Anthropic’s current privacy policy took effect on July 8, 2026. It adds terms that matter to lawyers, particularly around connecting Claude to other applications. This post is updated to reflect it.
If you are using Claude, Anthropic’s AI assistant, you probably want to know whether your conversations are private.
The answer is: it depends.
It depends on which type of account you have.
It depends on what settings you have chosen.
The key thing to remember is that paying for Claude does not automatically mean your data is handled in a way that is appropriate for confidential or sensitive information. What matters is whether you are using a consumer or a commercial/business level plan.
This post explains how Claude actually handles data, what changes across account types, and how they impact legal professionals.
Consumer vs. Commercial Accounts
Anthropic offers several Claude plans, but they do not all provide the same privacy protections. From a confidentiality perspective, there are really two categories that are important: consumer and commercial-grade accounts.
Consumer accounts include Free, Pro, and Max. Commercial-grade accounts include Team, Enterprise, and API-based usage. Team and Enterprise together make up what Anthropic calls Claude for Work, and both run under the Commercial Terms of Service: “When a commercial customer creates a Claude for Work account (Team or Enterprise plan), under our Commercial Terms of Service the customer is the ‘Controller’ of the data submitted by its Users.”
What Happens to Your Data on Consumer Accounts
If you are using Claude on a Free, Pro, or Max plan, your conversations may be retained and may be used to improve Anthropic’s models depending on your settings. In generative artificial intelligence this is what is referred to as training. No lawyer (or anyone concerned about privacy) should ever allow training on data they enter into an AI. Fortunately, training on Claude comes down to one setting. The only way to know if you have been opted out already or if training is on is to open your privacy settings and look. If training is on, I recommend that you turn it off.
Checking if Training is On
To check to see if training is on, go to the web version of Claude, click on Settings, then Privacy. The toggle is called “Help Improve Claude.” The direct link is claude.ai/settings/data-privacy-controls. Make sure the toggle is grayed out. This means it is off. If you do not want Anthropic to know your location information, toggle that off as well. Keep in mind, even if you toggle “Location metadata” off, Anthropic still infers a rough location for security purposes.

Retention in Consumer Accounts
Retention follows the same setting as training. If you allow training, Anthropic may “retain your data in a de-identified format for up to 5 years in our model training pipelines.” If you do not allow it, the answer is less clear than it used to be. When Anthropic announced this system in August 2025, it said that anyone who declined training would “continue with our existing 30-day data retention period.” That number is no longer in the privacy policy or in the current help center article on retention. The policy now says only that Anthropic “retains your personal data for as long as reasonably necessary for the purposes and criteria outlined in this Privacy Policy.” I would not assume the 30 days still applies to stored chats without asking Anthropic.
Retention for Deleted Chats in Consumer Accounts
There is a 30-day period that is still documented, and it is different from training. When you delete a conversation, it comes out of your chat history immediately and is “[d]eleted from our back-end storage systems within 30 days.” To put it plainly, in consumer accounts, if you delete a chat, it takes 30 days for it to be removed from Anthropic’s systems.
Flagged Chats in Consumer Accounts
There is a third period that is easy to miss. If your chat is flagged by Anthropic’s automated systems as violating the Usage Policy, Anthropic retains “inputs and outputs for up to 2 years and trust and safety classification scores for up to 7 years.” Turning off model training does not turn that off. The policy says so directly. Even if you opt out, Anthropic will still use inputs and outputs for model improvement when a conversation is flagged for safety review or when you report something through the feedback tools. While Anthropic does not provide a list of what will get you flagged, the Usage Policy does provide some guidance in this regard.
Rating a Chat: Thumbs Up or Thumbs Down
There is one more thing that the training setting does not cover, and this is one that often escapes notice in privacy reviews. If you click thumbs up or thumbs down on a response, Anthropic keeps the whole exchange. “When you provide us feedback via our thumbs up/down button, we will store the entire related conversation, including any content, custom styles or conversation preferences, in our secured back-end for up to 5 years.” It does that whether or not you have model improvement turned off, and it may use the conversation to train its models. Anthropic de-links the feedback from your user ID first and does not combine it with your other chats. The content is still the content.
Picture the sequence. You ask a question, Claude gives you a bad answer, you hit thumbs down the way you would on many social media sites. You have just handed over the full conversation for five years. If the chat is one you would not want retained, do not rate it.
