To find out what happens to personal, client, or confidential data after it reaches an AI service, evaluate the exact product, account type, deployment route, and enabled features—not just the provider’s name. Training use, visible chat history, backend deletion, safety monitoring, and data sent to connected tools are separate questions, and each may have a different answer.
1. Define exactly what service you are evaluating
Record the configuration people will actually use before comparing privacy claims. A consumer app, business workspace, API, cloud-hosted deployment, and individual API endpoint may have different settings and terms, even when they carry the same provider’s brand.
Capture the account and technical route
- Product name and account tier, including whether users are signed into a personal or organization-managed account.
- Whether people use a web or mobile interface, an API, or a cloud marketplace deployment.
- Models, API endpoints, and modes in use, plus any enabled file, memory, voice, browsing, coding, or agent features.
- The organization, project, or workspace that owns the configuration, and who can change its controls.
Deployment route can change who processes the data. Anthropic’s API retention documentation distinguishes its first-party API arrangements from use through Amazon Bedrock and Google Cloud Agent Platform, where the cloud provider is the data processor. Check the terms for the route you use rather than assuming first-party terms apply unchanged.
Map integrations and other recipients
List connected apps, cloud services, MCP servers, and other tools that receive prompts, files, or tool-call data. OpenAI notes that remote MCP servers are third parties whose own retention policies apply to data sent to them; Anthropic and Google documentation also describes data handling across integrations. A provider’s privacy terms do not, by themselves, establish how each connected service handles information.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
2. Inventory the data that enters and leaves the system
Include more than the text a user types. Make a list of information submitted, generated, or collected around the interaction so that each category can be matched to a stated purpose, retention period, and deletion control.
- Prompts, generated answers, files, images, audio, and video.
- Feedback, ratings, and conversations or files flagged for safety review.
- Account identifiers, device or browser information, usage metadata, and subscription details.
- Content retrieved from connected apps, tool calls, generated summaries, and feature-specific application state.
- Information retained for service operation, security, abuse prevention, or legal obligations.
For example, Google’s Gemini Apps Privacy Hub lists prompts and uploads alongside generated content, app, browser, and device information, connected-app information, location, and subscription information. Treat that as a description of Gemini Apps—not as a complete inventory for every AI product.
3. Separate each use of the data
For every category in your inventory, ask separately whether it is used to provide the requested service, maintain or secure the service, prevent abuse, support human review, improve products, train models, personalize responses, or meet a legal obligation. Identify which setting or contract governs each purpose, who can change it, and whether it affects data already submitted or only future use.
“Not used for training” does not mean “not stored,” “not reviewed,” or “deleted.” A service may retain information for operation or safety even when it is excluded from model training. Likewise, a training choice may apply to one product and not another.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →One scope-specific example: Anthropic’s August 28, 2025 consumer-policy announcement says users of its Free, Pro, and Max consumer plans can choose whether their data is used to improve Claude. It says that, when a consumer user allows model-training use, new or resumed chats and coding sessions are retained for five years; users who do not make that choice remain on the stated 30-day period. The announcement says the change does not apply to commercial services or API use, so do not apply those consumer terms to those offerings.
4. Compare retention by data category, not by headline number
Build a retention table for the exact product and configuration. For each row, note the ordinary retention period, what starts the clock, whether the data appears in user-visible history, how backend deletion works, who can delete it, and any exceptions. Keep different data types—such as API inputs, product chats, feedback, safety records, and application state—in separate rows.
