Check seven things in the terms for the plan you'll actually use: whether your inputs train AI models, how long chats and files are kept, whether people can read them, which companies receive them, who owns inputs and outputs, what security evidence exists, and how the terms can change. Consumer and business plans often answer differently.
Allow about 30 minutes per tool, and start from the account, not the brand. A member of staff pasting client notes into a personal login is covered by the consumer terms, whatever your company contract for the same assistant says. This is practical guidance for choosing tools, not legal advice.
Open the document that actually governs your plan
An AI tool may publish half a dozen documents, and the one that turns up first in a search is often the wrong one for a business. Before reading anything, list what exists:
- Privacy policy. How the vendor handles personal data. Often written mainly for individual, consumer accounts.
- Terms of use. The contract for consumer accounts.
- Business or commercial terms. The contract for team, business, enterprise and API plans. For those plans it usually takes the place of the consumer documents where your content is concerned.
- Data processing agreement (DPA). The contract covering personal data you put into the tool, such as customer or staff details. What to check in an AI vendor's DPA covers it clause by clause.
- Usage policy. What you're not allowed to do with the tool.
- Trust or security centre. Certifications, security reports, and usually the list of sub-processors.
- Help-centre articles on data controls. Where the real setting names live, and often the clearest plain-English statements.
Why this matters: in 2025 Anthropic changed how it handles chats for Claude Free, Pro and Max, letting users choose whether chats train its models and keeping them for up to five years if they agree. That change didn't apply to Team, Enterprise or API use, which sit under its commercial terms. Anyone who read only one set of documents could easily have got the wrong answer for the other kind of account. Check the plan name printed in each document before you rely on it.
The seven checks, in the order I'd read them
For each check: what to look for, what's fine, what should worry you, and how to confirm it.
1. Is your content used to train or improve models?
Look in the business terms and the help centre first, then the privacy policy. Fine: "not used for training by default" in the terms that govern your plan, or a clear setting you control on a consumer plan. Worry: a promise that covers "your data" but not files, feedback or outputs, or a catch-all such as "to develop and improve our services" with no training exclusion. Confirm by finding the actual setting in your account and noting what it says on the day you checked. If the setting is on and you want it off, stopping AI tools training on your business data walks through each major tool.
2. How long are chats, files and deleted items kept?
You want numbers of days for three things: active chats and files, items you delete, and anything kept for safety or legal reasons. Fine: stated periods, with an admin setting to shorten them. Worry: "as long as necessary for the purposes described", which is not a period at all. Some vendors offer zero data retention on certain plans, meaning inputs aren't stored after processing; what zero data retention means explains who qualifies and what it doesn't cover.
Even a zero-retention promise can move. Since 9 June 2026, Anthropic has kept prompts and outputs on its most capable "covered" models for 30 days, including for customers with zero data retention, and only in September added a route (by application) back to zero. A practice that approved Claude in 2025 on the strength of a zero-retention agreement, then moved to the newest models without re-reading the terms, would be keeping client material for a month without knowing it. Note the model names your approval covers, and re-check retention whenever you start using a newer model.
3. Can people at the vendor read your content?
Search for "review" and "reviewer". Some human access for abuse monitoring or support is normal. What matters is when it happens, whether you can switch it off, and how long reviewed material is kept. Google's consumer Gemini app is a useful example: chats that human reviewers have seen are kept for up to three years, separately from your account, so deleting your activity doesn't delete them.
4. Which other companies receive your data?
Look for the sub-processor list, meaning the other companies that handle your data for the vendor, such as its cloud host and AI model provider. Fine: a published list, with notice before new ones are added. Worry: "we may share information with partners" for marketing or advertising, or no list at all. A small tool built on a big provider's model usually sends your prompts to that provider, so the provider's terms matter too.
A missing list usually shows up at the worst moment. Take an illustrative two-person wedding-photography business that adds a free AI caption writer to its gallery workflow. Nobody searches the privacy policy for partner, which would have turned up "we may share information with partners to personalise advertising". The gap surfaces months later, when a corporate client booking an event sends a supplier questionnaire asking for every company that processes guests' photos. The photographer can name the gallery host but not the caption tool's AI provider, because the tool doesn't publish one, and has to switch tools mid-contract. Ten minutes with the find function at the start would have caught it.
5. Who owns what you put in and what comes out?
Business terms commonly say you own your inputs and outputs. Read the next paragraph as well: the licence you grant the vendor. "To provide and maintain the service" is narrow and normal. "Worldwide, perpetual, irrevocable, for any purpose" is broad and deserves a question. Ownership of outputs raises its own issues, covered in who owns the AI-generated content your business publishes.
