On business plans (Team and Enterprise), Anthropic does not use your data for model training by default. On consumer plans (Free and Pro), it does, unless each user manually opts out. Enterprise accounts never use data for training regardless of settings.
But the bigger risk for most UK businesses is not whether Anthropic trains on your data. It is what your staff are pasting into Claude with no policy, no oversight and no record of what was shared. Anthropic’s privacy controls govern what Anthropic does. They do not govern what your team does.
If you want a clear picture of where your business stands, book half an hour with Adam Gillett. No charge and no expectation that you buy anything.
On business plans (Team and Enterprise), Anthropic does not use your data for model training by default. On consumer plans (Free and Pro), it does, unless each user manually opts out. Enterprise accounts never use data for training regardless of settings.
But the bigger risk for most UK businesses is not whether Anthropic trains on your data. It is what your staff are pasting into Claude with no policy, no oversight and no record of what was shared. Anthropic’s privacy controls govern what Anthropic does. They do not govern what your team does.
If you want a clear picture of where your business stands, book half an hour with Adam Gillett. No charge and no expectation that you buy anything.
Last checked: 17 August 2026. We review this page quarterly to keep up with policy changes.
Anthropic publishes its data retention practices and training policies across several sources, including its privacy policy, its data usage documentation and its support centre. What follows is drawn from those sources.
The critical point is that business and consumer plans work very differently. Consumer products and commercial terms are governed by separate policies with separate defaults. Knowing which plan your staff are on determines everything that follows.
We are not Anthropic. We are We Do Your IT Support, a UK managed IT and cyber security provider.We have no commercial relationship with Anthropic. Our role here is to read the fine print so you do not have to, and to flag where the real risks sit for a business of your size.
Last checked: 17 August 2026. We review this page quarterly to keep up with policy changes.
Anthropic publishes its data retention practices and training policies across several sources, including its privacy policy, its data usage documentation and its support centre. What follows is drawn from those sources.
The critical point is that business and consumer plans work very differently. Consumer products and commercial terms are governed by separate policies with separate defaults. Knowing which plan your staff are on determines everything that follows.
We are not Anthropic. We are We Do Your IT Support, a UK managed IT and cyber security provider.We have no commercial relationship with Anthropic. Our role here is to read the fine print so you do not have to, and to flag where the real risks sit for a business of your size.
Consumer accounts on Claude Free, Pro and Max plans are designed for individual users, not for business confidentiality. They carry no contractual data protection, no data processing agreements and no guarantees around how conversation data is handled beyond the consumer terms.
Business accounts under commercial terms bring legal obligations. Claude Enterprise includes DPAs for GDPR compliance, configurable data retention, and the option for zero data retention. EU and UK users on consumer plans are protected by GDPR through standard contractual clauses for international data transfers, but that is not the same as having a negotiated commercial contract.
Your account type determines what happens to your corporate data. If your team is using personal Claude accounts on Free or Pro plans for work, they have the same data training exposure as any other consumer. The plan is the policy.
Claude Free, Pro and Max accounts are consumer products. Under Claude’s privacy policy, the default setting for data training is “On” for consumer accounts. That means chats and coding sessions can be used for future model training and to improve Claude unless each user toggles the training preference off. Before September 2025, Claude never used conversations for training. After September 2025, training on conversations became opt-in for users, but the default is opted in.
Claude retains data for up to five years if opted in. The retention period increased by 6,000% for consumer accounts compared to earlier policies. If users opt out of training, conversation data is retained for 30 days. Deleted conversations are retained for 30 days before permanent deletion, and may be retained in backups for 30 days beyond that. Flagged conversations can be reviewed and retained for up to 2 years.
Claude collects conversation data, including every message sent. Consumer accounts risk training data exposure unless opted out. There is no commercial DPA, no contractual guarantee and no enterprise-grade security measures governing how that data is handled. Claude’s consumer accounts are not HIPAA compliant. Anthropic does not sell users’ data to third parties, but it may use consumer data to conduct research, study user behaviour and improve its safety systems.
For a business, the implication is clear. Free users on consumer accounts should not be handling sensitive data, client information, contracts or anything commercially confidential. The legal exposure is yours, not Anthropic’s.
Claude Team is a commercial offering. Under commercial terms, Anthropic does not use Team plan content for model training by default, which is a meaningful step up from consumer plans. Your data is not feeding future Claude models unless your organisation explicitly opts in via programmes like the Development Partner Programme.
However, Team lacks several of the controls that matter most for confidential data. Zero data retention is generally not available for Team. Standard data retention of around 30 days applies. There are no comprehensive audit logs, no BAA for healthcare data, and fewer administrative controls than Enterprise.
Team is better than Free or Pro for business use. But if your firm handles genuinely confidential data, regulated information, or client material under legal privilege, Team does not offer enterprise-grade protection. It sits in a middle ground.
