Is It Safe to Upload Your Notes to ChatGPT?
Uploading your own class notes to ChatGPT is low risk once you opt out of training. Where the setting lives, how long data is kept, and what never to upload.
For notes you wrote yourself, yes, once you change one setting. On a personal ChatGPT account, OpenAI may use what you submit, attached files included, to improve and train its models unless you opt out under Settings and then Data Controls. Turn that off and the residual risk to your own lecture notes is small. The real caution belongs to material about other people.
That answer holds for the ordinary case and breaks in a few specific ones, which is what the rest of this page is for: where the opt-out actually lives, how long a conversation survives after you delete it, what Temporary Chat changes, why FERPA is usually the wrong law to reach for when the notes are your own, and the short list of material that should not go into any AI tool. If your worry is reliability rather than privacy, then how accurate ChatGPT is for studying covers that separately and is not rehashed here.
Does ChatGPT train on the notes you upload?
On a personal account, by default, yes. The OpenAI policy on how your data is used to improve model performance sets out that content submitted through the consumer ChatGPT product, which includes the files you attach, may be used to improve and train models unless you turn that off. Free, Plus, and Pro personal accounts all start in that state. Nothing undisclosed is happening here. The documented default is simply the permissive one, and most students never look at it.
Two things follow, and students tend to get them wrong in opposite directions.
- Training is not publication. Content used to improve a model does not become searchable, and no other user can pull up the file you attached. The exposure is statistical and indirect: what you submitted may shape a future model rather than be served back to a stranger verbatim.
- Indirect is still not zero. Once material has gone into a training run it cannot be unpicked afterwards, which is why this is a decision to make before you upload rather than one to regret later. Nothing about the setting is retrospective.
How do you turn it off, and what does the toggle not do?
Three steps, roughly ten seconds. Open Settings. Go to Data Controls. Turn off the option named “Improve the model for everyone”. The OpenAI Data Controls FAQ is where to confirm the current label, because interface wording moves and older guides describe menus that no longer exist.
What the toggle does is narrower than the name implies, and the two limits matter more than the switch itself.
It only works forward. Switching it off stops new conversations from being used for training. It reaches back into nothing and deletes nothing, so a term of chats you had before flipping it stays under the terms that applied at the time. If old conversations are the thing bothering you, the setting is not the fix.
It governs training, not storage. Opting out and deleting are separate actions, and treating them as one is the most common misreading of this control. Even with training off, OpenAI retains new chats for up to 30 days for abuse and safety review before removing them. That window applies to everyone, which is worth internalising: no consumer setting makes an upload disappear on the spot.
What does Temporary Chat change?
Temporary Chat is a separate mode rather than a variation on the training setting, and it is the closest thing a personal account has to a clean slate. A conversation held in it never appears in your chat history, is never used for training, and is automatically deleted from OpenAI systems within 30 days regardless of what your Data Controls say.
The practical use is narrow and worth knowing. If you have one file you are uneasy about, say a document that quotes a classmate or carries a name you would rather not hand over, a Temporary Chat is the right container for that single session. It also stacks with other features: ChatGPT Study Mode runs inside a Temporary Chat, so a tutoring session on sensitive material does not have to be a trade between the two.
The cost is that nothing carries over. You lose the thread, the context, and any ability to return to it tomorrow, so it suits a one-off rather than a revision habit you build across a semester.
Personal ChatGPT is not the same product as Team, Enterprise, or the API
Most of the contradictory advice online comes from this confusion. People assert that ChatGPT does not train on your data, and they are describing a business workspace or a developer platform, not the account a student signs up for. ChatGPT Team and Enterprise workspaces are excluded from training by default, with no toggle to hunt down, because the exclusion is contractual rather than optional.
| Aspect | Personal account (Free, Plus, Pro) | Team, Enterprise, or the API |
|---|---|---|
| Training on your content | On by default until you opt out yourself | Excluded by default, nothing to switch |
| Where the control lives | Settings, then Data Controls | No student-facing control to find |
| Retention of new chats | Up to 30 days for safety review, even with training off | Up to 30 days by default for abuse monitoring |
| Who is actually on it | Almost every student using ChatGPT | Workspaces, plus the apps built on top of OpenAI |
The API deserves its own line, because it is what almost every third-party study app calls rather than the consumer chat app. Inputs and outputs sent through the OpenAI API have been excluded from training by default since 1 March 2023, and are used to train or improve models only when a customer explicitly opts in. Retention is not zero, though: the API keeps inputs and outputs for up to 30 days by default for abuse monitoring, and zero data retention is a separate enterprise-only arrangement rather than something that applies automatically. So a study tool built on the API sits under a stricter training default than the chat window you would otherwise paste into, and under the same 30-day storage reality.
