Skip to content
For Membership Associations (opens in a new tab)

Security & Privacy Principles

CustomGPT.ai Security and Privacy Commitment

Your data is fully encrypted & files never stored

Data Use & Responsibility

  • Accuracy

    #1 for anti-hallucination technology

  • Data protection

    No training or sharing your data

  • Citations

    Every response has a link directly to its source

Feedback

Your security & privacy are our top priorities

Your data is fully encrypted & files never stored

  • Encrypted in transit and rest

    SSL encryption during transit. Industry-standard 256-bit AES encryption at rest.

  • No data sharing

    Fully-self contained bots with no data sharing between bots, even within the same account.

  • SOC 2

    CustomGPT.ai is SOC 2 Type 2 certified across Security, Availability, and Confidentiality.

  • IdP-Based End-User access

    CustomGPT.ai supports SAML 2.0 authenticated access for external users, allowing organisations to control agent access through their existing identity provider

  • Privacy First

    We never store your files, unless you choose to see them in responses. By default, your chatbot is private, which means only authorized users can query your chatbot.

  • GDPR

    We ensure transparency, control and protection of personal data in alignment with EU regulations

  • Protected

    Data and logs are untraceable back to an individual user

  • Secure vendors

    Best practices from secure vendors like AWS and Stripe.

A CustomGPT.ai dashboard showing a chat widget, agent usage, words stored and traffic by country.

Launch fully-integrated custom AI agents

Increase efficiency, drive revenue, and delight customers with instant answers from your information

Frequently Asked Questions

Does CustomGPT.ai guarantee the confidentiality of my proprietary information?

Absolutely. CustomGPT.ai is built on strong privacy principles, ensuring that any information uploaded to a bot remains within that bot’s environment, not shared with other bots, even those in the same account. Please visit our security principles.

It’s important to note that your data will not be incorporated into OpenAI training sets. For more details, please see their announcement and data usage policy : https://openai.com/policies/api-data-usage-policies.

Is data loaded via CSV completely private, and will it not be used to train the public version of ChatGPT?

Yes, the data loaded into CustomGPT.ai via CSV file remains entirely private. Furthermore, OpenAI has clarified that it does not use data from API calls for training their models. You can read more about this at https://techcrunch.com/2023/03/01/addressing-criticism-openai-will-no-longer-use-customer-data-to-train-its-models-by-default/.

Does data use on CustomGPT.ai end up on OpenAI servers and contribute to ChatGPT’s learning?

No, any data you interact with on CustomGPT.ai is not used to enhance the learning of ChatGPT. It’s confined to your specific bot, ensuring your content remains local and private. For further information, you can review OpenAI’s data usage policies at: https://openai.com/policies/api-data-usage-policies

Will the confidential data I share with CustomGPT.ai be used to learn for other people?

No, the data you share with CustomGPT.ai remains private and is not used to teach or provide insight for others. We have stringent data handling practices in place to ensure your data’s security and confidentiality. In fact, the data from one bot within your account has no effect on other bots within even your own account. Each bot is its own data silo.

How does CustomGPT.ai handle data privacy? Is our business data safe?

CustomGPT.ai prioritizes data privacy. We ensure that your business data stays safe by storing it in isolated environments per bot and not using it for any other purposes, including model training. You can find more about our data privacy policies on our Security and Trust page

Will the client’s employee handbook that I upload to CustomGPT.ai be used by OpenAI?

No, any documents you upload, including an employee handbook, will not be used by OpenAI or contribute to its model training. Your documents remain strictly within the context of your specific CustomGPT.ai bot.

Does CustomGPT.ai have a Data Processing Agreement (DPA), and what data is automatically collected from the user?

Yes, CustomGPT.ai operates under a DPA. As for data collection, CustomGPT.ai collects minimal user data required for service operation and improvement, in compliance with privacy laws and regulations. Detailed information can be found in our privacy policy: https://www.iubenda.com/privacy-policy/45263214

Can I trust CustomGPT.ai to keep my projects secure and isolated from other projects?

Yes, CustomGPT.ai is designed with a high level of security and ensures that every project is completely isolated from others. This isolation applies even to multiple projects under the same account. You can read more about our security measures on our Security and Trust page

Can I delete the files immediately after processing?

