Tech & Tools

Does ChatGPT Train on Your Company Data? It Depends Which Account Your Team Uses

On personal ChatGPT, Claude, Gemini and Copilot plans, a setting decides whether your chats train models. Business plans don’t train on your data by default.

Line drawing of a chat window with a client file attached, beside a settings card whose training switch flips off and a green shield appears.

Tuesday, 4:52 p.m.

Someone means to forward the holiday party sign-up sheet to one colleague. They hit Reply All.

Four hundred people now have everyone’s home address.

The sheet was fine in one inbox. Nothing brings it back.

I run a firm that builds AI agents for companies of 50 to 500 people, and on most first calls a COO asks whether ChatGPT trains on their data.

It depends on the account. On ChatGPT’s personal plans, OpenAI may train on your chats unless you opt out. On ChatGPT Business, Enterprise and the API, it doesn’t, by default. Claude, Gemini and Copilot draw the same line.

The account is the button. It decides where the words end up, and whether your company can see, audit or delete them.

What do ChatGPT, Claude, Gemini and Copilot do with what you type?

All from each company’s own pages, as of September 2026. Recheck before quoting one in a policy.

Does ChatGPT train on your data?

Possibly on the personal plans, and not by default on the business ones. On Free, Plus and Pro, OpenAI may train on your conversations unless you turn off Settings, Data controls, “Improve the model for everyone.” Even then, a thumbs up or down can send that whole conversation to training. Deleted chats go within 30 days (retention page).

On Business, Enterprise and the API, OpenAI’s enterprise privacy page says it doesn’t train on your data by default, and admins control retention. API data can be held up to 30 days for abuse checks, seen by authorized staff and contracted reviewers.

Does Claude train on your data?

Claude makes you choose. On Free, Pro and Max the choice comes at sign-up and lives under Settings, Privacy. With training on, de-identified chats are kept up to five years; with it off, deleted chats go within 30 days (retention page).

On Team, Enterprise and the API, Anthropic doesn’t train on your data by default, and deleted chats and API data go within 30 days. On every plan, a thumbs up or down sends the whole conversation, kept up to five years. Team and Enterprise owners can switch rating off.

Does Gemini use your data?

It can on a personal Google account, and I’d be most careful here. With Keep Activity on, chats are kept 18 months by default, can train Google’s AI, and a sample goes to human reviewers. Reviewed chats are kept up to three years, even after you delete them. Google’s Gemini Apps Privacy Hub asks you not to enter anything confidential you wouldn’t want a reviewer to see.

On a work Google account, Workspace terms apply: chats aren’t read by human reviewers or used to improve AI models, on most Workspace business editions.

Does Copilot use your data?

Microsoft has two Copilots, and only the free one trains on your chats by default. Consumer Copilot keeps chats 18 months by default and trains on them unless you opt out under your profile, Privacy, “Training on conversation activity.” Some get human review.

With Microsoft 365 Copilot on a work account, Microsoft doesn’t use your prompts, responses or files to train its foundation models, and admins set retention. It’s being renamed Microsoft Copilot, the free app’s name, so check the sign-in. It sees whatever the person asking can see. If the salary spreadsheet is shared with everyone in SharePoint, Copilot will hand it to anyone who asks.

Are the business plans good enough?

For most companies this size, yes. I’d treat them like your email provider: a vendor holding your files under a contract you can read. If you handle health records, read that contract first.

Is it safe to put company data in ChatGPT?

In a work account, mostly. The bigger risk is which account people reach for.

In a KPMG and University of Melbourne survey of more than 48,000 people in 47 countries (April 2025), almost half of employees admitted using AI against company policy, including uploading sensitive company information into free public tools. Only 40% said their workplace had any guidance on it. It’s self-reported, so likely a floor.

A project manager, Sunday night, pastes a client contract into her personal ChatGPT Plus to find the renewal date. Now it sits in her account and, unless she switched it off, in the training pool. When she leaves in March it leaves with her, and nobody at the company can get it back.

People will use AI either way. What you decide is whose account they use it in.

What does a simple AI policy look like?

Five rules, short enough to send round this week:

  1. Company work goes in approved work accounts only. You may already own one: Copilot Chat comes with Microsoft 365 on a work sign-in, and most Workspace editions include Gemini.
  2. Some things never go in any AI tool. Passwords and API keys, bank and card numbers, government IDs, health information, and anything a client contract says stays with you.
  3. One person approves new tools, inside two days. A slow yes sends people to personal accounts.
  4. Admins switch off what nobody needs. Feedback buttons, any connector that reaches further than the job.
  5. Tell people up front that work chats belong to the company. Admins can usually see them, and the AI account closes with the email. Anyone who already put client files in a personal account deletes those chats, no blame.

How does an AI agent handle your data?

An agent works one job, so the data question gets answered once, at setup. Ours run in your own cloud and your company’s business account with the AI provider, so the API terms above apply. Each agent gets its own login with only the permissions that job needs.

Take policy and leave questions. It answers HR questions in Slack or Teams from your handbook and the asker’s leave balance. It’s connected to your HR system, and its login still can’t see payroll. A pay dispute goes to your HR partner, and on every agent we build, a person approves money and customer messages.

If a chat tool would do the job, buy the chat tool.

Check the button

IT sent a recall request for the party sheet. Eleven people replied all to say it hadn’t worked.

Your team will keep typing. Make sure the button they press sends it somewhere you can still get it back.

PS, if there’s a job your team keeps pasting into a chat window, bring it to an agent scoping call. Thirty minutes, and we’ll tell you which permissions an agent would need, and which it never would.

Share in X ↗
Read next
Tactics

12 Questions to Ask an AI Agent Vendor Before They Say “Two Weeks”

Work with us Switchboard Agents Proven AI agents, done for you and live in weeks. AI Jumpstart Stop guessing where AI fits. We’ll map it and prove it. AI Deployment Studio Custom AI and software, built into how you work. Book a call →