6. What security evidence exists?
Look for an independent report or certificate (SOC 2 Type II or ISO/IEC 27001 are the common ones), encryption in transit and at rest, single sign-on on business plans, and a breach notification commitment in hours. Fine: documents you can request, with dates. Worry: "enterprise-grade security" with nothing behind it.
7. How can the vendor change the terms?
Search for "change", "modify" and "update". Fine: notice by email a stated number of days before changes take effect for business customers. Worry: changes that take effect when posted, with "continued use means acceptance" and no notice. Check whether a change applies to data you've already uploaded or only to new activity.
Some changes arrive as a new default rather than new wording. Since 16 June 2026, new users of SimplePractice's Note Taker have been opted in by default to keeping de-identified transcripts. In a clinic, that means the owner's account, set up and checked a year ago, can look fine while the therapist who joined last month is on the newer default. When anyone new joins, check their setting, not just yours. And look for what happens if the service closes: the AI calendar tool Clockwise shut down on 27 March 2026 and deleted user data rather than transferring it, so an export route matters as much as a deletion promise.
Words to search for, and what they give away
Open each document and use your browser's find function (Ctrl+F, or Cmd+F on a Mac). Search for word stems so you catch every variant: licen finds both spellings of licence, anonymi finds anonymise and anonymize.
| Search for | What you'll find | Treat it as a warning if… |
|---|---|---|
train | The training clause | It's missing from the business terms, or covers only some of your content |
improve | The catch-all purpose | "Improve our services" appears with no statement that this excludes training |
retain / retention | Storage periods | No number of days anywhere |
review | Human access | Reviewers can read content by default and reviewed items are kept longer |
third part / partner | Sharing | Sharing for marketing, advertising or "business purposes" |
sub-processor / subprocessor | Who else processes your data | No list, or no notice when it changes |
licen | The rights you grant the vendor | Perpetual, irrevocable, or "for any purpose" |
aggregat / de-identif / anonymi | Use of data derived from yours | Derived data can be used for anything, including training, with no definition of how it's anonymised |
feedback | What happens when you rate an answer | Rated conversations can be used even when training is switched off |
delet | Deletion and backups | Deleted content sits in backups for an unstated period |
modify / change | How terms change | Changes take effect on posting, with no notice |
You can ask an AI assistant to do the first pass on a long document, as long as you make it quote rather than summarise. Use a tool on a business plan, or a consumer account with training switched off, and paste in the public terms (never a contract marked confidential):
Below are the terms of service and privacy policy for [tool], [plan].
For each topic, quote the exact sentence(s) that answer it, with the
section heading. Do not paraphrase. If nothing in the text answers it,
write NOT FOUND.
Topics: 1 training on customer content 2 retention periods in days
3 human review 4 sub-processors 5 licence granted to the vendor
6 security certifications 7 how terms change and notice given
[paste text]
The answer that comes back (illustrative) tends to look sound at first glance: "1 Training: 'We do not use Customer Content to train our models' (Section 4.2). 2 Retention: 'We retain data for as long as your account is active' (Privacy, Retention). 3 Human review: NOT FOUND." Two things need fixing before you rely on it. Search the original for feedback: in many terms "Customer Content" is defined so that thumbs-up ratings and the conversations attached to them sit outside it, so the training answer is only partly true. And "as long as your account is active" is not a number of days, so check 2 is a warning, not a pass. Treat NOT FOUND as "search yourself", because models miss clauses in long documents, especially ones split across the privacy policy and a separate help article.
How the four big assistants answer, as of September 2026
The same brand can give opposite answers depending on the plan. This is what each vendor's own help pages said when this tutorial was checked. Setting names and retention periods change, so confirm on the vendor's page before relying on any of it.
| Assistant | Personal or consumer accounts | Business accounts |
|---|---|---|
| ChatGPT | Free, Plus and Pro chats can be used for training unless you switch off "Improve the model for everyone" under Settings, Data controls. Temporary Chats aren't used for training and are deleted from OpenAI's systems within 30 days | Business, Enterprise and API content isn't used for training by default |
| Claude | On Free, Pro and Max you choose, using the model-training switch under Settings, Privacy. If training is allowed, new chats can be kept for up to five years; if not, 30 days. Deleted chats aren't used for future training | Team, Enterprise and API use sit under commercial terms: no training on your content by default |
| Gemini | The "Keep Activity" setting controls whether chats are saved and used to improve Google's AI. Human reviewers may read some chats, and reviewed chats are kept for up to three years. With Keep Activity off, chats are kept for 72 hours | With a Workspace account, content isn't human-reviewed or used to train models outside your organisation without permission; admins set retention |
| Microsoft Copilot | Personal Microsoft accounts have their own privacy settings; check them separately | Copilot Chat signed in with a work account has enterprise data protection: prompts and responses aren't used to train foundation models |
The primary pages are worth bookmarking: OpenAI's data controls help article, Anthropic's guide to its model-improvement setting, and Google's Gemini Apps Privacy Hub. The practical lesson from the table: if staff use personal accounts for work, the consumer column applies to your client data, whatever your company has bought.
