Paying for ChatGPT Plus does not switch off training. Neither does paying for Claude Pro, Perplexity Pro or a personal Copilot. So, does ChatGPT train on your data? On every consumer tier of every major chatbot the answer in September 2026 is yes, by default, and the switch that stops it sits three clicks deep in a menu most lawyers have never opened.
Bans are the alternative, and they fail: when Hill Dickinson blocked ChatGPT, the ICO replied that “the answer cannot be for organisations to outlaw the use of AI and drive staff to use it under the radar” (BBC, February 2025). Samsung banned it in 2023 after a source-code leak; Clifford Chance never did and rolled out enterprise tools instead. Settings travel with the account. Here are the click-paths for five tools, checked against the vendors’ pages this month, and then the footnotes.
The short answer, tool by tool
| Tool (consumer tier) | Trains by default? | Where the switch is | After you opt out |
|---|---|---|---|
| ChatGPT Free, Go, Plus, Pro | Yes | Settings > Data Controls > “Improve the model for everyone” | Deleted chats gone within 30 days, barring legal or security holds |
| Claude Free, Pro, Max | Yes, since 28 Aug 2025 | Settings > Privacy > “Help improve Claude”; or Incognito | 30 days (five years if left on); flagged chats up to 2 years |
| Gemini (personal account) | Yes (“Keep Activity”) | Google Account > Gemini Apps Activity off | 72 hours; human-reviewed chats up to 3 years |
| Copilot (personal account) | Yes | Settings > Privacy > “Training on conversation activity” | Future chats only; advertising, safety, security and compliance uses continue |
| Perplexity Free, Pro, Max | Yes (“AI Data Retention”) | Account > Preferences > “AI data retention” | Data already collected “cannot be deleted or removed” |
Business tiers do not train by default: ChatGPT Business and Enterprise, Claude Team and Enterprise, Gemini for Workspace, Copilot with enterprise data protection and Perplexity Enterprise. The small-firm comparison is in ChatGPT Business vs Enterprise for law firms.
ChatGPT: Data Controls, Temporary Chat, memory and shared links
The switch. Profile icon > Settings > Data Controls > turn off “Improve the model for everyone”; on mobile, side-bar > profile > Data Controls. OpenAI also honours a privacy-portal request, “Do not train on my content” (OpenAI Data Controls FAQ). Business (called Team until 29 August 2025), Enterprise, Edu and the API do not train by default: “By default, we do not use your business data for training our models.”
Temporary Chat and memory. Temporary Chats “Aren’t used to train our models; May be reviewed only to monitor for abuse; Don’t get saved in your history and don’t create memories”, and are “deleted from our systems after 30 days”. Memory, the profile ChatGPT builds across chats, is separate; Sterling Miller’s in-house rule is to “Regularly clear the memory” (Ten Things).
Deletion. A deleted chat is “scheduled for permanent deletion from OpenAI systems within 30 days, unless … OpenAI must retain it longer for security or legal obligations” (OpenAI retention policy). Archiving is not deleting.
Shared links. In July and August 2025 roughly 4,500 shared ChatGPT conversations turned up in Google Search, some with names and business details, after users ticked a “Make this chat discoverable” box. OpenAI withdrew the feature as “a short-lived experiment” (Search Engine Journal), but deleting a chat still does not delete its share link. If you have ever sent a client a ChatGPT link, delete the link itself in Data Controls. The rest of the product is in ChatGPT for lawyers.
Claude: the training toggle and the five-year retention
Anthropic changed its consumer default on 28 August 2025. Free, Pro and Max users now train Claude unless they opt out, and Anthropic is “extending data retention to five years, if you allow us to use your data for model training”; opt out and you keep “our existing 30-day data retention period” (Anthropic). The switch: Settings > Privacy > “Help improve Claude” off. Or use Incognito, the ghost icon: “Your Incognito chats are not used to improve Claude, even if you have enabled Model Improvement.”
