BLOG
Terms of Use to Check Before Using ChatGPT and Claude at Work

"We're rolling out ChatGPT across the company. But we don't know whether what we type in will be used for training, and the IT department has put it on hold."
"We want to use Claude, but legal asked us, 'Have you checked the terms?' Where should we even look?"
"I can't explain the difference between the free plan, the paid plan, and the business plan."
When companies consult us about rolling out generative AI internally, this is usually where they first stumble. What stops them is not the technology but the lack of a shared understanding of the terms.
This article sets out the points to check before using ChatGPT (OpenAI) and Claude (Anthropic) for work, relying only on what is written in each company's official terms.
The content of this article reflects the official pages as checked on September 9, 2026. Terms get revised. Base actual decisions on the latest terms at the time and on review by your own legal department. This article is not legal advice.
1. Is the Data You Enter Used for Training?
This is the most common question. The answer differs by plan.
Individual Plans
OpenAI's Terms of Use say the following about how content is used.
We may use Content to provide, maintain, develop, and improve our Services, comply with applicable law, enforce our terms and policies, and keep our Services safe. (OpenAI Terms of use)
The terms then state explicitly that you can opt out if you do not want your content used for training.
Opt out. If you do not want us to use your Content to train our models, you can opt out by following the instructions in this article. (Ibid.; for the steps, see How your data is used to improve model performance)
Anthropic's consumer terms contain a statement with the same structure.
We may use Materials to provide, maintain, and improve the Services and to develop other products and services, including training our models, unless you opt out of training through your account settings. (Anthropic Consumer Terms of Service)
So on individual plans, both companies are set up so that your data may be used for training by default, and you opt out through your settings.
Business Plans
OpenAI clearly rules it out for business plans and the API.
We don't train our models on your organization's data by default. By default, we do not use data from ChatGPT Enterprise, ChatGPT Business, ChatGPT Edu, ChatGPT for Healthcare, ChatGPT for Teachers, or our API platform—including inputs or outputs—for training or improving our models. (OpenAI Enterprise privacy)
Anthropic's commercial terms go a step further.
Anthropic may not train models on Customer Content from Services. (Anthropic Commercial Terms of Service)
"Not by default" (OpenAI) and "may not" (Anthropic) differ in the strength of their wording. When you explain this internally, conveying that difference accurately helps prevent misunderstandings later.
2. Opting Out Has Exceptions
This point is easy to overlook. Anthropic's consumer terms state explicitly the cases in which your data is used for training even if you opt out.
Even if you opt out, we will use Materials for model training when: (1) you provide Feedback to us regarding any Materials, or (2) your Materials are flagged for safety review to improve our ability to detect harmful content, enforce our policies, or advance our safety research. (Anthropic Consumer Terms of Service)
In other words, sending a rating (feedback) on a response, and being flagged for safety review, both fall outside the opt-out.
When you write internal rules, it is safer not to say "We have opted out, so anything can be entered."
3. A Commonly Overlooked Pitfall: Signing Up with a Company Email Does Not Make It a Business Contract
This is the most dangerous misunderstanding in practice.
Even if you create an account with an email address on your company's domain, the contract remains an individual one. It is not unusual for people to assume that an individual plan they simply signed up for with a company email is a business contract.
What makes it confusing is that an organization name appears in the admin screen even on individual plans. At Anthropic, for example, individual-plan users are automatically assigned an organization name such as "(email address)'s Organization," and the user is treated as that organization's administrator. On screen it looks like a business contract, but the terms that apply are still the consumer terms.
What you need to check is not how the screen looks but the type of contract.
| What to check | Individual contract | Business contract |
|---|---|---|
| Applicable terms | Consumer terms | Commercial terms |
| Use for training | Included by default; turned off in settings | Not included |
| Seat management | No | Yes |
| Organization name | Auto-generated (e.g., "...'s Organization") | Actual organization name |
| Payment | Personal credit card, etc. | Invoiced under the business contract |
Coding Assistants Are Treated the Same Way
This is the part that is easy to miss. Anthropic's Privacy Center clearly separates how Claude Code is treated by plan type.
This article is about our consumer products such as Claude Free, Pro, Max and when accounts from those plans use Claude Code. (How long do you store my data?)
Meanwhile, the help article on the commercial side says this.
