[nonimo]
EN
Download

Does Claude train on your data? What Anthropic says

· Updated · Written and maintained by Joaquín Trapero, Nonimo

Does Claude train on your data? On a personal Claude account, yes, unless you have turned it off. Anthropic’s privacy policy states that it may use your inputs and outputs to train and improve its models unless you opt out through your account settings. On its commercial products the default runs the other way, and Anthropic states it will not.

That much you will find almost anywhere. What you will almost never find is the second half of the same paragraph, where the policy names two things it will do with your conversations even after you opt out, and the retention ladder behind it, which reaches seven years.

This guide reads the primary documents and says what each one says, with the date it carries. If the underlying worry is whether a paste has already gone wrong, that has its own guide and a different answer.

AccountTrains by defaultWho changes it
Free, Pro, MaxYesThe user, in Privacy Settings
Claude for Work, TeamNoNot applicable
Claude EnterpriseNoOwner controls feedback
Anthropic API, Claude GovNoNot applicable

Anthropic privacy policy of September 10, 2026, and privacy center articles of March 16 and August 19, 2026.

Does Claude train on your data on a personal plan?

Much of what you will find on this was written in 2025 and quotes a version of Anthropic’s policy that has since been replaced. The wording that governs you now sits in a document with a much newer date, and that is the one worth reading.

What the policy says today

The privacy policy effective September 10, 2026, puts it in one sentence: Anthropic may use your inputs and outputs to train and improve its models, unless you opt out through your account settings. The privacy center repeats it and adds where the switch lives, which is the model improvement setting inside Privacy Settings.

Two smaller points go with it and are worth knowing. Incognito chats are never used to improve Claude, even with the setting on. And if you turn the setting off, Anthropic states your previous and new chats will not be used for future training, though data already inside a training run in progress stays in that run.

Claude Code on a personal plan follows the same rule

This is the detail that catches technical people. Anthropic’s consumer privacy articles state that they cover Free, Pro and Max accounts and when accounts from those plans use Claude Code. The plan decides, not the tool.

So a developer at a firm who pays for Claude Pro personally and runs Claude Code against a client repository is on the consumer default, in a client’s codebase, unless someone turned the setting off. Under a commercial account the commercial default applies instead, which is one more reason which account people sign in with is the lever worth pulling first.

The opt out has two exceptions, and both are in the policy

Anthropic writes that even if you opt out, it will use inputs and outputs for model improvement in two cases: when your conversations are flagged for safety review, and when you have explicitly reported the materials, for example through its feedback mechanisms.

Neither is buried. Both are in the same paragraph as the right to opt out, in section 2 of the privacy policy. They just come after the clause where most people stop reading.

ExceptionTriggered byRetention
Flagged for safety reviewAnthropic’s automated systems2 years, scores 7
Explicitly reported materialAnyone pressing thumbs up or down5 years

Anthropic privacy policy effective September 10, 2026, and privacy center of July 1, 2026.

The difference between the two rows is who acts. The first is not something a user does or can see; the second is a button that looks like a rating. Both are worth naming in a written AI policy, because neither is covered by the setting people are told to check.

Conversations flagged for safety review

If Anthropic’s automated systems flag a chat as violating the Usage Policy, the content can be used to improve its ability to detect harmful content and to train models used by its safeguards team. The policy adds that flagged content is disassociated from your user ID first, and may be reidentified in order to enforce the terms against the responsible user.

Note the retention that goes with that flag. Inputs and outputs are kept for up to two years, and the trust and safety classification scores derived from them for up to seven.

7 years
the maximum Anthropic states it retains trust and safety classification scores for a flagged chat. The inputs and outputs behind them, up to two years. Privacy center, July 1, 2026

A score is not a transcript, and the distinction is real. It is also the longest period any of the four major AI providers states in its documents, and it attaches to a conversation you never chose to submit to anything.

The thumbs up, and the five years behind it

The second exception is the one anybody can trigger in a second. Press thumbs up or thumbs down and Anthropic stores the entire related conversation, including any content, custom styles and conversation preferences, on its systems for up to five years.

