Guide
Is It Safe to Upload Confidential Documents to ChatGPT or Other Cloud AI?
You have a contract you don't fully understand, a stack of client files, or a lease with a clause that worries you — and an AI chat window that would happily explain it. The question is whether the document should go into that window at all. The honest answer: it depends on the provider's published policies, on the tier of service you're actually using, and on the duties attached to the document. For a lot of documents, the safest answer is to never upload them anywhere — and that no longer means going without AI help.
What actually happens when you upload a document to a cloud AI
Mechanically, an upload means the full document leaves your device and lands on the provider's servers, where it is parsed, processed, and — for however long the provider's retention policy says — stored. The connection is almost always encrypted in transit, but encryption in transit protects the trip, not the destination. What happens at the destination is governed by the provider's own published terms and data-usage policies, and those documents are worth reading before your file is in them. A few patterns show up across the industry, stated openly in providers' own policy pages:
- Retention. Conversations and uploaded files are typically stored until you delete them, and several providers state that deleted content may persist in their systems for a further window — often around 30 days — before it is fully removed, with exceptions for legal or safety reasons.
- Training. Several major providers state that content from consumer-tier accounts may be used to train or improve their models unless you opt out. Business and enterprise tiers usually carry stronger commitments — but those commitments generally do not apply to a personal account, even if your employer has an enterprise contract.
- Human review. Policies commonly reserve the right for employees or contractors to review conversations, for example when content is flagged for safety or abuse.
- Legal process. A provider can be compelled to preserve and produce user data. This is not hypothetical: in 2025 a US federal court ordered a major AI provider to preserve user conversations — including ones users had deleted — as potential evidence in a copyright lawsuit.
None of this means cloud providers are doing anything secret. It's the opposite: these practices are disclosed in the policies most people click past. The real question is whether the duties attached to your document are compatible with them.
The questions to ask any cloud AI before uploading anything sensitive
This guide deliberately makes no claims about any specific vendor's current policy — policies change, and yours is the account that matters. Instead, here is the checklist. Every answer should come from the provider's own published documentation, not from a sales page or a forum post. If you can't find a written answer, treat that as your answer.
| Question | Why it matters |
|---|---|
| Is my content used to train models, and is that the default? | Opt-out defaults mean your document may already be in the pipeline before you find the setting. |
| How long is content retained after I delete it? | "Deleted" in the interface and "gone from the provider's systems" are different events, sometimes weeks apart. |
| Can employees or contractors read my conversations? | Human review clauses matter enormously for privileged or regulated material. |
| Does the no-training commitment apply to my tier? | Enterprise promises rarely extend to the free or consumer account you're actually logged into. |
| Where is my data processed and stored? | Jurisdiction affects which laws, subpoenas, and transfer rules apply. |
| Will the provider sign a DPA or BAA if I need one? | If you handle patient or regulated personal data, a service that won't sign is off the table regardless of its features. |
| What happens under legal hold? | Courts can order preservation of user data — including content you believed was deleted. |
Special duties: client files, board papers, patient records — and your own lease
Some documents carry obligations that make the checklist above more than due diligence:
- Client files. Lawyers owe duties of confidentiality, and several bar associations have published guidance on generative AI that turns on exactly the questions above — training use, retention, and who can see the material. An NDA-covered document has the same shape of problem: a cloud provider is a third party, and most NDAs don't carve one out.
- Patient records. In the US, uploading protected health information to a service that hasn't signed a business associate agreement is a compliance problem in itself, before any question of what the service does with the data.
- Board papers and deal documents. Unannounced financials and material non-public information have no business on infrastructure you don't control and can't audit.
- Your own documents. A lease, an offer letter, a medical report, a settlement agreement — these are "only" personal, but they contain your salary, your address, your health details, and often other people's too. You don't need a bar card to have a good reason to keep them off someone else's servers.
The alternative that makes the question moot: AI that never uploads the document
Every question above exists because the document leaves your device. There is now a class of on-device AI where it simply doesn't — the model, the index, and your questions all run locally, so there is no provider policy to audit because there is no upload.
