[nonimo]
EN
Download

Does Claude train on your data? An Irish guide to Anthropic

· Updated · Written and maintained by Joaquín Trapero, Nonimo

It depends on which account you are signed into, and the answer changed direction in 2026. Anthropic’s privacy policy of 10 September 2026 says it may use your inputs and outputs to train and improve its models unless you opt out through your account settings. Its commercial terms say the opposite, in one sentence: Anthropic may not train models on customer content.

That is the cleanest split of the four large assistants, and it is also the one most likely to be misremembered, because the consumer default moved. This guide works through Anthropic’s own documents, adds the two retention clocks that sit behind the training question, and puts both against the rules an Irish firm actually answers to. The controller here is Anthropic Ireland, Limited, in Dublin 4.

Does Claude train on your data, and on which plan?

Two documents govern this, and they are written for different readers. The consumer privacy policy covers Claude Free, Pro and Max, including Claude Code used from those accounts. The commercial terms cover the API, Claude for Work and Claude Enterprise.

AccountTrained on by defaultThe governing sentence
Claude Free, Pro, MaxYes, unless you opt out“unless you opt out through your account settings”
Claude Code on a personal planFollows the same settingSame policy, same switch
Claude for Work, EnterpriseNo“Anthropic may not train models on Customer Content”
Anthropic APINoSame commercial terms

Sources: Anthropic, Privacy Policy, 10 September 2026, section 2; Commercial Terms of Service, 17 June 2025, section B.

The consumer setting, and where it lives

The control is in Privacy Settings in your account, it can be changed at any time, and Anthropic states that if you turn model improvement off it will not use your previous or new chats for future training. That is a stronger promise than a switch that only covers future chats, and it is worth reading twice because it is unusual.

10 Sept 2026the privacy policy that governs consumer plans
17 June 2025the commercial terms that govern business plans
2exceptions that survive opting out of training
Anthropic, Privacy Policy and Commercial Terms of Service, as at 19 September 2026

There is a limit, and it is a law of physics rather than a policy choice. Your data will still be included in training runs already in progress, and in models already trained. A model that has learned something cannot be made to forget it because you changed a toggle afterwards.

What opting out still allows

Two exceptions survive the switch, and both are named in the policy. Conversations flagged for safety review may be used or analysed to improve detection and enforcement. Material you explicitly report through the feedback buttons may be used as well.

The feedback one catches people. Pressing thumbs down on an answer stores the entire related conversation, de-linked from your user ID, for up to five years. If the conversation contained a client’s file, a moment of irritation has just created a five year record. Our AI policy template has a line for this, and most firms have never thought to include one.

The whole conversation
What a thumbs up or down stores: "we will store the entire related conversation", de-linked from your user ID, for up to five years. Anthropic privacy centre, 16 March 2026

The practical rule for a firm is one line long. Treat the feedback buttons as publication, not as a gesture, and keep them away from anything with a client in it.

The two clocks: thirty days, and five years

Retention is where Anthropic is most specific of the four providers, and the specificity is a genuine credit. It is also where the training question stops being abstract, because the two answers have different clocks attached.

What happened to the chatHow long Anthropic may keep it
You deleted it30 days in backend storage
You allowed model improvementUp to 5 years, de-identified, in training pipelines
You pressed thumbs up or down5 years, whole conversation, de-linked from your ID
A safety classifier flagged it2 years for the text, 7 for the scores

Source: Anthropic privacy centre, How long do you store my data?, 1 July 2026.

Those four rows are not alternatives. A single conversation can sit in more than one of them, and the longest applicable clock is the one that answers a client’s question. Our guide to whether a paste is a breach explains why the answer matters within 72 hours rather than at leisure.

Deleting a conversation, and what that reaches

Delete a conversation and it leaves your history immediately and Anthropic’s backend storage within 30 days. That is the standard path, it applies on consumer and commercial plans alike, and it is the number to quote to a client who asks.

