
Every time you paste a client email into ChatGPT or upload a document to Claude, you’re handing over data. But where does it go? Is it training the next version of the model? Can other users see it? The answer depends on which tool you’re using and how you’ve configured it.
Most people assume their AI conversations are private by default. That’s not always true. Here’s what actually happens to your data across the major AI platforms, and how to take control.
What ChatGPT Does With Your Prompts
OpenAI’s default setting allows your conversations to be used for model training—unless you opt out. If you’re on the free tier or ChatGPT Plus, your prompts and the AI’s responses can be reviewed by human trainers and used to improve future models.
To opt out, go to Settings → Data Controls → Chat History & Training and toggle it off. Once disabled, your conversations won’t be used for training, but they also won’t appear in your history sidebar. You can still access them in the settings menu.
One exception: ChatGPT Enterprise and Team accounts don’t use customer data for training by default. If you’re using AI for work, make sure your organization has the right plan.
Claude’s Privacy-First Approach
Anthropic takes a stricter stance. By default, conversations with Claude are not used to train the model. Your prompts are stored temporarily for trust and safety monitoring (to catch abuse), then deleted within 90 days.
If you’re using Claude Pro or Team, your data stays even more locked down. Anthropic doesn’t sell user data or share it with third parties for advertising. You can also delete individual conversations manually at any time.
That said, if you’re using Claude via an API integration (like through a third-party app), the privacy terms of that app apply—not Anthropic’s. Always check the privacy policy of the tool you’re using.
Google Gemini and Your Google Account
Gemini ties directly into your Google account, which means privacy settings can get murky. By default, Gemini stores your conversations to improve its services. Google reviews some interactions (with personal info redacted) to train and refine the model.
To limit data collection, go to Gemini Apps Activity in your Google account settings and pause or delete your history. You can also use Incognito mode in Gemini, which prevents your prompts from being saved or used for training—but you lose conversation history.
One key difference: Gemini Advanced users (paid subscribers) have more control, including the ability to retain conversation history without contributing to model training. Free users have fewer options.
What Happens When You Upload Files
Uploading documents, images, or spreadsheets introduces another layer of risk. In ChatGPT, uploaded files are treated the same as text prompts—they’re subject to your training opt-in/opt-out settings. If training is enabled, your file contents could theoretically be used.
Claude doesn’t use uploaded files for training by default, but they are temporarily stored for processing and safety review. Gemini’s file handling depends on whether you’ve paused activity tracking.
General rule: don’t upload anything confidential unless you’re on an enterprise plan with explicit data protection guarantees. Treat free-tier AI tools like public utilities—they’re powerful, but not secure vaults.
What About Third-Party AI Tools?
Tools like Jasper, Copy.ai, and Notion AI are built on top of OpenAI, Anthropic, or Google models. That means they inherit those companies’ data policies—but also add their own. Some third-party apps store your prompts indefinitely or use them to improve their own products.
Before using a third-party AI tool, read its privacy policy. Look for answers to these questions:
- Does the tool store your prompts, and for how long?
- Is your data used for training or product improvement?
- Can you delete your data on request?
- Is your data encrypted in transit and at rest?
If the policy is vague or missing, assume the worst.
Anonymous Doesn’t Mean Invisible
Even when companies promise to “anonymize” your data, that’s not bulletproof. Researchers have shown that anonymized datasets can sometimes be re-identified, especially if prompts contain unique details (names, locations, project specifics).
If you’re working with sensitive material—legal documents, medical records, proprietary code—use a paid enterprise plan with a Business Associate Agreement (BAA) or Data Processing Agreement (DPA). Free-tier AI is not HIPAA or GDPR compliant by default.
Quick Privacy Checklist
Here’s how to lock down your AI usage right now:
- Turn off training in ChatGPT (Settings → Data Controls)
- Pause Gemini Apps Activity in your Google account
- Delete old conversations you no longer need
- Avoid uploading sensitive files to free-tier tools
- Use enterprise or team plans for work projects
- Review third-party app privacy policies before connecting them
- Consider using temporary email addresses for AI signups if you’re testing tools
AI tools are incredibly useful, but they’re not private by default. A few minutes of settings tweaks can make a big difference in how much control you keep over your data.
Want one practical AI tip like this every day? Subscribe to the One Two Three AI newsletter and get smarter about AI—one idea at a time.