Does uploading class notes break FERPA?
Almost certainly not, when the notes are your own, and the precision matters, because plenty of pages overstate this badly. FERPA is a United States federal law protecting education records held by an institution: grades, transcripts, disciplinary files, and the official record a school keeps about a student. It governs disclosure by the school and requires consent before those records go anywhere.
Notes you took yourself in a lecture are not education records held by your institution. Uploading them is not a FERPA event, and any warning that frames it as one has confused the student with the registrar. The law becomes live when the file contains something other than your own work:
- A roster, a group-project sheet, or a seminar list that names other students alongside anything identifying about them.
- Written feedback about a specific classmate, or any comment tying a named person to a result.
- Grade data, marks, or an assessment record belonging to the institution rather than to you.
If you are a teaching assistant, a demonstrator, or an instructor handling records about other people, that is exactly the situation FERPA was written for, and a personal ChatGPT account with no data agreement behind it is the wrong destination. For a student revising from material they wrote themselves, the live question is model training, not federal law.
The uploads that actually deserve caution
Strip the legal framing away and a simple filter is left: the risk scales with how much of the file belongs to somebody else. Your own annotated chapter on the Krebs cycle is not a privacy problem in any meaningful sense. These are:
- Anything clinical. Case notes, patient details, or ward material from a nursing or medical placement, even with a name removed, since a rare presentation plus a date plus a site can identify a person on its own.
- Other people who did not choose this. A shared document with classmate contact details, a peer review naming an individual, or interview transcripts from research where the participants consented to a defined use that did not mention an AI vendor.
- Anything under an obligation. Placement material covered by a confidentiality agreement, unpublished work belonging to a supervisor, or an employer document that came home with you from a part-time job.
The fix is usually not abstinence but redaction. Replace names with letters, remove dates and locations, cut the identifying particulars, and upload the concepts you actually need questions on. A study set generated from a de-identified version tests you on the same material and carries none of the exposure, which is a better trade than either extreme.
Do the same rules apply to other AI study tools?
No, and assuming they do is how people get caught out. Every tool sets its own defaults, and the two variables that matter are whether your content trains a model and which jurisdiction it is stored in. DeepSeek is the clearest illustration of the second point, since its own policy places user data and uploaded files in China, which is the reason several governments restricted it on official devices, and the specifics sit in the walkthrough on studying with DeepSeek. That is a policy question, not a quality one, and it is answered before you install rather than after.
At the opposite end sit local-first tools that never send anything anywhere. Obsidian keeps notes as plain files on your own device, which is the strongest privacy position available and the reason it keeps appearing in any honest roundup of AI note-taking apps for students. The trade is capability: a tool that sends nothing to a model cannot generate anything with one. Pick per file, not per principle.
Where GeniusPal stands, and where it does not
Since this site sells an upload-your-notes product, the policy should be stated plainly rather than implied. The GeniusPal privacy policy says: “The content you upload is stored securely and used only to generate your study sets. It stays private to your account. We do not use your content to train any model, and we do not share it with other users.” Uploaded material is kept while the account is active, and deleting the account removes personal data within a reasonable period, except where legal or accounting obligations require otherwise.
Now the part a marketing page would leave out. GeniusPal is a small product, not an enterprise platform with a compliance department and a signed data agreement waiting for your institution. Generation runs through the OpenAI API, which means uploads land under the same default 30-day retention window as any other API caller, and the training exclusion described above rather than a private arrangement. A privacy policy is a promise about conduct, not a technical guarantee about infrastructure, and that distinction is true of every tool in this category, this one included.
