ChatGPT ad personalization is now written into OpenAI’s privacy policy, and that single sentence is the whole story. Advertising inside ChatGPT stopped being an experiment somebody at OpenAI was quietly testing and became a documented product behaviour with a legal basis, a data flow, a retention story and a settings screen. When a company writes something into its privacy policy, it is telling you what it intends to do with your data for the foreseeable future.

The update landed alongside the biggest geographic expansion of ChatGPT ads so far, with OpenAI confirming on 11 August 2026 that sponsored placements were live in the United Kingdom, Mexico, Brazil, Japan and South Korea, on top of the United States, Canada, Australia and New Zealand. So the policy change and the rollout arrived together, which is not a coincidence. The policy exists to make the rollout lawful.

This guide covers what actually changed, how ChatGPT ad targeting works, what advertisers can and cannot see, and — the part almost every summary skips — why the rules for UK and European users are meaningfully stricter than the rules for American ones. If you use ChatGPT at work, or your organisation is deciding whether staff should be on a free tier at all, that distinction is the one that matters.

We have covered adjacent ground before: our guide to the latest ChatGPT feature update looks at what the product itself is becoming, and our walkthrough of Twitch’s AI training opt-out covers the same pattern of a platform changing its data terms and giving you a switch you have to find yourself. This article is about the switch inside ChatGPT.

What OpenAI Actually Changed in the Privacy Policy

chatgpt ad personalization privacy policy b ballot box with top slot

The revision is not a rewrite. It is a set of additions that describe things the policy previously had no language for, and each addition maps onto a product decision OpenAI has already made.

Advertising now has its own data flow

The headline change is that the policy now describes how ChatGPT ad selection works as an ordinary processing activity: what signals feed it, which accounts are in scope, what leaves OpenAI, and what a user can switch off. Before this, advertising was something OpenAI blogged about. Now it is something OpenAI has committed to in a document with legal weight. The practical effect is that the ChatGPT ad system has a written boundary you can hold the company to, rather than a marketing promise you have to take on trust.

Contact syncing arrived quietly

Buried under the advertising headlines is an optional contact-syncing feature that lets users find people they know across OpenAI services. It is off unless you enable it, and it is unrelated to ad targeting, but it belongs in any honest summary because address books are among the most sensitive data a consumer app can ask for. Enabling it uploads information about people who never agreed to anything. That is worth a moment’s thought before tapping accept.

Retention and processing got clearer

The update also adds detail on how long OpenAI stores data, how that data is processed and what controls exist over it, plus references to newer surfaces such as Atlas and Sora 2, and to the age-prediction and parental-control work OpenAI has been shipping for teen accounts. We wrote about that safety layer when ChatGPT introduced parent notifications, and the same principle applies here: transparency about a mechanism is not the same as the mechanism being optional.

Why the timing matters

OpenAI is projected to lose roughly 14 billion dollars in 2026. Advertising crossed 100 million dollars in annualised revenue within six weeks of the February launch. Those two numbers together explain why ChatGPT ads went from test to documented policy in half a year. A free tier with hundreds of millions of users is the largest untapped advertising inventory created this decade, and the privacy policy is the paperwork that unlocks it.

How ChatGPT Ad Personalization Actually Works

chatgpt ad personalization privacy policy c window shutter louvre slats

The mechanism is more interesting than the headlines suggest, because OpenAI has built something that looks less like conventional behavioural advertising and more like contextual advertising with a memory.

The signals that select an ad

ChatGPT ad matching draws on the topic of your current conversation, your past chats, and your previous interactions with ads. If you are asking about weeknight dinners, you may see a meal-kit or grocery-delivery placement. Crucially, those signals stay inside OpenAI’s systems. There is no third-party cookie, no identity graph being passed around an ad exchange, and no pixel following you off the platform. The profile that selects a ChatGPT ad lives where your conversations already live.

Where the ad appears on screen

Placements sit beneath the organic answer as a distinct block, clearly labelled as sponsored and visually separated from the response itself. OpenAI’s stated principle is blunt: ads do not influence the answers ChatGPT gives. That claim is the single most important commitment in the entire system, and it is also the hardest one for any outsider to verify. Nothing in the privacy policy makes it auditable.

