Can You Delete One Memory From OpenAI Dots? Not Yet.

October 6, 2026

OpenAI says Dots can retain context from chats and plugins, but users cannot yet view, edit, or delete one Dot memory. Here is what deletion actually reaches.

Can You Delete One Memory From OpenAI Dots? Not Yet.

Short answer: no. OpenAI says users currently cannot view, edit, or delete an individual memory from a Dot, including a detail that entered its context through a connected plugin. You can delete the Dot to delete its own context, but that does not delete files, Codex threads, ChatGPT conversations, or other ChatGPT memories stored elsewhere.

That is the key privacy tradeoff behind OpenAI's new always-on agent. Dots are designed to learn what matters to you, carry context across channels, use connected apps, and keep working in the background. Persistent context makes that possible. It also means that “turn off Memory,” “disconnect the plugin,” “delete the Dot,” and “delete everything the Dot touched” are four different actions.

Research cutoff: October 6, 2026.

OpenAI Dots Memory in One Minute

OpenAI introduced Dots on September 29 as always-on agents powered by GPT-6 Astra. Each Dot has its own cloud computer and browser, can connect to apps, can work proactively, and can carry context across ChatGPT, Slack, Teams, and other channels.

OpenAI's current Dots privacy, security, and safety FAQ establishes five separate facts:

  1. A Dot can retain context from conversations and plugins for as long as you keep the Dot.
  2. ChatGPT and the Dot can share memory in both directions.
  3. Turning off ChatGPT Memory stops future sharing but does not delete information the Dot already received.
  4. Disconnecting a plugin stops new access but does not delete information already built into the Dot's context.
  5. Users cannot currently view, edit, or delete an individual Dot memory.

Deleting the Dot deletes the Dot's own context. It does not automatically delete separately stored files, Codex threads, ChatGPT conversations, or ChatGPT memories.

The practical lesson is simple: a permission boundary, a memory boundary, and a deletion boundary are not the same thing.

What Is Confirmed

The central memory limitation is stated directly in OpenAI's documentation, not inferred from social posts.

You cannot currently inspect one Dot memory

OpenAI says you currently cannot view an individual Dot memory. That means there is no user-facing list where you can inspect every retained preference, fact, plugin-derived detail, or compacted piece of context in the Dot's own memory store.

You can see activity and task steps in Activity View, but an activity log is not the same as a complete memory inventory. It shows work the Dot performed; it does not claim to enumerate every detail retained in context.

You cannot directly edit or delete one Dot memory

OpenAI also says users cannot directly modify or delete one individual Dot memory. If one detail is wrong, too personal, outdated, or came from the wrong connected source, the documented deletion control for the Dot's own context is deleting the Dot itself.

This differs from ChatGPT's separate memory controls. OpenAI says any information the Dot has shared into ChatGPT Memory can be managed in ChatGPT's Memory settings. That does not provide a way to inspect or selectively delete the Dot's own retained context.

A Dot can keep context as long as the Dot exists

OpenAI says a Dot can retain context from conversations and plugins for as long as you keep the Dot. The product is meant to learn your goals, preferences, standards, and working patterns over time, so long-lived context is part of the design rather than an accidental cache.

That does not mean the Dot stores every raw input forever. OpenAI specifically says the Dot's context does not retain credentials, images, or screenshots. It also does not publish a complete field-by-field description of how context is selected, summarized, compacted, or retired.

Turning off ChatGPT Memory is prospective, not retroactive

Dots can receive memories and recent conversation context from ChatGPT, and conversations with a Dot can contribute to ChatGPT Memory. OpenAI says turning off ChatGPT Memory stops that sharing, but does not delete information the Dot already received.

This is a common privacy-control pattern: a toggle can stop a future flow without erasing what already crossed the boundary.

Disconnecting a plugin stops access, not learned context

OpenAI says disconnecting a service linked through a plugin stops new access through that connection. It does not delete information the Dot already built into its context.

Imagine a Dot reads a customer name, a project deadline, and a private strategy note from a connected workspace. Revoking the connection should stop the Dot from fetching new records. It does not, by itself, erase those three details from the Dot's retained context.

