How Do You Keep Company Data Out of a Public AI Tool?
The $20 plan you are paying for probably trains on your conversations by default. The tier that does not is a different product, and the gap matters more than the price.
By Merxtio Staff

Somebody on your team pasted a client contract into a chatbot last week to get a plain-English summary. They were being efficient, they were not being careless, and there is no button that un-pastes it.
The uncomfortable part is that paying for the tool probably did not protect you. This page covers what the consumer tiers actually do with your conversations, what the business tiers change, and the three-line policy that prevents most of this. About seven minutes.
Paying $20 does not buy privacy
This is the fact that catches people, and it catches paying customers hardest, because paying feels like it should have settled the question.
Consumer tiers of the major assistants — including the paid ones at around $20 a month — default to using your conversations to improve their models unless you opt out. The controls exist and they are not hidden, but the default is the thing most people never change.
The specifics differ by vendor and they move. ChatGPT keeps this under a data controls setting. Anthropic required existing users to make an explicit choice during late 2025, with retention running to five years where a user allowed training. Google's consumer plans follow the same broad pattern.
Go and look at your own settings rather than trusting any article, including this one. These policies change often enough that the only reliable version is the one on the screen in front of you today.
What the business tiers change
| Feature | Consumer plans | Business, team and enterprise plans |
|---|---|---|
| Training on your content | On by default on the major assistants, unless you opt out. | Excluded by default across the major providers. |
| How it is guaranteed | A setting, which any user can change and any new starter never touches. | A contractual term, which does not depend on individual behavior. |
| Retention | Can run to years where training is permitted. | Shorter and defined. Anthropic cut standard API log retention to seven days in September 2025. |
| Administration | None. Every account is its own island. | Central control, so leavers actually lose access. |
| Reported price | About $20 per person per month. | About $25 to $30 per user per month. |
| Item | USD per user per month, reported figures |
|---|---|
| Consumer plan | $20 |
| Claude Team | $25 |
| ChatGPT Team | $30 |
Five to ten dollars a person. That is the entire gap between a plan that may use your client's contract as training material and one contractually barred from it, and it is a rounding error against the cost of the conversation you would have to have with that client.
The part that is not about software
Trade secret protection has a condition attached: the holder has to take reasonable measures to keep the information secret. Something you have published, or handed to a third party with no confidentiality arrangement, is generally no longer protected.
Pasting proprietary material into a consumer AI account is difficult to describe as a reasonable measure to maintain secrecy, and coverage during 2026 reports courts beginning to take exactly that view — including a trade secret claim dismissed after the material had been uploaded to a chatbot.
None of this is legal advice, and the details will depend on your jurisdiction and your facts. The practical point stands regardless: the risk is not only that a model learns something. It is that the act of pasting can weaken the protection the information had.
Survey figures reported in 2026 suggest this is common rather than exceptional — a large majority of employees using generative AI say they paste company data into prompts, and most of those pastes go through personal accounts that no company system can see. Treat those numbers as indicative rather than precise; the direction is what matters.
Fix it in an afternoon
Check your own settings first, before anything else
You’ll have: Training switched off on every account your team uses today. · about 10 minutes
Open the data controls on each assistant your team actually uses and turn off training. Do it on your own account first so you know where the setting lives, then send the instructions round.
This is free, takes minutes, and closes most of the exposure immediately. Everything after it is about making the fix durable.
Write three lines about what never goes in
You’ll have: A rule short enough that people remember it. · about 20 minutes
Not a policy document. Three lines, in plain language, naming the categories: client identifiable information, anything under an NDA, credentials, and unreleased financials.
Long policies fail because nobody finishes them. The value is entirely in people knowing there is a line, since most exposure comes from someone who genuinely did not think a summary request counted.
Give people a sanctioned tool that is good enough
You’ll have: An approved option nobody has to work around. · about An hour
A ban does not work. It moves usage onto personal accounts and phones, where you cannot see it — which is measurably worse than sanctioned use, because now the pastes are invisible as well as unprotected.
Provide something people actually want to use, on a plan that excludes training. That converts a shadow problem into a governed one.
Say what to do after a mistake
You’ll have: A route that does not require anyone to confess to a disaster. · about 10 minutes
Someone will paste something. If the only available response is admitting to a serious incident, they will say nothing and you will find out much later.
Make it small: tell whoever owns this, delete the conversation, and note what was in it. A team that reports these quickly loses far less than one that hides them.
The tool selection guide touches this in one line — that data handling often differs between free and paid plans — and this is the detail behind it. The short version: the free tier is usually the most permissive of all, which makes it the worst place for anything confidential.
Questions people ask
- Does ChatGPT train on my data?
- On consumer plans, by default, unless you opt out in the data controls — and that includes the paid tier at around $20 a month. Business, team and enterprise plans exclude training on your content by default. Check your own settings, since these policies change often.
- Is ChatGPT Plus private?
- Not in the way most subscribers assume. Paying removes usage limits and unlocks models; it does not by itself stop conversations being used for training. That is a separate setting on consumer plans and a contractual term on business ones.
- Can I put client information into an AI tool?
- Not into a consumer account, and not without checking what you have agreed with that client. Many confidentiality agreements restrict disclosure to third parties, and a public AI service is a third party. On a business tier with training excluded the position is much stronger, but the agreement still governs.
- Does paying for AI stop it training on me?
- Paying for a consumer plan generally does not. Paying for a business or team plan generally does, because exclusion is written into the terms rather than left to a setting. That distinction — plan type, not price — is the one worth understanding.
- What is the difference between ChatGPT Plus and Team for privacy?
- Plus is a consumer plan where training is a setting you control. Team is a business plan where training on your content is excluded by contract, with central administration so access ends when someone leaves. Reported at about $30 per user per month against $20.
- What should an AI policy say?
- Three lines beat thirty pages: name what must never be pasted, name the sanctioned tool, and say what to do after a mistake. Avoid a blanket ban — it pushes usage onto personal accounts you cannot see, which is worse than the problem it was meant to solve.