Can I put client data into Claude?
Often yes, but the plan you are on changes the answer. Anthropic states that by default it does not use inputs or outputs from its commercial products, which include Claude for Work Team and Enterprise plans and the API, to train its models, while on the consumer Free, Pro, and Max plans model training is governed by a setting you choose in Privacy Settings and can change at any time. In both cases, conversations flagged by Anthropic's safety systems can still be reviewed and used to improve its trust and safety models. Before client material goes in, remove identifying details where you can and check what your own client agreement and professional obligations require.
Which Claude you are on changes the answer
Anthropic runs two different sets of terms, and that split is the most important thing to understand before a client file goes near a chat window. Commercial products sit under the Commercial Terms. Consumer plans sit under the Consumer Terms. The model training policy is not the same in both places.
For commercial products, Anthropic's privacy documentation states that by default it will not use your inputs or outputs to train its models. Its August 2025 announcement of the updated Consumer Terms said the same thing from the other direction: the consumer changes do not apply to services under the Commercial Terms.
For the consumer plans, Free, Pro, and Max, including Claude Code used from one of those accounts, model training is governed by a setting you control. Anthropic described it as a choice, said new users select it during signup, and said existing users had until October 8, 2025 to make a selection in order to keep using Claude.
The practical read for a small firm: if you routinely handle other people's confidential material, moving the firm onto a Team or Enterprise plan puts you under the commercial terms, where the published default is no training on your inputs and outputs. That is a different footing than five people each paying for Pro.
- Under the Commercial Terms: Claude for Work, which is the Team and Enterprise plans, the Anthropic API, API access through Amazon Bedrock and Google Cloud Vertex AI, Claude Gov, and Claude for Education.
- Under the Consumer Terms: Free, Pro, Max, and Claude Code used from one of those accounts.
What the consumer training setting controls, and what it does not
Anthropic's help center lists the conditions under which consumer chats and coding sessions may be used to improve its models. There are three: you allow it in your privacy settings, the conversation is flagged for safety review, or you explicitly opt in some other way, such as joining the Trusted Tester program.
I am not going to tell you which way your setting is currently pointing. Anthropic does not publish one universal default that applies to every account, and the rollout put the choice in front of different people at different moments. Go look at the actual toggle. On desktop it is under Settings, then Privacy, then the control labeled Help Improve our AI models. Check it on every account in your office, not just your own.
The safety review exception is the part most summaries skip, and it is the one worth knowing. Anthropic states that if its safety classifiers flag your conversations, those conversations may still be used to improve its internal trust and safety models, detect harmful content, enforce its policies, and support its safety research. Turning the training setting off does not remove that path.
Turning the setting off also works forward, not backward. Anthropic says your data stays in model training runs already in progress and in models already trained, and that it will stop using previously stored chats in future training runs. One more detail that matters if you connect Claude to your file storage: Anthropic states that training data does not include raw content from connectors such as Google Drive or MCP servers, but content is included if it was copied directly into the conversation.
Incognito chats are useful, but they are not a vault
Incognito chats are available to Free, Pro, Max, Team, and Enterprise users. They are not saved to your chat history or to Claude's memory, and Anthropic states they are not used to improve Claude even when the model improvement setting is turned on. For a quick question you would rather not have sitting in a chat list, that is a reasonable tool.
Treating incognito as a private mode where nothing is recorded is a mistake, and a small firm should know the limits before relying on it.
- Incognito chats are still retained for 30 days by default, or longer under an organization's custom data retention setting on Enterprise.
- On Team and Enterprise plans, incognito chats are included in organizational data exports available to account Owners.
- On Enterprise, incognito chats are included in the Compliance API.
- Incognito mode is not available inside projects, and a closed incognito chat cannot be reopened or converted to a regular chat.
How long anything actually stays
On the consumer plans, Anthropic states the standard retention period is 30 days if you do not allow your data to be used for model improvement. If you do allow it, it says data may be retained in de-identified form for up to 5 years in its model training pipelines, applying to new or resumed chats after the setting is enabled. Deleting a conversation removes it from your chat history immediately, deletes it from back-end storage within 30 days, and keeps it out of future model training.
