AI security & privacy · Guide
Where does ChatGPT store your data? Plans, regions and Australian options
Where does ChatGPT store your data? On personal plans, OpenAI stores content in the US and around the world. As at September 2026, new ChatGPT Enterprise and Edu workspaces and approved API customers can store content at rest in Australia, and ChatGPT Business is gaining a region choice. On every plan, the model still processes prompts offshore.
- By
- Elias
- Published
- Last reviewed
- Reading time
- 7 min read
Where does ChatGPT store your data on each plan?
It depends on the plan. On personal plans, OpenAI says content is stored on its own and its service providers’ systems “in the US and around the world”. ChatGPT Business is gradually adding a storage-region choice, while new ChatGPT Enterprise and Edu workspaces and approved API projects can already store content at rest in Australia. The position as at September 2026:
| Plan | Where content is stored | Used to improve models? | Deletion |
|---|---|---|---|
| Free, Go, Plus, Pro | US and around the world | Yes, unless the user turns it off in Data controls | Deleted chats removed within 30 days, unless already de-identified or kept for security or legal reasons; temporary chats held up to 30 days |
| Business | A region chosen at checkout, where that option has rolled out; with a non-US region, a copy of prompts and responses is also kept in the US for a limited time | Not by default | Chats kept until deleted; deleted chats removed within 30 days, with legal and security exceptions |
| Enterprise, Edu | A chosen region for new workspaces, including Australia | Not by default | Owners can set a workspace retention period; deleted conversations removed within 30 days unless legally required |
| API | No regional commitment by default; Australia for approved projects | Not unless you opt in (since 1 March 2023) | Abuse-monitoring logs kept up to 30 days by default |
Sources: OpenAI consumer data, OpenAI enterprise privacy, ChatGPT Business storage, ChatGPT data residency and OpenAI API data controls.
The practical point for a firm is that the plan, not the product name, decides where client information ends up. A staff member pasting a client email into a personal ChatGPT account is on the first row, whatever the firm has bought. Our guide to setting up ChatGPT Business securely covers moving staff onto a managed workspace.
Does data residency mean ChatGPT processes data in Australia?
No. Data residency controls where content is stored at rest, not where the model processes it. As at September 2026, OpenAI offers inference residency, which keeps the model’s processing in-region, only in the United States, Europe and the United Arab Emirates. An Australian ChatGPT Enterprise workspace stores its conversations in Australia but sends prompts offshore to be answered.
The fine print matters:
- What the Australian option covers. Conversations, uploaded files, custom GPTs, memory, image generation and Code Interpreter outputs, plus their backups and replicas.
- What it may not cover. Workspace metadata and name, billing information, user logins, transient processing, and anything sent through connected apps, MCP servers or web search, which follows that provider’s own terms.
- New workspaces only. OpenAI describes residency as set when a workspace is provisioned, so an existing workspace may need to be recreated. Confirm this with OpenAI before planning a migration.
- Business plans. Choosing a non-US region still leaves a copy of every prompt and response in the United States for a limited time for safety, abuse monitoring and enforcement, and the region choice does not include inference residency.
- The API. OpenAI’s Australian endpoint (
au.api.openai.com) offers storage but not processing, requires approval for Modified Abuse Monitoring or Zero Data Retention, and adds a 10% charge for eligible models released on or after 5 March 2026.
How long does OpenAI keep your data?
Usually up to 30 days after deletion, with exceptions. Deleted ChatGPT conversations are removed from OpenAI’s systems within 30 days unless OpenAI must keep them for legal or security reasons, and on ChatGPT Enterprise and Edu, owners can set a workspace retention period so conversations are not kept indefinitely.
The API is more granular. By default, abuse-monitoring logs, which can contain prompts and responses, are kept for up to 30 days. The Responses API stores application state for 30 days by default unless a request sets store to false, and files, vector stores and assistant threads are kept until you delete them. Approved customers can apply for zero data retention or Modified Abuse Monitoring, which exclude customer content from those logs for eligible endpoints (OpenAI).
Does Australian privacy law require data to stay in Australia?
No. The Privacy Act 1988 does not require personal information to stay on Australian soil. It regulates how an organisation handles that information wherever it goes, so location still changes your obligations and your risk.
