It depends on the vendor, your plan, and your settings. Check all three because policies change.
A few patterns hold across many major AI vendors:
- Business, enterprise, and education tiers typically do not train on your data by default. That commitment usually lives in the data processing terms, and it is a key reason organizations choose paid workspace plans over personal accounts.
- Consumer (free and personal) plans vary. Some train on conversations by default with an opt-out toggle; others have made training opt-in or off by default. This is the tier where settings matter most, and where defaults have shifted over the past few years.
- API access is generally not used for training by default.
What to do:
- Find the training or data-use setting in each tool your staff use, and document what you chose.
- Look for the vendor’s data processing addendum or trust page; search it for terms like “train,” “model improvement,” and “retention.”
- Treat personal accounts used for work as the common gap. Staff may paste supporter data into a free personal account without checking its settings or terms.
- Put your expectations in writing in your AI policy.
Use the source links below to read each vendor’s current policy. The overall pattern has been stable: paid organizational tiers are safer by default, and consumer settings need checking.
Go deeper: Data security and privacy basics · Create your AI policy