the European Union; every business plan includes an Article 28 data processing agreement, at no extra cost; we and our subprocessors are contractually barred from training on your data; prompts and answers are not retained by default; and you delete your conversations when you decide to.

Why we built Recato

For those who cannot take the risk

Recato is an AI assistant built in Portugal: it does not train models on your data, it deletes conversations whenever you decide, and the data processing agreement is there to download and hand to your data protection officer. The detail is at Compliance and in data processing agreement (DPA).

You can try it without creating an account. In that trial there is not yet a contract between us: use examples, not real client data.

Sources

This page is for information only and is no substitute for legal advice. Providers' terms change: always check the sources.