Guides · Choosing the right tier - ChatGPT and Claude: free vs business vs enterprise vs API
The difference between the tiers is not the features. It is the data handling. Personal and free versions of ChatGPT and Claude can use your conversations for training and give a business no contract, visibility or control. Business, enterprise and API tiers do not train on your data by default, carry data processing agreements and put an admin in charge. This guide compares the four families on the things an owner should actually care about.
The tiers, translated - Four families of account, whatever the marketing names say.
Both vendors rename their plans more often than anyone would like, but the shape underneath is stable. Every ChatGPT or Claude account your business might touch falls into one of four families.
- Personal: Free, Plus, Pro (ChatGPT) and Free, Pro, Max (Claude). Consumer products under consumer terms. Priced for individuals, governed for individuals: the account holder controls the settings, not the business. This is the family your staff already have in their pockets.
- Business and Team. The same chat product, moved onto commercial terms: no training on your data by default, a data processing agreement available, and an admin who can see and manage the workspace. The minimum sensible home for company data.
- Enterprise. The business family plus the controls larger organisations are audited against: stronger admin tooling, single sign-on, compliance features and, on OpenAI’s side, options like UK and EU data residency.
- API. Not a chat app at all: the raw model access that systems are built on, under commercial terms. This is what an AI employee or agent runs on, and it carries the strongest data posture of the four families by default.
The comparison - The five rows that matter, across both vendors.
Feature lists change monthly. These are the rows a business owner should actually decide on, checked against both vendors’ published policies in July 2026.
| Personal / free | Business / Team | Enterprise | API | |
|---|---|---|---|---|
| Trains on your data by default? | ChatGPT: yes, unless the user opts out. Claude: the user chooses; you cannot verify it. | No, both vendors. Training is opt-in only. | No, both vendors. Training is opt-in only. | No, both vendors. Never without express permission. |
| Retention you can rely on | Roughly 30 days minimum for abuse monitoring, even with history off. Opted-in Claude data can be kept for years. | Deleted data purged within about 30 days; the same abuse-monitoring floor applies. | Same as business, plus contractual retention terms in the agreement. | Inputs and outputs deleted within about 30 days by default; zero-retention arrangements available on approval. |
| Who controls the account | The individual. The business has no visibility and no admin rights. | A workspace admin: members, access and data owned at organisation level. | Full admin tooling, single sign-on, organisation-wide policy. | Your systems. Access is scoped to what the integration is built to do. |
| DPA available? | No. Consumer terms only. | Yes, both vendors. | Yes, both vendors. | Yes, both vendors, under commercial terms. |
| Right for company data? | No. This is the leak: not to the public, but out of your governance. | Yes, as the sensible minimum. | Yes, where scale or compliance demands it. | Yes, and it is what proper AI systems are built on. |
One difference worth knowing if UK or EU data residency matters to you: OpenAI offers in-region storage, including the UK, for its enterprise and API customers. Anthropic stores customer data in the US by default, and genuine EU hosting for Claude currently means running it through a cloud platform’s EU region. Not a reason to panic, but a configuration decision someone should make on purpose.
The row that bites - The most expensive tier is the free one your team already uses.
Every business we review has AI in it already. The question is never whether AI is in the building. It is whether the accounts it runs on answer to the business or to nobody.
- The gap, precisely. A personal account means no DPA, no admin visibility, no audit trail, and no way for the business to see, control or delete what was pasted. On ChatGPT’s consumer tiers, it may also mean the content trains future models, because that is the default unless the individual switched it off.
- What it does not mean. The pasted data is not published or searchable, and it does not leak to competitors. Free tiers are not a public disclosure. They are a governance hole: the business has handed company data to a supplier it has no contract with, on settings it cannot see.
- The fix costs less than the worry. Move company use onto a business tier, sign the DPA, write the one-page policy. The gap between the free family and the business family is the cheapest risk reduction in AI, and it is almost always the first thing we implement.
Which tier should your business be on?
If company data touches AI at all, the floor is a Business or Team plan with the DPA signed: no training by default, an admin who answers to you, and a contract behind it. Enterprise earns its keep when you need single sign-on, residency options or compliance tooling, not before. And when AI stops being a chat window and starts being part of how the business runs, the systems get built on the API, where the data posture is strongest by default.
Choosing the tier is the easy half. Configuring it: the no-training settings, the retention decisions, the DPA, the staff policy, the isolation between clients, is the half that actually protects you, and it is exactly what Assist IQ sets up for every business we work with. If you want the worked answer for your business rather than the general one, that is what the review is for.
Tier questions, answered straight.
From the vendors' own published policies, checked July 2026. Tier names and gating shift; we re-verify on every refresh. Practical guidance, not legal advice.
Does using the API instead of the chat app change my privacy protection?
Yes, significantly, for both providers. OpenAI’s API has not trained on customer data by default since March 2023, with roughly 30-day abuse-monitoring logs and optional zero data retention. Anthropic’s Claude API deletes inputs and outputs within about 30 days by default and never trains on that data without express permission. Consumer chat apps carry weaker default protections than either API.
Is my business data stored in the UK, or does it go to the US?
It depends on vendor and tier. OpenAI offers data residency for its enterprise, education and API customers, letting eligible businesses store data at rest in the UK or Europe among other regions. Anthropic stores customer data in the US by default, with no dedicated EU region of its own; genuine EU hosting for Claude currently means running it through a cloud platform’s European region.
Can my staff just use their personal ChatGPT Plus for work?
They can, and that is the problem: a personal Plus account still runs under consumer terms, trains on conversations by default unless that person opted out, and gives the business no DPA, no visibility and no way to delete what was pasted. Paying for Plus does not make an account a business account. Terms make it one, and only the business families carry them.
What admin controls do business plans get that free accounts do not?
The pattern across both vendors: business tiers add workspace administration, with single sign-on and audit capabilities concentrated in the business and enterprise families, and some controls, like Anthropic’s compliance API and automatic user provisioning, reserved for enterprise. Free and personal accounts get none of this. Exact gating shifts with vendor plans, so we verify the current lines during setup.
Do OpenAI or Anthropic sell my business data to third parties?
Neither vendor states that it sells customer data to third parties. Worth knowing: “we do not sell your data” and “we do not train on your data” are separate commitments, and a business should check both rather than assume one implies the other. On business and API tiers both vendors commit to no training by default; on consumer tiers the training defaults differ between the two.
Start with a free enquiry
Not a discovery call. Not a pitch with a calendar link. Five questions about how your business actually runs, and it costs nothing. Ross reads every enquiry himself and replies within one working day with a straight first answer: what looks worth automating, and what doesn’t.
If it looks like we can genuinely help, the next step is the AI Operations Day: one working day inside the business, followed by a written Opportunity Map. It shows what is hurting, what should stay human, and the best one or two jobs to prove first. That part comes later, and only if it makes sense for you.
Free to ask. No obligation. Ross replies personally within one working day.