What you can safely paste into ChatGPT, Claude, and Gemini

The safest choice is not the most expensive one. Paying for a personal Pro plan buys better models, not a contract that protects your company's data.

Business & Economy · 2026-09-03

Someone on your team has a customer file open in one window and a chatbot in the next. They paste in a few paragraphs to get a quick summary, it works, and the next day they do it again. The question that follows is a fair one : which of these tools is safe to hand real work to?

It turns out to be the wrong question, or at least not the first one. The choice that decides your exposure is not which chatbot, and it is not free versus paid. It is whether the account your employee is typing into belongs to them or to the company.

The line that matters is not free versus paid

Four AI models, each assigned a different role, worked through this question together in a Polora conversation, and they agreed on where to start : sort every account into one of two piles. In the first pile are personal accounts, including the paid ones with familiar names like Plus, Pro, Max, and Advanced. In the second are the accounts a company sets up and manages for its staff, sold as business or enterprise plans.

The reason this split matters more than the price is that the two piles are governed by different things. A personal account, paid or not, runs on the standard terms every individual clicks through. A company account runs on a contract between the provider and your business. Almost everything that follows comes down to that one difference.

Whose account it is, not the price, decides your exposure. · personal account A personal account, paid or not, runs on the standard terms every individual clicks through. · company account A company account runs on a contract between the provider and your business.
Whose account it is, not the price, decides your exposure. · personal account A personal account, paid or not, runs on the standard terms every individual clicks through. · company account A company account runs on a contract between the provider and your business.

Does your input train the model?

On the personal side, the published policies now point the same way : what you type can be used to help train future models unless someone goes into the settings and turns that off. This holds across all three services, and one of them is worth pausing on, because it changed recently.

For a long time Claude did not train on personal conversations by default, and it was widely treated as the safe exception. The panel's researcher checked the current policy and found the exception is gone. Anthropic updated its consumer terms in 2025 so that data from Free, Pro, and Max accounts can be used to improve its models, with the setting turned on unless the user opts out. As of now, all three consumer products train on your input by default.

The business and enterprise tiers are where the contract does its work. OpenAI, Anthropic, and Google all state that content from their business customers is not used to train their general models by default. Here your company is the customer, and that promise is a term of the agreement rather than a switch each employee has to remember to flip.

The catch is that the opt-out only helps if every person remembers it, and you have no way to prove they did.

How long the data stays

Retention is the least glamorous of these concerns and often the most surprising. On a personal account your chats generally sit in your history until you delete them, and deletion is not always immediate.

The specific numbers differ by provider. OpenAI says deleted conversations are removed from its systems within thirty days, apart from cases where it is required to keep them. Google's consumer Gemini keeps activity for eighteen months by default, adjustable to three or thirty-six months. Chats that a human reviewer has seen can be held for up to three years, even after you delete your activity. Anthropic's new terms carry the sharpest edge : if a consumer user allows their data to be used for model improvement, the retention period can stretch to five years.

In a company-managed account, an administrator sets the retention and deletion rules for everyone, and Google Workspace adds tools built for holding and retrieving records. The point is not that these windows are always shorter. It is that the company, not the individual employee, decides.

What a lawsuit would expose

The panel was firm on a point that is easy to miss : a promise not to train on your data is not a promise that the data can never be disclosed. Information held by any provider can still be reached through a subpoena, a court order, or your own obligations once a dispute begins.

This is where consumer accounts become a particular headache. If the relevant chats live in employees' personal accounts, the company often cannot answer basic questions. Who used AI with customer data? What exactly did they upload? Can those conversations be preserved once a lawsuit starts, then collected and produced properly? That last process, known as legal discovery, is hard to satisfy when the records are scattered across accounts the company cannot see. Business tiers do not make legal exposure vanish, but they give a company the central identity, logs, retention controls, and legal-hold tools needed to respond.

※ Legal discovery : the stage of a lawsuit in which each side must hand over the documents and records the other side is entitled to ask for.

So does paying for Pro fix it?

This is the question most people actually want answered, and the panel's answer was no. A personal Pro or Advanced subscription buys capability : stronger models, higher limits, longer memory, more features. It does not buy a contract governing your data.

What it leaves out is everything that made the business tier different. There is no company-to-provider agreement, no way to enforce or even confirm that every employee turned the training setting off, no organization-wide control over how long data lives, and no reliable way to preserve or export conversations if you are sued. A twenty-dollar personal plan and a free account have far more in common with each other than either has with a company account.

One more caution the group raised applies no matter which tier you use. Pasting privileged legal material or sensitive negotiations into any outside AI service can create its own confidentiality problems, and no subscription fixes that. Those uses belong with counsel's approval.

A rule a small team can actually follow

The panel landed on a rule simple enough to fit on a single page. Personal AI accounts, free or paid, are for material that is already public, invented, or genuinely stripped of identifying detail. Real customer data and confidential company documents go only into a company-approved business or enterprise workspace, and only when that specific use has been cleared.

In plain terms, that means keeping customer names, financial and health records, passwords and keys, source code, contracts, HR files, and anything received under someone else's confidentiality obligation out of any consumer account, however much it costs. The takeaway from the whole exchange is short : treat the free and the personal-paid tools as the same thing, and let the price of a plan decide the quality of your answers, never the safety of your data.

