
The Paragraph You Cannot Take Back
Someone on your team pastes a client contract into a chatbot and asks for a summary. The summary is excellent. The question of where that contract now lives arrives about four seconds later, usually from someone in a different department.
This is the most common privacy question in small organisations right now, and it rarely gets a clean answer. Search results are full of confident claims that were true for one product on one tier in one year.
The answer is knowable, and it takes about ten minutes per tool. What makes it hard is that most people ask one question when there are really three.
The Short Answer
Whether your input trains a model depends on the tier you are using, not on the brand. Consumer plans have commonly used conversations to improve models with an opt-out available, while business, enterprise, and developer tiers typically exclude customer content from training by default.
That default matters more than any setting, because defaults are what applies to the colleague who signed up alone on a Tuesday. Nobody reads a data policy before pasting.
The workable rule is short. Put confidential material only into a tier where non-training is the default and the terms are in writing, and treat every other tool as public.
Three Questions Hiding Inside One

The first question is training. Does your content get used to improve the model that other people will use later? This is the one everybody asks and the easiest to control.
The second is retention. How long does the provider keep what you sent, even if it never trains on it? Abuse monitoring, support, and legal obligations mean the answer is rarely zero, and retention windows differ by tier.
The third is human review. Can a person at the company see a conversation, and under what circumstances? Most providers describe some limited review for safety and quality, which is precisely why a training opt-out is not a confidentiality guarantee.
Answer all three before you decide a tool is safe for sensitive work. A product can be excellent on the first question and unremarkable on the other two.
Where the Setting Usually Lives
Look in account settings under a heading about data controls, privacy, or model improvement. Consumer products tend to place the training toggle there, sometimes bundled with chat history.
Read what the toggle actually does before you relax. In several products, switching off training also disables saved history, which changes how the tool works day to day and pushes people to switch it back on.
Workspace and business plans usually move the decision upward. The administrator sets it once for everyone, which is the main practical advantage of a business tier over a pile of individual subscriptions.
Developer access through an API is the third case. Non-training is the common default there, with separate retention windows described in the documentation.
How the Tiers Actually Differ

Tier, not brand, is the variable that predicts the terms. This table describes the typical shape of the market rather than any one product, because specific terms change and belong on the provider’s own page.
| Access type | Typical training default | Typical retention | Admin control | Suitable for confidential work |
|---|---|---|---|---|
| Free consumer chatbot | Often used to improve models, opt-out available | Retained unless deleted | None | No |
| Paid consumer subscription | Same as free tier in many products | Retained unless deleted | None | No |
| Business or team workspace | Customer content typically excluded | Defined window, admin visibility | Yes | Usually, with terms in writing |
| Enterprise agreement | Excluded, contractually documented | Negotiated | Yes, plus logging | Yes |
| Developer API | Excluded by default in most platforms | Short defined window | Via account | Yes, if your own storage is secure |
| Third-party app built on an API | Depends on that app, not the model provider | Depends on that app | Varies | Only after checking the app itself |
| Free browser extensions | Frequently unclear | Frequently unclear | None | No |
The row that catches organisations out is the last two. A note-taking tool or extension built on someone else’s model has its own policy, and the reassuring name of the underlying model tells you nothing about it.
The row that saves money is the business workspace. Moving a team off individual consumer subscriptions usually costs less than the first incident review would.
The Clauses Worth Finding in a Policy
Search the policy for the word “improve”. Language about improving services or models is where training permissions usually sit, and it is often phrased in a way that reads harmless.
Then search for “retain” and “delete”. You want the retention period, whether deletion is available on request, and whether deleted content persists in backups for a further window.
Look for “human review” or “authorised personnel” next. The presence of such a clause is normal, and its absence is more likely a sign of a vague policy than of stronger protection.
Finally check for “sub-processor” or a list of third parties. A tool that passes your content to another vendor inherits that vendor’s practices, and you inherit both.
What a Professional Duty Adds on Top
If you handle client data under a professional obligation, the vendor’s terms are the floor rather than the answer. Accountants, lawyers, clinicians, and recruiters all carry duties that no software setting satisfies on their behalf.
Two extra requirements usually apply. You need a documented basis for using the tool, and you need to be able to describe what happened to a specific record if someone asks.
Client consent and contractual clauses may also come into play, particularly where a contract predates the availability of these tools. Older agreements often contain confidentiality language that assumes no third-party processing at all.
Regulated fields have another wrinkle worth naming. Regional rules on where data is stored can rule out a tool entirely, no matter how good its training policy looks.
Which Setup Fits Your Situation

