Does Claude train on your data, and what does it keep?
· Updated · Written and maintained by Joaquín Trapero, Nonimo
Does Claude train on your data? Not by default, and that answer is worth less than it sounds. On the consumer plans, Anthropic’s privacy centre states that using your chats to improve Claude takes an explicit choice on your part. On the business plans, the Commercial Terms put it as an obligation: Anthropic may not train models on Customer Content from the Services.
So far, so reassuring. But training is one question out of five, and a firm that stops there has answered the easy one. The text still left your office, something still holds it, someone may still read it, and the clock that governs it is not always 30 days. This guide goes through the rest, from Anthropic’s own pages, all of which were open in front of us on 19 September 2026.
Every claim below is quoted from a published Anthropic document with its date, and the same tests are applied to ChatGPT, Gemini and Copilot. Nothing here says one of the four is safest, because nothing in the documents supports that sentence.
Does Claude train on your data?
The answer has two halves, and they point in different directions.
On Free, Pro and Max, it is a choice you make
Anthropic’s privacy centre article on model training, last updated 16 March 2026, states that consumer Claude data is not used for model training by default and that using it requires explicit user action. The setting lives in Privacy Settings, and the phrasing on the page is that you choose to allow Anthropic to use your chats and coding sessions to improve Claude.
Two things are excluded even when you have said yes. Incognito chats are not used to improve Claude, in Anthropic’s words, “even if you have enabled Model Improvement”. And raw content pulled in through a connector, from Google Drive or an MCP server, is not used unless it was copied directly into the conversation.
There is a detail worth checking in your own account rather than taking from a page. When the choice is presented as you sign up, or in a notice inside the app, a switch that is already on is still a switch you have to notice. Look at Privacy Settings and read what it currently says, for each person who signed up separately.
On Claude for Work and the API, it is a contract
The Commercial Terms of Service, effective 17 June 2025, contain one sentence that does the work: “Anthropic may not train models on Customer Content from Services.” That is a promise in a contract rather than a toggle in a menu, which makes it harder to undo by accident and easier to show an insurer when you answer questions about your AI use.
| Where the text went | Training by default |
|---|---|
| Free, Pro, Max, including Claude Code on those plans | No, and switching it on is a choice |
| Claude for Work, Team, Enterprise | No, by contract |
| The Anthropic API | No, by contract |
| Any of the above, if flagged for safety review | The safety route is separate, and no switch covers it |
What Anthropic collects, and the three routes that are not the switch
The privacy policy, effective 10 September 2026, lists the sources Anthropic draws on to train its models. Three of the six are the open internet, commercial datasets and data Anthropic generates internally. The two that concern a firm are these: data that users provide, including Inputs and Outputs from the Services, unless users opt out, and “Materials flagged for safety, security, or policy review”.
Read those two together and the shape of the answer changes. The switch governs the first. It does not govern the second.
| Source Anthropic lists for training | Does your setting control it |
|---|---|
| Publicly available information via the Internet | Not yours to control |
| Datasets obtained through commercial agreements | Not yours to control |
| Inputs and Outputs from the Services | Yes, this is the switch |
| Feedback users explicitly provide | Yes, by not giving feedback |
| Materials flagged for safety, security or policy review | No |
| Data Anthropic generates internally | Not yours to control |
Six sources, and exactly one and a half of them sit behind the setting people think of as the answer. That is no criticism of the drafting, which is unusually clear, but a warning about the shorthand, because “we have turned training off” is what gets repeated back to a client.
Alongside the content itself, the policy describes ordinary service data: account details, usage and device information, and information from outside services you connect. If you enable a connector, Claude may send your Inputs, Outputs and instructions to that service to act on your behalf, and what happens there is governed by that provider rather than by Anthropic. The same pattern, under another name, runs through Gemini’s connected apps and Copilot’s agents.
How long Anthropic keeps it
Anthropic runs four clocks here, and only the first is the one people quote.
Thirty days, and what it covers
Delete a conversation and Anthropic states it is removed from your chat history immediately and deleted from backend storage systems within 30 days. The same 30 days applies to API inputs and outputs, which are deleted automatically unless an exception applies or a zero data retention agreement is in place.
That is a clean answer, and for most firms it is the operative one.
The five years that arrive with the switch
If you allow your data to be used to improve Claude, a longer clock starts. Anthropic states that it may retain your data, with identifiers removed, for up to five years in its model training pipelines. The extended period applies to new or resumed chats and coding sessions rather than retrospectively to your whole history.
