Privacy Rules by Vendor
How the major AI platforms handle your data — by plan tier. Last updated: February 23, 2026.
Informational only — not legal advice. Vendor policies change frequently; always verify current terms directly with each vendor and consult qualified legal counsel for compliance decisions.
ChatGPT
OpenAI
| Feature | Free Free | Plus / Pro Plus / Pro | Team / Business Team / Business | Enterprise Enterprise |
|---|---|---|---|---|
| Risk score | Critical | High | Medium | Low |
| Training on your data | Opt-out | Opt-out | No | No |
| Contractual no-training | No | No | Yes | Yes |
| Retention control | Fixed | Fixed | Fixed | Configurable |
| Human review | Possible | Possible | Possible | Restricted |
| Certifications | None documented | None documented | SOC 2 Type IIGDPR-align | SOC 2 Type IIGDPR-alignHIPAA-ready (with BAA)ISO 27001FedRAMP (select) |
Consumer-grade. Conversations may be used to train models by default. Users can opt out in Settings → Data Controls but there is no contractual guarantee. Staff and contractors may review chats for safety/abuse.
Still consumer-grade. Training opt-out available in settings but not contractually guaranteed. OpenAI can change the policy at any time. No business-level controls or compliance certifications.
Data is not used for model training by default. SOC 2 Type II certified. However, third-party contractors can still review conversations for abuse monitoring without explicit permission. Retention is fixed at ~30 days.
Contractual no-training guarantee. Admin-configurable retention. Human access only with explicit customer permission (except legal obligations). HIPAA-ready with BAA. SOC 2, GDPR alignment, some FedRAMP offerings.
Claude
Anthropic
| Feature | Free Free | Plus / Pro Pro | Team / Business Team | Enterprise Enterprise |
|---|---|---|---|---|
| Risk score | High | High | Medium | Low |
| Training on your data | Opt-out | Opt-out | No | No |
| Contractual no-training | No | No | Yes | Yes |
| Retention control | Configurable | Configurable | Configurable | Configurable |
| Human review | Possible | Possible | Restricted | Restricted |
| Certifications | None documented | None documented | SOC 2 Type IIGDPR (DPA available) | SOC 2 Type IIGDPR (DPA)HIPAA-ready (with BAA)ISO 27001 |
Consumer-grade. Following 2025 policy changes, data retention increased significantly. Training opt-out is available but requires manual verification. No business-level compliance guarantees or admin controls.
"Pro" is still a consumer account — not a business plan. Following 2025 policy changes, retention can extend up to 5 years for some data. Opt-out available but no contractual guarantees. Solo practitioners should note the lack of enterprise protections.
Contractual "no training on customer data" guarantee. Admin-controlled data retention. SOC 2 Type II, SAML SSO, SCIM, audit logs. DPA available for GDPR compliance. Commercial Terms of Service with explicit confidentiality.
Contractual no-training guarantee. Admin-controlled retention with option to disable chat history entirely. HIPAA-ready with signed BAA. Fine-grained RBAC, audit logs, client-side encryption option, SSO/SCIM.
Gemini
| Feature | Free Gemini App (Free) | Plus / Pro Gemini Advanced | Team / Business Gemini in Google Workspace | Enterprise Gemini Enterprise |
|---|---|---|---|---|
| Risk score | Critical | Critical | Medium | Low |
| Training on your data | Yes (default) | Yes (default) | No | No |
| Contractual no-training | No | No | Yes | Yes |
| Retention control | Fixed | Fixed | Configurable | Configurable |
| Human review | Possible | Possible | Restricted | Restricted |
| Certifications | None documented | None documented | SOC 2 Type IIISO 27001ISO 27017ISO 27018GDPRHIPAA (with BAA) | SOC 2 Type IIISO 27001ISO 27017ISO 27018ISO 42001 (AI)FedRAMP HighHIPAA (with BAA)GDPRBSI C5 |
Consumer product. Data may be used to improve Google AI models. Human review by Google staff for quality and safety. No business-level security guarantees. Not appropriate for business or confidential data.
Still a consumer product despite the premium price. Data may be used to improve models. Human review possible. No business controls, workspace isolation, or DLP. Not suitable for confidential business data.
Business-grade. Data is not used to train models outside the customer domain. Respects existing Google Workspace permissions. Includes DLP controls, IRM, comprehensive audit logs, and AI classification. SOC 2, ISO 27001.
Highest tier. Adds data sovereignty controls, CMEK/CSE, External Key Manager, VPC Service Controls. ISO 42001 (AI management), FedRAMP High for government. Full HIPAA compliance support. Regional processing options.
Grok
xAI
| Feature | Free Free (X users) | Plus / Pro Premium+ | Team / Business Business | Enterprise Enterprise (Vault) |
|---|---|---|---|---|
| Risk score | Critical | High | Medium | Medium |
| Training on your data | Opt-out | No | No | No |
| Contractual no-training | No | No | Yes | Yes |
| Retention control | Unknown | Unknown | Configurable | Configurable |
| Human review | Unknown | Unknown | Restricted | Restricted |
| Certifications | None documented | None documented | SOC 2GDPRCCPA | SOC 2GDPRCCPA |
Consumer tier with very limited public documentation on data handling. xAI claims data is not used for training, but documentation and independent validation are limited. Treat as high-risk for any business data.
xAI states data is not used for training on all tiers, but limited public documentation and no independent audits. Newer platform with less established track record. Not suitable for confidential business data.
Launched January 2026. No training on business data. SOC 2, GDPR, CCPA compliant. Centralized admin controls, usage analytics, SSO. However, platform is newer with limited enterprise deployment history.
Launched January 2026. Enterprise Vault provides premium isolation with dedicated infrastructure, customer-managed encryption keys, and isolated data planes. Custom SSO, SCIM, RBAC. Note: platform is still relatively new and maturing.
Perplexity
Perplexity
| Feature | Free Free | Plus / Pro Pro | Team / Business Enterprise Pro | Enterprise Enterprise Pro |
|---|---|---|---|---|
| Risk score | Critical | Critical | Medium | Medium |
| Training on your data | Yes (default) | Opt-out | No | No |
| Contractual no-training | No | No | Yes | Yes |
| Retention control | Fixed | Fixed | Configurable | Configurable |
| Human review | Possible | Possible | Restricted | Restricted |
| Certifications | None documented | None documented | SOC 2 Type IIGDPR (claimed)HIPAA (claimed, unverified) | SOC 2 Type IIGDPR (claimed)HIPAA (claimed, unverified) |
High risk. Data is used for model training by default. Broad tracking including cookies, IP addresses, device info, and search history. No end-to-end encryption. Third-party analytics active. Not suitable for any business data.
Training opt-out available but tracking and third-party analytics remain active. No contractual guarantees for business use. GDPR compliance not met by default. Not suitable for confidential business data.
No training on enterprise data (guaranteed). SOC 2 Type II. GDPR and HIPAA compliance claimed but not independently verified. Configurable retention. Tracking/cookies still present. Limited sub-processor transparency.
Same as Team/Business tier — Perplexity currently maps enterprise customers to the Enterprise Pro offering. Claims compliance but lacks independent verification for GDPR and HIPAA. Treat with caution for regulated data.
Check how these rules apply to your specific setup
Get a personalised risk assessment based on your tools, data, and industry.
Informational only — not legal advice. Vendor policies change frequently; always verify current terms directly with each vendor and consult qualified legal counsel for compliance decisions.
