Calendar Icon White
September 15, 2026
Clock Icon
7
 min read

Does Claude Train on Your Data? (2026 Facts)

Yes on consumer plans (claude.ai Free/Pro/Max) by default since Aug 28, 2025 unless you opt out; no on the API and business plans. Retention, opt-out, and how to keep sensitive data out of Claude entirely.

Does Claude Train on Your Data? (2026 Facts)
ChatGPT
Perplexity
Grok
Google AI
Claude
Summarize and analyze this article with:

TL;DR

  • It depends how you use Claude. On consumer plans (claude.ai Free, Pro, Max), Anthropic does train on your chats and coding sessions by default — unless you opt out — following a terms change on August 28, 2025.
  • On commercial products (the API, Claude for Work, Enterprise, Education, Government), your data is not used to train models.
  • On consumer plans, opting out keeps a 30-day retention window; staying opted in extends retention to up to 5 years.
  • Either way, the safest move is to keep sensitive data out of Claude in the first place — Strac redacts PII, PHI, and secrets before they ever reach it.

✨ Does Claude Train on Your Data?

Yes on consumer plans (unless you opt out); no on commercial plans. This is the single most misreported fact about Claude, because the answer changed in 2025. If you use claude.ai on a Free, Pro, or Max account, Anthropic can now use your conversations and coding sessions to train its models unless you turn that setting off. If you use Claude through the API or a business plan, Anthropic does not train on your data. Knowing which bucket you’re in is the whole game.

Diagram showing Claude trains on consumer data by default but not commercial API data
Does Claude train on your data? Consumer plans: yes by default since Aug 2025 (opt out available). Commercial: no.

What Changed in August 2025

Before 2025, Anthropic did not train on consumer conversations by default. That reversed with Anthropic’s updated consumer terms. Under the updated policy:

SettingWhat happens to your data
Stay opted in (default)Chats and coding sessions may be used to train Claude; retention extends to up to 5 years
Opt outYour new conversations are not used for training; retention stays at 30 days
Existing usersWere prompted to choose by September 28, 2025

The retention change is the part people miss: leaving the training setting on extends how long your conversations can sit in Anthropic’s pipeline from 30 days to as much as five years. Anthropic has said it de-identifies this data and does not sell it — but it is still your content, in a training set, for years.

The Commercial Side: API, Work, and Enterprise

Business use is treated very differently. Under Anthropic’s commercial terms, traffic through the API, Claude for Work, Enterprise, Education, and Government is not used to train models. Anthropic also offers Zero Data Retention (ZDR) for qualifying use cases, and can sign a BAA for HIPAA workloads. So a company building on the Claude API is in a fundamentally different position than an employee using a personal Claude Pro account — which is exactly where the risk hides.

Why This Is Really a Shadow-AI Problem

Here’s the trap: your company may have an enterprise Claude agreement with no training and ZDR — but your employees also have personal Claude Pro accounts, and they paste work data into those. That consumer traffic is trained on by default. You don’t control Anthropic’s consumer policy, and you can’t see which account an employee used. The only durable control is to stop sensitive data from reaching Claude at all — on any account.

✨ How Strac Protects Data Before It Reaches Claude

Strac’s browser DLP detects and redacts PII, PHI, secrets, and source code in real time — in the browser, before the text is submitted to claude.ai, the Claude API, or Claude Code. It works whether the employee is on a corporate or personal account, with no proxy and no TLS interception. So it doesn’t matter whether that particular Claude account trains on data or not: the sensitive part never leaves.

Strac redacting sensitive data in a Claude conversation
Strac redacting PII and PHI inside a Claude conversation in real time.
Strac browser DLP blocking sensitive data before it reaches Claude
Strac’s browser DLP warns and blocks sensitive data before it’s submitted to Claude — on any account, no proxy, no TLS interception.

For the fuller picture, see Is Claude AI safe, Claude data privacy, Claude DLP, and Is Claude HIPAA compliant.

Strac coverage across SaaS, cloud, endpoint, email, browser and AI
Strac protects data across Claude and every other AI tool, SaaS app, cloud store, and endpoint — one policy.

🌶️ Spicy FAQs: Claude and Training

Does Claude train on your data?

On consumer plans (claude.ai Free, Pro, Max) - yes, by default, since August 28, 2025, unless you opt out. On commercial products (API, Claude for Work, Enterprise, Education, Government) - no, your data isn’t used for training.

How do I stop Claude from training on my data?

On a consumer plan, open your privacy settings and turn off the model-training / ‘help improve Claude’ option. Opting out also keeps retention at 30 days instead of up to 5 years. Commercial API and business accounts aren’t used for training in the first place.

How long does Anthropic keep my Claude conversations?

If you leave the training setting on (consumer), retention extends to up to 5 years. If you opt out, it’s 30 days. Commercial products follow the commercial data terms, and Zero Data Retention is available for qualifying use.

Is the Claude API used for training?

No. Under Anthropic’s commercial terms, API traffic - along with Claude for Work, Enterprise, Education, and Government - is not used to train models.

Is it safe to put company data into Claude?

Only if you control the account and the data. The safer approach is to redact sensitive data before it reaches Claude - because employees often use personal Claude accounts (which do train by default). Strac does this automatically in the browser.

The Bottom Line

Claude trains on consumer conversations by default now (since August 2025) and not on commercial API traffic. But you can’t police which account an employee uses — so the reliable control is to keep sensitive data out of Claude entirely. Strac redacts it before it’s ever submitted. Book a demo to see it in action.

Does Claude train on your data?
How do I stop Claude from training on my data?
How long does Anthropic keep my Claude conversations?
Is the Claude API used for training?
Is it safe to put company data into Claude?
Discover & Protect Data on SaaS, AI, MCP, Endpoints & Cloud
Strac provides end-to-end data loss prevention for all SaaS and Cloud apps. Integrate in under 10 minutes and experience the benefits of live DLP scanning, live redaction, and a fortified SaaS environment.
Trusted by enterprises
Data Security + Compliance Automation

Latest articles

Browse all

Get Your Datasheet

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Close Icon