ChatGPT, Claude, Gemini and Copilot data privacy: what each provider does with your data
10 min read · Reference · Last verified October 3, 2026
As of October 3, 2026, the business and enterprise plans of ChatGPT, Claude, Gemini for Workspace and Microsoft Copilot all say they do not train on your prompts by default. Consumer plans differ, and retention varies by provider. None of these policies change what an employee types into the prompt box.
This is a reference, not a hot take. Each section summarises what the provider publicly states and links to the source, then points at where the real risk sits once the policy is in place.
OpenAI / ChatGPT
Consumer ChatGPT (Free / Plus / Pro)
- Training: conversations can be used to improve OpenAI's models unless you turn off “Improve the model for everyone” in Settings → Data controls. OpenAI says Temporary Chats are not used for training. How your data is used to improve model performance.
- Retention: Temporary Chats are deleted from OpenAI's systems after 30 days and may be reviewed only to monitor for abuse. Temporary Chat and data controls.
- Real risk: in a corporate context, a personal account means the company has no say over the training setting and no visibility into what was sent.
ChatGPT Business / Enterprise / Edu and the API
- Training: OpenAI says it does not train on inputs or outputs from business products by default. Enterprise privacy · ChatGPT Business data and privacy.
- Retention: Enterprise workspace owners can set a custom retention policy, and data is encrypted in transit and at rest.
- Real risk: employees still paste sensitive content in plaintext. Retention and training controls limit downstream exposure but don't change what reaches the model. If the conversation is retained for compliance, the secret in it is retained too.
Anthropic / Claude
claude.ai consumer (Free / Pro / Max)
- Training: Anthropic says chats are used for training only if you choose to allow it in Privacy Settings, or if a conversation is flagged for safety review. Incognito chats are not used even with the setting on. Is my data used for model training?.
- Retention: deleted chats leave your history immediately and are removed from back-end storage within 30 days. If you allow training, chats may be kept in de-identified form for up to 5 years. Content flagged for a usage policy violation can be kept for up to 2 years. How long do you store my data?.
Claude for Work / Enterprise / API
- Training: Anthropic says that by default it does not use inputs or outputs from its commercial products to train its models, and its commercial terms state that “Anthropic may not train models on Customer Content from Services”. Commercial data use · Commercial Terms.
- Retention: API inputs and outputs are automatically deleted from the back end within 30 days of receipt or generation, with limited exceptions. Zero data retention is available by agreement, and Enterprise plans can configure custom retention. Retention for commercial organizations.
- Real risk: Claude is a favourite for long-form work, so employees paste big artefacts: documents, threads, drafts. Claude Code adds repository files to the context. The provider's terms say what happens after the upload, not whether it should have been uploaded.
Google / Gemini
Consumer Gemini
- Training and review: a subset of chats is reviewed by human reviewers, including Google's trained service providers, to improve Google services. Reviewed chats are not deleted when you delete your activity and are kept for up to three years. Temporary chats are not used to train Google's AI models.
- Retention: Gemini Apps Activity auto-deletes after 18 months by default, configurable to 3 or 36 months or indefinite. Temporary chats are kept for 72 hours. Gemini Apps privacy hub.
- Real risk: personal Google accounts in a corporate setting sit outside Workspace audit logs.
Gemini for Google Workspace
- Training: Google says Workspace content is not human reviewed or used for generative AI model training outside your domain without permission.
- Retention: prompts and responses in Gemini in Workspace are retained from 90 days to indefinitely, as set by admins, and Gemini app conversations up to 36 months. Generative AI in Google Workspace privacy hub.
- Real risk: the large context window invites pasting full Docs and Sheets content. Workspace data controls cover documents at rest, not what a user types into Gemini.
Microsoft and GitHub Copilot
Microsoft Copilot and Copilot Chat (work accounts)
- Training: Microsoft says prompts and responses are processed within the Microsoft 365 service boundary under enterprise data protection and are not used to train the underlying foundation models. Copilot Chat privacy and protections.
