In plain English

What happened
Yes, as long as you decide it instead of letting the default decide for you. Every major vendor trains on personal-plan conversations unless you turn it off, and none of them train on business plans by default. OpenAI's own words: on personal ChatGPT accounts it may use your content to train, while for Business, Enterprise and the API it does not by default. Anthropic and Google draw the same line. Meta now charges for the difference: $1.25 versus $0.10 per million tokens, and the cheap tier is the one that trains.
Why it matters to your business
Most small businesses adopted AI one free account at a time, which means most are on the personal plans where training is on unless someone turned it off. That is fine for a draft social post. It is not fine for a client list, unreleased pricing, or anything you signed a confidentiality agreement about. The fix is three settings and one rule, and it takes an afternoon.
Do this
Today: open the data setting on every AI account your business uses and turn training off. This week: move whoever pastes customer information onto a business plan. Then write the one-line rule for what never goes in, and tell the people who paste.

Turn it off: where the switch is on each tool

  1. 1

    ChatGPT (Free, Go, Plus, Pro)

    Settings, then Data Controls, then turn off "Improve the model for everyone." OpenAI says after you opt out it [will not train](https://help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance) on new conversations. For a one-off sensitive item, Temporary Chat is also documented as [not used for training](https://help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance).

  2. 2

    Claude (Free, Pro, Max)

    Privacy Settings, then the model-training choice. Say no. Anthropic says declining keeps the [30-day retention](https://www.anthropic.com/news/updates-to-our-consumer-terms) period, while saying yes extends retention to five years. Team, Enterprise and API use are [not covered](https://www.anthropic.com/news/updates-to-our-consumer-terms) by this at all; they run under commercial terms that do not train.

  3. 3

    Gemini

    Turn off Keep Activity. Google's own page asks you not to enter confidential information you would not want [a reviewer to see](https://support.google.com/gemini/answer/13594961), and notes that temporary chats are kept [72 hours](https://support.google.com/gemini/answer/13594961) and not used for training.

  4. 4

    Move the people who paste customer data onto a business plan

    ChatGPT Business, ChatGPT Enterprise and the OpenAI API are [opted out by default](https://help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance); OpenAI's enterprise page states it [does not train](https://openai.com/enterprise-privacy/) on that data. Claude Team and Enterprise are the same. If one person in your shop handles client files, that seat is the one to upgrade. It ends the question.

  5. 5

    Redact before you paste, on any plan

    Swap the client's name for "the client," the dollar figure for "[price]," the address for "[address]." The model does the same work on the redacted version. Two minutes, and it removes most of the exposure regardless of which plan or setting you are on.

  6. 6

    Write the one-line rule and put it where people paste

    "Client names, unreleased pricing, employee matters and anything under NDA never go into a personal AI account." That sentence is the policy. Tape it to the monitor if you have to.

Three settings, one plan change, one rule. After that, the only information a model can train on is information you decided it could.

Why the default is the problem

The vendors are not hiding any of this; it is on a settings page nobody opened. OpenAI's help center says plainly that on personal accounts it may use your content to train its models. Anthropic made it an explicit choice, and attached a cost to saying yes: retention goes from 30 days to five years. Google's Gemini page tells you in so many words not to enter confidential information.

Meta made the trade visible in dollars. Its Muse Spark model has two prices for the same thing: a standard tier at $1.25 per million input tokens that is not used to improve Meta's products, and a contributor tier at $0.10 that is. Same model. The discount is your data.

What is safe to paste anyway

Once training is off and the sensitive slice is out, the rest of your work carries no real exposure even on a personal plan: a draft of a public post, a reformatted spreadsheet, a brainstorm about a headline, a rewrite of your own website copy. If a model somewhere learned from that, nothing was lost. Draw the line through your information, not through your tools, and most of what you do lands on the safe side of it.

Reality check

Turning off training is not the same as the vendor not keeping your data. Anthropic's 30-day retention still applies when you decline, Google keeps temporary chats for 72 hours, and every provider retains something for safety and abuse review. "Not trained on" is the right bar for most businesses. If your bar is "never stored at all," that is a different product, usually called zero data retention, and it is a conversation with the vendor, not a settings page.

So the honest answer is yes, it is safe, provided you make it safe. The switches exist, the business plans exist, and the vendors have written down which is which. Flip the settings today, upgrade the one seat that handles client data, and write the one line. That is the whole job.

Sources

  1. 1.OpenAI Help — How your data is used to improve model performance
  2. 2.OpenAI — Enterprise privacy
  3. 3.Anthropic — Updates to our consumer terms (training choice, retention)
  4. 4.Google — Gemini Apps Privacy Hub
  5. 5.Meta for Developers — Meta Model API pricing (Muse Spark standard vs contributor tier)