Safety · Hero

Does ChatGPT, Copilot, Claude or Gemini train on your data?

The useful detailsIt depends on the plan, not the brand. As of October 2026, the personal versions of ChatGPT, Gemini and Claude can use your chats to improve their models unless you switch that off (ChatGPT and Gemini are on by default; Claude asks you to choose), while the business versions (ChatGPT Business and Enterprise, Microsoft Copilot on a work account, Claude Team and Enterprise, and Gemini in Google Workspace) don't train on your content by default. "Not used for training" still doesn't mean "not stored": every one of them keeps your chats for some period, and some keep them indefinitely unless an admin sets a limit.

The short answer, vendor by vendor

  • ChatGPT: Free, Go, Plus and Pro can train on your conversations unless you turn off Improve the model for everyone. OpenAI says it does not use Business, Enterprise or Edu workspace content for training by default (OpenAI, Data controls).
  • Microsoft Copilot: signed in with a work or school (Entra) account, prompts and responses are covered by enterprise data protection and are not used to train the underlying models (Microsoft). Signed in with a personal Microsoft account, consumer terms apply.
  • Claude: on Free, Pro and Max, Anthropic uses your chats for training only if you allow it in your privacy settings. On commercial plans (Team, Enterprise, the API), it does not train on inputs or outputs by default (Anthropic, consumer; Anthropic, commercial).
  • Gemini: on a personal Google account, chats saved while Keep Activity is on are used to improve Google's AI, with some reviewed by people. With a qualifying Google Workspace account, Google says your content is not human reviewed or used for model training outside your domain without permission (Google, Gemini Apps Privacy Hub; Google Workspace Privacy Hub).

Free downloadSetting rules for your team? Start from the free one-page AI use policy template.

The work-plan matrix (checked October 9, 2026)

This is the comparison most articles skip: the same four tools, split by the account type your staff actually sign in with.

Tool and planTrains on your content by default?Where the setting isWho controls itHow long chats are kept
ChatGPT Free, Go, Plus, ProYesSettings → Data controls → Improve the model for everyoneThe individual userSaved chats stay until deleted; deleted chats are scheduled for permanent deletion within 30 days. Temporary chats: up to 30 days
ChatGPT BusinessNoNot applicable; feedback you choose to send is the exceptionWorkspace adminsAdmins control retention; deleted or unsaved chats removed within 30 days, unless the law requires longer
ChatGPT Enterprise / EduNoNot applicableWorkspace adminsAdmins set retention; deleted chats removed within 30 days unless legally required
Copilot, personal Microsoft accountOlder app: yes, with an opt-out. New app (Aug 18, 2026): see note belowOlder app: Profile → Privacy → Training on conversation activityThe individual userOlder app: 18 months by default
Microsoft Copilot Chat / Microsoft 365 Copilot, work (Entra) accountNoNot applicable; look for enterprise data protectionMicrosoft 365 adminsLogged and governed by your organization's retention policies
Claude Free, Pro, MaxOnly if you allow itSettings → Privacy → Help improve our AI modelsThe individual userDeleted chats gone from back-end storage within 30 days. If training is allowed, de-identified data can be kept up to 5 years
Claude TeamNoNot applicableOwners (can also switch off the feedback buttons)Kept for chat history; deleted chats removed within 30 days
Claude EnterpriseNoNot applicableOwnersIndefinite by default; Owners can set a custom period, minimum 30 days
Gemini app, personal Google accountYes, while Keep Activity is onGemini Apps Activity → Keep ActivityThe individual userAuto-delete defaults to 18 months (3, 36 or never also available). With Keep Activity off, chats are held 72 hours. Human-reviewed chats: up to 3 years
Gemini in Workspace and Gemini app, work accountNoNot applicableWorkspace adminsWorkspace apps: 90 days to indefinite, set by admins. Gemini app: up to 36 months, default 18

Sources for every row are in the sections below and the source list at the end. Plans and settings change often; recheck the vendor page before you approve a tool.

ChatGPT: how to turn off ChatGPT training

On a personal ChatGPT account, the setting is called Improve the model for everyone. When it's off, new conversations aren't used to train OpenAI models, and they still appear in your history (OpenAI, Data controls).

ChatGPT opt-out of training, step by step (web):

  1. Open your account menu and select Settings.
  2. Select Data controls.
  3. Select Improve the model for everyone, turn it off, then Done.

On iOS or Android: open the sidebar, tap your profile icon, then Data controls and turn the setting off. Signed in, the choice follows your account across devices.

