Short answer
Before connecting sensitive apps, know which permissions are shared, what a Dot keeps, and which actions still need your approval or takeover.
Permissions follow your ChatGPT connections
A Dot can use plugins you have already connected in ChatGPT, ChatGPT Work, or Codex, within the permissions you granted. Manage plugin and data access in ChatGPT’s Plugins tab; those permissions are shared across all four experiences. OpenAI privacy and safety FAQ
Proactive research has narrower tools
A Dot may review permitted connected sources before you ask and save private notes. Its proactive research tools cannot directly send messages, change content through plugins, or control a browser or computer. Any later action must follow the usual action rules and safety checks. OpenAI privacy and safety FAQ
Memory and Dot context are related, but distinct
A Dot can receive memories and recent conversation context from ChatGPT, and its conversations can contribute to ChatGPT Memory. Turning Memory off stops that sharing but does not delete information already received. Dot context can retain conversation and plugin context while you keep the Dot; it does not retain credentials, images, or screenshots. You currently cannot inspect or edit individual Dot memories. OpenAI says content is encrypted in storage and in transit. OpenAI privacy and safety FAQ
Disconnecting and deleting have limits
Disconnecting a plugin stops new access through that connection, not context already built. Resetting the Dot deletes its conversations, saved memories, and scheduled tasks. It does not delete separately stored files, Codex threads, or ChatGPT conversations the Dot created; other ChatGPT memories remain in Memory settings. Files saved elsewhere follow that location’s retention rules. See the permissions guide for reset steps. OpenAI privacy and safety FAQ
Training depends on the plan and setting
OpenAI says Business, Enterprise, and Edu workspace data is not used to train its models by default. On personal plans, “Improve the model for everyone” controls whether Dot conversations and work may be used, including Dot actions, work delegated to other agents, scheduled automations, and connected-app information used in conversations. OpenAI says it does not train directly on proactive research or its notes; information later brought into an eligible conversation or task may be used depending on your settings. OpenAI privacy and safety FAQ
Custom Rules do not replace required checks
Custom Rules can define which supported actions a Dot may take independently, which need approval, or which it should avoid. They cannot disable core safety requirements, Auto-review, or restrictions on proactive research. Some sensitive actions require you to take over; others may ask for approval each time. Advance approval is limited to the action you specifically described. OpenAI privacy and safety FAQ
Review activity and treat outside instructions as untrusted
Activity View shows ongoing and delegated tasks and lets you add context, redirect, or ask the Dot to stop. Websites, emails, and documents can contain malicious instructions; their text does not grant permission. OpenAI describes model safeguards, plugin permissions, Custom Rules, Auto-review, and safety monitoring as layers that reduce risk, but do not eliminate mistakes. OpenAI privacy and safety FAQ
Sign-ins, purchases, and device access
For supported sign-in flows, the Dot pauses while you enter credentials in a secure login form; those credentials go to the browser environment rather than the model. This does not cover passwords shared in chats, documents, or plugins. Security checks may require you to take over. Access to your camera, microphone, or screen requires connecting your computer and granting the ChatGPT app permission in device settings. Purchases using a card saved on a merchant site require approval, which can be given in advance when it specifically covers that purchase. OpenAI privacy and safety FAQ
Availability and human review
OpenAI says Dots are not yet available to users under 18. It also says limited human review may occur in certain cases, including safety-related cases, even when model improvement is off. To request access to, correction of, or deletion of personal information, OpenAI points users to its Privacy Portal or [email protected]. OpenAI privacy and safety FAQ
FAQ
Can OpenAI review Dot activity if model improvement is off?
OpenAI says limited human review may occur in certain circumstances, including safety-related cases.
Can I view or edit individual Dot memories?
No. OpenAI says individual Dot memories cannot currently be viewed, deleted, or directly modified. Deleting the Dot removes its context.
Can I request access to or deletion of personal information?
OpenAI says you can submit a request through its Privacy Portal or email [email protected].