// AI Privacy
What Goes In: Who Trains on Your Data
Part 1 of a 2 Part series on AI Privacy.
Many people have the same question. They want to use ChatGPT or Claude for real work, but they're nervous about what happens to whatever they type in. Is it private? Is some engineer reading it? Is it getting baked into the next model so it can pop out in front of a stranger someday?
It isn't which company you pick. It's whether you're on a consumer plan or a business plan. That line runs straight through every major provider.
So I went through the big models the way you'd vet any vendor you let near your data. The current terms for Anthropic (Claude), OpenAI (ChatGPT), Meta AI, and xAI's Grok, lined up against three questions. Do they train on your consumer chats by default? Can you turn that off? and, what do the business contracts actually promise?
The one rule that covers most of it
If you handle client data, health or financial records, or anything you'd call a trade secret, do not run it through a free or personal account. Use a business or enterprise tier with a signed Data Processing Agreement, and a HIPAA Business Associate Agreement if you touch health data.
That's the whole ballgame for most small businesses. Everything below is the detail behind it.
The reason the rule works is that all four providers draw the same dividing line. On the business side, your data is contractually walled off from training. On the consumer side, every one of them now uses your chats to improve their models by default. Three let you opt out. Meta doesn't, at least not in the U.S.
Here's how they stack up.
Provider | Trains on consumer chats by default? | Consumer opt-out? | Business tier trains by default? |
|---|---|---|---|
Anthropic (Claude) | Yes, since Sept 2025 | Yes | No |
OpenAI (ChatGPT) | Yes | Yes | No |
Meta AI | Yes, and feeds ad targeting | No U.S. opt-out | N/A |
xAI (Grok) | Yes | Yes | No |
Now the provider-by-provider tour, because the differences in the fine print are where it gets interesting.
Anthropic (Claude)
For years Anthropic was the privacy holdout. Consumer chats weren't used for training and got deleted in 30 days. That changed in 2025. Under the updated consumer terms, Claude Free, Pro, and Max users now have to actively opt out, or their new chats get used to train the model. Existing users had until September 28, 2025 to choose.
You turn it off at Settings, then Privacy, then "Help improve Claude." Critics called the consent popup a dark pattern because the data-sharing switch was pre-toggled on next to a big "Accept" button. If you leave training on, retention jumps from 30 days to as long as five years in de-identified form. That's roughly a sixtyfold increase, which is the kind of detail nobody mentions in the cheerful "we've updated our terms" email.
Business is cleaner. Claude for Work, Education, and API access run under commercial terms and are not used for training. That's a contract, not a toggle you have to remember to flip.
OpenAI (ChatGPT)
Same basic shape. Free, Plus, and Pro personal accounts feed model improvement by default through a setting called "Improve the model for everyone," which is on unless you change it. You'll find it under Settings, then Data Controls. Temporary Chat skips both training and history.
The wrinkle here is the lawsuit. In the New York Times case, a judge ordered OpenAI to preserve all output logs, including deleted chats, for consumer users. That indefinite-hold ended in September 2025, and OpenAI went back to its normal 30-day deletion. But in January 2026 a separate order required OpenAI to hand over a sample of 20 million de-identified ChatGPT logs in discovery. Worth knowing that "I deleted it" and "it's gone" aren't always the same sentence when litigation is involved.
Business and API data isn't trained on by default. DPAs and HIPAA BAAs are available for the right tiers.
Meta AI
This is where it stops being a normal privacy conversation. Meta uses your AI interactions to improve its products by default, and there is no consumer toggle to stop it. Private messages with friends aren't used unless someone drops them into a Meta AI chat. Public Facebook and Instagram posts are fair game.
U.S. users have no opt-out. The objection form Meta offers only applies in places like the EU, the UK, and Brazil where the law forces the issue. And starting December 16, 2025, Meta AI conversations don't just train the model, they feed ad targeting across Facebook and Instagram. Religion, health, and politics are excluded from targeting on paper. The broader move is plain enough. For Meta, your chatbot conversations are a new input into the same advertising engine that's been running for fifteen years.
A coalition of 36 privacy organizations asked the FTC to step in. One advocate described it as industrial-scale privacy abuse wearing the costume of a friendly assistant. There's no enterprise version that fixes this. Meta's business product is a customer-service bot, not a confidential-work tool. Treat Meta AI as public.
xAI (Grok)
Grok is the most tangled up with a social platform, and that's the problem. By default it trains on your content and interactions. If you use Grok inside X, your public posts and prompts get used to fine-tune the model.
The part that you should pay attention to is the licensing. X's updated terms, effective January 15, 2026, expanded the definition of "Content" to explicitly include your AI prompts, inputs, and outputs, and granted X a worldwide, royalty-free, perpetual license to use them for any purpose. You can opt out of the in-app training, but that doesn't touch the broader content license.
And like the others, Grok had a sharing leak. In August 2025 its "Share" feature exposed conversations to search engines with no warning, and reporting found that more than 370,000 chats got indexed, including medical questions, business details, and at least one password. There's an enterprise tier with zero data retention, but on the consumer side, assume anything you put into Grok on X is effectively public.
What to actually do
If you handle anything sensitive, use a business tier with a DPA, and a BAA if health data is involved. ChatGPT Enterprise and Claude for Work both contractually keep your data out of training, and the same is true of the business tiers from Google and other major providers. For the strictest setup, ask for zero data retention in writing, because it isn't automatic and it isn't universal.
If you have to use a consumer tool, turn off training now and use the temporary or incognito mode when it exists. Claude and ChatGPT both give you the switch, as do most of the other consumer apps. Just remember the opt-out only works going forward. It can't pull your old chats out of a model that already learned from them.
And treat Meta AI and Grok-on-X as public spaces. Don't paste a client contract into either one. For that matter, don't hit "Share" on any chatbot for anything you wouldn't post on a billboard, because OpenAI, Meta, and xAI have all leaked shared chats to search engines.
What stands out across all of it is how invisible it is. You download an app, type into the box, maybe connect your email, and it feels like texting a smart friend. The part where your words might sit on a server for five years, get read by a human, or end up training the next model is buried in a settings menu most people never open. Worth opening it.
This is part one of two. This week was about what goes in, the data you hand over and what gets done with it. Next week is about what comes out, what someone can pull back out of an AI model after it's trained, and why the people most exposed are often the ones already underserved.
Liked this? There’s more.
AI news and know-how for the Gulf Coast, straight to your inbox. No spam, ever.
Subscribe