> For the complete documentation index, see [llms.txt](https://handbook.harmonic.security/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://handbook.harmonic.security/handbook/4.-data-protection-and-residency/4.5-training-opt-out-and-data-usage.md).

# 4.5 Training opt-out and data usage

How to confirm whether prompts, files, connector data, and feedback are used for model improvement across consumer, business, enterprise, and API plans.

*Last reviewed: August 18, 2026*

{% hint style="info" %}
Training use is a governance question, not a checkbox to trust from memory. Confirm the account type, product surface, and contract terms.
{% endhint %}

## Training opt-out and data usage: what security teams need to know

AI providers handle data usage differently across consumer, team, enterprise, and API products. The same user may have several account paths with different defaults.

A good review asks whether inputs, outputs, files, feedback, evals, and telemetry can be used to improve models or services. It also asks what happens when users sign in with personal accounts.

## Common training opt-out and data usage security failures

* Enterprise users assume consumer settings apply to managed workspaces.
* API data terms are read as ChatGPT terms, or the reverse.
* Feedback and eval data are left out of the review.
* Personal accounts become the training-use gap.
* Contract language is not linked to technical enforcement.

## Training opt-out and data usage security controls checklist

* Confirm training-use terms by product surface and account type.
* Document default settings for managed tiers and consumer tiers separately.
* Block or detect personal-account use for corporate data.
* Review feedback, evals, files, and telemetry in addition to prompts.
* Keep vendor docs and contract excerpts in the evidence pack.

## Anthropic

### Overview

As of the last review date, Anthropic does not use inputs or outputs from its commercial products — Claude for Work, the Anthropic API, and Claude Gov — to train its models by default. The documented exception is explicit feedback: when a user submits a thumbs up or down, the related conversation may be used for training and is stored for up to five years, de-linked from user and customer IDs. Team and Enterprise Primary Owners and Owners can disable feedback submission org-wide via the Rate chats setting, which closes that path.

Cowork follows the account and workspace context rather than creating a separate training tier. Its remote sessions can move among web, desktop, and mobile, while local capabilities still depend on the desktop. Confirm that every Cowork user is operating in the intended commercial workspace, especially when personal Pro or Max accounts are also available.

Claude Tag is available through Team and Enterprise organizations, but its Slack conversations are stored separately from Claude chat history and its channel work is billed to the organization while direct messages use the individual's Claude account. Include both modes in the commercial-versus-consumer account check; the surface looks the same in Slack even though the identity and billing context differ.

Consumer plans follow a different model. Data from Free, Pro, and Max plans — including Claude Code sessions under those plans — is used to improve Anthropic's models when the user allows it through the Model Improvement privacy setting, when conversations are flagged for safety review, or through explicit opt-in programs. Incognito chats are never used to improve Claude, and training data excludes raw content from connectors and MCP servers unless it is copied directly into the conversation. Check the actual setting for each user population rather than assuming which way it points.

### Anthropic documentation

* [Is my data used for model training? (Commercial)](https://privacy.claude.com/en/articles/7996868-is-my-data-used-for-model-training)
* [Is my data used for model training? (Consumer)](https://privacy.claude.com/en/articles/10023580-is-my-data-used-for-model-training)
* [Claude Code data usage](https://code.claude.com/docs/en/data-usage)
* [Use Claude Cowork on web, desktop, and mobile](https://support.claude.com/en/articles/15520349-use-claude-cowork-on-web-desktop-and-mobile)
* [What is Claude Tag?](https://support.claude.com/en/articles/15594475-what-is-claude-tag)

### Applicable Harmonic guides for Anthropic

* [Securing Claude Cowork: A Security Practitioner's Guide](https://www.harmonic.security/resources/securing-claude-cowork-a-security-practitioners-guide)

## OpenAI

### Overview

As of the last review date, OpenAI does not train its models on business data by default: ChatGPT Business, Enterprise, Edu, Teachers, and Healthcare workspaces and the API Platform (since March 1, 2023) require explicit opt-in before customer content is used for training. Consumer ChatGPT is the opposite case — OpenAI does use data from the consumer versions of its services as a training data source, which is why the tenant and account controls in 1.3 are training controls too.

Two review notes. First, data-control behavior on the API Platform varies by endpoint and feature, so confirm terms per integration rather than per vendor. Second, personal workspaces registered under company email addresses may be subject to deletion or merge into the enterprise workspace — but until that capture happens, corporate data pasted into them sits under consumer terms.