This article is about certain commercial products, including the Anthropic Messages API and Claude Code on Enterprise plans. (I have a zero data retention agreement with Anthropic. What products does it apply to?)
So the same tool is treated as a consumer product when used on an individual plan and as a commercial product when used on a business plan. Because development tools handle your own source code, the impact is far greater than with chat.
If Used for Training, Data Is Kept for Up to 5 Years
The retention period when you allow training use on a consumer plan is also stated explicitly.
If you allow us to use your chats or coding sessions to improve Claude, we may retain your data in a de-identified format for up to 5 years in our model training pipelines. (Ibid.)
Turning the setting off later does not completely erase the data retroactively.
If you decide to turn off the model improvement setting, we will not use your previous or new chats or coding sessions for future model training. ... Your data will still be included in model training runs that are already in progress, or in models that have been trained. (Ibid.)
It is worth making sure everyone in your company understands that turning the setting off once you notice does not undo what has already happened.
For Work, Personal Accounts Should Be Prohibited
Based on these facts, we recommend the following policy.
Limit the use of generative AI that handles business data to accounts under a business contract, and explicitly prohibit work use of personal accounts.
There are four reasons.
- Different terms apply. Individual contracts fall under the consumer terms, where training use is included by default. Any practice that depends on settings breaks down as soon as the person in charge changes.
- The company cannot see it. Administrators cannot see how personal accounts are being used. There is no way to check who entered what, and the account cannot be recovered when an employee leaves.
- Settings are left to individuals. The company has no way to confirm whether someone has opted out. Even when a person uses it in good faith, a single setting changes how the data is handled.
- It cannot be undone retroactively. Data already used for training is not removed from training already in progress, even if the setting is turned off.
A ban alone leaves staff stuck, so it has to come with a business-contract alternative at the same time. A ban without an approved environment to use actually increases unmanaged use.
4. What Happens Inside the AI Company When Data Is Used for Training
When people hear "used for training," many imagine that the text they entered is stored as is, read by employees, and served up verbatim in answers to other users. First, we look at the general mechanism, which is not specific to any one service, and then at what the two companies officially state.
First, the General Processing Flow
This is the general mechanism for using a cloud-based AI through an API, not limited to ChatGPT or Claude. Details vary with each provider's implementation and contract terms, but the basic structure is largely the same. As an example, consider sending an internal document to an API to have it proofread or summarized.
| Stage | What happens | Where the data is |
|---|---|---|
| 1. Sending the request (your company → AI provider) | The document text and the instructions (prompt) are bundled into one request, encrypted in transit (TLS), and sent to the provider's API | In your system's memory. If you have configured logging on your side, also on your own servers or databases |
| 2. Authentication and preprocessing (API gateway) | The API key or token is checked to confirm a legitimate user, and usage limits are checked. The content is run through a filter that automatically flags harmful content | In the provider's gateway memory (temporarily) |
| 3. Inference (AI model environment) | The document and instructions are converted into the units the model works with (tokens), and the proofreading, summarizing, or rewriting is processed on hardware such as GPUs | In the inference server's memory. Released from memory when processing ends |
| 4. Returning the response (AI provider → your company) | The generated text returns to your app over an encrypted connection, and the document is updated | In your application or storage |
| 5. Storing monitoring logs and automatic deletion (provider storage) | Inputs and outputs are stored for a set period to detect policy violations and analyze failures, then deleted when the period expires | In isolated, encrypted storage on the provider side (typically a combination of object storage and a key management service) |
Three points in this flow are worth noting.
- The model does not learn while processing a request. Inference in step 3 is "computation," and the model's contents (its parameters) do not change during it. Training is a separate process (batch processing) in which data stored in step 5, or collected separately, is later gathered into a training dataset and the model is rebuilt. So whether "inputs are used for training" is decided not by this flow itself but by whether the data stored in step 5 is passed on to the training process. That is decided by the contract and settings. The commitment we saw in Section 1 that "business plans are not used for training" is a promise not to make that handoff.
- Data remains on the provider side only in step 5. The data in steps 1 to 4 disappears when processing ends. What stays on the provider side for a period is what is stored as monitoring logs in step 5. That retention period, and who can access the data during it, are what the official statements covered in the second half of this section describe.
