[nonimo]
EN
Download

Does Claude train on your data? Anthropic's answer, by plan

· Updated · Written and maintained by Joaquín Trapero, Nonimo

On a personal plan, only if you allowed it. On Claude for Work and the Anthropic API, no, unless you opted in. Anthropic’s own documents say so, with dates, and that is where most questions about Claude and privacy begin.

It is also the least useful thing you can know if you run a practice in Australia, because training is one of several things that can happen to a client’s details, and it is not the one the Privacy Act 1988 reaches first.

This page reads Anthropic’s own documents for what they say, and then applies the test an Australian regulator applies, which is a different test. Our guides to ChatGPT, Gemini and Microsoft Copilot do the same for those assistants.

Does Claude train on your data?

Anthropic splits its answer by product, and the split runs along the line between consumer and commercial rather than between free and paid.

ProductTrained on by defaultExceptions Anthropic states
Free, Pro, MaxOnly if you allowed itSafety review, explicit choices to opt in
Claude for Work, Team and EnterpriseNoDevelopment Partner Program
Anthropic APINoReported material, an explicit choice to opt in
Claude through Bedrock or VertexNoGoverned by that platform

Anthropic Privacy Center, “Is my data used for model training?” and “How do you use personal data in model training?”, read 19 September 2026.

For commercial products the wording is short: “We will not use your chats or coding sessions to train our models, unless you choose to participate in our Development Partner Program.” The same article adds the ordinary exception that if you explicitly report material, for instance with a thumbs up or thumbs down, that material may be used.

The commercial default is available on plans a small practice can buy, and moving to it is the change most firms have not made. Nothing on the screen tells a user which kind of account they are in, so someone has to check, account by account. Our organisations page is written for that check.

What de-identified means, and what it does not

The word that carries the consumer promise is de-identified, and it is worth reading with the same care as the rest. Anthropic says data retained for training is held in de-identified form, meaning it is separated from the account that produced it. The Privacy Act gives that word a meaning of its own, and how it differs from pseudonymised is worth knowing before either reaches your policy.

That is a real reduction in risk and it is not the same as the text being gone. A de-identified copy of a paragraph about a client is still a paragraph about a client. In disability services, de-identification is a legal test as well as a promise, and what has to come out of a progress note is a longer list than most people expect.

Identifiability is a property of the whole document rather than of the name at the top of it, which is the subject of our guide to client data and AI breach reporting. That is true of every provider, and of our own product too.

The choice you were asked to make in 2025

Consumer plans work differently because Anthropic changed them. In a post dated 28 August 2025 it told users of Free, Pro and Max that they would be asked to choose whether their chats could be used for model improvement, that new users would choose when signing up, and that existing users had until 8 October 2025 to decide.

The same post extended retention to five years for anyone who allowed it. If nobody in your practice remembers making that choice, somebody made it, and it is in Settings under Privacy.

28 Aug 2025Anthropic tells Free, Pro and Max users they must choose
8 Oct 2025the deadline for existing users to decide
Five yearsretention for anyone who allowed model improvement
Anthropic, Updates to Consumer Terms and Privacy Policy, 28 August 2025

Coding sessions count too

Anthropic’s wording throughout is “chats and coding sessions”, and the distinction is worth flagging for any practice that writes its own tools or uses a developer. A coding session carries whatever the code and the context carry, which in a professional setting can include a client’s data in a test fixture.

The consumer setting governs Claude Code used from a Free, Pro or Max account. Commercial plans and the API run on the commercial default instead, which is the opposite way round from what people assume about developer tools.

What Anthropic collects

The privacy policy, effective 10 September 2026, uses a compact vocabulary that is worth learning because every other document refers back to it.

The content you submit to the Services through these interactions, including via third-party applications, services, and content you choose to upload, integrate or interact with using our Services, are your “Inputs”. Inputs generate responses and actions (“Outputs”).

Inputs and Outputs are the category that holds a client’s file. Around them sit the usual account, device and usage records, and the policy also contemplates content arriving through applications from other companies that you connect to it, which widens what a conversation can reach, in the same way connectors do at every other provider.

Two features deserve a deliberate decision rather than a default. Connected tools can pull a document into a conversation that nobody meant to send, and projects or shared workspaces can make one person’s uploaded file visible to colleagues. Both are configuration questions for whoever runs your systems.

