Skip to content
agentboards.org

Before you paste · AI privacy guide

Who gets your prompt?

Training off is a useful control. It is only one part of privacy. Find out who processes your data, how long copies remain, and when a local model might make sense.

Provider sources checked 2026-10-06 · Policies vary by model, plan and feature · Educational guide, not AgentBoards’ own privacy policy

Training

Can your content improve a model?

Retention

Which copies remain, and for how long?

Access

Which companies or authorized people can see it?

Location

Where does processing and storage happen?

Three questions · No sign-up

Find your starting point

Choose categories only. Don’t paste private information. These tools keep answers in this page’s memory; they do not submit, save or send your choices to analytics. The site’s normal page analytics may still run.

1. What kind of information would you use?
2. Which requirement matters most?
3. How will you use AI?

Answer all three questions to see a suggested next step. This is an educational starting point, not a security certification.

Choose controls, not a privacy badge

There is no universal “most secure” tier. Local inference gives you control but transfers responsibility to your device and software. Managed services can offer stronger organizational controls while still processing data outside your device.

Personal ChatGPT or Claude

Training
Check your model-improvement setting. A paid personal plan alone is not a business data agreement.
Retention & access
Chat history, safety review and feedback have separate rules. Do not assume every conversation disappears after 30 days.
Why choose it
Easy to start; useful for public information and low-sensitivity tasks.
Tradeoff
Personal account controls may not meet your employer’s requirements.
Next step
Remove identifiers and use an approved account before adding work material.

Personal chat, training off

Training
Disable model-improvement sharing in the account’s privacy or data controls. Review feedback and connected tools separately.
Retention & access
Training off does not mean no storage or no authorized human review. Deleting a chat and disabling training do different jobs.
Why choose it
A useful first step without buying hardware or setting up an API.
Tradeoff
Data still reaches a hosted service. Safety, legal and feature-specific exceptions can apply.
Next step
ChatGPT: Settings → Data controls. Claude: review Privacy / model-improvement controls; use Incognito for chats excluded from model improvement.

Business / Team / Enterprise

Training
OpenAI and Anthropic commercial offerings generally do not train on business data by default; explicit sharing and feedback need separate review.
Retention & access
Workspace retention is plan- and feature-dependent. Buying a business seat does not automatically provide zero retention.
Why choose it
Organization access controls, administration and contractual protections.
Tradeoff
Seat commitments and administration; files, memory and connected apps can have different lifecycles.
Next step
Ask the administrator which data agreement, retention settings, connectors and models are approved.

Direct model API

Training
OpenAI and Anthropic APIs do not use inputs and outputs for training by default, subject to explicit opt-ins.
Retention & access
Default abuse-monitoring retention is generally up to 30 days. Stored objects, model-specific rules and legal or safety exceptions can extend this.
Why choose it
Pay for usage and control what your application sends.
Tradeoff
Your own app, tracing, database and logs can create additional copies.
Next step
Minimize payloads, redact secrets and inventory every storage layer, including tools.

API with approved zero retention

Training
A retention agreement is separate from the provider’s training policy.
Retention & access
Eligibility, approval, supported endpoints and model exceptions matter. “ZDR” is not a blanket promise covering every feature or legal obligation.
Why choose it
Can reduce provider-side storage for eligible inference requests.
Tradeoff
May restrict features or model choice; does not remove your application’s own logs.
Next step
Verify the exact organization, project, model, endpoint and contract before sending sensitive data.

AWS Bedrock

Training
Review the selected model’s terms and your AWS configuration rather than relying on a general cloud label.
Retention & access
AWS documents zero retention by default with exceptions: some models retain traffic up to 30 days; flagged traffic can receive AWS human review. Retained content described in this policy is not shared with third-party model providers.
Why choose it
Fits AWS identity, region and infrastructure controls.
Tradeoff
Specific model policies, invocation logging and cross-region routing still need review.
Next step
Check the model’s abuse policy, logging destinations and destination region. Confirm any ZDR eligibility with AWS.

Google Cloud / Vertex AI

Training
Google documents no training on managed-model customer data without permission.
Retention & access
Zero retention depends on the model and features. Grounding can retain data for 30 days. Some advanced Anthropic models require retention and sharing with Anthropic for abuse monitoring.
Why choose it
Central cloud governance and integration with existing Google Cloud workloads.
Tradeoff
Google Cloud does not guarantee that the model provider never receives your data.
Next step
Check the exact model, abuse-monitoring terms, logging, grounding and provider-sharing settings.

