Skip to article
ELSELAND AI
EN
Play on mobile
Editorial illustration about handling work documents carefully

GPT-6 Astra and Work Files: What Should Stay Private?

GPT-6 Astra data privacy depends on where you use it, what you upload and which tools receive the material. A model name is not a privacy policy. Before sharing a work file, confirm that you are allowed to send it to the exact account, workspace and connected services involved.

Keep passwords, access tokens and information you have no authority to disclose out of the prompt. For other material, reduce the file to what the task genuinely needs. The checklist below is an operational starting point, not legal advice or a guarantee that a workflow meets your organization's obligations.

01

Classify the file before choosing a setting

Start with three questions: who owns the information, who is allowed to receive it, and what harm would disclosure cause? A public brochure, an internal planning note and a customer export deserve different treatment. If the owner or permitted use is unclear, ask the responsible person before uploading; technical access to a file does not establish permission to share it.

A useful first pass is to remove credentials, personal identifiers, confidential prices, unreleased plans and unnecessary individual records. If the task only needs the shape of a spreadsheet, use invented rows with the same columns. If it needs a paragraph's tone, share that paragraph rather than the complete contract. Restricted or regulated material needs the organization's approved process, not a reassuring answer from the model.

02

GPT-6 Astra data privacy starts with the product

For a personal ChatGPT account, the Data Controls FAQ explains the training preference. Turning off Improve the model for everyone keeps new conversations out of model training, but does not remove them from history. The FAQ also distinguishes the separate Codex full-environment training setting. Check the controls for the surface you actually use.

An employer-managed workspace can have its own access and retention rules. Ask the administrator which account, project and connected apps are approved for the file. Do not transfer work into a personal account simply because its interface looks the same. An API application adds another operator: its developer may retain requests or outputs independently of the model provider.

03

Not used for training does not mean not stored

OpenAI's API data controls, checked on September 18, 2026, state that API data is not used for training unless the customer opts in. The same documentation describes abuse-monitoring logs and application state. Default logs can be kept for up to 30 days, with stated legal and safety exceptions.

Zero Data Retention and Modified Abuse Monitoring require eligibility and approval; they are not implied by choosing Astra. Endpoint and feature conditions still matter. For a sensitive workflow, have the owner verify the actual organization settings and every storage component. Do not use an API statement to describe all personal ChatGPT interactions, and do not interpret a no-training setting as a promise of instant deletion.

04

Make a smaller, inspectable copy

Create a working copy and remove information the task does not need. Replace names with neutral labels consistently so relationships remain understandable. A label such as Customer A can still be identifiable when combined with an exact job title, date or unusual event; minimizing details is more than replacing a name.

Check comments, tracked changes, hidden sheets, speaker notes, screenshots and metadata before sharing. A black rectangle drawn over text may only hide it visually. Use an appropriate redaction method, export the result, reopen it and test whether the removed text can still be selected or searched. Keep the original in its approved location and avoid putting sensitive values into the redacted filename.

05

Follow the file beyond the upload button

Draw a simple path: device → application → model provider → connected tool → saved output. Not every workflow has every step, but each recipient needs a reason to receive the data. A search query, a shared project or an external integration can create an additional disclosure even when the original upload was approved.

OpenAI's file-input documentation explains that processing differs by format: PDFs can provide text and page images, while non-PDF documents use text extraction. This describes what the system can process, not authorization to share it. Avoid enabling unrelated tools, and inspect generated excerpts before sending a summary to a wider audience. Summaries can repeat sensitive facts too.

06

Delete the right object, not just the conversation

The ChatGPT retention guide, checked on September 18, 2026, distinguishes chats, Library files and project files. Archiving is not deletion. Deleting a chat does not delete a file that remains in Library; project and custom-GPT files have their own lifecycle. Deletion is generally scheduled within 30 days under the documented conditions, with exceptions.

Before the task starts, name the person responsible for cleanup and identify the copies that must be handled. Include the input, shared links, exported output and any application logs under your control. Follow record-retention requirements rather than deleting evidence that must be preserved. If a secret was exposed, notify the owner and revoke or rotate it as appropriate; removing the chat alone is not a complete response.

07

An upload decision you can explain to a colleague

Proceed only when you can identify the owner, approved destination, minimum necessary content, tool recipients and cleanup policy. If any answer is missing, pause or use synthetic material. This provides a reviewable decision rather than relying on the model to label the file safe.

For a harmless practice exercise, use a description of a public game instead of internal player records. You can explore the game collection without uploading a work document. Elseland AI is a separate destination for playing games, not a privacy tool or an endorsement of any data-handling configuration.

Sources and further reading

  1. Data Controls FAQ

    GPT-6 Astra data privacy starts with the product

  2. API data controls

    Not used for training does not mean not stored

  3. file-input documentation

    Follow the file beyond the upload button

  4. ChatGPT retention guide

    Delete the right object, not just the conversation

Next step

Take a play break

Find a game to explore.Explore games