Incognito Chats
If you have training on, you may avoid it for an individual chat by using the incognito option. Incognito chats are not used to improve Claude even if you have model improvement enabled.
Summary for Consumer Accounts
In practical terms, here is what you need to know about consumer level accounts:
- Your prompts may be stored for a period of time.
- Your content may be reviewed by humans in limited circumstances.
- Your data may be used for product improvement unless you have disabled that option.
Fundamentally, what this means is that consumer Claude accounts are not designed for regulated or confidential environments.
Commercial Accounts: How Team, Enterprise, and API Usage Are Different
Claude for Work, meaning the Team and Enterprise plans, and API-based usage operate under different terms. These offerings are designed for organizational use and generally include:
- Stronger contractual privacy commitments
- No training on customer data
- More predictable data handling and retention controls
The structure for commercial accounts is different from consumer accounts. Under the Commercial Terms the customer is the controller and Anthropic is the processor, which means Anthropic processes the data as instructed by the customer rather than on its own terms. Two consequences follow. Your firm, not Anthropic, sets the rules for that data. And if you are on someone else’s Team account, that someone else is the one holding the controls.
Anthropic does not use commercial data for model training unless the customer joins its Development Partner Program. That is the customer’s choice to make, so it is worth confirming your firm has not made it before you assume training is off.
Commercial accounts are the tier intended for businesses, institutions, and professional environments where confidentiality matters. It is also the tier that aligns more closely with what lawyers, health providers, and other regulated professionals expect.
The key here is that there is only one way to get these protections. You only get them by being on a commercial/business grade plan.
A Warning about Fable: Zero Data Retention Does Not Apply
The Fable 5 model is different from other models. Anthropic designates some models as Covered Models, meaning a model whose capabilities “represent a substantial step up from prior generations and create elevated risk if misused.” Claude Fable 5 and Claude Mythos 5 are on that list. Covered Models “require 30-day data retention; ZDR is therefore not available for either model.” ZDR is zero data retention, an arrangement some commercial customers negotiate so that Anthropic keeps nothing. All of the other retention numbers I explained are the maximum period the data is currently kept. For Covered Models, the number is a minimum, and it cannot be negotiated away.
If your firm negotiated a zero data retention agreement and someone starts using Fable 5, ZDR will not apply to the chat. Fortunately, the API does not quietly substitute a different model. It returns an error telling you to enable retention. You can carve out one workspace: “Organizations with a ZDR arrangement can make Claude Fable 5 and Claude Mythos 5 available in a specific workspace by enabling 30-day retention for that workspace only. Other workspaces in the organization keep zero data retention.” This helps prevent attorneys and staff from inadvertently using a model that lacks ZDR.
Keep in mind that if you switch models in the middle of a conversation, it is likely that the entire conversation will be retained under this new policy. Anthropic does not specifically address this issue, but each entry in a chat resends the prior conversation as part of the new prompt. Therefore, it makes sense that the entire conversation is covered. In order to find out for certain, I recommend reaching out to Anthropic to ask.
The ZDR issue with Fable 5 only changes things for firms that negotiated zero data retention. Everywhere else, your chats are already retained, and Claude Fable 5 is no different. For firms with ZDR, what I suggest is that you discourage attorneys and staff from using Claude Fable 5 with any confidential information or any data you do not want retained.
Specific Additions to the July 8, 2026 Policy
Connectors
The first major addition is about connected applications. A connector allows Claude to connect to various applications. For example, there is a connector that allows Claude to access your Microsoft 365 account. I suggest you review the policies related to connected applications very carefully. Claude can take actions in other services on your behalf, and the policy now spells out what that does to your data. “Claude may send your Inputs, Outputs, and instructions to Third-Party Services to perform actions on your behalf (such as reading files, sending messages, or retrieving information).” The consequence of using connectors is: “The Third-Party Service receives this data directly and processes it according to its own privacy policy.”
Once you connect Claude to your email, document storage, or practice management system, Anthropic’s terms are no longer the only terms. Whatever the receiving service does with data, it does under its own policy. Anthropic also puts the authority question back on you. Before you enable an integration or tell Claude to act on another service, you are expected to make sure you have the authority to grant that access. For a lawyer, that is not only a technical question. It is also a client confidentiality question.