The mechanics of undoing it are worth stating exactly, because they are better than people assume and narrower than people hope. Deleting a chat means it will not be used to train future models. Changing the setting or deleting the account excludes your data from future training. Neither reaches into a training run that has already happened, or into a model already trained.
The phrase to read carefully is “de-identified format”. It means identifiers have been stripped before the data enters the pipeline, and that is a real protection. It does not mean the text is gone, and it does not mean a document is unrecognisable to someone who has seen the original. For a firm, the safer assumption is the simple one: what you allow into the pipeline stays available to Anthropic for five years.
The flagged conversation, and the clock nobody reads
Here is the clock that belongs in your written rule. Where automated systems detect a Usage Policy violation, Anthropic’s wording is that “we retain inputs and outputs for up to 2 years and trust and safety classification scores for up to 7 years”.
Nothing about a client file is a policy violation. But classifiers are probabilistic, and a firm does not get to see what tripped one. A criminal defence brief, a safeguarding note, a medical report in a personal injury matter: none of these is misuse, and all of them contain the vocabulary a safety classifier is built to notice. If one is flagged, the 30 days you told your client about has quietly become two years.
Microsoft’s consumer product has its own version of this clock, and no way to opt out at all, as the Copilot guide sets out.
Training is not the same as passing through Anthropic’s servers
This is the distinction the whole subject turns on, and it is why “Claude does not train on our data” is a poor answer to give a client.
Five separate things happen to a document when someone sends it, and the training promise addresses exactly one of them.
| What happens to the document | Does “we do not train on it” answer it |
|---|---|
| It is transmitted to a company outside your firm | No, the disclosure has already happened |
| It is retained for some period | No, retention is a separate clock |
| An automated classifier reads it | No, and this is how a chat gets flagged |
| Legal process can reach the company holding it | No, no setting affects a lawful request |
| Its text is used to adjust model weights | Yes, this one |
Four of those five are what a client is actually asking about when they ask whether their file is safe. If your answer to them is the fifth row on its own, it is true but beside the point, and the difference will matter if you ever have to explain the sequence in writing. The place to give the fuller answer is before anyone asks, in an AI clause in your terms of business.
The safety route no switch turns off
Anthropic’s own list of training sources includes materials flagged for safety, security or policy review, and it sits outside the user setting. The privacy policy also sets out when personal data goes to government authorities and law enforcement: where Anthropic believes in good faith that disclosure is reasonably necessary to comply with law or an enforceable governmental request, to prevent serious harm, to address fraud, or to enforce its terms.
None of that is unusual, and every provider in this category has an equivalent. The point is narrower and it is the point of this whole guide. A firm that tells a client “Claude does not train on your data” has made a true statement that does not answer the question the client asked.
What you can say instead is short and it survives scrutiny. The tool does not train on our material, it is deleted within 30 days of us deleting it, and it went to a company we chose deliberately. Three facts, all checkable, and none of them pretending the document never left the building. What to do when it did is the subject of the breach guide.
Who your data controller is, if your firm is in the UK
Read the same clause in four providers’ policies on the same afternoon and a split appears, always for the same reason: the United Kingdom left the European Economic Area in 2020, so each company’s European entity either covers Britain or does not.
Anthropic’s privacy policy is on the side that covers it. Section 9 reads that if you live in the European Economic Area, the UK or Switzerland, together called the European Region, the controller responsible for your personal data is Anthropic Ireland, Limited, at South Bank House, Barrow Street, Dublin 4.
| Provider | Controller named for a UK user | Where |
|---|---|---|
| Claude | Anthropic Ireland, Limited | Dublin |
| Microsoft Copilot | Microsoft Ireland Operations Limited | Dublin |
| ChatGPT | OpenAI OpCo, LLC | San Francisco |
| Gemini | Google LLC | Mountain View |
What Dublin buys you, and what it does not
It buys a counterparty inside the European Region for the purposes of that policy, which is a real difference from the last two rows in the table. It does not buy data residency, and the two are constantly confused. The same clause read from the other three sides is in the guides on ChatGPT, Gemini and Copilot.
Your regulator is unchanged either way: the ICO supervises your firm, because your firm is the controller for your client’s data no matter which vendor you chose. And the international transfer question does not go away, because Anthropic’s own policy says the data crosses the Atlantic regardless.
