Somebody at your business is pasting customer details into an AI tool right now.
Whether that matters depends on which tier the account is on, not which brand it is. And "not used for training" is a narrower promise than most people hear.
John "Holliday" Mahlow
Founder, Cursive Media
Someone in your business has pasted a customer email into a chatbot to get help writing a reply. Probably this week. Almost certainly without asking anyone.
That is not a scandal and the answer is not to ban it, which never works and mostly teaches people to do it on their phones instead. It is worth understanding what actually happens to that text, because the honest answer is more specific than either the panic or the reassurance.
The tier is the variable, not the brand
The question people ask is whether a given company trains on your data. The question that determines the answer is which account you are using.
Both major vendors draw the same line in roughly the same place. OpenAI states it does not train on business data by default, covering ChatGPT Team, Enterprise, Edu and the API platform, with business customers opted out unless they choose otherwise. Anthropic's consumer documentation says chats are not used to improve its models unless you actively turn that on in Privacy Settings, and keeps commercial terms in a separate document entirely.
So the free login your receptionist opened and the paid business account your operations manager set up are governed by different documents, and only one of those was chosen by anybody.
Check yours rather than trusting a summary, including this one. These policies change, and a blog post is a snapshot of a page that gets edited.
"Not used for training" is narrower than it sounds
This is the part that gets lost, and Anthropic's consumer documentation is a good example precisely because it is unusually clear about it.
Alongside the opt-in for model improvement, it notes that conversations flagged for safety review may be analysed to improve policy enforcement, and that thumbs up or down feedback is stored for up to five years, de-linked from your identity, and used for research and model training. Incognito chats are excluded from model improvement even when the setting is on.
None of that is sinister. It is normal operational practice and it is disclosed. But it means the sentence people repeat, that their data is not used for training, is doing less work than they think: not training is not the same as not stored, not reviewed, and not retained.
If your standard is that nobody outside the business could ever see a given piece of text under any circumstance, no cloud tool of any kind meets it, and AI is not the interesting part of that problem.
The real exposure is the account, not the model
Training policy is the thing everybody debates. Account hygiene is the thing that actually goes wrong.
A staff member signs up with a personal address, builds up months of chat history containing customer names, addresses, job details and quoted prices, and then leaves. That history goes with them, into an account your business cannot audit or switch off. No training policy on earth addresses that, and it is the same structural mistake as letting a vendor own your Google profile or registering your domain under somebody's personal email.
Business tiers exist mostly to solve this. You get central administration, and a contract that names your company rather than an individual.
That is worth more than the training clause everyone reads first.
What should not go in regardless
Some categories are not a settings question. Card numbers and bank details, anything covered by a signed confidentiality agreement, health information, and identity documents belong nowhere near a general-purpose chat window, whatever tier it is on.
If your industry is regulated, that is a compliance conversation with someone qualified rather than a decision to make from a blog post. Nothing here is legal advice.
For ordinary business text, a workable habit is to strip the identifying parts before pasting. "Draft a reply to a customer whose install ran two days late" gets you the same output as pasting the thread with their name, address and invoice number attached.
A one-page rule beats a ban
Write down which tool the business uses and on which account, then list what may never be pasted into it. One page, no policy language, given to everyone who touches a customer. The point is not legal cover; it is that most of this happens because nobody was ever told there was a rule, and people improvise sensibly right up until the moment they improvise badly. A page on the wall converts a judgement call into a known answer, which is the only thing that survives a busy Tuesday.
Then go into the settings today, look at the model-improvement toggle with your own eyes, and screenshot it. Defaults get revised, and the screenshot is what tells you later whether something changed underneath you.
If you are weighing up where AI genuinely belongs in your stack and want the data questions answered before anything gets built rather than after, book a strategy call. It is a much shorter conversation at the start of a project than at the end of one.
John "Holliday" Mahlow
Founder, Cursive Media