Claude Enterprise is where the privacy picture changes substantially. Enterprise accounts never use data for training regardless of settings. That guarantee is contractual, not just a toggle.
Enterprise offers zero data retention, data processing agreements for GDPR compliance, and the ability to configure organisation-wide retention policies. Enterprise accounts can be configured for HIPAA compliance through a Business Associate Agreement. All user data is secured using AES-256 encryption at rest, and protected in transit using TLS 1.2 or higher.
Enterprise comes with custom pricing and requires contract negotiation. For regulated sectors, legal practices and firms handling client-sensitive information, it is the only plan where Claude is suitable for confidential data.
If you or your staff are on consumer plans, here is how to check and adjust your settings:
STEP ONE- CHECK YOUR PLAN
Open Claude and look at your account or admin settings. Your plan type (Free, Pro, Team, Enterprise) determines your defaults.
STEP TWO – TOGGLE TRAINING OFF
In consumer accounts, go to Settings, then Privacy. To opt out, users must toggle “Help improve Claude” to OFF. This prevents your chats and coding sessions from being used for future model training. Users must actively opt in to allow data for model training, but the default is on.
STEP THREE – DELETE INDIVIDUAL CHATS
You can delete individual chats to prevent them from being used in model improvement. Deleted conversations are retained for 30 days before permanent deletion from Anthropic’s systems.
STEP FOUR – USE INGOCNITO WINDOW
Incognito mode conversations are never used for model training. If a staff member needs to use a consumer account for a one-off task, incognito mode reduces the data training exposure. Note that future conversations in normal mode will still follow the default unless the toggle is off.
STEP FIVE – ENTERPRISE ADMINS
Should contact their Anthropic account team to enable or verify zero data retention and configure retention policies at organisation level. A comprehensive audit of your current settings is worth doing before rolling Claude out to staff.
Claude’s privacy policy is clearer than ChatGPT’s according to independent evaluations, but clarity does not mean the defaults are safe for business use. Sensitive information is filtered or obfuscated before being used for model improvement on consumer plans, but the data is still collected.
Zero data retention (ZDR) is available only on Enterprise plans and the Anthropic API under commercial terms. When enabled, prompts and model outputs are not stored by Anthropic after the response is generated.
What ZDR covers: eligible features such as Claude Code under Enterprise. Once enabled, your data leaves Anthropic’s systems immediately after processing.
What ZDR does not cover: some product surfaces, including the claude.ai web chat interface and certain integrations, are not covered. Covered Models (such as Anthropic’s Mythos-class models, including Fable 5) require a mandatory 30-day data retention period even under ZDR. As of June 2026, to use those models, retention must be enabled in the specific workspace. Microsoft reportedly restricted employee use of Claude Fable 5 over concerns about this new data retention policy.
To verify ZDR is active, check your Enterprise console or contact your Anthropic account manager. Nominal user access for safety monitoring is logged and restricted, and Anthropic employs cybersecurity measures including multifactor authentication across its infrastructure.
Zero data retention (ZDR) is available only on Enterprise plans and the Anthropic API under commercial terms. When enabled, prompts and model outputs are not stored by Anthropic after the response is generated.
What ZDR covers: eligible features such as Claude Code under Enterprise. Once enabled, your data leaves Anthropic’s systems immediately after processing.
What ZDR does not cover: some product surfaces, including the claude.ai web chat interface and certain integrations, are not covered. Covered Models (such as Anthropic’s Mythos-class models, including Fable 5) require a mandatory 30-day data retention period even under ZDR. As of June 2026, to use those models, retention must be enabled in the specific workspace. Microsoft reportedly restricted employee use of Claude Fable 5 over concerns about this new data retention policy.
To verify ZDR is active, check your Enterprise console or contact your Anthropic account manager. Nominal user access for safety monitoring is logged and restricted, and Anthropic employs cybersecurity measures including multifactor authentication across its infrastructure.
ZDR is a strong control, but it is not a blanket guarantee. If your organisation needs it, confirm exactly which features and AI models it applies to before treating it as complete protection.
This is the section that matters most for your business.
Anthropic’s Claude AI privacy policy governs what Anthropic does with the data collected through its platform. It does not govern what your employees choose to paste into Claude, or any other AI tools they have access to.
When companies realise staff are already using Claude, the question is rarely about the vendor’s policy. It is about the corporate data entered into pipelines nobody authorised, monitored or even knew about. Client contact lists, financial records, contracts, patient data, pupil data, payroll files. Shadow AI usage is the real source of legal exposure for most SMEs. Employee access to AI tools without governance is the gap.
No usage policy from Anthropic will stop a staff member copying a confidential spreadsheet into a Claude Free prompt. No data retention setting will undo that disclosure. The data retained by Anthropic is only part of the picture. The data that leaves your organisation in the first place is the risk you control.
