ChatGPT Privacy Center and Security History Explained: Two New Ways to Check Your Account
OpenAI added two account-control surfaces in late September 2026. Privacy Center, from September 21, gathers what ChatGPT does with your data in one place for Free, Go, Plus and Pro users. Security history, from September 25, lists sign-ins and changes to your password protections, with time, location and device.
Related reading
Context for this storyChatGPT Temporary Chat Explained: The New Personalize and Save Controls
OpenAI is rolling out two new controls in ChatGPT temporary chat. You can now start one that uses your memories, custom instructions and plugins, and you can save a temporary chat to your history. Saving converts it into a regular chat, which then follows your account's model-improvement settings.
ChatGPT Computer History Explained: Is ChatGPT Watching What You Do on Your Mac?
Computer History lets the ChatGPT Mac app reference what you have been doing in other apps and websites. It is off by default, limited to Pro, Business and Enterprise, and available in supported regions including the EEA, Switzerland and the UK. It requires Memories everywhere, and stores unencrypted summaries on your Mac.
How to Turn Off Gmail's AI Features (and What Each One Does)
Gmail's AI features are controlled by two settings groups: "smart features in Gmail, Chat, and Meet" and "Google Workspace smart features." Turning both off disables Gemini summaries, Help me write, Smart Compose, and Smart Reply -- but you also lose package tracking, inbox categories, and flight events in Calendar.
OpenAI shipped two account-checking surfaces four days apart in late September 2026, and neither got much attention because neither is an AI feature. Privacy Center, on September 21, puts everything ChatGPT does with your data in one place, and it is on the free plan. Security history, on September 25, answers a question a lot of people have quietly wondered about: has anybody else signed into my ChatGPT? Here is where each one lives and what it actually tells you.
Key Takeaways
- Privacy Center is free. OpenAI: it is "rolling out to signed-in ChatGPT Free, Go, Plus, and Pro users."
- It is a map, not a new control panel. OpenAI: "Your privacy controls remain in ChatGPT Settings." Privacy Center explains and links; it does not replace the switches.
- It covers six areas: "chat privacy, memory, personalization, data use, connected apps, and account security."
- It is hidden under Help on the web, not under Settings. Account menu, then Help, then Privacy Center.
- Security history lists sign-ins and sign-outs, plus "changes to multi-factor authentication (MFA), passkeys, and other security settings."
- Each event carries time, location and device details -- which is what makes an intrusion visible rather than theoretical.
- OpenAI hedges the detail quality itself: "Some details may be approximate or unavailable." A location that looks wrong is not proof of a break-in.
- OpenAI named no plan for security history. Unlike Privacy Center, the release note carries no plan list, so we are not asserting one.
Where to Find Each One
Two different menus, which is the main reason people will not find them by accident. These are OpenAI's own paths, from its release notes.
| Surface | Web | iOS | Android |
|---|---|---|---|
| Privacy Center | Account menu, then Help, then Privacy Center | Settings, then Privacy Center | Settings, then Privacy center |
| Security history | Settings, then Security and login, then Security history | Not named by OpenAI | Not named by OpenAI |
Two honest gaps in that table. OpenAI describes the security history path for "ChatGPT on the web" and does not name an iOS or Android route, so on mobile treat it as unconfirmed rather than absent. And Privacy Center is the rare ChatGPT feature that lives under Help on the web rather than Settings, which is worth remembering because it is the last place most people look for a privacy page.
Privacy Center: What It Is For
It is the answer to "what does ChatGPT actually do with what I type?", assembled in one place instead of scattered across six settings screens. OpenAI's description: Privacy Center "brings together information about chat privacy, memory, personalization, data use, connected apps, and account security, with links to the settings that manage them."
The important sentence is the next one: "Your privacy controls remain in ChatGPT Settings." Nothing moved. If you have turned off model training, or set memory to off, or disconnected an app, those switches are where they were. Privacy Center is documentation with shortcuts attached.
That is less exciting than a new control, and more useful than it sounds. The six areas it covers are exactly the ones this site gets asked about, and each of them has its own separate behaviour that is easy to get wrong:
- Chat privacy and what a temporary chat does and does not keep.
- Memory, including the project-scoped kind.
- Personalization, which is a different setting from memory.
- Data use, meaning whether your conversations train future models.
- Connected apps, which is where third parties get read access.
- Account security, which is now where security history sits.
OpenAI adds the usual caveat: "Available options depend on your plan, region, and workspace settings." On a work or school account an administrator's settings sit on top of yours, and in some regions the defaults differ.
Security History: Checking Whether Someone Else Has Been In
This is the more practically useful of the two, and the shorter to explain. OpenAI: "We're introducing security history, a new way to review recent security activity for your OpenAI account."
What gets logged, in OpenAI's words:
- Sign-ins and sign-outs
- Changes to multi-factor authentication (MFA)
- Changes to passkeys
- Changes to other security settings
And for each one: "Events include the time, location, and device details."
That combination is what makes the feature worth five minutes of your attention. A ChatGPT account often holds years of conversations, uploaded documents, connected email and calendar, and on some plans connected bank accounts. Until September 25 there was no consumer-facing way to check whether a session you did not start existed. Now there is a list.