Anthropic says it unlinks feedback from your user ID before using it, does not combine it with your other conversations, and excludes raw content pulled in from connectors such as a drive, though content copied directly into the chat is included. All of that is true and none of it changes the first fact: the whole exchange was handed over, to be kept for up to five years, with one click.

How long Anthropic keeps what you typed

Anthropic keeps what you type on four separate timers. The privacy center publishes them separately for consumer and commercial products, and the numbers are the same.

Four clocks, and only one of them is short

Deleted chat30 days
Flagged content2 years
Training and feedback5 years
Classification scores7 years
Anthropic privacy center, July 1, 2026. Every figure is a stated maximum, not a fixed period, and the bars are scaled against the longest of them

Read the bars and the picture reorders itself. The thirty days everyone quotes is the shortest clock in the set and applies only to something you deliberately deleted. Everything else runs in years, and none of it depends on an action you took.

Deleting a chat, and what deletion does not reach

Delete a conversation and it leaves your history immediately and Anthropic’s storage systems within 30 days. That is a clean promise and Anthropic repeats it in three places.

What it does not reach is anything that has already been used. If a chat was used for model improvement before you deleted it, deletion removes the copy, not the training run. The privacy center says so directly: your data stays in runs already in progress and in models already trained. That is the same asymmetry at every one of the four major assistants, and it is a property of how models are built rather than a policy choice.

Projects behave differently from chats on Enterprise, and the difference bites. Anthropic states that project retention takes precedence over chat retention, that projects are retained indefinitely by default, and that chats inside a project are therefore not deleted by a chat retention period. A firm that sets thirty days and files everything in projects has set nothing.

Training is one use of your text, not the only one

All of the above turns on a confusion worth naming, because it is the one that gets client files pasted into chatbots by people who believed they had checked the box that mattered.

We do not train on your data is a promise about one use. It says your words will not be folded into a future model. It does not say that nobody read them, that nothing was kept, or that they never left your office. Four separate questions, and answering one of them tells you nothing about the other three.

What still happens with training off

What still happensWhere Anthropic says so
The conversation is stored and retainedPrivacy center, data retention
Automated systems classify itPrivacy policy, section 6
Flagged content is reviewed and keptPrivacy policy, section 2
It is disclosed under valid legal processPrivacy policy, section 3

Anthropic privacy policy effective September 10, 2026, and privacy center articles of July 1, 2026.

In a country with no federal data regulator, the fourth row is the one that decides your exposure. Nobody is going to write you a letter about a training setting. Somebody may serve a subpoena, and the question then is not what the provider promised about model building but what it holds and can be made to produce. A federal judge has read Anthropic’s terms that way, in the Heppner ruling on a defendant’s chats with Claude.

That is also why server location, discussed further down, answers less here than the marketing suggests. The copy exists. Where it sits is a detail compared with who can reach it.

It is worth saying that this is not a criticism of Anthropic in particular. Every provider behind the four major assistants publishes a training commitment and every one of them keeps, classifies and discloses the same text under the same kinds of conditions. The commitment is real and it answers one question out of four. Reading it as the answer to all four is the mistake, and it is a mistake the wording invites.

Commercial plans flip the default, with one door left open

On Claude for Work, Claude Enterprise, the Anthropic API and Claude Gov, the privacy center states that by default Anthropic will not use your inputs or outputs to train its models. That is the sentence a firm is buying, and it is unambiguous.

The exception is the same button as before. If someone in your organization explicitly reports feedback or a bug, Anthropic may use those chats to train its models, and stores the entire related conversation for up to five years. The commercial default removes the routine case. It does not remove the click.

The admin control most owners never open

There is a switch for this and almost nobody knows it exists. Anthropic states that a Primary Owner or Owner of a Team or Enterprise plan can disable feedback submission for the whole organization, through the Rate chats setting under organization settings, data and privacy.

That is a change of about ninety seconds that closes the only remaining training path on a commercial plan. It is the kind of thing an IT provider running the rollout should do on day one, and the kind of thing that never happens if nobody names it.

The same settings screen holds the other control worth knowing about, and it comes with a floor. An Enterprise owner can set a custom retention period for chats and projects, and Anthropic states the minimum is 30 days, counted from the last activity rather than from creation.

