You are building a shortlist of acquisition targets. Or checking whether a supplier is about to go under, or reading up on a competitor before a pitch, or looking into somebody you are considering hiring.
You have been careful. Nothing confidential has been pasted in, no documents uploaded, no customer data anywhere near it. The document you are writing never leaves your laptop.
The confidential thing was the question.
What actually happens when ChatGPT searches
Two mechanisms run, and they leak differently.
The query goes out to search providers. OpenAI's own description is direct: "ChatGPT search typically rewrites your query into one or more targeted queries that it sends those providers." Its help centre illustrates this with a biotech researcher asking about drugs targeting CCR8 for cancer. ChatGPT might first search for "CCR8 immunotherapy drug development 2025", then, after reading the results, send a more specific follow-up to other providers, in OpenAI's example "CHS-114 conference 2025".
Read that example as a diagram of your exposure rather than a feature explanation. The system does not send one blurred version of your question. It sends a first query, learns from what comes back, and sends sharper ones. On Enterprise and Edu workspaces OpenAI names Bing as the search engine, and its consumer page also links to Shopify's privacy policy for how a partner may further process queries.
Then pages get fetched. OpenAI publishes the identities its systems use. Crawling for the search index is done by OAI-SearchBot. Fetches triggered by something a user asked are handled by ChatGPT-User, and OpenAI notes that "because these actions are initiated by a user, robots.txt rules may not apply".
What does not go out is worth being equally precise about. OpenAI states it does not share your IP address or any ChatGPT account information with third-party search providers in order to run the search. For Enterprise and Edu, it states that data sent to Bing and to data providers "is disassociated from a user's account", not accompanied by user or account IDs, device IDs, session IDs or IP addresses, and that requests are "sent on behalf of OpenAI and are not connected to a specific customer or user account".
Two things do travel with the query. Approximate location derived from your IP, which OpenAI may share to improve accuracy. And, if Memory is on, content from your memories: OpenAI says the rewrite "may also leverage relevant information from memories to make the query better and more useful".
De-identification protects who asked. It does not protect what was asked
This is the whole point, and it is why "is the tool secure" is the wrong question.
Everything above is a reasonable privacy design. It strips your identity from the outbound request, and does nothing to the subject of the request, because the subject is what the search provider needs in order to return anything.
So the real test is not whether the query can be traced back to you. It is how many parties could plausibly be asking that exact question. For "best CRM for manufacturers", thousands. For a named forty-person engineering business in a niche sector, combined with the words administration, acquisition, litigation or redundancies, considerably fewer. The intent is legible in the string whether or not your name is attached to it, and it is now sitting in a log at a company you have no contract with, governed by their privacy policy rather than yours.
Worth being honest about the other direction too, because it cuts your way. When ChatGPT fetches a page, the request comes from OpenAI's infrastructure, identified as ChatGPT-User. It does not come from your office IP range. Compared with an analyst clicking through a target's website from a corporate connection, browsing through ChatGPT tells the target less, not more. These are two different exposures, and it is worth knowing which one you are actually managing.
The one documented incident, and the right lesson to draw from it
From October 2025 site owners began finding long, conversational strings in their Google Search Console reports, some of them reading like complete ChatGPT prompts. The analyst Jason Packer published the finding on 29 Oct 2025 and worked with Slobodan Manić to reproduce it. They traced the behaviour to a URL being prepended to searches, which Google then tokenised, so the text surfaced in the Search Console data of sites ranking for those tokens. It was covered widely in November 2025. OpenAI acknowledged it, said it affected a small set of searches, and said it had been fixed.
Do not build a policy on a fixed bug. Build it on what the bug revealed: the query leaves the conversation and travels through infrastructure outside your agreement, so when something goes wrong out there, it surfaces in somebody else's analytics rather than in your incident log. That is a property of web search, not a defect, and it will still be true after the next fix.
What to research this way, and what not to
The line is not about sensitivity in general. It is about whether your interest is itself information.
| Research | Reasonable through ChatGPT search? | Why |
|---|---|---|
| Markets, sectors, standards, published pricing, vendor documentation | Yes | The query reveals a topic, not an intention |
| A supplier you already contract with, routine diligence | Usually | Thousands of people ask the same question about a known company |
| An acquisition target before an approach | No | The name plus the question is the deal |
| A named individual, especially where allegations are involved | No | It is also personal data, processed through a chain you have not documented |
| Anything under an NDA where the counterparty's name and the deal type together give it away | No | Confidentiality obligations do not care that you typed rather than told |
| Anything where knowing you are looking would move a price or a negotiation | No | Interest is the leak |
The controls, strongest first
There are more of these than most admins realise, and one of them is widely misunderstood.
