How to Stop AI Tools Training on Your Business Data

Coding Liquids tutorial cover featuring Sagnik Bhattacharya for How to Stop AI Tools Training on Your Business Data.
Coding Liquids tutorial cover featuring Sagnik Bhattacharya for How to Stop AI Tools Training on Your Business Data.

Put client work on business plans, which OpenAI, Anthropic, Google and Microsoft don't train on by default. On any personal or free account that stays in use, turn off the model-training switch in privacy settings. Then check the AI features inside your other software, because the chat apps are only half the exposure. Allow about two hours.

What follows is a way to inventory every AI tool your team touches, the switch for each of the main assistants as they stood in September 2026, a short rule for staff, and a ten-minute quarterly check that keeps it all switched off. One caveat before you start: turning training off stops future use. It doesn't pull back anything already used, and it doesn't stop the vendor storing your chats for a set period.

Follow me on Instagram@sagnikteaches

Four routes from your business into someone's training set

Most owners think of one route, the chat window. There are four, and the last two catch people out.

Connect on LinkedInSagnik Bhattacharya
  1. Personal and individual accounts. Free and individual paid plans (ChatGPT Free and Plus, Claude Free and Pro, the Gemini app on a personal Google account, the free Copilot app, Perplexity Free and Pro) are consumer products. Paying $20 a month doesn't make an account a business account, and on most of these the training setting is on until someone switches it off.
  2. AI features inside other software. Writing assistants, design apps, transcription tools and booking systems have added AI features, each under its own terms. Some default to training, some don't, and the default often differs between the individual and team versions of the same product.
  3. Public content. Meta says publicly shared Instagram and Facebook posts, including photos, were part of the data used to train its generative AI models. It says it doesn't use private messages with friends and family unless someone in the chat shares them with Meta AI.
  4. Feedback buttons. The thumbs up and down under an answer are a separate channel. Anthropic says that if you submit feedback, it may use that conversation for training, even on its commercial products. Google says that when Keep Activity is off and you don't submit feedback, your future Gemini chats aren't used to improve its models.

Route 4 is the easiest to trip over, because it happens on the plans you've already made safe. Picture an illustrative events agency on Claude Team. An account manager pastes in a venue contract and asks for a summary. The summary misses the cancellation-fee clause, so she presses thumbs down and types "missed clause 14, cancellation fees" to report it. The business plan kept that chat out of training by default; by Anthropic's own description, the feedback she submitted may let that conversation be used after all, contract text included. Nothing about it felt risky to her: she was trying to be helpful. The fix is a habit, not a setting: report bad answers in your own error log, not through the vendor's buttons, on any chat containing client material.

Subscribe on YouTube@codingliquids

Stage 1: Find every account touching business content (45 minutes)

You can't switch off what you don't know about. Ask each person which AI tools they use for work, including on their phone, then cross-check three places: card and bank statements for AI subscriptions, the browser extensions on shared computers, and the list of connected apps in your Google or Microsoft admin console. Staff rarely hide tools on purpose; they just don't think a free app counts.

Record what you find in a simple table. The last column is where the next two stages happen.

ToolWho uses itPlanAccount owned byWhat goes inAction
ChatGPTOwnerPlus (individual)Owner's personal emailClient emails, quotesMove to a business plan
GrammarlyFront deskFreeFront deskEvery email typed in the browserSwitch training off
Booking system AI assistantEveryoneIncludedBusinessClient names, notesAsk the vendor in writing

Note who owns each account as well as who uses it. An account on someone's personal email leaves with them, chat history and all, which is a separate problem covered in setting up company AI accounts instead of personal logins.

Stage 2: Move client work onto plans that don't train by default

A setting can be switched back on by anyone with the login. A business plan's terms can't. So for the people who handle client details, the lasting fix is a business plan, where not training on your content is the contractual default. These are the list prices in USD as of September 2026.

VendorPlans that don't train on your content by defaultList priceWorth knowing
OpenAIChatGPT Business, Enterprise, the APIBusiness Standard $25 per user a month, or $20 billed annuallyMinimum 2 seats
AnthropicClaude Team, Enterprise, the APITeam Standard $25 per seat a month, or $20 annuallyMinimum 2 seats
GoogleGemini inside Google Workspace business plansWorkspace from about $7 per user a month (annual)Already included if you pay for Workspace
MicrosoftCopilot Chat signed in with a work account; Microsoft 365 CopilotCopilot Chat included; Copilot Business $21 per user a month (annual)Microsoft says prompts and responses aren't used to train foundation models
PerplexityEnterprise Pro and Enterprise MaxEnterprise Pro $40 per seat a monthPerplexity says Enterprise data is never used for training

Two points save money here. First, if you already pay for Google Workspace or Microsoft 365, check whether the AI included there covers the work before buying a second assistant. Second, not everyone needs a seat. The people who paste client names, messages or files need one; someone who only brainstorms captions can use a personal account with training off, under the rule in Stage 4. Classifying your data first makes that line easy to draw.