30 days
the shortest retention an Enterprise owner can configure for chats and projects. An organization that wants nothing kept cannot get there through this setting. Anthropic privacy center

So the answer to the question a cautious firm actually asks, whether it can tell Claude to keep nothing, is no on the standard controls. Zero data retention exists, but Anthropic describes it as a negotiated agreement on qualifying accounts rather than a switch, and it is incompatible with several features of the product. A firm should not promise a client more, and the data sentences of an engagement letter should say only what the contract delivers.

Who can read a conversation, and who can be made to hand it over

Three different routes, with three different rules, and only one of them involves Anthropic deciding anything. In a government office there is a fourth route that no vendor table shows, the public records request, and it reaches the prompt itself.

RouteWho reaches itWhat decides
Your own organizationAn admin, if your account is linkedYour email domain
Anthropic staffSafety, support and enforcement workIts own policies
A government requestLaw enforcement or a courtValid legal process

Anthropic consumer terms of October 8, 2025, privacy policy of September 10, 2026, and its published policy on governmental requests.

For a firm with privileged material the middle row is the least interesting and the first is the most, because it is the only one that is under your control and the only one most people have never checked. Checking it belongs in the AI policy a managing partner writes and has to enforce, since the person who signs that policy is rarely the one pasting.

The employer email address clause

Anthropic’s consumer terms of service, effective October 8, 2025, state that if you use an email address owned by your employer or another organization, your account may be linked to that organization’s enterprise account, and the organization’s administrator may be able to monitor and control the account, including having access to your materials.

The terms add that Anthropic will give you notice before linking, unless the organization is responsible for telling you or already has. It is the same clause that exists at OpenAI and at Microsoft, and it runs in the direction people do not expect: a personal account opened with a work domain is reachable from the firm.

Government requests, and the notice Anthropic says it gives

Anthropic publishes its policy for government requests, and two of its commitments are worth quoting because the other providers here do not state them in the same terms.

It says it does not disclose information about customers or end users in response to government requests except under valid legal process, such as a validly issued subpoena or warrant, with an exception for emergencies involving imminent physical harm or death. It says it evaluates each request and may reject ones that are overly broad or vague.

And it says it will give users notice when their data is requested, unless it believes it is legally prohibited from doing so or another rare exception applies, adding that where data is sought on an API or enterprise customer it will generally ask the requester to contact that customer first. For a firm holding privileged material, being told is the difference between moving to quash and finding out afterward.

Where the servers are, and what that does and does not buy

Anthropic states that it uses multiple cloud providers, that by default it may route customer traffic to select countries in the United States, Europe, Asia and Australia unless otherwise agreed, and that data is stored in the US. Developer platform and Enterprise customers billed by usage can select a traffic routing location.

For an American firm that closes the question rather than opening one. Storage is domestic, routing is configurable on the plans where it matters, and there is no federal regulator you would have to show the answer to anyway. The version of this question that does matter to you is the insurance one, because the insurer’s application asks.

HIPAA: a standard Enterprise plan is not covered until someone turns it on

This is the sharpest caveat in Anthropic’s documentation and it is one line on a page most buyers never open. Anthropic states that standard Claude Enterprise plans do not include business associate agreement coverage without action from a Primary Owner.

Coverage begins when that owner activates HIPAA compliance in the organization’s data and privacy settings and accepts the agreement. Until then a firm that bought Enterprise, believing Enterprise meant covered, is not covered, and the only sign is a missing checkmark in the HIPAA Compliance section of those same settings. Every vendor gates it differently, and which products a business associate agreement actually reaches is the comparison worth making before anyone signs.

Anthropic adds that the agreement covers only the single organization that accepted it, and that the step cannot be reversed from organization settings. The API has a switch of its own: an admin turns on HIPAA readiness in the Claude Console and accepts a BAA there, and that is permanent too. Team plans and the personal Free, Pro and Max plans cannot turn HIPAA on at all. Two gates, both in admin settings, neither announced to the people typing.

The features the agreement leaves outside

Even once it is on, the agreement does not cover everything in the product. Anthropic publishes a table that goes feature by feature, and the pattern is that anything sending data to a third party sits outside it.