- Storage on your side is your responsibility. Whatever remains in your own logs or storage in steps 1 and 4 is yours to manage, regardless of the AI provider's terms. "The AI provider deletes it in 30 days" and "it stays in our own logs" are separate matters.
The above describes the general mechanism; how each company actually implements it has to be checked on its official pages. From here on, we look at what the two companies officially say they do when data stored in step 5 is passed to the training process.
Unlinking from the Account Before Training
Anthropic describes removing the link to the user ID and filtering sensitive information before data is used for training.
Where you have allowed us to use your chats and coding sessions to improve Claude, we will automatically de-link them from your user ID (e.g. email address) before it's used by Anthropic. (How Do You Use Personal Data in Model Training?)
We will use tools and processes derived from our work on privacy-preserving analysis tools to filter or obfuscate sensitive data. (Ibid.)
OpenAI also says it takes steps to reduce the personal information contained in training data.
We retain certain data from your interactions with us, but we take steps to reduce the amount of personal information in our training datasets before they are used to improve and train our models. (How your data is used to improve model performance)
Our models are built to learn about the world, not about private individuals. We don't seek out personal information, we don't build profiles from public data, and we work to identify and remove personal identifiers from training sets wherever possible. (OpenAI Consumer privacy)
Both companies explain that they separate data from "whose input it was" and reduce personally identifying information before using it for training. However, what they describe is processing of personal information. Within what we checked, we found no statement about removing trade secrets such as unpublished business plans, customer lists, or source code.
The Whole Conversation Goes into Training; Raw Data from Connected Services Does Not
Anthropic states specifically what is used for training.
Chat and coding session data we may use for improving our models includes the entire related conversation, along with any content, custom styles or conversation preferences, as well as data collected when using Claude for Chrome. It does not include raw content from connectors (e.g. Google Drive), including remote and local MCP servers, though data may be included if it's directly copied into your conversation with Claude. (Is my data used for model training?)
In other words, simply connecting a service such as Google Drive does not put the original files into training, but they become subject to training once pasted into the conversation. This gives you a basis if your internal rules draw a line such as "connecting is allowed, pasting is not."
Models Do Not Store Text Like a Database
Anthropic explains how a trained model treats the original data as follows.
Models do not store text like a database, nor do they simply "mash-up" or "collage" existing content. Models identify general patterns in text in order to help people create new content, and they do not have access to or pull from the original training data once the models have been trained. (How Do You Use Personal Data in Model Training?)
OpenAI describes the stages of training and where the data comes from.
OpenAI trains its models in two stages. First, we learn from a large amount of data. Then, we use data from ChatGPT users and human trainers to make sure the outputs are safe and accurate and to improve their general capabilities. (OpenAI Enterprise privacy)
OpenAI uses data from different places including public sources, licensed third-party data, and information created by human reviewers. We also use data from versions of ChatGPT and other services for individuals. (Ibid.)
Both companies explain that a trained model does not answer by referring to the original text. On the other hand, this also means that specific data cannot later be pulled out and deleted. We cover this point in the section below on requesting corrections or deletion.
Uses Are Limited
Anthropic limits what personal information contained in training data can be used for.
We do not use such personal data to contact people, build profiles about them, to try to sell or market anything to them, or to sell the information itself to any third party. (How Do You Use Personal Data in Model Training?)
Data Covered by the Exceptions Takes a Separate Route
The opt-out exceptions mentioned in Section 2 (feedback and safety review) are handled separately from ordinary training data.
For feedback, the whole conversation is stored after being unlinked from the user, and it is not combined with other conversations.
When you provide us feedback via our thumbs up/down button, we will store the entire related conversation, including any content, custom styles or conversation preferences, in our secured back-end for up to 5 years. ... We de-link your feedback from your user ID (e.g. email address) before it's used by Anthropic. ... We do not combine your feedback with your other conversations with Claude. (Is my data used for model training?)
OpenAI also says that sending feedback makes the whole conversation available for training.
If you choose to provide feedback, the entire conversation associated with that feedback may be used to train our models. (How your data is used to improve model performance)
Conversations flagged for safety review are kept longer.
We retain inputs and outputs for up to 2 years and trust and safety classification scores for up to 7 years if your chat or session is flagged by our automated trust and safety systems as violating our Usage Policy. (How long do you store my data?)
In addition, Anthropic's privacy policy states explicitly that it may re-link data to the user in order to deal with policy violations.
