What happens to data sent to an AI model, by plan

Training, retention, human access, and connected files: what vendors' own pages say for personal plans, business workspaces, and the API.

King & Company, updated

In short

The answer is set by the plan and the contract before it is set by the brand. Personal subscriptions, business workspaces, API access, and zero-retention arrangements each carry different terms for training, retention, human review, and connected files, and the same vendor publishes a separate page for each. This article walks through those four questions with the vendors' own wording, dated, so you can check your firm's plan against it.

What happens to data sent to an AI model depends more on the plan you are on than on the brand you chose. The same model carries different terms on a personal subscription, in a business workspace, over the API, and under a zero-retention arrangement, and each vendor publishes those terms on separate pages.

That matters when a partner or a client asks where a rent roll, a tax organizer, or a policy schedule goes once someone uploads it. A single yes or no on training does not answer the question. There are four questions, and each has its own answer per plan. Everything quoted below was read on October 2, 2026, and these pages change, so treat each link as the thing to re-check.

The path a document takes when you send it to a model

When someone pastes a lease into a chat window, the text travels to the vendor's servers, the model reads it to produce a response, and the response comes back. Two things can remain afterward, and the terms treat them separately.

The first is the conversation itself. Anthropic says of its business plans that it retains chats and coding sessions in the product to provide a consistent product experience, which is why last week's chat is still in the sidebar. The second is the vendor's own back-end copy, kept for operations and abuse monitoring. On the API, where there is no chat history, the same page says Anthropic automatically deletes inputs and outputs on its back end within 30 days of receipt or generation, with listed exceptions. OpenAI's developer documentation says its abuse monitoring logs may contain prompts and responses and are kept for up to 30 days by default, unless longer retention is required by law.

Whether any of that stored content is later used to train a model is a separate decision, governed by the plan.

Four questions to ask about any AI tool

  1. Training. Can the vendor use what we send to improve its models?
  2. Retention. How long is it kept, and what extends that period?
  3. Human access. Who at the vendor can read it, and under what conditions?
  4. Connected data. When the assistant reads from a drive, mailbox, or other connected system, where does that content go?

Personal plans versus business workspaces versus the API

Anthropic publishes a separate page for each of these product classes, so the table uses its wording. Dates in parentheses are the "updated" dates shown on each page.

QuestionPersonal plan (Free, Pro, Max)Business workspace (Claude for Work)APIZero data retention agreement
TrainingChats are used if you choose to allow it, or if a conversation is flagged for safety review. Incognito chats are not used. (March 16, 2026)"By default, we will not use your inputs or outputs from our commercial products to train our models." Feedback and explicit opt-in are the exceptions. (August 18, 2026)Same commercial page and same default as the business workspace.Sits on top of the commercial default. Free, Pro, and Max are not on the page's list of covered products.
RetentionWith model improvement on, data is kept "in a de-identified format for up to 5 years" in training pipelines. Deleted chats leave back-end storage within 30 days. (July 1, 2026)Chats are kept in the product. A deleted chat is removed from history immediately and from back-end storage within 30 days. (July 1, 2026)Inputs and outputs are deleted from the back end within 30 days by default.Applies to "eligible Anthropic APIs", products using a commercial API key, and Claude Code for Enterprise plans. Safety classifier results are still kept.
Human access"By default, Anthropic employees cannot access your conversations" unless you consent through feedback or review is needed to enforce the usage policy. (March 16, 2026)Not stated on the commercial pages linked in this table. Ask for it in writing.Not stated on the commercial pages linked in this table.Not addressed directly. The page allows retention "where needed to comply with law or combat misuse or harm."
Connected dataRaw content from connectors and MCP servers is excluded from training data, though content copied directly into a conversation may be included.Not addressed separately on the commercial pages linked in this table. Ask for it in writing.Whatever your application sends is an input, so the rows above apply.Not addressed on the page.

A paid personal subscription sits in the first column. Anthropic groups Pro and Max with Free as consumer products, so a broker or staff accountant paying for their own Pro account is on consumer terms, whatever the firm assumes.

What the other vendors say in their own words, as of October 2026

OpenAI API. OpenAI's developer documentation states that data sent to the OpenAI API is not used to train or improve OpenAI models unless you explicitly opt in. That page covers the API platform only. ChatGPT Business and Enterprise are governed by OpenAI's separate enterprise privacy page, which is the one to read if your firm is on either plan.

Microsoft Copilot. Microsoft's documentation (dated July 9, 2026) states: "Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs". The same page says interaction data is stored in alignment with the contractual commitments covering the organization's other Microsoft 365 content and is encrypted while stored, and that Copilot services have opted out of the abuse monitoring with human review that is available in Azure OpenAI. It also notes that Anthropic and OpenAI models may act as subprocessors, that admins decide whether to use them, and that additional terms may apply.

Gemini in Google Workspace. Google's privacy hub (updated August 14, 2026) says: "Your content is not human reviewed or otherwise used for Generative AI model training outside your domain without permission." It applies only to qualifying Workspace and education editions, so a personal Google account is outside it.