Where the servers are
This is where the residency answer gets uncomfortable, and it is the half of the comparison that does Anthropic no favours.
Anthropic’s privacy centre page on server locations, last updated 15 June 2026, is short and unambiguous. It says Anthropic uses multiple cloud providers, that it may route customer traffic to select countries in the US, Europe, Asia and Australia, and then the sentence that settles it: “Note that data is stored in the US.”
Processing is not confined either. The same page states that data may be processed for internal purposes such as safety review, product support or incident response in countries where Anthropic or its affiliates operate.
The residency option on offer points the other way
Where a routing choice exists, it goes in the direction Britain is not asking for. Enterprise plan customers billed on usage are offered the ability to keep inference in the US only for their organisation, and Developer Platform users can configure a routing location through the documentation. There is no published UK residency option, and no published EU residency option, for storage.
That is a straightforward disadvantage against a Microsoft tenant that has bought UK data residency, and against a new ChatGPT Enterprise workspace that can store at rest in the UK. It should be weighed. It should also be kept in proportion, because as the ChatGPT guide sets out, UK storage residency there comes without UK inference residency, so the document is still processed abroad. Nobody in this market keeps a British firm’s client letter inside Britain from start to finish.
Does Anthropic share or sell your data?
The policy does not describe a sale, and it does not describe advertising against your conversations. That last point is a genuine difference from one of the other three, and it is worth noting without inflating it: it reflects a business model rather than a virtue, and business models change.
What the policy does describe is disclosure to service providers and affiliates, to government authorities and law enforcement on the grounds set out above, as part of a merger or similar corporate event, and to outside services you connect yourself. It also mentions research publications, and an account linked to an employer’s enterprise account.
| Route out named in the policy | When |
|---|---|
| Service providers and affiliates | To operate the service |
| Government authorities and law enforcement | Where it believes in good faith that the law or an enforceable request requires it |
| A merger, bankruptcy or transfer of business assets | As part of the transaction |
| Outside services you connect | When Claude acts on your behalf through a connector |
| Your employer’s enterprise account | Where your account is linked to it |
The connector case is the one to think about in an office. If someone links Claude to a document store, the instruction to fetch a file crosses to that provider, whose terms then govern. Your external IT provider will know which connectors are live before you do.
Does Claude Code train on your repository?
The answer follows the account rather than the tool, which is the general rule worth learning.
On Free, Pro and Max plans, Claude Code sessions fall under the consumer terms and the same model improvement setting, and Anthropic named coding sessions explicitly when it introduced the choice. Under the Commercial Terms, the prohibition on training covers Customer Content from the Services, which includes what the developer tools send.
For a firm, the practical risk in a repository lies less in the source code than in the fixtures: the test data, the seed files, the support ticket pasted into a comment, the client name in a branch. Those are personal data the moment they describe a real person, and the account that ran the session decides the terms they were sent under.
| Where the coding session ran | The terms that applied |
|---|---|
| Your own Pro or Max account | Consumer terms, and that person’s model improvement setting |
| A Team or Enterprise seat you bought | Commercial Terms, training excluded |
| A contractor’s personal account | Their terms, their setting, your controller duty |
| The API, inside something you built | Commercial Terms, 30 days or zero data retention |
Most small British firms do not run a repository at all, so this looks like someone else’s problem. It usually arrives through a contractor. A developer building your case management integration works on their own Max subscription, points a coding tool at a database dump you supplied for testing, and every row in it is your client’s.
The account is theirs and the setting is theirs. The controller obligation is still yours, which is why the list of what never goes in, in your AI policy, should name test data as well as correspondence.
What changes between the plans
Six plans in four rows, and the differences are contractual rather than technical.
| Plan | Training default | Retention you can set |
|---|---|---|
| Free, Pro, Max | Off, with a switch to turn on | No |
| Team | Excluded by the Commercial Terms | No |
| Enterprise | Excluded by the Commercial Terms | Custom retention controls are offered |
| API | Excluded by the Commercial Terms | 30 days, with zero data retention available |
The fourth row is the only one that lets a firm get close to leaving nothing behind, and it is the row a small practice never reaches, because it requires building something rather than buying a seat. That gap between what is contractually available and what an office of fifteen people can actually deploy is the whole story of this market, and it is why these decisions usually get made by whoever runs your systems.
How to turn training off and delete what is there
Four steps, none of which costs anything.