What is excluded by design

Two exclusions are worth knowing. ChatGPT ads are not shown on accounts belonging to users under 18, and they are suppressed around sensitive subject matter including health, mental health and politics. This is a meaningful design choice — the categories that generate the most advertising revenue in conventional media are precisely the ones OpenAI has carved out — and it is the sort of commitment that is easy to make at launch and gets pressure-tested later, when growth targets arrive.

The ads history you can inspect

Every ChatGPT ad you are shown is recorded in an ads history with timestamps and brand names, and you can clear that history whenever you like. This is a genuinely better transparency posture than most advertising platforms offer. It also quietly confirms something worth internalising: a durable record exists of which commercial messages were placed in front of you inside what most people experience as a private conversation.

Who Sees ChatGPT Ads and Who Does Not

chatgpt ad personalization privacy policy d label tag punched hole

The tier split is the fastest way to understand the commercial logic, and it is the first thing to check before you worry about settings at all.

The plans that carry advertising

Ads are shown to logged-in adult users on the Free and Go plans. Every paid tier above that — Plus, Pro, Business, Enterprise and Education — remains ad-free. If your organisation buys ChatGPT licences, your staff are almost certainly not seeing a ChatGPT ad at all. If your staff are using personal free accounts for work, they are.

ChatGPT planSees ads?Ad personalization applies?Typical use
FreeYesYes, subject to your settingsPersonal, casual, shadow work use
GoYesYes, subject to your settingsLow-cost personal tier
PlusNoNot applicableIndividual power users
ProNoNot applicableHeavy individual workloads
BusinessNoNot applicableSME team deployments
EnterpriseNoNot applicableLarge organisations, admin controls
EducationNoNot applicableSchools and universities

The markets where ads are live

The rollout began in the United States in February 2026 and reached Canada, Australia and New Zealand before the European move. The United Kingdom became OpenAI’s first European ad market, and the August 2026 announcement confirmed the United Kingdom, Mexico, Brazil, Japan and South Korea as live markets. Several large European Union countries remain outside the rollout, which tells you how much the regulatory environment is shaping the map.

The opt-out nobody mentions

There is one more option that most coverage omits entirely. Free-tier users can opt out of ChatGPT ads altogether, in exchange for fewer daily messages. That is an unusually honest trade to put in front of a user: your attention or your allowance. It is also the clearest possible statement of what the ChatGPT ad system is worth to OpenAI per user.

chatgpt ad personalization privacy policy e closed door in frame

This is the section that most international coverage gets wrong, and it is the one that matters most to British readers.

Consent, not legitimate interest

On 2 June 2026 OpenAI updated its European advertising privacy terms to state that it will serve personalised ads only to users who explicitly opt in, and that it relies on that consent as the legal basis for processing — explicitly rejecting the “legitimate interest” basis that much of the programmatic advertising industry leans on. Under the UK GDPR, that distinction is not cosmetic. Consent must be a clear affirmative action, it must be as easy to withdraw as it was to give, and it cannot be bundled into a terms-of-service acceptance.

What non-consenting users still see

Declining does not make ChatGPT ads disappear in the UK. It changes what selects them. Users who do not consent still see advertising, but chosen from limited information — the current conversation, approximate location and time of day — rather than a personalised profile built from chat history, memories and past ad interactions. In other words, the UK default without consent is contextual advertising, which is a genuinely different product from behavioural advertising, and a much smaller data-protection footprint.

The comparison that makes it concrete

AspectUnited StatesUnited Kingdom and EU
Default for personalised adsOn, subject to settingsOff until you opt in
Legal basisNotice and choiceExplicit consent
If you declineLess personalised adsContextual ads only
Signals used when personalisedChat topics, history, ad interactionsSame, but only after opt-in
Withdrawing permissionSettings toggleSettings toggle, must be as easy as consenting
Regulator to complain toFTC and state attorneys generalICO in the UK, lead DPA in the EU

Why this shapes the rollout map

Read the table and the geography explains itself. Consent-based advertising produces a smaller addressable audience than opt-out advertising, so a consent regime makes each market less immediately valuable and more operationally complex. That is a large part of why several major EU markets are still waiting while the United Kingdom went first, and it is why the ChatGPT ad business will look structurally different on either side of the Atlantic for years.