The solo freelancer using AI for drafting: A consumer plan is fine for your own writing, marketing copy, and general research. Keep client names, contracts, and anything under an agreement out of it entirely.
The small team with shared clients: Move to a business workspace and set the policy centrally. The cost difference is modest and it removes the weakest link, which is the individual account nobody configured.
The agency handling client material daily: Business or enterprise tier, written terms, and a one-page internal rule about what may be pasted. Your clients will eventually ask, and the answer should already exist.
The developer building a product on an API: Check the platform’s retention window, then audit your own storage. Most real exposure in this setup comes from logs and databases you control rather than from the model provider.
The healthcare, legal, or financial professional: Assume no general consumer tool is acceptable for client material. Use tools your regulator or professional body recognises, and document the reasoning.
The manager who suspects staff are already pasting things: Ask before you ban. A short survey usually reveals the specific tasks people are solving, and a sanctioned tool for those tasks works better than a rule nobody follows.
A Ten-Minute Audit You Can Run This Week
List every AI tool anyone on the team uses, including browser extensions and anything bundled into software you already pay for. The list is almost always longer than the manager expects.
For each one, find the tier, the training default, and the retention period. Write the three answers in a shared document with the date you checked them.
Then set the rule in one sentence per tool. Something as plain as “client names never go into this one” is understood and followed far more reliably than a policy document.
Revisit the list twice a year. Terms change, tools get acquired, and the extension somebody installed in March is still running in September.
Decide Once, Write It Down
The genuinely dangerous state is not using these tools. It is using them without anyone knowing which tier is in play or what the terms say.
Ten minutes per tool converts an open question into a written answer, and a written answer survives staff changes. That is the whole exercise.
For choosing tools in the first place, our roundup of AI tools for small business covers the wider selection. Meeting recordings raise this question most sharply, and our guide to AI meeting assistants covers what to check before one joins a client call.
FAQ
Do AI tools train on the things you type into them?
It depends entirely on which tier you are using. Consumer plans have often used conversations to improve models unless you switch that off, while business, enterprise, and developer tiers typically exclude customer content from training by default. Confirm the current terms on the provider's own site before assuming either.
Is turning off training history the same as deleting my data?
No, and conflating the two causes most of the confusion here. Opting out of training usually stops your content improving future models, while the provider may still retain it for a period to handle abuse and support. Retention and training are separate settings with separate timelines.
Can staff at an AI company read my conversations?
Limited human review exists at most providers for safety and quality purposes, and the policies describe when it applies. This is why confidential material should not be pasted into a general assistant regardless of the training setting. Access being rare is not the same as access being impossible.
Does a paid subscription mean my data is private?
Paying more does not automatically change the data terms. What matters is the tier you are on, since a consumer subscription and a business workspace can sit at completely different points in the same company's policy. Read the terms attached to your specific plan.
What should I do if a colleague already pasted client data into a chatbot?
Treat it as a disclosure and follow whatever process your organisation uses for one. Check the workspace settings, request deletion where the provider offers it, and record what was shared. Then fix the cause, which is almost always the absence of a clear internal rule.
Some links may be affiliate links. We may earn a commission at no extra cost to you.
This article was written with AI assistance. It is researched and fact-checked, not based on personal hands-on testing unless explicitly stated.
Comments
Post a Comment