Is It Safe to Upload Bank Statements, IDs, and Photos to ChatGPT? What Actually Happens to Your Files

Try the free tool
Rotate PDF →Rotate all pages or selected pages of a PDF by 90, 180, or 270 degrees. The rotation is saved permanently into the file - free, no upload, everything in your browser.
Every week, millions of people drag a bank statement, a tax form, or a photo of their driver's license into ChatGPT and ask it to "check this" or "summarize the numbers." Most never read what happens next. This guide walks through the actual mechanics — where the file goes, how long it stays, whether it trains future models — and then goes document-by-document through the risk, ending with a practical workflow you can use today.
Quick answer
Uploading a document to ChatGPT sends the file to OpenAI's servers. Files shared in personal (free and Plus) chats may be retained for ~30 days by default and can be used for model training unless you turn that off in Settings → Data Controls. That means the honest rule is: fine for documents you'd be comfortable emailing a stranger's help desk; not fine for anything with account numbers, full ID images, or medical records unless you redact first.
Try Rotate PDF — free, no sign-up, and it runs entirely in your browser.
Where your file actually goes
When you attach a file to a chat, three things happen:
- The upload. The file is transmitted to OpenAI's servers and stored there — this is the fundamental difference from browser-based tools, where processing happens on your own machine.
- The retention window. OpenAI's published policy has held that files in consumer chats are retained for around 30 days before deletion (enterprise plans differ, with stricter defaults).
- The training question. Consumer-plan conversations have historically been eligible for model training by default, with an opt-out toggle in Settings → Data Controls ("Improve the model for everyone"). Team/Business/Enterprise plans do not train on your data by default. Policies change — check your plan's current terms before relying on any of this.
The nuance most people miss: deleting the chat from your history does not necessarily pull the file out of the retention pipeline immediately, and "retention" and "training eligibility" are separate systems. Turning off training does not delete anything; deleting a chat does not promise exclusion from a training set already created.
Risk by document type
| Document | Risk level | What's actually exposed | Safer approach |
|---|---|---|---|
| Bank statements | High | Account numbers, balance, transaction history, address | Black out account numbers, or summarize the numbers yourself |
| Tax documents (W-2, 1099, returns) | High | SSN, income, employer, dependent details | Remove SSN and employer EIN before uploading |
| Driver's license / passport | High | Full ID-number, DOB, address — identity-theft starter kit | Don't upload full IDs; crop to just the part you need explained |
| Photos of yourself | Medium | Face biometrics tied to your chat content | Prefer describing the question; avoid bulk photo dumps |
| Resume / CV | Medium-low | Phone, email, address, employment history | Trim contact header first if just asking for writing feedback |
| Medical records | High | Diagnoses, IDs, insurance numbers (extra-sensitive category) | Redact identifiers; consider whether you need AI at all here |
| Contracts / NDAs | Medium | Confidential or legally binding clauses | Check confidentiality clauses first; many prohibit third-party processing |
| Homework / essays | Low | Originality only — but see training-note below | Fine for feedback; fine for most users |
| Code (non-proprietary) | Low | Logic, not personal data | Fine; enterprise repos deserve enterprise plans |
The redaction workflow that takes two minutes
Before uploading anything from the high-risk rows:
- Make a copy. Never redact your only original.
- Remove, don't cover. PDF viewers that "cover" text with a black box often leave the real text underneath — select-and-delete or use a proper redaction tool that actually strips the text layer.
- Scrub the metadata too. Photos and PDFs carry hidden metadata — author names, creation timestamps, sometimes GPS coordinates from the phone that photographed the document. This is the step almost everyone forgets.
- Upload the cleaned copy only.
For step 3, you can use our free Metadata Washer: drop in a JPG, PNG, or PDF, see every metadata entry it carries (GPS, author, software), and strip it all — entirely in your browser, with no upload, so the act of checking doesn't itself leak the file.
What about "temporary chat" mode?
ChatGPT's temporary-chat option doesn't save the conversation to your history and doesn't train on it — but the file still transits and is processed on OpenAI's servers during the session, and short-term retention for abuse monitoring still applies. It reduces the training and history footprint; it does not make the upload local. If a document is sensitive enough that you're relying on temporary mode, it's sensitive enough to redact first.
A simple decision rule
Ask yourself one question before any upload: "Would I mind if this file were stored on a stranger's server for a month?"
- If yes, obviously fine — upload away.
- If no: redact the sensitive fields, strip the metadata, then upload the cleaned copy.
- If the whole document is sensitive (medical, legal, full ID): describe the problem in words instead of attaching the file. You'll often get 90% of the value from a good description.
The tools that process files locally — your operating system, offline editors, and browser-based utilities that never transmit the file — are the right home for anything you wouldn't hand to a stranger. AI chat is phenomenally useful; it's just useful to you, on your terms, when you control exactly what it sees.
Try it with a free tool
Want to skip the manual work? Our free Rotate PDF works right in your browser — no signup, no uploads, and it works equally well on desktop and mobile.




