Unofficial guide · Updated September 30, 2026
Is OpenAI dots safe? Safety, privacy and control, explained
A dot can read your apps, use a browser and act for you, so it’s fair to ask what could go wrong. Here’s how OpenAI’s safeguards work, what you control, and the limits OpenAI itself admits.
By the Dots Playbook editors · Checked against 5 sources on September 30, 2026 · 9 min read
On this page
The short answer
- Each dot works in its own sandboxed cloud computer; your computer stays separate unless you connect it.
- Auto-review checks actions like sending email before they run.
- For supported sign-ins, passwords never enter the model’s context.
- On personal plans, “Improve the model for everyone” controls training; Business, Enterprise and Edu are off by default.
Key facts
- Launched
- Sep 29, 2026
- Model
- GPT-6 Astra
- Included in
- Pro, Business Premium
- Create on
- Desktop only
- Minimum age
- 18
The layers of protection
OpenAI describes five layers working together (OpenAI Help Center):
- Model safeguards: GPT-6 Astra is trained to refuse harmful requests, including biological and cybersecurity misuse.
- Plugin permissions limit what the dot can access.
- Custom rules let you set extra boundaries.
- Auto-review checks certain planned actions before they run.
- Safety monitoring watches for harmful behaviour while the dot works.
A sandboxed workspace for each dot
Every dot has its own cloud computer. A sandbox limits the code and tools it can reach, cloud environments are isolated between users, and the environment where the dot runs code is kept separate from the systems that enforce the key safeguards, so a dot can’t switch those checks off (OpenAI). Your own computer stays out of reach unless you connect it, and a connected computer is still subject to a local sandbox and action checks.
What needs your approval
| Action | What happens |
|---|---|
| Reading, analysing, drafting in your chat | Allowed within the access you’ve granted |
| Sending messages or sharing files | Needs authorisation covering the information and type of recipient; health data needs a named recipient |
| Buying with a card saved on a merchant site | Needs your approval (can be given in advance for that purchase) |
| Permanently deleting data, installing unknown software, granting new security-sensitive access | Confirmed with you every time |
| Changing a password, moving money between accounts | Always handed back for you to do yourself |
Reading, analysing, drafting in your chat
- What happens
- Allowed within the access you’ve granted
Sending messages or sharing files
- What happens
- Needs authorisation covering the information and type of recipient; health data needs a named recipient
Buying with a card saved on a merchant site
- What happens
- Needs your approval (can be given in advance for that purchase)
Permanently deleting data, installing unknown software, granting new security-sensitive access
- What happens
- Confirmed with you every time
Changing a password, moving money between accounts
- What happens
- Always handed back for you to do yourself
Approving one message doesn’t give your dot ongoing permission to contact people, and delegating or continuing work later never widens what you approved (OpenAI).
Custom rules
Custom rules let you set how your dot helps within those built-in limits, for example “never send email”. For each action you choose: take action without asking, take action if pre-approved, ask before taking action, or hand off to you (OpenAI Help Center). Your dot can help you write rules, but changes need your approval. Rules can’t remove mandatory confirmations, hand-backs or core safety requirements (OpenAI).
Auto-review: an independent check before acting
Before a dot sends an email or changes a file, a separate system called Auto-review checks the planned step against your instructions, custom rules and safety requirements. For email it checks the recipient and the content, to catch a wrong address or information you didn’t mean to share. If it blocks a step, the dot may ask you, try an allowed alternative, hand the step to you, or stop. Your approval can’t override core safety requirements (OpenAI).
Passwords and secure sign-in
For supported sign-ins, the model pauses while you fill in a secure login form, and the form sends your credentials straight to the browser environment. Saved passwords go through a dedicated encrypted credential service. Either way, the password stays outside the model’s context (OpenAI).
What proactive research can and can’t do
Background research reads permitted, connected sources and saves private notes for the dot. OpenAI enforces in code that research tasks can’t send messages to other people, change content through plugins, or control a browser or computer. Custom rules can’t loosen these restrictions (OpenAI Help Center).
