A detailed look at how major AI services handle user data, separating training from storage and highlighting best practices for protecting sensitive information in AI interactions.
The central question in any AI privacy policy is not whether a company trains its models on your material, but whether it keeps the material at all. Those are separate promises, and they have different consequences for anyone pasting sensitive text into a chatbot, enterprise tool or API. OpenAI’s policies, for example, distinguish between training use, retention limits and temporary chat features, while Anthropic’s documentation sets out a 30-day retention window for certain covered models.
That distinction matters because turning off training does not undo earlier use, and it does not necessarily stop a company from holding your data for a period of time for safety, legal or operational reasons. OpenAI says personal data is kept only as long as needed to provide services or satisfy business and legal obligations, and that deleted conversations or accounts are removed from systems within 30 days unless retention is required for another purpose. Anthropic says prompts and outputs for covered models are retained for 30 days to support safety work.
The practical advice is to check the policy, not the marketing page. Users should look for the words training, retention, human review, service provider and delete, because these terms usually reveal far more than a product banner does. OpenAI’s API data-use policy says users can opt out of training through the privacy portal, but also notes that feedback can still be used for model improvement; its ChatGPT guidance says Temporary Chat is not stored or used for training.
For people who handle client files, medical notes or business plans, the safest rule is to redact before pasting. Replace names, account numbers, addresses and other identifiers with placeholders, and assume anything entered into a general-purpose AI service could be reviewed by a human under some circumstances. Anthropic and OpenAI both describe safety and policy-enforcement processes that can involve internal handling of user interactions, even where the material is not used for training.
The same caution applies in the workplace, where AI tools are often governed by company accounts and administrative controls. OpenAI’s business-facing materials say customer data is not used for training by default, but enterprise use still sits within a managed environment with its own rules. That means workers should not assume a work chatbot is private in the way a personal account might be, and companies should set a clear policy before staff begin using AI widely.
For users in the UK and the EU, deletion and access rights still matter, but they are not absolute. A service may remove personal data from its systems while keeping some records for legal, security or fraud-prevention reasons, and neither deletion nor export reaches information already absorbed into a model. The result is a simple rule: if the information would be costly to expose, do not rely on settings after the fact; decide before sending it.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





