Analysis12 min readSeptember 7, 2026By RunSolo

Can You Put Client Data Into ChatGPT? Depends on Your Plan

Three separate protections — not trained on, a data processing agreement, retention control — and they unlock at three different prices. Free, Plus and Pro clear none of them.

You have a client's contract, or their customer list, or a folder of their support emails. You want to paste it into ChatGPT and get an hour back.

The question everyone asks is "is that safe?" It's the wrong question, because safety isn't a property of the product. It's a property of the plan you're on — and the plans don't line up with what they cost or what they're called.

We read the data terms for ChatGPT, Claude, Gemini and Copilot at their own pages. There are three separate protections, they unlock at three different prices, and the one most people assume they already have is the one consumer plans never get at any price.

This is not legal advice and we are not lawyers. Every source is linked so you can read it yourself, and where we couldn't open something we say so.

Ad

Three gates, not one

This is the same shape we found in who owns AI-generated work, where copyright indemnity turned out to be gated by tier — the consumer plan gets the licence, the business plan gets the promise to defend you. Data works the same way, except there are three gates and they don't open together.

What you wantWhat it actually gets youWhere it starts (OpenAI)
Not trained onYour inputs stay out of the modelBusiness and above, plus the API
A DPAA contract making the vendor your data processorBusiness, Enterprise, API
Retention controlYou decide how long anything is keptEnterprise, Healthcare and Edu only

Free, Plus and Pro clear none of them. And notice that Business clears two of three — a paying business customer still doesn't control retention.

ChatGPT, by tier

On consumer plans the setting is called "Improve the model for everyone." OpenAI's Data Controls FAQ is written entirely as instructions for switching it off, which tells you what the default is.

What turning it off does, in OpenAI's words: "Your conversations will still appear in your chat history but won't be used to train ChatGPT."

Read that again. Opting out of training is not deletion. Your conversations stay. Temporary Chats are the separate thing — those are "deleted from our systems after 30 days", aren't used for training, and "may be reviewed only to monitor for abuse."

On the business side, OpenAI's enterprise privacy page (updated 8 January 2026) inverts the defaults for ChatGPT Business, Enterprise, Healthcare, Edu, Teachers and the API: by default it does not train on your data, and your inputs and outputs are yours — "where the law allows," which is the same hedge that made the ownership article interesting.

Two details on that page matter more than the headline:

Retention control is named for three products, and Business isn't one of them. OpenAI says you control how long data is kept on Enterprise, Healthcare and Edu. Pay for Business and you get the training protection without the retention control.

Feedback is an opt-in to training. OpenAI says that if you've explicitly shared data — "for example, through feedback mechanisms" — that data may be used for training. Clicking thumbs-up on a response is that mechanism.

And the DPA line, quoted directly: OpenAI will sign a Data Processing Addendum covering "ChatGPT Business, ChatGPT Enterprise and the API." Three products. Not Free, not Plus, not Pro. You request it through a form; it isn't automatic.

Claude, and the default that changed

Anthropic did something in 2025 that nobody else on this list did: it changed the consumer default.

Per Anthropic's own announcement on 28 August 2025, Claude Free, Pro and Max — "including when they use Claude Code" — moved to a model where you choose whether your chats train Claude, with "data retention to five years, if you allow us to use your data for model training." Decline and it's 30 days. Existing users had until 8 October 2025 to choose.

Explicitly excluded: "Claude for Work, Claude for Government, Claude for Education, or API use, including via third parties such as Amazon Bedrock and Google Cloud's Vertex AI." The commercial tiers were never in scope.

(A lot of coverage gives that deadline as 28 September 2025. Anthropic's own page says 8 October. We're going with the primary.)

Anthropic's retention documentation, dated 1 July 2026, adds the number nobody quotes. Deleted chats go from your history immediately and from backend storage within 30 days. But if a conversation is flagged by automated trust-and-safety systems, inputs and outputs are kept up to 2 years — and classification scores up to 7 years.

Seven years, on a consumer plan, from an automated flag, regardless of your training setting.

Gemini and Copilot

Google draws the cleanest line of the four. Its Workspace privacy hub (updated 14 August 2026) states that Workspace "does not use customer data for training models without customer's prior permission or instruction" and that "your interactions with Gemini stay within your organization."

The important structural difference: Gemini data is customer data governed by Google's Cloud Data Processing Addendum, which already applies to qualifying Workspace editions. Google is the only one of the four where the DPA comes with the plan rather than being something you request. Consumer Gemini on a personal Google account runs under entirely separate terms.

Microsoft states it three times on its Copilot privacy page (updated August 2026): "Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs." Copilot services have opted out of Azure OpenAI's abuse monitoring, which elsewhere includes human review, and admins can set retention through Purview. One carve-out worth knowing: Anthropic models used as a subprocessor are currently excluded from the EU Data Boundary.

Microsoft also declines to use optional customer feedback for foundation model training — the opposite of OpenAI's position.

What "we don't train on your data" doesn't mean

There are four separate questions here, and vendors answer them in four different places. A page that answers one says nothing about the others.

  1. Is it used for training?
  2. How long is it kept?
  3. Can a human look at it?
  4. Is there a contract making the vendor your processor?

"Not used for training" is entirely compatible with: stored on the vendor's servers indefinitely, retained for years under a safety flag, reviewed by a human for abuse monitoring, used for training anyway because you clicked thumbs-up — and preserved past your deletion request by a court.

That last one isn't hypothetical.

A court has already overridden a deletion policy

In May 2025, in the New York Times litigation, OpenAI was ordered to preserve output log data that would otherwise have been deleted — including data subject to user deletion requests and statutory erasure rights.

