Frequently asked questions - Security
Custom GPT keeps your data until you decide what to do with it. You can use Custom GPT's capabilities to delete your documents immediately after processing. If you choose to keep the documents to benefit from features like citations and links, they'll stay with Custom GPT until you choose to remove them.
No, your business data is not used to train the ChatGPT model. The information you provide when interacting with Custom GPT stays strictly within your specific bot instance and is not incorporated into any OpenAI model training. See OpenAI’s data usage policy: https://openai.com/policies/api-data-usage-policies.
Absolutely. CustomGPT is built on strong privacy principles, ensuring that any information uploaded to a bot remains within that bot's environment, not shared with other bots, even those in the same account. It's important to note that your data will not be incorporated into OpenAI training sets.
No, any data you interact with on CustomGPT is not used to enhance the learning of ChatGPT. It's confined to your specific bot, ensuring your content remains local and private. For further information, you can review OpenAI's data usage policies at : https://openai.com/policies/api-data-usage-policies
Yes
No, the data you share with Custom GPT remains private and is not used to teach or provide insight for others. We have stringent data handling practices in place to ensure your data's security and confidentiality. In fact, the data from one bot within your account has no effect on other bots within even your own account. Each bot is its own data silo.
If you believe there's a security issue or that someone might have gotten unauthorized access to data on Custom GPT, send us an email. Don't worry, we won't share your email with others. We promise to take your concern seriously and will thoroughly investigate the matter.
Custom GPT prioritizes data privacy. We ensure that your business data stays safe by storing it in isolated environments per bot and not using it for any other purposes, including model training.
No, any documents you upload, including an employee handbook, will not be used by OpenAI or contribute to its model training. Your documents remain strictly within the context of your specific Custom GPT bot.
Yes, Custom GPT operates under a DPA. As for data collection, Custom GPT collects minimal user data required for service operation and improvement, in compliance with privacy laws and regulations.
Yes, Custom GPT is designed with a high level of security and ensures that every project is completely isolated from others. This isolation applies even to multiple projects under the same account.
Yes – there is an option to immediately delete the original files after processing. This gives you added protection.
All data uploaded to a bot stays within that silo. It is not even shared with other bots in the same account.
Also, OpenAI has now clarified that they do not use data from API calls in their training (aka: the infamous Samsung issue!). You can see:
OpenAI's data usage page: https://openai.com/policies/api-data-usage-policies
We take data protection seriously at CustomGPT. Our security measures include strong encryption, access controls, and a robust system architecture designed to prevent unauthorized access or data breaches. We are committed to regularly updating and improving our security practices to protect your business data effectively.
The General Data Protection Regulation, a comprehensive data protection law in the EU, governs how organizations must protect personal data and privacy. Custom GPT complies with the GDPR by getting user consent for data collection, protecting user data, allowing users to access or delete their data, notifying users of data breaches, and ensuring third-party vendors also follow GDPR rules. Custom GPT is GDPR ready & compliant
Yes, we can complete a DPA Form to execute our Data Privacy Addendum for you.
Custom GPT, while built on top of the OpenAI's Chat GPT API, operates within its private VPC instance in Amazon AWS US East. This ensures that your data and interactions are segregated and not mixed with the general Chat GPT usage or with other users.
The infrastructure specifics, like the usage of AWS or another cloud service are laid out in our privacy policy: https://www.iubenda.com/privacy-policy/45263214
Yes, CustomGPT is SOC 2 Type II compliant. See our trust center
Entity maintains a record of information security incidents, its investigation, and the response plan that was executed in accordance with the policy and procedure defined to report and manage incidents.
Entity maintains a record of information security incidents, its investigation, and the response plan that was executed in accordance with the policy and procedure defined to report and manage incidents.
This is a general FAQ