Allow training, and the clock becomes five years

Those five years run inside Anthropic’s model training pipelines, where the chats are kept in de-identified form. It applies only to new or resumed chats after the setting was enabled, which means the exposure is dated rather than retrospective. The wording is doing a lot of work there, because neither Irish nor EU law defines that category, and a label is not a status.

Flagged conversations, and the seven year tail

The third clock is the one nobody expects. If a chat is flagged by Anthropic’s automated trust and safety systems as violating its usage policy, inputs and outputs are kept for up to two years, and the classification scores for up to seven.

30 daysto clear a deleted conversation from backend storage
5 yearsin training pipelines, if you allow model improvement
7 yearsfor trust and safety classification scores on a flagged chat
Anthropic privacy centre, How long do you store my data?, 1 July 2026

Nothing in that list is sinister, and every large provider keeps something for abuse handling. The point for an Irish firm is that “we delete in thirty days” is the shortest of three numbers, not the only one, and a client asking how long their letter exists deserves the longest.

Training and passing through your data are not the same question

Here is the distinction everything in this guide turns on, and Claude is the clearest place to see it, because the training answer is genuinely good on a business plan and the other answers are unchanged by it.

Suppose an Irish accountant puts a client’s payroll summary into Claude for Work. Anthropic may not train on it. The text still left the office, still arrived at a company outside it, is still retained while the conversation exists, is still deletable only on request, and is still reachable by lawful process. Every one of those is true with the training promise fully honoured. For chartered accountants, the CCAB-I prohibition falls on that data whatever the plan.

Two different promises
"Anthropic may not train models on Customer Content" is a promise about use, not about receipt, retention or disclosure. Commercial Terms of Service, 17 June 2025, section B

So the real question for a professional is whether the document should have left the building at all, whatever the provider does about training. Our guide to whether that is a breach works through the notification test, which turns on risk to the people in the document and not on the vendor’s training policy.

Where Claude’s data actually sits

This is where Anthropic is more candid than most, in a sentence that its competitors’ marketing does not have an equivalent for.

Routing is not storage

Anthropic can route commercial customer traffic to selected countries in the United States, Europe, Asia and Australia, and Claude Enterprise customers billed on usage can select a routing location. Then comes the sentence: note that data is stored in the United States.

ProviderStorage in the EEAOn which plans
AnthropicNo, storage is in the USRouting can be selected, storage cannot
OpenAIYes, EEA and SwitzerlandEligible API, and new Enterprise or Edu
MicrosoftYes, under the EU Data BoundaryCommercial Copilot, with exceptions
GoogleYes, with data regionsEnterprise editions, or bought separately

Sources: each provider’s own documentation, consulted 19 September 2026 and cited in full below.

The reason the difference exists is architectural rather than legal. Storage in one place and inference in another are separate engineering decisions, and a provider can honour one without the other. Anthropic says so openly, which is worth more to a firm writing a transfer record than a page of reassurance would be.

That table is a comparison of commitments, not of safety, and no Irish regulator has ranked them. What it shows is that residency is the dimension where these four products differ most, and the dimension where a firm is most likely to assume rather than check. Our Copilot guide has the Microsoft half in detail.

Transfers, and the mechanism that carries them

For transfers out of the EEA, Anthropic relies on adequacy decisions where they exist and on the European Commission’s standard contractual clauses where they do not. That is the ordinary answer and it is the one your own transfer record will cite. The list of subprocessors and their locations is published in the Anthropic Trust Center, and it is the document your external IT provider should be reading, not the marketing page.

Anthropic Ireland, Limited, and an arbitrator in Dublin

Anthropic’s presence in Ireland is not a formality, and it shows up in two places a solicitor will notice.

The controller is in Dublin 4

The privacy policy states that for people in the EEA, the UK or Switzerland, the data controller is Anthropic Ireland, Limited, at 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29. The Data Protection Officer is reachable at a published address, and the policy points complainants to the supervisory authority where they live or work.

The arbitration clause with an Irish appointing authority

The commercial terms go further than most. For customers in the EEA, Switzerland or the UK, disputes are determined by a sole arbitrator in Dublin under the UNCITRAL rules, and the appointing authority is the President for the time being of the Law Society of Ireland.

