Short version: on a business plan with training turned off, it's usually reasonable for ordinary business data: a customer's name, a job address, what they ordered. On ChatGPT Business and Enterprise, Claude's Team and Enterprise plans, Gemini through Google Workspace, and Copilot with a work account, the vendor says it doesn't train its models on your chats by default. Personal accounts can work differently. And some data shouldn't go into any general chat tool at all: card numbers, Social Security numbers, and passwords, plus patient health information unless your practice has a Business Associate Agreement that covers that specific tool.
Below is what each vendor says on its own pages as of October 2026, what never to paste, and a five-rule policy you can hand your staff. These policies change often. Every claim links to the vendor's page, so check the link before you rely on it.
"Safe" is really three questions
- Training: can the vendor use what you type to improve its models? This is the one people worry about, and it's the easiest to control.
- Retention: how long does the vendor keep your chats, including the ones you deleted?
- Human review: can someone at the vendor read them, and when?
Turning off training answers the first question only. Your chats are still stored for a while, and OpenAI, Anthropic, and Google each describe cases where they review conversations or keep them longer, such as suspected abuse or legal requirements. That's why a few kinds of data stay out entirely, whatever the settings say.
What the four big assistants say, as of October 2026
ChatGPT (OpenAI)
On personal accounts, OpenAI says it may use your conversations to train its models. You can opt out by turning off "Improve the model for everyone" under Settings › Data controls. Temporary chats aren't used for training, though OpenAI may keep a copy for up to 30 days, and deleted chats are scheduled for permanent deletion within 30 days unless OpenAI has to keep them for security or legal reasons.
On ChatGPT Business, ChatGPT Enterprise, and the API, OpenAI doesn't train on your data by default. On Business, your workspace admin controls how long chats are kept. API inputs and outputs may be retained for up to 30 days to provide the service and spot abuse.
Claude (Anthropic)
On Claude's Free, Pro, and Max plans, Anthropic uses your chats for training if you choose to allow it through a model-improvement toggle under Settings › Privacy, or if a chat is flagged for safety review. If you allow it, Anthropic may keep de-identified data for up to five years. A chat you delete is removed from Anthropic's back-end storage within 30 days and won't be used to train future models, and Incognito chats aren't used for training at all.
On Claude's business plans and the API, Anthropic doesn't use your inputs or outputs for training by default. API inputs and outputs are deleted within 30 days, with exceptions such as usage-policy enforcement and legal requirements.
Gemini (Google)
In the personal Gemini app, Google's Keep Activity setting is on by default if you're 18 or over. While it's on, Google uses your activity to improve its AI models, and human reviewers read a subset of chats. Reviewed chats are kept for up to three years, even if you delete your activity, and Google's own privacy notice asks you not to enter confidential information you wouldn't want a reviewer to see. Turning Keep Activity off stops your future chats from being used for training unless you send feedback, though Google still holds them for up to 72 hours.
With a Google Workspace business account, Google says your content isn't reviewed by humans or used to train AI models outside your organization without your permission, and your admin decides how long Gemini chats are kept.
Copilot (Microsoft)
Signed in with a work or school account, Copilot falls under Microsoft's enterprise data protection, and Microsoft says prompts, responses, and the company data Copilot reads aren't used to train its foundation models. For personal Microsoft accounts, Microsoft says that in the updated Copilot app it released in August 2026, prompts, responses, and file contents aren't used to train foundation models; the older version of the app has a training opt-out instead. If you use the personal app without a Microsoft 365 subscription, you may see ads, and personalized ads can draw on your chat history unless you turn ad personalization off.
The button to leave alone
The thumbs-up and thumbs-down buttons are the exception people miss. OpenAI says that when you rate a response, the whole conversation may be used for training even if you've opted out. Anthropic stores the whole related conversation for up to five years when you send feedback, on business plans too, though an owner of a Team or Enterprise plan can switch the rating buttons off for everyone. Google says feedback from the personal Gemini app can include the last 24 hours of your chats. If a chat has customer data in it, don't rate it.
What never goes into a general chat tool
- Card numbers and bank account numbers. No drafting or summarizing job needs them, and a chat history is one more place they could leak.
- Social Security, driver's license, and passport numbers. If a document has them, black them out before you upload it.
- Passwords, API keys, and login codes. That includes the ones visible in a screenshot you're asking for help with.
- Patient health information, unless your practice has a Business Associate Agreement that covers that specific tool (more below).
- Anything a client contract says stays private. Read the confidentiality clause before you paste. If it limits sharing with outside parties, an AI vendor may count. When in doubt, ask the client or leave it out.
