Start with the purchased surface
| Surface | Evidence to open | Do not assume |
|---|---|---|
| ChatGPT business workspace | Plan, workspace controls, order form and current business terms | That API endpoint controls or ZDR eligibility apply. |
| OpenAI API | Organization, project, endpoint, data-control approval and request trace | That a ChatGPT workspace setting governs API traffic. |
| Consumer ChatGPT | Consumer terms and account settings | That business no-training or enterprise controls apply. |
| Embedded legal product | Legal vendor agreement, model provider role and complete subprocessor path | That the law firm contracts directly with OpenAI. |
| Astra | Current official availability and future product terms | That existing API or ChatGPT controls transfer before launch. |
No training is one field, not the whole confidentiality answer
OpenAI states that business data is not used to train its models by default and that API data is not used for training unless the customer explicitly opts in. Preserve the operative agreement, eligible account and any data-sharing settings. Separate customer content from feedback, telemetry, account data and information sent to third-party services.
A no-training rule does not answer how long abuse-monitoring logs or application state persist, who may access flagged content, how files are deleted, where data is processed or which downstream systems keep a copy. Keep those questions as separate rows in the decision record.
Read the API retention table endpoint by endpoint
OpenAI’s current technical documentation says abuse-monitoring logs may include prompts and responses and are retained for up to 30 days by default, unless longer retention is required by law or otherwise permitted under the documentation. The endpoint table then separates abuse monitoring from application state and ZDR eligibility.
| API pattern | Documented state | Buyer check |
|---|---|---|
| Chat Completions | 30-day default abuse monitoring; no application state except documented features | Project setting, files, audio and cache exceptions. |
| Responses | 30-day default abuse monitoring and, when stored, at least 30-day application state | store, background mode, tools, files and cache behavior. |
| Conversations and threads | Objects can remain until deleted and are not universally ZDR eligible | Deletion owner and lifecycle test. |
| Files and vector stores | Stored objects have separate deletion and retention behavior | Expiry, deletion evidence and downstream copies. |
Treat ZDR and MAM as approved configurations
OpenAI says Zero Data Retention and Modified Abuse Monitoring require prior approval and acceptance of additional requirements. Approved customers can configure controls at organization or project level. ZDR excludes customer content from abuse-monitoring logs and changes store behavior for certain endpoints, but endpoints and capabilities marked ineligible may still keep application state.
Preserve the approval, organization and project identifiers, selected mode, model and endpoint, effective date and exception notices. Do not describe the whole OpenAI account as ZDR because one project has the setting. A production trace should show which project processed the request.
Inventory application state and feature exceptions
The Responses API, conversations, background mode, prompt caching, files, vector stores, image or audio inputs and other features can create different state. OpenAI’s documentation also notes that severe-risk safety retention and certain legal requirements can change the ordinary path. The correct record therefore names the endpoint and every enabled capability.
Run a non-sensitive canary test: submit, inspect stored objects, export where supported, delete, wait the documented interval and verify the observable result. State what the test proves and what remains outside customer visibility. A successful canary is route-specific evidence, not proof that no backup or exception exists.
Follow data sent to tools and third parties
OpenAI’s API documentation says remote MCP servers and other network services are third parties whose retention policies apply to data sent to them. The same principle applies to search, connectors, observability, ticketing and the firm’s own middleware. Record the tool owner, transmitted fields, purpose, access, retention and deletion path.
Tool authority also matters. Restrict destinations and credentials, validate arguments and log approvals. A model response or tool-call proposal is not authorization to send client material or alter a system.
Review residency and human access for the exact product
Business security pages may describe controls available to eligible products or plans. Confirm the purchased surface, region, support route and contract rather than generalizing a vendor-wide statement. Ask when provider personnel may access content, which events trigger review, what is logged and what evidence the customer can receive.
Do not claim that a business agreement or technical control automatically preserves privilege or satisfies a jurisdiction’s professional rules. Preserve the facts for the assigned lawyer: parties, purpose, confidentiality duties, access restrictions, location, incident path and firm controls.
Close with a route-specific approval packet
- Name the workflow, data classes and prohibited inputs.
- Identify the exact ChatGPT plan, API organization and project, or embedded vendor route.
- Attach the operative agreement and current product documentation.
- Record endpoint, model, features, tools, storage and logging.
- Test permissions, export, deletion and incident contact with non-sensitive data.
- Name the human reviewer, system of record and rollback owner.
- Set a review trigger for product, endpoint, model, contract or feature changes.