Reassuring phrases that deserve a second read
These appear on many AI product pages. None of them is a problem on its own, but each is weaker than it sounds.
- "We never sell your data." Selling isn't the same as training on it, sharing it with partners, or keeping it for years. Check those separately.
- "We don't train on your data." Whose models? The vendor's own, or also the AI provider it uses? And which data: chats only, or files, feedback and outputs too?
- "Data may be used in aggregated or de-identified form." Ask for what. Free text such as emails and contracts is hard to strip of identifying detail, so this deserves a precise answer.
- "Enterprise-grade security." A marketing phrase. Ask for the report or certificate and its date.
- "Your data is encrypted." Encryption protects data from outsiders in transit and in storage. It doesn't stop the vendor itself from reading or processing it.
- "You own your outputs." Good, but it doesn't stop another user receiving a very similar answer, and it says nothing about the licence you grant over your inputs.
- "We may update these terms from time to time." Standard wording. The question is how much notice you get and whether you can leave before the change applies.
Record what you found on one page
A record means you only do this once per tool, and you can show a client or insurer how you decided. Pair it with a simple data classification, so the record says which kinds of information staff may put in; how to classify business data before using AI tools gives four workable categories.
AI TOOL DATA CHECK
Tool and plan: ______________ Checked by: ________ Date: ________
Documents read (with their "last updated" dates):
______________________________________________________
1 Training Default: ________ Setting name and location: ________
Our setting: ________
2 Retention Chats: ___ days Files: ___ days Deleted items: ___
Admin can shorten? Yes / No
3 Human review When: ____________ Reviewed items kept: ____________
4 Sharing Sub-processor list: ________ Notice of changes: ___ days
5 Ownership Inputs: ______ Outputs: ______ Licence to vendor: ______
6 Security Report or certificate: ______ Dated: ______
Single sign-on: Yes / No Breach notice: ___ hours
7 Changes Notice: ___ days How we're told: ______________
Data staff may put in: [ ] public [ ] internal [ ] client confidential
[ ] personal data [ ] health or financial data
Decision: approve / approve with conditions / reject
Conditions: ______________________________ Review again by: ________
Save a PDF of each document next to the record. Terms change, and a dated copy is the simplest proof of what you agreed to.
Here is the record completed for an illustrative five-person bookkeeping practice checking a mid-sized AI meeting-notes tool on its team plan. The figures are the kind a vendor might publish, not any particular product's:
Tool and plan: [notes tool], Team plan Checked by: practice manager
Date: 14 Sep Documents: Terms (updated 2 Jun), Privacy (2 Jun),
DPA (v3), Trust page, help article "Data controls"
1 Training Default: off on Team. Setting: Admin > Data > "Improve
our AI" (greyed out for members). Our setting: off
2 Retention Recordings: 90 days Transcripts: until deleted
Deleted items: 30 days in backups Admin can shorten? Yes
3 Human review Only if we open a support ticket and grant access
4 Sharing List published: cloud host + one AI model provider
Notice of changes: 30 days by email
5 Ownership Inputs: ours Outputs: ours Licence: to provide service
6 Security SOC 2 Type II report on request, dated March
Single sign-on: Yes Breach notice: 72 hours
7 Changes Notice: 30 days How told: email to account owner
Data staff may put in: [x] internal [x] client confidential
[ ] payroll or bank details
Decision: approve with conditions
Conditions: recordings cut to 30 days; no payroll calls recorded;
owner email forwarded to shared inbox. Review by: March
The conditions are where the value is. Retention was the only check that didn't fully pass, and the admin setting fixed it in two minutes. The "no payroll calls" line reflects the practice's own data categories, not a flaw in the tool. And forwarding the account-owner email matters because check 7 relies on someone actually reading the change notices.
Confirm the settings match the record
A record is only true if every account matches it. Once a tool is approved, ask each person who uses it to open the data or privacy settings and send a screenshot, then compare them with the record. In a six-person team this takes about 15 minutes, and it regularly turns up something: one person signed in with a personal account on the same email address, or a contractor on a free plan with training switched on. On business plans, the admin console usually shows which accounts belong to your organisation; anyone using the tool for work who isn't listed there is outside your terms.