What Advertisers Can and Cannot See

chatgpt ad personalization privacy policy f loudspeaker cabinet two cones

This is where most of the anxiety sits, and where the policy is unusually specific — which is a good sign, because vague privacy language is where bad practice hides.

The hard boundary

Advertisers do not receive your conversations, your chat history, your memories or your personal details. What they receive is aggregated performance reporting: totals for views and clicks, and conversion measurement through OpenAI’s own pixel and conversions API. A brand can learn that its campaign drove a certain number of clicks. It cannot learn that you specifically asked ChatGPT about a medical symptom, a redundancy, or a competitor’s pricing.

DataAdvertiser accessUsed to select a ChatGPT ad?
Content of your conversationsNoYes, as topic context
Chat history across sessionsNoYes, if personalization is on
Saved memoriesNoYes, if personalization is on
Name, email, account detailsNoNo
Previous ad clicks and dismissalsAggregated onlyYes
Approximate location and timeAggregated onlyYes, including contextual-only mode
Campaign views, clicks, conversionsYesUsed for optimisation

The boundary that is doing the work

Notice the pattern in the middle column. Almost everything sensitive is used by OpenAI and withheld from advertisers. That is a real protection, and it is stronger than the open real-time-bidding model that dominates the web, where personal signals are broadcast to hundreds of vendors before an impression is served. But it concentrates rather than reduces risk: OpenAI now holds an unusually rich commercial profile of hundreds of millions of people, and the only thing standing between that profile and the advertising market is OpenAI’s own policy.

What to do with that in a risk register

Treat it the way you would treat any single-vendor concentration of sensitive data. It is a cybersecurity and vendor-management question, not just a marketing curiosity. The relevant control is not “ban ChatGPT” — that never works — but knowing which of your people are on ad-supported tiers and what they are typing into them.

The ChatGPT Ad Settings You Should Change Today

Five minutes of settings work removes most of the exposure. Do it once and the defaults stop mattering.

Turn off ad personalization

Open Settings, find the ads or personalization section, and switch off personalised ads. On a UK account you may never have opted in, in which case there is nothing to turn off and you are already on contextual-only ChatGPT ad selection. Verify rather than assume; consent screens are easy to click through when you are trying to get to a chat window.

Clear your ads history and ad data

The same area exposes your ads history and a one-tap delete for ChatGPT ad data. Clearing it resets the interaction signal that personalisation feeds on. Combine it with a review of your saved memories, because memories are one of the inputs to personalised selection and most people have accumulated far more of them than they realise.

Check the tier your team is actually on

This is the control that matters most for organisations, and it is not a setting inside ChatGPT at all. If staff are on personal free accounts, they are on the ad-supported tier, their conversations are feeding a commercial profile, and your organisation has no visibility. A paid Business or Enterprise seat removes ChatGPT ads entirely and puts the account under administrative control. That is a licensing decision with a data-protection payoff.

Write the rule down

Whatever you decide, put it in your acceptable-use policy in one sentence: which tier is approved, what may be typed into it, and what must never be. A policy nobody wrote is a policy nobody follows, and “we assumed people knew” is not a defence anyone has ever won with.

What ChatGPT Ads Mean for Businesses

The privacy policy update is a consumer story on the surface and a governance story underneath. Three implications are worth acting on.

Shadow AI just got a revenue model

Staff using personal ChatGPT accounts for work has always been the quiet risk. What has changed is that those accounts are now commercially instrumented. Conversations on a free account contribute to a profile that selects advertising, which means the incentive to retain and analyse that conversational data has gone up, not down. The mitigation is unglamorous and effective: provide a sanctioned, ad-free tier so nobody has a reason to use a personal one.

Your data-protection paperwork needs a line about it

If your organisation processes personal data through any ChatGPT tier, your records of processing and any relevant impact assessment should reflect what the updated policy says. Auditors increasingly ask which AI services staff use, on what terms, and who signed off. Being able to answer in one page is worth more than any amount of retrospective explanation, and our trust and security overview sets out the questions we work through with clients.