Shared chats and exports leave their own trail

Sharing and exporting create copies too. Anthropic documents both, sharing and unsharing conversations and exporting your Claude data, and each copy lives outside the conversation you were looking at.

A shared conversation is a link, and a link is a disclosure to whoever holds it. An export is a file on somebody’s laptop, subject to whatever that laptop is subject to. Neither is a flaw, and both are the kind of thing a practice discovers during an incident rather than before one, which is why they belong in the rules staff actually follow, not in a policy nobody reads.

How long Anthropic keeps it

Retention is where the consumer answer becomes concrete, and the numbers are published.

What is keptPlanHow longWhat triggers it
A conversation you deleteFree, Pro, MaxUp to 30 days in the back endDeleting it from your history
A de-identified copy for trainingFree, Pro, MaxUp to five yearsAllowing model improvement
Data from a feedback submissionNot split by planFive yearsRating a reply or reporting material
Inputs and outputs of a flagged conversationNot split by planUp to 2 yearsA classifier flagging a Usage Policy breach
Trust and safety classification scoresNot split by planUp to 7 yearsThe same flag
Data on the accountEnterpriseIndefinite by defaultNo custom retention period being set
Inputs and outputsCommercial, by agreementNot stored after the responseA zero data retention arrangement

Anthropic Privacy Center, “How long do you store my data?”, last updated 1 July 2026, with its articles on Enterprise retention controls and zero data retention.

Those clocks answer different questions. The 30 days are what people mean when they ask about deletion: a conversation removed from your history leaves the back end within 30 days. The five years in training pipelines apply only where model improvement was on, and Anthropic describes the retained copy as de-identified. The safety clocks belong to a different system entirely.

On Enterprise, retention becomes a setting

The consumer numbers are fixed. On the Enterprise plan they are not. Anthropic publishes an article on configuring custom data retention controls for Enterprise plans, and says that by default data is retained indefinitely unless a custom retention period is set.

Read that twice, because it runs the opposite way to what people expect from a commercial plan. The commercial tier gives you control over retention rather than a shorter default, and a firm that buys it and configures nothing has chosen indefinite. That is an administrative decision with a compliance consequence, and it is worth recording the date it was made.

Feedback has its own five years

Alongside those, Anthropic says it retains data associated with a feedback submission for five years, and that it de-links feedback from your user ID before the data is used internally.

The practical reading is the same as for ChatGPT: rating a reply is a deliberate act of sending, not a passive one. It is the most common way a careful decision to opt out gets undone, at every provider that offers the buttons.

What safety flagging does to the clocks

If an automated classifier flags a conversation as violating the Usage Policy, Anthropic says it retains inputs and outputs for up to 2 years, and the trust and safety classification scores for up to 7 years. It also says flagged conversations may be used to improve its detection models regardless of your training setting.

None of that is unusual, and every provider we have looked at has an equivalent. It is worth knowing because it is the one path where a setting you chose does not govern the outcome.

Turning it off only works from now on

The article on changing the model improvement setting is exact about the limit of the switch.

Your data will still be included in model training that has already started and in models that have already been trained, but we will stop using your previously stored chats and coding sessions in future model training runs.

That is a fair description of how model training works, and the other three providers have the same limitation. It means the value of turning training off is entirely prospective, which is a reason to make the decision before staff start using a tool rather than after.

Incognito chats sit outside the training path altogether: Anthropic says they “are not used to improve Claude, even if you have enabled Model Improvement”.

Training and transit are two different questions

The difference between the two decides whether any of the above matters for an Australian practice, and it is why our approach for organisations treats control and residency as two separate lines rather than one.

A promise not to train is a promise about one downstream use of your text. It says the words will not be folded into a future model. It does not say the text stayed in your office, that it was not stored, that no person could read it under a safety review, that it was not held under legal process, or that the computer it ran on was in this country.

What a safety review implies

One of the exceptions above is easier to follow in plain words. A conversation flagged by an automated classifier can be examined, and Anthropic says flagged material may be used to improve its detection models regardless of your training setting.

That is a sensible thing for a provider to do and it is published rather than hidden. For a practice, it means the set of people who could in principle see a client’s paragraph is not empty, on any of these services, and a policy that tells staff nobody ever reads their chats is telling them something no provider claims.