- Check the setting per person, not per firm. On consumer plans, model improvement is chosen user by user. One partner opting out does nothing for the trainee who signed up separately.
- Use Incognito chat for anything sensitive. Anthropic states these are excluded from model improvement even when the setting is on. They are still transmitted, so this rules out one use, not the disclosure itself.
- Delete the conversation, not just the window. Deletion removes it from history immediately and from backend storage within 30 days, and excludes it from future training runs.
- Write down which plan each person is on. The contract follows the account, so this single list answers most of the questions above for your firm.
There is a fifth step that is not about settings. Decide, in writing, which documents may never go into any of these tools. The AI policy template gives you the shape of that page, and collecting the acknowledgements is what makes it enforceable.
Is Claude safe under UK law?
No regulator has ruled on a named product, and any page telling you the ICO has approved or rejected Claude is wrong. What applies is the ordinary law: the UK GDPR together with the Data Protection Act 2018, supervised by the ICO, with your professional regulator and your indemnity insurer sitting on top. Compliance is a property of your use rather than of the product, and the checks that decide it fall differently on each assistant.
Your firm is the controller. You need a lawful basis for the disclosure, and you owe data minimisation and the security duty in Article 5(1)(f) and Article 32. Whether a given upload is also a reportable breach is a separate test with its own clock of 72 hours, worked through in the guide on client data and a data breach.
The regulator’s own advice is the practical bit
Asked whether personal data can be shared with a company to improve an AI model, the ICO’s innovation advice gives a sequence rather than a yes or no. Identify at least one lawful basis before any sharing starts. Then minimise: “If an organisation is able to anonymise the information, or remove identifiable information from the documents shared, then they should do so.” Then put a data sharing agreement in place that covers what happens at each stage.
Note what that is and is not. It is a duty to reduce, not a route out of the law. Removing identifiers from a document does not take it outside the UK GDPR if the link back still exists, and the difference between pseudonymised and truly anonymous data is set out at length in the breach guide rather than repeated here.
One more duty arrived recently. The ICO states that all data protection provisions of the Data (Use and Access) Act 2025 came into force on 19 June 2026, and one of them requires you to help people who want to complain about how you use their information.
You must acknowledge such a complaint within 30 days and respond without undue delay. If a client writes to you about a file that went into a chat box, that letter is now a complaint on a clock.
Identify at least one lawful basis before any sharing starts.
Anonymise the information, or remove identifiable information from the documents shared, where you are able to.
Put a data sharing agreement in place that covers what happens at each stage.
Acknowledge a complaint about how you use someone's information within 30 days, and respond without undue delay.
What none of this fixes
Everything above describes a service. The problem in a small office is a person, at the end of a long day, with a document that will not summarise itself. In a GP practice it is often a discharge summary that someone wants in plain English, and masking the patient’s details before it reaches Claude happens on the practice computer, not in Anthropic’s terms.
A single page of British correspondence carries more than people picture: a name, a date of birth, an NHS number, a National Insurance number, a postcode that identifies a household, a file reference at a named previous adviser, and often a second person who never agreed to anything. No setting in any account changes what is in that page. The account decides what happens after it is sent.
What a masking tool does here, and what it does not
The facts first, so you can check them. Nonimo is a Mac and Windows app that finds identifiers in text before it is sent and hides them, working on the machine rather than in a cloud, with a policy set by IT rather than by each user.
For the United Kingdom it covers NHS numbers, UTRs and driving licence numbers written after their label, National Insurance numbers with or without one, and postcodes, plus a vehicle registration, masked as a number plate when a word such as “Registration:” comes before it, and a mobile number that follows a label such as “Mobile:”.
Each of them is masked in front of you, where you can undo it, so the person who knows the matter has the last word on every change.
What it puts in their place is a reversible label, and the key linking each label to the real detail is kept encrypted on your own computer. That is pseudonymisation in the sense Article 4 gives the word, so the data remains personal data for whoever holds the key, and the key is yours. It lowers risk. It does not move a document outside data protection law, and a firm that tells a regulator otherwise has made a claim it cannot support.
What it keeps on your computer is set out on Nonimo’s security page.
Decide which account each person signs in with.
Five lines at most: the documents that may never go in.
Name who to call when someone does it anyway.
If you buy nothing at all, three things still help. Decide which account each person signs in with. Write a short list, five lines at most, of the documents that may never go in. Name the person to call when someone does it anyway.
