Your Data

The Privacy Toggle: You're Half Right

Turn off training on Claude and ChatGPT, know where your data actually lives, and what to ask for at work

Start Here: Flick It On Both Apps

Two minutes, both apps, done. This is the half of the story the toggle genuinely answers — with it off your chats stop being used to train the models, and your data stops sitting in a training pipeline for years.

Claude

  1. Open SettingsPrivacy
  2. Find "Help improve Claude"
  3. Switch it off

Off = new chats aren't used for training, and standard retention drops to 30 days. On = chats can be kept for training for up to 5 years. Anthropic's own explanation

ChatGPT

  1. Open SettingsData Controls
  2. Find "Improve the model for everyone"
  3. Switch it off

This no longer deletes your chat history — training opt-out and history are separate settings now. OpenAI's data controls FAQ

Why You Can Actually Trust It

The toggle isn't a polite request — it's a commitment in a published privacy policy, which is a legal document. And regulators have shown teeth on exactly this: companies caught building AI on data they shouldn't have held have been ordered to delete the entire model, not just the data — it happened to Everalbum's facial-recognition models and to Weight Watchers' Kurbo app. The honest caveat: those were smaller companies, not the major labs — but the precedent is set, and the big labs write their policies knowing it exists.

One thing the toggle can't do: untrain the past. Anything used for training before you flicked it stays learned. The switch is forward-looking — which is the best reason to flick it today rather than someday.

The Other Half: Where Your Data Lives

Whatever the toggle says, the everyday versions of Claude and ChatGPT process and store your chats on US infrastructure. Claude's consumer product stores workspace data in the US only — there's no European residency option on claude.ai, even for Enterprise. Deleted chats also keep a copy for around 30 days before they're gone, and conversations flagged for safety review can still be looked at whatever your setting says.

For most personal use, none of that is a problem. It becomes one the moment the data isn't only yours — which is why the real question at work isn't "is this private?" but "am I allowed?"

What Goes In, What Stays Out

Toggle on, this is fine

  • Drafts, plans, and thinking out loud
  • Questions about your work, with the names taken out
  • Anything you'd be comfortable posting under your own name

Stays out of a personal chat, whatever the settings say

  • ·Passwords, keys, or anything that unlocks something
  • ·Client names, records, or details you've promised to protect
  • ·Other people's personal or medical information
  • ·Anything covered by an NDA or a data agreement

The test is one question: would it hurt someone if it escaped? If yes, it doesn't go in — that's the rule that covers everything no toggle can.

If Your Agreements Say Europe Only

Plenty of companies have client contracts or data agreements that restrict where personal data can be processed. If that's yours, the everyday apps were never the answer — but two proper routes exist:

1

An enterprise setup that processes in Europe

Claude runs with European data residency via AWS Bedrock (Frankfurt) or Google Vertex, and OpenAI offers EU residency on its API and enterprise tiers. Business tiers also aren't trained on by default, and come with the data processing agreement your compliance people will ask about.

2

A model hosted where your data is allowed to live

European-hosted providers, or models run on your own infrastructure, keep the processing inside your borders entirely. More setup, total control — the right answer for the strictest agreements.

Not sure what your agreements say? This is the message to send whoever looks after data at your company — copy it as is:

Send to whoever owns your data agreements
Quick question for whoever owns our data agreements: do any of our client contracts or DPAs restrict where personal data can be processed (for example EU or UK only)? Asking because the everyday versions of AI chat tools (Claude, ChatGPT) process and store chats on US infrastructure regardless of their privacy settings. If our agreements care about that, there are two proper routes: an enterprise setup with European processing (Claude runs in Europe via AWS Bedrock Frankfurt or Google Vertex, OpenAI offers EU data residency on its business tiers), or an EU-hosted model. Happy to pull together options if useful.

The Two-Minute Privacy Check-Up

Rather than mapping all of this onto your own situation yourself, have the AI do it. Paste this into Claude (or ChatGPT) exactly as written — it interviews you about how you actually use these tools, then hands back your personal answers: the settings to change, what to stop pasting, and whether your use needs the business conversation.

The privacy check-up prompt
Give me a privacy check-up on how I use AI chat tools. Interview me one question at a time — don't move on until you understand: which AI tools I use and on what plans, what kind of things I paste into them, whether other people's information ever appears in my chats, whether I use them for work, and what promises my company has made about data (client contracts, GDPR, anything like that). Then give me a direct, personal read: 1. The settings I should change today, with exactly where they live. 2. What I should stop pasting, based on what I told you. 3. Whether anything in my use needs a business tier or a different setup, and what to ask for. Be honest with me, not reassuring. If something I'm doing is risky, say so plainly. And note: you're not my lawyer — flag anything where I need a real data protection person.

The Honest Bit

None of this is legal advice — if your company handles regulated data, the person who owns your data agreements gets the final word, and the message above is how you start that conversation. And no toggle makes a consumer chat a vault: flagged conversations can be reviewed, copies exist for a month after deletion, and the past can't be untrained. The toggle answers the training question properly. The would-it-hurt-someone rule answers the rest.

The Fine Print, If You Want It

Go Deeper