Short answer. Turn off training settings on consumer AI tools. Use enterprise tiers or on-premise solutions for sensitive work (financial statements, customer PII, contracts, proprietary IP). Never paste sensitive data without checking the specific tool's retention and training policies. Assume any AI conversation is public until you have verified otherwise.
The Consumer AI Privacy Baseline
ChatGPT, Claude, Gemini, and other consumer tools use your inputs to improve the model unless you disable the setting. Even with disabled training, some tools retain conversations for 30 days for safety review.
For basic productivity use (drafting emails, summarizing public documents, general research), consumer tiers are fine. The privacy risk is manageable.
For sensitive data (customer PII, financial statements, employee records, contracts, IP), consumer tiers are risky. The training or retention policies may include your data in ways you did not intend.
Turn off training in every consumer AI you use. In ChatGPT: Settings > Data controls > 'Improve the model for everyone' off. In Claude: Settings > Privacy > Model training off. Similar in others.
When To Move To Enterprise Tiers
Financial data at scale. Pasting your P&L into ChatGPT Plus for a one-off analysis is usually fine. Building a workflow that regularly processes financial data needs enterprise privacy.
Customer PII. Any workflow that processes customer names, addresses, SSNs, or health information needs enterprise-grade tools with signed data protection agreements.
Regulated industries. Healthcare (HIPAA), finance (PCI-DSS), legal (attorney-client privilege), education (FERPA). Consumer AI is not compliant. Enterprise or on-premise is required.
Trade secrets or proprietary IP. Do not paste your unpublished product designs, source code, or strategic plans into consumer AI. Enterprise tiers usually have stronger IP protections.
Practical Data Safety Rules
Assume conversations are readable. Even with training off, assume someone at the AI vendor could read your conversations. Do not paste anything you would not want a stranger to see.
Redact before pasting. Remove names, dollar amounts, and identifiable details before pasting. Ask AI to help you with the analysis in the abstract, then apply to your specific numbers offline.
Use business email accounts. Do not sign into ChatGPT with your personal Gmail for business use. Separate accounts, separate data trails.
Train employees on categories. Give employees explicit lists: fine to paste (public data, drafts, general research), not fine (customer data, financials, contracts). Repeat quarterly.
Audit AI use. Talk to employees quarterly about what they are pasting into AI. Most privacy incidents come from well-meaning employees who did not know the boundaries.
Frequently Asked Questions
Is ChatGPT safe for business use? +
For general productivity work with training disabled and no sensitive data pasted, yes. For sensitive data or regulated industries, no.
What is a DPA and do I need one? +
Data Processing Agreement. A contract between you and the AI vendor specifying how they handle your data. Enterprise tiers usually include one. Consumer tiers do not. If you need one, upgrade.
Can I use AI on a client's confidential data? +
Only with the client's written permission, using tools with appropriate DPAs, and typically only enterprise tiers. Consumer AI on client-confidential data is usually a breach of confidentiality.
What if I already pasted sensitive data into ChatGPT? +
Delete the conversation. Turn off training. Consider whether affected parties need to be informed depending on your industry and the sensitivity of what was pasted.
