Everyday AI data handling
Review files that stay in an AI project
A project file can supply context to more than one chat and remain available beyond the original upload. Review the project’s participants, shared sources, reuse and ordinary removal process before adding confidential material. Keep project access separate from connected-service permissions and from legal erasure or preservation decisions.
For Team workspace administrators and privacy
Record who can use the source and how its lifecycle ends.
Fictional project and intended access. No file is uploaded, collaborator invited or project deleted.01
Identify what the project shares
OpenAI documents ChatGPT projects as a way to keep related chats, files, instructions and sources together. On the web, a project’s chats can use its shared files and instructions. This differs from attaching a file for one isolated request.
Record the project, file purpose and participants before upload. Review both uploaded material and connected context. Do not infer that the original source system’s permissions automatically describe every later project copy or generated answer containing information from it.
Source context: OpenAI: Projects and chats · OpenAI: ChatGPT Work security
02
Review the actual collaborator boundary
Identify who owns the project, who is intended to use its files and what controls the current product exposes for those participants. Record effective access rather than inventing a role model from another collaboration tool. Changes to membership can change who obtains context from the project.
The populated exercise uses a fictional owner, an intended collaborator and an unrelated account. It states the desired access without asserting that a particular product grants those roles automatically. Verify that the actual project configuration can enforce the intended boundary before confidential files are added.
| Fictional participant | Intended use | Evidence required |
|---|---|---|
| SYNTHETIC_OWNER | Manage the example source | Actual project-control scope |
| SYNTHETIC_COLLABORATOR | Use approved example context | Actual access to this project |
| UNRELATED_ACCOUNT | No access intended | Separate-account observation |
03
Follow reuse into chats and outputs
A project source can inform later work, so review whether the content is appropriate for the project’s overall purpose rather than only its first question. A generated summary or exported result can become another copy with its own audience.
Keep a source record linking the file to its owner, allowed purpose and review date. If the file is replaced, note which version should be used and whether earlier chats or outputs still contain older content. Updating the current source is not proof that every earlier answer was rewritten.
Source context: OpenAI: Projects and chats · OpenAI: ChatGPT Work security
04
Separate ordinary removal from other copies
OpenAI’s Work security guidance states that project files remain associated with the project until removed or the project is deleted, subject to applicable deletion rules. Review the actual removal action and record what it affects. Do not describe it as immediate deletion from every possible location.
Connected-service records, Library files, downloaded outputs and earlier conversations may have separate handling. This page covers ordinary project-file lifecycle. Legal erasure requests, preservation duties or holds need the responsible legal/privacy process and the linked guides.
Source context: OpenAI: ChatGPT Work security
05
Keep the project’s source list current
Assign an owner to periodically review participants and source files, particularly when the project’s purpose changes or a colleague leaves. Retire unnecessary material using the supported process and record unresolved retained copies.
Use the synthetic file and lifecycle sheet to practise the review without creating a real shared project. The pack does not upload, invite, delete or connect anything. Aona input protection, provider project access and source-system permissions remain separate controls that need their own evidence.
Put it into practice
Shared project-file lifecycle exercise
Track a fictional source file from upload decision through reuse and ordinary removal.
Fictional project and intended access. No file is uploaded, collaborator invited or project deleted.
| Stage | Example decision | Observation |
|---|---|---|
| Add source | Use synthetic-project-note.txt only | Not uploaded |
| Share context | Owner and one intended collaborator | Access unverified |
| Reuse | Keep the example purpose and version | Untested |
| Retire | Review project and other copies separately | Not performed |
Work through your review
Use the checks to organise the evidence you need. Your selections stay in this tab.
0 of 3 reviewed
Example files for this task
Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.
README.mdInspect
# Shared AI project file exercise
All participants, project names and source text are fictional. This pack performs no upload, invite, connection or deletion.
Use the supplied note and populated intended-access example to plan a review. Record the actual project’s available roles and permissions instead of assuming the example labels are product roles. Keep ordinary file removal separate from legal erasure/hold decisions and from copies in other systems.
## Guide and sources
Canonical guide: https://aona.ai/resources/guides/shared-ai-projects-confidential-files/
Source review: 2026-09-21
- OpenAI: Projects and chats: https://learn.chatgpt.com/docs/projects
- OpenAI: ChatGPT Work security: https://learn.chatgpt.com/docs/enterprise/chatgpt-work-cloud-security
Download README.mdsynthetic-project-note.txtInspect
SYNTHETIC PROJECT SOURCE
Project: SYNTHETIC_U06_TRAINING
Version: 1
Purpose: prepare a fictional training checklist.
Content: review the sample, note an owner, then record a next step.
No customer, employee or confidential company information is included.
Download synthetic-project-note.txtproject-lifecycle.csvInspect
stage,fictional_example,intended_scope,actual_evidence,status
Owner,SYNTHETIC_OWNER,Manage example source,TO_RECORD,UNVERIFIED
Collaborator,SYNTHETIC_COLLABORATOR,Use approved project context,TO_RECORD,UNVERIFIED
Unrelated account,UNRELATED_ACCOUNT,No access,TO_RECORD,UNTESTED
Source file,synthetic-project-note.txt,Training purpose and version1,TO_RECORD,NOT UPLOADED
Generated output,Fictional checklist,Same approved audience,TO_RECORD,NOT CREATED
Removal,Project source and other copies reviewed separately,Record supported action,TO_RECORD,NOT PERFORMED
Download project-lifecycle.csvreview-record.mdInspect
# Project source review
Project purpose and owner: ____________________
Actual participants/roles and access evidence: ____________________
File owner, purpose and version: ____________________
Chats/outputs that may reuse it: ____________________
Ordinary removal action and effect: ____________________
Copies governed elsewhere: ____________________
Legal/privacy escalation if required: ____________________
Decision: NOT YET REVIEWED
Download review-record.mdBefore you proceed
Keep these distinctions clear
- Approving only the first chat
- A project source can be reused across related chats, so review its continuing purpose and audience.
- Equating source replacement with erased history
- Earlier conversations or exported results can remain separate records.
Apply it to employee AI use
Bring your actual data path.
Aona can help evaluate supported employee input paths when files are submitted to AI.
This does not establish control of project membership, provider deletion or every retained project copy.
Bring the permitted file purpose and actual submission path to a scoped review while the workspace owner verifies project access.
Review your use caseFAQ
Questions for this decision
Is a project file the same as a one-off attachment?
Does this worksheet define ChatGPT’s exact collaborator roles?
Does removing the project file remove all earlier summaries?
Does this page decide legal erasure or preservation obligations?
Evidence behind the guide
Sources and scope
Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.
- OpenAI: Projects and chats
Documents shared project files, instructions and sources across related chats.
vendor · checked 2026-09-21 - OpenAI: ChatGPT Work security
Describes project-file association and separate retained-copy/control boundaries.
vendor · checked 2026-09-21