Three details trip people up:

  • Thumbs up or down overrides the opt-out for that chat. OpenAI says that if you send feedback, the entire conversation tied to it may be used for training.
  • Turning training off doesn't delete anything. Delete chats separately. A deleted chat is removed from your view immediately and scheduled for permanent deletion from OpenAI's systems within 30 days, with exceptions for security or legal obligations (OpenAI, Chat and file retention).
  • Temporary chat is the "don't keep this" option. It isn't used to train models, doesn't appear in history and doesn't update memory, but OpenAI may keep a copy for up to 30 days for safety.

ChatGPT Business and Enterprise. OpenAI's enterprise privacy page says it doesn't train on business data by default, unless you explicitly opt in, for example through feedback. In ChatGPT Business, workspace admins can view, export and delete members' conversations, which is worth telling staff.

Microsoft Copilot: does Copilot use your data for training?

The answer depends on how the person signed in.

Work or school (Entra) account. Microsoft Copilot Chat and Microsoft 365 Copilot run under enterprise data protection. Microsoft says prompts and responses stay within the Microsoft 365 service boundary, are logged under your retention policies, are available for eDiscovery, and are not used to train the underlying large language models (Microsoft 365 Copilot Business FAQ). Microsoft's Learn documentation says this protection applies when users sign in with Entra accounts, and lists the places a personal account can be used by mistake: the Copilot app, Edge, and Copilot Chat in Outlook and Teams (Microsoft Learn).

Personal Microsoft account. For the older consumer Copilot app, Microsoft's FAQ says it uses conversation activity (including uploaded images and files) for AI training except for opted-out users and some excluded groups, such as users signed in with Entra accounts, Microsoft 365 Personal and Family users of Copilot inside the Office apps, signed-out users and under-18s (Microsoft, Privacy FAQ for Copilot). Its opt-out is under your profile → Privacy → Training on conversation activity (and Training on voice conversations) (Microsoft, Copilot privacy controls).

Microsoft released an updated consumer Copilot app on August 18, 2026. Its privacy controls page, as of October 9, 2026, covers memory, shared experiences across Bing, Edge and MSN, chat history, web search and ads, and refers to the Microsoft Privacy Statement for how data is used. If staff use the new app on personal accounts, check the current statement rather than assuming the old opt-out still applies. For work, the simple rule holds: work content goes in through the work account.

Claude: is Claude training on my data?

On Claude Free, Pro and Max, Anthropic uses your chats and coding sessions to improve its models only if you allow it, or if a conversation is flagged for safety review (Anthropic).

How to turn off Claude training: select your name → Settings → Privacy, and toggle Help improve our AI models off. The same path works on mobile (Anthropic, change your settings). Turning it off stops your previous and new chats from being used in future training, but data already in a training run or a trained model stays there.

Retention is where Claude differs most from the others (Anthropic, how long we store data):

  • If you allow training, de-identified chats can be kept in training pipelines for up to 5 years.
  • Deleted chats leave your history immediately and back-end storage within 30 days.
  • Thumbs up or down feedback stores the whole conversation for up to 5 years.
  • Incognito chats aren't used for training even if the setting is on.

Claude Team and Enterprise. Anthropic doesn't train on commercial inputs or outputs by default, and Owners can switch off the feedback buttons for the whole organization under Organization settings → Data and Privacy (Anthropic, commercial). On Enterprise, chats and projects are kept indefinitely unless an Owner sets a custom retention period, with a 30-day minimum (Anthropic, Enterprise retention).

A next stepNot sure what your team already puts into AI tools? An AI security assessment finds out. Start with a free 30-minute call.

Gemini: how to stop Gemini training on your chats

On a personal Google account, the control is Keep Activity in Gemini Apps Activity. While it's on, Google uses your activity to provide and improve its services, including training generative AI models, and a subset of chats is reviewed by people; reviewed chats are disconnected from your account and kept for up to three years (Google, Gemini Apps Privacy Hub).

To stop Gemini training: open Gemini Apps Activity and turn Keep Activity off. Future chats won't be used to train Google's models unless you send feedback, but they are still held for 72 hours so Gemini can respond and for safety. Temporary chats aren't used for training either. Two catches: chats already reviewed aren't deleted when you delete your activity, and some connected apps, including Google Workspace, stop working in the Gemini app while Keep Activity is off.

Is Gemini training on Gmail? For Google Workspace business accounts, Google says your content, including what Gemini reads from Gmail or Drive to answer you, isn't used to train generative AI models outside your domain without permission and isn't reviewed by people (Google Workspace Privacy Hub). For personal accounts, the Gemini Apps notice says information Gemini gets from Connected Apps such as Gmail is saved and used under that notice, including to provide and improve Gemini Apps. If you connect a personal Gmail to the Gemini app, treat it like anything else you type into a consumer tool.

