ChatGPT vs Gemini vs Claude: as of 2026, all three train on free-tier conversations by default. Each lets you opt out, but none of it makes a consumer plan safe for confidential work data. Here’s what I verified by hand, and what to do about it this week.
Right now, someone on your team is pasting a customer list into a free ChatGPT tab. Someone else is dropping an unreleased contract into Gemini to “just summarize it.” Nobody asked security. Nobody filed a ticket. It’s fast, it works, and the risk feels like someone else’s problem.
This is shadow AI, employees using personal, unapproved AI accounts for real work data, and it’s the single most common way company information leaks into an AI training set today. The uncomfortable question most people never stop to ask: “Is the free AI window I’m using right now actually okay for this document?”
So I checked. I opened the free web version of all three major assistants, went into the actual settings, and compared what happens to your data against each vendor’s official policy. Below is what I found, and the one thing you should do about it before Monday.
How I Compared This
This comparison mixes two kinds of evidence, and I label which is which so you can trust each line:
- ✅ Hands-on: I logged into the free web version of ChatGPT, Gemini, and Claude and confirmed the setting locations and defaults myself.
- 📄 Documented: Data retention periods, training conditions, and enterprise-tier policies come from each vendor’s official privacy policy and terms.
All findings reflect the web interface as of 2026. AI data policies change often. ChatGPT, Gemini, and Claude have all revised theirs in the last 18 months, so treat the settings paths as a starting point and confirm on your own screen.
ChatGPT vs Gemini vs Claude: The Free-Tier Privacy Table
| ChatGPT (Free) | Gemini (Free) | Claude (Free) | |
|---|---|---|---|
| Trains on your chats by default? | ✅ Yes | ✅ Yes | ✅ Yes |
| Can you opt out? | ✅ Yes (Settings › Data Controls) | ✅ Yes (Keep Activity) | ✅ Yes (Settings › Privacy) |
| Human reviewers may read samples? | 📄 Limited (abuse review) | 📄 Yes (Google warns humans may review) | 📄 Limited (safety review) |
| What opt-out does NOT stop | 📄 ~30-day abuse-review retention; data already trained can’t be pulled back | 📄 ~72-hour storage; human-reviewed chats kept up to 3 years | 📄 Safety-flagged chats may still be used |
| Default retention if you don’t opt out | 📄 Used for training | 📄 Tied to Keep Activity | 📄 Up to 5 years (changed Aug 2025) |
In one line: All three free plans are opt-out, not opt-in. Your conversations feed model training unless you turn it off, and even then, none of them promise zero retention.
ChatGPT Free: Opting Out Isn’t Deletion
On the free plan, ChatGPT uses your conversations to train its models by default. The switch to turn this off is real but buried: Settings › Data Controls › “Improve the model for everyone” › Off. Most people never open that menu.

Two things people misread here. First, turning it off is not deletion. OpenAI still retains new chats for up to ~30 days for abuse review before removing them. Second, and more important: the opt-out is forward-looking only. Anything you’ve already sent that entered a training corpus cannot be pulled back. Flipping the switch protects tomorrow’s chats, not last month’s.
Gemini Free: The One Where Humans Might Read It
Gemini’s free tier is the most exposed of the three on one specific axis: Google explicitly warns that human reviewers may read sampled conversations to improve the service. This isn’t a bug. It’s disclosed policy.
You opt out by turning off Keep Activity (in Gemini: Menu › Settings & help › Activity, or at myactivity.google.com/product/gemini), or by using Temporary Chat. Google renamed this setting from “Gemini Apps Activity” in September 2025, so older guides still use the old name.

The catch is significant. Even with activity off, conversations can be stored briefly (~72 hours) to run the service. And critically, anything a human reviewer has already read is kept on a separate track for up to three years, and you can’t see, audit, or delete it. Turning the setting off stops the future flow; it doesn’t reach back for what a reviewer already saw.
(Note: Google does not train on Workspace, Enterprise, or API data, only consumer Gemini. More on that below.)
Claude Free: The Plan That Used to Be the Safe One
This is the plot twist. For a long time, Claude was the privacy pick. Anthropic’s policy said it did not train on your conversations and generally deleted data within 30 days.
That changed on August 28, 2025. Anthropic updated its consumer terms so that Free, Pro, and Max conversations are now used to train Claude by default, unless you opt out, and data may be retained for up to five years. You opt out in Settings › Privacy.