Stage 3: Switch off training on the accounts that stay personal

For every consumer account that stays in use, find the switch. These are the labels and locations the vendors' own help pages gave in September 2026. Menus move, so if a label doesn't match, search the vendor's help centre for "model training".

ToolWhere the switch isWhat it doesn't cover
ChatGPT (Free, Go, Plus, Pro)Settings, Data controls, turn off "Improve the model for everyone". The Privacy Portal's "Do not train on my content" request does the same.Chats already used. Temporary Chats aren't used for training but may be kept for up to 30 days.
Claude (Free, Pro, Max)Settings, Privacy, the model-improvement toggleConversations you send feedback on. Anthropic keeps chats for 30 days with the toggle off, and up to five years with it on.
Gemini app (personal Google account)Turn off Keep Activity in Gemini's activity settings, or use Temporary ChatsTemporary Chats are kept for up to 72 hours. Feedback you submit.
Microsoft Copilot (free app)Privacy settings: "Model training on text" and "Model training on voice"Microsoft says opting out doesn't exclude conversations from general product improvement, advertising, safety or compliance uses. It takes up to 30 days to apply.
Perplexity (Free, Pro, Max)Account settings, the AI Data Retention toggle, which is on by defaultOther people's accounts: it's set per account, so every user on a Free, Pro or Max plan has to switch it off.
Grammarly (individual)Account data settings, "Product Improvement and Training"On multi-user Pro accounts only an admin can change it.
Canva (Free, Pro)Privacy settings; Canva says training on your content is off unless you opt inNothing to change unless someone opted in. On Canva Business and Enterprise the control is disabled and content isn't used.

Do this with the person sitting next to you, on their device, and take a screenshot of the finished setting for your records. It takes two or three minutes per account, and it's the only way to be sure it happened on the phone app as well as the laptop. On ChatGPT the switch follows the account across devices once it's set.

Keep the result as a one-page record. For an illustrative three-person video production company, it might read:

PersonTool and planDeviceSettingFoundLeft as
DirectorChatGPT PlusLaptop and phoneImprove the model for everyoneOnOff, screenshot saved
EditorPerplexity ProLaptopAI Data RetentionOn (the default)Off, screenshot saved
EditorGemini app, personal Google accountPhoneKeep ActivityOnOff, screenshot saved
ProducerClaude ProLaptopModel-improvement toggleOffOff, screenshot saved
ProducerCopilot free appPhoneModel training on text and on voiceOn, onOff, off; applies within 30 days

Four of five accounts needed a change, and the one already off belonged to the person who had never used it for client scripts. The record also becomes the list for the quarterly check below: the same five rows, opened again, in about five minutes.

The AI inside your other software needs its own check

Chat assistants are easy because the vendors publish clear pages. The harder part is every other tool that has quietly added AI. Three examples show how much defaults vary. Zoom says it doesn't use customer audio, video, chat, screen sharing or attachments to train its AI features (sold under the AI Companion name until June 2026) or third-party models. Otter says it trains its own models on de-identified recordings and transcripts, and that Enterprise workspaces are opted out by default. Canva defaults individual accounts to no training. Three tools in the same category of "things a small team uses daily", three different answers.

Here's how that plays out for an illustrative four-person accountancy practice that records client calls with Otter on the Pro plan. Otter's page says Enterprise workspaces are opted out of training by default; it doesn't say the same of Pro. Following the rule below (a vague answer means "yes, it trains"), the practice treats Pro as training until Otter confirms otherwise in writing. In the meantime it has two options: stop recording calls where clients discuss their personal finances, or find the setting and get the confirmation. Moving up a plan is not automatically the answer either, because Business, at $19.99 a user a month billed annually, isn't Enterprise, and the same question has to be asked of it.

For anything not on the table above, send the vendor these questions and keep the reply:

Subject: How our data is used by your AI features

Hello,

We use [product] on the [plan name] plan. Before we keep using its AI
features, please confirm in writing:

1. Is any of our content (text, files, images, recordings, customer
   records) used to train or improve AI models, yours or a third party's?
2. If yes, is that on by default, and where do we switch it off?
3. Which third-party AI providers process our content, and do their
   terms allow them to train on it?
4. How long is content sent to the AI features kept?
5. Where is this commitment written: terms of service, data processing
   agreement, or a help page?

Thank you,
[Name], [Business]

Question 5 matters most. A promise on a marketing page can change without notice; a promise in the data processing agreement is part of your contract. If the answer is vague, treat the default as "yes, it trains" until you hear otherwise, and keep client details out of that feature. What to check in an AI tool's privacy policy and terms covers reading the documents yourself.

What a five-person tattoo studio changed

Consider an illustrative studio: the owner, who also tattoos, three artists and a front-desk manager. Their data includes consent forms with medical questions, reference photos clients send in, the artists' original designs, deposit records and a busy public Instagram portfolio.