Zero data retention: what it covers and what it leaves out

Zero data retention is an arrangement a vendor approves for specific products, and a user cannot switch it on from a chat app.

Anthropic's page limits it to eligible APIs, products using a commercial organization API key (including Claude Code through the API), and Claude Code for Enterprise plans. It says safety classifier results are still retained to enforce the usage policy, and that certain models it calls Covered Models require limited data retention and review as part of its safety work.

OpenAI says its Zero Data Retention and Modified Abuse Monitoring controls are subject to prior approval, and its documentation lists endpoints that are not eligible, including files, vector stores, assistants, threads, and batches. A workflow built on stored files can therefore fall outside the arrangement even when the firm has one.

The exceptions most summaries skip

Feedback. A thumbs up or thumbs down sends the conversation down a different path. On Anthropic's commercial products, a conversation submitted with feedback may be retained for up to 5 years and may be used for training, after being de-linked from user identifiers. The same page says owners on Team and Enterprise plans can turn feedback off with the "Rate chats" setting. Google says Workspace feedback is used to improve its products but is not used to train the generative AI models behind Workspace.

Flagged content. Anthropic says that when inputs or outputs are flagged for a usage policy violation, it may keep the inputs and outputs for up to 2 years and trust and safety classification scores for up to 7 years. Both periods run well past the 30-day default.

Deleted chats. Deleting removes a conversation from the user's history at once, and from back-end storage within 30 days on Anthropic's plans. For a firm with a client request to destroy records, that delay belongs in the answer.

What your admin controls, and what the vendor controls

In a business workspace, a good part of the retention answer is the firm's own configuration.

The vendor controls the training default, the abuse-monitoring window, and the flagged-content rules. Permissions inside the workspace are the firm's job, and we cover them in AI agent permissions and governance.

How to check your own firm's plan

  1. Open the billing or admin page of each AI tool in use and write down the exact plan name. Note any personal subscriptions staff expense.
  2. Find the vendor's training page for that plan and save the sentence that applies, with the date.
  3. Find the retention page and note the default period, the deletion delay, and the flagged-content period.
  4. In the admin console, check the retention setting, the feedback setting, and which connectors are enabled.
  5. If the firm uses the API or has a zero-retention agreement, list which products and endpoints it covers.
  6. Give the result to your compliance lead or counsel, and put the plan names into your acceptable use policy.

Published commitments carry weight. The FTC wrote in January 2024 that model-as-a-service companies that fail to abide by their privacy commitments to users and customers may be liable under the laws it enforces, adding that "there is no AI exemption from the laws on the books." This article describes what vendors publish and is not legal advice. Tax and accounting firms have further obligations, covered in our piece on the Safeguards Rule, and your own counsel should confirm how any of this applies to you.

Why it matters whose account the work runs on

Every answer above attaches to an account. When a consultant runs your client's documents through the consultant's own subscription or API key, the consultant's plan and contract govern that data, and your firm has neither the admin console nor the agreement.

For that reason we build inside the client's own AI workspace. The firm's contract with the model vendor governs the documents, the firm's admin sets retention and connectors, and the workflows and skills stay in the firm's account when the engagement ends. The setup steps are in how to set up secure AI workflows for confidential client data, and if you want help checking your current plans against these four questions, get in touch.

Common questions

Does Claude train on my data?

It depends on the plan. Anthropic's privacy center says that by default it does not use inputs or outputs from its commercial products (Claude for Work, the API) to train models, with exceptions for feedback a user submits and for explicit opt-in. On Free, Pro, and Max, chats are used when the user allows it in privacy settings or when a conversation is flagged for safety review.

Does a paid personal plan protect my data the same way a business plan does?

No. Anthropic groups Pro and Max with Free as consumer plans, with their own training and retention pages, and its zero data retention page lists only API and enterprise products as covered. Paying for a personal subscription does not put the firm under the commercial terms.

If I delete a chat, is it gone?

It leaves your history right away and the vendor's storage on a delay. Anthropic says a deleted conversation is removed from chat history immediately and deleted from back-end storage within 30 days. Content flagged for a usage policy violation, and conversations submitted with feedback, are kept longer.

What is zero data retention, and do we need it?

It is an arrangement, approved by the vendor, that keeps customer content out of the vendor's normal retention, such as OpenAI's abuse monitoring logs. It applies to eligible API and enterprise use, it does not cover everything, and both Anthropic and OpenAI describe data that is still kept. Whether your firm needs it is a decision for your compliance lead and counsel, based on what your clients and regulators require.

Does the AI vendor own what the model writes for us?

Anthropic's Commercial Terms of Service say the customer owns its outputs, and Microsoft's Copilot documentation states that it does not claim ownership of Copilot's output. Those are commercial terms, so read the terms for the plan you are on, and ask counsel about copyright questions, which the vendors do not settle for you.

Tell us where the time is going

King & Company embeds with your team and builds the AI workflows, skills, and integrations around the work you already do. Describe the work your team would rather not be doing, and we will come back with how we would approach it.