Unofficial guide. Not affiliated with, endorsed by, or sponsored by OpenAI.

Dots Playbook

Unofficial guide · Updated September 30, 2026

Is OpenAI dots safe? Safety, privacy and control, explained

A dot can read your apps, use a browser and act for you, so it’s fair to ask what could go wrong. Here’s how OpenAI’s safeguards work, what you control, and the limits OpenAI itself admits.

By the Dots Playbook editors · Checked against 5 sources on September 30, 2026 · 9 min read

On this page

The short answer

  • Each dot works in its own sandboxed cloud computer; your computer stays separate unless you connect it.
  • Auto-review checks actions like sending email before they run.
  • For supported sign-ins, passwords never enter the model’s context.
  • On personal plans, “Improve the model for everyone” controls training; Business, Enterprise and Edu are off by default.

Key facts

Launched
Sep 29, 2026
Model
GPT-6 Astra
Included in
Pro, Business Premium
Create on
Desktop only
Minimum age
18

The layers of protection

OpenAI describes five layers working together (OpenAI Help Center):

  1. Model safeguards: GPT-6 Astra is trained to refuse harmful requests, including biological and cybersecurity misuse.
  2. Plugin permissions limit what the dot can access.
  3. Custom rules let you set extra boundaries.
  4. Auto-review checks certain planned actions before they run.
  5. Safety monitoring watches for harmful behaviour while the dot works.

A sandboxed workspace for each dot

Every dot has its own cloud computer. A sandbox limits the code and tools it can reach, cloud environments are isolated between users, and the environment where the dot runs code is kept separate from the systems that enforce the key safeguards, so a dot can’t switch those checks off (OpenAI). Your own computer stays out of reach unless you connect it, and a connected computer is still subject to a local sandbox and action checks.

What needs your approval

ActionWhat happens
Reading, analysing, drafting in your chatAllowed within the access you’ve granted
Sending messages or sharing filesNeeds authorisation covering the information and type of recipient; health data needs a named recipient
Buying with a card saved on a merchant siteNeeds your approval (can be given in advance for that purchase)
Permanently deleting data, installing unknown software, granting new security-sensitive accessConfirmed with you every time
Changing a password, moving money between accountsAlways handed back for you to do yourself

Reading, analysing, drafting in your chat

What happens
Allowed within the access you’ve granted

Sending messages or sharing files

What happens
Needs authorisation covering the information and type of recipient; health data needs a named recipient

Buying with a card saved on a merchant site

What happens
Needs your approval (can be given in advance for that purchase)

Permanently deleting data, installing unknown software, granting new security-sensitive access

What happens
Confirmed with you every time

Changing a password, moving money between accounts

What happens
Always handed back for you to do yourself

Approving one message doesn’t give your dot ongoing permission to contact people, and delegating or continuing work later never widens what you approved (OpenAI).

Custom rules

Custom rules let you set how your dot helps within those built-in limits, for example “never send email”. For each action you choose: take action without asking, take action if pre-approved, ask before taking action, or hand off to you (OpenAI Help Center). Your dot can help you write rules, but changes need your approval. Rules can’t remove mandatory confirmations, hand-backs or core safety requirements (OpenAI).

Auto-review: an independent check before acting

Before a dot sends an email or changes a file, a separate system called Auto-review checks the planned step against your instructions, custom rules and safety requirements. For email it checks the recipient and the content, to catch a wrong address or information you didn’t mean to share. If it blocks a step, the dot may ask you, try an allowed alternative, hand the step to you, or stop. Your approval can’t override core safety requirements (OpenAI).

Passwords and secure sign-in

For supported sign-ins, the model pauses while you fill in a secure login form, and the form sends your credentials straight to the browser environment. Saved passwords go through a dedicated encrypted credential service. Either way, the password stays outside the model’s context (OpenAI).

What proactive research can and can’t do

Background research reads permitted, connected sources and saves private notes for the dot. OpenAI enforces in code that research tasks can’t send messages to other people, change content through plugins, or control a browser or computer. Custom rules can’t loosen these restrictions (OpenAI Help Center).

