AI Tools That Don’t Train on Your Data: The Tiers That Keep Work Private

A closed brass padlock resting on a laptop keyboard, representing AI tools that keep your data private and do not train on your inputs

Last updated: September 2026

If you paste a client’s drawing set or an unreleased design into an AI tool, the first question is not how good the answer is; it is whether that input just became training data. The answer depends almost entirely on which tool and which tier you used, and the split is sharp: the business and API tiers of the major vendors do not train on your inputs by default, while several of the consumer tiers do unless you change a setting. This guide lists which is which, with the exact vendor terms, so you can pick a tool that keeps confidential work confidential.

This is the actionable list; for the underlying concept see our pillar on AI tool data security and engineering IP, and it sits under our roundup of the best AI tools for engineers.

Short answer: The tools that do not train on your data by default are the business and API tiers: the OpenAI API and ChatGPT Enterprise, Team, and Edu; the Anthropic API and Claude for Work; the paid Google Gemini API; and Microsoft 365 Copilot for business. The consumer tiers are the trap. Consumer ChatGPT trains by default unless you turn off a setting, consumer Claude has trained by default since 2025 unless you opt out, and the free Google Gemini API explicitly uses your content and may have humans review it. Same brand, different tier, opposite answer. For confidential or IP work, use a no-training business or API tier, and confirm the setting before you upload.

A brass padlock securing a metal wire, a metaphor for locking down your data
Whether your input becomes training data is decided by the tier, not the brand. Photo: Pexels.

What “does not train on your data” actually means

Three things get conflated, so separate them. Training means your inputs are used to improve the model itself. Retention means the vendor stores your data for a period, often to monitor abuse, without training on it. And human review means a person may read a sample of conversations. A tool can retain your data briefly without training on it, which is why the OpenAI API keeps abuse logs for up to 30 days while still not using that data for training. “Does not train” is the specific promise you want for confidential work, and it is the one that varies most by tier. For the deeper treatment of these distinctions, see our data-security pillar linked above.

The tools and tiers that do NOT train by default

These are the safe defaults for confidential and IP work. The OpenAI API does not use data sent to it to train or improve OpenAI models unless you opt in, and Zero Data Retention is available to eligible customers (OpenAI). Anthropic’s commercial terms state it “may not train models on Customer Content” across the API, Claude for Work, Enterprise, Education, and Government (Anthropic). The paid Google Gemini API does not use your prompts or responses to improve Google’s products (Google). And Microsoft states that in Microsoft 365 Copilot for business, prompts, responses, and data accessed through Microsoft Graph “aren’t used to train foundation LLMs” (Microsoft). ChatGPT Enterprise, Team, and Edu also exclude business data from training, per OpenAI’s enterprise privacy page.

Tool / tier Trains by default? How to stay private
Business and API tiers
OpenAI API No (opt-in only) Default; enable Zero Data Retention for stricter storage
ChatGPT Enterprise / Team / Edu No Default on these tiers
Anthropic API / Claude for Work No Default under the commercial terms
Google Gemini API (paid) No Use the paid tier, not the free one
Microsoft 365 Copilot (business) No Default on a business license
Consumer and free tiers
ChatGPT Free / Plus / Pro Yes Turn off “Improve the model for everyone”; use Temporary Chat
Claude Free / Pro / Max Yes (since 2025, unless you opt out) Turn off model improvement; use Incognito chats
Google Gemini API (free) Yes Do not upload IP; switch to the paid tier
Consumer and business rows are grouped deliberately. Business/API rows verified on vendor pages; OpenAI’s consumer and enterprise details are per OpenAI’s help and enterprise-privacy pages. Confirm current terms before uploading.

The tools that DO train by default, and how to turn it off

The consumer tiers are where confidential work leaks. On consumer ChatGPT (Free, Plus, and Pro), a setting called “Improve the model for everyone” is on by default; turning it off in Data Controls stops future training, and Temporary Chat is not used for training, per OpenAI’s help documentation. Consumer Claude changed in 2025: on the Free, Pro, and Max plans, new and resumed chats are used to improve the model unless you opt out, retained for up to five years if allowed, though Anthropic states that “Incognito chats are not used to improve Claude” (Anthropic’s commercial terms keep business data excluded throughout; the consumer change is on its privacy page). And the free Google Gemini API is blunt about it: Google says to “not submit sensitive, confidential, or personal information to the Unpaid Services,” because that content is used to improve its products and may be human-reviewed (Google). Whether the model trains on your uploads is the same question we examine for CAD work in does ChatGPT train on my drawings.

