llm-integration.eu

Claude Data Privacy: Does Claude Train on Your Data?

Claude data privacy by plan: training, opt-out, retention and processor role on Free, Pro, Max, Team, Enterprise, API and Bedrock, plus a 2026 DPO checklist.

Updated 10 min readFacts verified on 19 September 2026

TL;DR

Claude data privacy depends on the plan, not the model. On Free, Pro and Max, Anthropic trains on your chats unless you opt out and keeps them for up to 5 years if you allow it. Team, Enterprise, the API, Bedrock and Google Cloud run under commercial terms that exclude training. Company data belongs only there.

Does Claude train on your data?

Yes on consumer plans, no on business plans. Claude Free, Pro and Max allow training unless the user switches it off. Team, Enterprise and the Claude API run under Anthropic’s Commercial Terms, which prohibit training on customer content. On Amazon Bedrock and Google Cloud your contract is with the cloud provider, which also excludes training.

Anthropic’s Privacy Policy, effective 10 September 2026, puts the consumer rule in one sentence: “We may use your Inputs and Outputs to train and improve Anthropic AI models, unless you opt out through your account settings.” The Commercial Terms say the opposite for business customers: “Anthropic may not train models on Customer Content from Services.”

The consumer change arrived with the Consumer Terms update of 28 August 2025. Existing users had until 8 October 2025 to choose. Claude for Work (Team and Enterprise), Claude for Government, Claude for Education and the API, including Bedrock and Google Cloud, were explicitly out of scope.

Access route Contract Training on your content Default retention Anthropic’s role
Claude Free, Pro, Max Consumer Terms + Privacy Policy Yes, unless opted out 30 days after deletion; up to 5 years with training on Controller (Anthropic Ireland in the EEA)
Claude Team Commercial Terms + DPA No (default) Until the user deletes, then 30 days Processor
Claude Enterprise Commercial Terms + DPA No (default) As Team, plus custom retention from 30 days Processor
Claude API (direct) Commercial Terms + DPA No Deleted within 30 days; ZDR on request Processor
Amazon Bedrock, Google Cloud Contract with AWS or Google No Per cloud setting, ZDR available No access (Bedrock)

Sources: Privacy Center, commercial training, Privacy Center, organization retention, API and data retention.

One exception applies everywhere: feedback. When a Team or Enterprise user clicks thumbs up or down, the entire conversation goes to Anthropic, is stored for up to 5 years and may be used for training.

What happens to data on Claude Free, Pro and Max?

On consumer plans Anthropic is the controller of your data under GDPR, not your service provider. With training on, chats are kept de-identified for up to 5 years. With training off, deleted chats leave the back end within 30 days. There is no data processing agreement on these plans, so they cannot legally carry your customers’ personal data.

The retention rules come from the Privacy Center article on consumer retention, dated 1 July 2026:

  • Deleted chats: removed from back-end storage within 30 days.
  • Training allowed: de-identified for up to 5 years in training pipelines.
  • Flagged for Usage Policy violations: inputs and outputs up to 2 years, classifier scores up to 7 years.
  • Feedback: 5 years.
  • Incognito chats: never used for training, even with the setting on.

The opt-out only works going forward. Anthropic says your data stays “in model training that has already started and in models that have already been trained”. Whatever an employee pasted three months ago with training on cannot be pulled back.

To switch training off, follow the Privacy Center instructions dated 3 August 2026:

  1. Click your name and choose Settings.
  2. Open Privacy, or go straight to claude.ai/settings/data-privacy-controls.
  3. Toggle off the switch under Help Improve our AI models.
  4. Use incognito chats for anything sensitive on top of that.

The bigger issue for European companies sits in the Consumer Terms that apply to residents of the EEA and Switzerland: “Non-commercial use only. You agree that you will not use our Services for any commercial or business purposes.” A Pro subscription on a company card is therefore a terms violation, not just a privacy gap. Our position: consumer plans have no legitimate place in company work, opt-out or not.

How do Claude Team and Enterprise differ on privacy?