Free is a commercial relationship, not a gift

The clearest lesson from this update is structural. Free AI tiers are becoming ad-supported media products, with the economics that implies. Nothing here is scandalous — OpenAI has been more transparent than most platforms were at the equivalent moment — but the direction is set. Anywhere a free AI tool is doing real work in your business, assume that its terms will get more commercial, not less, and plan the paid path before you need it.

What ChatGPT Ads Mean for Marketers

If you buy media, the same policy update reads as a product launch, and the economics have moved fast.

The price has fallen a long way

ChatGPT ads launched in February 2026 at a 60 dollar CPM, a premium price justified by scarcity and novelty. By April the range had fallen to roughly 25 to 35 dollars, with some reported rates as low as 15 dollars. That is the familiar shape of a new inventory source finding its clearing price as supply expands. Read against the opening price, each later figure is a straightforward percentage of where the ChatGPT ad market started.

Reported ChatGPT ad CPM as a share of the February launch price (100% = $60)
February 2026, launch — $60 100%
April 2026, upper range — $35 58%
April 2026, lower range — $25 42%
Lowest reported rate — $15 25%

Access has opened up too

The minimum spend told the same story. Early buyers faced commitments in the region of 200,000 to 250,000 dollars, reduced to about 50,000 dollars by April and removed entirely on 5 May 2026. Self-serve buying arrived through OpenAI’s ads manager, with cost-per-click bidding recommended in the three-to-five dollar range alongside the CPM reach objective, plus custom audience uploads, daily budgets, geographic targeting and conversion optimisation.

The performance numbers deserve caution

Early results have been quoted enthusiastically. Similarweb data put overall ChatGPT ad click-through at 0.68 per cent, with a top quartile around 1 per cent and an observed peak of 5.4 per cent, while Criteo reported over 1,000 brands live through its integration and retail conversion rates approaching twice those of traditional search.

Reported ChatGPT ad click-through rate, scaled against the 5.4% observed peak
Observed peak 5.4%
Top quartile 1.0%
Overall average 0.68%

Novelty inflates early engagement in every new ad format, and a peak eight times the average is a sign of variance rather than a benchmark to plan against. Budget on the average.

Earned visibility still beats bought visibility

One strategic caveat. Buying a ChatGPT ad places a labelled sponsored block underneath the answer. Being cited inside the answer is a different and more durable outcome, and it is not for sale. That is the discipline we cover in our GEO services work and in our guide to measuring brand visibility across ChatGPT, Gemini and Perplexity. The organisations that win the next few years will do both, and will understand that the sponsored slot is the cheaper half.

Frequently Asked Questions

Does ChatGPT read my conversations to sell ads?

OpenAI uses conversation context to select advertising, but advertisers never receive the conversations themselves. The distinction is between a system that reads your chat to choose a ChatGPT ad, and a system that hands your chat to a brand. Only the first is happening.

Can I stop seeing ads entirely?

Yes, in two ways. Move to any paid tier from Plus upwards and advertising is removed completely. Or stay on the free tier and take the advertising opt-out, which trades ChatGPT ads for a lower daily message allowance.

Are UK users treated differently from US users?

Yes, and materially so. Personalised advertising in the UK and EU requires explicit opt-in consent, and OpenAI has stated it relies on consent rather than legitimate interest. Without consent you get contextual advertising selected from the current conversation, approximate location and time.

Do ads change the answers ChatGPT gives?

OpenAI says they do not, and that placements appear as a clearly labelled block separate from the organic response. That commitment is stated in policy but is not externally auditable, which is a reasonable thing to keep an eye on rather than a reason to panic.

What should an employer actually do about this?

Three things: find out who is using personal free accounts for work, provide an approved ad-free tier so they do not need to, and record the decision in your acceptable-use policy. The tier question resolves most of the exposure on its own.

Is contact syncing related to advertising?

No. Contact syncing is a separate optional feature for finding people you know across OpenAI services, and it is off unless you enable it. It is worth declining anyway unless you have a specific reason to want it, because it shares information about people who never consented themselves.

References