The honest answer is that it depends which plan you're on, and the difference between them is bigger than most people using them realize.
The screen looks the same. The agreement behind it is not.
What the providers say they do
Worth reading from the source, because this is a place where general impressions are out of date.
Business, team and enterprise plans. Anthropic's commercial terms say plainly that Anthropic may not train models on customer content from the services. OpenAI says its business, enterprise and API products are not used to train its models by default, with sharing available as an opt-in.
Free and personal accounts. A different agreement. Anthropic's consumer plans use your chats to improve the models when you allow it, which is a setting a person can change without telling anybody. That's the crux of the problem: it's an individual's choice about your company's information.
The API. The strictest option, and the one anything built for you would use. Not used for training, and retention is configurable, down to none for qualifying customers.
Checked against both companies' own terms on 2 September 2026. These policies change, so check them again before making a decision that depends on one.
The risk nobody plans for
It isn't the provider. It's that somebody on your team has a personal account.
The common version is completely ordinary. Somebody is stuck on a difficult reply to a customer, so they paste the email into whichever tool they use at home, get a good draft, and send it. Nothing malicious happened and your customer's details are now in an account your company has no agreement covering and no ability to audit.
That's the actual exposure in most small businesses, and it's a policy problem rather than a technology one.
What's genuinely fine
Worth saying, because caution about this sends some people too far the other way.
- Your own writing. Service descriptions, a job advert, a rewrite of a page.
- Anything already public. Your prices, your hours, your website copy.
- Work with the names taken out. A contract with the parties replaced, a complaint with the customer anonymized.
- Anything on a proper business plan, in the ordinary run of work. That's what the agreement is for.
What needs more thought
- Health information. Different rules, and in most cases a specific agreement with the provider.
- Anything covered by a contract with your own customer. Plenty of commercial agreements restrict who may process the data you hold. Read yours before assuming.
- Payment details and credentials. Never, in any tier. There's no version of this that's fine.
- Personal records at volume. One customer's address in a draft reply is different from uploading your whole customer list, both practically and legally.
Four rules worth setting
Short enough that people will follow them, which matters more than being thorough.
- One account, paid for by the company. This single change fixes most of the exposure, and it costs $20 to $25 US per person a month.
- Never paste credentials or payment details. No exceptions and no judgement calls.
- Customer names come out when they don't need to be in. Most of the time the question works without them.
- Say which tools are approved. People use something. If you don't name one, they'll pick their own, and you won't know which.
A rule people can remember beats a policy document nobody opens.