tuesday, october 6, 2026 · the day's ai, attributed published by trilot llc · wyoming
guide · running the business

What your AI tools keep, and for how long

Work out what each AI tool in your stack keeps, who is allowed to read it, and which of those promises somebody else can suspend.

Published 2026-09-04 · Updated 2026-09-04 · Read 10 min · Reviewed by Rami Steitieh

Verified 2026-09-04 · Rami
on this page · 0 / 0 checked

You have pasted a client’s contract into a chat window to get the payment terms summarised. You have dropped a spreadsheet of customer emails into a tool to have the duplicates cleaned out. You have asked an assistant to rewrite a performance review with the employee’s name still in it. Then someone asked whether that was allowed, and you found you could not say what happens to that text after the answer comes back.

The answer depends on four separate things, and almost everyone collapses them into one. This guide pulls them apart and shows you where the current answer sits for the tools you already use. It is not for a company with a compliance function and outside counsel, who have a process for this and do not need a web page. It is for the solo operator or small team running the same software with none of that scaffolding, who would like to stop guessing.

Storing, training, reading and transmitting are four different things

The first is training: whether the vendor uses what you typed to improve its models. This is the one everyone asks about, and it has the clearest answers, because vendors write it down.

The second is retention: how long a copy of your text sits on the vendor’s systems, and what happens when you press delete. Retention is separate from training. A vendor can promise never to train on your data and still hold it for a year.

The third is human review: which people, under what conditions, are allowed to read it. The platforms in this guide all describe a path that ends with a person. OpenAI names specialised third-party contractors who review for abuse and misuse [4]. Google tells you not to type anything you would not want a reviewer to see [6]. This is the part that sits in the paragraph most people scroll past.

The fourth is transmission, and it is the one no setting changes. Even at the strictest end of the scale, where OpenAI offers zero data retention for eligible API endpoints to customers with a qualifying use case [4], the request still travelled to a machine you do not own and was processed there. If your obligation is that certain material must not leave your control at all, no retention setting satisfies it. Not stored is not the same as not sent, and the two get confused constantly.

Anthropic’s privacy policy, effective 8 July 2026, says that “We may use your Inputs and Outputs to train and improve Anthropic AI models, unless you opt out through your account settings” [1]. The opt-out is not absolute. The same policy says that even if you opt out, Inputs and Outputs will be used for model improvement when “your conversations are flagged for safety review to improve our ability to detect harmful content, enforce our policies, or advance AI safety research” [1].

Now read the commercial side. Anthropic’s Commercial Terms, effective 17 June 2025, state flatly that “Anthropic may not train models on Customer Content from Services”, and that the customer “retains all rights to its Inputs” and “owns its Outputs” [3]. OpenAI’s enterprise privacy page, updated 8 January 2026, says “We do not train our models on your data by default” for its business offerings [4]. Google’s Gemini Apps Privacy Hub takes the opposite tack for the consumer product and simply warns you off: “Please don’t enter confidential information that you wouldn’t want a reviewer to see or Google to use to improve our services” [6].

The pattern is consistent across these vendors. On the consumer tier, the default points toward use, and you are expected to find a toggle. On the commercial tier, the default points away from use, and it is written into a contract rather than a settings page. Same brand, same model, different legal object. If your work involves other people’s information, the tier you are logged into is a more important fact than the model you selected.

A retention promise is a decision, not a property of the system

In 2025 a court in the New York Times litigation ordered OpenAI to retain consumer ChatGPT and API customer data indefinitely. OpenAI opposed it publicly, saying “This fundamentally conflicts with the privacy commitments we have made to our users” [5]. The order covered ChatGPT Free, Plus, Pro and Team, and API customers without a zero data retention agreement. It did not cover ChatGPT Enterprise or ChatGPT Edu customers, or API customers using zero data retention endpoints [5]. In an update dated 22 October 2025, OpenAI said it was no longer under that order, that its obligations under it ended on 26 September 2025, and that deleted conversations and API data are again removed within 30 days [5]. A defined set of user data from April to September 2025 is still held under legal hold, accessible only to a small audited legal and security team, and OpenAI says that data “will not be turned over to the New York Times, the Court, or anyone else at this time” [5].

Take the news out and the structure remains. A published retention window describes what a vendor does when nothing external forces its hand. It is a commitment, not a physical limit, and something outside your relationship with the vendor can suspend it for as long as the suspension lasts. That is not a scandal and it is not unique to any one company. It is what a promise is.

Two practical things follow. The tiers exempted from that order were the ones with contracts behind them, which is a fair description of what a contract buys. And whatever a vendor cannot produce is the only material that is genuinely out of reach of a future demand.

The delete button governs the copy you can see

Deletion is usually described in two stages, and the second one is where the surprises live. On Anthropic’s consumer products a deleted conversation is removed from your chat history immediately and deleted from back-end storage systems within 30 days [2]. That is the ordinary path. The exceptions are longer. If a chat is flagged by automated trust and safety systems as violating the Usage Policy, inputs and outputs are retained for up to 2 years and trust and safety classification scores for up to 7 years [2]. Press the thumbs up or thumbs down button, or file a bug report, and data associated with that submission is retained for 5 years [2]. If you have allowed your chats to improve the model, data may be retained in de-identified form for up to 5 years in model training pipelines [2].

Google’s numbers are shaped differently. Gemini Apps Activity auto-deletes after 18 months by default, and you can change that to 3 months or 36 months or switch auto-delete off entirely [6]. Temporary chats, and chats you have when Keep Activity is off, are retained with your account for 72 hours so the service can respond to you [6]. Then the clause that matters most: chats reviewed by human reviewers, along with related data such as your language, device type, location information or feedback, “are not deleted when you delete your activity. Instead, they are retained for up to three years” [6].

