Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteBefore you send sensitive, regulated, personal, or proprietary information to an AI service, identify the exact product and plan, then verify what its governing documents say about data use, retention, connected features, security, and remedies. A provider’s privacy or security webpage is useful, but it may not be the binding contract—and a promise for one product or account type may not cover another.
1. Identify the exact service and governing contract
Start with the service you will actually use, not the provider’s general brand. Record its product name, tier, account type, deployment route, and region if relevant. Consumer chat, a business workspace, an enterprise deployment, and an API can have different terms even when they use the same underlying models.
Collect the terms of service, privacy notice, product- or service-specific terms, data processing addendum (DPA), security addendum, order form, and any negotiated enterprise agreement. Read the precedence language: if documents conflict, which one controls? OpenAI’s legal index, for example, lists separate individual terms, privacy policy, service terms, DPA, business agreement, enterprise privacy, and data-use materials. The relevant documents depend on the service and relationship.
For organizational use of Microsoft Copilot and Copilot Chat, Microsoft says the Microsoft Products and Services DPA and Product Terms apply, with Microsoft acting as processor. That statement concerns organizational use; do not assume it describes consumer accounts or every connected feature. See Microsoft’s documentation.
#1 Best Overall
2. What happens to prompts, uploads, and outputs?
Make a list of the information the service may receive: prompts, generated responses, uploaded files, images or audio, connector data, feedback, and usage or diagnostic data. For each type, look for permitted uses such as delivering the service, model training or improvement, safety and abuse detection, analytics, human review, and legal compliance.
Check whether a rule is a default, an opt-out, an opt-in, a configurable setting, or a negotiated contractual commitment. A setting that can be changed is not necessarily a promise that applies to every account or feature.
As one specifically scoped example, OpenAI states that, by default, it does not use data from ChatGPT Enterprise, ChatGPT Business, ChatGPT Edu, ChatGPT for Healthcare, ChatGPT for Teachers, or its API platform—including inputs or outputs—to train or improve its models. This is OpenAI’s statement about those named products and the default; it is not a provider-wide rule or an independent assessment. Consult its business data privacy information and the agreement for your account.
Anthropic says commercial customers can opt out of model training through account settings and describes customer-content rights and confidentiality in its stated terms. Microsoft says specified organizational Copilot prompts, responses, and Microsoft Graph data are not used to train foundation models, while web-query handling is distinct. These are provider-specific descriptions with different scopes, not a like-for-like comparison. Check Anthropic’s transparency information, Microsoft’s Copilot documentation, and your applicable terms.
Rank #2
- Used Book in Good Condition
3. How long are chats and other data retained?
Do not treat “chat deletion” as a complete retention policy. Ask about saved conversation history, backend storage after deletion, abuse-monitoring logs, uploaded files, application state, backups, and exceptions for legal requirements or policy enforcement. Find out whether a retention setting requires approval and whether it covers the endpoint and feature you plan to use.
Anthropic’s Privacy Center says API inputs and outputs are deleted from its backend within 30 days, subject to stated exceptions, including services with longer retention, a different agreement, policy enforcement, or legal requirements. For commercial products that save conversations, Anthropic says saved chats remain in product history to support continuity; after a user deletes a chat, it is removed from history immediately and backend systems within 30 days. These are Anthropic’s published timeframes, not an industry standard. See its retention guidance.
OpenAI says Zero Data Retention controls require approval, and its API documentation warns that some endpoints or capabilities may retain application state even when the control is enabled. Confirm eligibility and coverage for the exact API path rather than relying on the label alone. See OpenAI’s API data controls documentation.
4. Does the DPA cover this feature?
Read the DPA alongside the main service agreement. Check the covered products and data, processing roles and instructions, confidentiality, subprocessors, international transfers, breach notification, help with individual-rights requests, deletion or return, audit evidence, and exceptions. Then verify that the DPA is incorporated into the agreement governing the service and covers the features you will use.
Recommended Free Tools
OpenAI’s DPA says it applies to customer data submitted through the API or specified business services under the applicable business terms, enterprise agreement, or other governing agreement. It also says certain compliance materials are provided on reasonable request no more than annually. The DPA’s scope and request terms matter; a public privacy page alone does not establish that the DPA covers a particular product or use. Read the OpenAI DPA together with the applicable service agreement.