If our systems flag Inputs or Outputs for harmful content or for potentially violating our policies, we disassociate the content from your user ID to train our trust and safety internal classification and generative models. However, we may re-identify the Inputs or Outputs to enforce our Terms of Service or Usage Policy with the responsible user if necessary. (Anthropic Privacy Policy)
Even Under Business Contracts, Where Data Is Not Used for Training, It Is Stored for a Period
Business contracts and the API are not used for training, but data is stored for a period to monitor for abuse. The official pages also state who can access it during that period.
OpenAI may securely retain API inputs and outputs for up to 30 days to provide the services and to identify abuse. After 30 days, API inputs and outputs are removed from our systems, unless we are legally required to retain them. (OpenAI Enterprise privacy)
Our access to API business data stored on our systems is limited to (1) authorized employees that require access for engineering support, investigating potential platform abuse, and legal compliance and (2) specialized third-party contractors who are bound by confidentiality and security obligations, solely to review for abuse and misuse. (Ibid.)
For Anthropic API users, we automatically delete inputs and outputs on our backend within 30 days of receipt or generation, except:
- When you use a service with longer retention under your control (e.g. Files API)
- When you and we have agreed otherwise (e.g. zero data retention agreement)
- If we need to retain them for longer to enforce our Usage Policy (UP)
- In compliance with the law (How long do you store my organization's data?)
For certain high-capability models (Covered Models), Anthropic also publishes how its staff access stored data.
By default, no Anthropic personnel can read your retained conversations. Human review can occur only through a controlled access path—for example, when content is flagged by our automated trust and safety systems for potential harm. These reviews can only be performed by a small set of approved reviewers. Every instance of access is recorded in a tamper-proof log that reviewers cannot suppress or modify. (Data retention practices for Covered Models)
When you explain internally what "used for training" means, these four points make it easier to understand.
- The model does not learn while processing a request. Training is a separate process that uses stored data, and whether data is handed over to it is decided by the contract and settings
- Before data goes to training, the link to whose input it was is removed and personal information is reduced
- A trained model does not store the original text and does not refer to it
- That is exactly why specific data cannot be removed from a trained model after the fact
5. Who Owns the Rights to the Output?
Both companies state explicitly that the rights to outputs belong to the user.
As between you and OpenAI, and to the extent permitted by applicable law, you (a) retain your ownership rights in Input and (b) own the Output. We hereby assign to you all our right, title, and interest, if any, in and to Output. (OpenAI Terms of use)
Anthropic agrees that Customer (a) retains all rights to its Inputs, and (b) owns its Outputs. (Anthropic Commercial Terms of Service)
However, OpenAI's same terms also state that output may not be unique.
Due to the nature of our Services and artificial intelligence generally, output may not be unique and other users may receive similar output from our Services. (OpenAI Terms of use)
The premise that other users may receive similar output matters whenever you treat generated content as your own original content without changes.
6. Age and Account Requirements Differ
Here the two companies clearly differ.
| Minimum age | |
|---|---|
| OpenAI | 13 or older, or the minimum age required to consent in your country. Users under 18 need a parent's or guardian's permission |
| Anthropic | 18 or older, or the minimum age required to consent in your location, whichever is higher |
Minimum age. You must be at least 13 years old or the minimum age required in your country to consent to use the Services. If you are under 18 you must have your parent or legal guardian's permission to use the Services. (OpenAI Terms of use)
You must be at least 18 years old or the minimum age required to consent to use the Services in your location, whichever is higher. (Anthropic Consumer Terms of Service)
In workplaces that include interns or student part-timers, this is worth checking.
7. Prohibited Uses
Both companies set out prohibited uses in their usage policies. Below are the ones that may come up at work.
From OpenAI's usage policies (Usage policies), the items most likely to be relevant to business:
- Attempting to destroy or compromise other people's systems or property, or to infringe intellectual property rights
- Aggregating, monitoring, profiling, or distributing individuals' private or sensitive information without their permission
- Providing advice that requires a license (such as legal or medical advice) without appropriate involvement by a qualified professional
- Building facial recognition databases without the consent of the data subjects
Anthropic's usage policy (Usage Policy) is built on pillars such as the following.
