Guide
Is it safe to use ChatGPT with client data?
Short answer
Not by default. Whatever a person types into ChatGPT, Claude or any hosted AI reaches that provider, and for a firm bound by client confidentiality that can be a disclosure even if the provider never trains on it. It becomes safer when the identifying data is swapped out before the message leaves, which is what Safe-Desk does.
Updated September 24, 2026 · SOPHIA XT LLC
What happens to what you type
A prompt travels to the AI provider's servers, is processed there, and is kept for some period under that provider's terms. What differs between plans is mainly whether it may be used to train future models and how long it is kept.
Business plans. OpenAI says it does not train on inputs or outputs from ChatGPT Business, ChatGPT Enterprise or its API by default (OpenAI business data). Anthropic says it does not use data from its commercial products, including Claude for Work and the API, for training (Anthropic).
Consumer plans. On free and individual paid plans, both companies may use chats to improve their models unless the user turns that off in settings (OpenAI data controls, Anthropic consumer terms). Staff using personal accounts at work are on these plans.
No training is not the same as no disclosure. The provider still receives the text.
Which rules care
Tax preparers answer to IRC 7216 on disclosing tax return information. Lawyers answer to Model Rule 1.6 and ABA Formal Opinion 512. Tax and accounting firms, mortgage brokers and many others fall under the FTC's Safeguards Rule. SEC-registered advisers answer to Regulation S-P. Each industry page goes through the details: accountants, law firms, insurance agencies, financial advisors.
Medical and dental practices need a Business Associate Agreement with any vendor that receives patient information. Anthropic says its Team and individual plans can't be covered by one (Claude Help Center). Safe-Desk does not sign one either, so it is for everyday office work, not patient information.
How to use AI without sending the data
Swap the identifying values for placeholders before the message leaves, let the AI work on the placeholder version, and put the real values back only for the person who asked. The AI still writes the letter, the summary or the reply; it just never holds the SSN, the account number or the client's name.
Your staff type
Draft an extension reminder for client Dana Reyes, SSN 123-45-6789, EIN 12-3456789. Her 2025 AGI was $84,200 and the refund goes to routing 021000021, account number 4432019876.
The AI sees
Draft an extension reminder for client [NAME_1], SSN [SSN_1], EIN [EIN_1]. Her 2025 AGI was [TAX_FIGURE_1] and the refund goes to routing [ROUTING_1], account number [ACCOUNT_1].
The owner's log
Sep 24, 2026, 2:14 PM UTC: Front desk. The message was sent. Swapped out: Social Security number, Employer ID number (EIN), Bank routing number, Bank account number, Tax return figure, Person's name (detected).
The staff member reads the answer with the real values back in. The log names what kind of data was caught, never the values.
Safe-Desk does this in the browser extension, the Windows app, a chat inside Safe-Desk, a connector for your own Claude or ChatGPT, and an API for your own software. See how it works.
What stays a risk
Safe-Desk does not make a firm compliant on its own and does not certify compliance. It has not been audited for SOC 2. It does not sign a Business Associate Agreement, so it is not for patient information. Names, addresses and dates are caught from your client list and from context; context detection is a best effort, because names have no checksum. Anything your firm sets to Flag is sent as written and reported to the owner.
Facts can identify a client without a name. A detailed account of an unusual matter may still point to one person, so staff judgment and a written policy still matter.
Questions
Does ChatGPT train on what I type?
On ChatGPT Business, Enterprise and the API, OpenAI says not by default. On free and individual plans it may, unless you turn off the setting to improve the model. Check the provider's current terms for your plan.
Is ChatGPT Business or Claude Team enough on its own?
They remove training on your data by default and add admin controls. They do not stop a staff member from sending a client's SSN to the provider, and they do not give the owner a record of what kind of client data went out. Safe-Desk works inside those accounts to do both.
What about using AI with patient information?
You need a Business Associate Agreement with every vendor that receives it. Safe-Desk does not sign one, so it is not for patient information.
Related
- How to stop staff pasting client data into ChatGPTPolicy, approved accounts, a gate in the browser, and a log the owner reads.
- A ChatGPT and AI use policy for small firmsWhat the policy should say, and a one-page sample to copy.
- How Safe-Desk compares with the other ways to keep client data out of AIEnterprise DLP, browser-only extensions, private workspaces and banning AI, side by side.
- SecurityWhat we keep, what we never keep, and every subprocessor.
Try it at your firm.
Start free trialSee how it worksSafe-Desk costs $19 per staff member a month, with a 14-day free trial. Each seat includes $5 of AI a month inside Safe-Desk, pooled across the firm, and AI beyond that is billed at the model's cost plus 30%. Using your own ChatGPT or Claude through the extension or the connector costs nothing extra. Optional setup: we set it up for $149 for up to 10 staff, $10 for each extra person.