Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsChoose an AI chatbot for sensitive work by checking the exact product, account, contract, retention rules, administrative controls, data location, and connected features—not by relying on a brand name or a “not used for training” promise. Use only a service and configuration approved for the data you plan to submit. If approval is unclear, redact the material or do not enter it.
What does “private” need to mean for your work?
Before comparing chatbots, define the data and obligations involved. “Confidential” could mean internal business plans, customer records, personal information, regulated data, or legally privileged material; each may have different rules. Ask the owner of your organization’s privacy, security, or legal requirements to classify the material and interpret any applicable obligations.
Then name the specific way you intend to use the service: a personal consumer account, a qualifying work account, a managed business workspace, an API, or an agent embedded in another tool. A personal account does not acquire business protections simply because you use it for work. Terms and controls can vary by product, account, plan, region, model, and feature.
Which protections should you compare?
| Area | Questions to ask | Why it matters |
|---|---|---|
| Product and account scope | Which exact product, account type, plan, region, model, and terms govern this use? | One provider can make different commitments for consumer chat, managed workspaces, APIs, and agents. |
| Training and improvement | Are prompts, files, responses, feedback, or connected data used to train or improve models? Does the commitment cover subprocessors or third-party models? | “Not used for training” may apply only to specified products or features. |
| Retention and deletion | How long are prompts, files, responses, activity history, logs, abuse-monitoring records, feedback, and backups retained? What exceptions apply? | Excluding data from training does not mean that it is immediately deleted. |
| Identity and administration | Are SSO or MFA, roles, least-privilege access, audit, retention policies, DLP, and controls for agents or connectors available on this plan? | Controls matter only if they exist for the selected service and are configured for the workflow. |
| Location and contract | Which data-processing addendum applies? Where may data be stored or processed, and what regional or feature exceptions apply? | Residency commitments and legal terms can be limited by product, model, or circumstance. |
| Integrations and routing | Can a prompt invoke web search, a connector, an agent, or another model? Which terms govern that route? | A connected feature may process data under additional documentation or terms. |
What do providers say about their business and consumer services?
The following are provider statements, not independent audits of every possible setup. Confirm the current agreement, product scope, and configuration before relying on them.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
| Provider and service scope | What its official materials say | What to verify |
|---|---|---|
| OpenAI business products and API | OpenAI’s business-data materials describe organization data protections for ChatGPT Enterprise, Business, Edu, Healthcare, Teachers, and API, and refer users to product-specific retention information. They also describe data-processing addenda, eligible regional storage and processing, and administrative features such as MFA, roles, SSO, and, for some products, SCIM. OpenAI’s security materials describe an independent SOC 2 Type 2 examination for its API and ChatGPT business services and ISO certifications for specified services. | Eligibility, retention, residency, controls, and certification scope differ by service and plan. Check that the exact product and configuration are covered; a certification is not blanket approval for a particular data category or use. |
| Microsoft Copilot for organizations | Microsoft says organizational Copilot and Copilot Chat enterprise data protection is covered by its DPA and Product Terms, uses customer data as instructed, and does not use prompts, responses, or Graph data to train foundation models. It also says applicable identity, permission, sensitivity-label, retention, and audit policies carry through, with controls varying by subscription. | Microsoft documents Bing web queries as a separate service with different data-handling practices and directs customers to inspect agent privacy statements and terms. Its Microsoft 365 Copilot privacy documentation says prompts and responses are stored as activity history, admins can set retention, processing can route to other regions in some circumstances, and some third-party models have regional-boundary exceptions. |
| Google Gemini for Google Workspace | Google says qualifying Workspace use receives Workspace protections: content is not human reviewed or used for model training outside the domain without permission, and existing controls such as data-region policies and DLP apply. Google also documents that Gemini access follows Workspace permissions and can be restricted by administrators and file owners. | Google distinguishes qualifying Workspace use from Gemini used as an additional service without a qualifying Workspace edition; consumer terms may apply in the latter case, and chats may be reviewed or used to improve services. Verify the edition and account in use. |
| Anthropic Claude consumer service | Anthropic’s consumer privacy materials describe model-improvement settings. If improvement is enabled, chats may be retained in de-identified form in model-training pipelines for up to five years, according to its current privacy documentation accessed in 2026. | Anthropic describes exceptions for flagged usage-policy violations and legal or policy needs. Its consumer terms should not be assumed to govern commercial products. Check the settings and terms for the actual product. |
| Anthropic API | Anthropic’s platform documentation says zero data retention applies under an organization-level arrangement and means prompts and responses are not stored at rest after the API response returns. | Confirm that the arrangement is in place and covers the exact product and request path. Other record types, sessions, or tools may follow different retention models. |
Why are training and retention separate checks?
Training describes whether content is used to improve or train models; retention describes whether and how long data is kept for other purposes. A service can exclude prompts from foundation-model training yet retain conversation history, activity logs, safety-review records, or feedback under separate rules. Ask for retention periods by data type, along with deletion behavior and exceptions—not just a yes-or-no training answer.
For example, Anthropic’s consumer policy says enabled model-improvement data may be retained in de-identified form for up to five years. It also describes retention of inputs and outputs for up to two years for specified flagged usage-policy violations, and classification scores for up to seven years. These are limits in the described consumer policy and exceptions, not general retention rules for Claude or other AI services.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
How can connected features change the data path?
A chatbot may send some requests to a web-search service, connector, agent, or third-party model. Those features can have distinct terms, privacy statements, regional handling, and retention. Microsoft, for example, describes Bing web queries as a separate service and tells customers to inspect agent terms; Microsoft 365 Copilot documentation also notes circumstances involving other regions or third-party models.
Inventory the features users can actually invoke, not only those enabled by default. Include browser and mobile apps, connected repositories, feedback tools, web search, agents, plugins, and model routing. For each, identify what information can be sent, who processes it, and which terms apply.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
How should you evaluate a chatbot before allowing sensitive inputs?
- Classify the material. Record whether the intended inputs are public, internal, confidential, personal, regulated, or legally privileged. Ask the responsible privacy, security, or legal owner to interpret the organization’s requirements where needed.
- Specify the exact setup. Name the service, account, plan, region, model, and enabled features—including apps, web search, connectors, agents, and feedback.
- Read the controlling documents. Confirm the applicable terms and data-processing addendum, then check training use, retention by data type, deletion, subprocessors, breach handling, data location, and legal exceptions.
- Match controls to the workflow. Check identity and permissions, MFA or SSO, audit, administrator retention settings, DLP, and least-privilege access to connected repositories. Confirm the selected plan includes the controls you need.
- Pilot without sensitive information. Use synthetic or already-public material. Verify administrator settings and inspect logs and access behavior before approving confidential inputs.
- Document and maintain the decision. Tell users what may be submitted and which approved service and account they must use. Set a reporting process for accidental disclosure, and review the decision when terms, enabled models, or features change.
What should not count as approval by itself?
- A vendor’s “not used for training” statement, without checking retention and feature-specific handling.
- The words “enterprise,” “private,” or “encrypted,” without confirming the contract, product scope, settings, and data category.
- A certification or compliance statement without checking which services, regions, configurations, and controls it covers.
- A general privacy page when the actual workflow uses an API, agent, connector, search feature, or third-party model with separate terms.
No provider privacy page alone establishes that a chatbot is suitable for every confidential task. Make the decision against the current terms and your organization’s requirements for the specific service and configuration you will use.
Quick Recap
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

