Your Account Type Decides What the Model Learns, practitioner guidance from TheAICommand
← AI News
Policy

Your Account Type Decides What the Model Learns

Four assistants, four published positions on training and retention, and not one of them turns on the wording of the prompt. As at 24 September 2026, the default is set by the account tier that was signed in. Here is what each page states, what it does not state, and the register that records it.

·TheAICommand

Quick answer

As at 24 September 2026, OpenAI states it may use consumer content to train models unless the user opts out, and Anthropic uses consumer chats where the user allows it or a chat is flagged for safety review. All four vendors publish a no-training position for business tiers. Record the tier, the toggle and the retention window.

The tier decides the default, not the prompt. Four assistants are read here, being ChatGPT, Claude, Gemini and Microsoft Copilot, and all four publish a position on whether what is typed into them trains a model. As at 24 September 2026, those positions are set by the account tier that was signed in, and inside the consumer band they differ.

The account you signed in with is the control

The question "is it safe to paste this" has no general answer, and the assistant cannot supply one. The answer is a lookup against the account: which product, which tier, which toggle state, which retention window, checked on which date. That is a register, and the only form in which this information survives a staff change or an audit question.

Three facts drive the register. Consumer defaults differ between vendors, so a rule of thumb learned on one assistant is wrong on the next. Every business, enterprise and commercial tier read for this article publishes a no-training position, but each is scoped differently, which makes the tier and the exact wording the highest-value fields. None of that touches Australian obligations, because the paste itself is a use or a disclosure of personal information before any vendor setting is applied.

No vendor is said to have changed its position, because no archived earlier version was read.

What do the four vendor pages actually say?

Assistant and tierWhat the page statesDate the page carries
OpenAI, services for individualsContent may be used to train models, with an opt-out in Settings under Data ControlsRelative update label only, position as at 24 September 2026
OpenAI, Business, Enterprise and the application programming interface (API)No training on inputs or outputs by default, with an opt-in available to API customersRelative update label only, position as at 24 September 2026
Anthropic, consumer ClaudeChats used to improve models where the user allows it, where a chat is flagged, or where the user opts in another way16 March 2026
Anthropic, commercial productsNo training on inputs or outputs by default18 August 2026
Google, Gemini Apps on a personal accountActivity kept 18 months by default, with a subset sent to human reviewers29 June 2026
Google WorkspaceContent not human reviewed or used for model training outside the domain without permissionBody 14 August 2026, read as at 24 September 2026
Microsoft Copilot (formerly Microsoft 365 Copilot)Prompts, responses and Microsoft Graph data not used to train foundation models18 August 2026

OpenAI's help centre page, "How your data is used to improve model performance", states, as at 24 September 2026, "By default, we don't use inputs or outputs from ChatGPT Business, ChatGPT Enterprise, ChatGPT Edu, or our API to improve our models." Anthropic's commercial privacy page, "Is my data used for model training?" (commercial), dated 18 August 2026, states "By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models." Microsoft Learn's page, "Data, Privacy, and Security for Microsoft Copilot", last updated 18 August 2026, states "Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs, including those used by Microsoft Copilot." The Google Workspace privacy hub for generative AI, whose body carries 14 August 2026, states "Your content is not human reviewed or otherwise used for Generative AI model training outside your domain without permission."

Read those four sentences closely and the scope is narrow in every case. Microsoft's page separates optional customer feedback, which may be used to improve Copilot but not to train the foundation models, and is managed by an administrator control. Anthropic's commercial page keeps a feedback carve-out alongside the default. Google's Workspace wording turns on the phrase "outside your domain without permission", which is a boundary rather than an absence of processing. OpenAI's page keeps an opt-in route open for API customers, so a business-tier register row records whether anyone has opted the API in, not only that the default holds. A register field that reads "does not train on data" is therefore wrong on all four. The accurate field transcribes that vendor's own scope, being inputs and outputs at OpenAI and Anthropic, foundation models at Microsoft, and training outside the domain without permission at Google Workspace, with feedback handled separately and the tier confirmed on [DATE_CHECKED].

A two column comparison sets the consumer tier of four assistants against the business tier of the same four, showing that the training default changes with the account rather than with the wording of the prompt.
The account tier, not the prompt, sets the training default.

Why do two consumer tiers behave in opposite ways?

The same OpenAI help page states "When you use our services for individuals, such as ChatGPT and Codex, we may use your content to train our models." The opt-out sits in Settings, under Data Controls, in the setting labelled Improve the model for everyone, according to OpenAI's page "Data controls in ChatGPT" as at 24 September 2026. Neither OpenAI page displays a date, only a relative label, so the register records the date the page was read and the URL beside it.

