Where your AI chats live, and who can read them
Work out in 20 minutes which of your AI accounts is safe to paste a client's material into, and fix the two or three that are not.
on this page · 0 / 0 checked
Most of what passes through your business now passes through a chat box first. A client’s contract, a half-priced quote you are testing, the paragraph of an email you did not want to write, the spreadsheet with everyone’s rates in it. All of it lands in a company’s systems under a retention policy you agreed to by clicking a button, and you have almost certainly never read the number that matters: how long the copy sticks around after you delete it.
This guide is the 20-minute version of reading it. It covers the three vendors a small operator actually uses, what each one keeps and for how long, and the one change that moves your exposure more than every privacy toggle combined. It is not compliance advice. If you handle patient records, regulated financial data, or anything governed by a specific regime, you need a lawyer and a signed data processing agreement, not a web guide. This is for the freelancer or the four-person team who wants to know which of their existing accounts is safe to paste a client’s material into on a Tuesday afternoon.
The tier you buy decides more than the toggle you flip
Every vendor runs two different businesses under one brand. The consumer product is cheap because your usage is worth something to them. The commercial product is a contract, and the contract is where the promises live.
On Claude’s consumer plans, deleted conversations are “removed from your chat history immediately” and “deleted from our back-end storage systems within 30 days” [2]. If you leave model improvement on, Anthropic says it “may retain your data in a de-identified format for up to 5 years in our model training pipelines” [2]. That difference is visible on the price list: model training is shown as “Opt-out” on Free, Pro and Max, and “None by default” on Team and Enterprise [4]. Anthropic’s Commercial Terms of Service, which state that the services they cover “are not for consumer use” because “our consumer offerings (e.g., Claude.ai) are governed by our Consumer Terms of Service instead”, contain one flat sentence: “Anthropic may not train models on Customer Content from Services” [3].
OpenAI draws the line in the same place. Its enterprise privacy page states that “data from ChatGPT Business, ChatGPT Enterprise, ChatGPT for Healthcare, ChatGPT Edu, ChatGPT for Teachers, and the API Platform (after March 1, 2023) isn’t used for training our models, unless you have explicitly opted in to share your data with us to improve the services” [5]. API inputs and outputs are held “for up to 30 days to provide the services and to identify abuse”, then removed “unless we are legally required to retain them” [5]. You “can also request zero data retention (ZDR) for eligible endpoints if you have a qualifying use-case” [5]. Consumer ChatGPT is not on that list of products excluded from training, which is the tell: when a vendor publishes the set of tiers it will not train on, the tiers missing from the set are the answer to your question.
Google’s consumer assistant works on a timer instead of a contract. You can “change your auto-delete setting in Gemini Apps Activity from the default of 18 months to 3 months, 36 months, or indefinite” [8]. Turning the Keep Activity setting off does not mean nothing is stored: “Future chats are still saved for 72 hours so Gemini can respond to you, process your feedback, and protect Google, its users, and the public” [8].
So the honest summary is that a consumer account is a good place to think out loud and a bad place to put material you do not own. That is not a moral judgment about the vendors. It is what you bought.
”Deleted” means at least three different things
When you press delete, three separate things could happen, and only the first one is guaranteed.
The chat leaves your screen. That happens immediately on Claude [2]. Then, on a delay, it leaves back-end storage: 30 days for Claude consumer plans [2], and up to 30 days for OpenAI API inputs and outputs unless the law requires longer [5]. Then there are the derived copies, and this is the layer nobody checks.
Google is unusually direct about it. Chats picked for human review “(and related data like your language, device type, location info, or feedback) are not deleted when you delete your activity. Instead, they are retained for up to three years” [8]. Your delete button does not reach them. Anthropic’s consumer retention page has the same shape of exception in a different place: if a chat or session is flagged, Anthropic retains “inputs and outputs for up to 2 years and trust and safety classification scores for up to 7 years” [2].
The practical version is that deletion is a promise about the copy you can see, plus a shorter promise about the copy in storage, plus no promise at all about a copy a human or a classifier has already touched. If a paragraph would be a problem in three years, deleting the chat is not the control you think it is.
A court order outranks the privacy page
In June 2025, OpenAI published its response to a court order in the New York Times case that required it to “retain consumer ChatGPT and API customer data indefinitely”, including “even deleted ChatGPT chats and API content that would typically be automatically removed” [6]. The retention policy did not change. The policy was simply outranked.
The detail worth memorizing is who was exempt. “This does not impact ChatGPT Enterprise or ChatGPT Edu customers. This does not impact API customers who are using Zero Data Retention endpoints under our ZDR amendment” [6]. OpenAI’s obligations “under the earlier order ended on September 26, 2025”, and it now says it will “securely store limited historical April–September 2025 user data” that “will not be turned over to the New York Times, the Court, or anyone else at this time” [6].
Read that exemption list again. It is not a list of people who cared more about privacy. It is a list of contract tiers. When an outside party reached in, the boundary it stopped at was commercial, not technical and not ethical.
The new pattern is vendors handing you the keys and the alerts
The current direction of travel is worth understanding even though you will not buy it, because it tells you what the vendors think sovereignty actually costs.