Deleting a Dot does not delete every related artifact

Deleting the Dot deletes its own context. OpenAI separately lists other data stores that remain:

Those records have to be reviewed and deleted through the system that owns them.

The Four Controls People Are Most Likely to Confuse

Turn off ChatGPT Memory

This stops future memory sharing between ChatGPT and the Dot. It does not remove information already received by the Dot, delete the Dot's context, delete source conversations, or delete files.

Disconnect a plugin

This stops future access through that plugin connection. It does not erase details already incorporated into the Dot's context and does not necessarily delete records in the connected service.

Delete the Dot

This deletes the Dot's own context. It does not delete separately stored conversations, files, Codex threads, ChatGPT memories, or connected-service records.

Delete the source record

Deleting a source email, document, calendar event, chat, or file affects that source system. OpenAI's FAQ does not say source deletion automatically finds and removes every derived detail already represented in Dot context.

This is why a deletion plan needs a data map, not one button.

What Is Still Unclear

OpenAI documents the user-facing boundary well enough to act, but several implementation questions remain open.

How Dot context is represented internally

The public documentation does not provide a complete schema for Dot context. It does not say which details remain as raw text, which become summaries, which are embedded or indexed, how conflicts are resolved, or how context is compacted after months of use.

It would be speculation to call every retained detail a conventional database row or to assume the model receives the entire lifetime context on every request.

How quickly deletion reaches every storage layer

The FAQ says deleting the Dot deletes its own context, but it does not give a Dot-specific deletion timeline or describe propagation through active systems, backups, safety records, and service-provider infrastructure.

OpenAI's broader consumer data guide explains account, Temporary Chat, model-improvement, human-access, and privacy-request controls. It does not turn the Dot FAQ's concise deletion statement into a detailed per-layer retention schedule.

Whether selective memory controls are planned

“Currently cannot” leaves room for a future product change, but OpenAI has not announced a public date or roadmap for viewing, correcting, or deleting individual Dot memories.

What reported memory surprises actually prove

Some users have reported surprising personal recall or objected to limited memory visibility. These posts show real concern and attention. They do not prove that OpenAI secretly restored deleted data.

A remembered detail could come from Dot context, ChatGPT Memory, recent conversation context, a connected app, a separately stored conversation, a file, another service, or model inference. Without a reproducible trace, absence from one settings screen is not proof of where the answer came from.

The complete behavior of every plugin

Dots can connect through a large plugin ecosystem. OpenAI documents shared permissions and action rules, but each connected service still has its own retention, deletion, audit, sharing, and backup behavior. A Dot deletion cannot promise to erase a copy already created in a third-party system.

What Dots Do to Reduce Risk

The memory limitation should not be presented as if Dots have no safeguards.

Proactive research is restricted to read-only tools

OpenAI says a Dot's proactive background research can read from permitted connected sources and save private notes, but those research tools cannot directly send messages, change plugin content, or control a browser or computer.

Any follow-up action is subject to the normal action rules and safety checks.

Sensitive actions can require approval or takeover

The FAQ says the most sensitive actions, such as changing a password or transferring money, require the user to take over. Other actions, including permanently deleting data or installing software, may require approval each time. Some recurring actions can be approved in advance within the authorized scope.

Approving one message does not grant ongoing permission to contact people on the user's behalf.

Custom Rules and Auto-review add policy layers

Users can set Custom Rules to allow, require approval for, or block supported actions. Auto-review checks certain planned actions against the user's instructions, Custom Rules, and safety requirements.

OpenAI says Custom Rules cannot disable core safety requirements, turn off Auto-review, or remove proactive-research restrictions. These layers reduce action risk, but OpenAI also says Dots can still make mistakes.

The Dot's cloud computer is separate by default

The Dot runs on its own cloud computer. OpenAI says a user's personal computer and contents remain separate unless the user chooses to connect the device and grants the required operating-system permissions for camera, microphone, or screen access.

That boundary is material. It is not the same as a promise that all Dot processing stays on the user's device—the opposite is true: the Dot is a hosted cloud agent.