FeatureUnder the agreement
Chat, Projects, ArtifactsCovered
Web Search, Research, Voice, SkillsCovered
File creation and code executionCovered, without network access
Connectors and MCP serversNot covered for data sent to third parties
Enterprise Search, Claude in ChromeNot covered for data sent to third parties
CoworkNot covered
Claude Design, Slides and Docs, in betaNot available once HIPAA is on

Anthropic privacy center, Business Associate Agreements for Commercial Customers, read September 26, 2026.

Claude Code has a gate of its own. Anthropic’s table covers it only with zero data retention enabled, on qualified accounts, which leaves out its remote and web modes; and HIPAA readiness on the API, the switch an admin turns on in the Console, does not cover Claude Code at all. If protected health information is in scope for your firm, that table is a procurement document, and so is the equivalent list at OpenAI.

Does Anthropic sell or share your data?

Anthropic states it does not sell personal data as that term is defined by applicable laws and regulations. It also states that you can opt out of sharing your personal data for targeted advertising to promote its own products and services, and that it honors global privacy controls.

That is the same structure OpenAI’s US policy now has, and it needs the same careful reading. Selling is ruled out; a narrower kind of sharing, specific to advertising, exists and is switched off by you rather than by them. Neither company describes sending conversations to advertisers, and neither should be read as doing so.

The longer list of who else receives data is in section 3 of the policy, and it answers the question in its everyday sense rather than the legal one.

RecipientWhat reaches them
Affiliates and corporate partnersThe categories in section 1
Service providers and business partnersHosting, auditing, safety and fraud work
Your organization’s administratorYour materials, if your account is linked
Outside services you connectInputs, outputs and instructions you send

Anthropic privacy policy, section 3, effective September 10, 2026.

The third row is the one a firm should read twice, and the fourth is the one that grows fastest. Connectors and MCP servers send your inputs and outputs directly to the third party, which processes them under its own policy; Anthropic states plainly that it does not control those practices. That is the same problem a client security questionnaire is trying to surface when it asks about subprocessors.

How to turn training off, and how to delete what is there

Four things, none of which needs a budget or a meeting. Do them in order, and write down that you did.

StepWhere the setting isWhat it does
1. Turn off model improvementPrivacy SettingsKeeps previous and new chats out of future training; the two exceptions above still stand
2. Turn off Rate chats (Team or Enterprise)Organization settings, data and privacyCloses the feedback path for everyone at once
3. Set a retention period, and check where chats liveThe same organization settings screen, on EnterpriseThirty days is the floor; chats inside projects follow the project, which defaults to indefinite
4. Delete what is already thereThe conversations themselvesIt leaves your history immediately and Anthropic’s storage systems within 30 days

Anthropic privacy center articles, read September 19, 2026.

Then note the date. Anthropic’s policy carries September 10, 2026, and its privacy center articles carry four different dates between March and August; a check is only ever a check of a version.

That last step is the one firms skip and the one that pays. An undated note saying training is off is worth nothing to a client asking what you had in place last March, and it is worth nothing on the renewal form your insurer sends either. A dated line in a shared document costs nothing and answers both.

What a tool can do here, and what no tool can do, including ours

Software of this kind can mask identifiers before text is sent, because identifiers sit in predictable places in a document and some of them carry check digits a machine can verify. It can show what it changed so a human can overrule it, and it can leave a record that the control was on.

It cannot decide that a document is too sensitive to send at all. It cannot see that a paragraph identifies a client through facts rather than names. And it cannot make you compliant, because compliance is not a property that software has.

What our engine does and does not do in the United States

An SSN, an EIN or a Medicare beneficiary identifier beside a label the engine recognizes is masked before the text goes, and the replacement is a general REFERENCE tag, never the digits. An email address is replaced without asking, because its format leaves no doubt, and so is a card number with a valid check digit. You see each change and can undo it.

Nonimo runs on the computer itself, on Mac and Windows, and IT sets the policy step for the whole firm rather than for each user. What it replaces, it replaces reversibly, keeping the mapping encrypted on the user’s own computer. That is pseudonymization rather than anonymization, and it is how our pages for organizations describe it too.

What the app keeps on your disk is set out on Nonimo’s security page.

