Skip to content
Adrythm

Using AI in your business

Is it safe to put customer information into ChatGPT or Claude?

Updated October 4, 2026

Yes, it is safe on a business plan or the API, if staff know what to leave out. ChatGPT Business and Enterprise, Claude Team and Enterprise, and both APIs do not train on customer information by default. Personal Free, Go, Plus, Pro and Max accounts can, unless training is off. Card numbers, Social Security numbers and passwords never go in.

If staff will paste customer details, put them on a business plan or the API

If your team will paste customer names, addresses, job notes or invoices into an AI chat, give them seats on a business plan or build on the API. Do not let each person use a personal account. The plan decides whether customer details can train the vendor's models, and who can read them later.

Both vendors draw the same line. OpenAI's enterprise privacy page (updated January 8, 2026) says of ChatGPT Business, Enterprise and the API Platform: "We do not train our models on your data by default." Anthropic's commercial privacy article (August 18, 2026) says: "By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models." Claude for Work is Anthropic's name for its Team and Enterprise plans.

Personal plans work the other way round. For ChatGPT and its other services for individuals, OpenAI says "we may use your content to train our models" unless you opt out. Since announcing new consumer terms on August 28, 2025, Anthropic has asked every Claude Free, Pro and Max user to choose, and the choice can be changed later.

Not for customer data

Personal plans
ChatGPT Free, Go, Plus and Pro. Claude Free, Pro and Max. Chats can be used for training while the setting is on, and they sit in an account you do not control.
If someone already uses one for work, switch training off today and move them over.

The default answer

Business plans
ChatGPT Business and Enterprise. Claude Team and Enterprise. No training by default, and an owner or admin controls members, connected apps and, on some plans, retention.
Right for an office where several people paste customer details every day.

For built tools

The API
OpenAI's API Platform and the Anthropic API. No training by default, and inputs and outputs are deleted after about 30 days unless a feature, an agreement or the law keeps them longer.
Right when a developer builds a tool, such as a quote writer, that sends job data automatically.

For example

An office manager at a four-person electrical company pastes last week's 40 job notes, with names and street addresses, into her personal ChatGPT Plus account to draft follow-up emails. With Improve the model for everyone on, those chats can be used for training. The same work in a ChatGPT Business workspace is not used for training by default, and the owner can see and delete it if she leaves.

If anyone uses a personal account for work, switch training off today

If someone already uses a personal ChatGPT or Claude account for work, have them turn training off before the next chat. It takes a minute and only changes what happens from then on.

  1. ChatGPT on the web: open the account menu, select Settings, then Data controls, turn off Improve the model for everyone and select Done. On the iPhone or Android app, open the sidebar, tap your profile icon, then Data controls. Signed in, the choice follows the account to every device.
  2. Claude on the web or desktop: select your name, then Settings, then Privacy, and switch off the toggle Anthropic's help page calls Help Improve our AI models. The mobile app uses the same path.
  3. For a one-off sensitive chat: use Temporary Chat in ChatGPT or an incognito chat in Claude (the ghost icon at the top right of a new chat). Neither is used for training, and both vendors may still keep a copy for up to 30 days.

The switch looks forward, not back. OpenAI says that once you opt out, "new conversations will not be used to train our models." Anthropic says it will stop using earlier chats in future training, but "your data will still be included in model training runs that are already in progress, or in models that have been trained."

It does not delete anything. OpenAI's data controls page answers "Does turning off model training delete my chats?" with "No." Delete chats separately.

What happens to a chat after it is sent

If you delete a chat, count on about 30 days, not instantly

Plan as if a deleted chat stays on the vendor's systems for up to 30 days, longer if the law requires. Both vendors hide it from you at once and erase it later.

Claude with training on

5 years

The longest Anthropic says it may keep de-identified chats in its training pipelines when a personal account allows training.

  • ChatGPT, personal plans. Saved chats stay "until you delete them." A deleted chat is scheduled for permanent deletion "within 30 days, unless the chat was already de-identified and disassociated from your account or OpenAI must retain it longer for security or legal obligations." Archiving changes neither retention nor training.
  • ChatGPT Business. Workspace admins can set how long data is kept. Deleted or unsaved conversations go within 30 days "unless longer retention is required by law, or is reasonably necessary to protect our services or any third party from harm."
  • Claude, personal plans. A deleted chat is "Deleted from our back-end storage systems within 30 days." With training on, Anthropic "may retain your data in a de-identified format for up to 5 years in our model training pipelines," for chats started or resumed after the setting was turned on. With it off, the 30-day period applies.
  • Claude Team and Enterprise. Anthropic keeps chats in the product, and a deleted chat goes from the back end within 30 days. Enterprise owners can set a retention period of at least 30 days under Organization settings, Data and Privacy; without one, Anthropic says data "is retained indefinitely."
  • The APIs. OpenAI keeps abuse monitoring logs "for up to 30 days" by default, and some endpoints keep conversation data until deleted. Anthropic deletes API inputs and outputs "within 30 days of receipt or generation," except where a feature you use keeps them longer, a zero data retention agreement applies, or the law or its usage policy requires more.

Flagged chats are kept longer. Anthropic keeps inputs and outputs "for up to 2 years" when its automated systems flag a chat as breaking its usage policy, and classification scores for up to 7 years.

What the 2025 court order meant for deleted ChatGPT chats

In 2025, a court order in The New York Times' lawsuit made OpenAI keep consumer ChatGPT and API content, deleted chats included. OpenAI said it covered ChatGPT Free, Plus, Pro and Team and API use without a zero data retention agreement, but not Enterprise or Edu.

