At this point I would be surprised if internal sandboxes are not trivially by-passed and that openai's agents do not (at the very least) have complete read access to all user accounts, chat histories and uploaded documents. Orthonogally, openai could still be wholesale lying about not training on this user data, of course.