That order has ended. Per analysis from Duane Morris, a stipulated modification approved on 9 October 2025 terminated the ongoing preservation obligation as of 26 September 2025. Already-segregated logs stayed retained, EEA/Swiss/UK requests were excluded, and targeted preservation continues for specific accounts named in an appendix.

We nearly opened this article with that order as a live warning. It isn't one, and saying so would have been false.

What it is is precedent, and the lesson from the lawyers is the useful part: automated deletion policies must yield to litigation holds, and a company can't refuse on privacy-law grounds alone. Your vendor's deletion promise is a policy, not a guarantee — it operates until a court says otherwise.

Ad

Why this is your problem and not the vendor's

Here's the part that decides the question, and it has nothing to do with which model is better.

You are usually your client's data processor. You're handling their data on their instructions. Under GDPR that makes them the controller, and the controller stays liable to the people whose data it is for what their processors do — they can chase you for it afterwards, but the exposure lands on them first.

So when you paste your client's customer list into a tool where you have no DPA, you've introduced a sub-processor your client never agreed to, into a chain they're still answerable for. That's a breach of your contract with them before it's ever a regulatory matter.

For US readers the mechanism is different and the conclusion is the same. Under CCPA and CPRA you need a written contract with any service provider receiving personal information, prohibiting them from selling or sharing it and requiring deletion on instruction. And having those terms in place is what limits your liability for a violation the vendor causes. Without the contract, the liability doesn't transfer.

Either way: the DPA isn't paperwork. It's the thing that moves the risk. And it's the gate consumer plans never clear.

If you're in a licensed profession the bar is higher still. The American Bar Association's Formal Opinion 512 (July 2024) concluded that a client's informed consent is required before putting their confidential information into a self-learning AI tool — and that boilerplate consent in an engagement letter isn't adequate, because informed consent requires actually explaining the risk. Most readers aren't lawyers, but plenty are bound by a confidentiality clause that says something similar in weaker words. The ABA is just the profession that wrote it down first.

The exposure you're not thinking about

Everything above is about the deliberate paste. That's the one you worry about, which means it's not the dangerous one.

The dangerous one is your automations. If you run a Make or Zapier scenario with an AI step — summarise this inbound email, draft a reply, categorise this form response — then the prompt content is sent to the model provider every time it runs. Client names, email bodies, form fields, all of it.

In a processor chain, the AI provider becomes a sub-processor under your agreement with the automation platform. Under GDPR Article 28(2) a processor can't engage a sub-processor without the controller's authorisation, and where that authorisation is general, you're supposed to be told about changes and given the chance to object.

The line that stuck with us, from a compliance write-up of exactly this setup: if your automation delivers personal data to a service you have no agreement with, that gap is yours.

We should say plainly that we recommend these automations. Our client follow-up automation guide describes workflows that put client data through an AI step. This article is the companion to that one. The deliberate paste happens when you're paying attention. The automation runs a thousand times while you're not.

What to actually do

If you're on Free, Plus, Pro or Max and handling client data: turn off model training today — it takes thirty seconds and it's the one control you have. Understand that it doesn't delete anything and doesn't get you a DPA. For anything genuinely confidential, either move to a business tier or don't paste it.

If you're paying for a business tier: check whether your plan includes retention control or only the training protection. On OpenAI those are different products.

If you have a DPA in place: check your automations, not just your chat window. List every AI step in every scenario and confirm the destination is covered.

Read your client contracts before your vendor's terms. Your confidentiality clause is the document that governs you. The vendor's page tells you what's technically happening; the contract tells you what you promised.

And if you handle health data, financial records, legal files, or anything belonging to someone who'd sue you: talk to an actual lawyer about your specific situation. This article can tell you what four companies published and when. It cannot tell you what your contract says or which regime you're under.

The Bottom Line

There are three protections, not one, and they unlock at three different prices: your data not being trained on, a data processing agreement making the vendor your processor, and control over how long anything is retained. Free, Plus and Pro get none of them. Even a paid business tier may get two of three — OpenAI names retention control for Enterprise, Healthcare and Edu, not Business. Google is the only one of the four where the DPA arrives with the plan instead of being requested. And 'we don't train on your data' answers one question out of four: it says nothing about how long it's kept, who can read it, or whether anyone is contractually your processor.

What to do

Turn model training off today if you're on a consumer plan — it is the only control you have there, and it takes half a minute. Then audit your automations rather than your chat window, because an AI step inside a Make or Zapier scenario sends client data every time it runs, and that is where the volume is. Before anything else, read the confidentiality clause in your client contract: that is the document that actually binds you.

For the sibling question — who owns what these tools produce, and why the indemnity is gated the same way — see who owns AI-generated work. If you're in a licensed trade, the advertising rules are a separate layer again, which we mapped in AI real estate advertising rules.

Ad


Not legal advice, and we are not lawyers. Every vendor claim above is linked to the page it came from, with the date that page carried when we read it on 7 September 2026 — these terms change, and Anthropic's changed materially in 2025. Where we could not open a primary source we have said so in the text: the CCPA and GDPR points come from law-firm commentary rather than statutory text, the ABA opinion from the ABA's own summaries rather than the PDF, and the court order from a law firm's analysis because the filing's text layer would not extract. Some links in our articles may be affiliate links — read our policy.

Ad

Enjoying this article?

Get more like this every Tuesday. Free.

By subscribing, you agree to our Privacy Policy.

R

Written by

RunSolo

We check AI tool pricing and limits at the vendor source, run hands-on tests where we say we did, and publish our corrections in the article text.

Related Articles