- Retention: prompts and responses are logged and stored in Exchange for auditing and eDiscovery, and the same retention policies used for Microsoft Copilot apply.
- Real risk: users can paste or upload organisational content into the chat. Enterprise data protection governs what happens to it after, not whether it should be sent.
GitHub Copilot
- Training: GitHub states it does not use Copilot Business or Copilot Enterprise customer data to train AI models. Only individual plans may have data used for training, with an opt-out. Hosting of models for GitHub Copilot.
- Model providers: GitHub documents zero data retention agreements with OpenAI and with Anthropic for generally available Anthropic features.
- Real risk: Copilot ships nearby file content as context. A
.envopen in another tab can be uploaded as part of a request. Business terms don't prevent the upload, they say what happens to it after.
Cursor
- Training: Cursor's privacy policy states that they do not use Inputs or Suggestions to train their models - with narrow exceptions (security review, explicit feedback, or explicit user agreement). Users manage their preferences in-app.
- Routing: Cursor proxies to OpenAI, Anthropic, or its own models depending on settings. Bring-your-own-key changes who you trust but not what data leaves the laptop.
- Real risk: Cursor sends full file context and walks across files in agent mode. Their training-opt-out controls who can use the data after the fact; it does not redact what was actually sent.
The pattern
Every enterprise tier says the same thing in different words: we don't train on your data, we don't retain it longer than needed, and we limit who sees it. Those commitments are real and valuable. None of them prevent the actual exposure, which happens the moment the prompt is sent.
If the only thing between an employee's clipboard and a third-party model is a checkbox in a settings menu, the risk is what gets sent, not the retention policy. Redacting sensitive values before the prompt reaches the provider closes that gap. See how redaction works with ChatGPT and Claude and why DLP tools miss what goes into AI.
Want a control that catches it before the prompt is sent? NexusNest redacts sensitive data in prompts to ChatGPT, Claude, Gemini, Copilot and Cursor in flight, before they reach the provider. Explore PromptWall →
Frequently asked questions
Does ChatGPT use my data for training?
On consumer plans, conversations can be used to improve the model unless you turn off "Improve the model for everyone" in Data controls, and Temporary Chats are not used for training. OpenAI says it does not train on business data from ChatGPT Business, Enterprise, Edu or the API by default.
Does Claude train on my chats?
Anthropic says consumer chats on Free, Pro and Max are used for training only if you choose to allow it or if a conversation is flagged for safety review. For commercial products and the API, Anthropic says it does not use inputs or outputs to train its models by default.
Is Gemini private for work use?
Google says content in Gemini for Google Workspace is not human reviewed or used to train generative AI models outside your domain without permission. Consumer Gemini works differently: a subset of chats is reviewed by human reviewers, and activity auto-deletes after 18 months by default.
Does Microsoft Copilot train on my prompts?
Microsoft says Copilot Chat prompts and responses are processed within the Microsoft 365 service boundary under enterprise data protection and are not used to train the underlying foundation models. Prompts and responses are logged for audit and eDiscovery.
If the provider does not train on my data, is it safe to paste sensitive data?
Not automatically. Training opt-outs and retention limits govern what happens after the data reaches the provider. They do not change what an employee sends. Redacting sensitive values before the prompt leaves removes the exposure at the source.
Sources
All claims in this article come from each provider's own public documentation, linked in the sections above, and were last checked on October 3, 2026. Providers update terms often, so check the source pages for the current version.
- Cursor - Privacy & Privacy Mode
Related
Product
- PromptWall Redacts sensitive data before it reaches the AI tool.
- NetLens How AI is really used, on redacted text only.
- AI Control Panel Buy, assign and revoke every AI account.
- Pricing Plans for every team size.
Keep reading
- Redact sensitive data before ChatGPT and Claude What redaction software works with AI tools.
- AI governance vs DLP Why DLP tools miss what goes into AI.
- Stop employees pasting data into ChatGPT A playbook that does not block productivity.