Verification
The second is verification. Anthropic may ask you to verify your age or identity. If you agree, what it collects can include an image of your government-issued identity document and your image in photo or video form, along with facial geometry templates, which the policy acknowledges “may be considered ‘biometric data’ in some jurisdictions.” Some jurisdictions have passed laws related to biometric data. As a result, you will want to check the relevant laws in the jurisdiction(s) in which you practice or where your clients are located.
Studies and Marketing
The last two changes are smaller, and they are separate from each other. The policy now describes research studies, surveys, and interviews. If you take part in one, Anthropic collects your responses along with your account data. Participation is voluntary, so there is nothing to opt out of.
The second is about how Anthropic communicates with you. The stated purpose is “To provide you with service updates, communications, and to provide tailored recommendations about our Services that may be of interest to you.” These relate to Anthropic’s own services, not third-party products. If you want out of the marketing, the route is the unsubscribe link in the emails themselves. I could not find a toggle for it in Claude’s settings.
One last note, Anthropic continues to say that it does not sell your data and that Claude has no ads. If you are interested in learning more about protecting your privacy across websites, take a look at the Global Privacy Control website. GPC is a browser signal that tells the sites you visit you are opting out of the sale and sharing of your data. Anthropic says it honors it, but it does not respond to the older Do Not Track signal. GPC is not an Anthropic site.
Why Confusing Naming is an Issue
Anthropic is not unique in confusing names for its different accounts. Many AI companies use terms like Pro, Team, or Premium in ways that suggest business readiness.
A Pro plan in generative AI usually means better features or higher limits. It does not necessarily mean stronger confidentiality protections. A Team plan usually means shared billing and collaboration features. With Claude it also means the Commercial Terms. That is Anthropic’s structure, though, not an industry rule. Check the terms for the specific generative AI product you are using.
If you are a lawyer this is an important distinction. Client confidentiality is not a marketing concept. It is a professional obligation.
What This Means for Lawyers
If you are using Claude with any client information, even in anonymized form, you need to be very clear about which tier you are on and what Anthropic’s terms say about data use and retention.
Consumer accounts are not designed to support attorney client confidentiality. That does not mean you cannot use them at all. It does mean you need to be careful about how you use them.
In practical terms, that usually means:
- Do not paste identifiable client information into consumer AI tools.
- Do not assume that paying for Pro makes a service safe.
- Do not rely on marketing language instead of reading the actual privacy terms.
- Do not connect Claude to your email, your files, or your case management system without knowing what that service does with the data it receives, and without confirming you have the authority to grant the access.
If you want to use Claude as part of your legal workflow, the appropriate path is Claude for Work or API-based usage with proper contractual protections.
The Bottom Line
Claude can be a powerful tool. Fortunately, Anthropic is relatively transparent about its privacy practices. None of this post is meant to be an accusation or a warning about misconduct. This post is simply a reminder that not all paid accounts are created equal, and not all AI tools are structured for professional confidentiality. What it comes down to is:
- If you are using Claude casually, consumer plans are fine.
- If you are using Claude professionally, especially as a lawyer, you need to be much more deliberate.
- Privacy is not about the label on the plan. It is about the actual terms behind it. The only way to be certain is to read the terms and to make sure you keep up-to-date with the changes.
TL;DR for Lawyers
- Free / Pro / Max = consumer accounts. Do not use for real client data. If you do use these account types, anonymize.
- Team provides certain commercial protections, because Team is part of Claude for Work and runs under the Commercial Terms.
- Claude for Work (Team or Enterprise) or API access with proper agreements is the appropriate path for confidential client work.
- If you allow training, your data may be retained for up to 5 years. If you do not, Anthropic said 30 days back in August 2025, but the current policy no longer commits to a number.
- Deleting a chat is the one place 30 days still appears. It leaves your history immediately and Anthropic’s back-end storage within 30 days.
- Chats flagged by the automated safety systems are kept longer. Up to 2 years for the content and up to 7 years for the classification scores.
- Connecting Claude to another app sends your data to that app, which handles it under its own privacy policy.
- Do not rate any chats with a thumbs up or thumbs down. Rating overrides your training setting and stores the entire conversation for five years.
- Zero data retention agreements do not cover Claude Fable 5 or Mythos 5. Those models require a 30-day retention floor that you cannot opt out of.
- If you are not sure which account type you have, assume you are not protected.