The inventory took 40 minutes and found seven AI touchpoints:

  • The owner's ChatGPT Plus, on a personal email, used for aftercare emails, price replies and describing custom pieces. Training was on.
  • Two artists using free ChatGPT on their phones to brainstorm designs, one of whom sometimes uploaded client reference photos.
  • Free Grammarly on the front-desk browser, reading every email typed there.
  • A Canva Pro account for flash sheets and flyers.
  • A new AI reply assistant in the booking system.
  • The Instagram portfolio.
  • A free Zoom account used for occasional design consultations, with no AI features on.

What they changed, and what it cost:

  1. Two ChatGPT Business seats for the owner and front-desk manager, the two people who handle client messages: $50 a month on monthly billing, or $40 billed annually. The owner cancelled the $20 Plus plan, so the net rise was $30 a month on monthly billing.
  2. Training switched off on the artists' personal ChatGPT accounts, plus a rule: brainstorm styles freely, but never upload a client's photo, name or skin details to a personal account.
  3. Grammarly's training control switched off on the front-desk account.
  4. Canva checked: nobody had opted in, so nothing to change.
  5. Booking-system vendor emailed with the five questions. Until the answer arrived, the AI reply feature stayed off.
  6. Instagram treated as public. Nothing posted publicly can be pulled back from a platform's training data, so the owner now posts finished work only, and keeps custom designs that haven't been tattooed yet off public posts.

Total time was about two and a half hours, including the vendor email. The part that took longest was the artists' phones, because each had a different app version and the menus were in slightly different places.

Stage 4: Write the rule down so it stays switched off

Settings drift. New staff join, someone reinstalls an app, a vendor adds a feature. A written rule catches what the settings miss. Put this in your staff handbook or AI policy, adjusted to your tools:

AI and training: our rule

1. Client names, contact details, photos, health or payment information
   and anything under a confidentiality agreement go ONLY into our
   business AI accounts: [list them].
2. If you use a personal AI account for work ideas, switch model
   training off first, and never put client information into it.
3. Don't press thumbs up/down or "send feedback" on chats that
   contain client information.
4. Before trying any new AI tool or feature with work material,
   tell [name]. They'll check how it uses our data.
5. Freelancers working on our clients' material follow rules 1-4.

Rule 3 is the one nobody thinks of, and rule 4 is the one that stops the problem recurring. If staff are already signing up for tools you haven't approved, stopping staff pasting client data into free tools deals with that directly.

A ten-minute check every quarter

Put a recurring reminder in the calendar for the first week of each quarter and run through five questions:

  1. Has anyone joined, left or changed role? New people need the rule and the settings; leavers need their access removed.
  2. Has any tool on the inventory added a new AI feature? Vendor release notes and "what's new" emails are where these appear.
  3. Open two or three personal accounts at random and confirm the training switch is still off.
  4. Check card statements for new AI subscriptions.
  5. Has any vendor changed its terms? Most email you when they do; search your inbox for "terms" and "privacy policy" from the last quarter.

If staff need a quick way to run a one-off chat that stays out of history, when to use ChatGPT's Temporary Chat explains where it helps and where it doesn't. And if the question behind all of this is how long vendors keep your data rather than whether they train on it, read what zero data retention means next.

The vendors' own pages are the place to confirm any of this before you rely on it: OpenAI's enterprise privacy page, Anthropic's model-training article and Microsoft's Copilot privacy controls.

Questions owners ask after switching training off

Does switching training off delete what I have already typed in?

No. The switch stops future chats being used for training; it doesn't pull back anything already used, and your chat history stays where it is. If a past chat held something sensitive, delete that chat, and if it was serious, ask the vendor's privacy team what deletion options apply to your account.

Is the API safer than the chat app for training?

For training, yes by default. OpenAI and Anthropic both say they don't train on API inputs and outputs unless the customer opts in. The API is billed separately, per token, and needs someone to build or configure the tool that calls it, so it suits automations rather than everyday chatting.

If a freelancer uses their own AI account on my client work, what can I do?

Put it in the contract. Add a clause saying client material may only be processed in AI tools that don't use it for model training, and that the freelancer must switch training off or use a business plan. Ask them to confirm which tools they use before the work starts.

Do business plans ever use my data for anything?

They still store and process it to run the service, keep logs, and check for abuse, for periods set in the terms. Not training is a different promise from not keeping. If retention matters to you, read the vendor's data processing agreement and look for the retention period and any zero-retention option.

Further reads

Sources: OpenAI enterprise privacy page and help centre articles on data controls and Temporary Chat; Anthropic privacy centre articles on model training and model-improvement settings; Google Gemini Apps Privacy Hub; Microsoft Copilot privacy controls support page; Perplexity help centre on data collection; Grammarly support on Product Improvement and Training Control; Canva Shield and privacy help pages; Zoom AI Companion privacy page; Otter.ai privacy and security page; Meta's privacy pages on generative AI. All checked September 2026.

Want your AI accounts audited and locked down?

On a 1:1 call we'll list the AI tools your team actually uses, decide which work belongs on a business plan, and agree the settings and staff rule that keep client material out of training.

Book a 1:1 call with me