Patient information and the BAA question
If you're a HIPAA-covered practice, or you handle patient information for one, OpenAI, Anthropic, and Google each say in their own words that patient information needs a signed business associate agreement (BAA) first. As of October 2026:
- OpenAI doesn't offer a BAA for ChatGPT Business. It offers BAAs for the API, reviewed case by case, and for ChatGPT Enterprise or Edu customers with a sales-managed account, and keeps a separate list of its HIPAA-eligible products.
- Anthropic offers a BAA for its API and Enterprise plans. Team plans and individual plans can't enable HIPAA.
- Google lists the Gemini app and Gemini in Workspace as covered under the Workspace HIPAA business associate amendment, which your Workspace administrator has to accept before anyone uses patient information. Gemini in Chrome isn't covered.
- Microsoft says Copilot with a work account supports HIPAA compliance when it's properly configured, but the web searches Copilot runs aren't covered by its BAA.
Even with a BAA in place, not every feature is covered; each vendor publishes exclusions. A BAA is where the conversation with your compliance advisor starts, not where it ends.
A five-rule AI policy for your office
Copy this, change what doesn't fit, and walk your staff through it:
- Use the company account, not a personal one. Work goes into the business plan the company pays for, where training is off by default and the business, not the employee, controls the account.
- Never paste the list. Card numbers, bank numbers, Social Security numbers, passwords, and API keys never go into an AI chat. Patient health information never goes into a general AI tool unless the practice has a Business Associate Agreement that covers that specific tool. If a document contains any of these, black them out first.
- Share only what the task needs. To draft a reply, the AI needs the question. It doesn't need the customer's phone number, address, and account history.
- A person reads it before it leaves. Nothing AI-written goes to a customer, vendor, or employee until someone has read all of it. Whoever sends it owns it.
- No ratings on customer chats, and ask when unsure. Don't press thumbs up or down on a conversation that contains customer information. If you're not sure whether something can go in, ask the owner before you paste it.
How custom software handles it differently
A chat window sends whatever you paste into it. Software built for one job can be stricter, because the software decides what the AI sees, not the person at the keyboard. When we build AI into a client's software:
- We send the AI only what the job needs and keep sensitive details out where the job allows. A receipt reader sends the receipt; the customer record stays in your database. Free-Lance, a tool I built for freelance production crew, for example, redacts documents before sending and refuses tax forms.
- Designated sensitive fields are encrypted at rest.
- AI calls go through a business API account we hold for your software, never a personal login. On Anthropic's API, per the policies above, that means no training on your data by default and deletion within 30 days.
- A person approves the paperwork and anything touching money. The AI reads and drafts, someone checks it, and the software does the math. A few small steps run on their own and are logged, such as sorting bug reports, or reading a crew member's off-script reply to a booking text and sending a short answer, with anything unclear going to a person.
We walk through that pattern with real examples in AI reads the paperwork, you approve it, and the 12 jobs AI can do for a small business show where it fits day to day. For the wider picture, see our practical guide to AI for small business.
If you run a medical, legal, or financial practice, run your AI policy past your compliance advisor before you roll it out.
Frequently asked questions
Does ChatGPT train on what I type?
On personal accounts, OpenAI says it may, unless you turn off "Improve the model for everyone" in your data controls settings. On ChatGPT Business, ChatGPT Enterprise, and the API, OpenAI says it doesn't train on your data by default. That's as of October 2026, so check OpenAI's help page before relying on it.
Can I put patient information into Claude on a Team plan?
No. As of October 2026, Anthropic says Team plans and individual plans can't enable HIPAA. Its business associate agreement covers the API and Enterprise plans, and only for the features it lists.
Is turning off training enough to make it safe?
It's the most important setting, but not the only one. Vendors still store chats for a period, can review conversations flagged for abuse, and on several services rating a response with thumbs up or down can send that conversation for training anyway. Card numbers, Social Security numbers, and passwords should stay out regardless.
What's the simplest safe setup for a small office?
One business plan for the whole team from the vendor you already use, an owner or manager as the admin, a short written policy like the five rules above, and a walkthrough so everyone knows what never gets pasted.
Does AI in custom software send my whole customer list to the AI company?
It shouldn't. We send the AI only what the job needs and keep sensitive details out where the job allows — Free-Lance, for example, redacts documents before sending and refuses tax forms. The calls go through a business API account we hold for your software, never a personal login, where the vendor doesn't train on the data by default. Ask any developer exactly what gets sent, and get the answer in writing.