When to stop reading and ask an adviser
You can do the seven checks yourself. Bring in a solicitor or data-protection adviser when any of these apply:
- The tool will handle health, financial or children's data, or other sensitive categories that data-protection law such as the GDPR treats more strictly.
- Your client contracts contain confidentiality or data-location clauses, and you can't tell whether the tool's terms meet them.
- The AI will make or shape decisions about individuals, such as screening job applicants or setting prices for specific customers.
- You process personal data at a scale or in a way that may call for a formal risk assessment; whether you need a DPIA before using AI tools sets out the usual triggers.
- What the salesperson told you contradicts what the documents say, and the vendor won't put the difference in writing.
Take your one-page record to that conversation. An adviser can review a specific finding far faster (and more cheaply) than a whole stack of vendor documents.
Follow-up questions on AI privacy terms
If I switch off model training now, is data already used for training removed?
Not from models already trained. OpenAI says new conversations won't be used for training once you switch the setting off. Anthropic says it stops using your stored chats in future training runs, but data already in a training run that has started, or in models already trained, stays there. Switch it off before sensitive work starts, and keep client data on a business plan.
Is a business plan always safer than a consumer plan?
Usually the defaults are better: no training on your content by default, admin controls, and a data processing agreement. It isn't automatic, though. You still need to check retention settings, which connectors staff can switch on, and who in your organisation can see shared chats and projects. Run the same seven checks on the business terms rather than assuming.
How often should I re-check an AI tool's terms?
Whenever the vendor emails you about a terms or privacy update, at every renewal, and at least once a year for tools that handle client or staff data. Save a dated PDF of the terms and privacy policy on the day you approve a tool, so you can compare the wording later and see exactly what changed.
Further reads
- Questions to Ask an AI Vendor Before You Sign Anything — Turn any gaps you find into written questions for the vendor.
- Where Is Your Data Stored When You Use AI Tools? — Where your prompts and files physically end up, and why it matters.
- Is It Safe to Put Customer Data Into ChatGPT? — Applies these checks to the question owners ask most.
- Are ChatGPT, Claude, Gemini and Copilot GDPR-Compliant? — How the major assistants line up against data-protection law.
- How to Set Up Company AI Accounts Instead of Personal Logins — Move staff off personal logins so business terms apply.
- Does Microsoft 365 Copilot Keep Your Business Data Private? — A closer look at Copilot's protections for work accounts.
- Is Gemini Safe for Confidential Business Data in Workspace? — What Workspace accounts change about Gemini's data handling.
- Who Owns AI Chat History When an Employee Leaves? — What happens to chat history when someone leaves.
- How to Write an AI Disclosure Statement for Your Website — An AI-use inventory, the five parts of a good statement, a fill-in template, a picture framer's example and wording to avoid.
- AI Compliance Checklist for Small Businesses: What Applies to You — Map each AI use to the rules it triggers, work through data-protection and EU AI Act checks, and see a language school's uses mapped end to end.
- AI Tool Approval Process: How Staff Request a New AI Tool — The request form staff fill in, the checklist the reviewer works through, and the three replies, so new AI tools get approved in days, not months.
- What to Do Before You Buy Any AI Tool: A 10-Point Checklist — Ten checks to run before paying for any AI tool, from pricing the job it replaces to reading the exit terms, with a kitchen-fitter worked example.
- AI for Small Business Owners: A Plain-English Beginner's Guide — What an owner should know before starting with AI: how chat tools really work, the four kinds of product, data rules, costs and a first fortnight.
- Barriers to AI Adoption in Small Businesses and How to Clear Them — Eight practical barriers that keep small firms from adopting AI, the cheapest way past each, and the few barriers you should respect rather than clear.
- How to Keep Up With AI in 30 Minutes a Week — A timed weekly routine for owners: scan your own tools' release notes, filter hard, test one change on real work, and log what you decide.
- Does Your Business Insurance Cover AI Mistakes? — Match each kind of AI mistake to the policy that would respond, spot the new AI exclusions at renewal, and send your broker five precise questions.
- Restaurant AI Tools: 12 Questions to Ask Before You Sign Up — Twelve written questions for any restaurant AI vendor, with red flags, a scoring sheet and five test calls to make before you commit.
- AI Culling vs Outsourced Editing: Which Saves Photographers More? — AI culling costs $10-$18 a month; outsourced editing costs $0.20-$0.50 an image. Work out which buys back more of your hours per dollar.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: OpenAI Help Center (Data controls in ChatGPT; Temporary Chat); Anthropic announcement on consumer terms updates and Anthropic Privacy Center; Google Gemini Apps Privacy Hub and Generative AI in Google Workspace Privacy Hub; Microsoft Learn (enterprise data protection in Copilot). Checked 27 September 2026.