What you can safely paste into ChatGPT, Claude, and GeminiWhat you can safely paste into ChatGPT, Claude, and GeminiAn employee pastes customer data into a chatbot to save time. The real question is not which tool or free versus paid, but whether the account belongs to them or to the company.The line that matters is not free versus paid · Whose account it is, not the price, decides your exposure.Does your input train the model?How long the data staysWhat a lawsuit would exposeSo does paying for Pro fix it?Treat the free and the personal-paid tools as the same thing, and let the price of a plan decide the quality of your answers, never the safety of your data.Sources help.openai.com · OpenAI : keeping history on while disabling training, anthropic.com · Anthropic : updates to our consumer terms, docs.anthropic.com · Anthropic : data usage

People on my team paste customer data and internal documents into ChatGPT, Claude, and Gemini every day, and I am not sure which is actually safe. Explain clearly, for someone who is not a lawyer, the real difference between the free and personal-paid consumer plans and the business or enterprise tiers on three points: whether your input is used to train the model, how long it is retained, and whether it could surface in legal discovery. Use each provider's current published policy. What practical rule should a small company set for what can and cannot go into a consumer AI account, and does paying for a Pro subscription actually fix the problem, or only buy better models?

Corporate Risk and Compliance Specialist · claude-sonnet-5

The core risk framework, from a compliance perspective Let me give you the practical mental model, since I don't have live search this round to pull exact clause text — treat specific retention-day numbers as approximate and worth verifying against current policy pages before you finalize a written policy. The general pattern across all three providers Free / consumer personal-paid (ChatGPT Plus, Claude Pro, Gemini Advanced): - Your content can be used to improve/train models by default unless you manually opt out in settings (OpenAI, Google) — Anthropic has generally been more conservative here but check current terms. - Retention is typically tied to your account and can persist even after deletion for some backend period (often 30 days minimum for abuse/safety review, sometimes longer). - No contractual protection. These are consumer terms of service — click-through agreements, not negotiated contracts. There's no Business Associate Agreement, no data processing addendum, no liability structure. - Discovery exposure: consumer accounts have essentially no defined legal hold, litigation hold, or discovery-response process. If you're sued and opposing counse…

IT Operations and Security Administrator · deepseek-v4-pro

I’m an IT/security admin, not a lawyer — so here’s the operational read. Short answer: none of the consumer plans — free or the paid “Pro/Max/Advanced” ones — are safe for customer data or internal documents. The business/enterprise tiers are materially safer, but only if you actually configure and enforce them. Paying for Pro mostly buys better models and higher limits, not corporate data protection. The three points that actually matter 1. Is your input used to train the model? Consumer plans: - ChatGPT free/Plus/Pro — training is on by default. OpenAI says it may use your content to improve models unless the user turns off “Improve the model for everyone” in settings. That is a personal opt-out, not a company control. - Gemini consumer apps — Google uses consumer Gemini conversations to improve and train its models. On a personal Google account, you should assume training/human review is in play unless you’ve specifically limited or turned off activity settings. - Claude free/Pro/Max — this is the exception. Anthropic generally does not train on consumer content by default; training is opt-in. But that still doesn’t make it a corporate too…

Researcher · claude-sonnet-5

Fact-check: one important correction, everything else largely holds up I ran three searches to verify the specifics both debaters used. The overall three-tier framework both of you laid out is directionally correct and well-matched to current published policy — but there's one significant factual error in the IT Admin's post that changes the picture for Claude specifically. Correction: Claude is NOT currently the "training-off exception" The IT Admin stated: *"Claude free/Pro/Max — this is the exception. Anthropic generally does not train on consumer content by default; training is opt-in."* This was true historically but is no longer accurate. Anthropic changed this in a major policy shift: - Effective September 2025, Anthropic's own documentation states: "Consumer users (Free, Pro, and Max plans): Starting August 28, 2025, we're giving you the choice to allow your data to be used to improve future Claude models. We will train new models using data from Free, Pro, and Max accounts when this setting is on." - Critically, the setting defaults to ON, not off — a third-party review notes "The current policy frames consumer training as opt-out, the opt-out itsel…

The Arbiter · gpt-5.6-terra

The useful line is not “free versus paid.” It is personal consumer account versus company-managed business/enterprise account under business terms. One correction to carry into the final answer: Claude consumer plans should not be treated as a training-safe exception. Anthropic’s current consumer policy makes model-improvement sharing an opt-out choice, with the setting on by default for applicable new/resumed activity; opting in can also bring a much longer retention period. So, in practice, all three consumer services require a “do not enter confidential company data” rule, whether free or personally paid. Two nuances are essential: - “Not used for training” is not “cannot be disclosed.” Data held by any provider may still be subject to lawful subpoena, court order, regulatory request, or your own discovery obligations. - Enterprise is risk reduction and governance, not a magic confidentiality cloak. It gives the company contractual terms, admin control, identity management, retention/deletion settings, and often audit/e-discovery capabilities. It does not cure an NDA breach, eliminate privilege-waiver risk, or make sensitive data appropriate to paste without a…

The Arbiter's Final Verdict · gpt-5.6-terra

Bottom line For company data, the meaningful dividing line is not free versus paid. It is: - Personal/consumer account — including paid personal plans such as ChatGPT Plus/Pro, Claude Pro/Max, and Gemini Advanced. - Company-managed business or enterprise account — under business terms, with admin controls and usually a DPA or equivalent privacy commitments. A personal Pro subscription generally buys better models, higher limits, and features. It does not turn a consumer account into a company-controlled, contract-protected workspace. For a small company, the safe default is: > Do not put customer data or confidential internal material into any consumer AI account, even a paid one. > Use consumer AI only for public, synthetic, or genuinely de-identified information. Use real business data only in an approved company business/enterprise workspace. The practical differences | Question | Consumer free / personal-paid plans | Business / enterprise tiers | |---|---|---| | Can prompts be used to train models? | Often yes by default or unless each user opts out. This applies to current consumer offerings from OpenAI, Anthropic, and Google. | Providers…