Anthropic's consumer privacy page, "Is my data used for model training?" (consumer), dated 16 March 2026, runs the other way. It lists the circumstances in which consumer chats are used to improve models, the first being that the user chose to allow it, alongside chats flagged for safety review and other forms of opt-in. The same page states "Your Incognito chats are not used to improve Claude, even if you have enabled Model Improvement in your Privacy Settings."

Same task, same paste, opposite defaults. On one consumer product the content is in scope unless the user turns it off. On the other it is out of scope unless the user turns it on, with the separate route that a chat flagged for safety review is used whether or not the user allowed it. A staff handbook that says "turn training off in your AI tool" does not survive that difference: on one product it is a required action, on the other a check that nothing was switched on. Record it per assistant, not per organisation.

The eighteen month default nobody set

Google's consumer position is not a training toggle in the first instance, it is a retention default. The Gemini Apps Privacy Hub carries the Gemini Apps Privacy Notice, last updated 29 June 2026, which states "You can change your auto-delete setting in Gemini Apps Activity from the default of 18 months to 3 months, 36 months, or indefinite." Eighteen months applies where nobody changed the setting.

A single figure, 18 months, sits at the centre of the frame, with the three alternative auto-delete settings of 3 months, 36 months and indefinite arranged around it.
Gemini Apps Activity auto-deletes at 18 months by default, notice last updated 29 June 2026.

Two further mechanics matter more than the headline number, and they sit on differently dated parts of that hub. The privacy questions section, last updated 10 August 2026, states that temporary chats, and chats taken with Keep Activity off, are retained with the account for 72 hours. Temporary chats are not used to train Google's AI models, and with Keep Activity off the same applies to future chats where the user does not submit feedback. Submit feedback with Keep Activity off and the conversation is reviewed by trained teams and retained for up to three years, disconnected from the account. The Privacy Notice, last updated 29 June 2026, separately states that a subset of conversations is sent to service providers for human review, and that chats already reviewed are not deleted when activity is deleted but retained for up to three years. Deleting activity is therefore not a complete erasure claim, and a register recording only the auto-delete number overstates it.

Google states the practical instruction itself in the notice: "Please don't enter confidential information that you wouldn't want a reviewer to see or Google to use to improve our services, including machine-learning technologies." That is a more defensible line in an internal policy than anything paraphrased.

The privacy questions section also states Gemini on a work or school Google Account may be subject to different data handling terms, and points to the Workspace material quoted earlier, so the surface can look identical on two devices while the governing terms differ.

How long does the text survive after deletion?

Retention is a second axis, and it does not move with the training toggle. Anthropic's consumer page, "How long do you store my data?", dated 1 July 2026, states "If you allow us to use your chats or coding sessions to improve Claude, we may retain your data in a de-identified format for up to 5 years in our model training pipelines." The same page sets longer windows where a chat is flagged under the usage policy, including trust and safety classification scores for up to seven years. OpenAI's page Data controls in ChatGPT, as at 24 September 2026, states that temporary chats may be retained for up to 30 days for safety purposes.

The seven year classification-score window sits outside the table below, and the two year row inside it applies only where a chat is flagged.

WindowProduct and tierThe setting or event that produces itPage date
72 hoursGemini Apps, personal accountKeep Activity off, or a temporary chat10 August 2026
30 daysOpenAI, services for individualsTemporary chatsAs at 24 September 2026
30 daysConsumer ClaudeBack end deletion after the user deletes a chat1 July 2026
18 monthsGemini Apps, personal accountDefault auto-delete setting29 June 2026
2 yearsConsumer ClaudeChat flagged under the usage policy1 July 2026
3 yearsGemini Apps, personal accountContent already sent for human review29 June 2026
5 yearsConsumer ClaudeDe-identified, after a model improvement opt-in1 July 2026

The ladder runs from 72 hours to five years across the three products that publish a retention window. Record the window for ordinary use of the tier, and note the flagged window beside it.

A five rung ladder of the retention windows runs from 72 hours at the base to five years at the top, each rung naming the vendor, the tier and the setting that produces that retention window.
The retention ladder, from 72 hours to five years, each figure carrying its own page date.

Two cautions belong beside the ladder. First, every one of these numbers came from a help page that can be edited without notice, so each row carries the date its page displays, or the date it was read where the page displays none. Second, nothing on any of these pages states that switching training off removes content already collected. Opting out and erasure are separate operations with separate evidence, and a policy that treats them as one overstates what the toggle does.

Does a business tier make the paste lawful?

It does not, and no source read for this article suggests otherwise. The vendor page answers what the vendor does with the content. Australian law asks a prior question, whether the content was permitted to leave the organisation's control at all.

The Office of the Australian Information Commissioner's guidance on privacy and the use of commercially available AI products, published 21 October 2024 and last updated 17 January 2025, states that "the OAIC recommends that organisations do not enter personal information, and particularly sensitive information, into publicly available AI chatbots and other publicly available generative AI tools". The guidance also frames the operational distinction: entering personal information into a tool outside the organisation's control is capable of being a disclosure, not merely an internal use, and the regulator expects controls, training and auditing.