An Irish appointing authority
Anthropic's commercial terms send European disputes to a sole arbitrator in Dublin, appointed by the President of the Law Society of Ireland. Commercial Terms of Service, 17 June 2025, section J.2.a

That clause is easy to skim past and hard to unsee. A commercial dispute between an Irish practice and Anthropic is heard in Dublin, in English, before an arbitrator chosen by the head of the profession most of the firms reading this belong to.

The one thing the policy does not say

OpenAI’s Europe policy names the Irish Data Protection Commission as its lead supervisory authority in as many words. Anthropic’s does not name a lead authority at all, and points you to the supervisory authority where you live or work.

Do not read more into that than it carries. A controller established in Dublin is the ordinary case for the one-stop-shop mechanism under Article 56 of the GDPR, and the DPC has described itself as lead supervisory authority for many large technology companies with their main establishment in Ireland.

But Anthropic has not written it down. The accurate thing to tell a client is that you would raise it with the DPC and ask, rather than that Dublin is formally in charge. Who leads for OpenAI, Google and Microsoft is set out in our other guides.

Claude inside Microsoft Copilot, and the boundary it is outside

There is a second way Irish firms use Claude without choosing it, and it changes the residency answer. Microsoft offers Anthropic models inside Copilot, and an administrator decides whether to enable them.

The line an admin toggle can undo

Microsoft’s own documentation adds a line that belongs on the page of anybody comparing these products: models provided by Anthropic as a subprocessor are currently excluded from the EU Data Boundary.

If your tenant has turned those models on, the Copilot guarantee that made your compliance team comfortable does not cover that path. It is one admin toggle, and it is easy to miss.

None of that is hidden, and none of it is wrongdoing, but it shows that a residency answer is a property of a configuration on a given date, rather than of a brand. The person who can tell you whether those models are enabled is your administrator, and in most Irish firms of this size that is an outside provider. It is also the kind of detail the cyber questionnaire will start asking about.

What the Irish regulator has said, and what it has not

The DPC has not opened a public inquiry into Anthropic. It has opened one into Google Ireland Limited, under section 110 of the Data Protection Act 2018, over whether a Data Protection Impact Assessment was required before developing an AI model. The absence of an Anthropic inquiry is not a clearance, and nobody should present it as one.

What the DPC has done is more useful to you than an enforcement headline. In September 2024 it asked the European Data Protection Board, under Article 64(2) of the GDPR, for an opinion on the use of personal data to develop and deploy AI models. The Board delivered it on 17 December 2024, answering when a model may be considered anonymous, and how a controller shows that legitimate interests is the right basis.

The scale is worth a line of its own. The DPC received 16,160 new cases from individuals in 2025, a rise of 45 per cent on the year before, and it put 4 questions to the European Data Protection Board about AI models. The DPC is also no longer the only regulator in this area, and who enforces the AI Act in Ireland was settled by a separate Act.

16,160new cases from individuals at the DPC in 2025
+45 %the increase on the year before
4questions the DPC put to the EDPB about AI models
DPC Annual Report 2025, 30 June 2026; DPC statement on the EDPB opinion, 18 December 2024

That is the Irish angle worth carrying. The European framework these four companies are measured against was shaped by a question asked from Dublin, and it is the framework your own DPIA has to satisfy.

The four questions the DPC asks before you start

The DPC’s own AI guidance, published on 18 July 2024, is written for you rather than for Anthropic. Before you start using a system, it asks you to understand what personal data it uses, where that data goes when a third party is involved, whether the provider retains or reuses it, and how the product lets you meet your obligations.

For Claude, all four are answerable from the documents listed at the end of this guide, which is more than can be said for most software a small firm buys. The guidance also reminds a user of an AI product that it “could be a data controller” in its own right, which is the sentence that turns a convenience into a filing obligation. The EU AI Act guide covers the separate regime that now sits alongside it.

What Irish professional rules ask, whichever model you use

On 12 November 2025 the Law Society of Ireland published guidance on generative AI for the profession. It names Claude explicitly, alongside Copilot, ChatGPT and Gemini, and its central line is about the versions, not the vendors: free and paid consumer versions are not suitable for securely handling personal data or client confidential data by default.