Two carve-outs survive the opt-out. Anthropic’s Privacy Policy, effective 10 September 2026: “Even if you opt-out, we will use Inputs and Outputs for model improvement when: (i) your conversations are flagged for safety review … or (ii) you’ve explicitly reported the materials to us” (Anthropic Privacy Policy). Flagged conversations are kept for up to two years, and you do not decide what gets flagged.
Team, Enterprise, the API, Bedrock and Vertex do not train by default. Feedback, though, stores “the entire related conversation” for up to five years, so owners should disable “Rate chats” under Organization settings > Data and Privacy; Claude for lawyers has the rest.
Gemini: Apps Activity and the 72-hour window
Google’s consumer Gemini page is blunt: “Please don’t enter confidential information that you wouldn’t want a reviewer to see or Google to use to improve our services.” Switch “Keep Activity” off under Gemini Apps Activity and chats are kept for 72 hours only; but a portion of chats is human-reviewed, and “Reviewed chats: Retained for up to 3 years, disconnected from your account” (Gemini Apps Privacy Hub). On a Workspace account the position flips: “Your content is not human reviewed or otherwise used for Generative AI model training outside your domain without permission.”
Copilot: personal opt-out vs the work tenant
Two products share a name. On a personal Microsoft account, Copilot conversations may be used to “Train our generative AI models” unless you switch off “Training on conversation activity” and “Training on voice conversations” under profile > Settings > Privacy; the opt-out covers future conversations only and does not stop use “for advertising, digital safety, security, and compliance purposes” (Microsoft Copilot privacy controls).
On a work tenant with enterprise data protection there is no setting to find, because the promise is contractual: “prompts, responses, and data accessed through Microsoft Graph aren’t used to train foundation models”. The risk there is oversharing: “Permissions set years ago and never revisited now define what an AI tool will surface on demand” (ABA Law Technology Today, 2026). A lawyer logged into the Copilot app with a personal account is on the training tier; the Office logo proves nothing.
Perplexity: the AI Data Retention toggle
“For Free, Perplexity Pro and Perplexity Max users, AI Data Retention is enabled by default.” Switch it off under Account > Preferences > “AI data retention”. Then: “Opt-outs only apply to data collected after the opt-out date; Previously collected training data cannot be deleted or removed.” Enterprise is different (“your data is never used for AI training purposes”), and downgrading to Free switches the default back on (Perplexity Help Center). More in Perplexity for lawyers.
What opting out does not do
Four channels stay open after you opt out:
- Abuse review. Temporary Chats “may be reviewed only to monitor for abuse”; business tiers use “specialized third-party contractors” for the same purpose. “No training” was never “no human eyes”.
- The 30 days. Deleted means scheduled for deletion. Every vendor here keeps deleted or temporary content for up to 30 days.
- Legal holds. From 13 May to 26 September 2025 a preservation order in the New York Times litigation forced OpenAI to keep every deleted chat of Free, Plus, Pro and Team users; only Enterprise, Edu and zero-data-retention API customers were excluded, and 20 million de-identified logs were later ordered produced.
- Privilege. In United States v. Heppner (S.D.N.Y. 2026) a defendant’s consumer-Claude exchanges were held to be protected by neither privilege nor work product, and Anthropic’s consumer privacy policy was part of the reasoning. See does using ChatGPT waive attorney-client privilege.
The daily hygiene checklist
Sterling Miller’s rules fit on an index card: “Use ‘temporary chat’ … Regularly clear the memory. Turn off ‘Improve model for everyone.’ Delete all chats every day or on a regular timeframe.” Add these: check which account you are logged into before you type; never rate a chat containing client material; delete share links, not just chats; anonymise before you paste, even on a no-training tier; and re-check the settings quarterly, because defaults change.
Three prompts make the habit stick. The first follows Brooke Loesby’s test in the ABA Journal: not “My client Sarah is suing her business partner for embezzling $400,000” but “I am working on a partnership dispute involving allegations of financial misconduct”.
Run this on the firm's no-training tier or a local model, never on a consumer chatbot.
