Category: AI

  • Paying for ChatGPT or Claude Doesn’t Make Your Business Data Confidential

    Paying for ChatGPT or Claude Doesn’t Make Your Business Data Confidential

    A growing number of business owners run day-to-day work, drafting emails, summarizing contracts, brainstorming strategy, through a paid AI subscription, and assume that because they’re paying, their conversations are private. That assumption is often wrong. Consumer-paid plans like ChatGPT Plus or Pro, Claude Pro or Max, and Gemini Advanced buy you speed, higher limits, and better models than the free tiers, but they remain consumer products governed by individual terms of service and privacy policies, not the enterprise contracts that come with real confidentiality guarantees.

    This post covers general business confidentiality. It doesn’t address the separate, more demanding duty attorneys owe under the rules of professional conduct, that’s a different discussion for another day. If you’re a lawyer, the short version is: do not put client information into a free or consumer-tier AI tool. And to be clear, nothing here is a recommendation of one platform over another; each has its own strengths, and this is simply a look at what their policies actually say.

    Are Your Prompts and Responses Actually Confidential?

    Not completely. Your prompts and the model’s responses are processed and stored on the provider’s own systems, not end-to-end encrypted the way a secure messaging app is. Providers retain data for operational, safety, legal, and, depending on your settings, model-improvement purposes. Consumer paid plans don’t come with the contractual protections, a data processing agreement, zero-data-retention options, audit rights, that commercial and enterprise tiers typically include. Treating a paid consumer chat as a private notebook is a real risk for client data, employee or customer personal information, or anything covered by an NDA or a regulatory obligation.

    Will Your Conversations Be Used to Train the Model?

    This is where the platforms diverge most, and it’s worth checking your own account settings rather than assuming.

    • OpenAI (ChatGPT, including Plus): the default is on. Your conversations may be used to train future models unless you turn off “Improve the model for everyone” under Settings, Data Controls. Temporary Chats are never used for training and are deleted after 30 days regardless. Business, Enterprise, Team, and Edu plans include additional controls and generally exclude customer data from training by default.
    • Anthropic (Claude Free, Pro, Max): the default is off. Anthropic only uses your chats to improve Claude if you affirmatively turn that setting on in Privacy Settings, with one exception: conversations flagged by Anthropic’s safety systems can still be analyzed to improve abuse detection regardless of your setting. Incognito chats are excluded from training even when the general setting is on. Feedback submitted through the thumbs up or down button is retained for up to five years and may be used regardless of your training preference. Claude for Work and API accounts don’t train on customer content by default.
    • Google (Gemini, including Advanced): controlled by the “Keep Activity” setting. When it’s on, your chats, and Gemini Live audio, video, or screenshares, may be used to improve Google’s AI models, with your activity auto-deleted after 18 months by default (adjustable). When it’s off, chats aren’t used for training, but Google still retains them for 72 hours to operate the service and guard against abuse, and submitting feedback can bring part of that conversation back into scope for review.

    Across all three, an opt-out, or a decision not to opt in, is forward-looking only. Data already folded into a completed training run can’t be pulled back out after the fact.

    Can a Human Actually Read What You Typed?

    Yes, in a limited way, on every platform. A restricted set of employees or contractors can review flagged or sampled conversations to investigate abuse, respond to a support request you initiated, handle legal process, or check response quality when training and improvement settings are enabled. Google is explicit that a subset of chats go through human review to improve its models and keep the platform safe, and that reviewed conversations are retained separately for up to three years, even after you delete your own activity history. None of the major platforms promise that no human will ever see a given conversation; they promise that access is limited, logged, and tied to a specific business reason.

    What This Means for Your Business.

    A paid subscription buys you capability, faster responses, higher limits, stronger models, not enterprise-grade confidentiality. If your team is putting anything sensitive into an AI tool, contract terms, financial data, employee information, unreleased product details, the safer path is an approved commercial or enterprise account whose contract actually restricts training and human access, backed by an internal policy that keeps that kind of information off personal accounts.

    Even on a consumer plan, you can meaningfully cut your exposure:

    • Turn off the model-improvement or training setting, and use Temporary, Incognito, or “Keep Activity off” modes where available.
    • Keep confidential, personal, or regulated data out of the tool entirely.
    • Review and delete chat history on a regular schedule.
    • Check the current settings and policy language for the specific plan your team actually uses, these terms change, and the version that matters is the one attached to your account today.

    Policies on all three platforms have shifted meaningfully over the past year, and they’ll shift again. The summary above reflects each provider’s stated policy as of this writing; the only reliable source going forward is the terms and privacy settings tied to your own account.

    This post is provided for general informational purposes only and does not constitute legal advice. It does not address the separate confidentiality obligations attorneys owe under the rules of professional conduct. Reading this post does not create an attorney-client relationship. Contact ME to discuss your company’s specific circumstances.