OpenAI Data Retention Update: Response to New York Times Litigation
OpenAI has ceased the indefinite retention of consumer ChatGPT and API content following the expiration of a legal order on September 26, 2025. While standard 30-day deletion cycles have resumed for new data, OpenAI continues to securely store a limited set of historical user data from April through September 2025 to meet ongoing legal obligations related to a lawsuit by The New York Times.
Data Retention Status and Current Policies
As of October 22, 2025, OpenAI is no longer under a legal order to retain consumer ChatGPT and API content indefinitely. The following retention policies are now in effect:
- Deleted ChatGPT Conversations and Temporary Chats: Automatically deleted from OpenAI systems within 30 days.
- API Data: Automatically deleted after 30 days.
OpenAI maintains that these policies align with industry privacy norms and their own internal commitments to users.
Historical Data Hold (April–September 2025)
Despite the expiration of the general retention order, The New York Times continues to demand the preservation of specific user data from the period of April to September 2025.
OpenAI is securely storing this limited historical data under a legal hold. This data is managed under the following constraints:
- Access Control: Accessible only to a small, audited OpenAI legal and security team.
- Usage Restrictions: Used exclusively for meeting legal obligations; it cannot be used for any other purpose.
- Disclosure Status: OpenAI has explicitly stated that this data will not be turned over to The New York Times, the Court, or any other party at this time.
Scope of Impacted Users
The legal demands for data retention impacted different user tiers differently:
- Impacted Users: ChatGPT Free, Plus, Pro, and Team subscribers, as well as OpenAI API users (excluding those with Zero Data Retention agreements).
- Non-Impacted Users:
- ChatGPT Enterprise and ChatGPT Edu customers.
- API customers utilizing Zero Data Retention (ZDR) endpoints under a ZDR amendment.
Legal Context and Privacy Arguments
OpenAI COO Brad Lightcap characterized the demands from The New York Times as a "sweeping and unnecessary demand" and an "overreach" that risks user privacy without aiding the resolution of the lawsuit.
To challenge the order, OpenAI took the following actions:
- Motion for Reconsideration: Filed a motion arguing that the preservation of "all output data" was overbroad and breached privacy norms.
- Court Clarification: Secured a clarification from the Magistrate Judge on May 27 that ChatGPT Enterprise data was excluded from the preservation order.
- Appeals: Filed appeals with the District Court Judge to overturn the retention requirements.
Training and Privacy Protections
OpenAI stated that the legal retention orders did not alter their fundamental training policies:
- Business Customers: Models are not trained on business data by default.
- Consumer Customers: Users retain control over whether their chats are used to improve ChatGPT via account settings.