The safeguards the guidance actually names

The first item on its list of safeguards is a contractual obligation on the provider to treat data as confidential and apply zero data retention periods. Written into a firm’s terms, that safeguard becomes a statement the client can rely on, as in the data paragraph of an Irish engagement letter AI clause.

Anthropic offers zero data retention on the API by agreement, for qualifying cases. It is not a setting in the Claude app, and a firm that believes it has one should be able to point at the clause. Our Irish cyber cover guide sets out how these questions surface at renewal.

What the Law Society lists as a safeguardAvailable for Claude?
Contractual confidentiality and zero data retentionOn the API, by agreement
A data processing agreement limited to your purposesYes, the Anthropic DPA
Technical settings that limit data sharingYes, Privacy Settings and Incognito
Running the system locally or in your own environmentNot for Claude itself

Source: Law Society of Ireland, generative AI guidance, December 2025, read against Anthropic’s published terms.

That table is a checklist rather than a verdict. Three of the four are available, and the fourth is not available from any of these four assistants, which is worth saying because a firm comparing them will otherwise assume one of them offers it.

Privilege, and the document that left the firm

The same guidance makes the litigation point rather than the regulatory one. Intentionally giving privileged communications to a free or paid model without appropriate safeguards may lose the benefit of privilege, because it is an intentional release to a third party outside the firm. That risk is identical across all four products, and no vendor setting touches it. In the High Court, that risk now sits beside what a deponent swears about AI.

Incognito chats, connectors and Claude Code

Three features change the answer, and none of them are obvious from the settings page.

  1. Incognito chats are not used to improve Claude, even when model improvement is on. On commercial plans they are deleted within 30 days unless flagged.
  2. Connector content is outside the training set. Anthropic states that chat data it may use for training does not include raw content from connectors such as a document store, or from remote and local servers, though anything copied into the conversation is in.
  3. Claude Code on a personal plan follows the consumer setting. A developer in the firm working from a personal subscription is on the consumer terms, whatever the company thinks it bought.

The third of those is the one that reaches Irish practices with a single technical person, and it is a procurement problem rather than a privacy one. A seat bought on a card by whoever needed it first is a consumer contract, and the firm does not find out until somebody reads the terms.

The connector exception deserves a second look too. It is generous, and it is narrow in a specific way: anything copied into the conversation is in, whatever its origin. A paragraph pasted out of a document store is text in a chat, not connector content, and the distinction is invisible while you are working. That is exactly the habit our AI policy template is designed to catch.

How to change the setting and clear what is there

  1. Check which account. A personal login and a work seat are two different contracts, and only one of them rules out training.
  2. Open Privacy Settings and set model improvement. Turning it off excludes previous and new chats from future training, by Anthropic’s own statement.
  3. Delete the conversations you should not have started. They leave your history at once and backend storage within 30 days.
  4. Stop using the feedback buttons on client work. They store the whole conversation for five years, and that is not undone by the training setting.
  5. Ask for the zero retention clause if you need it. It is a commercial agreement on the API, not a toggle, and your provider negotiates it.
  6. Write down the answer. A firm that can show its reasoning is in a different position from a firm that can only show its intentions, and our template ends with the signature block that makes it evidence.
  7. Diary the review. Three of the documents behind this guide were updated in 2026. A setting you checked last winter is not a setting you can describe to a client today.

Why the date on each of these documents matters

Every answer above is dated, and that is not pedantry. The consumer training default is the part of this guide most likely to be out of date first, because it has already moved once.

DocumentDate it carriesWhy it matters to you
Privacy Policy10 September 2026Sets the consumer training default and the exceptions
Commercial Terms17 June 2025Carries the sentence ruling out training, and the Dublin arbitration
Retention article1 July 2026Holds the 30 day, five year, two year and seven year clocks
Server location article16 June 2026Says routing can be selected and storage is in the US

A firm that tells a client “Claude does not train on our data” without naming the plan and the date has made a claim it cannot support six months from now. The version that survives is narrower: on this plan, under these terms, as at this date. That is the standard the cyber questionnaire guide sets for every answer you sign.