A server in a blue-lit data center where AI vendors process and store prompts
Retention is not the same as training; a tier can store data briefly without learning from it. Photo: Pexels.

The tier trap: same tool, different answer

The single most important idea here is that the brand does not tell you the answer; the tier does. The clearest example is Google Gemini: the paid API does not train on your content, while the free API explicitly does and may have humans read it. The same split runs through the others, with consumer Claude training by default while Claude for Work does not, and consumer ChatGPT training by default while ChatGPT Enterprise does not. Users in the EEA, Switzerland, and the UK get the paid-tier no-training protections even on Google’s free tier, a regional exception worth knowing. The practical rule is simple: for anything confidential, do not assume; check the specific tier’s terms, because moving up one tier often flips the answer entirely.

How the major assistants’ data policies compare. Video: Shared Security Podcast via YouTube.

A checklist before you upload confidential work

  • Confirm the tier. A business, enterprise, or paid API tier is the baseline for no-training; consumer tiers are not.
  • Check the setting. On a consumer tier, turn off the model-improvement toggle and prefer a temporary or incognito chat.
  • Prefer the API or a business plan for IP. The OpenAI and Anthropic APIs do not train by default, and Zero Data Retention tightens storage further.
  • Watch the free-tier exception. A free API tier can train even when the paid one does not, as with Google Gemini.
  • Read the retention window. No-training does not mean no-storage; know how long data is kept and why.

If the work is a client’s material specifically, pair this with whether it is safe to use AI with client drawings, and read the clauses that govern all of this in AI tool terms of service for engineering.

Frequently asked questions

Which AI tools don’t train on my data?

The business and API tiers of the majors: the OpenAI API and ChatGPT Enterprise, Team, and Edu; the Anthropic API and Claude for Work, Enterprise, and Education; the paid Google Gemini API; and Microsoft 365 Copilot for business. Each states that your inputs are not used to train its models by default. The consumer and free tiers are the ones to be careful with, and moving to a business or API tier is the reliable way to guarantee no training.

Does ChatGPT train on what I type?

On the consumer plans, Free, Plus, and Pro, yes by default. You can turn off the “Improve the model for everyone” setting in Data Controls to stop future training, or use Temporary Chat, which is not used for training. ChatGPT Enterprise, Team, and Edu do not train on your data, and neither does the OpenAI API. So the answer depends on which ChatGPT you are using, not on ChatGPT as a brand.

Is the API safer than the app?

Usually yes. The OpenAI and Anthropic APIs do not train on your inputs by default, whereas the consumer apps are opt-out, so the API is generally the safer place for confidential work. The important exception is Google’s free Gemini API, which does use your content and may have it human-reviewed; there you need the paid API tier for the no-training protection.

Did Claude change its data policy?

Yes. Since 2025, consumer Claude on the Free, Pro, and Max plans uses your new and resumed chats to improve the model unless you opt out, with retention of up to five years for allowed data. Incognito chats are excluded, and the commercial and API tiers, including Claude for Work, were never used for training. If you are on a consumer plan and handle sensitive work, check your privacy setting or move to a commercial tier.

Sources

Written by the CognitiveFuture editorial team. We build our guidance from vendors’ own terms, privacy, and documentation pages, each linked above; where a vendor page could not be retrieved directly at the time of writing, we say so and attribute the claim to that page. Data policies change, so confirm the current terms for your specific tier and region before uploading confidential material. This is general information, not legal advice.

Richard Johnson
About the author

Richard Johnson

Richard Johnson is an AI specialist at one of the world's largest technology companies, where he has spent the past three years helping organizations adopt AI. CognitiveFuture extends that work publicly: gathering the available evidence on each tool, from vendor documentation to independent reviews and user feedback, and cutting a crowded market down to the right choice for the job in front of you.

Scroll to Top