What "not used for training" doesn't cover

A business plan solves the training question. It doesn't solve these:

  • Storage. Claude Enterprise and ChatGPT Enterprise keep chats until someone sets a limit. Ask who owns that setting.
  • Internal visibility. ChatGPT Business admins can view and export members' chats; Copilot and Gemini prompts are discoverable under your own retention and eDiscovery tools. Tell staff before they assume a chat is private.
  • Feedback buttons. On ChatGPT, Claude and Gemini consumer plans, a thumbs up or down can send the whole conversation for review or training.
  • Connected apps and plug-ins. Third-party connectors follow their own terms, not the AI vendor's.
  • Your obligations. Under PIPEDA, an organization stays responsible for personal information it transfers to a third party for processing and must use contractual or other means to provide a comparable level of protection (OPC, cross-border processing guidelines). The privacy commissioners' generative AI principles add that outputs inferring information about a person count as collecting personal information. A business plan with a data processing agreement is how you meet the first duty; it's not a reason to paste anything.

This is general information, not legal advice. For the information rules themselves, see what information should not go into AI tools.

A 10-minute check for your own team

  1. List which of the four tools your staff use, and on which account type. Personal accounts are the usual gap; our guide to AI tool sprawl covers how to find them.
  2. For every personal account used for work, either move the work to an approved business account or, at minimum, have the person turn training off today using the paths above.
  3. On each business plan, find the retention setting and write down who owns it. Our AI risk assessment template has a register to record it in.
  4. Decide whether staff may use the feedback buttons on work content.
  5. Put the result in your AI use policy: approved tools, account type, and what never goes in.

FAQ: AI training on your data

Does ChatGPT train on your data if you pay for Plus?

Yes, by default. Plus and Pro are personal plans, so Improve the model for everyone is on until you turn it off. Business and Enterprise workspaces are not used for training by default.

Does turning off training delete my past chats?

No. On ChatGPT, Claude and Gemini, the training setting and deletion are separate. Delete chats or history separately, and expect back-end deletion to take up to 30 days (Gemini Apps Activity follows its own auto-delete period).

Is Microsoft Copilot Chat safe to use with client information?

Signed in with a work (Entra) account, Copilot Chat runs under enterprise data protection and prompts aren't used to train the models. Whether client information belongs there is still a question for your policy and your client contracts.

Can my employer see my ChatGPT Business chats?

Workspace admins on ChatGPT Business can view, access, export and delete members' conversations, according to OpenAI's enterprise privacy page. Assume work chats are work records.

Are temporary or incognito chats completely private?

No. ChatGPT may keep temporary chats for up to 30 days for safety, and Gemini holds chats for 72 hours even with Keep Activity off. They aren't used for training, but they're not instant deletion.

Where Hero fits

Hero's AI security assessment checks which accounts your team really uses, what the settings are, and where client or employee information goes, with access you approve and can remove. It starts from C$1,500. If you're choosing a business plan in the first place, an AI Readiness Assessment settles which tool fits before you pay for seats, and Copilot training covers safe use for Microsoft 365 teams.

Related: What information should not go into AI · AI use policy template · How to reduce AI tool sprawl

Sources checked (October 9, 2026): OpenAI Help Center, Data controls in ChatGPT and Chat and file retention in ChatGPT · OpenAI, Enterprise privacy at OpenAI (updated January 8, 2026) · Microsoft, Microsoft 365 Copilot Business (en-CA) · Microsoft Learn, What is Microsoft Copilot? · Microsoft Support, Privacy FAQ for Microsoft Copilot, Microsoft Copilot privacy controls and Microsoft Copilot for individuals: your privacy controls and choices · Anthropic Privacy Center, Is my data used for model training? (consumer, March 16, 2026; commercial, August 18, 2026), How long do you store my data? and How long do you store my organization's data? (both July 1, 2026), How do I change my model improvement privacy settings? and Configure custom data retention controls for Enterprise plans · Google, Gemini Apps Privacy Hub (September 24, 2026) and Generative AI in Google Workspace Privacy Hub (October 6, 2026) · OPC, Guidelines for processing personal data across borders and Principles for responsible, trustworthy and privacy-protective generative AI technologies.

A CLEAR NEXT STEP STARTS HERE

Find out what your team already puts into AI.

A free 30-minute call is the start. We’ll tell you honestly whether an AI security assessment, training, or a one-page policy is the right first step.

Free 30-minute call with our founder · Video call, camera optional