Prompt injection and malicious content

Web pages, emails and documents can contain hidden instructions meant to hijack an agent. Dots are designed to tell your instructions apart from content they come across, and that content doesn’t grant permission on its own. Tool restrictions, pre-action checks, approvals and monitoring add further protection, which OpenAI says reduces the risk but doesn’t eliminate it (OpenAI Help Center).

Memory and your data

  • Your dot shares memory with ChatGPT in both directions. Turning off Memory in ChatGPT stops the sharing but doesn’t delete what the dot already received.
  • The dot keeps context from conversations and plugins for as long as you keep the dot. It doesn’t retain credentials, images or screenshots.
  • You can’t view, edit or delete individual dot memories; deleting the dot deletes its context. Disconnecting an app stops new access but doesn’t remove what the dot already learned.
  • Content is encrypted at rest and in transit.
  • Human review may occur in limited circumstances, including safety cases, even with model improvement off.

All of the above: (OpenAI Help Center). To request access to, correction or deletion of your personal data, OpenAI points to its Privacy Portal or dsar@openai.com.

Is my data used to train models?

For ChatGPT Business, Enterprise and Edu workspaces, OpenAI doesn’t train on your data by default. For personal plans, the “Improve the model for everyone” setting in ChatGPT decides whether your dots’ conversations and work may be used, which can include actions dots take, work they delegate, automations you set up, and connected-app data used in your conversations. OpenAI removes personal identifiers where possible first (OpenAI Help Center).

OpenAI doesn’t train directly on proactive research or its notes, but if the dot pulls a research note into an eligible conversation, that content can be used depending on your setting (OpenAI). See Data controls in ChatGPT for how to turn it off.

Honest limits, and our practical tips

OpenAI says plainly that dots can still make mistakes, including when following your rules, and asks you to review consequential work (OpenAI Help Center). The GPT-6 Astra system card covers the evaluations and remaining limitations (OpenAI).

Our suggestions for a careful start (our advice, not OpenAI’s):

  • Connect a few apps first, and add more once you trust how it works.
  • Add a custom rule such as “ask before sending any email or message”.
  • Keep secrets out of chats and documents your dot can read.
  • On a personal plan, decide on the training setting before you connect work data.
  • Check the activity view on desktop during the first week.

Frequently asked questions

Is OpenAI dots safe to use?

OpenAI has built several layers of protection: a sandboxed cloud computer per dot, plugin permissions, custom rules, an independent Auto-review check before actions like sending email, and safety monitoring. OpenAI also says dots can still make mistakes, so review consequential work.

Can my dot see my passwords?

For supported sign-ins, no: you enter credentials in a secure form that sends them straight to the browser environment without exposing them to the model. That protection doesn’t cover passwords you paste into a chat, a document or a plugin.

Can my dot spend my money?

It can buy things with a card you’ve saved on a merchant’s website, but those purchases need your approval, which you can give in advance for a specific purchase. Transferring money between financial accounts is always handed back to you.

Does OpenAI train on my dot’s data?

Not by default for ChatGPT Business, Enterprise and Edu workspaces. On personal plans, the “Improve the model for everyone” setting controls whether your dots’ conversations and work may be used. OpenAI doesn’t train directly on proactive research or its notes.

Can I delete what my dot remembers?

You can’t currently view or delete individual dot memories. Deleting (resetting) your dot deletes its own context. Memories shared with ChatGPT are managed separately in ChatGPT’s memory settings.

Can people at OpenAI see my dot’s activity?

OpenAI says human review may happen in limited circumstances, including safety-related cases, even when model improvement is turned off.

Sources

  1. OpenAI: How we build safety, security, and privacy into dots (official, published September 29, 2026, checked September 30, 2026)
  2. OpenAI Help Center: Dots privacy, security, and safety FAQs (official, published September 29, 2026, checked September 30, 2026)
  3. OpenAI Help Center: Getting started with your dot (official, published September 29, 2026, checked September 30, 2026)
  4. OpenAI Help Center: Data controls in ChatGPT (official, published September 29, 2026, checked September 30, 2026)
  5. OpenAI: GPT-6 Astra system card (official, published September 29, 2026, checked September 30, 2026)

Dots is new and changes fast. If something here is out of date, the official pages win.