Check retention before uploading business files: ChatGPT files in Library must be deleted separately from chats.; Microsoft Purview retention policies apply to Copilot, ChatGPT Enterprise and other AI apps.; Deletion in one location doesn't remove copies saved in projects or shared outputs.
Image: AI Tool Review Desk

Data Handling

Part of AI tool privacy and data handling

Reviewing retention settings before uploading business files

Trace chats, uploaded files, projects and compliance copies before deciding whether a business file may enter an AI tool.

Before uploading a business file, identify where the file and interaction are stored, which retention rule applies, and how each copy can be deleted. In Microsoft Purview, check the AI-app location and, for other AI apps, whether a collection policy has the setting to capture content.

For ChatGPT, check chats and files separately. Deleting a chat does not delete a file saved to Library.

Map the file’s locations

Record the account, product, feature and upload route. Note whether the file is attached to a chat, saved in Library or a project, supplied through a connected service, or copied into an output that has been saved or shared elsewhere.

New Microsoft Purview retention policies support these locations: Microsoft Copilot experiences, Microsoft 365 Copilot, Security Copilot, Copilot in Fabric, Copilot Studio, Enterprise AI apps, Entra-registered AI apps, ChatGPT Enterprise, Microsoft Foundry, Other AI apps, ChatGPT, Google Gemini, Microsoft Copilot (consumer version) and DeepSeek. Select the location that matches the intended workflow.

Retention policies for Microsoft 365 Copilot and Microsoft 365 Copilot Chat are separate from Teams chats. Policies include prompts and responses for Microsoft 365 Copilot and Copilot Studio; other Microsoft Copilots and generative AI apps are included when a collection policy has the setting to capture content.

Captured prompts include text users type and selected AI-app prompts captured as prepopulated messages. Responses include text, links and references, and Exchange mailboxes store data copied from these messages.

The policy path is Microsoft Purview portal > Solutions > Data Lifecycle Management > Policies > Retention. Compliance administrators decide whether a policy retains content, deletes it, or retains it and then deletes it, and whether its scope is adaptive or static.

For an adaptive policy, create one or more adaptive scopes before creating the retention policy. A policy assigns retention settings at the container level, so confirm that the selected location and scope cover the account and workflow used for the upload.

AI app locations supported by Microsoft Purview retention policies

  1. Microsoft 365 CopilotYes – separate retention for prompts and responses
  2. Microsoft Copilot (consumer version)Yes – included under general AI app scope
  3. ChatGPT EnterpriseYes – subject to workspace-specific retention settings
  4. Copilot StudioYes – includes prompts and responses
  5. Google GeminiYes – only if collection policy captures content
  6. DeepSeekYes – only if collection policy captures content
  7. Other AI appsYes – depends on collection policy capture setting

Check what deletion means

In ChatGPT, delete an individual chat or clear ChatGPT history to remove conversations from the account. Deleted chats are removed from the account immediately and scheduled for permanent deletion within 30 days, unless they have been de-identified and disassociated from the account or must be retained longer for legal or security reasons.

Delete a ChatGPT file separately from its chat: use Settings > Storage or Library. Files deleted this way are scheduled for permanent deletion within 30 days; deleting the chat that contains a file does not delete a copy saved to Library.

For a file in a project or connected service, and for an output saved or shared elsewhere, identify the relevant location and who controls deletion there. Do not assume that removing a chat deletes copies held in those locations.

Microsoft Purview retention can retain or delete messages for compliance reasons. Verify backend retention with eDiscovery tools rather than relying on messages visible in the AI app.

Decide before uploading

For a ChatGPT Enterprise workspace, ask the administrator which retention duration applies. Confirm the account type and settings in use; retention rules can depend on the account and configuration.

For Microsoft workflows, ask the compliance administrator which Purview location, policy scope and retain-or-delete action apply. If you are not an administrator, contact your help desk, IT department or administrator; confirm whether a collection policy captures content when using other AI apps.

Ask who can delete the chat, file, project item, connected-service copy and saved or shared output, and who can use eDiscovery to verify retained messages. Record why each file class needs to be uploaded and what deletion route applies to every copy; hold the file back if a material copy or route cannot be explained.

Pre-upload checklist for business files in AI tools

  1. Identify file locationCheck if file is in chat, Library, project, connected service, or shared output.
  2. Confirm retention policyVerify if the account uses ChatGPT Enterprise or Microsoft Purview policies.
  3. Determine deletion rightsConfirm who can delete the chat, file, project item, or shared copy.
  4. Record retention rationaleDocument why the file is uploaded and what deletion path applies to each copy.
  5. Hold back if unclearDo not upload if a material copy or deletion route cannot be explained.

More from Data Handling

Data Handling

AI tool integration

Trace a task from source to approved result, then assess browser, workflow, connector and API routes, including permissions and failures.