For organizational Copilot and Copilot Chat use, Microsoft identifies its DPA and Product Terms as governing documents and describes Microsoft as a processor. Confirm the specific organization, product, and feature are within that scope rather than extending the statement to other Copilot experiences.
5. What security evidence and controls apply?
Separate a provider’s description of security from independent assurance and from controls your organization must configure. Check which product, environment, and data flows a report or certification covers; whether you can obtain the independent report; and what identity, access, retention, or configuration responsibilities remain with you.
OpenAI describes AES-256 encryption at rest and TLS 1.2 or higher in transit for its business data, and lists certifications and audit information for specified services. Those are OpenAI’s stated controls, not an independent security assessment of every product or configuration. See its business data security information.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Rank #4
- Used Book in Good Condition
Microsoft describes enterprise protections including encryption, tenant isolation, and application of organizational identity, permissions, sensitivity labels, retention settings, and audit controls; it also notes details vary by subscription. Verify which protections are available and enabled for the subscription in question in Microsoft’s documentation.
6. What service commitments and remedies are promised?
Privacy and security terms do not answer whether the service has an uptime target, support-response commitment, scheduled-maintenance rules, incident-notice deadline, service credits, liability cap, suspension rights, or data-export and transition support. Find the service-level terms and order form for the exact plan. Check what counts as an outage, how to request a remedy, and what happens to your data if service ends or access is suspended.
The official documents cited here identify where service terms and agreements fit in the document set; they do not establish one comparable availability or support commitment across providers. Do not assume a percentage, response time, or credit unless it appears in the contract that governs your account.
7. Trace connectors, agents, search, and subprocessors
Draw the full data path: core AI service, connectors, retrieval sources, agents, plugins, browsing or search, API endpoints, and subprocessors. For each, ask what information leaves the core service, who controls that processing, which terms apply, and whether the same training, retention, residency, and compliance commitments follow the data.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallMicrosoft says Copilot web queries are sent to Bing under separate data-handling practices and terms, and advises checking an agent’s own privacy statement and terms. A core Copilot commitment should not be assumed to describe those separate paths. See Microsoft’s Copilot privacy documentation. OpenAI’s warning that controls can differ by API endpoint and capability is another reason to trace the feature, not just the account. See OpenAI’s API data controls documentation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.8. Compare providers on the same questions
If you are choosing among services, compare the actual plans and agreements rather than broad privacy claims. Use one row per provider, product, and account type; mark a point “not stated” when the applicable document does not establish it.
| What to compare | What to record |
|---|---|
| Coverage and contract hierarchy | Product, plan, account type, governing agreement, precedence rules, region if relevant |
| Data use | Rules for prompts, outputs, uploads, telemetry, and feedback; training, human review, safety monitoring; defaults and user controls |
| Retention and deletion | Timeframes by data type, endpoint, and feature; deletion process; backups, logs, and exceptions |
| DPA and processing | Scope, roles, subprocessors, location and transfers, legal assistance, deletion or return, audit evidence |
| Security | Controls and independent assurance for the purchased service; customer configuration duties |
| Service commitments | Availability, support, maintenance, incident notice, remedies, liability, suspension, export, and exit |
| Connected features | Separate terms and handling for browsing, search, connectors, agents, and integrations |
9. Turn the review into a go/no-go decision
- Classify the data. Identify whether the proposed inputs include personal, regulated, confidential, or proprietary information, and apply your organization’s rules for that category.
- Map the exact workflow. Record the product, tier, account type, region if relevant, API endpoint or feature, connectors, and agents involved.
- Collect governing documents. Save the applicable terms, privacy notice, DPA, service terms, security materials, and order form; identify which document controls if provisions conflict.
- Resolve material gaps. Ask the provider or procurement/legal team for written clarification on training, retention, DPA coverage, connected services, incident notice, and exit rights where the documents are unclear.
- Configure and document. Apply available data-use, retention, access, and logging controls, then record their scope and any approval or eligibility limits.
- Recheck changes. Provider terms and product behavior can change. Review the current documents before procurement and when adding a plan, connector, agent, or materially different use.
This review helps identify contractual and operational fit; it does not by itself determine legal compliance. Suitability depends on the data, jurisdiction, configuration, agreement, and the organization’s obligations.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