When the Privacy Act says the disclosure happens

The Office of the Australian Information Commissioner describes the moment that matters, in its Guidance on privacy and the use of commercially available AI products published 21 October 2024 and updated 17 January 2025. Its worked example is an insurance company putting a customer’s claim details into a public chatbot.

By entering the personal information into the AI chatbot, the insurance company is disclosing the information to the owners of the chatbot.

The disclosure is finished when the text arrives. Training is a second event, with a second answer. This is why “it does not train on my data” is a true sentence that settles less than the person saying it believes.

  1. Does the text reach a system outside your organisation, such as Anthropic's?

    YesThe paste is a disclosure to the owners of the chatbot, finished when the text arrives.

    NoWith protections that keep it inside, the OAIC treats it as a use rather than a disclosure.

  2. Is model improvement switched off?

    YesFuture training is ruled out. The disclosure, if there was one, has already happened.

    NoThe conversation may also go into future training runs.

The first question is the one the Privacy Act asks. The setting only answers the second.

Transit first, training second. OAIC guidance on commercially available AI products, updated 17 January 2025

The test that decides which side you are on

The regulator draws the other half of the line by asking about control, not about brand.

If your organisation is using a proprietary AI system rather than a publicly available chatbot, for example, and has protections in place to ensure that information entered into the system will not be disclosed outside the organisation (such as to the system developer), this will constitute a use rather than a disclosure of personal information.

Which side you are on turns on your contract and your configuration. A commercial Claude account with a data processing agreement is a materially stronger position on that test than a personal one, and it is still a position you have to be able to evidence in writing on the day somebody asks.

Who is the controller, and why your paperwork depends on it

Anthropic’s privacy policy names Anthropic PBC as the controller for users outside the European region. That is the position for a consumer account opened in Australia: you are a user of somebody else’s service, and they decide what happens to the data.

Who at Anthropic can read a conversation

The consumer documentation answers this directly, and it deserves the same prominence as the equivalent sentence for Gemini, where Google states that a subset of chats is read by reviewers.

By default, Anthropic employees cannot access your conversations unless: You explicitly consent to share your data with us as a part of giving us feedback.

The second exception is enforcement of the Usage Policy, and there Anthropic says only designated members of its Trust and Safety team may access the data, and only where they need it for that work. Those are different commitments from Google’s, published by each company about its own product, and the difference is the sort of thing that gets flattened into “they are all the same”.

Your paperwork depends on the plan

Anthropic’s commercial terms turn that around. When a customer creates a Claude for Work account, the customer is the controller of what its users submit, and Anthropic acts on the customer’s instructions. For a practice, that is the difference between using a service and engaging a provider. Engaging a provider is what the checklist seven law societies wrote for small and midsize firms asks solicitors to test, down to the other providers behind the vendor.

That difference should show up in two documents you already have: your engagement letter, if it says anything about how client information is handled, and your written AI policy, which is the thing an insurer or a regulator will ask to see first.

Zero data retention, and who can ask for it

Anthropic documents zero data retention arrangements for commercial customers, under which inputs and outputs are not stored after the response is returned. It is negotiated rather than switched on, and it is not a consumer feature.

It is worth naming because it is the only arrangement among the four providers that answers the storage question with a zero, and because a firm that needs that answer should know it exists rather than assuming no provider offers it. Litigators in New South Wales have a particular reason to ask, because the Supreme Court’s practice note on AI lets subpoenaed material into a tool only where the supplier is bound to confidentiality and no training.

Does Anthropic share it?

The privacy policy lists the ordinary categories, and the useful thing is to read them as a list rather than as reassurance.

Service providers and business partners

For hosting, research, fraud prevention and safety investigations.

Legal and regulatory requirements

Where Anthropic believes disclosure is reasonably necessary to comply with law or prevent harm.

Internal processing

Including review for safety, product support and incident response, in countries where Anthropic or its affiliates operate.

Multiple cloud providers

Named on its published subprocessor list rather than left implicit.

Who else may receive your data. Anthropic privacy policy, effective 10 September 2026

One line of the policy is worth having in front of you when somebody asks whether a conversation could ever be produced.

Personal data may be disclosed pursuant to regulatory or legal requirements.