- Do not violate laws or engage in illegal activity
- Do not compromise critical infrastructure
- Do not compromise computers or networks
- Do not violate privacy or identity rights
- Do not create or spread misinformation
- Do not engage in fraudulent, abusive, or predatory practices
In addition, Anthropic's consumer terms prohibit using the service to develop competing services.
To develop any products or services that compete with our Services, including to develop or train any artificial intelligence or machine learning algorithms or models or resell the Services. (Anthropic Consumer Terms of Service)
If you are planning to build a service that uses AI, check how this clause should be interpreted with your legal team.
8. When Is Data Deleted?
Anthropic's privacy policy describes how deleted conversations are handled.
...which will be removed immediately from your conversation history and automatically deleted from our back-end within 30 days. (Anthropic Privacy Policy)
However, the same policy also states that data may be retained regardless of a deletion request, for example because of legal or contractual obligations. Operate on the assumption that deleting something does not always mean it is gone.
For OpenAI, the handling of temporary chats is published.
With temporary chats, your conversations are automatically deleted, don't inform your ChatGPT memory, and aren't used to train our models. (OpenAI Consumer privacy)
9. What Happens When You Ask an AI Company to Correct or Delete Data or Code?
"We accidentally pasted customer information." "Our internal source code had been loaded into a coding assistant on a personal account." "ChatGPT gives an incorrect career history for one of our executives." In cases like these, what can actually be undone by making a request to the AI company? Below we go through it case by case, within what is written on the official pages.
Case 1: Deleting Conversations or Coding Sessions Yourself
Both companies say deleted conversations are removed from their systems within 30 days. However, both have exceptions.
When you delete a chat (or your account), the chat is removed from your account immediately and scheduled for permanent deletion from OpenAI systems within 30 days, unless: The chat has already been de-identified and disassociated from you, or OpenAI must retain it longer for security or legal obligations. (Chat and File Retention Policies in ChatGPT)
If you decide to turn off the model improvement setting, we will not use your previous or new chats or coding sessions for future model training. Additionally, if you delete a chat from your chat history, it will not be used to train future models. Your data will still be included in model training runs that are already in progress, or in models that have been trained. (How long do you store my data?)
What deletion removes is the stored conversation. Data that has already been unlinked and separated for training (OpenAI), and training already in progress or completed (Anthropic), are not covered by deletion.
Case 2: You Want to Withdraw Data Already Used for Training
Within what we checked, neither company's official pages offer a procedure for removing specific data from a trained model. Anthropic states explicitly that rights regarding training data are limited.
This includes your right to request a copy of your personal data, and to object to our processing of your personal data or request that it is deleted. We make every effort to respond to such requests. However, please be aware that these rights are limited, and that the process by which we may need to action your requests regarding our training dataset are complex. (How Do You Use Personal Data in Model Training?)
OpenAI's privacy policy also excludes data separated for training from deletion requests.
Once you choose to delete Personal Data, we will remove it from our systems within 30 days unless we need to retain it for longer as described below, or it has already been de-identified and disassociated from your account when you allow us to use your Content to improve our models. (OpenAI Privacy policy)
What a request can stop is future training use. As we saw in Section 4, a trained model does not store the original text, so an operation like "remove just this conversation" is not something the system is designed for in the first place.
Case 3: Incorrect Output About You or Someone at Your Company
For incorrect personal information in outputs, both companies provide a channel for correction and deletion requests. However, they word their response as being "to the extent possible."
If you notice that ChatGPT output contains factually inaccurate information about you and you would like to request a correction or removal of the information, you can submit these requests through privacy.openai.com or to dsar@openai.com, and we will consider your request based on applicable law and the technical capabilities of our models. (OpenAI Privacy policy)
Please note that we cannot guarantee the factual accuracy of Outputs. If Outputs contain factually inaccurate personal data relating to you, you can submit a correction request and we will make a reasonable effort to correct this information—but due to the technical complexity of our large language models, it may not always be possible for us to do so. (Anthropic Privacy Policy; the contact address is privacy@anthropic.com)
Requests involve identity verification. OpenAI states that it cannot act on a request if it cannot verify your identity.
In order to protect your Personal Data from unauthorized access, change, or deletion, we may require you to verify your credentials before you can submit a request to know, correct, or delete Personal Data. ... If we cannot verify your identity, we will not be able to honor your request. (OpenAI Privacy policy)
Response deadlines depend on the applicable law. Anthropic says it will respond within one month where the EU or UK GDPR applies. Check which period applies to users in Japan when you make a request.