That is the general shape everywhere. Deleting removes the copy in your interface and starts a clock on the copy in ordinary storage. It does not reach the copies that were pulled out of the ordinary path for review, and reviewed material is by definition the material somebody already found interesting. OpenAI describes the access side of the same process for API business data: access is limited to authorised employees who require access for engineering support, investigating potential platform abuse and legal compliance, and to “specialized third-party contractors who are bound by confidentiality and security obligations, solely to review for abuse and misuse” [4]. The confidentiality obligation is real. So is the reading.

Every hop between you and the model has its own terms

Most small teams do not send data to one vendor. They send it through an automation platform to a vendor, or through a note-taking app that calls a vendor, and each hop has its own policy and its own clock.

Zapier is a fair illustration because its terms are explicit about the division. For content moving in and out of Zap workflows, “you, the customer, are considered the ‘data controller’ of that data from a privacy perspective”, and “Zapier is the ‘data processor’” [7]. Zapier holds Zap content and history on its own schedule: on the first Monday of each month it deletes old Zap content and history, which works out at up to 69 days before that sweep and at least 29 days after it, and customers on Company or Enterprise plans can set a custom retention period of between 7 and 30 days [7]. Zapier also says it engages third-party subprocessors and affiliates to help provide the service, and that all of its subprocessors “have undergone an internal legal and security review” [7]. The same structural question applies to every other platform that passes your text onward.

So a document routed from your inbox through an automation platform to a model has at least three retention clocks running on it, only one of which you were thinking about. If you are in scope of the GDPR, this is also the point where the law is specific. Article 28(2) says that “The processor shall not engage another processor without prior specific or general written authorisation of the controller” [8]. You are the controller in that sentence. The authorisation is something you gave, probably by accepting terms, possibly without reading which subprocessors were on the list.

Work backward from the obligation, not forward from the settings page

The wrong way to do this is to open the privacy settings of each tool and tighten everything you can find. You end up with a tidy settings page and no idea whether it is sufficient, because sufficiency is defined somewhere else.

Start from the duty instead. Under the GDPR, a controller “shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation” [8], and that processing must be governed by a contract setting out “the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects” [8]. That is the shape of the answer you need for every professional obligation, whether it comes from data protection law, a professional body, or a clause in a client agreement. Name the duty, then find the document that satisfies it.

The document is usually a data processing addendum, and both major vendors point at one. OpenAI says it is able to execute a DPA with customers “for their use of ChatGPT Business, ChatGPT Enterprise, and the API in support of their compliance with GDPR and other privacy laws” [4]. Anthropic’s Commercial Terms say that data submitted through the services will be processed in accordance with the Anthropic Data Processing Addendum, incorporated into those terms by reference [3]. Note what each list is attached to. OpenAI names business products and the API, not a personal subscription [4], and Anthropic’s addendum sits inside its commercial contract rather than its consumer policy [3]. That is the real reason the tier matters.

Then apply the blunt test to each workflow. Tell the person whose information is in that prompt exactly where it went, how long a copy exists, and who is permitted to read it. If saying that out loud would surprise them, you have found the workflow to fix first, and the fix is usually either a different tier or a different amount of information in the prompt.

checklist
Auditing one AI workflow
0 of 8 · saved in this browser only
calculator
Conversations still sitting in vendor storage
— conversations

Chats per working day × working days inside the window, counting 22 working days per 30 calendar days. Ignores the longer windows that apply to flagged or reviewed content. Computed in the page; nothing is sent anywhere.

What still goes wrong

Every number in this guide has an effective date attached to it, and those dates are recent. Anthropic’s privacy policy took effect on 8 July 2026 [1]. OpenAI’s enterprise privacy page was updated on 8 January 2026 [4]. Anthropic’s Commercial Terms date from 17 June 2025 [3]. Whatever you verified about a vendor a year ago is now a historical fact about that vendor. The audit is not a one-off, and there is no version of this that stays done.

You also cannot verify any of it from outside. Everything above is a published statement about internal practice, and reading it carefully gets you an accurate picture of what a company has committed to, not proof of what its systems do. That is a real limit, and it is the honest reason the transmission question deserves more weight than it usually gets. The strongest control available to a small team is not a setting. It is deciding that certain material does not go into the prompt in the first place, which costs you some convenience and nothing else.

Finally, none of this answers the question underneath. Your client, your patient or your employee did not choose the vendor, has probably never read its retention schedule, and in most cases was not asked. Getting the tier right and the addendum signed makes you compliant with your own obligations. It does not make the other person informed, and if you would rather they did not find out from someone else, telling them is a separate piece of work that no settings page does for you.

sources
  1. 01Anthropic — Privacy Policy (effective 8 July 2026)anthropic.com
  2. 02Anthropic — How long do you store my data?privacy.claude.com
  3. 03Anthropic — Commercial Terms of Service (effective 17 June 2025)anthropic.com
  4. 04OpenAI — Enterprise privacy (updated 8 January 2026)openai.com
  5. 05OpenAI — How we're responding to The New York Times' data demandsopenai.com
  6. 06Google — Gemini Apps Privacy Hubsupport.google.com
  7. 07Zapier — Data privacy at Zapierzapier.com
  8. 08GDPR — Article 28, Processorgdpr-info.eu
next guide
Auditing an AI tool you did not build
10 min · verified 2026-09-05
related guides