The policy also names the Office of the Australian Information Commissioner as the place an Australian user can lodge a complaint, which is a small but real acknowledgement of where its Australian users sit. The regulator’s own view of the underlying activity is in the breach guide.

Where the servers are, and why routing is not residency

Anthropic answers the location question in the documentation for its commercial products, and the answer is one paragraph that says two different things.

Note that data is stored in the US. By default, we may route customer traffic to select countries in the US, Europe, Asia and Australia, unless otherwise agreed upon or at your instructions.

For the consumer plans the published answer is looser: “As a global company, we may process data in different countries where we or our partners operate.” The privacy policy adds that personal data is transferred to servers in the United States and to countries outside the European Economic Area.

Australia appears in the commercial sentence, and it is worth being precise about what it means. Routing describes where a request may travel. Storage is stated separately, and it is the United States. Those are not the same commitment, and neither of them is the commitment that matters under Australian Privacy Principle 8.

Three things that sentence does not establish are worth naming, because each of them gets read into it.

It does not say your data rests in Australia

The same paragraph says storage is in the United States.

It does not say a request is processed here

Routing names countries traffic may pass through, not where the model runs.

It does not change the recipient

That is the only thing Australian Privacy Principle 8 asks about.

What the routing sentence leaves open. Anthropic Privacy Center, commercial products documentation

APP 8 asks who received it, not where the disk is

Australian Privacy Principle 8 turns on the recipient being a person who is not in Australia. Section 16C then treats anything that overseas recipient does in breach of the principles as a breach by you. A packet that passed through a data centre in Sydney on its way to a company in San Francisco has not changed who received it. A New South Wales council has a stricter line: its Act looks at the state border.

What Anthropic commits toWhere
Storage of dataUnited States
Default traffic routingUS, Europe, Asia and Australia
Vertex AI processing regions for its modelsUS, EU, Belgium, Netherlands, Singapore, Taiwan

Anthropic Privacy Center, commercial products documentation, read 19 September 2026; Google Cloud data residency table, last updated 16 September 2026.

The platform route, and what its table actually shows

The third row is there because running a model through a cloud platform is what people reach for when they want data kept in the country. On Google Cloud’s published residency table, the options it lists for keeping machine learning processing within a region, for Anthropic’s models, are the United States and European Union multi-region locations plus Belgium, the Netherlands, Singapore and Taiwan.

There is no Australian column for those models, on a page last updated three days before this one was written. By contrast the same table does list australia-southeast1 for a small number of Google’s own models, which is covered in the guide to Gemini. That asymmetry is a fact about the platform rather than about either company, and it is the kind of detail that should be checked on the day an architecture is designed.

The rules on cross-border disclosure themselves, including the routes APP 8.2 leaves open, are set out in our guide to which AI tools you can use under the Privacy Act. The 30-day assessment clock that starts on suspicion belongs to a different regime, the Notifiable Data Breaches scheme in s 26WH, and it is covered in our guide on when a paste becomes a reportable breach. Neither is something a vendor controls.

Three things people believe that Anthropic’s documents do not say

All three come up in practice, and the documents quoted above answer each of them. Each also has a close relative among the beliefs about ChatGPT, Gemini and Copilot.

"Claude does not train on anything."

True on commercial plans by default. On consumer plans it depends on a choice made in 2025, and conversations flagged for safety are used regardless.

"Turning it off deletes what was used."

It stops future use. Anthropic says data already in a training run or a trained model stays there.

"Traffic routed through Australia means it is stored here."

The same paragraph says storage is in the United States. Routing and storage are two commitments.

Three beliefs, against Anthropic's own documents quoted on this page

None of those is a criticism of Anthropic, whose documentation is more explicit about the limits of its own switches than most commentary written about it. They are places where a summary written by somebody else quietly widened a commitment.

Claude’s privacy settings: what to change today, at no cost

The settings are quick and the decision that precedes them is the one that counts.

  1. Decide which account people sign in with. Consumer or commercial changes the training default, the retention default and who the controller is.
  2. Check the model improvement setting, in Settings then Privacy, on every account in the practice. It is per account, and staff sign in with whatever is open.
  3. Stop rating replies, or accept that reporting material puts it in front of Anthropic deliberately, for five years.
  4. Delete what should not be there, and expect 30 days rather than instant.
  5. Write down the answer, because an insurer will ask. The wording that satisfies an underwriter is its own craft, and it is in our guide to the AI questions on a cyber questionnaire.