Case 4: Requesting Deletion of Data Entered by Employees Under a Business Contract
Under a business contract, employees do not make requests to the AI company as individuals. The point of contact is your own administrator. Anthropic states explicitly that under business contracts, the customer company is the data controller.
Please note, the Privacy Policy does not apply where Anthropic acts as a data processor and processes personal data on behalf of commercial customers using Anthropic's Commercial Services. In those cases, the commercial customer is the controller, and you can review their policies for more information about how they handle your personal data. (How Do You Use Personal Data in Model Training?)
Deleting an account or organization also goes through the administrator.
If you are a Claude for Work, Claude for Enterprise or Console user, you will need to contact your accounts primary owner, owner, or account manager to have your account deleted. ... Note that organization level account deletion requests must be made by your accounts Primary Owner. (Deleting commercial Anthropic accounts)
Enterprise plan customers can also set custom retention timelines for their organization's data. (Can you delete data that I sent via Team and Enterprise plans?)
OpenAI's business plans have the same structure: administrators can delete employees' conversations, and deleted conversations are removed within 30 days.
Workspace admins have control over workspaces and can view, access, export, and delete end user conversations in the workspace. (OpenAI Enterprise privacy)
Your workspace admins control how long your data is retained. Any deleted conversations are removed from our systems within 30 days, unless we are legally required to retain them. (Ibid.)
So under a business contract, unless you decide internally "who the administrator is" and "whom employees report to when they notice they have entered something by mistake," a deletion request will never even get started.
Case 5: Source Code
Code is treated the same way as chat. Anthropic's pages consistently say "chats or coding sessions" together, and both the deletion deadline and the fact that data cannot be taken back out of trained models are the same as for chat.
OpenAI's Codex has a training setting that is separate from the chat setting.
If you use Codex on a personal ChatGPT plan, the "Improve the model for everyone" setting also applies to your Codex tasks. ... Codex has a separate setting for training on full environments in Codex Settings. Changing the ChatGPT setting or opting out through the privacy portal does not change that Codex setting. (Data Controls FAQ)
Turning off the chat training setting does not change the separate training setting for Codex environments (entire repositories). If you use a development assistant on a personal account, there are two settings to check.
What a Request Can Undo
| Request | What can be undone |
|---|---|
| Deleting stored conversations and code | Deleted within 30 days. Exceptions remain for legal obligations and safety reasons |
| Stopping future training use | Possible through settings or an opt-out |
| Removal from trained models | No procedure. Not excluded from training in progress or completed |
| Correcting incorrect personal information in outputs | Can be requested, but handled "to the extent possible." Identity verification required |
| Deleting employee data under a business contract | Your own administrator is the point of contact. Removed within 30 days once the administrator deletes it |
The practical conclusion is that a request can only undo data that is still stored. Whatever has gone into training cannot be brought back by a request. That is exactly why you need to decide "what may be entered," covered in the next section, before anything is entered.
10. What to Decide in Your Internal Rules
Based on everything above, here are the things that reading the terms alone will not settle. Each company has to decide these for itself.
- Which plan to use. Since training use depends on the plan, this is the first decision. Put in writing a policy of choosing business plans whenever business data is involved.
- What may be entered. Customers' personal information, unpublished financial information, information covered by confidentiality agreements with other companies. Show where the line is between what may and may not be entered, using concrete examples. "Do not enter confidential information" alone is not enough for staff to make decisions in practice.
- How to handle outputs. On the premise that other users may receive similar output, decide whether outputs can be used externally as is or whether a review step is needed.
- Who approves. Decide where to submit requests and who makes the decision when someone wants to start using a new AI service.
- What to do after an accidental entry. As we saw in Section 9, a request can only undo data that is still stored. Decide the steps and who owns them: the person who notices deletes the conversation, reports it to the administrator, and if necessary submits a request through the AI company's channel. Under a business contract, the administrator is the point of contact for deletion, so make sure everyone knows who the administrator is.
- When to review. Terms get revised. Decide who checks them and how often, for example every six months.
We provide AI implementation support that includes putting internal rules like these in place. We can also help you design configurations that keep your data inside your organization.
