Privacy & IT
What "training on your data" actually means in 2026, what to do per plan tier, common IT objections with concrete rebuttals, and a one-page memo you can paste into an email to your IT lead.
This page exists because internal IT tends to ask the same question within the first couple of weeks: "Are you sure that thing isn't reading our customer data into a public AI?" The answer is yes, you can be sure — but only if your team is on the right plan and the right settings are in place. This page tells you what to set, what to say, and what memo to send.
Before you start
You'll need:
- Confirmation of which plan tier your team is on. Pro / Plus / Max / Team / Enterprise — each behaves differently. (Free is not in scope for this Playbook.)
- 5 minutes of your IT lead's attention. This whole page exists so that conversation goes well the first time and doesn't recur every quarter.
The two-minute version
If you're skimming, this is the whole page in four sentences:
- Anthropic Claude and OpenAI ChatGPT both offer paid plans where your data is contractually excluded from training the next model. Those plans are Team, Enterprise, and Business for both vendors.
- Pro / Plus / Max plans (the $20–$200/mo single-user tiers) train on your data by default unless you flip a switch in settings. This is the most common surprise.
- Both vendors hold SOC 2 Type II certification, which is the IT-respected baseline. They also support GDPR data-processing agreements if you have EU prospects or customers.
- For regulated data (HIPAA / financial / FedRAMP), there's a separate Zero-Data-Retention addendum available on Enterprise — ask the vendor's sales team directly.
The rest of this page is the long version, the specific settings to change, and the memo to send IT.
What "training on your data" actually means
When an AI vendor trains on your data, it means the text and files from your conversations may be sampled into the dataset used to build the next-generation model. In practice that means:
- Your data does not appear verbatim in someone else's response. Models don't quote training data directly; they build statistical patterns from it.
- But your data could, in extreme edge cases, leak into a future model's behavior in a way that's traceable to your company. Real-world examples are rare, but the risk is non-zero — and it's the risk IT is asking you to manage.
The way to manage it is simple: don't be on a tier that trains on your data. Or if you must be, flip the opt-out toggle.
What to do, by plan tier
Anthropic Claude
| Plan | Trains on your data by default? | What to do |
|---|---|---|
| Free | Yes | Don't use Free for work data. |
| Pro ($20/mo) | Yes — by default. Anthropic updated this in October 2025. | Open Claude → Settings → Privacy → switch off "Help improve Claude." Verify in writing to IT. |
| Max ($100/$200/mo) | Yes (same as Pro) | Same opt-out path. |
| Team Standard / Premium | No — contractually never trains. | Nothing to flip. The Team / Premium agreement is your guarantee. |
| Enterprise | No | Plus optional Zero-Data-Retention (ZDR) addendum for regulated data. |
Reference: Anthropic Privacy Center — Data Retention and Anthropic Consumer Terms (Oct 2025 update).
OpenAI ChatGPT / Codex
| Plan | Trains on your data by default? | What to do |
|---|---|---|
| Free | Yes | Don't use Free for work data. |
| Plus ($20/mo) | Yes — by default. Same surprise as Claude Pro. | Open ChatGPT → Settings → Data Controls → Improve the model for everyone → switch off. |
| Pro ($200/mo) | Yes (same opt-out) | Same path. |
| Team ($25/seat/mo, 2+ seats) | No — contractually never trains. | Nothing to flip. |
| Business / Enterprise | No | Plus admin retention controls + audit logging + RBAC. |
One catch on the opt-out: even with training off in settings, clicking the thumbs up / thumbs down rating on a response sends that specific chat to OpenAI for training. If you want absolute non-disclosure, don't rate responses — or use Team+ where the rating doesn't enroll the chat in training.
Reference: OpenAI Data Controls FAQ.
What to put in writing for IT
Once you've confirmed the plan + the opt-out (where applicable), send IT a short note that includes these four things:
- The vendor and tier. "We're on Claude Team Standard, paid annually." / "We're on ChatGPT Team, 5 seats."
- The training disposition. "Per the contract, our data is not used for model training. (For Pro/Plus tier: 'Training opt-out is verified per attached screenshot.')"
- The compliance posture. "[Vendor] is SOC 2 Type II certified. The current report is available under NDA on request."
- The data-handling expectations. "We will not paste customer PII, contract terms, or financial data into prompts." (Or: "We will only paste the following categories…")
That four-line note clears 80% of IT's questions. The rest are objection patterns covered below.
Common IT objections + concrete responses
"I don't trust paid plans to actually exclude training data."
Response: SOC 2 Type II audit reports cover the vendor's enforcement of contractual commitments. Both Anthropic and OpenAI hold current Type II certifications, which means a third-party auditor independently verified that the controls (including the training-exclusion control) operated as documented over a 6–12 month window. Ask the vendor for the report; both will provide one under NDA within a business day.
"What if a former employee's prompts contained trade secrets?"
Response: On Team/Enterprise tiers, prompts and responses are stored in the workspace, not in the public model. When the employee leaves, the workspace admin can delete their conversation history (Settings → Members → Remove → Delete data). Nothing about that user's prompts persists in the model used for everyone else.
"Where does the data physically live?"
Response: Anthropic processes data primarily in AWS US regions; OpenAI in Microsoft Azure US regions. Both vendors offer data-residency commitments on Enterprise. For most US-based mid-market manufacturers, the default US data path is the right answer. If you have specific data-residency rules (e.g., the company has a German subsidiary), put that in front of the vendor's enterprise sales team — both have EU-region options.