What a tool can do here, and what no tool can do, including ours

Software of this category masks identifiers before the text is sent. It does not make an organisation compliant, because compliance is a property of an organisation and not of a product, and no Irish regulator has named a tool. What ours does is pseudonymisation: the mapping back to the person is kept, encrypted, on your own machine, so it is reversible by design and the result is still personal data under the GDPR.

The problem masking does not solve

Take every name out of a short attendance note and read what is left. A specific address, a child in the household, a file reference at a named previous adviser and the county will identify the matter to anyone who has seen the file, and often to anyone in the same town. Identifiability is a property of the whole document. That argument cuts against our own product, and we would rather write it down than have a client find it.

Our Irish results, both halves

The Irish layer of our engine has been measured against typical Irish office documents, using the settings it ships with. Most of the seeded identifiers were fully masked, some only in part and some not at all, and a few of the decoys that should have been left alone were masked anyway. It came out as the weakest of the layers we ship. A detection rate quoted without its false positives is a sales claim, which is why we give both halves.

Most of the partial cases came from one missing abbreviation. “Co.” made the engine read the full stop after it as the end of a sentence, so the address was cut short and the county stayed visible while the panel reported the address as covered. Adding the abbreviation fixed most of them, without moving any other market and without touching a single extra decoy. Half a masked address is, by our own written rule, worse than none.

There are Mac and Windows apps, with a free plan limited to 200,000 words a month, and the engine runs on the machine under a policy step that IT sets, not each user. Across a firm, IT adds a browser extension deployed by policy, a compliance panel and a monthly report.

If your answer is to move to a business plan and write one page of rules, that is a good answer and it costs nothing. Our organisations page is for the firms that get there and want the control as well. The same questions for the other three assistants are answered in our ChatGPT guide, our Gemini guide and our Copilot guide.

Sources

Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.

Common questions

Does Claude train on your data?

On consumer plans it can. Anthropic's privacy policy of 10 September 2026 says it may use your inputs and outputs to train its models unless you opt out in your account settings. On commercial plans the terms say it may not train on customer content.

How long does Anthropic keep Claude conversations?

Thirty days after you delete one. If you allow your chats to improve Claude, Anthropic may keep them in de-identified form for up to five years in its training pipelines. Conversations flagged by its safety systems are kept for two years.

Who is the data controller for Claude in Ireland?

Anthropic Ireland, Limited, registered at 6th Floor, South Bank House, Barrow Street, Dublin 4. The privacy policy of 10 September 2026 names it as the controller for people in the EEA, the UK and Switzerland.

Are Claude conversations stored in Europe?

No. Anthropic can route commercial traffic to selected countries in Europe, but its own privacy centre article of 16 June 2026 adds that data is stored in the United States. Routing and storage are two different commitments.

What does opting out of Claude training actually stop?

It stops future chats being used to improve the models, and Anthropic says previous chats are excluded too. It does not stop use where a conversation is flagged for safety review, or where you submit feedback through the thumbs buttons.

Can an Irish business get zero data retention with Anthropic?

It is available by agreement on the Anthropic API, not as a setting in the Claude app. The Law Society of Ireland lists a contractual zero retention period among the safeguards that can make a tool appropriate for client material.

Does Anthropic sell personal data?

Its privacy policy states that it does not sell personal data as that term is defined by applicable laws and regulations, and that it honours global privacy controls for targeted advertising of its own products.

Is Claude allowed for client files in an Irish firm?

The Law Society of Ireland's December 2025 guidance names Claude among the systems it covers and says free and paid consumer versions are not suitable for securely handling client confidential data by default. Enterprise versions still need due diligence.

Where would an Irish complaint about Claude go?

Anthropic Ireland, Limited is the controller for the European region, and Ireland is where a complaint would naturally start. Unlike OpenAI, Anthropic's policy does not name a lead supervisory authority, so ask the DPC rather than assume.