Guides · AI and your data - Is AI safe for my business data?

Yes, when it is set up on the right tier with the right controls. Business and API versions of ChatGPT and Claude do not train on your data by default and are covered by data processing agreements. Personal and free accounts are where the real exposure lives. The risk to manage is governance, not your data appearing on the open internet. This guide explains both halves honestly, from the vendors’ own published policies.

The real question - The fear is about five things. Here they are, named.

Business owners rarely ask “is AI safe?” in the abstract. They ask five specific questions, usually late at night. This guide answers each one from the vendors’ own published policies, checked in July 2026.

  • Where does my data go, and who can see it?. To the AI vendor’s servers, under whichever terms your account tier carries. That last clause is the entire game: the same prompt typed into a personal account and a business account travels under completely different rules. Nobody outside the vendor sees it either way; the difference is what the vendor may do with it.
  • Do OpenAI or Anthropic train on my data?. On business, enterprise and API tiers: no, not by default, on either platform, and both put that in writing. On personal tiers it depends: ChatGPT’s free and paid consumer accounts train on conversations by default unless the user opts out, and consumer Claude asks each user to choose. The exposure lives in personal accounts, not business ones.
  • What if my data gets deleted, or I lose access?. Both vendors publish deletion commitments: deleted conversations and closed accounts are purged from their systems within about 30 days, with narrow exceptions such as legal holds and safety-flagged content. The honest caveat: anything already used to train a model cannot be retroactively removed. Deletion is a control, not a time machine.
  • How do I implement this safely?. The same way you would any supplier handling your records: the right tier, a data processing agreement, access controls, and a staff policy that says which accounts may touch company data. None of that is exotic. It is ordinary supplier governance, applied to a new supplier.
  • Are my staff already pasting data into free ChatGPT?. Statistically, someone probably is, and it is the one worry on this list we would act on this week. The section below covers what that does and does not expose, because the honest version is scary enough without the myths.

The core fact - The tier decides everything.

One fact does most of the reassuring, and it is durable across both vendors: business and API tiers do not train on your data by default, and personal tiers are where the exposure lives. Checked against both vendors’ published policies, July 2026.

Account typeTrains on your data?Business protections
ChatGPT Free / Plus / Pro (personal)Yes, by default. The individual user can opt out in their own settings.No business DPA. No admin visibility or audit trail for the employer.
Claude Free / Pro / Max (personal)The individual user chooses in their own privacy settings. The business cannot see or verify that choice.No business DPA. No admin visibility or audit trail for the employer.
ChatGPT Business / Team / Enterprise, and the OpenAI APINo, not by default. Training only happens if the organisation explicitly opts in.DPA available. Admin controls, with organisation-level ownership of the data.
Claude for Work / Team / Enterprise, and the Anthropic APINo. Anthropic states retained business data is never used for training without express permission.DPA available under Commercial Terms. Admin controls, organisation-level ownership.

Two facts worth holding onto alongside the table. First, even in the most private consumer configurations, both vendors retain inputs for roughly 30 days for abuse monitoring, so “nothing is stored” is never quite true; genuine zero-retention arrangements exist but are approved business and API options, not defaults. Second, data residency differs: OpenAI offers UK and EU storage for its business tiers, while Anthropic stores data in the US by default, with EU hosting available by running Claude through cloud platforms. If UK residency matters to you, it is a configuration decision, and it has to be made deliberately. The full tier-by-tier picture is in our comparison guide.

The one to act on - Your staff are probably already using AI. On whose account?

An employee pasting company data into a personal AI account is the most common real exposure we see, and it deserves an honest description: the risk is a governance gap, not a public leak.