ChatGPT Work inherits the workspace's business data protections, but connected applications retain and process their own copies under separate terms. Desktop Work can also use local files and applications. Review the workspace, plugin or app, and downstream system together rather than treating the ChatGPT training setting as the only data-use decision.

### OpenAI documentation

* [Enterprise privacy at OpenAI](https://openai.com/enterprise-privacy/)
* [Data controls in the OpenAI platform](https://developers.openai.com/api/docs/guides/your-data)
* [Managing members, seat types, roles and access in ChatGPT Enterprise](https://help.openai.com/en/articles/8266401-managing-members-seat-types-roles-and-access-in-chatgpt-enterprise)
* [Work Admin FAQ](https://learn.chatgpt.com/docs/enterprise/work-admin-faq)

### Applicable Harmonic guides for OpenAI

* [Securing ChatGPT Enterprise Guide](https://www.harmonic.security/resources/securing-chatgpt-enterprise-guide)

## Frequently asked questions about training opt-out and data usage

### Do AI providers train on enterprise data?

By default, no — for the major providers' business and API offerings. OpenAI states it does not train on business data from ChatGPT Business, Enterprise, Edu, or Healthcare workspaces or the API Platform without explicit opt-in, and Anthropic does not train on commercial-product data by default, with explicit thumbs up/down feedback as the documented exception. Consumer tiers are different: consumer ChatGPT data is a training source, and consumer Claude data can be used when the user's Model Improvement setting allows it. These terms have changed before — confirm the current policy pages and your contract.

### Is training opt-out enough?

No. A training commitment says nothing about retention, residency, access, logging, or DLP, and it does not stop users from moving corporate data into personal accounts where the training answer is different. Treat the no-training default as one row in the data-protection review, alongside the retention and residency rows in 4.3 and 4.4.

### What is the consumer-tier gap?

Employees may use free or personal accounts where data can be used for training — consumer ChatGPT data is a training source, and consumer Claude data (including Claude Code on Free, Pro, and Max plans) can be used when the Model Improvement setting allows it. The subtle case is a personal workspace registered under a company email, which runs under consumer terms until the organization claims or merges it. Tenant restrictions (see 1.3) are the enforcement layer.

### Should feedback be reviewed?

Yes — feedback is the standard exception to no-training defaults. On Anthropic commercial plans, a thumbs up or down submits the related conversation, which may be stored for up to five years, de-linked from user and customer IDs, and used for training; org owners can disable this via the Rate chats setting. Treat eval and support-ticket data the same way: separate handling rules that deserve their own review line.

### What evidence should be kept?

Keep dated copies of the vendor policy pages, the contract or DPA language, workspace settings screenshots — including feedback and model-improvement settings — an account-scope inventory, and the personal-account controls in force. Training policies changed materially in 2025, so date-stamp everything and re-verify on a schedule rather than at renewal only.

## Applicable regulations and frameworks

| Governance page                                  | Relationship to this article                                                                                                                       |
| ------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------- |
| G.1 Map your controls to NIST AI RMF and CSF 2.0 | This article supplies implementation evidence for the NIST AI RMF and matching NIST CSF 2.0 outcomes.                                              |
| G.5 SANS Critical AI Security Guidelines mapping | This article implements relevant SANS Data Protection guidance.                                                                                    |
| G.7 Ownership and RACI for AI security           | This control depends on the ownership and evidence responsibilities defined in the RACI.                                                           |
| G.9 HIPAA controls for AI systems handling PHI   | Conditional: for a workflow handling ePHI, this supports HIPAA PHI identification, minimum-necessary handling, retention, and disclosure controls. |

*G.2, G.3, G.4, and G.9 are conditional mappings. They apply only when the deployment is within the legal or regulatory scope described on the linked governance page.*

## Related handbook guidance

* [4. Data Protection & Residency](/handbook/4.-data-protection-and-residency.md)
* [4.4 Retention and Zero Data Retention](/handbook/4.-data-protection-and-residency/4.4-retention-and-zero-data-retention.md)
* [4.2 Data classification for AI prompts and outputs](/handbook/4.-data-protection-and-residency/4.2-data-classification-for-ai-prompts-and-outputs.md)
* [G.2 EU AI Act obligations for deployers](/reference/governance-and-frameworks/g.2-eu-ai-act-obligations-for-deployers.md)
* [6.3 Compliance APIs by platform](/handbook/6.-observability-audit-and-evidence/6.3-compliance-apis-by-platform.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://handbook.harmonic.security/handbook/4.-data-protection-and-residency/4.5-training-opt-out-and-data-usage.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