Anthropic announced Enterprise Frontier Safeguards on 1 September 2026, “rolling out to customers in phases, starting later this fall” [1]. Activity data used for monitoring “can be stored in the customer’s own cloud account (such as Amazon S3, Azure Blob Storage, or Google Cloud Storage)”, so that data lives “in infrastructure they control, under their own encryption keys, access policies, and audit logging” [1]. Anthropic “doesn’t charge for Enterprise Frontier Safeguards”; if you store data in your own cloud account, “their cloud provider bills them for that storage, as well as reads, writes, and data egress fees” [1]. Automated systems still analyse traffic for “attempts to develop offensive cyber or biological capabilities and signs of stolen or leaked credentials”, but when something fires, “those flags go directly to the customer and their people take it from there”, and “no human review by Anthropic employees is required” [1]. Until the full system is ready, “eligible customers will receive ZDR on Fable 5 and Fable 5.1” [1].
OpenAI previewed the same shape on 19 August 2026. Its Private Safety Processing is built so that “automated systems can identify potential misuse and return limited safety signals without exposing the underlying prompts or responses to OpenAI personnel”, with OpenAI receiving only “a narrowly defined signal indicating the type of activity involved” [7]. For zero data retention deployments, “customer content remains on infrastructure the customer controls”, and OpenAI says it is “also developing an option in which content is stored on OpenAI infrastructure, encrypted with keys controlled by the customer” [7].
Notice what is being transferred along with the encryption keys. Somebody now has to receive an alert saying a session looked like credential theft, at 2am, and decide what to do. Anthropic says it developed its version “in close collaboration with more than 100 customers”, including the Analysis and Resilience Center for Systemic Risk, “whose members include the chief information security officers of the largest US banks, including Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo”, plus leaders at Comcast, KPMG, Mastercard, Salesforce and Visa [1]. Those are organizations that already run a staffed incident response desk. Data sovereignty at the top of the market is sold as a transfer of responsibility. That is the reason it is free, and it is the reason it does not scale down to you: you would be buying an alert stream with nobody behind it.
The 20-minute pass that actually changes your exposure
Start by listing the AI accounts that touch material you do not own. For most solo operators that is two or three: a main assistant, whatever is inside the code editor, and one research tool.
For anything client-owned, move it onto a tier the vendor’s own terms exclude from training. This is the single change with the biggest effect, and it is cheaper than people assume. Claude Team is $20 per seat per month billed annually, or $25 monthly, “for teams of 2 to 150”, and its feature list includes “no model training on your content by default” [4]. Claude Pro, the consumer plan, is $17 per month with the annual discount, $200 billed up front, or $20 monthly [4]. On a per-person basis you are paying single-digit dollars a month to move from a toggle to a plan whose default is the other way round.
For consumer accounts you keep, turn model improvement off and treat the 30-day back-end window as your floor rather than your ceiling [2]. On Gemini, set Gemini Apps Activity auto-delete to 3 months, the shortest option offered [8], and write down somewhere that human-reviewed chats will outlive it by up to three years [8]. If you build on an API, ask your vendor directly whether your endpoints qualify for zero data retention before you assume they do [5].
Then account for the tools that are not chat windows. A code editor, a workspace, an answer engine and an automation runner each publish their own retention terms, and each is a separate company holding a copy. Connecting two of them does not average their policies, it stacks them: your client’s document is now governed by whichever one keeps it longest, on whichever tier you happen to be paying for there. The work is boring and it is 10 minutes per tool. Open the vendor’s own privacy or security page, find the retention number and the training clause, and write both in a note next to the account name. If a vendor makes that hard to find, treat the difficulty as the answer.
Defaults are Claude Team annual and Claude Pro annual [4]. Computed in the page; nothing is sent anywhere.
What still goes wrong
You cannot verify any of this. Nothing on a retention page gives you a way to confirm that a deletion actually happened, or that a copy was not made somewhere you were not told about. You are trusting an assertion from a company with a commercial incentive to make it, and the only real remedy is that a false assertion in a signed contract is a much bigger problem for them than a false one in a help article. That asymmetry is the whole reason the tier matters.
Note also how much of the protection is worded as a default rather than an absolute. Anthropic’s price list says “None by default” for Team and Enterprise model training [4], and OpenAI’s exclusion holds “unless you have explicitly opted in to share your data with us to improve the services” [5]. A default is a thing an administrator can change, including one who is not you. If you are buying seats for other people, check the admin setting as well as the plan.
Zero retention is also never quite zero. Claude retains flagged inputs and outputs for up to 2 years and classification scores for up to 7 years [2], and OpenAI states that “images flagged for potential CSAM will continue to be retained for manual review and reporting purposes, even in Zero Data Retention deployments” [7]. Both exceptions are defensible. Both mean the marketing word and the operating reality are different words, and you should plan against the second one.
Finally, these numbers move. Consumer terms get revised, court orders arrive and expire, and a tier that carried a no-training default when you signed up may be restructured. Every date in this guide is the date it was checked, at the top of the file. Diary a 15-minute re-read once a year, and do it again the week any vendor emails you about updated terms, because that email is the only warning you will get.
- 01Anthropic — Developing Enterprise Frontier Safeguards with our customersanthropic.com
- 02Anthropic Privacy Center — How long do you store my data?privacy.claude.com
- 03Anthropic — Commercial Terms of Serviceanthropic.com
- 04Anthropic — Claude pricingclaude.com
- 05OpenAI — Enterprise privacyopenai.com
- 06OpenAI — How we're responding to The New York Times' data demandsopenai.com
- 07OpenAI — Offering Zero Data Retention for frontier modelsopenai.com
- 08Google — Gemini Apps Privacy Hubsupport.google.com