Rank #4
These published examples show why one provider-wide retention number is usually misleading:
| Product and data category | Published period and scope | Important qualification |
|---|---|---|
| Anthropic commercial API inputs and outputs | Automatically deleted from backend storage within 30 days of receipt or generation, according to its commercial retention FAQ accessed in 2026. Anthropic retention FAQ | Longer user-controlled feature retention, an agreement, Usage Policy enforcement, or law may change the period. |
| Anthropic commercial product chats and safety records | Deleted chats disappear from visible history immediately and are deleted from backend storage within 30 days. The same FAQ says flagged Usage Policy violations may result in inputs and outputs being kept for up to 2 years, and trust-and-safety classification scores for up to 7 years. Anthropic retention FAQ | These are separate data categories and exceptions, not one retention period for all commercial data. |
| Anthropic Free, Pro, and Max consumer chats and coding sessions | The August 28, 2025 announcement states five years when the user allows model-training use; otherwise, it says the existing 30-day period continues. Anthropic announcement | This statement concerns the specified consumer plans, not Anthropic’s commercial services or API. |
| Google Gemini Apps temporary chats and chats made with Keep Activity off | Retained with the account for 72 hours for response and protection purposes, according to the Gemini Apps Privacy Hub last updated September 24, 2026. Google Gemini Apps Privacy Hub | The Hub separately says reviewed chats and related data may be retained for up to 3 years after activity deletion. |
| Google Gemini Apps Activity | The Hub describes 18 months as the default auto-delete setting, with options for 3 months, 36 months, or indefinite retention. Google Gemini Apps Privacy Hub | This is an activity setting, not a statement that every data category is retained for exactly that period. |
| OpenAI API abuse-monitoring data | The API data-controls documentation, accessed in 2026, lists 30-day abuse-monitoring retention for several endpoints. OpenAI API data controls | This is not a universal API rule: endpoints differ, and application-state retention and Zero Data Retention eligibility also vary by endpoint. |
5. Find out what “delete” and “zero retention” cover
Ask what a user’s delete action changes immediately and what happens later in backend systems. Check whether the stated deletion covers visible history, files, feedback, safety-review material, application state, backups, and information already passed to tools. Also look for legal or policy exceptions. For example, Google says human-reviewed conversations are not deleted when Gemini activity is deleted, while Anthropic describes policy-enforcement and legal exceptions in its commercial retention FAQ.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
Do not assume a “zero data retention” (ZDR) label means no data of any kind is stored across every product and feature. OpenAI says approved organizations can set retention controls at organization and project levels, but ineligible endpoints or capabilities may retain application state even when ZDR is enabled. Anthropic says ZDR is enabled per organization and applies only to eligible API features; it does not cover every consumer or commercial interface or third-party integration. Read the applicable OpenAI endpoint controls and Anthropic API retention terms for the specific feature in question.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.6. Verify who controls the setting and which users it protects
For every privacy control, confirm whether it is available to an end user, an administrator, or only through a contract; whether approval is required; whether it applies at the organization, project, or individual level; and which models, endpoints, tools, and modes qualify. Record the answer alongside the setting, not just the marketing label.
Check that the account is actually covered by the business terms you expect. Google distinguishes Gemini Apps from qualifying Workspace use: its Workspace FAQ says Workspace submissions are not human-reviewed or used for generative AI model training outside the customer’s domain without permission. It also warns that users without qualifying Workspace licenses are subject to different terms when using the Gemini app.
7. Use a consistent comparison before approving a service
If you are evaluating multiple services, compare the same data categories and product scope for each. A shorter stated period for one category does not establish that a provider is more private overall if another service uses different exceptions, retains different data, or applies different controls.
| Comparison field | What to record |
|---|---|
| Product and route | Exact product, tier, account type, API or interface, deployment route, endpoints, enabled features, and organization. |
| Data categories | Inputs, outputs, files, feedback, identifiers, metadata, connected-app content, tool calls, and application state. |
| Use and training | Service, safety, review, improvement, and training purposes; relevant controls; and whether the choice is prospective. |
| Retention and deletion | Period for each data category, start of the retention clock, visible-history behavior, backend deletion, and exceptions. |
| Controls and exclusions | User and administrator controls, approval requirements, eligible features, excluded endpoints, and contractual commitments. |
| Other recipients | Cloud providers, connected apps, MCP servers, and other subprocessors, with their applicable terms. |
| Evidence | Link to the current primary documentation or contract and the date you checked it; use “not stated in the reviewed source” when a material term is not established. |
8. Record what remains unresolved
Provider documentation is not, by itself, a determination that a particular use complies with your organization’s legal, contractual, residency, or security obligations. The examples above cover selected OpenAI API, Anthropic API and commercial and consumer offerings, and Google Gemini and Workspace offerings; they do not compare every provider or settle jurisdiction-specific requirements. For sensitive or regulated information, have the relevant security and legal reviewers assess the actual contract, deployment, data flows, and applicable obligations before use.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