- Overseas disclosure. Before disclosing personal information to an overseas recipient, an APP entity must take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, and section 16C can make the entity accountable for the recipient’s breaches (OAIC APP 8 guidelines).
- Use or disclosure. The OAIC treats information that stays within your effective control as a use rather than a disclosure, and says entering personal information into a publicly available chatbot discloses it to the chatbot’s owner (OAIC AI guidance).
- Security. Since 11 December 2024, APP 11 states that reasonable steps to protect personal information include technical and organisational measures (Privacy and Other Legislation Amendment Act 2024).
- Best practice. The OAIC recommends that organisations do not enter personal information, particularly sensitive information, into publicly available generative AI tools.
Where data sits is also only part of the question. Which laws can reach it depends on who controls it and under what contract, not only on the data centre’s address. Our plain-English guide to AI and the Australian Privacy Principles goes further.
Which AI services can store or process data in Australia?
Several services can store data in Australia, fewer can also process it there, and the answer often differs by model. This table reflects each provider’s documentation as at September 2026. These lists change every few months, so check the linked source before relying on a row.
| Service | Storage in Australia | Model processing in Australia | Worth knowing |
|---|---|---|---|
| ChatGPT Enterprise or Edu | Yes, for new workspaces | No | In-region processing is offered only in the US, Europe and the UAE (OpenAI) |
| ChatGPT Business | Region choice at checkout rolling out; confirm Australia is offered | No | A US copy of prompts and responses is kept for abuse monitoring |
| OpenAI API | Yes, for approved projects | No | Needs Modified Abuse Monitoring or Zero Data Retention |
| Azure OpenAI in Microsoft Foundry, Standard deployment in Australia East | Yes | Yes, within Microsoft’s Australian geography | Global deployments can process anywhere, and new models reach region-bound deployments last (Microsoft Learn) |
| Microsoft Copilot (Microsoft 365) | Follows your Microsoft 365 data location | Planned for December 2026 | Anthropic models are on by default and excluded from in-country processing (Microsoft Learn) |
| Gemini on Google Cloud (Vertex AI, now documented as Gemini Enterprise Agent Platform), Sydney | Yes | Yes, for the models Google lists for that region only | The global endpoint carries no residency commitment (Google Cloud) |
| Gemini in Google Workspace | No: Workspace data regions are the US, Europe or no preference | No Australian option documented | Content is not used for training outside your domain without permission (Google) |
| Anthropic’s Claude API | No: storage is US only (Anthropic) | No: US or global routing | Anthropic offers other regions, including Australia, through cloud partners (Claude) |
| Claude on Amazon Bedrock, AU inference profile | Bedrock does not store inputs or outputs by default (AWS) | Yes, across Sydney and Melbourne | Only some Claude models are offered through the AU profile; check the current list before you design around one |
Microsoft’s local processing date comes from its Copilot roadmap, which lists December 2026 for Australia.
What should a firm do next?
Decide what level of control each kind of information needs, then pick the service that meets it. A common result is a business AI plan for general work and a tighter option for client files.
- Move everyone onto business accounts. Personal plans store content in the US and elsewhere, and training is on unless each user opts out.
- Decide whether storage or processing is the requirement. Read client contracts and engagement terms for data-location clauses. Some ask for data to be held in Australia without saying whether processing counts.
- If Australian storage is enough, ChatGPT Enterprise with Australian residency may meet it. Set retention and review which connected apps are allowed, because apps and web search sit outside residency.
- If Australian processing is required, look at region-bound deployments on Azure, Amazon Bedrock or Google Cloud, or a private assistant built on one of them.
- Record the decision in your AI policy and privacy policy, and recheck it every quarter.
For example, a 40-person accounting firm whose largest client’s contract requires both storage and processing in Australia might keep ChatGPT Business for newsletters and internal drafting, and use a private assistant for that client’s files. The firm should put those files only into a private assistant whose provider confirms in writing that storage and processing stay in Australia, and ask the same of any private AI service, including ours. We compare the options for legal work in private AI vs ChatGPT for law firms.
This is general information, not legal advice.
