Codex opt out of training, and what to verify

By Rogier Muller08.15.26
Codex opt out of training, and what to verify

Check the account and data control separately

OpenAI’s Codex plan and data-controls guidance says ChatGPT training data controls apply to content processed through Codex. It states that business inputs and outputs are not used to improve models by default, while Plus and Pro conversations may be used unless training is turned off. API organizations have their own data-sharing settings.

Confirm the account, workspace and access method actually used by each client. Record the applicable setting and date with your organization’s approval record. A business account elsewhere on the same machine does not establish the policy for a session signed into a personal account. Check the current agreement and official guidance when requirements depend on specific data handling.

Training opt-out is not a read restriction

The setting concerns use of submitted content for model improvement. It does not decide which local files, environment variables, screenshots or connected systems the agent can access. It also does not, by itself, establish a retention period or eliminate every form of storage.

A .gitignore entry prevents ordinary Git tracking; it is not a filesystem permission boundary. Likewise, injecting a secret into a process environment can still expose it to commands running in that environment. Keep credentials outside the agent’s accessible environment where possible, and use narrowly scoped credentials when an authorized task needs them.

Test the actual access boundary

Use a disposable repository with synthetic files representing allowed and forbidden data. Configure the intended filesystem, sandbox and connector permissions, then attempt both an allowed read and a denied read. Inspect the tool result and the underlying control. An agent’s statement that it will avoid a file is not proof that the file is inaccessible.

Repeat the test for any shell, browser or MCP path that could reach the same data. Do not run this exercise against real secrets or your most sensitive repository. The purpose is to verify the control before relying on it.

For a team review, keep three separate answers: what may be accessed, what the provider may do with submitted content, and how long relevant records may be retained. Use the Codex security documentation for client controls and the applicable service agreement for contractual requirements.

Updated 21 September 2026: checked the official data-controls guidance, removed unsupported client anecdotes, and corrected the suggestion that ignore files or runtime secret injection automatically prevent agent access.

Where does your team stand?

Each team member completes the proficiency matrix individually. You receive a PDF with the team baseline and a recommended next step.

Assess your team