OpenAI's update of October 22, 2025 says its obligations "ended on September 26, 2025" and deleted chats are again removed within 30 days. It still keeps "limited historical" user data from April to September 2025, locked to a small legal and security team. The point for an owner: the 30-day promises carry a legal exception, and in 2025 it was used.

If staff click thumbs up or down, the whole conversation can go to training

Tell staff not to rate replies in any chat that holds customer details. Rating sends the conversation to the vendor as feedback, and both vendors document that feedback can be used for training even where chats otherwise are not.

OpenAI's data controls page says that after selecting thumbs up or thumbs down, "the entire conversation associated with that feedback may be used to train OpenAI models," even if you opted out. Anthropic's commercial article says that if you "explicitly report feedback or bugs to us (e.g. via our thumbs up/down feedback button)" it may use those chats to train, and it stores "the entire related conversation" for up to 5 years.

On Claude Team and Enterprise, an owner can switch rating off. The Rate chats setting sits under Organization settings, Data and Privacy, and stops members sending thumbs feedback to Anthropic.

If you are on a business plan, tell staff the owner can read their chats

Tell staff that chats in a company workspace belong to the company and are not private. That is the point: customer work stays where the owner can see and delete it.

OpenAI says ChatGPT Business "workspace admins have control over workspaces and can view, access, export, and delete end user conversations in the workspace." Anthropic says that on Team and Enterprise plans, even incognito chats "are included in organizational data exports available to account Owners."

The vendors can see some of it too. OpenAI limits access to Business chats to its staff for engineering support, abuse checks and legal compliance, and to contractors who review for abuse. For personal accounts its help center adds a line worth printing: "Please do not enter sensitive information that you would not want reviewed or used."

Connectors reach further than a pasted note

If you connect email, files or a CRM, start with read-only access

Connect only the apps a task needs, and set each one to read-only or ask-first until you trust it. A connector lets the assistant pull in customer records nobody pasted, and on some apps act on them.

Anthropic says connectors let Claude "access your apps and services, retrieve your data, and take actions within connected services," with each person's own permissions. Its warning: "you're granting Claude permission to access and potentially modify data within that service." OpenAI says its connected apps can "take supported actions in the connected service," and lists an Allow all actions permission that "carries elevated risk because supported actions may run without another confirmation."

  • ChatGPT Business. OpenAI says "many apps are enabled by default." Admins can change that, so check the list before staff connect a mailbox.
  • Claude Team and Enterprise. An owner has to enable a connector for the organization first, and normally each person then signs in to it. Owners can mark each tool Always allow, Needs approval or Blocked, for example letting Claude summarize email but not send it.
  • Training. On business plans, neither vendor trains on connector data by default. On personal ChatGPT plans, OpenAI "may use information accessed from apps to train our models" while training is on. On personal Claude plans, raw connector content is left out of training, but anything copied into the chat is not.
  • The other company. OpenAI says "Data shared with apps is handled according to each app's terms of service and privacy policies." An app maker is a separate business with its own rules, so read its policy before connecting it to customer records.

What never goes in, and the policy to hand staff

Never paste card numbers, Social Security numbers, bank details or passwords

Keep card numbers, Social Security numbers, bank account numbers and passwords out of every AI chat, on every plan. A business plan changes who can use the data, not the fact that a copy now sits on another company's servers.

Anthropic's help center asks people to be careful with "Financial information (SSN, credit card numbers, bank account details)", "Health records or medical information" and "Passwords or private login credentials."

Card data has its own rules. The PCI Security Standards Council's guide for small merchants (April 2024) puts it in capitals: "IF YOU DON'T NEED CARD DATA, DON'T STORE IT." A card number that arrives by email should be processed and the email deleted. A card number in a chat history is the same problem.

The FTC says the same about the rest. Its guide for businesses says to use Social Security numbers "only for required and lawful purposes" and to "Keep only what you need for your business." A job note needs the address and the problem. It does not need the card on file.

Do privacy laws apply to a small service business using AI?

Often not the big ones, but check. California's Attorney General lists three tests for the CCPA. A business is covered if it has gross annual revenue over $25 million (raised for inflation to $26,625,000 from January 1, 2025, per the California Privacy Protection Agency), buys, sells or shares the personal information of 100,000 or more California residents or households, or earns half or more of its revenue from selling it. A covered business must handle delete requests, with exceptions, and tell its service providers to delete too.

The FTC Safeguards Rule covers "financial institutions," a term the FTC says is broader than everyday speech and turns on what a business does. A business that finances its own jobs should check the definition. A covered business must pick service providers that can protect customer data and write security expectations into their contracts. An AI vendor that processes customer data can fit that definition of a service provider.

Hand staff this policy

Print this and have each person read it before they get a seat. It is a starting point built on the vendor behaviour above, not legal advice.

  • Company accounts only.

    Customer details go only into the company's ChatGPT Business or Claude Team workspace, signed in with your work login. Never into a personal account.

  • Never paste:

    card numbers, Social Security numbers, bank details, passwords, gate or lockbox codes, or health details.

  • Paste the minimum.

    Use a first name or job number in place of a full name and address when the task does not need them.

  • No ratings.

    Do not click thumbs up or down in a chat that holds customer details.

  • Ask before connecting.

    Do not connect email, files, the CRM or the calendar without the owner's OK.

  • Check the output.

    Read every reply before it reaches a customer, and check prices, dates and names against the job.

  • Assume it is visible.

    The owner can read and export company chats, and deleted chats can sit with the vendor for about 30 days.

  • Report mistakes.

    If something sensitive goes in, tell the owner that day so the chat can be deleted.

Still have a question this page did not answer?

Ask it on a call. Twenty minutes, a straight answer, and no follow-up sequence if you decide not to work with us.