In short: Custom audiences in ChatGPT Ads are built on customer lists you upload in Ads Manager: Email addresses and phone numbers, raw or SHA-256-hashed, or Android advertising IDs, as CSV or TXT. The lists are matched against signed-in users and can be included or excluded in campaigns, with a minimum of 25,000 matched users. This guide covers the two choices that actually matter: Whether audience lists are the right tool at all in a channel where most of the traffic is new customers, and how to handle the GDPR side properly. Because uploading customer lists to an ad platform is a privacy decision, not a technical detail.
What custom audiences are
Under Audiences in OpenAI Ads Manager you can create custom audiences by uploading lists of identifiers. The format requirements are simple:
- Email addresses and phone numbers, either raw or already SHA-256-hashed
- Android advertising IDs (GAID), raw
- File format: CSV with column headers or TXT with one value per line, up to 500 MB
You can create an empty audience first and add members later, and for TXT files you select the identifier type separately. After upload, the list is matched against signed-in ChatGPT users, and the audience becomes usable in campaigns once it has at least 25,000 matched users. That number is worth pausing at: Since people often use a different email address in ChatGPT than the one they gave you, only a share of your list will match, so your raw list should be considerably larger than 25,000. For many businesses this is the real threshold.
First choice: Are lists the right tool in this channel?
The reflex from Meta and Google is to use customer lists for retargeting and lookalikes. Leave that reflex at the door here, for one simple reason: Over 80 percent of ad-driven ChatGPT traffic comes from new customers. ChatGPT Ads is a new-customer channel, where the strength is meeting people in the middle of a decision they are discussing with an advisor, and the primary targeting is the conversation's context through context hints, not who the user is.
That leaves three sensible use cases, in order of priority:
- Excluding existing customers. The most underrated move. Upload your customer list as an exclusion and you stop paying for clicks from people who already buy from you, so the whole budget works on new customers. In a channel where the traffic is new anyway, this is the cheapest optimization there is.
- Excluding employees and partners. The same logic at smaller scale, mostly relevant for large organizations that clear the match threshold.
- Including warm lists. Known contacts who are not customers yet, for example leads from events or downloads. It works, but requires large lists, and ask yourself honestly whether email does not reach the same people cheaper.
If your lists are too small for the minimum, that is not a loss. Contextual targeting is the channel's real strength, and your money is usually better spent on good context hints and more ad variants.
Second choice: The GDPR side, and why hashing does not save you
When you upload a customer list to OpenAI, you are sharing personal data with a third party for marketing purposes. That triggers a set of obligations, and the most common misunderstanding first: Hashing is not anonymization. A SHA-256-hashed email address is still personal data under the GDPR, because anyone who already holds the address can unambiguously link it to a person. Hashing is good security practice in transit, not an exemption from the rules. That means you need four things in order:
- A legal basis. The safe basis for sharing customer data with an ad platform is consent. Check what people actually consented to when you collected the address: A yes to a newsletter is not a yes to sharing the address with OpenAI. If you rely on legitimate interest, the balancing test must be documented, and the right to object to direct marketing is absolute either way.
- The duty to inform. Your privacy policy must describe that customer lists may be shared with ad platforms for targeting and exclusion, who the recipients are, and how people opt out. When we set up our own advertising, we updated our policy before the first krone was spent, and we recommend that order.
- Minimize and clean up. Upload only the identifiers needed for matching, never full CRM exports with names, purchase history and notes. Delete audiences that are no longer used, and establish a routine for updating exclusion lists when customers request deletion.
- Third-country transfers. OpenAI is a US company, so the upload involves a transfer to the US. Make sure the legal mechanism, the EU-U.S. Data Privacy Framework and Standard Contractual Clauses, is documented in your assessment.
Does that sound like a lot for an ad feature? That is the point. The exclusion list that saves you a few hundred euros a month is quickly not worth an inadequate consent history. Do the work once, document it, and reuse the setup across platforms.
Practical checklist before uploading
- Clarify the purpose: Exclusion or inclusion, and of whom
- Verify that the consents or legal basis cover sharing with OpenAI
- Update the privacy policy before the list is uploaded
- Hash email addresses and phone numbers yourself with SHA-256, and remove all other columns
- Check that the list is large enough for the 25,000 threshold to be realistic after matching
- Set a calendar reminder to maintain and delete lists
Audiences and the pixel are two sides of the same data strategy
Customer lists tell the platform who to reach or avoid. The OpenAI pixel tells it what actually happens afterwards: Which clicks become leads, bookings and purchases. If you have to pick one first, pick the pixel. It has no minimum volume, it makes conversion optimization possible, and it builds the measurement data you need to judge whether audience lists are worth the effort at all. The whole paid picture, with the platforms, the prices and the interplay with organic visibility, lives in the pillar guide on AI advertising.
