AWAI at Work, Plainly
ai tools

Using AI to Draft Emails, What the Official Docs Say

What OpenAI and Microsoft officially document about business data handling when you use AI tools to draft workplace emails.

Drafting emails is one of the most common ways people use AI tools at work, and it's also one of the easiest places to accidentally paste in information you shouldn't. Before relying on an AI tool for this, it's worth knowing exactly what the vendor's own documentation says happens to your text once you submit it, rather than assuming based on how the tool feels to use.

What OpenAI's documentation commits to for business accounts

OpenAI publishes a dedicated enterprise privacy page covering ChatGPT Business, ChatGPT Enterprise, ChatGPT for Healthcare, ChatGPT Edu, ChatGPT for Teachers, and its API Platform. The stated commitments are organized into three areas:

Ownership: "We do not train our models on your data by default," and the business customer owns the inputs and outputs, where allowed by law, for these account types. For ChatGPT Enterprise, ChatGPT for Healthcare, and ChatGPT Edu specifically, the customer also controls how long their data is retained.

Control: Enterprise-level authentication is available through SAML SSO, with fine-grained control over who in an organization has access to which features.

Security: OpenAI states it has completed a SOC 2 audit, and that data is encrypted at rest (AES-256) and encrypted in transit (TLS 1.2+) both between the customer and OpenAI, and between OpenAI and its own service providers.

The important detail for anyone drafting work email with a free or personal ChatGPT account: these specific data-ownership and no-training-by-default commitments are described for the business products listed above. If you're using a personal, non-business account to draft a work email, check which account type you're actually logged into, since the commitments on OpenAI's enterprise privacy page apply to the business products it names, not necessarily to every consumer tier.

What Microsoft documents for Copilot in Word, Outlook, and Excel

Microsoft's official documentation for Microsoft Copilot (the current name for what was previously called Microsoft 365 Copilot) states plainly: "Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs, including those used by Microsoft Copilot." This appears twice in Microsoft's documentation, once in the overview and again in the FAQ section, which suggests it's a commitment Microsoft wants to be unambiguous about.

Microsoft's documentation also describes a specific access-control detail that matters for email drafting: "Microsoft Copilot only surfaces organizational data to which individual users have at least view permissions." In practice, this means if you ask Copilot to help draft an email referencing a document, it will only pull details from files you already have permission to view, not from your organization's full data store.

For EU-based users, Microsoft's documentation notes additional handling: EU traffic stays within the EU Data Boundary, while worldwide traffic can be routed to the EU or other countries/regions for processing.

What neither document promises

Reading both pages closely, there are things neither vendor commits to:

  • Neither guarantees the drafted email will be factually accurate. Microsoft's documentation states this directly: "The responses that generative AI produces aren't guaranteed to be 100% factual... users should still use their judgment when reviewing the output before sending them to others."
  • Neither removes your responsibility to avoid pasting sensitive data you shouldn't share, even with these protections in place. A no-training commitment means your draft text won't be used to improve the underlying model, but it does not mean the text wasn't processed or temporarily stored at all; OpenAI's page notes customers using ChatGPT Enterprise, ChatGPT for Healthcare, or ChatGPT Edu can control their own data retention period, which implies the data is retained for some duration by default, just not used for training.

A practical checklist before you draft a work email with AI

  1. Check your account type. Business/enterprise tiers tend to carry stronger documented commitments than personal, free-tier accounts.
  2. Don't paste information you wouldn't otherwise send over a regular, unencrypted channel, even with encryption-in-transit documented, since that protects the data moving between systems, not your decision about what to include.
  3. Always read the draft before sending. Both vendors' own documentation explicitly disclaims full factual accuracy, specific tone matches, or guaranteed judgment.
  4. If you're on a business account, ask your IT or admin team what access-control settings they've configured, since both platforms document that admin-level controls affect what the tool can see and do, separate from the baseline privacy commitments.

Key takeaways

  • OpenAI's enterprise privacy page states that it does not train its models on business customer data by default, and that customers on the listed business tiers own their inputs and outputs where legally allowed.
  • Microsoft's Copilot documentation states explicitly that prompts, responses, and Microsoft Graph data are not used to train the underlying models.
  • Both vendors document encryption and access controls, but neither commits to factual accuracy of AI-drafted content.
  • Account type matters: documented privacy commitments described on these pages are tied to named business products, not automatically to every account tier.
  • Always review an AI-drafted email before sending; the vendors' own documentation says you should.

Sources

  1. OpenAI, Enterprise privacy at OpenAI
  2. Microsoft Learn, Data, Privacy, and Security for Microsoft Copilot
ai toolsworkplacedata privacy