One caution OpenAI writes itself, and it matters if you are the anxious type: "Some details may be approximate or unavailable." Location in a log like this is usually derived from an IP address, which can place you in the wrong city, show a mobile carrier's hub rather than your street, or move because you used a VPN. An unfamiliar city on its own is weak evidence. An unfamiliar device, or a sign-in at a time you were asleep, is much stronger.
What to Do If You See Something You Do Not Recognise
Treat it as a compromised password until proven otherwise, and work in this order. OpenAI points to its "Keeping your OpenAI account secure" help article for this, and the two protections that show up in security history are the two worth turning on:
- Change your password. This is the only step that ends an attacker's existing access on its own.
- Turn on multi-factor authentication, so a stolen password is no longer enough by itself.
- Consider a passkey, which replaces the password with your device's own unlock.
- Review connected apps, because an app you authorized keeps its access regardless of your password.
- Check security history again in a day, since any of the above that you did will now appear in it as a dated event, and anything you did not do will stand out against them.
The nice property of the design is that step 5 works: because the log records MFA and passkey changes too, your own remediation leaves a trail you can recognise.
Should You Bother?
Open security history once, today, if your ChatGPT account has anything in it you would not post publicly. It takes under a minute, it costs nothing, and the only reason not to is that until this week it did not exist.
Open Privacy Center if you have ever wondered whether your chats train the models. That is the single question it is best placed to answer for your specific account, plan and region, rather than in the abstract.
Skip Privacy Center if you have already set your controls deliberately. It adds no switches. If you have turned off training and memory and you know where both live, there is nothing here you do not have.
Do not read either one as a plan upgrade. Privacy Center is explicitly on Free and Go as well as Plus and Pro. Neither surface is a reason to pay, and if you are weighing that decision, whether ChatGPT Plus is worth it is the page for it.
Sources
- OpenAI Help Center, "ChatGPT Release Notes", the entry "Privacy Center in ChatGPT" dated September 21, 2026 and the entry "Security history in ChatGPT" dated September 25, 2026. Every quoted line here comes from those two entries, read September 26, 2026.
- OpenAI links a dedicated "Privacy Center in ChatGPT" help article and a "Keeping your OpenAI account secure" article from those entries. Neither had a readable archived copy on September 26, 2026, so nothing on this page rests on them; we will add their detail once they can be read.
Read next
Keep up without the jargonChatGPT Temporary Chat Explained: The New Personalize and Save Controls
OpenAI is rolling out two new controls in ChatGPT temporary chat. You can now start one that uses your memories, custom instructions and plugins, and you can save a temporary chat to your history. Saving converts it into a regular chat, which then follows your account's model-improvement settings.
ChatGPT Computer History Explained: Is ChatGPT Watching What You Do on Your Mac?
Computer History lets the ChatGPT Mac app reference what you have been doing in other apps and websites. It is off by default, limited to Pro, Business and Enterprise, and available in supported regions including the EEA, Switzerland and the UK. It requires Memories everywhere, and stores unencrypted summaries on your Mac.
How to Turn Off Gmail's AI Features (and What Each One Does)
Gmail's AI features are controlled by two settings groups: "smart features in Gmail, Chat, and Meet" and "Google Workspace smart features." Turning both off disables Gemini summaries, Help me write, Smart Compose, and Smart Reply -- but you also lose package tracking, inbox categories, and flight events in Calendar.
Frequently Asked Questions
How do I tell if someone else has signed into my ChatGPT account?
Use security history, added September 25, 2026. On the web, go to Settings, then Security and login, then Security history. It lists sign-ins and sign-outs with the time, location and device details for each one, so an unfamiliar entry is visible.
Where is the ChatGPT Privacy Center?
On the web, open your account menu, select Help, then select Privacy Center. On iOS, open Settings and select Privacy Center. On Android, open Settings and select Privacy center. It is not under the main Settings list on the web.
Is the ChatGPT Privacy Center free?
Yes. OpenAI says it is "rolling out to signed-in ChatGPT Free, Go, Plus, and Pro users." You do need to be signed in. What you see inside depends on "your plan, region, and workspace settings."
Does the Privacy Center change my privacy settings?
No. It is a reference surface, not a new set of switches. OpenAI: "Your privacy controls remain in ChatGPT Settings." The Privacy Center explains what ChatGPT does with your data and links out to the settings that control it.
What does ChatGPT security history actually show?
Sign-ins, sign-outs, and changes to multi-factor authentication, passkeys and other security settings. Each event carries the time, location and device. OpenAI warns that "some details may be approximate or unavailable," so treat a rough location as a hint, not proof.
Which plans get security history?
OpenAI does not say. Its release note names no plan and no region, and describes it as history "for your OpenAI account" rather than for a subscription tier. Treat it as unstated rather than paid-only, and check your own Settings.
What should I do if I see a sign-in I do not recognise?
Change your password, then review what else is connected. OpenAI points to its "Keeping your OpenAI account secure" help article for this, and separately offers multi-factor authentication and passkeys, both of which show up in security history when changed.