Prompt injection and malicious content
Web pages, emails and documents can contain hidden instructions meant to hijack an agent. Dots are designed to tell your instructions apart from content they come across, and that content doesn’t grant permission on its own. Tool restrictions, pre-action checks, approvals and monitoring add further protection, which OpenAI says reduces the risk but doesn’t eliminate it (OpenAI Help Center).
Memory and your data
- Your dot shares memory with ChatGPT in both directions. Turning off Memory in ChatGPT stops the sharing but doesn’t delete what the dot already received.
- The dot keeps context from conversations and plugins for as long as you keep the dot. It doesn’t retain credentials, images or screenshots.
- You can’t view, edit or delete individual dot memories; deleting the dot deletes its context. Disconnecting an app stops new access but doesn’t remove what the dot already learned.
- Content is encrypted at rest and in transit.
- Human review may occur in limited circumstances, including safety cases, even with model improvement off.
All of the above: (OpenAI Help Center). To request access to, correction or deletion of your personal data, OpenAI points to its Privacy Portal or dsar@openai.com.
Is my data used to train models?
For ChatGPT Business, Enterprise and Edu workspaces, OpenAI doesn’t train on your data by default. For personal plans, the “Improve the model for everyone” setting in ChatGPT decides whether your dots’ conversations and work may be used, which can include actions dots take, work they delegate, automations you set up, and connected-app data used in your conversations. OpenAI removes personal identifiers where possible first (OpenAI Help Center).
OpenAI doesn’t train directly on proactive research or its notes, but if the dot pulls a research note into an eligible conversation, that content can be used depending on your setting (OpenAI). See Data controls in ChatGPT for how to turn it off.
Honest limits, and our practical tips
OpenAI says plainly that dots can still make mistakes, including when following your rules, and asks you to review consequential work (OpenAI Help Center). The GPT-6 Astra system card covers the evaluations and remaining limitations (OpenAI).
Our suggestions for a careful start (our advice, not OpenAI’s):
- Connect a few apps first, and add more once you trust how it works.
- Add a custom rule such as “ask before sending any email or message”.
- Keep secrets out of chats and documents your dot can read.
- On a personal plan, decide on the training setting before you connect work data.
- Check the activity view on desktop during the first week.
Frequently asked questions
Is OpenAI dots safe to use?
OpenAI has built several layers of protection: a sandboxed cloud computer per dot, plugin permissions, custom rules, an independent Auto-review check before actions like sending email, and safety monitoring. OpenAI also says dots can still make mistakes, so review consequential work.
Can my dot see my passwords?
For supported sign-ins, no: you enter credentials in a secure form that sends them straight to the browser environment without exposing them to the model. That protection doesn’t cover passwords you paste into a chat, a document or a plugin.
Can my dot spend my money?
It can buy things with a card you’ve saved on a merchant’s website, but those purchases need your approval, which you can give in advance for a specific purchase. Transferring money between financial accounts is always handed back to you.
Does OpenAI train on my dot’s data?
Not by default for ChatGPT Business, Enterprise and Edu workspaces. On personal plans, the “Improve the model for everyone” setting controls whether your dots’ conversations and work may be used. OpenAI doesn’t train directly on proactive research or its notes.
Can I delete what my dot remembers?
You can’t currently view or delete individual dot memories. Deleting (resetting) your dot deletes its own context. Memories shared with ChatGPT are managed separately in ChatGPT’s memory settings.
Can people at OpenAI see my dot’s activity?
OpenAI says human review may happen in limited circumstances, including safety-related cases, even when model improvement is turned off.
Sources
- OpenAI: How we build safety, security, and privacy into dots (official, published September 29, 2026, checked September 30, 2026)
- OpenAI Help Center: Dots privacy, security, and safety FAQs (official, published September 29, 2026, checked September 30, 2026)
- OpenAI Help Center: Getting started with your dot (official, published September 29, 2026, checked September 30, 2026)
- OpenAI Help Center: Data controls in ChatGPT (official, published September 29, 2026, checked September 30, 2026)
- OpenAI: GPT-6 Astra system card (official, published September 29, 2026, checked September 30, 2026)
Dots is new and changes fast. If something here is out of date, the official pages win.