The statutory anchor sits in the Privacy Act 1988 (Cth), Schedule 1, Australian Privacy Principle 6.1, in Compilation No. 104, compilation date 4 June 2026, which states that "If an APP entity holds personal information about an individual that was collected for a particular purpose (the primary purpose), the entity must not use or disclose the information for another purpose" unless an exception applies. Personal information collected to administer a claim, a grievance or an employment file was not collected so that a model could process it. Moving it to a business tier changes the vendor's training posture, not the secondary use.

This is general information and not legal advice. The register records the tier as evidence, because a recollection of which plan someone was on in October is not evidence.

Build the register, then the prompts that fill it

The artefact is an assistant register with one row per assistant in actual use. Each fact carries its own source, because one row routinely draws on two vendor pages, as the OpenAI row does.

Assistant and productPlan tierAccount owner roleTraining default and sourceToggle location and sourceToggle state and sourceRetention window and sourceDate checkedReview due
[ASSISTANT_NAME][PLAN_TIER][ACCOUNT_OWNER]not statednot statednot checkednot stated[DATE_CHECKED][REVIEW_DUE]

The governance half is a second table, filled last. Approved destination is a tier whose Australian Privacy Principle 6 assessment is recorded, or "no assistant", because a tier without that assessment is not an approved destination.

Assistant and productWork classes barredApproved destination
[ASSISTANT_NAME]Client, claimant and personnel material[APPROVED_TOOL]

Settings text is evidence of the toggle state only, so the toggle state cell reads "settings screen, read [DATE_CHECKED]" and the vendor page URL stays in the cells for the published position. Client, claimant and personnel material is barred from the consumer tier, and moving it to a business or commercial tier answers the vendor question only, not the Australian Privacy Principle 6 question set out above.

TheAICommand works to the Verified Draft Method: de-identify the inputs, ground the model in your own source material, keep a person at the decision point, verify against the primary source, and log what happened.

The prompts below build the register without importing a fact from the model's memory of a vendor policy. Run all three on the highest tier the organisation holds, because the inventory, the policies and the settings text are internal documents, and a register built on a consumer account breaks its own rule.

Prompt
You are helping build an internal assistant register. Below is a de-identified list of the AI
assistants and plan names in use at [ORGANISATION]. No account names, no user names, no client
content are included.

[ASSISTANT_NAME] - [PLAN_TIER] - owner role: [ACCOUNT_OWNER]
[ASSISTANT_NAME] - [PLAN_TIER] - owner role: [ACCOUNT_OWNER]

The date checked for every row is [DATE_CHECKED].

Produce a markdown table with one row per assistant and these columns: assistant and product,
plan tier, account owner role, training default and source, toggle location and source,
toggle state and source, retention window and source, date checked.

Rules. Do not fill any cell from your own knowledge of vendor policy. In the toggle state
column write "not checked" in every row, because that value comes from the account and not from
any document I have supplied. For every other cell you cannot support from text I supply, write
exactly "not stated" and leave its source blank. In a final list, name each cell marked "not
stated" and the settings screen or vendor documentation section that would state it, for
example "training default: the vendor's help centre page on how customer data is used". Do not
write a URL, because I will supply the URL from the page I open.

What to check: exactly four cells per row are populated, being the four you supplied, the toggle state cell reads "not checked", and the rest read "not stated". Any populated fifth cell is the model answering from memory, and the row is discarded, not corrected. The final list names a page type for each blank cell and volunteers no address, and any URL the model offers is memory, deleted before the register is saved.

Prompt
Use only the attached documents. Attached are [ORGANISATION]'s privacy policy and acceptable
use policy. I will describe a class of document, not its contents.

Document class: [DOCUMENT_CLASS], for example a rehabilitation report, a grievance file note,
or a customer complaint record.

From the attached documents only, produce a de-identification checklist to clear before any
part of that document class is pasted into an AI assistant. For each item, quote the clause of
the attached policy that requires it. If the attached documents do not address an item, write
"not covered by the attached policy" and do not supply a general best practice substitute.

The next list is the one place you may use general knowledge. Under the heading UNGROUNDED,
list the fields typically found in that document class that must be replaced with placeholders
such as [CLAIMANT_NAME], [CLAIM_NUMBER] and [EMPLOYER] before any paste, and state that I must
confirm each field against a real example before relying on it.

What to check: everything above the UNGROUNDED heading quotes a clause that actually appears in the attached policy, and the gaps are returned as gaps. A checklist with no "not covered" lines on a policy that predates generative AI is a warning sign. Confirm the output describes the document class and never reproduces content from a real file.