Yes – there is an option to immediately delete the original files after processing. This gives you added protection.

I’ve heard of this privacy incident with Samsung. Do I need to be worried?

All data uploaded to a bot stays within that silo. It is not even shared with other bots in the same account. You can see our security principles on our Security and Trust page

Also, OpenAI has now clarified that they do not use data from API calls in their training (aka: the infamous Samsung issue!). You can see:

  1. The announcement here: https://techcrunch.com/2023/03/01/addressing-criticism-openai-will-no-longer-use-customer-data-to-train-its-models-by-default/
  2. OpenAI’s data usage page: https://openai.com/policies/api-data-usage-policies
How can we be assured our business data will be protected and there are no data breaches?

We take data protection seriously at CustomGPT.ai. Our security measures include strong encryption, access controls, and a robust system architecture designed to prevent unauthorized access or data breaches. For an in-depth understanding of how we ensure data protection, please refer to our security principles on our Security and Trust page. We are committed to regularly updating and improving our security practices to protect your business data effectively.

Is our business data used to train the ChatGPT model?

No, your business data is not used to train the ChatGPT model. The information you provide when interacting with CustomGPT.ai stays strictly within your specific bot instance and is not incorporated into any OpenAI model training. See OpenAI’s data usage policy: https://openai.com/policies/api-data-usage-policies.

Are you using the general ChatGPT? Or private instances on Azure?

CustomGPT.ai, while built on top of the OpenAI’s ChatGPT API, operates within its private VPC instance in Amazon AWS US East. This ensures that your data and interactions are segregated and not mixed with the general ChatGPT usage or with other users.

The infrastructure specifics, like the usage of AWS or another cloud service are laid out in our privacy policy: https://www.iubenda.com/privacy-policy/45263214

Does CustomGPT.ai support the GDPR?

CustomGPT.ai supports the GDPR by having policies in place that protect your privacy and data rights. In addition to being GDPR compliant, we are also SOC 2 Type 2 compliant – independently audited by INTERCERT CPA LLC for the period May 24, 2025 to May 23, 2026, report dated July 27, 2026, across Security, Availability, and Confidentiality. See our SOC 2 Type 2 Certification page, or request the report via our Trust Center.

How does CustomGPT.ai comply with the GDPR?

CustomGPT.ai complies with the GDPR by getting user consent for data collection, protecting user data, allowing users to access or delete their data, notifying users of data breaches, and ensuring third-party vendors also follow GDPR rules.

Can I get a DPA?

Customers on our Enterprise plan may complete our DPA Form to execute our Data Privacy Addendum. This agreement is only available for Enterprise customers. Non-enterprise customers are unable to enter into a DPA with CustomGPT.ai. Additionally, CustomGPT.ai cannot customize DPAs for individual cases.

Can I request to download or delete my data?

Complete our Privacy Request Form to request to download or delete all of your data.

How long does CustomGPT.ai retain my data?

CustomGPT.ai keeps your data until you decide what to do with it. You can use CustomGPT.ai’s capabilities to delete your documents immediately after processing. If you choose to keep the documents to benefit from features like citations and links, they’ll stay with CustomGPT.ai until you choose to remove them.

How does CustomGPT.ai handle breach management?

If you believe there’s a security issue or that someone might have gotten unauthorized access to data on CustomGPT.ai, send us an email at ops@customgpt.ai. Don’t worry, we won’t share your email with others. We promise to take your concern seriously and will thoroughly investigate the matter.

Is CustomGPT.ai SOC 2 Compliant?

Yes. CustomGPT.ai is SOC 2 Type 2 compliant. See our SOC 2 Type 2 Certification page for the current audit period and auditor, or request the report via our Trust Center.

Is CustomGPT.ai ISO/IEC 42001 compliant?

Need CustomGPT.ai to be ISO/IEC 42001 compliant? No problem, just let us know. CustomGPT.ai is fully prepared and on track for formal ISO/IEC 42001 certification in the near term.

Is CustomGPT.ai available for private cloud or on-premises deployment?

CustomGPT.ai is a cloud-only service. Private cloud and on-premises deployment are not available.

Start Your First Hallucination-Free Project With CustomGPT.ai