Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Before you send sensitive, regulated, personal, or proprietary information to an AI service, identify the exact product and plan, then verify what its governing documents say about data use, retention, connected features, security, and remedies. A provider’s privacy or security webpage is useful, but it may not be the binding contract—and a promise for one product or account type may not cover another.

1. Identify the exact service and governing contract

Start with the service you will actually use, not the provider’s general brand. Record its product name, tier, account type, deployment route, and region if relevant. Consumer chat, a business workspace, an enterprise deployment, and an API can have different terms even when they use the same underlying models.

Collect the terms of service, privacy notice, product- or service-specific terms, data processing addendum (DPA), security addendum, order form, and any negotiated enterprise agreement. Read the precedence language: if documents conflict, which one controls? OpenAI’s legal index, for example, lists separate individual terms, privacy policy, service terms, DPA, business agreement, enterprise privacy, and data-use materials. The relevant documents depend on the service and relationship.

For organizational use of Microsoft Copilot and Copilot Chat, Microsoft says the Microsoft Products and Services DPA and Product Terms apply, with Microsoft acting as processor. That statement concerns organizational use; do not assume it describes consumer accounts or every connected feature. See Microsoft’s documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. What happens to prompts, uploads, and outputs?

Make a list of the information the service may receive: prompts, generated responses, uploaded files, images or audio, connector data, feedback, and usage or diagnostic data. For each type, look for permitted uses such as delivering the service, model training or improvement, safety and abuse detection, analytics, human review, and legal compliance.

Check whether a rule is a default, an opt-out, an opt-in, a configurable setting, or a negotiated contractual commitment. A setting that can be changed is not necessarily a promise that applies to every account or feature.

As one specifically scoped example, OpenAI states that, by default, it does not use data from ChatGPT Enterprise, ChatGPT Business, ChatGPT Edu, ChatGPT for Healthcare, ChatGPT for Teachers, or its API platform—including inputs or outputs—to train or improve its models. This is OpenAI’s statement about those named products and the default; it is not a provider-wide rule or an independent assessment. Consult its business data privacy information and the agreement for your account.

Anthropic says commercial customers can opt out of model training through account settings and describes customer-content rights and confidentiality in its stated terms. Microsoft says specified organizational Copilot prompts, responses, and Microsoft Graph data are not used to train foundation models, while web-query handling is distinct. These are provider-specific descriptions with different scopes, not a like-for-like comparison. Check Anthropic’s transparency information, Microsoft’s Copilot documentation, and your applicable terms.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. How long are chats and other data retained?

Do not treat “chat deletion” as a complete retention policy. Ask about saved conversation history, backend storage after deletion, abuse-monitoring logs, uploaded files, application state, backups, and exceptions for legal requirements or policy enforcement. Find out whether a retention setting requires approval and whether it covers the endpoint and feature you plan to use.

Anthropic’s Privacy Center says API inputs and outputs are deleted from its backend within 30 days, subject to stated exceptions, including services with longer retention, a different agreement, policy enforcement, or legal requirements. For commercial products that save conversations, Anthropic says saved chats remain in product history to support continuity; after a user deletes a chat, it is removed from history immediately and backend systems within 30 days. These are Anthropic’s published timeframes, not an industry standard. See its retention guidance.

OpenAI says Zero Data Retention controls require approval, and its API documentation warns that some endpoints or capabilities may retain application state even when the control is enabled. Confirm eligibility and coverage for the exact API path rather than relying on the label alone. See OpenAI’s API data controls documentation.

4. Does the DPA cover this feature?

Read the DPA alongside the main service agreement. Check the covered products and data, processing roles and instructions, confidentiality, subprocessors, international transfers, breach notification, help with individual-rights requests, deletion or return, audit evidence, and exceptions. Then verify that the DPA is incorporated into the agreement governing the service and covers the features you will use.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

OpenAI’s DPA says it applies to customer data submitted through the API or specified business services under the applicable business terms, enterprise agreement, or other governing agreement. It also says certain compliance materials are provided on reasonable request no more than annually. The DPA’s scope and request terms matter; a public privacy page alone does not establish that the DPA covers a particular product or use. Read the OpenAI DPA together with the applicable service agreement.