Match the OpenAI surface to the legal job
Research, drafting, document analysis and agentic action do not create the same control problem. A research workflow needs source freshness, citation inspection and a place to record the authority the lawyer actually relied on. Drafting needs controlled precedent, redline review and a prohibition on silent changes to material protections. Document analysis needs an omission sample and a reproducible way to inspect the underlying text. Agentic work adds tool authority, destination, logging and stop conditions.
Record one approved job rather than a general permission to use ChatGPT. Name the input, transformation, output, system of record and accountable reviewer. The model may support the task, but the legal team remains responsible for the final work and the underlying authority.
Treat account administration as a control
Confirm who can invite users, create projects, issue keys, enable data sharing, add connectors and change retention settings. Use managed identities and least-privilege roles. Remove access when a user changes role, and test offboarding for the workspace, API project and any connected service. Personal accounts and shared keys make the evidence path difficult to reconstruct.
For API work, separate development, test and production projects. Apply spend limits, service accounts and tool permissions to the environment that will process approved data. A screenshot from an administrator console should record the organization, project, date and reviewer; it should not be treated as permanent proof because settings can change.
Measure pricing and lock-in at the completed-task level
OpenAI plans, API prices, model availability and included features can change. Open the current official pricing and order form before a decision rather than copying a historical seat or token price. Record usage, cache, files, tools, retries, support and reviewer minutes for the workflow. A lower token rate can still produce a more expensive completed task if it increases retries or legal review.
Exit planning belongs in procurement. Test whether prompts, files, outputs, configuration and audit records can be exported in a usable form; identify which custom GPTs, tool schemas, retrieval indexes or application code would need replacement. Keep source material and approved precedent in firm-controlled systems so model or vendor migration does not require rebuilding the legal record.
Decide when a managed workspace is enough
A business workspace can suit bounded drafting, analysis and research when its administrator controls, file handling and review path match the job. An API application can provide tighter routing, structured outputs, tool restrictions and firm-side logging, but it also makes the firm responsible for architecture, security, testing and operations. An embedded legal product can add domain workflow and support while creating another contract and subprocessor layer.
Choose the smallest route that produces the required evidence. Do not build custom infrastructure only to imitate a managed feature, and do not choose a managed interface when the workflow needs enforceable tool permissions or system integration it cannot provide. Preserve the reason, rejected alternatives and review date.
Use rejection conditions, not enthusiasm
Test representative and adversarial cases with the same sources and review rubric. Reject or restrict the route when it invents authority, misses a material issue, exposes an unapproved tool, stores data outside the recorded path, prevents usable export, or increases review time beyond the accepted threshold. A polished answer is not a compensating control for one of those failures.
Keep successful and failed cases in the evaluation record subject to the firm’s retention policy. Note whether the result was generated, reviewed, approved and used. Re-test after a model, endpoint, tool, connector, contract or material configuration change.
Preserve source versions and change notices
Public documentation is a living source. Record the page URL, checked date, relevant section and customer-specific document that supports each approved control. Subscribe the named owner to material product, model, endpoint and contract notices. When a page changes, compare the exact field rather than re-approving the vendor from memory.
Link changes to affected workflows. A new model may require regression without changing retention; a new tool may change third-party processing without changing the base model. Keep the release event, impact analysis, decision and reviewer in the same change record.
The bottom line
ChatGPT can support research, drafting, document analysis and controlled agent workflows, but the brand name does not answer the data question. Approve one bounded route, not “OpenAI” in general. Keep accuracy, confidentiality, retention, tool authority and legal review as separate decisions.
FAQ
Does OpenAI train on law-firm API data?
OpenAI says API data is not used to train models unless the customer explicitly opts in. Confirm the operative account, agreement and data-sharing settings.
Does OpenAI API have zero data retention by default?
No. OpenAI documents up to 30 days of abuse-monitoring retention by default for many endpoints. ZDR and MAM require approval and have endpoint and feature limitations.
Does ChatGPT Enterprise use the same retention controls as the API?
Do not assume that it does. ChatGPT business workspaces and API organizations are separate surfaces with their own plans, settings and documentation.
Can OpenAI data controls establish privilege protection?
No. They provide facts for legal review. Privilege and professional-duty conclusions depend on the workflow, agreement, facts and jurisdiction.
Sources checked
- Data controls in the OpenAI platform, checked 2026-09-03.
- Business data privacy, security and compliance, checked 2026-09-03.
- Services Agreement, checked 2026-09-03.
- Path to Astra, checked 2026-09-03.
Operational information, not legal advice. Verify current terms, account configuration and applicable professional duties before use.