What the Privacy Act asks, and what no setting answers

The OAIC has not banned any of these tools. Its position is a recommendation, and it should be quoted as one. Which tool you choose is therefore left to you, and what the Privacy Act actually asks of each one is the part worth working through before you decide.

As a matter of best practice, the OAIC recommends that organisations do not enter personal information, and particularly sensitive information, into publicly available AI chatbots and other publicly available generative AI tools, due to the significant and complex privacy risks involved.

The binding obligation is APP 6, which asks whether the person whose information it is would reasonably expect this use or disclosure. A client who instructed you on a family matter did not contemplate a language model, and if your engagement letter is silent, that is an argument you do not have. Family files raise the bar, because a single affidavit can touch almost every category the Act treats as sensitive, each with stricter rules than a name.

The regulator has already written your scenario

In December 2025 the regulator wrote again on generative AI in the workplace and named the products by brand, Claude among them.

Its case study is an employee uploading a customer’s hardship application, with health and family details, against the employer’s own policy. That is the scenario we build for, described by a regulator rather than a vendor.

Whichever tool you use, your cyber insurer will ask about it, so it pays to know what a cyber policy covers in Australia.

What none of this fixes

Every control on this page, Claude’s privacy settings included, governs what Anthropic does after your text arrives. None of them governs whether it arrives.

That gap is where our own software sits, and it is worth being exact about what it does. Nonimo runs on the machine, replaces identifiers in the text before it is sent anywhere, and shows what it changed so a person can overrule it.

It pseudonymises: the mapping can be reversed, and it is kept encrypted on the user’s own computer, which is a smaller claim than the word anonymisation makes. What it keeps is set out on Nonimo’s security page, and the licence terms on the licence page.

If you buy nothing, three things still help: decide which accounts people use, write one page naming what may never be pasted, and name the person to call when someone does it anyway. Comparing tools comes afterwards, which is the right order.

Sources

Every page below was open in front of us on 19 September 2026.

Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.

Common questions

Does Claude train on your conversations?

On Free, Pro and Max, only if you chose to allow it in Claude's privacy settings, and conversations flagged for safety review are used regardless. On Claude for Work and the Anthropic API, Anthropic says it does not train on your data unless you join its Development Partner Program.

How long does Anthropic keep my chats?

Deleted conversations leave its back end within 30 days. If you allowed model improvement, it may keep data in de-identified form for up to five years in its training pipelines. Material flagged for safety runs on separate and longer clocks.

What happens if I turn model improvement off?

Anthropic says it stops using your previous and new chats for future training. It also says data already inside a training run, or inside a model already trained, stays there. Turning it off only works from now on, not retrospectively.

Are Incognito chats used for training?

Anthropic says Incognito chats are not used to improve Claude even when model improvement is enabled. That is a statement about training. It is not a statement that the text never left your office, which is the question the Privacy Act asks first.

Can Claude data be kept in Australia?

Anthropic says data is stored in the United States and that it may route customer traffic to select countries in the US, Europe, Asia and Australia. Routing is not residency. On Google Cloud's Vertex AI, the options for keeping processing within a region, for Anthropic models, do not include Australia.

Who is responsible for the data, Anthropic or my firm?

It depends on the plan. For consumer plans Anthropic PBC is the controller. Under its commercial terms, a Claude for Work customer is the controller of what its users submit, and Anthropic acts on the customer's instructions.

Does Anthropic hand data to authorities?

Its privacy policy, effective 10 September 2026, says it may disclose personal data pursuant to regulatory or legal requirements, and where it believes disclosure is reasonably necessary to comply with law or prevent harm. That is the ordinary position for a cloud service.

Does a thumbs up send my whole conversation?

Anthropic says that if you explicitly report material, for example through its feedback buttons, that material may be used to train its models, and that it keeps data associated with a feedback submission for five years. It de-links feedback from your user ID first.

Is Claude safe for client files in an Australian practice?

No provider setting answers that. Australian Privacy Principle 6 governs the disclosure that happens when the text is sent, and Australian Privacy Principle 8 turns on the fact that the recipient is overseas. Both apply whether or not training is on.