For organizational Copilot and Copilot Chat use, Microsoft identifies its DPA and Product Terms as governing documents and describes Microsoft as a processor. Confirm the specific organization, product, and feature are within that scope rather than extending the statement to other Copilot experiences.

5. What security evidence and controls apply?

Separate a provider’s description of security from independent assurance and from controls your organization must configure. Check which product, environment, and data flows a report or certification covers; whether you can obtain the independent report; and what identity, access, retention, or configuration responsibilities remain with you.

OpenAI describes AES-256 encryption at rest and TLS 1.2 or higher in transit for its business data, and lists certifications and audit information for specified services. Those are OpenAI’s stated controls, not an independent security assessment of every product or configuration. See its business data security information.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft describes enterprise protections including encryption, tenant isolation, and application of organizational identity, permissions, sensitivity labels, retention settings, and audit controls; it also notes details vary by subscription. Verify which protections are available and enabled for the subscription in question in Microsoft’s documentation.

6. What service commitments and remedies are promised?

Privacy and security terms do not answer whether the service has an uptime target, support-response commitment, scheduled-maintenance rules, incident-notice deadline, service credits, liability cap, suspension rights, or data-export and transition support. Find the service-level terms and order form for the exact plan. Check what counts as an outage, how to request a remedy, and what happens to your data if service ends or access is suspended.

The official documents cited here identify where service terms and agreements fit in the document set; they do not establish one comparable availability or support commitment across providers. Do not assume a percentage, response time, or credit unless it appears in the contract that governs your account.

7. Trace connectors, agents, search, and subprocessors

Draw the full data path: core AI service, connectors, retrieval sources, agents, plugins, browsing or search, API endpoints, and subprocessors. For each, ask what information leaves the core service, who controls that processing, which terms apply, and whether the same training, retention, residency, and compliance commitments follow the data.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft says Copilot web queries are sent to Bing under separate data-handling practices and terms, and advises checking an agent’s own privacy statement and terms. A core Copilot commitment should not be assumed to describe those separate paths. See Microsoft’s Copilot privacy documentation. OpenAI’s warning that controls can differ by API endpoint and capability is another reason to trace the feature, not just the account. See OpenAI’s API data controls documentation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

8. Compare providers on the same questions

If you are choosing among services, compare the actual plans and agreements rather than broad privacy claims. Use one row per provider, product, and account type; mark a point “not stated” when the applicable document does not establish it.

What to compare What to record
Coverage and contract hierarchy Product, plan, account type, governing agreement, precedence rules, region if relevant
Data use Rules for prompts, outputs, uploads, telemetry, and feedback; training, human review, safety monitoring; defaults and user controls
Retention and deletion Timeframes by data type, endpoint, and feature; deletion process; backups, logs, and exceptions
DPA and processing Scope, roles, subprocessors, location and transfers, legal assistance, deletion or return, audit evidence
Security Controls and independent assurance for the purchased service; customer configuration duties
Service commitments Availability, support, maintenance, incident notice, remedies, liability, suspension, export, and exit
Connected features Separate terms and handling for browsing, search, connectors, agents, and integrations

9. Turn the review into a go/no-go decision

  1. Classify the data. Identify whether the proposed inputs include personal, regulated, confidential, or proprietary information, and apply your organization’s rules for that category.
  2. Map the exact workflow. Record the product, tier, account type, region if relevant, API endpoint or feature, connectors, and agents involved.
  3. Collect governing documents. Save the applicable terms, privacy notice, DPA, service terms, security materials, and order form; identify which document controls if provisions conflict.
  4. Resolve material gaps. Ask the provider or procurement/legal team for written clarification on training, retention, DPA coverage, connected services, incident notice, and exit rights where the documents are unclear.
  5. Configure and document. Apply available data-use, retention, access, and logging controls, then record their scope and any approval or eligibility limits.
  6. Recheck changes. Provider terms and product behavior can change. Review the current documents before procurement and when adding a plan, connector, agent, or materially different use.

This review helps identify contractual and operational fit; it does not by itself determine legal compliance. Suitability depends on the data, jurisdiction, configuration, agreement, and the organization’s obligations.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.