"What about GDPR? We have prospects in the EU."
Response: Both vendors offer a Data Processing Agreement (DPA) that satisfies GDPR Article 28 requirements. On Team/Enterprise, the DPA is auto-signed as part of the agreement. On Pro/Plus you have to request it. If your EU prospects' personal data ever appears in prompts (even just a name and email), having a signed DPA in place is the minimum baseline.
"How do I know what employees are pasting in?"
Response: Both vendors surface workspace-level activity logs to admins (Settings → Audit Logs on Team/Enterprise). For tighter governance, set a written policy that names the categories of data not permitted (customer PII, contract terms, source code, credentials), and enforce the policy through training rather than blocking — blocking is brittle and pushes the behavior to personal accounts (which is the worst outcome).
"We're not allowed to use any AI per company policy."
Response: This is a real one and worth taking seriously. Two paths: (a) ask whether the policy is "no AI ever" (rare) vs. "no Free-tier AI" (much more common — they don't trust the consumer plans), in which case Team/Enterprise often clears the bar; or (b) propose a 30-day pilot scoped to one workflow (e.g., monthly distributor scorecards using only data already shared internally). Pilot framings carry better than blanket adoption proposals.
"What if the AI hallucinates and we send the wrong data to a customer?"
Response: Every skill in this Playbook is designed for a human-in-the-loop. The skill produces a draft; the analyst reviews it; only then does the analyst (a real human) ship it. The Playbook is explicit about this — see the Where the AI stops section on every skill page. The risk model is the same as a junior analyst sending a draft to a senior analyst for review — except faster.
"Is this just shadow IT?"
Response: Shadow IT is an unapproved tool bought on a personal card and used off the books. Putting your AI usage inside a formally-approved Team plan with admin oversight is the opposite of shadow IT — it's the controlled adoption path IT wants the rest of the company to follow. Position the Playbook's workflows as the documented, audited reference implementation.
When you actually do need a different setup
For most marketing analysts at mid-market manufacturers, the standard Team/Pro setup with training opt-out is sufficient. Escalate to a tighter configuration if any of these apply:
- Protected health information (PHI) — you need a Business Associate Agreement (BAA), which both vendors offer on Enterprise only. HIPAA exposure usually means Enterprise + ZDR addendum.
- Financial customer data subject to GLBA / SOX — same answer: Enterprise + ZDR.
- EU residents' personal data in prompts — Team/Enterprise DPA satisfies this; Pro requires you to request the DPA.
- Trade secrets the company has actually classified as such (formula, source code, M&A target lists) — these never go in prompts regardless of plan tier. Use the Playbook's skills for the work that doesn't require them.
- Federal contractor / FedRAMP — Enterprise-only conversation; involve your existing FedRAMP-cleared platform partner.
If any of the above describes your role, talk to Jason before running any skill against that data.
The paste-ready memo for IT
Copy this and adapt the bracketed bits:
Subject: AI tooling — Claude / ChatGPT for [your role]
Hi [IT lead],
I'm starting to use a structured AI workflow as part of my [role] work, and I want to keep you in the loop on the security posture before I scale it up.
Vendor + plan: [Anthropic Claude on Team Standard, billed annually] / [OpenAI ChatGPT on Team, 5 seats].
Training exclusion: Our plan tier contractually excludes our data from training future models. ([For Pro/Plus tier: "I've also turned off the consumer 'help improve' setting — happy to screenshot."])
Compliance posture: The vendor holds SOC 2 Type II certification. I can request the current report under NDA if useful for your records.
Data handling: We will not paste customer PII, signed contracts, or financial line items into prompts. The workflows we're using produce drafts that I review before anything leaves the building (full Playbook with the workflows attached / link).
Workflow source: This is a structured framework called Headstart from NunnCurtis Labs. It's not a generic "use ChatGPT for everything" suggestion — it's a defined set of skills with a defined data shape and a human-in-the-loop step at the end of every workflow.
Happy to set up a 15-minute call if you have specific questions, or to scope a 30-day pilot that's tighter than the steady-state setup.
[Your name]
When something goes wrong
- "IT said no, but we already started using ChatGPT Plus." Pause. Two things to do, in order: (1) flip the training opt-out today (5 seconds, no IT approval needed), (2) propose a Team upgrade with the memo above. The fastest path to a yes is showing IT that the next version of the setup is tighter than the current version.
- "Our company already has an enterprise AI vendor we're supposed to use." Use it for the skills that work in it. The Playbook's prompts are vendor-portable — a Claude prompt usually runs in a properly-configured enterprise instance of GPT or Gemini with minor edits. Email Jason if a specific skill won't run in your enterprise vendor.
- "IT wants to do a security review before we proceed." Welcome it. Send them this page, the vendor's SOC 2 report, and the Playbook URL. Most reviews complete in under a week once the four-line summary above is in their hands.
- "A specific skill needs data that we can't paste." Read the skill page's Where the AI stops section and the Inputs to attach list — most skills are designed around exports the analyst already has access to. If a particular skill genuinely needs data you can't share, email Jason and we'll either modify the skill or flag it as out of scope for your environment.
Where to go next
- Installing Claude Desktop — to verify the Pro vs Team plan you're on (Settings → Subscription).
- Installing OpenAI Codex — same for the OpenAI side.
- Guarantee and support — what's covered if a skill produces unexpected output.