There’s one more clause worth knowing: under Anthropic’s policy published June 2026, conversations flagged for safety review can still be used to train models regardless of your opt-out choice. If you chose Claude specifically because it was the “private” option, that assumption is now out of date.
The Paid-Plan Myth: Why Plus and Pro Aren’t Safer
Here’s what surprises people most. You might assume paying around $20 a month upgrades your privacy. It doesn’t. ChatGPT Plus/Pro and Google AI Pro are still consumer plans, and all three vendors apply the same opt-out-by-default training policy to them that they apply to free.
Paying more gets you faster models and higher limits. It does not, by itself, take your data out of the training pool.
Real data isolation isn’t a price tier. It’s a different class of plan. Think of it as a ladder:
- Consumer (Free / ChatGPT Plus / ChatGPT Pro / Google AI Plus / Google AI Pro / Claude Pro): Trains on your data by default. You can opt out, but it’s still a personal plan with personal-plan protections.
- Team / Enterprise: Not used for training by default, and a Data Processing Agreement (DPA) is typically available. But don’t assume more than that. Zero Data Retention and HIPAA BAAs usually aren’t included at this level.
- API / Enterprise contract: Where the strong guarantees live: Zero Data Retention (ZDR), BAA for healthcare, and negotiated DPA terms, because they’re contractual, not default.
The takeaway: if you need real assurance for sensitive work, opting out on a consumer plan reduces exposure but doesn’t eliminate it. Genuine isolation starts at Team/Enterprise and is fully guaranteed only at the API/contract level.
Which Should You Use for Work Data?
Stop asking “which AI is safest.” The right question is “how sensitive is this data, and what class of plan am I on?” Match the two:
| Data type | Consumer plan (Free/Plus/Pro) | Team / Enterprise / API |
|---|---|---|
| Public or throwaway (brainstorms, public info) | ✅ Fine (opt out of training first) | ✅ Fine |
| Internal (drafts, internal docs) | ⚠️ Only with training off, and only if policy allows | ✅ Preferred |
| Confidential (customer data, unreleased code, financials, PII) | 🚫 Never | ✅ Required (with DPA/ZDR/BAA as needed) |
The single rule that captures it: confidential data never goes into a consumer AI plan, free or paid, no matter which toggle you’ve flipped.
Your One Step This Week
Two actions, both under ten minutes.
1. Opt out on every account you use (forward-looking, but do it now):
- ChatGPT: Settings › Data Controls › “Improve the model for everyone” › Off
- Gemini: Menu › Settings & help › Activity › Keep Activity › Off
- Claude: Settings › Privacy › turn off model training
One honest caveat: opting out sharply reduces how your data is used, but none of these switches gets you to zero. Safety and abuse-review exceptions remain, and past data already used can’t be recalled.
2. Post a one-line AI data rule where your team will see it (Slack, Notion, wherever):
“Personal/free AI accounts (ChatGPT, Gemini, Claude) are fine for public or throwaway text only. Never paste customer data, unreleased code, financials, or anything confidential. Use our approved Team/Enterprise account for that.”
That one sentence prevents more leaks than any tool setting.
FAQ
QWhich is more private: ChatGPT, Gemini, or Claude?
Which is more private: ChatGPT, Gemini, or Claude?
QDo ChatGPT, Gemini, and Claude train on your chats by default?
Do ChatGPT, Gemini, and Claude train on your chats by default?
QIs a paid plan like Plus or Pro safer than the free plan?
Is a paid plan like Plus or Pro safer than the free plan?
QHow do I stop these AI tools from training on my data?
How do I stop these AI tools from training on my data?
QCan I paste confidential work data into a free AI chatbot?
Can I paste confidential work data into a free AI chatbot?
Sources
- OpenAI: How your data is used to improve model performance
- OpenAI: ChatGPT privacy & data controls
- Google: Gemini Apps Privacy Hub
- Anthropic: Updates to Consumer Terms and Privacy Policy
- Anthropic: Is my data used for model training?
Policies and settings paths verified as of 2026. Confirm current defaults on your own screen before relying on them; these change frequently.