  • What is actually at risk. A personal account means no company DPA, no confidentiality commitment to the business, no admin visibility, and no way to see or delete what was pasted. On ChatGPT’s consumer tiers the content may also train future models by default unless that individual opted out, and the business cannot check.
  • What is not at risk. Pasted data is not published, made searchable, or shown to other users. It does not leak onto the open internet, and neither vendor states that it sells your data. Anyone selling you AI governance with those claims is selling fear, and it makes the real gap harder to see.
  • What to do about it. Give the team a sanctioned business account, write a one-page policy saying company data goes there and nowhere else, and turn the personal-account habit into a provisioning problem you have solved. This takes days, not months, and it is part of every setup we run.
The right way, by default

AI is safe for business data when someone sets it up to be.

Every system Assist IQ builds runs on business and API tiers with no-training configurations, under data processing agreements at both layers: the AI vendor’s and our own with you. Client data is isolated per client, retention and deletion controls are configured deliberately rather than left on defaults, and every engagement includes the staff-policy piece, because the best-configured system in the world does not help if the team is still on personal accounts.

None of this is heroic. It is the ordinary discipline of treating an AI vendor like any other supplier that touches your records, applied by people who do it every week. That is the whole reassurance: not that AI is magically safe, but that setting it up safely is a known, checkable job.

The questions owners actually type into ChatGPT at midnight.

Answered from OpenAI's and Anthropic's own published policies, checked July 2026. Policies change; we re-verify this page on every refresh. This is practical guidance, not legal advice.

Does ChatGPT train on my business data?

Not by default on ChatGPT Team, Business, Enterprise or the API: OpenAI states it does not use those inputs and outputs for training unless a business explicitly opts in. Personal Free, Plus and Pro accounts are different: by default OpenAI does train on those conversations, unless the individual user disables it in their data controls. The account tier, not the technology, is what decides.

Is Claude safe for confidential company information?

On Anthropic’s commercial terms, covering Claude for Work, Team, Enterprise and the API, your data is not used for training by default and is covered by a DPA. Personal consumer Claude works differently: individual users choose whether Anthropic may train on their chats, and data can be kept for years if they opt in. Confidential business data belongs on a business tier with a signed DPA, not a personal account.

Can my staff leak company data by using free ChatGPT or Claude?

Functionally, yes. A personal free-tier account has no company DPA, no admin visibility, and on ChatGPT’s consumer tiers may train on the input by default unless that individual opts out. Even with training off, both platforms retain inputs for roughly 30 days for abuse monitoring. The real risk is the total absence of business control or audit trail, not public leakage.

What happens to my data if I cancel my subscription?

OpenAI deletes account data within 30 days of account deletion, with exceptions for legal holds, safety-flagged content and anything already used to train a model, which cannot be un-trained. Anthropic’s standard retention already removes deleted conversation data from its systems within about 30 days. Cancelling is not the risky moment people imagine; the setup while you were a customer is what matters.

Do OpenAI and Anthropic offer a Data Processing Agreement?

Yes, both. OpenAI can execute a DPA for ChatGPT Business, Team, Enterprise and API customers, supporting UK GDPR compliance. Anthropic offers a DPA under its commercial terms, covering Claude for Work, Team, Enterprise and the API. Neither offers a business-grade DPA on free consumer accounts, because those run under consumer terms rather than commercial contracts.

Can I get zero data retention, so nothing is stored at all?

Both vendors offer it, on request, for specific products only. OpenAI’s zero data retention requires prior approval and covers eligible API endpoints, not the consumer ChatGPT app. Anthropic’s is enabled per organisation via its sales team and covers most Claude API usage, excluding the chat interfaces. For most businesses the default business-tier retention is already appropriate; zero retention is for genuinely sensitive workloads.

Start with a free enquiry

Not a discovery call. Not a pitch with a calendar link. Five questions about how your business actually runs, and it costs nothing. Ross reads every enquiry himself and replies within one working day with a straight first answer: what looks worth automating, and what doesn’t.

If it looks like we can genuinely help, the next step is the AI Operations Day: one working day inside the business, followed by a written Opportunity Map. It shows what is hurting, what should stay human, and the best one or two jobs to prove first. That part comes later, and only if it makes sense for you.

Tell us what is slowing you down

Free to ask. No obligation. Ross replies personally within one working day.