Here is a question I want to put to a general-purpose AI tool: [paste question].
Rewrite it so it contains no name, company, place, date, amount, case number or unusual fact that would let a reader infer which matter or client it concerns, while keeping the legal issue intact. Generalise contextual identifiers (an unusual job title, a small town) to a neutral description.
Output: (1) the abstract question; (2) every detail you removed and what replaced it, so I can re-apply them offline.Using browsing, open the current data-controls or privacy page for ChatGPT (Data Controls FAQ), Claude (privacy.claude.com model-training article), Gemini (Gemini Apps Privacy Hub), Microsoft Copilot (privacy controls page) and Perplexity (data collection article).
For each, quote verbatim the sentence stating the training default for consumer accounts, the opt-out path, and retention after opt-out. Compare against <on_file>[paste last quarter's table]</on_file> and list every change in wording, old and new sentence side by side. If a page will not load, say so rather than reconstructing it from memory.Draft a five-question multiple-choice quiz for lawyers joining a [12-lawyer] firm, testing: which ChatGPT tiers train by default; the difference between a personal and a work Copilot account; what Temporary Chat does and does not do; whether Claude's opt-out covers safety-flagged chats; what happens to a share link when the chat is deleted. One correct answer per question, with a one-sentence explanation naming the vendor page it rests on. Then a one-page checklist of the five opt-out click-paths.Where to go next: for the plan-level view, read is ChatGPT confidential for lawyers and the other confidentiality guides; to turn the checklist into firm rules that name approved tiers, use the law firm AI policy template. Knowing which tier of each tool you are on is a five-minute settings exercise; in AI Lab for Lawyers we do it live, on participants’ own accounts, and then practise anonymising a real document.
Frequently asked questions
Does ChatGPT use my conversations for training?
Yes on Free, Go, Plus and Pro, unless you turn off Improve the model for everyone under Settings > Data Controls. Paying for Plus or Pro does not change the default. ChatGPT Business, Enterprise, Edu and the API do not train on your data by default. Temporary Chats are not used for training but are kept for up to 30 days and may be reviewed for abuse.
How do I stop ChatGPT training on my data?
Click your profile icon, then Settings, then Data Controls, and switch off Improve the model for everyone; the setting syncs across devices. On mobile the path runs from the side-bar to your profile to Data Controls. OpenAI also honours a privacy-portal request titled Do not train on my content. For client work, move to ChatGPT Business or Enterprise, where no-training is the default and a data processing agreement is available.
Is Temporary Chat really private?
Partly. OpenAI says Temporary Chats are not used to train its models, do not appear in your history and do not create memories. But they are deleted from OpenAI's systems only after 30 days and may be reviewed to monitor for abuse. During the 2025 New York Times preservation order, chats of Free, Plus, Pro and Team users were retained regardless. Treat it as a privacy improvement, not a confidentiality guarantee.
Does Claude train on my data?
On Free, Pro and Max, yes by default since 28 August 2025, with data retained for up to five years if you leave the toggle on. Switch it off under Settings > Privacy > Help improve Claude and retention drops to 30 days. Team, Enterprise, API, Bedrock and Vertex use do not train by default. Even after opting out, conversations flagged for safety review or explicitly reported by you can still be used.
Can deleted ChatGPT chats be recovered?
Not by you, but they are not gone at once. A deleted chat leaves your account immediately and is scheduled for permanent deletion within 30 days, unless it has already been de-identified or OpenAI must retain it longer for security or legal obligations. Between May and September 2025 a court order forced OpenAI to keep deleted chats of Free, Plus, Pro and Team users; 20 million de-identified logs were later ordered produced.
Does Microsoft Copilot train on my data?
It depends on the account. With a personal Microsoft account, conversations may be used for training unless you switch off Training on conversation activity under Settings > Privacy, and the opt-out does not cover advertising, safety, security and compliance uses. On a work tenant with enterprise data protection, prompts, responses and data accessed through Microsoft Graph are not used to train foundation models, and there is no setting to find.