Flagged content is held longer. Anthropic states it retains inputs and outputs for up to 2 years, and trust and safety classification scores for up to 7 years, where a chat is flagged by its automated systems as violating the Usage Policy. Separately, using the thumbs up or thumbs down button stores the entire related conversation for up to 5 years. On Team and Enterprise, an Owner can switch that off with the Rate chats setting under Organization settings, then Data and Privacy.
For the API, Anthropic states it automatically deletes inputs and outputs within 30 days of receipt or generation, with exceptions including services with longer retention under your control such as the Files API, cases where a zero data retention agreement is in place, Usage Policy enforcement, and legal requirements.
Treat all of these numbers as current rather than permanent. Anthropic has revised its retention terms before, most visibly in August 2025. The privacy center articles linked below are the source of truth, and they are worth rechecking before you copy any figure into a firm policy document.
The rule a small firm can actually follow
This is not legal advice, and it is not tax or compliance advice either. What follows is an operating habit that keeps most of the value while keeping the exposure small. For anything with real consequences, ask the person whose license is on the line.
If you are a lawyer, this ground is already covered by professional rules. ABA Formal Opinion 512, issued July 29, 2024, applies the existing Model Rules of Professional Conduct to generative AI tools. Under Rule 1.6 on confidentiality, a lawyer must keep confidential all information relating to the representation of a client, regardless of its source, unless the client gives informed consent. The opinion goes a step further on tools that learn from what is put into them: it concludes that because many self-learning tools available at the time of writing were designed so their output could lead directly or indirectly to disclosure of that information, a client's informed consent is required before inputting information relating to the representation, and that boilerplate language in an engagement letter does not amount to informed consent. The opinion also notes that this conclusion rests on the capabilities of the tools as of its publication and could change as they do.
Opinion 512 also applies Rule 1.1 on competence, which the ABA describes as requiring lawyers to understand the benefits and risks of the technologies they use to deliver legal services, and Rule 1.4 on communication, which requires reasonably consulting the client about the means used to accomplish their objectives. It further tells managing and supervising lawyers to set clear firm policies on permitted use and to train the people they supervise. Your state bar may have gone further than the ABA. Accountants, financial advisers, and anyone else practicing under a professional standard should assume their own regulator has published something as well, and go find out what it says.
The habit itself is short enough to teach an office in ten minutes.
- Remove identifying details before you paste. Names, account and matter numbers, addresses, dates of birth, and dollar figures tied to a specific person can usually come out without hurting the work. Claude does not need to know whose file it is to tighten a paragraph or catch a gap in a checklist.
- Work from summaries and templates rather than source documents. Most of the value is in structure, tone, sequence, and completeness, and all of that survives redaction.
- Read the contract before their material goes anywhere. Engagement letters, NDAs, vendor terms, and client data agreements often already say something about third-party processing and subcontractors. If yours does not answer the question, ask the client rather than assuming.
- Write down which plan and which settings your firm uses, and make it uniform. One person working from a personal Free account undoes the policy for everyone else.
- Check the source before you rely on a summary of the rules, including this one. Policies change, and the links below are where the current version lives.
Sources
Policies and product details change. Check the source rather than trusting this page indefinitely.
- Anthropic Privacy Center: Is my data used for model training? (Free, Pro, Max)
- Anthropic Privacy Center: Is my data used for model training? (commercial products)
- Anthropic: Updates to Consumer Terms and Privacy Policy, August 28, 2025
- Anthropic Privacy Center: How do I change my model improvement privacy settings?
- Anthropic Privacy Center: How long do you store my data? (consumer plans)
- Anthropic Privacy Center: How long do you store my organization's data? (commercial products)
- Anthropic Support: Use incognito chats
- ABA: First ethics guidance on a lawyer's use of AI tools, July 29, 2024
- ABA Formal Opinion 512, Generative Artificial Intelligence Tools (PDF)
Need to send this to someone else?
I will email you this answer with every source linked, so it stands up when it lands in front of IT, legal, or finance. Plus the questions that usually come next. Unsubscribe any time.
Want to know what Claude can actually do in your business?
Four questions, about a minute, and Claude writes three automations for your specific situation with the exact prompts. No account.
Build my plan