Use the reporting route that matches the problem: report private information exposed in OpenAI content through the Report Content form; send requests about your own personal data through OpenAI’s Privacy Portal or dsar@openai.com; and report technical vulnerabilities or security incidents under OpenAI’s Coordinated Vulnerability Disclosure policy. These are separate processes, and a report sent to the wrong one may not reach the team equipped to handle it.
Choose the right OpenAI reporting route
| What happened | Where to report it |
|---|---|
| OpenAI-hosted content exposes private information or otherwise violates privacy | Report Content form, or an applicable in-product report option |
| You want to access, delete, or correct your own personal information | OpenAI’s Privacy Portal or dsar@openai.com |
| You found a technical vulnerability or security incident | Follow the Coordinated Vulnerability Disclosure policy |
| The concern is about model behavior, such as a jailbreak or hallucination | Use OpenAI’s dedicated safety channels, not the vulnerability policy |
Report a privacy violation in content
If a ChatGPT conversation, GPT, shared link, ad, or other content on an OpenAI product exposes private information, use the Report Content form or the product’s report flow when one is available. The form includes “Privacy violation” as a reason and asks for a description and, where available, the direct URL. You can also attach a screenshot and add context.
For a ChatGPT message, OpenAI’s Help Center instructions are to select the thumbs-down icon under the message, choose “Select an issue,” select “Safety or Legal concern,” and follow the prompts. Other content types may have their own in-product reporting option.
What to include
- A direct link to the content, if available, so the reviewer can locate it.
- A concise explanation of what information is exposed and why it presents a privacy concern.
- An optional screenshot or other relevant context.
The form asks you to attest that your submission is truthful, accurate, and complete, and OpenAI says reports submitted through it are confidential to the reporter and OpenAI. Include only details needed to explain and locate the issue; avoid adding unrelated sensitive information.
#1 Best Overall
Request access to, deletion of, or correction to your own data
A data-rights request is different from reporting content that exposes someone’s private information. For a request concerning your own personal information, use OpenAI’s Privacy Portal or email dsar@openai.com. OpenAI’s 2026 privacy-rights report also lists privacy@openai.com and direct in-product requests for access, deletion, and correction.
OpenAI reported that it received 5,986,331 global data-access requests in 2025 and averaged less than four days to respond; 6,705,206 deletion requests, averaging less than three days; and 351,297 correction requests, averaging less than two days. These are organization-wide historical averages published in 2026, not promised response times for an individual request.
Rank #2
Report a technical vulnerability or security incident
For a technical issue that could reasonably compromise the confidentiality, integrity, or availability of OpenAI systems, follow the Coordinated Vulnerability Disclosure policy. It describes the authorized testing scope, secure communication, and reporting process. OpenAI directs security incident reporters to submit an encrypted report and vulnerability researchers to its Bug Bounty Program.
- Follow the policy’s testing and disclosure requirements.
- Send the report through its encrypted process when reporting a security incident.
- Do not publicize technical details while a fix is underway.
OpenAI says it aims to acknowledge receipt within three business days. That is an aim for acknowledgment, not a guaranteed resolution time.
Free tools Windows power users keep installed
One-click scans. No signup required.
Model behavior and AI safety concerns use a different route
The vulnerability policy is for technical vulnerabilities, not problems such as prompt jailbreaks, hallucinations, or policy bypasses. OpenAI’s CVE Assignment Policy states: “AI model safety vulnerabilities which include behavior or content (prompt ‘jailbreaks,’ model hallucinations, policy bypasses, etc) are not within scope of this policy.” Use OpenAI’s dedicated safety channels for those issues rather than submitting them as technical vulnerability reports.
Quick Recap
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