Team and Enterprise are commercial products under the Commercial Terms, with Anthropic’s DPA incorporated by reference. Anthropic does not train on their content by default. Chats stay stored until users delete them. Only Enterprise allows custom retention periods, and only usage-based Enterprise offers US-only inference. Neither plan has an EU processing option.

The difference is admin control. The pricing page lists SSO for both, but SCIM, audit logs, the Compliance API and “Custom data retention controls” only for Enterprise. The Privacy Center adds the details: default retention is indefinite, the shortest period you can set is 30 days, and Owners set it under Organization settings > Data and Privacy. The period does not cover Claude Design, Claude Tag, Managed Agents or features built on Claude Code on the web.

On location Anthropic is blunt. Its server location article of 15 June 2026 says traffic may be routed to the US, Europe, Asia and Australia, and “data is stored in the US”. The only restriction available is US-only inference on usage-based Enterprise plans, billed at 1.1x API rates. If you need EU storage, Team and Enterprise do not provide it. ChatGPT Enterprise handles residency differently, as our Claude vs ChatGPT comparison for Europe shows.

Two settings every Team or Enterprise Owner should check on day one:

  • Rate chats under Organization settings > Data and Privacy: turn it off so employees cannot send whole conversations to Anthropic as feedback, where they would sit for 5 years and be trainable.
  • Retention period (Enterprise only): set it to what your deletion policy requires, for example 90 days.

For developer teams on Claude Code the same pattern applies, per the Claude Code docs: consumer accounts 5 years or 30 days, commercial accounts 30 days by default. Session transcripts are also stored locally in plaintext under ~/.claude/projects/ for 30 days. This .claude/settings.json in the repository shortens local retention and turns off nonessential traffic to Anthropic:

{
  "cleanupPeriodDays": 7,
  "env": {
    "CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC": "1",
    "DISABLE_FEEDBACK_COMMAND": "1"
  }
}

Who is the processor on the API, Bedrock and Google Cloud?

On the direct Claude API Anthropic is your processor, represented in the EU by Anthropic Ireland Limited, with Standard Contractual Clauses in its DPA. On Amazon Bedrock and Google Cloud the cloud provider is the processor and Anthropic does not see your prompts. These two are the only routes that keep Claude inference verifiably inside the EU today. What each route costs per seat or token is in our Claude pricing plans overview.

The API does not keep inputs long term by default. The Privacy Center states deletion within 30 days, and zero data retention is available per organization on request. The exception is Covered Models such as Claude Fable 5.1, where Anthropic requires 30 days of retention for safety review on every platform. If you go direct, our Claude API key guide covers key creation, workspaces and rotation.

On Bedrock, the AWS data protection page states that model providers have no access to prompts, completions or logs. Google commits not to use customer data for training without permission.

Which region, inference profile and residency premium to pick is covered in our GDPR comparison of Claude providers. The Frankfurt setup is in the Claude on AWS Bedrock EU guide, the Google route in Claude on Vertex AI in Europe.

What must employees never paste into Claude?

On consumer accounts, no company data at all, because the Consumer Terms rule out business use. On Team and Enterprise, whatever your DPIA approves, but no special category data under GDPR Article 9 without a separate review. Anthropic’s own help center warns against sharing financial details, health records, passwords and confidential documents.

The help article on sensitive data, dated 22 May 2026, lists exactly those four categories. We turned them into a traffic light you can drop into your AI policy:

Data type Free, Pro, Max Team, Enterprise API, Bedrock, Google Cloud (EU)
Public text, marketing, research Private use only Allowed Allowed
Internal code without secrets No Allowed Allowed
Customer personal data No Only with DPIA and transfer assessment Allowed with DPA and EU region
Health, HR, applicant data No Case-by-case approval Only after DPIA
Passwords, API keys, credentials No No No
Trade secrets, contracts under NDA No After NDA review After NDA review

Credentials are red everywhere. They have no business in any prompt, and for Claude Code feedback uploads Anthropic only redacts “known API key and token patterns”, not every kind of secret.

Checklist for your data protection officer

A DPO does not need a new method for Claude, just five pieces of evidence: which contract applies, whether training is excluded, how long data is kept, where it is processed, and how you stop shadow use on consumer accounts. The list below follows the order in which auditors usually ask. Duties under the AI Act come on top; see our EU AI Act checklist for LLM deployers.