Prompt
Below is text I exported from the settings screens of [ASSISTANT_NAME] on [DATE_CHECKED].
Before pasting, I have replaced the signed-in address with [ACCOUNT_OWNER], the workspace or
tenant name with [ORGANISATION], and any billing detail with [REDACTED].

[PASTE EXPORTED SETTINGS TEXT]

Before anything else, write one line that reads either "No identifier found" or "Identifier on
line N", an identifier being an email address, a tenant name or a person's name. If you found
one, stop there and do not process the text.

Then write a single evidence line for the assistant register in this form: assistant, plan
tier, training toggle state, retention setting, date checked, source of each value.

Use only the text above. Where the text does not show a value, write "not verified" for that
value and say which settings screen would show it. Do not infer the plan tier from the
features listed.

What to check: the model reported no identifier remaining in the pasted text, and the plan tier is taken from the exported text rather than inferred from which features appear. Confirm that every "not verified" entry names a specific screen. The date checked must match the date of the export, not the date the prompt was run.

Do this Monday

Build one row. The artefact is the Assistant Data Register, the tables above, held wherever the organisation keeps its control documents. The owner is the risk or compliance lead who owns the acceptable use policy, because the register is evidence for it.

The first step fits in under an hour.

  1. Choose the assistant used most across the team.
  2. Open the vendor's own page for that product, starting from the pages linked above.
  3. Use the first prompt above to lay out the table.
  4. Correct every cell against the page, and date the row.
  5. Set review due to six months after the date checked, or to the next plan change, whichever comes first, because the vendor pages carry no change notification.

This article fills the training default cell for all four vendors and the retention cell for the consumer tiers only. On Microsoft Copilot and Google Workspace no toggle or retention window was read for this article, and both are administered at the tenant, so those cells are filled by the administrator who owns the tenant and until then read "not stated" with the date of the attempt.

The check that proves it worked is mechanical. Read the three fact and source pairs, being training default, toggle location and retention window. Each either sits beside a URL that resolves to the vendor page stating it, or reads "not stated", and no cell carries a number from recollection. The toggle state cell is filled from the account, not from a vendor page. If the row passes, fill the governance table, naming the work classes barred and the approved destination.

The bottom line

The account tier decides the default, and the four vendors do not share a default inside the consumer band. As at 24 September 2026, OpenAI states it may use content from its services for individuals to train models unless the user opts out, Anthropic states consumer chats are used where the user allows it, where a chat is flagged for safety review, or on another opt-in, and Google keeps Gemini Apps activity for 18 months unless the setting is changed. All four publish a no-training position for their business, enterprise or commercial tiers, but each is scoped to its own wording and carries its own carve-out, being feedback at Anthropic and Microsoft, an API opt-in at OpenAI, and the domain boundary at Google Workspace. None of that answers the Australian question, because Australian Privacy Principle 6 and the regulator's guidance apply to the paste itself, whatever the vendor does afterwards. Record the tier, the toggle and the retention window with a date and a URL, and move client, claimant and personnel work off the consumer tier.

TheAICommand. Intelligence, At Your Command.

Frequently asked questions

Does a business or enterprise tier make it lawful to paste client information into an assistant?
No source here supports that. The vendor default answers one question only, whether the content is used to train a model. The Office of the Australian Information Commissioner recommends that organisations do not enter personal information into publicly available generative AI tools, and Australian Privacy Principle 6 restricts use or disclosure of personal information for a secondary purpose whatever the vendor setting says.
Where does the training toggle sit on a consumer OpenAI account?
In Settings, under Data Controls, as the setting labelled Improve the model for everyone, according to the OpenAI page Data controls in ChatGPT as at 24 September 2026. Both OpenAI help pages carry a relative update label rather than a date, so the register records the date the page was read rather than a page date, with the URL beside it as evidence.
How long does Google keep Gemini Apps activity by default?
Eighteen months, according to the Gemini Apps Privacy Notice last updated 29 June 2026, changeable to 3 months, 36 months or indefinite. The privacy questions section of the same hub, last updated 10 August 2026, states that chats taken with Keep Activity off, and temporary chats, are retained with the account for 72 hours. Temporary chats are not used to train Google's AI models, and with Keep Activity off the same applies to future chats where the user does not submit feedback.
Does switching training off delete what was already collected?
No vendor page read for this article states that it does, and Anthropic's retention page, dated 1 July 2026, states the opposite: data already in a training run in progress, or in a model already trained, stays there. The pages state separate retention windows: up to five years de-identified in Anthropic model training pipelines after a consumer opt-in, 30 days for OpenAI temporary chats, and up to three years for Gemini content already sent for human review.

Tags

Data PrivacyVendor PolicyAI GovernancePrivacy ActAssistant Tiers
← Back to AI News