| Control | What it does | What it does not do |
|---|---|---|
| Offline web search | ChatGPT uses OpenAI's indexed and cached content instead of live search at request time. OpenAI describes it as designed "to help organizations reduce the chance that web search queries are sent to a live external search provider at request time" | Guarantee coverage, freshness, retrieval of a specific URL, or a citation timestamp |
| Lockdown Mode | Limits browsing to cached content, disables deep research and agent mode, blocks file downloads and live connector access | Change training settings, or prevent prompt injection reaching the model in cached content |
| Workspace Web search setting | An admin turns web search off for the workspace and for GPTs created in it | Apply to third-party GPTs |
| Web search permission by role | Removes search for a named group. Features that depend on it, including deep research and ChatGPT agent, go with it | Exist on every plan. This is role-based access control, so Enterprise and Edu |
| Sites, in deep research | Restrict research to domains you list, or prioritise them while still allowing the wider web | Stop the search mechanism itself where the wider web is still permitted |
| Temporary Chat | Keeps the exchange out of your history and stops Memory being used, which narrows what the rewritten query can contain | Stop the query reaching a search provider |
| Memory off | Removes the risk of your own prior context being folded into an outbound query | Affect anything else about the search |
Temporary Chat is the one to watch, because it is the control people reach for and the one that does the least here. It protects the record inside your account. It does not protect the request leaving it. If a colleague tells you the research was fine because they used a temporary chat, they have solved a different problem.
Offline web search is the serious answer, and it is not self-serve. OpenAI lists it as available for eligible workspaces including certain Enterprise, Edu, Healthcare, Teachers, regulated and federal configurations, with availability depending on plan, contract, workspace configuration and admin settings. Some regulated configurations have it on by default, others need OpenAI to enable it, and in some workspaces it arrives through a Lockdown Mode role. If confidential research is a real part of your work, that is a conversation to have with your OpenAI account team, and it is a reason the tier decision matters. The ChatGPT Business and Enterprise governance gap sets out the rest of what sits on the Enterprise side of the line.
The honest alternatives when the subject is genuinely sensitive
None of these are workarounds. They are what the work looks like when the confidentiality is real.
Bring the material yourself. Collect the filings, the accounts, the site pages and the reports, upload them, and ask your questions of those. No query goes to a search provider, and you keep the part you actually wanted, which was the analysis.
Use sources you already have paperwork with. Deep research can draw on authenticated data services you have access to, connected as apps. A query going to a data provider you already contract with is inside a relationship you have governed. A query going to a general search partner is not.
Split the question. Research the sector, the mechanism, the regulation and the comparable transactions in the tool. Do the named part outside it. Most of the value in that research was never in the name.
Use an adviser. When confidentiality is the deliverable rather than a preference, that is what an engagement letter is for.
Decide the categories in advance. One page: what may be researched in the tool, what may not, and who to ask when it is unclear. A rule invented at the moment of temptation is not a rule. If you do not know what your people are already doing, start with a shadow AI audit, because the account you never bought is where this behaviour usually lives.
The decision in front of you
The documentation here is better than most vendors publish and the controls are real. The honest answer to the question in the title is that browsing is safe enough for the overwhelming majority of what your team looks up, and unsuitable for a specific, identifiable minority.
The test to hand your team is one sentence. Would you be relaxed about this query, rewritten and sharpened, sitting in a third-party search provider's logs?
Three things worth doing this month. Find out which ChatGPT plan the people doing competitor and target research are on, because the controls above mostly live on the managed tiers. If you are on Enterprise, ask your OpenAI account team whether offline web search is available for your workspace and what it would cost you in freshness. And write the one-page category rule, before the deal that makes it urgent.
If the exposure you are worried about runs the other way, a tool reaching into your systems rather than a query reaching out to the web, that is a separate question with separate controls: see ChatGPT's deep research and the HubSpot connector.
Where this fits the rest of the picture is set out in the complete view of ChatGPT and the OpenAI API for UK businesses.
We are an OpenAI Select Partner and a HubSpot Diamond Solutions Partner. We resell nothing, take no margin on your usage, and some of our OpenAI implementation work ends with telling a client to configure what they already pay for rather than build anything. If you want the research workflow designed so the sensitive part never reaches a search provider, request a quote.
Stay Updated with Our Latest Insights
Get expert HubSpot tips and integration strategies delivered to your inbox.