Local model, verified offline

Training
With local weights and fully offline processing, prompts need not go to a hosted model provider.
Retention & access
You control local storage. Apps can still save chats, logs and backups; cloud models, sync and tools can send data out.
Why choose it
Strong control over where inference happens; no per-token hosted-model bill.
Tradeoff
Hardware, maintenance, power and model-quality limits. Downloadable models are not the proprietary ChatGPT or Claude models.
Next step
Disable cloud fallback and internet tools; test with network access blocked. Secure the device, local logs and backups.

Before you share anything sensitive

Minimize the data first: use synthetic examples, remove identifiers and secrets, and send only what the task needs. Confirm permission to use work data.

Personal chat

Review model-improvement sharing in account controls. Check saved history, memory, files and connected apps separately. In Claude, feedback can share the associated conversation and be retained for years; do not submit sensitive examples as feedback.

Business workspace

Confirm your organization’s approved service and data agreement. Ask who can access chats, what retention is configured, how deletion works, and whether feedback sharing and connectors are enabled.

API or managed cloud

Write down every recipient: your app, model host, cloud platform, tools, observability services and authorized reviewers or subprocessors. Verify the model-specific retention policy, region, logs and any provider-sharing requirement. Request applicable agreements and subprocessor information; do not assume every prompt is sent to an annotator.

Local / offline

Use downloaded weights and a local runtime. Disable cloud fallback, web tools, telemetry and cloud sync; review backups. For Ollama, OLLAMA_NO_CLOUD=1 disables its cloud features after restart. Test the full workflow with network access blocked, then secure local storage and device access.

Spot the privacy trap

Would you trust this claim?

Four common assumptions. Pick an answer to reveal the catch.

1. You turn model training off. What have you established?
2. Your company buys business AI seats. Is retention now zero?
3. Does using a cloud platform guarantee no model-provider sharing?
4. A local model uses a cloud web-search tool. Is the whole workflow offline?

0 of 4 answered

Editable assumptions · USD

When does local hardware pay off?

Light usage often favors pay-as-you-go APIs. Frequent, sustained workloads can justify hardware if a local model delivers the quality and speed you need. A subscription buys a capped chat product; its price does not guarantee the API workload entered below.

Starting examples: Claude Pro $20/month and Sonnet 4.6 API $3 input / $15 output per million tokens, checked October 6, 2026 (pricing). Managed-cloud rates, $1/hour GPU rental and $1,500 hardware are illustrative assumptions, not quotes. Replace them with your model, region and hardware costs.

Workload & comparison period
Subscription & direct API
Managed model API — e.g. Bedrock / Vertex
Local hardware

Adjust manually: token volume does not determine runtime here. Include idle time if powered on.

Rented GPU — self-hosted model
Estimated costs over 36 months
OptionUpfrontMonthly equivalent36-month total
Chat subscription$0.00$20.00$720.00
Direct API$0.00$12.00$432.00
Managed model API$0.00$22.00$792.00
Local hardware$1,500.00$49.67$1,788.00
Rented GPU$0.00$70.00$2,520.00

Local running cost: $8.00/month. Hardware payback versus direct API: 375 months (beyond your comparison period); versus managed API: 108 months (beyond your comparison period).

What the calculation includes

API = input millions × input rate + output millions × output rate. Local running cost = watts ÷ 1,000 × hours × electricity price + upkeep. Local monthly equivalent spreads purchase cost minus end-of-period resale over the selected months, then adds running cost. Payback uses purchase price divided by monthly operating savings; it excludes future resale. GPU rental uses the entered hours and hourly price plus monthly extras.

This is a cost scenario, not a benchmark. The same token count does not imply the same quality, capacity or runtime. Measure your workload before buying hardware. Enter labor, storage, backups, idle time and upgrades where relevant. Taxes, financing, API caching/batch discounts, tools, extra inference tokens and usage overages are not automatically modeled. Enterprise plans may combine seats and metered usage. Cloud GPU rental is still cloud processing, not offline privacy.

Check the terms that apply to you

These summaries describe published policies as of 2026-10-06. Recheck before making a purchasing or data-handling decision. A “30-day” policy is not a universal maximum; legal, safety, feedback and stored-feature exceptions can differ.