Our Core AI Security Pack is designed to close exactly this gap. It deploys Microsoft Purview for activity monitoring and data classification, web and AI tool usage filtering, and includes a written AI policy for staff. It addresses staff behaviour, not just vendor promises.
To summarise: your plan type determines whether Anthropic trains on your data. Enterprise and Team plans do not by default. Consumer plans do. But what your staff put into Claude matters more than what Anthropic does with it afterwards.
Book half an hour with Adam Gillett. No charge and no expectation that you buy anything.
Need an AI policy now? Download our free AI Policy Template as a starting point for governing how your team uses Claude and other services.
It depends entirely on your plan type. On consumer plans (Claude Free, Pro and Max), your conversation data can be used for AI training and to train AI models unless you opt out through privacy settings. On enterprise accounts and the Claude API under commercial terms, Claude does not train on your data by default. That guarantee is contractual.
The answer is the same as above, but worth restating. Consumer accounts risk data training exposure unless each user explicitly toggles training off. The default is on. On Claude for Work plans (Team and Enterprise), data is not used for model training unless your organisation opts in. You can check your current settings under Privacy in your Claude account. User control over model training helps manage data privacy, but only if users actually exercise it.
The pricing structures are fundamentally different. ChatGPT Enterprise uses a per seat model with usage limits included. Claude Enterprise charges a seat fee plus usage billed separately based on input and output tokens at API rates (claude api pricing). Depending on your seat count and token usage, Claude could cost more or less than ChatGPT Enterprise. Check Anthropic’s pricing page and OpenAI’s enterprise pricing for current rates before committing. We cover the broader comparison on a separate page.
On Claude Enterprise with zero data retention enabled and proper internal controls, yes. Enterprise is suitable for confidential and regulated work. On consumer plans, no. Claude’s consumer accounts are not HIPAA compliant and carry no contractual data protection. Team plans sit between the two. For truly confidential data, Enterprise is the only appropriate option, combined with staff training and governance. Isolation of tasks prevents tampering with local computer networks when using Claude Code.
The team plan, by comparison, offers standard seats and premium seats at fixed rates billed annually or monthly with a minimum of five seats, giving you more predictable budgeting.
Yes. On consumer plans, go to Settings, then Privacy, and toggle “Help improve Claude” to OFF. This prevents your future conversations from being used for training. You can also delete individual chats. Enterprise plans do not train on your data by default, so there is nothing to opt out of. The training consent toggle on consumer accounts gives you control, but only if every user in your organisation knows to use it.The training consent toggle on consumer accounts gives you control, but only if every user in your organisation knows to use it.
Claude Code is a feature designed for developers and technical users. It allows you to write, debug, and run code within Claude. On Enterprise plans, Claude Code can be configured to use Zero Data Retention, meaning that your code and related data are not stored after processing. This provides an additional layer of privacy and security for sensitive development work. However, on consumer accounts, data entered through Claude Code may be used for model training if the training toggle is enabled.
Consumer accounts include Claude Free, Pro, and Max plans. These are intended for individual users rather than businesses. By default, these accounts have data training enabled, meaning conversation data and inputs may be used to improve Claude’s models and retained for up to five years if users do not opt out. There is no contractual data protection or Data Processing Agreement (DPA) with Anthropic for these accounts, making them unsuitable for confidential or regulated business data.
Anthropic’s Claude AI Privacy Policy outlines how data is collected, used, and retained across different account types. It specifies the data retention periods, the purposes for which data is processed, and the controls available to users, including the training consent toggle. The policy also describes security measures such as encryption and access controls. The Privacy Policy is a key document governing all Claude users and is regularly updated to reflect changes in data handling practices.
The Consumer Terms of Service apply to Free, Pro, and Team accounts. These terms grant Anthropic permission to use conversation data for training by default unless users opt out. They also set out user rights, obligations, and acceptable use policies. Accepting these terms is mandatory to continue using Claude on consumer plans after the September 2025 update. Businesses using consumer accounts should be aware that these terms do not provide enterprise-grade data protection.
Enterprise accounts offer the highest level of data privacy and security. Data is never used for training models regardless of user settings, and Zero Data Retention can be enabled for eligible features. Enterprise plans include Data Processing Agreements for GDPR compliance, configurable retention policies, and options for HIPAA compliance through Business Associate Agreements. These accounts are suitable for handling sensitive, confidential, or regulated business data.
Claude’s Privacy Policy is a comprehensive document that governs data collection, usage, retention, and user rights. It applies to all account types but operates differently depending on whether the account is consumer or enterprise. The policy includes details on data encryption, international transfers, employee access, and user controls such as the training consent toggle. It is essential reading for understanding how Claude protects your information and what controls you have available.
This website uses cookies to improve your experience. Choose what you're happy with.
Required for the site to function and can't be switched off.
Help us improve the website. Turn on if you agree.
Used for ads and personalisation. Turn on if you agree.