What happens to your data when you use AI?
Everything you type into or upload to an AI assistant goes to the provider's servers and is processed and stored there. What the provider does with it afterwards depends on the plan you use and on your settings.
That makes AI and privacy a matter of two questions. How long does the provider keep your conversations? And does it use them to train its models? The answer differs between a personal and a business plan, even at the same provider.
This article describes what ChatGPT, Claude, Gemini and Microsoft Copilot do with your input according to their own privacy documentation, as of October 2026. Providers change their terms regularly. So check the settings in your own account.
What does an AI provider store about you?
An AI provider stores your conversations, your uploaded files and your feedback. Conversations stay in your history until you delete them.
These periods apply per provider:
- ChatGPT: according to OpenAI, a deleted conversation is permanently removed from its systems within 30 days, unless a legal or security obligation requires keeping it longer
- Claude: according to Anthropic, deleted conversations are removed from back-end storage within 30 days. If you allow training, Anthropic may keep your data for up to 5 years for model training, in a form that is not linked to your identity
- Gemini: the activity of a personal account is kept for 18 months by default. You can change that. If you turn activity off, Google still keeps conversations for up to 72 hours
- Copilot: the conversation activity of a personal account is kept for 18 months by default. You can delete conversations earlier yourself
With Gemini, part of the conversations can be read by human reviewers when the Keep Activity setting is on. Those conversations are disconnected from your account and kept for up to 3 years.
When you give an answer a thumbs up or down, you send that conversation to the provider as feedback. OpenAI states that the entire conversation may then be used for training, even if you have turned training off.
Are your conversations used to train AI models?
On personal plans that can happen; for business products it does not happen by default. This is what the providers' documentation says (as of October 2026):
| Provider | Personal plan | Business product |
|---|---|---|
| OpenAI (ChatGPT) | Input can be used for training, you can turn this off | ChatGPT Business, Enterprise, Edu and the API: no training by default |
| Anthropic (Claude) | Free, Pro and Max: training if you allow it in the settings | Claude for Work and the API: no training by default |
| Google (Gemini) | Training when Keep Activity is on | Gemini in Google Workspace: no training without the customer's permission |
| Microsoft (Copilot) | Conversation activity can be used for training, you can turn this off | Copilot with a Microsoft 365 business licence: prompts and responses are not used to train the foundation models |
Training means that your text can become part of the material a next version of the model learns from. OpenAI writes that it takes steps to reduce the amount of personal information in training data. Still, assume that text you make available for training cannot be taken back.
How do you turn off training on your input?
You turn off training in the privacy settings of your account. It works like this per provider:
- ChatGPT: go to Settings, choose Data controls and turn off Improve the model for everyone. A Temporary Chat is not used for training as long as you do not save it; OpenAI may keep a copy for up to 30 days for safety purposes
- Claude: go to the privacy settings and turn off Model Improvement. Incognito chats are not used for training, even when Model Improvement is on
- Gemini: turn off Keep Activity under Gemini Apps Activity. New conversations are then not used to train the models
- Copilot: turn off model training in the privacy settings of your personal Copilot account
With ChatGPT and Gemini, the setting applies to new conversations. So turn it off before you work with confidential information.
What is the difference between a business and a personal plan?
With a business plan, your company signs an agreement with the provider that sets out what happens to the data. With a personal plan, the consumer terms apply and every user arranges their own settings.
In practice, a business plan makes four differences:
- Training is off by default. That applies to all accounts in your organization
- The provider offers a data processing agreement. You need one as soon as you have personal data processed
- An administrator manages access. They decide who has an account and revoke it when someone leaves
- Retention periods can be set. With Microsoft Copilot, among others, an administrator sets how long conversations are kept
If an employee uses a personal account for work, your company cannot see what is entered and the arrangements in your business agreement do not apply. So record which accounts are allowed for work.
Which data is better left out?
In a personal account, do not enter data that identifies another person or information your company wants to keep confidential. Think of:
- names, addresses and contact details of customers or employees
- medical, financial or legal data about people
- passwords, API keys and login details
- contracts, quotes and figures that are not yet public
Often you can still have the task carried out. Replace names with a role, such as customer A and supplier B, and remove amounts or addresses the question does not need. The answer stays usable and the data stays with you.
When does your data stay entirely with you?
Your data stays entirely in your own environment when you run an AI model on your own hardware. Nothing then goes to an external provider.
That takes a suitable computer or server and someone who manages the model. How that works and what you need for it is explained in running AI locally.
What do you have to arrange by law as a business?
If you process personal data of customers or employees with AI, the GDPR applies. Among other things, you then need a legal basis and a data processing agreement with the provider. The steps are in using AI in a GDPR-proof way.
In addition, the EU AI Act sets requirements for AI systems and for their use. The risk levels and the dates are in the EU AI Act explained.
Frequently asked questions
Does ChatGPT store my conversations? Yes. Conversations stay in your account until you delete them. According to OpenAI, a deleted conversation is permanently removed from its systems within 30 days, unless a legal or security obligation requires keeping it longer (as of October 2026).
Are my ChatGPT conversations used for training? On personal plans, OpenAI can use your input to train models. You turn that off via Settings, Data controls, Improve the model for everyone. For ChatGPT Business, Enterprise, Edu and the API it does not happen by default.
Does Claude train on my conversations? On Claude Free, Pro and Max, conversations are used for training if you allow it in the privacy settings. For Claude for Work and the API, Anthropic does not use inputs and outputs to train models by default (as of October 2026).
Is a business AI plan safer for privacy? For the business products of OpenAI, Anthropic, Google and Microsoft, your input is not used to train models by default. Your company signs an agreement with the provider and an administrator manages access. Your own obligations under the GDPR continue to apply.
Which data should I not enter into an AI assistant? In a personal account, do not enter personal data of customers or employees, passwords or confidential company information. Replace names with a role, such as customer A, if you still want to have the task carried out.
Taking AI further in your business
Ready to move from reading to doing? See how we approach AI implementation on your own infrastructure, discover what AI automation can take off your plate, read the AI agent pricing guide, or learn it yourself with our 1-on-1 AI training. Questions about your situation? Book a free intro call.
