netzstrategen AI Operations.
Strategy

What AI Providers Do With Your Data: Privacy Terms Compared

Published on 6/26/2026 · André Hellmann

The most common data privacy question about AI is: “What happens to my data?” The honest answer: it depends less on the provider than on the access tier. The same provider treats data in a free account completely differently than under a business contract. This comparison shows where the difference sits — and what matters for ChatGPT, Claude, Gemini, and Copilot.

Positioning

Discuss the next step in a free diagnostic call. Book a call →

Contents

The decisive difference: consumer vs. business

The most important line runs not between providers but between access tiers. In a consumer account (free or personal subscription), inputs are often used for training by default at the major providers, unless you opt out. In business, enterprise, and API tiers, training on customer data is excluded by default.

Anyone using AI in a company should therefore never work through private free accounts. Switching to a business tier is the single biggest data privacy lever — regardless of provider.

The four comparison dimensions

Providers can be compared cleanly along four questions:

  • Training: Are inputs used for model training — and in which tier?
  • Retention: How long is data stored?
  • Data location: Is data processed in the EU, is there an EU data region?
  • Contract: Is there a data processing agreement (DPA) and enterprise controls?

The providers at a glance

As of 2026 — and explicitly noting that terms change fast; always check current provider documentation before deployment.

  • OpenAI / ChatGPT: Consumer (Free, Plus, Pro) trains on inputs by default, with opt-out in Data Controls. Business, Enterprise, and Edu do not train by default. The API does not train and retains inputs for around 30 days for abuse monitoring; Zero Data Retention is available for Enterprise (Source: OpenAI, 2026).
  • Anthropic / Claude: Since August 2025, Anthropic uses consumer chats (Free, Pro, Max) for training unless you opt out — with retention up to five years when enabled. Commercial tiers (Team, Enterprise, API, Bedrock, Vertex) are exempt. Note: conversations flagged for safety review may be used regardless of opt-out under the updated policy (Source: Anthropic, 2025/2026).
  • Google / Gemini: Workspace and enterprise data is not used for training and not reviewed by humans. In free consumer Gemini, training is on by default, with opt-out (Source: Google Workspace, 2025).
  • Microsoft / Copilot: Prompts, responses, and data accessed via Microsoft Graph are not used to train the foundation models; the EU Data Boundary applies. Important caveat: since January 2026 Microsoft uses Anthropic as a subprocessor — those models sit outside the EU Data Boundary commitment (Source: Microsoft Learn, 2026).
  • European and open-source options: Providers like Mistral as well as open-source models and self-hosted AI are the lever for maximum data control and digital sovereignty.

It is not the provider that decides on data privacy first, but the access tier and the contract.

The Cloud Act factor

With US providers, one residual question remains even in the enterprise tier: the US Cloud Act can grant US authorities access to data held by US companies — even when stored in the EU. EU data regions and the EU-US Data Privacy Framework mitigate this but do not fully resolve it. For especially sensitive data, European or self-hosted models are the more consistent answer. More on this under data residency.

What this means for provider choice

Three consequences:

  1. Never work through consumer accounts. A business or enterprise tier with a DPA is mandatory.
  2. Choose the model by sensitivity. Everyday tasks on established business tiers; highly sensitive data on EU/self-hosted solutions.
  3. No lock-in. Keeping models swappable lets you react to changed terms. At netzstrategen this is part of AI Operations — the best model per task, sensitive data stays in-house. How to set this up in practice is shown in Configure AI for data privacy; which risks are real is assessed in AI & data privacy: which risks really count.

Frequently asked questions

Does ChatGPT train on my data?

In a consumer account, yes by default, unless you opt out in Data Controls. In Business, Enterprise, and via the API, not by default (Source: OpenAI, 2026).

Is Claude or ChatGPT more privacy-friendly?

In the business tier there is little between them: neither trains on customer data there. The relevant difference sits in the consumer space and in details like retention and EU data region — and it changes constantly.

Is an enterprise contract enough for GDPR compliance?

It is the foundation (DPA, no training use), but not everything. Legal basis, data minimization, data location, and the Cloud Act factor belong to it. Where the biggest lever sits is shown in a free diagnostic call.

Sources

What's next