If you buy nothing at all, do these five things

  1. Check which plan each person is signed in to. It sets the training default, and on Claude Code it sets it silently.
  2. Turn off model improvement, and turn off Rate chats if you have an owner seat. Two switches, one of them for the whole organization.
  3. Look at where your chats live before you set retention. A project keeps them forever no matter what the chat rule says.
  4. If you touch health data, open the agreement settings. Enterprise is not covered until a Primary Owner turns it on and accepts.
  5. Write the never list. Five lines naming what may never be pasted. Yours will name things nobody else can guess.

A firm that does all five is in better shape than one that bought a tool and did none of them. If a control later looks worth it, our license terms say plainly what ours is and is not.

Two things you will read elsewhere that are wrong today

We checked both claims below against the current documents on September 19, 2026.

The first is that if you pay for Claude, it does not train on your data. Several pages say it, and one of them is a community post that says the Pro plan does NOT train on your data. Pro is a consumer plan and carries the consumer default; the products where the default reverses are Claude for Work, Claude Enterprise, the API and Claude Gov.

The second is that opting out removes your conversations from training entirely. It removes the routine case. Anthropic’s own policy keeps two paths open after you opt out, one of which any user can trigger with a single click, and the second of those stores the whole conversation for five years.

What you will readWhat Anthropic says todayWhere it says so
A paid plan does not train on your dataPro is a consumer plan and trains by default; the default reverses on Claude for Work, Enterprise, the API and Claude GovPrivacy policy of September 10, 2026, and privacy center of August 19, 2026
Opting out takes your chats out of training entirelyTwo paths stay open: chats flagged for safety review and feedback you submitPrivacy policy, section 2, September 10, 2026

Checked against the current documents on September 19, 2026.

Both errors have the same shape, and it is the shape to watch for across this whole subject. A sentence that was true of one plan, or true on one date, keeps getting repeated until it describes a product that no longer exists. Every claim in our guides carries the date we read the source, and this page will need rereading too: three of the nine documents behind it changed during 2026.

Sources

Checked September 19, 2026. Every link below returned a live page on that date.

The same questions for the other three assistants: does ChatGPT share or sell your data, what Gemini does with your data, and does Microsoft Copilot train on your data.

Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.

Common questions

Does Claude train on your data?

On Free, Pro and Max, yes by default. Anthropic's privacy policy states it may use your inputs and outputs to train and improve its models unless you opt out through your account settings. On commercial products the default is the reverse.

Does Claude for Work or the API train on your data?

No by default. Anthropic states it will not use inputs or outputs from commercial products such as Claude for Work, the Anthropic API and Claude Gov to train its models, unless you report feedback or otherwise choose to allow it.

Does Claude Code train on your data?

It follows the plan it runs under. Anthropic's consumer articles cover Claude Code when used from a Free, Pro or Max account, so the consumer default applies. Under a commercial account the commercial default applies instead.

If I opt out of training, is my data excluded?

Not entirely. The privacy policy names two exceptions that still apply after you opt out: conversations flagged for safety review, and materials you explicitly report, for example through the thumbs up and thumbs down button.

How long does Anthropic keep my Claude conversations?

Deleted conversations leave Anthropic's storage systems within 30 days. Conversations used for model improvement may be kept, deidentified, for up to five years. Flagged content is kept up to two years, and its classification scores up to seven.

Does Anthropic sell your data?

Anthropic states it does not sell personal data as that term is defined by applicable laws. It does let you opt out of sharing personal data for targeted advertising of its own products, and says it honors global privacy controls.

Is Claude HIPAA compliant?

Claude is not HIPAA compliant on its own; Anthropic signs a BAA only for Claude Enterprise and the Claude API. On Enterprise, only the Primary Owner can turn HIPAA on, by accepting Anthropic's standard BAA with one click in organization settings, and Anthropic says the change cannot be undone. Team, Free, Pro and Max cannot enable it. Cowork, beta features and Claude Code without zero data retention stay outside the agreement.

Where does Anthropic store Claude data?

In the United States. Anthropic states that traffic may be routed to select countries in the US, Europe, Asia and Australia by default, and adds that data is stored in the US.

How do I stop Claude from training on my chats?

Open your Privacy Settings and turn off the model improvement setting. Anthropic states that previous and new chats will then not be used for future training, though data already inside a training run in progress stays there.