What the popular AI tools are actually allowed to do with your data.
Not the marketing. The terms. We read what ChatGPT, Gemini, Copilot, Claude, Perplexity, Grok, Meta AI and DeepSeek permit themselves to do with what you type, on the tiers most professionals actually use.
On the consumer tiers that a solo GP, a small firm or a sole practitioner actually uses, the mainstream AI tools generally store what you type, many train on it by default, some let staff read it, and several sit under legal regimes outside the UK. "The business tier is safe" is true and beside the point, because most professionals are not on the business tier. If you would not post it publicly, most of these tools are not where it belongs.
Consumer tiers, read from the terms.
The rubric is the same for each tool: does it train on your inputs by default, how long does it keep them, can a human read them, and what is the catch. Figures are for the personal or free tiers unless noted.
| Tool | Trains on your input by default? | Retention | Human review | The catch |
|---|---|---|---|---|
| ChatGPT | Yes, opt-out buried in Settings, Data Controls | Saved until you delete, then up to 30 days | Yes, staff may review | API and business tiers are not trained on; consumers are. A 2025 US court order (the NYT case) forced retention of even deleted chats, since largely lifted. |
| Google Gemini | Yes, unless turned off | Apps Activity 18 months by default; reviewed chats kept up to 3 years even after you delete | Yes, a subset goes to human reviewers | Paid API and Vertex are exempt; the consumer app is not. |
| Microsoft Copilot | Yes on consumer, on conversation activity unless opted out | Per policy | Per policy | Commercial (work account) and the Microsoft 365 apps are covered by enterprise data protection; standalone consumer Copilot is not. |
| Anthropic Claude | Yes, unless you decline; the Aug 2025 setting defaults to on | 30 days if you decline training, 5 years if you allow it | For safety classification | Consumer plans only (Free, Pro, Max); Work, Gov, Edu and API run under separate commercial terms and are exempt. |
| Perplexity | Yes, with an opt-out toggle in the product | Kept until you delete, then open-ended | Per policy | In 2026 Perplexity dropped its 30-day deletion promise and its change-notification promise from the policy text; the in-product opt-out toggle remains. Enterprise and the Sonar API are zero-retention. |
| xAI Grok | Yes, on your prompts, its responses, and your public posts (non-EU) | Retained for security regardless of your setting | xAI can read chats; not end-to-end encrypted | Opt-outs are split across several settings and are not retroactive. |
| Meta AI | Yes, on your Meta AI chats and public posts | Per policy | Per policy | There is no simple in-app opt-out and the WhatsApp toggle was removed; UK and EU users can object under GDPR via a form. WhatsApp messages stay end-to-end encrypted, but Meta AI interactions do not. |
| DeepSeek | Yes | Stored indefinitely on servers in China | Per policy | Subject to China's 2017 National Intelligence Law, which can compel access. Banned for government use in several countries. A Jan 2025 breach exposed over a million records. |
Methodology: each verdict is read from the tool's own current published consumer terms and from public reporting, on the tier a typical solo professional uses. Terms change often, so we date-stamp this page and you should confirm any single cell against the live policy, linked in the sources below, before you rely on it.
In 2026 the protections got weaker, not stronger.
The usual advice is "just opt out." The problem is that the opt-outs are quietly being weakened across several providers at once:
- Perplexity dropped its 30-day deletion promise and its change-notification promise from the policy text in 2026; the in-product opt-out toggle remains, but retention is now open-ended.
- Anthropic began using consumer chats to train Claude from its August 2025 update, with the setting defaulting to on and retention rising to five years if you allow it.
- Meta removed the WhatsApp opt-out toggle and offers no simple in-app opt-out for Meta AI, though UK and EU users can object under GDPR.
The direction of travel is less user protection, not more. A tool you were told to "just opt out of" last year may quietly train on you this year. An opt-out you have to keep watching is not confidentiality.
Your duty does not have an opt-out.
If you are a solicitor, a doctor, an accountant or in HR, the confidential material you handle is not yours to feed into a system that stores or trains on it. Every UK regulator has said so, and a UK tribunal has ruled that putting confidential documents into a public AI tool can waive privilege and trigger a duty to notify the regulator and the ICO. The tools in the table above are, on their consumer tiers, mostly the wrong place for that work. That is the entire reason Hush exists.
The rubric, and the tool that passes it.
A tool is safe for confidential professional work when the answer to all four is right:
- Are your inputs stored? With Hush, no. Conversations are never saved to our servers.
- Can they train a model? No. We never train on what you type.
- Can a human read them? No. There is no conversation or document stored to read.
- Whose legal reach is it under? On hardware we own, with no US parent, so there is nothing to hand to a foreign order.
Hush runs on hardware we own and keeps no conversations or documents. What you type is processed, then gone, so there is nothing to leak, sell, subpoena or quietly start training on. It is the confidentiality a Microsoft lawyer told the French Senate, under oath, he could not promise.
Use AI on the work you cannot put into ChatGPT.
Try it on a real letter or a real document, the kind you would never paste into the tools above. No card, no account needed.
Start Free →Prefer to check one tool at a time? Use the interactive AI training checker. Or see the side-by-side comparisons, or read our own security page.
This page summarises third-party terms as published and reported at the review date, for general information. It is not legal advice, and the tools' terms change. Verify any point against the primary source before you act on it.