Frequently Asked Questions
Does training use differ between free and paid plans?
What the official terms describe is a difference between individual and business plans. OpenAI states explicitly that it does not use business plans or the API for training by default, and Anthropic's commercial terms say it may not train on customer content. On individual plans, both work by opting out in your settings. Within what we checked, we found no statement that handling differs between free and paid plans.
If we opt out, is it fine to enter confidential information?
Under the terms, the opt-out has exceptions. Anthropic's consumer terms state explicitly that data is used for training when you send feedback or when it is flagged for safety review. Do not treat an opt-out as grounds for entering confidential information.
Can we use outputs in our own products?
Both companies state in their terms that the rights to outputs belong to the user. However, OpenAI notes that output may not be unique, and Anthropic's consumer terms prohibit use for developing competing services. The answer depends on the use case, so check your specific use with your legal team.
From what age can people use these services at work?
OpenAI requires users to be 13 or older (with a parent's or guardian's permission if under 18), and Anthropic requires 18 or older. Since the standards differ, check them for each service you use.
If we sign up with a company email address, does it become a business contract?
No. Even with an email address on your company domain, the contract remains an individual one once you sign up for an individual plan. Individual plans also show an auto-generated organization name in the admin screen, so they can look like a business contract, but the consumer terms are what apply. Confirm the contract type by whether there is seat management and how billing works.
Is it a problem for employees to use personal accounts for work?
We do not recommend it. The reasons: the consumer terms apply and training use is included by default; the company cannot see how the accounts are used; settings are left to individuals; and data used for training cannot be withdrawn retroactively. If you prohibit it, provide a business-contract alternative at the same time. A ban without an approved environment to use increases unmanaged use.
When we send a document to an AI, does the AI memorize it on the spot?
In the general mechanism of cloud-based AI, processing a request (inference) is computation that does not change the model's contents, and the data disappears from memory once processing ends. Training is a separate process that later uses data stored on the provider's side. So whether it "memorizes" anything depends on whether stored data is passed to the training process, which is decided by the contract and settings.
If our data is used for training, will the text we entered appear as is in other people's answers?
Both companies' official pages explain that before training they remove the link to the user and reduce personal information, and that a trained model does not store text like a database. On the other hand, there is no procedure for removing specific data from a trained model. The official pages say neither "it will appear as is" nor "it will never appear," so not entering trade secrets at all is the safer practice.
We accidentally entered confidential information. Can we get it deleted by asking the AI company?
Both companies say stored conversations are deleted within 30 days if you delete them yourself. However, data already separated for training, and training in progress or completed, are not covered. You can also request correction of incorrect personal information in outputs, but it is handled "to the extent possible." Under a business contract, your own administrator is the point of contact for deletion.
Are coding assistants treated the same way?
It depends on the plan type. Anthropic's Privacy Center states explicitly that it treats use of Claude Code by individual-plan accounts (Free, Pro, Max) as a consumer product and use on Enterprise plans as a commercial product. Development tools handle your own source code, so the impact is greater than with chat. Deletion and removal from trained models work the same way as for chat, and OpenAI's Codex has an environment training setting that is separate from chat.
How do we find out when the terms change?
Both companies announce updates to their terms. A practical approach is to include in your internal rules who checks them and when. The content of this article is also as of September 9, 2026.
Summary
What trips companies up when using generative AI at work is not the technology but a lack of shared understanding. The points to check come down to these eight.
- Training use depends on the plan you use
- The opt-out has exceptions
- Signing up with a company email does not change anything: an individual plan is still an individual contract
- Data is unlinked from the user before training, but it cannot be extracted from a trained model
- Rights to outputs belong to the user, but outputs are not necessarily unique
- Age requirements differ by service
- Prohibited uses are listed in the official policies
- A correction or deletion request can only undo data that is still stored
The third point in particular is one that easily goes unnoticed while day-to-day use continues. If you handle business data, we recommend limiting use to accounts under a business contract and explicitly prohibiting work use of personal accounts. Providing an approved environment to use is a prerequisite.
Beyond that, what may be entered, who approves, and when to review are things each company has to decide for itself.
If you would like help starting with your internal rules, please let us know through our contact page.
Disclaimer: This article was prepared by reviewing the official terms published as of September 9, 2026, and is not legal advice. Base actual decisions on the latest terms and your own legal review.