  1. Build an inventory of every Claude access route. Consumer accounts often show up as “Anthropic” or “Claude.ai” on expense reports.
  2. Ban consumer plans for work in writing in your AI policy, citing the non-commercial clause.
  3. File the DPA. Team, Enterprise and API use Anthropic’s DPA as part of the Commercial Terms; Bedrock and Google Cloud use the cloud provider’s.
  4. Assess the third-country transfer. Team and Enterprise store data in the US; record SCCs and, where needed, a transfer impact assessment in your records of processing.
  5. Disable feedback (Rate chats) and document the setting.
  6. Set deletion periods. Enterprise: custom retention from 30 days. Team: enforce deletion by policy, since no technical period can be set.
  7. Check Covered Models. Approving Fable 5.1 means accepting 30-day retention even under ZDR.
  8. Run a DPIA before allowing Article 9 or employee data.
  9. Involve the works council where one exists, as soon as audit logs or the Compliance API allow monitoring of behaviour or performance.
  10. Review yearly. Anthropic last changed its Privacy Policy on 10 September 2026.

FAQ

Does Claude train on my data?

On Claude Free, Pro and Max, yes, unless you opt out under Settings > Privacy. On Team, Enterprise and the API, no, because the Commercial Terms prohibit it. On every plan, thumbs up or down feedback and conversations flagged by safety systems may still be used for training.

How much does Claude Team cost compared with Pro?

Pro costs 20 USD per month billed monthly or 17 USD billed annually. A Team standard seat costs 25 USD monthly or 20 USD annually, for 2 to 150 users. Enterprise is 20 USD per seat per month plus usage at API rates. All prices from claude.com/pricing, in USD before tax.

Claude Pro vs Team: is Pro with opt-out enough for a company?

No. Even with opt-out Anthropic stays the controller instead of your processor, there is no DPA, and the EEA Consumer Terms explicitly forbid business use. A Team seat costs only 3 to 5 USD more than Pro and fixes all three problems. Price is not an argument.

How long does Anthropic keep my chats?

Consumer with training on: up to 5 years, de-identified. Consumer with training off, and Team: until you delete, then out of the back end within 30 days. Enterprise: custom period from 30 days. API: deleted within 30 days. Flagged violations: up to 2 years, classifier scores up to 7 years.

Does Claude Team or Enterprise process data in the EU?

Not with any guarantee. Anthropic routes traffic to the US, Europe, Asia and Australia and stores data in the US. The only location control is US-only inference for Enterprise. For EU processing use Bedrock or Google Cloud, see our provider comparison.

Is Claude GDPR compliant?

No plan is compliant or non-compliant by itself. Team, Enterprise and the API give you a DPA and a training exclusion, but the transfer to the US must be documented under SCCs. Consumer plans are out for company personal data. This is not legal advice; we summarise what Anthropic documents.

Sources

  1. Anthropic Privacy Policy (effective 10 Sep 2026) (19 September 2026)
  2. Anthropic Consumer Terms of Service (19 September 2026)
  3. Anthropic Commercial Terms of Service (19 September 2026)
  4. Anthropic: Updates to Consumer Terms and Privacy Policy (19 September 2026)
  5. Anthropic Privacy Center: Change model improvement settings (19 September 2026)
  6. Anthropic Privacy Center: How long do you store my data (consumer) (19 September 2026)
  7. Anthropic Privacy Center: Is my data used for model training (commercial) (19 September 2026)
  8. Anthropic Privacy Center: How long do you store my organization's data (19 September 2026)
  9. Anthropic Privacy Center: Where are your servers located (19 September 2026)
  10. Anthropic Privacy Center: Custom data retention for Enterprise (19 September 2026)
  11. Claude Code Docs: Data usage (19 September 2026)
  12. Claude pricing (19 September 2026)
  13. Anthropic Docs: API and data retention (18 September 2026)
  14. AWS Bedrock docs: Data protection (18 September 2026)

Related guides