Which leads somewhere unglamorous but correct. The honest position is not that one product is a vault and the rest are not. It is that a personal ChatGPT account trains on your uploads until you tell it to stop, that nothing you send anywhere disappears immediately, and that a cautious student keeps material they would not want to leave their control out of all of it. Do those three things and the remaining question is just how well you use the tool, which is a far more interesting problem than whether you were allowed to open it.
Frequently asked questions
Is it safe to upload your notes to ChatGPT?
For notes you wrote yourself, it is reasonably safe once you change one setting. On a personal ChatGPT account, free or paid, OpenAI states that content you submit, including the files you attach, may be used to improve and train its models unless you opt out under Settings and then Data Controls. Switching off the option to improve the model for everyone stops future conversations being used that way. It does not delete what is already in your history, and it does not mean instant deletion either, because OpenAI retains new chats for up to 30 days for abuse and safety review before removing them. The bigger question is not the setting but the contents. Your own lecture notes carry very little risk. A file holding other people, patient details from a placement, or material you are obliged to keep confidential is a different decision entirely.
How do you stop ChatGPT from training on your uploads?
Open Settings, go to Data Controls, and turn off the option named Improve the model for everyone. That one toggle stops new conversations, and the files attached to them, from being used to train or improve OpenAI models. Two limits are worth understanding before you rely on it. First, it works forward only: conversations already sitting in your history stay under the terms that applied when you had them, so flipping the switch today does not reach back through last term of chats. Second, opting out of training is not the same as opting out of storage. OpenAI still keeps new chats for up to 30 days for abuse review before deleting them. If you want a conversation that never enters your history and is never used for training at all, use Temporary Chat, which is removed from OpenAI systems within 30 days whatever your Data Controls setting says.
How long does ChatGPT keep files you upload?
Longer than clearing a chat suggests, and 30 days is the number to hold onto. Even with model training switched off, OpenAI retains new conversations for up to 30 days so they can be reviewed for abuse and safety, then deletes them. Temporary Chat behaves the same way behind the scenes: nothing appears in your history and nothing feeds training, but the conversation still sits in OpenAI systems for up to 30 days before it is automatically removed. The OpenAI API, which is what most third-party study apps call rather than the consumer chat app, carries the same default of up to 30 days of retention for abuse monitoring. Zero data retention exists as a separate enterprise arrangement rather than a default anyone gets. So treat any upload as something that lives somewhere for about a month, not something that vanishes the moment you delete the thread.
Does uploading class notes to ChatGPT violate FERPA?
Almost certainly not, when the notes are your own. FERPA is a United States federal law covering education records held by an institution: grades, transcripts, disciplinary files, and similar official records. It governs what a school may disclose about a student and requires consent before those records are released. Notes you took yourself in a lecture are not education records held by your institution, so uploading them is not a FERPA event, and any page telling you otherwise has overstated the law. FERPA becomes relevant when the file contains something else: a roster naming other students, written feedback about a specific classmate, grade data, or confidential institutional material. If you are a teaching assistant or an instructor handling records about other people, that is precisely the situation the law was written for, and a personal ChatGPT account is the wrong place for it. For your own revision material, the live issue is model training.
Keep reading
- AI & Studying
ChatGPT Study Mode: How to Turn It On and What It Changes
Study Mode makes ChatGPT ask questions, explain in layers, and check your understanding instead of handing over a finished answer. Here is the current way to switch it on across web, iOS, and Android, what to put in your first message, how to feed it your own notes, and the limits OpenAI states itself.
August 2, 2026 · 9 min read - AI & Studying
How Do Teachers Know If You Used ChatGPT?
Teachers rarely rely on one thing. They blend unreliable AI detectors with human signals, and the honest fix is to use AI to learn the material, not to write your work.
July 11, 2026 · 8 min read - AI & Studying
How to Make Flashcards With ChatGPT (Free Prompt)
ChatGPT can turn your notes into flashcards in seconds. Here is a copy-paste prompt for clean term and definition pairs, how to import them into Anki or Quizlet, and why you still skim them first.
July 17, 2026 · 8 min read - AI & Studying
Can ChatGPT Solve Math Problems? What to Know
ChatGPT can solve arithmetic, algebra, and many word problems, but because a plain model predicts text rather than calculating, it can be confidently wrong. Here is when to trust it and how to check.
July 24, 2026 · 9 min read