Does OpenAI Train on Dot Conversations and Work?

The answer depends on the account and settings.

For ChatGPT Business, Enterprise, and Edu workspaces, OpenAI says it does not use workspace data to train its models by default.

For personal ChatGPT plans, the Improve the model for everyone setting controls whether eligible Dot conversations and work may be used to improve models. OpenAI says this can include:

OpenAI says it does not train directly on proactive background research or the Dot's private notes. If information from that research appears in an eligible conversation or task, it may be used depending on the user's setting.

Turning model improvement off is not the same as preventing every human access. OpenAI says limited human review may still occur for safety-related and other documented reasons. Its consumer data guide says authorized personnel and trusted service providers may access content when needed for abuse or incident investigation, support, legal matters, or model improvement where the user has not opted out.

A Practical Dots Privacy Checklist

Before creating a Dot

Before connecting a plugin

While using a Dot

Before deleting a Dot

Where OpenVeil Fits—and Where It Does Not

OpenVeil is a privacy-focused hosted AI workspace for adults. For normal conversations, it keeps the reopenable chat-history record in the browser instead of maintaining a normal server-side chat-history account record. Documented OpenVeil product content is not used to train foundation models.

That is a different product shape from an always-on personal agent with persistent cross-channel context and thousands of connected apps. OpenVeil can be a useful narrower workspace when the job is to ask questions, research, analyze files, draft, use voice, or create media without giving one agent long-lived authority across email, Slack, calendars, repositories, and other services.

The limits matter:

The useful comparison is not “private versus unsafe.” It is narrow conversational authority versus persistent agentic authority. Choose the smaller authority surface when the task does not require the larger one.

Frequently Asked Questions

Can I see everything my OpenAI Dot remembers?

No. OpenAI says users currently cannot view individual Dot memories. Activity View can show tasks and steps, but OpenAI does not describe it as a complete memory inventory.

Can I tell my Dot to forget one fact?

You can correct the Dot in conversation, but OpenAI's documented product control does not currently let you view, directly edit, or delete one individual Dot memory. The documented way to delete the Dot's own context is to delete the Dot.

Does turning off ChatGPT Memory erase the Dot's memory?

No. It stops future memory sharing between ChatGPT and the Dot. OpenAI says it does not delete information the Dot already received.

Does disconnecting Gmail, Slack, or another plugin erase learned information?

No. Disconnecting stops new access through that connection. It does not delete information already built into the Dot's context.

Does deleting the Dot delete its files and conversations?

No. OpenAI says files, Codex threads, and ChatGPT conversations are stored separately. Other ChatGPT memories also remain unless managed through their own controls.

Does the Dot retain passwords, images, or screenshots in its context?

OpenAI says Dot context does not retain credentials, images, or screenshots. Files and media stored in other locations follow those locations' retention rules.

Is proactive research allowed to send messages or edit files?

OpenAI says proactive research uses restricted read-only tools that cannot directly send messages, change plugin content, or control a browser or computer. Later actions follow the usual approval and safety rules.

Does OpenVeil offer a Dot with selective memory controls?

No. OpenVeil is not an always-on autonomous personal agent or a control panel for OpenAI Dots. It offers a narrower hosted AI workspace with browser-local normal chat history and documented no-foundation-model-training boundaries.

Bottom Line

OpenAI Dots are built to remember enough to be useful over time. Today, that convenience comes with a blunt memory control: you can delete the Dot's context by deleting the Dot, but you cannot inspect, edit, or delete one individual Dot memory.

Turning off ChatGPT Memory, disconnecting a plugin, deleting the Dot, and deleting files or conversations all affect different data paths. None should be described as universal erasure.

Before giving one always-on agent access to several parts of your life, decide whether you can live with that control model. Connect the minimum sources, keep consequential actions behind approvals, review the separate stores the Dot creates, and use a narrower workspace when persistent cross-service authority is unnecessary.

Sources

When privacy, account control, uploads, and search matter, OpenVeil gives you a private AI workspace designed for that job.