The tier distinction
That is the whole answer.
Your policy applies to the tenant you bought. Your employees’ behaviour applies to whatever they are logged into — and someone with your enterprise seat and a personal free account in the same browser can move between them without noticing.
Nothing in the enterprise agreement reaches the personal session.
| Account type | Typical training posture | Who is using it |
|---|---|---|
| Free / personal paid | Used for model improvement by default; opt-out available | Anyone who signed up with their work email in five minutes |
| Team / Business | Excluded by contract | Whoever procurement onboarded |
| Enterprise / API with a DPA | Excluded by contract, retention negotiable | Your sanctioned deployment |
Verify before relying on this. Provider terms change, sometimes with little notice. Any page that states another company’s data-handling terms as settled fact — including this one — should be checked against the live agreement during procurement.
The larger risks
Five things that survive a no-training clause.
Training dominates the conversation because it is vivid. These are less discussed and, for most organisations, larger.
- 01
Retention
Conversations persist for a defined window even when excluded from training. Data in a third party’s storage is data in scope for their breach.
- 02
Human review
Most providers reserve the right to have staff review flagged conversations for abuse and safety monitoring. That is a legitimate safety control, and it is also a human reading your content.
- 03
Subprocessors
The provider’s infrastructure and support vendors sit inside the trust boundary you accepted.
- 04
Cross-border transfer
Where processing happens has GDPR consequences independent of whether a model was trained.
- 05
Your own obligations
If the data was PHI, submitting it to a vendor without a BAA is a disclosure regardless of what the vendor does next.
Deletion
“We’ll just delete the conversation.”
Deleting a conversation removes it from the interface and, after the retention window, from storage. If the content was already used in training, deletion does not extract its influence from the model’s weights — that is not a capability anyone currently offers at production scale.
Which is the real point: the effective control is at submission time. Once sensitive data has been sent to a third party, every remaining option is mitigation of a disclosure that has already occurred.
Straight answers
Do business and enterprise AI tiers train on submitted data?
Major providers contractually exclude business and enterprise API and workspace traffic from model training. Terms change, so treat any statement of this — including this page — as something to verify against the provider’s current agreement during procurement.
If training is excluded, is the data safe?
Not entirely. Retention windows, human review for abuse monitoring, subprocessor access, breach exposure and cross-border transfer all persist independently of training. Training is the most discussed risk, not the largest.
Can data already submitted be removed from a trained model?
Practically, no. Deleting a conversation removes it from the interface and eventually from storage under the provider’s retention policy. Influence already absorbed into model weights is not something deletion addresses.
Does an opt-out apply retroactively?
No. Opting out changes how future submissions are handled. Content submitted before the opt-out was governed by the terms in force at the time.