This is what our app, OpenIntelligence, is built for. It ingests PDFs, Office and iWork documents, spreadsheets, scans, notes, and even audio recordings; indexes them on your iPhone, iPad, or Mac; and answers questions about them with tappable citations back to the source. Retrieval, verification, and answering all run on the device — you can put the device in airplane mode and it keeps working. There's no account to create and no API key, and the App Store privacy label reads "Data Not Collected" — a claim you can verify yourself on the store listing.
The honest fine print, stated up front: OpenIntelligence requires iOS, iPadOS, or macOS 26 or later and Apple Intelligence-capable hardware — an iPhone 15 Pro or later, or an iPad or Mac with an M1 chip or later. It's free to download, with a one-time Lifetime unlock and Pro subscriptions for the full feature set.
Worked example: asking questions about a contract, on-device
Here's what the workflow looks like with the document that started this article — say, your lease:
- Import the PDF. Add the lease from Files, iCloud Drive, or the share sheet. If you want proof that nothing leaves the device, turn on airplane mode first; indexing and answering work the same either way.
- Let it index. The document is parsed and indexed locally — scanned pages go through on-device OCR.
- Ask a real question. "How much notice do I have to give before moving out, and what happens to my security deposit?"
- Tap the citations. The answer arrives with citations pinned to the clauses it came from. Tap one and you land on the exact passage — the notice provision, the deposit terms — so you're reading your lease's actual words, not a paraphrase you have to take on faith.
- Verify, then act. For a high-stakes document, the citation is the product. You confirm the answer against the source in seconds, which is exactly what you can't do with a confident paragraph of unsourced summary.
The same loop works across a whole folder of documents at once. For a step-by-step version, including the airplane-mode test, see how to chat with a PDF offline.
Why "I don't know" is a feature
With confidential documents, the failure mode professionals actually fear isn't a missing answer — it's a fluent, confident, wrong one. A hallucinated notice period or an invented indemnity clause is worse than no answer, because it reads exactly like a right answer.
OpenIntelligence is built to abstain: when retrieval and verification can't support an answer from your documents, it says so instead of improvising. Ask your lease about subletting when the lease has no sublet clause, and the useful response is "your documents don't answer this" — not a plausible-sounding clause that doesn't exist. Under the hood this runs on an open-source, 29-step retrieval-and-verification pipeline built on Apple's foundation models; the design goal is that every claim in an answer either carries a citation you can tap or doesn't get made.
When on-device isn't enough
An honest guide has to mark the boundaries, and on-device AI has real ones:
- Your hardware may not qualify. The Apple Intelligence floor is real: an iPhone 14, a base-model iPad without an M-series chip, or an Intel Mac can't run this class of on-device model. If that's your situation, the fallback is the checklist above plus minimization: redact identifiers, excerpt only the clause you need, and prefer a business tier with written no-training commitments.
- Your organization's rules may prohibit any AI processing. Some firms' policies and DLP rules bar processing client material with any AI tool, local or not, or on personal devices at all. Architecture doesn't override policy — ask before you process other people's confidential material.
- Redaction still matters downstream. On-device processing protects the document, but if you paste an AI-generated summary into an email, the summary carries whatever it carries. Confidentiality is a property of the whole workflow, not just the tool.
- Some jobs may want a bigger model. On-device models are smaller than frontier cloud models. When iOS and macOS 27 arrive (expected September 2026), OpenIntelligence will add optional support for Apple's Private Cloud Compute for the final synthesis step — strictly opt-in, per request, and only after showing you the exact payload before anything is sent. Today, every route runs on-device, full stop.
This is comprehension help, not legal advice
Nothing on this page — and nothing any AI tells you about a contract, medical record, or legal document — is legal, medical, or financial advice. On-device AI is a way to read and understand your own documents privately, with answers you can trace to the source. For decisions that matter, take what you learned (and the cited clauses you found) to a qualified professional.
That's the fair summary of the whole question. Uploading confidential documents to cloud AI isn't categorically unsafe — but it's only as safe as policies you have to read, trust, and re-check. Keeping the document on your device replaces that trust exercise with an architecture you can test yourself, airplane mode included. You can read more about how OpenIntelligence approaches this on the homepage, or just try it on a document you'd never upload.