Dot tracker
Dots safety and privacy: cloud isolation, read-only research, auto-review
What safeguards OpenAI built into Dots: isolated cloud compute, read-only proactive research, auto-review, Custom Rules and an activity view.
Giving an agent its own computer and access to your apps raises obvious questions. OpenAI has published a safety and privacy model for Dots; here is the structure of it.
Isolation
Each Dot works on its own cloud computer, separate from your machine. Your computer and its contents stay isolated unless you explicitly choose to connect it. For signing into supported websites, a Dot can use saved passwords without exposing them to the model.
Proactive research is read-only
When you are not actively working with a Dot, it looks for ways to help in the background — what OpenAI calls “proactive research.” It does this using the apps you connected, but only with read-only tools. Those tools cannot send messages, change app content, or control your browser or computer.
Action review and approvals
Actions that could affect your accounts or share information go through auto-review, which checks them against your instructions, your Custom Rules, and built-in safety requirements. The outcome determines:
- what can proceed automatically,
- what needs your approval,
- and what you must do yourself.
Some sensitive tasks — changing a password, for example — always stay with you.
Custom Rules and visibility
You can configure Custom Rules to allow specific actions, require approval, or block them. Built-in safety requirements always apply on top. A Dot’s progress, including background work, appears in an activity view, and you can redirect it as needed. If OpenAI’s monitoring detects a safety concern, it can pause or stop the Dot.
Data controls
- By default, OpenAI does not use content from ChatGPT Business, Enterprise, or Edu workspaces to improve its models.
- On personal plans, you control whether a Dot’s conversations and work are used to improve models.
- OpenAI says it does not train directly on proactive-research content or on a Dot’s own notes to itself — though information from them may inform an eligible conversation or task depending on your settings.
The bottom line
The design assumes the agent is capable enough to be useful and constrained enough to be auditable: isolated compute, read-only background access, review before consequential actions, and a visible activity log. OpenAI also states plainly that Dots can still make mistakes, so consequential work should always be reviewed.
Read our dedicated Dots security and privacy guide for the practical checklist.
Sources
Independent summary. Verify important details against OpenAI's own documentation.