A firm that does those three is in better shape than one that bought software and did none of them, and our other guides cover what to look for when it is time to judge a tool. Whether your insurance would pay out if it went wrong is a separate question, set out in the UK cyber insurance comparison.
Sources
Checked 19 September 2026.
- Anthropic, Privacy Policy, effective 10 September 2026. The training data sources including materials flagged for safety review, disclosure to government authorities, connectors to outside services, the transfer of data to US servers, and the section 9 controller clause naming Anthropic Ireland, Limited for the EEA, the UK and Switzerland.
- Anthropic, Commercial Terms of Service, effective 17 June 2025. The clause that Anthropic may not train models on Customer Content from Services, and the assignment of Outputs to the customer.
- Anthropic privacy centre, Claude consumer data retention periods, last updated 1 July 2026. The 30 days for deleted conversations, the five years in training pipelines where model improvement is allowed, and the two years for inputs and outputs plus seven years for classification scores on flagged chats.
- Anthropic privacy centre, Is my data used for model training, last updated 16 March 2026. Consumer data not used by default, the explicit action required, the exclusion of Incognito chats, and the exclusion of raw connector content.
- Anthropic privacy centre, Where are your servers located, last updated 15 June 2026. That data is stored in the US, the routing countries, the option for Enterprise to keep inference in the US only, and processing elsewhere for safety review, support and incident response.
- Anthropic privacy centre, commercial data retention, last updated 1 July 2026. Deletion of API data within 30 days, zero data retention agreements, and custom retention controls for Enterprise plans.
- ICO, Innovation advice: previously asked questions. The sequence of lawful basis, minimisation and a data sharing agreement, and the quoted line on removing identifiable information before sharing.
- ICO, The Data (Use and Access) Act 2025: what does it mean for organisations. All data protection provisions in force from 19 June 2026, and the complaints duty with its acknowledgement within 30 days.
- UK GDPR, Article 4 and the Data Protection Act 2018. The definition of pseudonymisation and the domestic regime the ICO supervises.
- OpenAI, Europe privacy policy, 24 August 2026; Google, Privacy Policy, effective 2 April 2026; Microsoft Privacy Statement. The other three rows of the controller table, each read from its own page. OpenAI’s domain returns 403 when fetched from the command line and was read in a browser.
Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.
Common questions
Does Claude train on your data?
Not on consumer plans by default. Anthropic's privacy centre states that using chats to improve Claude requires an explicit choice, and its Commercial Terms say it may not train models on Customer Content from the business services.
How long does Anthropic keep my Claude conversations?
Thirty days after you delete one. If you allow model improvement, Anthropic may retain data, with identifiers removed, in its training pipelines for up to five years, and that longer clock applies to new or resumed chats.
What happens if a conversation is flagged?
A different clock starts. Anthropic states that where automated systems detect a Usage Policy violation it retains inputs and outputs for up to two years, and trust and safety classification scores for up to seven years.
Does Claude for Work or the API train on our data?
No. The Commercial Terms of 17 June 2025 state that Anthropic may not train models on Customer Content from the Services. That is a contractual promise rather than a setting, and it covers Claude for Work and the API.
Where is Claude data stored, and is there a UK option?
In the United States. Anthropic's privacy centre states that data is stored in the US and that traffic may be routed to countries in the US, Europe, Asia and Australia. There is no UK or EU residency option published.
Who is my data controller for Claude if I am in the UK?
Anthropic Ireland, Limited, in Dublin. The privacy policy of 10 September 2026 names it as the controller for the European Economic Area, the UK and Switzerland together, so Britain is inside the European entity.
Does Claude Code train on your repository?
It follows the account. On Free, Pro and Max plans, Claude Code sessions sit under the consumer terms and the same model improvement setting. Under the Commercial Terms, training on Customer Content is excluded.
Is Anthropic's Claude GDPR compliant?
The question lands on your firm rather than on Claude, because compliance is a property of your use and not of the product. The regime is the UK GDPR with the Data Protection Act 2018, and the ICO supervises your firm as controller of your client's data. Anthropic's privacy policy of 10 September 2026 names Anthropic Ireland, Limited as the controller for UK users, and its privacy centre states that data is stored in the US.
Is it safe to put client data into Claude under UK law?
No regulator has ruled on a named product. Your firm stays the controller, needs a lawful basis, and the ICO advises removing identifiable information from documents before sharing them where that is possible.